From defb6bb0a43e16c1042661d6932a30efb3d63876 Mon Sep 17 00:00:00 2001 From: Ulas Kalayci Date: Wed, 29 Apr 2026 10:43:02 +0200 Subject: [PATCH] fix: remove broken plugin marketplace auth from code review workflow The plugin_marketplaces + plugins config triggered an OIDC token exchange that consistently fails with 401. Replace with a direct prompt, matching the pattern used in claude.yml which works reliably. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/claude-code-review.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index ac9f095..b7d85c3 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -24,6 +24,7 @@ jobs: uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - plugin_marketplaces: 'https://github.com/anthropics/claude-code.git' - plugins: 'code-review@claude-code-plugins' - prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}' + prompt: > + Review this pull request for bugs, logic errors, security issues, and adherence to project + conventions. Focus only on high-confidence issues that genuinely matter. Skip style nitpicks. + Post your findings as inline review comments on the relevant lines.