Skip to content

fix: use OIDC via claude-code-action, remove ANTHROPIC_API_KEY, harde…#16

Merged
yanas merged 1 commit into
masterfrom
fix/pr-classify-security
Mar 12, 2026
Merged

fix: use OIDC via claude-code-action, remove ANTHROPIC_API_KEY, harde…#16
yanas merged 1 commit into
masterfrom
fix/pr-classify-security

Conversation

@yanas

@yanas yanas commented Mar 12, 2026

Copy link
Copy Markdown
Owner

…n security

  • Switch from curl+ANTHROPIC_API_KEY to claude-code-action with OIDC token exchange — no long-lived secrets on the runner
  • Parse classifier output from the bot comment instead of step output
  • Delete the raw JSON bot comment after parsing
  • Pin actions/checkout and actions/github-script to commit SHAs
  • Add id-token: write permission for OIDC

…n security

- Switch from curl+ANTHROPIC_API_KEY to claude-code-action with OIDC
  token exchange — no long-lived secrets on the runner
- Parse classifier output from the bot comment instead of step output
- Delete the raw JSON bot comment after parsing
- Pin actions/checkout and actions/github-script to commit SHAs
- Add id-token: write permission for OIDC

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@yanas yanas merged commit 7584865 into master Mar 12, 2026
1 check passed
@github-actions

github-actions Bot commented Mar 12, 2026

Copy link
Copy Markdown

Claude encountered an error —— View job


I'll analyze this and get back to you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant