Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions .claude/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
{
"permissions": {
"allow": [
"Read",
"Glob",
"Grep",
"Bash(python *)",
"Bash(pip *)",
"Bash(pytest *)",
"Bash(git status)",
"Bash(git diff *)",
"Bash(git log *)",
"Bash(git branch *)"
],
"deny": [
"Bash(curl *)",
"Bash(wget *)",
"Bash(nc *)",
"Bash(ssh *)",
"Bash(scp *)",
"Read(.env)",
"Read(*credentials*)",
"Read(*secret*)",
"Read(*password*)"
],
"ask": [
"Write",
"Edit",
"Bash(git commit *)",
"Bash(git push *)"
]
}
}
37 changes: 37 additions & 0 deletions .github/workflows/nucleus-fix.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: Nucleus Fix Issue

on:
workflow_dispatch:
inputs:
issue-number:
description: 'Issue number to fix'
required: true
profile:
description: 'Permission profile'
required: false
default: 'safe_pr_fixer'
model:
description: 'LLM model'
required: false
default: 'claude-sonnet-4-20250514'

permissions:
contents: write
pull-requests: write
issues: read

jobs:
fix:
name: Fix issue #${{ inputs.issue-number }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: coproduct-opensource/nucleus@main
with:
issue-number: ${{ inputs.issue-number }}
api-key: ${{ secrets.ANTHROPIC_API_KEY }}
github-token: ${{ secrets.GH_PAT }}
profile: ${{ inputs.profile }}
timeout: '600'
model: ${{ inputs.model }}
27 changes: 27 additions & 0 deletions .github/workflows/nucleus-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
name: Nucleus Security Scan

on:
push:
branches: [master]
paths:
- '.claude/**'
- '.mcp.json'
pull_request:
paths:
- '.claude/**'
- '.mcp.json'

permissions:
contents: read

jobs:
scan:
name: Scan Agent Configs
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Scan Claude Code settings
uses: coproduct-opensource/nucleus/scan@v1.0.8
with:
claude-settings: .claude/settings.json