Automating AI reviews for Renovate major update PRs

Label Renovate major update PRs with ai-review and trigger AI reviews through GitHub Actions, with a standalone Claude Code workflow example.

Takahiro Iwasa
6 min read

Renovate creates dependency update PRs, but major updates still require checking for breaking changes that affect the application. Even a PR that changes only a version number and a lockfile can remove an API the application uses or change a configuration default.

Add a dedicated AI review label, such as ai-review, to major update PRs and trigger an AI review in GitHub Actions. In the example below, Renovate adds the label and a GitHub Actions workflow runs Claude Code.

What this helps solve

After Renovate creates a PR, someone still needs to read the release notes and search the code for affected APIs and configuration. When update PRs accumulate, that investigation can fall behind and delay merges.

An automatic AI review puts the following information on the PR before a human starts reviewing it:

  • Breaking changes described in release notes and migration guides.
  • Repository code that uses the affected APIs or settings.
  • Code the AI identifies as needing changes, with its reasoning.

This automates the initial search through release notes and code without manually invoking the AI for each PR. API removals and default changes that your tests do not cover can also be investigated. The AI can miss affected code, so a review with no reported issues does not mean the update is safe.

Label major update PRs

Add a major update rule to your repository’s renovate.json. If you already have a configuration, append the rule to its packageRules array.

renovate.json
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["config:recommended"],
"labels": ["dependencies"],
"packageRules": [
{
"matchUpdateTypes": ["major"],
"addLabels": ["ai-review"],
"automerge": false
}
]
}

matchUpdateTypes selects major updates, and addLabels adds ai-review. Renovate’s addLabels supplements existing labels, so this example adds both dependencies and ai-review. Setting automerge: false disables automatic merging so you can check the review and test results first.

AI reviews are independent of human review requests. Set reviewers separately if you also want to request a human review automatically.

Prepare the AI review

Create an ai-review label in the repository and configure Renovate to create PRs.

For Claude Code, follow the official setup instructions to install the Claude GitHub App and register ANTHROPIC_API_KEY in GitHub Actions secrets. The example below uses an Anthropic API key. To use an OAuth token instead, generate one with claude setup-token, store it as CLAUDE_CODE_OAUTH_TOKEN, and change the Action input to claude_code_oauth_token.

Trigger the review when a label is added

AI review workflow: label events and new commits pass through gate, which runs or skips Claude Code; review results are posted as PR comments.

Create .github/workflows/ai-review.yml in your repository. This workflow runs directly in that repository.

.github/workflows/ai-review.yml
name: "repo - AI Review"
on:
pull_request:
types: [labeled, synchronize]
permissions: {}
jobs:
gate:
name: Check label
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
review: ${{ steps.check.outputs.review }}
steps:
- name: Check the label
id: check
env:
REVIEW: >-
${{
github.event_name == 'pull_request'
&& (
(github.event.action == 'labeled' && github.event.label.name == 'ai-review')
|| (github.event.action == 'synchronize' && contains(github.event.pull_request.labels.*.name, 'ai-review'))
)
&& github.event.pull_request.head.repo.full_name == github.repository
}}
run: echo "review=$REVIEW" >> "$GITHUB_OUTPUT"
review:
name: ${{ needs.gate.outputs.review == 'true' && 'Claude' || 'Claude (not requested)' }}
needs: gate
if: needs.gate.outputs.review == 'true'
runs-on: ubuntu-latest
timeout-minutes: 30
concurrency:
group: ai-review-${{ github.repository }}-${{ github.event.pull_request.number }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: write
issues: write
id-token: write
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Review with Claude Code
uses: anthropics/claude-code-action@ed670b4cf9de2a5a570d130d2f6197b9e543cd64 # v1.0.240
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
allowed_bots: "renovate[bot]"
track_progress: true
prompt: |
REPO: ${{ github.repository }}
PR NUMBER: ${{ github.event.pull_request.number }}
Review this dependency update PR.
Check release notes and migration guides for breaking changes.
Find usages in this repository affected by those changes.
Report specific issues with file paths and line numbers.
Use inline comments for issues and the tracking comment for a summary.
Do not modify files or comment on style issues caught by linters.
claude_args: >-
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),WebFetch"

The pull_request activity type labeled fires when a label is added to a PR. Since any label can trigger it, the gate job checks whether the added label is ai-review and passes the result to the review job.

synchronize runs another review when commits are pushed to the PR branch. For this event, the condition checks whether the PR currently has ai-review. Renovate rebases also trigger another review. Use types: [labeled] to review only when the label is added.

The example runs only when the PR branch belongs to the same repository. It excludes PRs from forks, which cannot access the secrets.

The review job runs only when gate outputs review=true. Its check name is Claude for requested reviews and Claude (not requested) otherwise. This keeps skipped runs triggered by other labels from sharing the same check name as actual reviews.

Allow the bot and configure review permissions

When Renovate adds the label, a bot is the event actor. Set allowed_bots to renovate[bot] in Claude Code Action to allow that review. Replace the username if you use a different bot account.

The job’s permissions support reading code, posting PR comments, and authenticating the Claude GitHub App. The claude_args input specifies tools for inspecting and commenting on the PR and fetching web pages.

The prompt should ask the AI to connect release notes and migration guides to actual usage in the repository. Useful findings include calls to removed APIs, changed configuration options, and tests that need updating, with file paths and line numbers.

Verify the workflow and review again

Once the workflow is on the default branch, you can test it by manually adding ai-review to a PR within the same repository. Then check the following flow on a Renovate major update PR:

  1. Renovate creates the PR and adds ai-review.
  2. The gate job checks the label, then GitHub Actions runs the review job.
  3. Claude posts progress and a summary in a tracking comment, with inline comments for specific issues.

Removing and reapplying ai-review starts a new review. The example’s concurrency setting cancels an ongoing review for the same PR before starting the new one.

With synchronize enabled, additional pushes produce more reviews, comments, and usage costs. For frequent updates, you can run reviews only when the label is added and reapply it when needed.

To use another AI tool, keep the Renovate label rule and the gate job. Adapt the AI step, credentials, and the step that posts the review results to that tool. If the tool only outputs review text, you can run the review in a read-only job and post the results in a separate job.

Summary

Having Renovate add ai-review automates the steps from creating a major update PR to running an AI review. The findings stay on the PR as a starting point for investigating the update’s impact.

Reapply the label to request another review, or enable synchronize to review after every additional push. Before merging, check the migration guide and updated test results alongside the AI findings.

About the author

Takahiro Iwasa

Takahiro Iwasa

Software Developer

This blog shares technical notes from hands-on projects—architecture, implementation, and AWS service integrations.