]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
ci: Don't read claude settings from the repo
authorDaan De Meyer <daan@amutable.com>
Wed, 18 Mar 2026 12:40:13 +0000 (13:40 +0100)
committerDaan De Meyer <daan.j.demeyer@gmail.com>
Wed, 18 Mar 2026 12:48:55 +0000 (13:48 +0100)
Shouldn't be possible, but extra hardening never hurts.

.github/workflows/claude-review.yml

index 4e750b11fcde30adea062df1f034ed27651c26e2..91f98f695e2a654bddbfef7c99bdfe644d28946c 100644 (file)
@@ -264,6 +264,7 @@ jobs:
             --model us.anthropic.claude-opus-4-6-v1
             --max-turns 200
             --disallowedTools "WebFetch,WebSearch,Agent,TaskCreate"
+            --setting-sources user
             --json-schema '${{ env.REVIEW_SCHEMA }}'
           prompt: |
               REPO: ${{ github.repository }}