docs(dedup-program): reflect claude-review as a ci-workflows reusable workflow - #31
Conversation
… workflow The automated PR-review lane is now a ci-workflows reusable workflow (a peer of the zizmor/osv-scanner reusable workflows), dogfooded there and adopted by medley; medley's interactive @claude assistant remains correctly repo-local. This was an out-of-band addition not in the original phased plan. - inventory.md: reclassify — automated claude-review left REPO-SPECIFIC for a ci-workflows reusable workflow medley consumes by SHA-pin; claude-assistant (interactive @claude) is the lane that stays local. - plan.md: record it under a new "Out-of-band additions" section, backed by the existing D1/D5/D6 design rules; reference (not restate) the workflow's own security rationale. - rollout.md: medley now consumes its first ci-workflows reference; correct the medley (26->27) and ci-workflows (4->6) workflow counts. - README.md: note the addition in the program Status overview. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c2db8ececf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| `tool-version-drift-check`. Automated `claude-review` is no longer local — it was | ||
| lifted out-of-band to a `ci-workflows` reusable workflow that medley now consumes | ||
| by SHA-pin (see [plan.md](plan.md)); only the interactive `claude-assistant` lane |
There was a problem hiding this comment.
Update the medley inventory summary too
This added note now says medley consumes ci-workflows via claude-review, but the same inventory's medley overview still says it consumes ci-workflows for nothing today. When someone uses inventory.md as the current-state audit for Phase 6, those two statements give contradictory adoption status; please update the overview to mention the claude-review exception or qualify it as only the overlapping lanes remaining inline.
Useful? React with 👍 / 👎.
Documentation-only follow-up to ci-workflows #22 and medley #1155 (both merged).
The automated PR-review lane is now a
ci-workflowsreusable workflow(
claude-review.yml, a peer of thezizmor/osv-scannerreusable workflows),dogfooded there and adopted by
medley.medley's interactive@claudeassistant was split into a repo-local
claude-assistant.ymland remainscorrectly local. This was an out-of-band addition not in the original phased
plan, so the dedup-program docs are updated to reclassify it accurately.
Changes
claude-reviewremoved from medley'sREPO-SPECIFIC (stays local) list;
claude-assistant(interactive@claude)is the lane that stays local.
claude-reviewreusable workflow as done, backed by the existing D1/D5/D6design rules; references (does not restate) the workflow's own security
rationale.
ci-workflowsreference;corrected the medley (26→27) and ci-workflows (4→6) workflow counts.
No content is copied from ci-workflows' own README/CLAUDE.md; the docs reference
where the rationale and rules live.
Flagged (not fixed — out of scope)
inventory.md's "What
ci-workflowsprovides today" still lists only the originalfour composite actions +
link-check.yml; it does not reflect the Phase 1–3blocks already built (typos/editorconfig/gitleaks/actionlint/check-jsonschema and
the four hygiene actions; the
zizmor/osv-scanner/claude-reviewreusableworkflows). Pre-existing drift, broader than this change — worth a separate
refresh.
🤖 Generated with Claude Code