Repository navigation
v2.0.0 — BLOCK-only gate
Major release. CI reviewer shifts from "full code review" to a narrow BLOCK/PASS gate.
Why
Every consumer repo already runs `code-reviewer`, `adversarial-reviewer`, linters, and formatters locally on pre-commit. The CI review was duplicating that work on GitHub — paying per-turn for observations local reviewers had already produced (or explicitly passed on). The 2026-04-17 AAR catalogued the cost impact: `max_turns` kept getting raised (25 → 50) just to keep up with a prompt that got wider each time someone added a concern; infrastructure flakes cost real money on timeouts; doc-only PRs wasted full review budgets.
Breaking changes
- Prompt narrowed. "Code quality / best practices / test coverage / style" removed. Reviews no longer produce non-blocking observation lists. Focus is exclusively on:
- Clear bugs causing incorrect production behavior
- Reliability regressions
- Security vulnerabilities
- Missing async error handling
- Data-loss risk
- `max_turns` tightened. Auto-estimate is now `8 + lines/200` (+20% buffer, floor 15, ceiling 40). Was: `10 + lines/150` (floor 25, ceiling 50). Caller override range (1-50) unchanged. Consumer repos that override `max_turns` explicitly should review their values.
- Bypass marker grep anchored (`^VERDICT: (BLOCK|PASS)$`). Fixes a prior false-match on review prose that quoted the VERDICT strings.
Non-breaking additions
- Doc-only fast-skip. PRs that only touch `.md`, `LICENSE`, `CHANGELOG`, `.gitignore`-class meta files, image assets (`.png` etc.), `docs/`, `.github/ISSUE_TEMPLATE/**`, `.github/FUNDING.yml` short-circuit with `VERDICT: SKIPPED`. No paid review. Intentionally excluded from the skip: `CODEOWNERS`, `dependabot.yml`, `PULL_REQUEST_TEMPLATE.md` — they look meta but carry real security implications.
- SHA marker on posted reviews. Every comment starts with ``. Downstream scrapers can filter by SHA. Falls back to `github.sha` on non-`pull_request` triggers.
- Prior-comment minimize. Before each review run, previous marked comments are collapsed via `minimizeComment` (classifier: OUTDATED). Keeps PR conversations readable across iterations.
- Rename-aware doc-only classification. Uses the Pulls Files API and classifies the UNION of `previous_filename` and `filename`, so a `src/foo.py` → `docs/foo.md` rename can't hide code removal behind a doc path.
- Verdict file written BEFORE comment post. Turn-exhaustion or wall-clock timeout mid-post still produces a usable verdict file for CI.
Migration
One-character change per consumer caller workflow:
```diff
- uses: smartwatermelon/github-workflows/.github/workflows/claude-blocking-review.yml@v1
- uses: smartwatermelon/github-workflows/.github/workflows/claude-blocking-review.yml@v2
```
Status check name (`claude-review / run-review`) is unchanged. No branch-protection update needed.
Observed performance
Same diff sizes, before/after narrow prompt:
| PR | Claude review duration |
|---|---|
| PR #47 (old prompt, real review) | 5m 06s |
| PR #52 (new prompt, real review) | 1m 51s |
| PR #56 (new prompt, doc-only diff) | 0m 58s |
≈2.7× faster on equivalent review content; doc-only PRs effectively free.
Consumer impact on existing workflows
- Pinned to `@v1`: unchanged, receives v1.2.4 grep fix but not v2 behavior.
- Pinned to `@v2`: receives all new behavior on next PR run.
- Pinned to specific tag: unaffected until you bump.
Commits in v2.0.0 (vs v1.2.4)
- `60233b7` chore: restore self-applying caller for this repo (#41)
- `454f1ef` feat: doc-only fast-skip + SHA marker + prior-comment collapse (#47)
- `5254342` feat: narrow review prompt to BLOCK-only + lower max_turns floor (#52)
- `988148f` polish: resolve doc-only allowlist + marker follow-ups (#53)
- `137eaca` docs: clarify timeout 44% buffer is intentional (#56)
🤖 Generated with Claude Code