Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# Reviewers automatically requested for pull requests.
# Add co-maintainers per area as they join; see MAINTAINERS.md.

* @RichardAtCT

# Security-sensitive paths: always include the maintainer even when
# an area owner is added later.
/src/security/ @RichardAtCT
/src/claude/ @RichardAtCT
/src/api/ @RichardAtCT
/.github/workflows/ @RichardAtCT
/SECURITY.md @RichardAtCT
75 changes: 75 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,75 @@
name: Bug report
description: Something is broken or behaves unexpectedly
labels: ["bug", "needs-triage"]
body:
- type: markdown
attributes:
value: |
Thanks for the report. The fields below are what a maintainer needs to reproduce the problem without a round trip. Please fill in as many as you can.
- type: textarea
id: what
attributes:
label: What happened
description: What you did, what you expected, and what happened instead.
placeholder: Sent a photo with a caption; the bot replied "Working..." and never finished.
validations:
required: true
- type: textarea
id: steps
attributes:
label: Steps to reproduce
placeholder: |
1. Start the bot with AGENTIC_MODE=true
2. Send ...
3. Observe ...
validations:
required: true
- type: input
id: version
attributes:
label: Bot version
description: Output of `/status`, or the tag you installed. Say `main` and the commit if you run from source.
placeholder: v1.6.1
validations:
required: true
- type: input
id: sdk
attributes:
label: claude-agent-sdk and Claude Code CLI versions
description: "`poetry run pip show claude-agent-sdk | grep Version` and `claude --version`"
placeholder: 0.1.39 / 2.1.x
- type: dropdown
id: mode
attributes:
label: Mode
options:
- Agentic (default)
- Classic (AGENTIC_MODE=false)
- Project threads (ENABLE_PROJECT_THREADS=true)
validations:
required: true
- type: dropdown
id: auth
attributes:
label: Claude authentication
options:
- Claude CLI login (subscription)
- ANTHROPIC_API_KEY
- Other provider or custom base URL
- type: input
id: platform
attributes:
label: OS and Python version
placeholder: Ubuntu 24.04, Python 3.12.3
- type: textarea
id: logs
attributes:
label: Relevant log output
description: Run with `make run-debug` and paste the lines around the failure. Remove tokens, chat IDs and file paths you do not want public.
render: shell
- type: textarea
id: config
attributes:
label: Non-default settings
description: Any `.env` values you changed from `.env.example`, with secrets removed.
render: shell
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Security vulnerability
url: https://github.com/RichardAtCT/claude-code-telegram/security/advisories/new
about: Report a vulnerability privately. Please do not open a public issue for security problems.
- name: v2 roadmap
url: https://github.com/RichardAtCT/claude-code-telegram/blob/main/docs/ROADMAP-v2.md
about: Check whether your idea is already planned before opening a feature request.
51 changes: 51 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
name: Feature request
description: Propose a change or an addition
labels: ["enhancement", "needs-triage"]
body:
- type: markdown
attributes:
value: |
Before filing, check the [v2 roadmap](https://github.com/RichardAtCT/claude-code-telegram/blob/main/docs/ROADMAP-v2.md) and the open pull requests. If it is already planned, comment on that item instead so effort is not duplicated.
- type: textarea
id: problem
attributes:
label: Problem
description: What you are trying to do from Telegram and what gets in the way today.
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed behaviour
description: What the bot should do. If it involves a command or button, sketch the interaction.
placeholder: |
You: /sessions
Bot: [Yesterday: fix auth bug] [Mon: add tests] ...
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
description: Workarounds you tried, or other ways this could be solved.
- type: dropdown
id: scope
attributes:
label: Which part of the bot does this touch?
multiple: true
options:
- Agentic chat (orchestrator)
- Claude SDK integration
- Security / permissions
- Sessions and storage
- Webhooks, scheduler, notifications
- Project threads
- Voice, images, files
- Deployment and configuration
- Documentation
- type: checkboxes
id: help
attributes:
label: Contribution
options:
- label: I am willing to open a pull request for this
24 changes: 24 additions & 0 deletions .github/ISSUE_TEMPLATE/question.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
name: Question or support
description: Setup help, configuration questions, "is this possible?"
labels: ["question", "needs-triage"]
body:
- type: markdown
attributes:
value: |
Check [docs/setup.md](https://github.com/RichardAtCT/claude-code-telegram/blob/main/docs/setup.md) and [docs/configuration.md](https://github.com/RichardAtCT/claude-code-telegram/blob/main/docs/configuration.md) first. If GitHub Discussions is enabled for this repository, questions are better asked there so other users can answer too.
- type: textarea
id: question
attributes:
label: Question
validations:
required: true
- type: textarea
id: tried
attributes:
label: What you have tried
description: Commands run, settings changed, docs read.
- type: input
id: version
attributes:
label: Bot version
placeholder: v1.6.1
41 changes: 41 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
version: 2
updates:
# The Claude Agent SDK moves fast (0.1.39 -> 0.2.152 in six months).
# Surface it on its own so the bump is never buried in a grouped PR.
- package-ecosystem: pip
directory: /
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 5
labels: ["dependencies", "sdk"]
allow:
- dependency-name: claude-agent-sdk
- dependency-name: python-telegram-bot
- dependency-name: anthropic
commit-message:
prefix: "deps"

