From 96970b536c7ad01a577dc97d4aeef38aafc0869a Mon Sep 17 00:00:00 2001 From: Gianni Carlo Date: Mon, 5 Oct 2026 22:49:48 -0500 Subject: [PATCH] reviewer: point the guide's diff instructions at the file the harness writes The guide still told the agent to run `gh pr diff` and to diff against `origin/main`, which the hardened harness made impossible: `gh` is not on the sandbox's command allowlist, the agent holds no GitHub token, and the PR checkout is shallow with no base ref. The harness prefetches the diff into a file and names it in the task prompt, so the guide now says that, matching the android and support-pipeline guides. --- .github/claude/review-guide.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/claude/review-guide.md b/.github/claude/review-guide.md index abfe295..89af2a3 100644 --- a/.github/claude/review-guide.md +++ b/.github/claude/review-guide.md @@ -8,11 +8,14 @@ controller→service→DB-class convention, naming rules, and request flow. Judg This service handles **per-user data, auth, and money** (Apple/Google/RevenueCat subscriptions), so security and authorization bugs are the highest-priority findings. -**Main branch is `main`.** Diff against `origin/main`. +**Main branch is `main`.** The harness hands you the pull request's unified diff as a file. The checkout is the +PR head only (`fetch-depth: 1`): there is no `origin/main` ref and no `gh` access inside the review, and +`git log` / `git blame` see only the head commit. ## How to review -1. Get the diff: `gh pr diff `. The branch is checked out in the working directory. +1. Read the unified diff the harness wrote for you; its path is in the task prompt. The PR branch is already + checked out in the working directory. 2. **Do not review the diff in isolation.** For each non-trivial change, open the surrounding code and its **callers** with `Read`/`Grep`/`Glob` before judging. Diff-only opinions are not acceptable. For a new/changed route, always open the router to confirm which middlewares (`auth`,