From 4f58fdcf73763f97175a92a7853fe252742a6eed Mon Sep 17 00:00:00 2001 From: Damien Daspit Date: Wed, 30 Sep 2026 15:55:55 -0400 Subject: [PATCH 1/3] Let the Claude workflow push with its app token The checkout step persisted the job's read-only GITHUB_TOKEN as a git extraheader. That header takes precedence over the app token the action puts in the remote URL, so pushes went out as github-actions[bot] and were denied. See the #369 run. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/claude.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 3fe1ebf6..83f55a54 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -40,6 +40,9 @@ jobs: with: # Full history so git log and blame can find the commits AGENTS.md cites. fetch-depth: 0 + # The persisted read-only GITHUB_TOKEN header overrides the action's app token, so + # pushes went out as github-actions[bot] and were denied. + persist-credentials: false - name: Set up Python ${{ env.PYTHON_VERSION }} uses: actions/setup-python@v6 From 8f83d3695fa0e47faef0d2d7cbae4b980e811b6f Mon Sep 17 00:00:00 2001 From: Damien Daspit Date: Wed, 30 Sep 2026 16:06:16 -0400 Subject: [PATCH 2/3] Resolve rejected findings and hide old review summaries A finding the author rejected or deferred stayed open, so the PR carried threads nobody meant to act on. The review now resolves them and records them as withdrawn or accepted. Each round also posted a new summary beside the old ones. The review now minimizes its earlier summaries as outdated. Co-Authored-By: Claude Opus 5.5 --- .claude/skills/pr-review/SKILL.md | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/.claude/skills/pr-review/SKILL.md b/.claude/skills/pr-review/SKILL.md index dca0f646..1a9a1835 100644 --- a/.claude/skills/pr-review/SKILL.md +++ b/.claude/skills/pr-review/SKILL.md @@ -9,7 +9,8 @@ user-invocable: true Post one short comment per finding, anchored on the line it is about, then one summary comment. A review leaves the code alone: do not edit, commit, or push. -The only thread it resolves is its own finding, once addressed or withdrawn. +The only threads it resolves are its own findings, once addressed, withdrawn, +or rejected by the author. Unless verified findings are already in hand, get them first with `/code-review high `, without `--comment`: it finds and verifies, and @@ -42,10 +43,11 @@ open findings first, then add only what is new. - Fixed: `F3 addressed in :` and what fixed it, then resolve the thread by its `id`: `gh api graphql -F id= -f query='mutation($id: ID!) { resolveReviewThread(input: {threadId: $id}) { thread { isResolved } } }'` - - Author gave a reason: weigh it. If it holds, `F3 withdrawn:` and why, then - resolve the thread. If not, answer once with evidence; a point already - answered stays answered. - - Author chose to keep it, e.g. deferred to an issue: record it as accepted. + - Author rejected it, with or without a reason: weigh any reason given. If + it holds, `F3 withdrawn:` and why. If not, `F3 accepted:` with your + evidence, once. Either way, resolve the thread: the author has decided. + - Author chose to keep it, e.g. deferred to an issue: `F3 accepted:` and + where it went, then resolve the thread. - Still applies and its code changed: `F3 still applies at :` and why. - Still applies and its code is untouched: stay silent; the summary counts it. @@ -142,4 +144,13 @@ End with `Reviewed at `, the PR head from `gh pr view --json headRefOid`, not the merge commit checked out, so the next round knows where this one stopped. +Once the new summary is posted, minimize each earlier one as outdated, so only +the latest shows. An earlier summary is a top-level comment by `claude[bot]` +containing `Reviewed at`; leave its other comments, such as replies to an +`@claude` mention, visible. Take its `node_id` from the comments listing: + +``` +gh api graphql -F id= -f query='mutation($id: ID!) { minimizeComment(input: {subjectId: $id, classifier: OUTDATED}) { minimizedComment { isMinimized } } }' +``` + For an adversarial second pass, apply `docs/review/devils-advocate.md`. From 9054b768c4dd93c47ada166297bda69a71e5ad8c Mon Sep 17 00:00:00 2001 From: Damien Daspit Date: Wed, 30 Sep 2026 17:22:52 -0400 Subject: [PATCH 3/3] Keep rejected Critical findings open for a maintainer A Major: finding stays Blocking in Reviewable until a maintainer dismisses it, so the review no longer resolves one the author rejected. Rejected and deferred findings now share one rule. Co-Authored-By: Claude Opus 5.5 --- .claude/skills/pr-review/SKILL.md | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/.claude/skills/pr-review/SKILL.md b/.claude/skills/pr-review/SKILL.md index 1a9a1835..adb2dd53 100644 --- a/.claude/skills/pr-review/SKILL.md +++ b/.claude/skills/pr-review/SKILL.md @@ -10,7 +10,7 @@ user-invocable: true Post one short comment per finding, anchored on the line it is about, then one summary comment. A review leaves the code alone: do not edit, commit, or push. The only threads it resolves are its own findings, once addressed, withdrawn, -or rejected by the author. +or, unless Critical, rejected or deferred by the author. Unless verified findings are already in hand, get them first with `/code-review high `, without `--comment`: it finds and verifies, and @@ -43,11 +43,10 @@ open findings first, then add only what is new. - Fixed: `F3 addressed in :` and what fixed it, then resolve the thread by its `id`: `gh api graphql -F id= -f query='mutation($id: ID!) { resolveReviewThread(input: {threadId: $id}) { thread { isResolved } } }'` - - Author rejected it, with or without a reason: weigh any reason given. If - it holds, `F3 withdrawn:` and why. If not, `F3 accepted:` with your - evidence, once. Either way, resolve the thread: the author has decided. - - Author chose to keep it, e.g. deferred to an issue: `F3 accepted:` and - where it went, then resolve the thread. + - Author rejected or deferred it: weigh any reason given. If it holds, + `F3 withdrawn:` and why, then resolve the thread. If not, `F3 accepted:` + with your evidence or where it was deferred, once, then resolve it. An + accepted Critical finding stays open for a maintainer to dismiss. - Still applies and its code changed: `F3 still applies at :` and why. - Still applies and its code is untouched: stay silent; the summary counts it.