Automating AI reviews for Renovate major update PRs
Label Renovate major update PRs with ai-review and trigger AI reviews through GitHub Actions, with a standalone Claude Code workflow example.
Renovate creates dependency update PRs, but major updates still require checking for breaking changes that affect the application. Even a PR that changes only a version number and a lockfile can remove an API the application uses or change a configuration default.
Add a dedicated AI review label, such as ai-review, to major update PRs and trigger an AI review in GitHub Actions. In the example below, Renovate adds the label and a GitHub Actions workflow runs Claude Code.
What this helps solve
After Renovate creates a PR, someone still needs to read the release notes and search the code for affected APIs and configuration. When update PRs accumulate, that investigation can fall behind and delay merges.
An automatic AI review puts the following information on the PR before a human starts reviewing it:
- Breaking changes described in release notes and migration guides.
- Repository code that uses the affected APIs or settings.
- Code the AI identifies as needing changes, with its reasoning.
This automates the initial search through release notes and code without manually invoking the AI for each PR. API removals and default changes that your tests do not cover can also be investigated. The AI can miss affected code, so a review with no reported issues does not mean the update is safe.
Label major update PRs
Add a major update rule to your repository’s renovate.json. If you already have a configuration, append the rule to its packageRules array.
{ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": ["config:recommended"], "labels": ["dependencies"], "packageRules": [ { "matchUpdateTypes": ["major"], "addLabels": ["ai-review"], "automerge": false } ]}matchUpdateTypes selects major updates, and addLabels adds ai-review. Renovate’s addLabels supplements existing labels, so this example adds both dependencies and ai-review. Setting automerge: false disables automatic merging so you can check the review and test results first.
AI reviews are independent of human review requests. Set reviewers separately if you also want to request a human review automatically.
Prepare the AI review
Create an ai-review label in the repository and configure Renovate to create PRs.
For Claude Code, follow the official setup instructions to install the Claude GitHub App and register ANTHROPIC_API_KEY in GitHub Actions secrets. The example below uses an Anthropic API key. To use an OAuth token instead, generate one with claude setup-token, store it as CLAUDE_CODE_OAUTH_TOKEN, and change the Action input to claude_code_oauth_token.
Trigger the review when a label is added

Create .github/workflows/ai-review.yml in your repository. This workflow runs directly in that repository.
name: "repo - AI Review"
on: pull_request: types: [labeled, synchronize]
permissions: {}
jobs: gate: name: Check label runs-on: ubuntu-latest timeout-minutes: 5 outputs: review: ${{ steps.check.outputs.review }} steps: - name: Check the label id: check env: REVIEW: >- ${{ github.event_name == 'pull_request' && ( (github.event.action == 'labeled' && github.event.label.name == 'ai-review') || (github.event.action == 'synchronize' && contains(github.event.pull_request.labels.*.name, 'ai-review')) ) && github.event.pull_request.head.repo.full_name == github.repository }} run: echo "review=$REVIEW" >> "$GITHUB_OUTPUT"
review: name: ${{ needs.gate.outputs.review == 'true' && 'Claude' || 'Claude (not requested)' }} needs: gate if: needs.gate.outputs.review == 'true' runs-on: ubuntu-latest timeout-minutes: 30 concurrency: group: ai-review-${{ github.repository }}-${{ github.event.pull_request.number }} cancel-in-progress: true permissions: contents: read pull-requests: write issues: write id-token: write steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Review with Claude Code uses: anthropics/claude-code-action@ed670b4cf9de2a5a570d130d2f6197b9e543cd64 # v1.0.240 with: anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} allowed_bots: "renovate[bot]" track_progress: true prompt: | REPO: ${{ github.repository }} PR NUMBER: ${{ github.event.pull_request.number }}
Review this dependency update PR. Check release notes and migration guides for breaking changes. Find usages in this repository affected by those changes. Report specific issues with file paths and line numbers. Use inline comments for issues and the tracking comment for a summary. Do not modify files or comment on style issues caught by linters. claude_args: >- --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),WebFetch"The pull_request activity type labeled fires when a label is added to a PR. Since any label can trigger it, the gate job checks whether the added label is ai-review and passes the result to the review job.
synchronize runs another review when commits are pushed to the PR branch. For this event, the condition checks whether the PR currently has ai-review. Renovate rebases also trigger another review. Use types: [labeled] to review only when the label is added.
The example runs only when the PR branch belongs to the same repository. It excludes PRs from forks, which cannot access the secrets.
The review job runs only when gate outputs review=true. Its check name is Claude for requested reviews and Claude (not requested) otherwise. This keeps skipped runs triggered by other labels from sharing the same check name as actual reviews.
Allow the bot and configure review permissions
When Renovate adds the label, a bot is the event actor. Set allowed_bots to renovate[bot] in Claude Code Action to allow that review. Replace the username if you use a different bot account.
The job’s permissions support reading code, posting PR comments, and authenticating the Claude GitHub App. The claude_args input specifies tools for inspecting and commenting on the PR and fetching web pages.
The prompt should ask the AI to connect release notes and migration guides to actual usage in the repository. Useful findings include calls to removed APIs, changed configuration options, and tests that need updating, with file paths and line numbers.
Verify the workflow and review again
Once the workflow is on the default branch, you can test it by manually adding ai-review to a PR within the same repository. Then check the following flow on a Renovate major update PR:
- Renovate creates the PR and adds
ai-review. - The
gatejob checks the label, then GitHub Actions runs thereviewjob. - Claude posts progress and a summary in a tracking comment, with inline comments for specific issues.
Removing and reapplying ai-review starts a new review. The example’s concurrency setting cancels an ongoing review for the same PR before starting the new one.
With synchronize enabled, additional pushes produce more reviews, comments, and usage costs. For frequent updates, you can run reviews only when the label is added and reapply it when needed.
To use another AI tool, keep the Renovate label rule and the gate job. Adapt the AI step, credentials, and the step that posts the review results to that tool. If the tool only outputs review text, you can run the review in a read-only job and post the results in a separate job.
Summary
Having Renovate add ai-review automates the steps from creating a major update PR to running an AI review. The findings stay on the PR as a starting point for investigating the update’s impact.
Reapply the label to request another review, or enable synchronize to review after every additional push. Before merging, check the migration guide and updated test results alongside the AI findings.
Related posts
Migrating from aws-vault to Granted
I migrated to Granted after aws-vault development ended. Here is how role switching and console access differ, and what to check when carrying over credentials and configuration.
Risk Storming: Turning Architecture Concerns into Action
A practical guide to assessing architecture risks independently, reconciling different perspectives, and choosing mitigations the team can track.
Improving Cross-Team Communication with C4 Diagrams
C4’s four zoom levels offer a practical way to choose the right architecture view for business, development, operations, and security audiences.
Sign in with Slack Using Cognito User Pools and OIDC
Federating Cognito user pools with Slack over OIDC and wiring "Sign in with Slack" into a Next.js app with Amplify.
Deploying FastAPI on AWS Lambda with Lambda Web Adapter
Containerizing a FastAPI backend and deploying it to a single Lambda function with Lambda Web Adapter and AWS CDK.
