diff --git a/.github/actions/pr-review/action.yml b/.github/actions/pr-review/action.yml index 749250f..ee12b0a 100644 --- a/.github/actions/pr-review/action.yml +++ b/.github/actions/pr-review/action.yml @@ -122,7 +122,12 @@ runs: } >> "${GITHUB_ENV}" - name: Run Claude PR Review id: claude_review - uses: anthropics/claude-code-action@9ca9355b36297178e28d37c799d1c9c8a28e6507 # main: Claude Code 2.1.280 + uses: anthropics/claude-code-action@9171db3e57d6a3140a37ddc2ba92788584e0ead6 # v1.0.234: Claude Code 2.1.282 + env: + # This is a one-shot SDK turn: required audit agents must return before + # the parent finishes, rather than wait for a later background wakeup. + # Keep subagents available, but run their work in the foreground. + CLAUDE_CODE_DISABLE_BACKGROUND_TASKS: "1" with: anthropic_api_key: ${{ inputs.anthropic_api_key }} github_token: ${{ inputs.github_token }} diff --git a/README.md b/README.md index 4f4dfcf..59738ae 100644 --- a/README.md +++ b/README.md @@ -28,6 +28,11 @@ Keep broadly shared connector criteria in the connector mixin. Use repo-local The review assesses the whole change, including intent, correctness, security, meaningful test coverage, and operational risk. Prior findings are rechecked against current code; resolving a thread does not remove an unfixed blocker from the verdict. + +Required audit subagents run in the foreground: this is a one-shot CI review, +so their results must return before the parent finishes. Background task +handoffs are disabled; the job cannot resume a later conversation turn. + The agent posts its verdict in a working summary comment and never writes review-state metadata. After a successful run, CI publishes the report as a NEW comment carrying a visible reviewed-commit link and CI-owned review-state