Commit graph

6 commits

Author SHA1 Message Date
Adam Moussa
47185fa602
ci(terraform): fail mixed app and Terraform changes (#157)
Some checks failed
ci / ci / ci (push) Has been cancelled
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
* ci(terraform): fail mixed app and Terraform changes

* fix(ci): count deletions and honor the Terraform working directory

Deleted paths were excluded from the isolation diff, so a mixed change could pass. The checker now treats working-directory as the Terraform prefix.

* fix(ci): load the isolation checker from this workflow's commit

The second checkout used the caller's SHA and the caller's token, so a private clone of this repo could not resolve the script. The checker is now a composite action referenced with $/.
2026-10-02 00:54:43 +00:00
af2ee942ce
chore: remove retired pr-review and compliance-audit tooling
Three pieces of tooling for retired flows were still carried in this
repo, and the README documented them as if they were current.

- `.github/workflows/compliance-audit.yaml`: deprecated 2026-06-10.
  Its schedule was already stripped, and its live state in the Actions
  API is `disabled_manually`, so it was workflow_dispatch-only and
  inert. It was also the last consumer of the `CLAUDE_CI_APP_ID` and
  `CLAUDE_CI_APP_PRIVATE_KEY` org secrets.
- `scripts/rollout-review-workflow.sh`: a one-shot script that pushed a
  per-repo wrapper calling `claude-code-review.yaml`. That reusable
  workflow was deleted on 2026-05-13 and no longer exists in this repo
  or any of the 31 org repos, so the script could only ever open PRs
  for a workflow that resolves to nothing.
- README `PR Reviews`, `Scripts`, and the `claude-code-ci` GitHub App
  setup steps, which described the same retired flows.

The `ANTHROPIC_API_KEY` org secret is deliberately kept in the setup
table: it is still read by the active `reviewer-eval.yml` workflow in
`open-swe`. The `CLAUDE_CI_APP_*` secrets are now unreferenced across
the org, but this change only removes their documentation. Neither the
secrets nor the App itself are touched.

Setup steps are renumbered 1-3 with no gap, and the `see §5` reference
in the IAM section is repointed to §3. actionlint 1.7.12 (the version
pinned in ci.yaml) passes clean over the remaining workflows.
2026-07-28 12:34:26 -04:00
Adam Moussa
0889d0f4e4 Add id-token: write permission for claude-code-action
The action requires OIDC token access even when using an API key directly.
Also updates the rollout script template for future repos.
2026-05-06 19:44:35 -04:00
Adam Moussa
b7502a3bf8 Fix false-positive existence check in rollout script
gh api returns error JSON on 404, which made the variable non-empty.
Check exit code instead of output content.
2026-05-06 18:07:29 -04:00
Adam Moussa
0f166a5a6f Exclude shoc-frontend-new and shoc-backend from review and audit workflows 2026-05-06 17:34:29 -04:00
Adam Moussa
e24004415e Add Claude Code review and compliance audit workflows
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)
2026-05-06 15:10:48 -04:00