Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions .cursor/BUGBOT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# BugBot configuration
Comment thread
ValentaTomas marked this conversation as resolved.

This file contains the configuration for the BugBot.

## PR description

- Don't list all the changes by files/change types, just very briefly summarize what is the PR trying to accomplish.
- Don't list the changes files/dirs.
- Don't use sections, or lists, ideally just one short paragraph.
- Don't use emojis.

## PR review

Please review this pull request and provide feedback on:

- Potential bugs or issues
- Performance considerations
- Important security concerns

Be constructive and helpful in your feedback and be **very conscise**.
Skip general recommendations, skip summarizing the changes, and don't make any recommendations on code style.
Also skip any summarization about why the PR was done well, focus only on the code changes and the potential issues.
Comment thread
ValentaTomas marked this conversation as resolved.
Don't output final summaries, or final lists of action items.
29 changes: 24 additions & 5 deletions .github/workflows/claude-code-review.yml
Comment thread
ValentaTomas marked this conversation as resolved.
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: Claude Code Review

on:
pull_request:
types: [opened, synchronize]
types: [opened]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: API Comments: Permissions Denied

The workflow instructs Claude to post inline PR comments using gh api to create review comments, but the permissions only grant pull-requests: read. Creating PR review comments via the GitHub API requires pull-requests: write permission, causing the workflow to fail with a 403 Forbidden error when attempting to post comments.

Fix in Cursor Fix in Web


jobs:
claude-review:
Expand Down Expand Up @@ -38,7 +38,26 @@ jobs:
Be constructive and helpful in your feedback and be **very conscise**.
Skip general recommendations, skip summarizing the changes, and don't make any recommendations on code style.
Also skip any summarization about why the PR was done well, focus only on the code changes and the potential issues.

Use `gh pr comment` with your Bash tool to leave your review as a comment on the PR.

claude_args: '--allowed-tools "Bash(gh issue view:*),Bash(gh search:*),Bash(gh issue list:*),Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr list:*)"'
Don't output final summaries, or final lists of action items.
Reduce false positives—try to validate if the issue is really a valid problem in the changes.

When you find a *specific issue* in the code (bug, performance concern, security risk, etc.),
leave an **inline comment** on that exact file and line.
If no issues are found, do not post anything.

To comment inline, use this format exactly:

```bash
gh api \
--method POST \
-H "Accept: application/vnd.github+json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
/repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/comments \
-f body='${BODY}' \
-f commit_id="${{ github.event.pull_request.head.sha }}" \
-f path='${PATH}' \
-F line=${LINE} \
-f side='RIGHT'
```

claude_args: '--allowed-tools "Bash(gh api:*), Bash(gh issue view:*),Bash(gh search:*),Bash(gh issue list:*),Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr list:*)"'
Loading