2026-10-09-template-review-workflow-readonly
title: The Claude review workflow must not be able to push affects: dartway_cli: "0.24.0"
Who is affected
A project that has .github/workflows/claude-review.yml — every project created before
dartway_cli 0.24.0 keeps the file unless its owner deleted it. As created, the review step runs
anthropics/claude-code-action with track_progress: true and no github_token: the action
exchanges OIDC for the Claude App's installation token, which can write contents whatever
permissions: says, and tracking forces tag mode, whose tools edit and commit. A review run can
push commits to the pull request it reviews.
A project without the file does nothing.
What to change
In .github/workflows/claude-review.yml, in the with: of the anthropics/claude-code-action
step:
-
Add
github_token: ${{ secrets.GITHUB_TOKEN }}besideclaude_code_oauth_token. The workflow's own token is held to thecontents: readthe workflow already declares, so GitHub refuses a push;pull-requests: writeandissues: writestill cover the review comments. -
Delete the
track_progress: trueline. With an explicitpromptand no tracking the action runs in agent mode. -
Add a line to
claude_args, after--allowedTools:--disallowedTools "Edit,Write,MultiEdit,NotebookEdit,Bash(git commit:*),Bash(git push:*)"--allowedToolsonly adds to the toolset; this takes the edit and commit tools away even if a later action version grants them by default.
The comment block above the step in the framework's template explains the three locks and can be copied with them.
How to check
grep -nE '^\s*track_progress:' .github/workflows/claude-review.yml finds nothing, and the file
contains github_token: ${{ secrets.GITHUB_TOKEN }} and a --disallowedTools line naming
Bash(git push:*). The next pull request's review still posts its comments.