- package-ecosystem: pip
directory: /
schedule:
interval: monthly
open-pull-requests-limit: 5
labels: ["dependencies"]
ignore:
- dependency-name: claude-agent-sdk
- dependency-name: python-telegram-bot
- dependency-name: anthropic
groups:
python-minor-and-patch:
update-types: ["minor", "patch"]
commit-message:
prefix: "deps"

- package-ecosystem: github-actions
directory: /
schedule:
interval: monthly
labels: ["dependencies", "ci"]
commit-message:
prefix: "ci"
30 changes: 30 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
## Description

<!-- What changes and why. One feature or fix per pull request; open an issue first for anything larger than about 400 lines. -->

## Related issue

Closes #

## Type of change

- [ ] Bug fix
- [ ] New feature
- [ ] Breaking change (documented in CHANGELOG under "Changed" or "Removed")
- [ ] Documentation or tooling only

## How it was tested

<!-- Automated tests are required for behaviour changes. Say what you ran against a real Telegram bot and Claude session by hand, because the test suite cannot exercise the SDK or Telegram end to end. -->

- [ ] Tests added or updated
- [ ] `make test` and `make lint` pass locally
- [ ] Tested by hand against a running bot: <!-- what you did -->

## Checklist

- [ ] One concern per PR; unrelated changes are split out
- [ ] `CHANGELOG.md` has an entry under `[Unreleased]`
- [ ] Documentation updated (`README.md`, `docs/`, `.env.example`, `CLAUDE.md`) where settings or commands changed
- [ ] New settings default to current behaviour
- [ ] If AI tools helped write this change, I reviewed every line and the hand-testing above is mine
83 changes: 83 additions & 0 deletions .github/workflows/claude-code-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
name: Claude Code Review

# First-pass review on every pull request. It comments; it never approves,
# merges, or pushes. A human maintainer still reviews and merges.
#
# Requires one repository secret: CLAUDE_CODE_OAUTH_TOKEN (from
# `claude setup-token`) or ANTHROPIC_API_KEY. Swap the `with:` key below
# to match. See https://github.com/anthropics/claude-code-action
#
# `pull_request_target` is used so PRs from forks are reviewed (plain
# `pull_request` has no access to secrets on fork PRs). Because the
# workflow then runs with base-repo secrets against untrusted code, the
# tool allowlist is read-only plus `gh pr comment`; no arbitrary Bash.

on:
pull_request_target:
types: [opened, synchronize, ready_for_review, reopened]
paths-ignore:
- "**.md"
- "docs/**"

concurrency:
group: claude-review-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
review:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
issues: read
id-token: write
steps:
- name: Checkout PR merge ref
uses: actions/checkout@v6
with:
ref: refs/pull/${{ github.event.pull_request.number }}/merge
fetch-depth: 0

- name: Review
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
use_sticky_comment: true
prompt: |
REPO: ${{ github.repository }}
PR NUMBER: ${{ github.event.pull_request.number }}

You are the first-pass reviewer for a Telegram bot that gives
remote access to Claude Code. Read CLAUDE.md for the
architecture and the five-layer security model, then review
the diff of this pull request.

Report only findings you are confident about, most severe
first. Focus on:
1. Security regressions: anything that widens what a Telegram
user can make Claude do on the host. Path checks against
APPROVED_DIRECTORY, the can_use_tool callback, the
SecurityValidator patterns, webhook signature checks,
secrets in logs, new settings that relax defaults.
2. Correctness: async misuse (blocking calls, missing awaits,
shared state across concurrent updates), datetime handling
(must be timezone-aware UTC), SQLite migrations, Telegram
API limits (message length, rate limits, HTML escaping).
3. Scope: does the PR do one thing? Does CHANGELOG.md have an
entry? Are new settings documented in .env.example and
docs/configuration.md and defaulted to current behaviour?
4. Tests: are behaviour changes covered? Do tests assert the
new behaviour rather than mock it away?

Post one review comment using `gh pr comment` with a short
summary, then the findings as a list with file:line
references. If there is nothing worth raising, say so in one
line. Do not approve, request changes, merge, or push.
claude_args: >-
--allowed-tools "Read,Grep,Glob,Bash(gh pr view:*),Bash(gh pr diff:*),Bash(gh pr comment:*),Bash(git diff:*),Bash(git log:*)"
--disallowed-tools "Write,Edit,MultiEdit,NotebookEdit,WebFetch,WebSearch"
--max-turns 40
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Loading