Conversation
…R code execution)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Gate the Claude workflow so it only runs when the PR/issue author is a repo member (
OWNER/MEMBER/COLLABORATOR), by adding anauthor_associationcheck to the existingif:.Why
On a fork PR from an outside contributor, tagging
@claudemakes claude-code-action check out the fork head and run its install/build scripts (bun install/npm installrun the PR-suppliedpackage.json). Because the job passes nogithub_token, the action mints a token from the Claude GitHub App install via OIDC, which on this org is grantedcontents/pull_requests/issues/workflows= write — so the job'scontents: readdoes not bound it. The action's own docs confirmpackage.json/lockfiles stay at the PR head.The write-access check in the action is on the commenter, so a maintainer tagging
@claudeon an outsider's fork PR passes it. Gating on the PR/issue author instead blocks the agent from acting on untrusted fork code. Members' own PRs are unaffected.Tradeoff:
@claudewill no longer act on PRs opened by non-members. For assisting outside contributors, the action docs recommend passing a read-onlygithub_token(+ secret scrub / tool caps) rather than the write App token.Nothing else in the workflow changes.