Drop claude-review github action and just run it externally instead
What changed, and why it matters
This commit simply removes a GitHub Actions workflow that automatically used an Anthropic Claude AI tool to review pull requests. The project maintainers decided to run that review process externally instead of inside GitHub's CI system. No application code, cryptographic logic, or user-facing behavior changed.
No security action required. If the project still uses the same external Claude review, ensure the external process protects `ANTHROPIC_API_KEY` and repository access appropriately.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The deleted .github/workflows/claude-review.yml triggered on PR open/synchronize, checked out the PR with depth 1, and invoked anthropics/claude-code-action@v1 with ANTHROPIC_API_KEY and GITHUB_TOKEN to post AI-generated review comments. Removing it eliminates an automated CI job but does not modify any rust-lightning source, tests, dependencies, or build configuration.
Changed components
.github/workflows/claude-review.ymlInspect captured patch +0 / −39
diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml
deleted file mode 100644
index 0d6d645..0000000
--- a/.github/workflows/claude-review.yml
+++ /dev/null
@@ -1,39 +0,0 @@
-name: Claude Auto Review
-on:
- pull_request:
- types: [opened, synchronize]
-
-jobs:
- review:
- runs-on: ubuntu-latest
- permissions:
- contents: read
- pull-requests: write
- id-token: write
- steps:
- - uses: actions/checkout@v6
- with:
- fetch-depth: 1
-
- - uses: anthropics/claude-code-action@v1
- with:
- anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
- github_token: ${{ secrets.GITHUB_TOKEN }}
- prompt: |
- REPO: ${{ github.repository }}
- PR NUMBER: ${{ github.event.pull_request.number }}
-
- Please review this pull request with a focus on:
- - Code quality and best practices
- - Potential bugs or issues
- - Security implications
- - Performance considerations
-
- Note: The PR branch is already checked out in the current working directory.
-
- Use `gh pr comment` for top-level feedback.
- Use `mcp__github_inline_comment__create_inline_comment` to highlight specific code issues.
- Only post GitHub comments - don't submit review text as messages.
-
- claude_args: |
- --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.