Skip to content

ci: bump Claude PR Assistant pin v2.1.0 -> v2.5.1#108

Merged
nsportsman merged 1 commit into
mainfrom
ci/bump-claude-code-action-v2.5.1
Jun 3, 2026
Merged

ci: bump Claude PR Assistant pin v2.1.0 -> v2.5.1#108
nsportsman merged 1 commit into
mainfrom
ci/bump-claude-code-action-v2.5.1

Conversation

@nsportsman

Copy link
Copy Markdown
Collaborator

Bumps the central claude-code.yml reusable workflow pin from v2.1.0 to v2.5.1 (ba1070e).

What changes

The only three differences in the central claude-code.yml across this range:

  1. disable-sudo-and-containers: true on Harden-Runner — the CVE-2025-32955 hardening (closes the disable-sudo Docker-escape bypass).
  2. Review model claude-opus-4-7claude-opus-4-8.
  3. "Convert to PR review" step — Claude's review lands in the Reviews tab alongside Codex/Gemini instead of as a loose issue comment.

What does NOT change

The pinned anthropics/claude-code-action SHA is 38ec876 # v1.0.101 at both v2.1.0 and v2.5.1 — identical. This bump is purely the wrapper hardening + UX.

Part of the capability CI convergence sweep — folds every capability repo onto the same hardened central wrapper version.

🤖 Generated with Claude Code

Picks up three changes to the central Claude PR Assistant workflow:
- Harden-Runner disable-sudo-and-containers: true (CVE-2025-32955 fix)
- review model claude-opus-4-7 -> claude-opus-4-8
- 'Convert to PR review' step (review lands in Reviews tab)

The pinned claude-code-action SHA (38ec876 # v1.0.101) is unchanged
across this range, so this is purely the wrapper hardening/UX bump.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@nsportsman nsportsman requested a review from a team as a code owner June 2, 2026 23:55
@coderabbitai

coderabbitai Bot commented Jun 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@nsportsman, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 55 minutes and 51 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: afda4673-9f80-4064-beb1-6c7bcbe15dcb

📥 Commits

Reviewing files that changed from the base of the PR and between 7bb013e and 480f31c.

📒 Files selected for processing (1)
  • .github/workflows/claude-code.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/bump-claude-code-action-v2.5.1

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown

Claude review skipped — non-code PR (only changed files matching docs/**, .github/**, .claude-plugin/**, *.md, *.txt, images, or license-like files). Post @claude on a review comment to force a review.

@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown

Gemini review skipped — non-code PR (only changed files matching docs/**, .github/**, .claude-plugin/**, *.md, *.txt, images, or license-like files). Post @gemini on a review comment to force a review.

@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown

Codex review skipped — non-code PR (only changed files matching docs/**, .github/**, .claude-plugin/**, *.md, *.txt, images, or license-like files). Post @codex on a review comment to force a review.

@nsportsman nsportsman merged commit 31ac587 into main Jun 3, 2026
14 checks passed
@nsportsman nsportsman deleted the ci/bump-claude-code-action-v2.5.1 branch June 3, 2026 00:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant