* ci(terraform): fail mixed app and Terraform changes
* fix(ci): count deletions and honor the Terraform working directory
Deleted paths were excluded from the isolation diff, so a mixed change could pass. The checker now treats working-directory as the Terraform prefix.
* fix(ci): load the isolation checker from this workflow's commit
The second checkout used the caller's SHA and the caller's token, so a private clone of this repo could not resolve the script. The checker is now a composite action referenced with $/.
Three pieces of tooling for retired flows were still carried in this
repo, and the README documented them as if they were current.
- `.github/workflows/compliance-audit.yaml`: deprecated 2026-06-10.
Its schedule was already stripped, and its live state in the Actions
API is `disabled_manually`, so it was workflow_dispatch-only and
inert. It was also the last consumer of the `CLAUDE_CI_APP_ID` and
`CLAUDE_CI_APP_PRIVATE_KEY` org secrets.
- `scripts/rollout-review-workflow.sh`: a one-shot script that pushed a
per-repo wrapper calling `claude-code-review.yaml`. That reusable
workflow was deleted on 2026-05-13 and no longer exists in this repo
or any of the 31 org repos, so the script could only ever open PRs
for a workflow that resolves to nothing.
- README `PR Reviews`, `Scripts`, and the `claude-code-ci` GitHub App
setup steps, which described the same retired flows.
The `ANTHROPIC_API_KEY` org secret is deliberately kept in the setup
table: it is still read by the active `reviewer-eval.yml` workflow in
`open-swe`. The `CLAUDE_CI_APP_*` secrets are now unreferenced across
the org, but this change only removes their documentation. Neither the
secrets nor the App itself are touched.
Setup steps are renumbered 1-3 with no gap, and the `see §5` reference
in the IAM section is repointed to §3. actionlint 1.7.12 (the version
pinned in ci.yaml) passes clean over the remaining workflows.
- Reusable PR review workflow (repos call via thin wrapper)
- Weekly compliance audit across all org repos
- Rollout script to push wrapper workflow to all repos
- Uses GitHub App tokens for cross-repo auth (no PAT rotation needed)