Skip to content

feat: claude code security review#24

Open
SimonvanWijhe wants to merge 1 commit into
mainfrom
feat/claude-code-security-review
Open

feat: claude code security review#24
SimonvanWijhe wants to merge 1 commit into
mainfrom
feat/claude-code-security-review

Conversation

@SimonvanWijhe
Copy link
Copy Markdown
Member

No description provided.

Copilot AI review requested due to automatic review settings April 24, 2026 14:33
@SimonvanWijhe SimonvanWijhe requested a review from a team April 24, 2026 14:34
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow that runs Anthropic’s Claude Code Security Review on demand via workflow_call, using repository-specific security categories and false-positive filtering instructions tailored to the WordPress/Laravel + municipal/GDPR context.

Changes:

  • Introduces a new reusable workflow to run automated security review and comment on PRs.
  • Adds custom security category guidance for the scanner to prioritize project-relevant risks.
  • Adds a starter template for false-positive filtering instructions.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/claude-code-security-review.yml Adds the reusable “Security Review” workflow that checks out code and runs the Claude security review action, commenting on PRs.
.github/custom-security-categories.txt Defines project-specific security categories (WP/Laravel, GDPR, integrations, Elasticsearch, secrets, headers, dependencies).
.github/false-positive-filtering.txt Provides a scaffold for filtering guidance to reduce noisy findings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 2

- uses: anthropics/claude-code-security-review@main
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants