Skip to content

chore(deps): bump the actions group across 1 directory with 7 updates - #576

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-f3a151d1ad
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-f3a151d1ad

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 7 updates in the / directory:

Package From To
actions/checkout 6.0.2 6.0.3
petry-projects/.github-private/.github/workflows/ci-failure-analyst-reusable.yml db60a41eb00b127f201c7294c529c7c599324e4e 0ef7b6150516c4fa447700b4902e8ed406bcfb99
petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml 1 2
petry-projects/.github/.github/workflows/dependency-audit-reusable.yml 1 2
petry-projects/.github/.github/workflows/feature-ideation-reusable.yml 1 2
anthropics/claude-code-action 1.0.133 1.0.148
SonarSource/sonarqube-scan-action 8.1.0 8.2.0

Updates actions/checkout from 6.0.2 to 6.0.3

Release notes

Sourced from actions/checkout's releases.

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

... (truncated)

Commits

Updates petry-projects/.github-private/.github/workflows/ci-failure-analyst-reusable.yml from db60a41 to 0ef7b61

Commits
  • 0ef7b61 Merge branch 'main' into fix/action-sha-pinning
  • 2c7fc09 chore(deps): bump anthropics/claude-code-action from 1.0.128 to 1.0.133 (#406)
  • e040dc4 chore: apply manual instructions [skip ci-relay]
  • 768d8e1 fix: pin GitHub Actions to specific commit SHAs per compliance standard
  • 956b955 fix(dev-lead): set git identity before commit in commit_and_push (#369)
  • 6610e8a feat(engine): in-Claude model fallback before cross-provider switch (#380)
  • baf9ae2 fix(dev-lead): expose GEMINI_API_KEY so gemini fallback actually works (#381)
  • 2d43402 fix(dev-lead): centralize git identity setup; apply to fix-ci & fix-reviews (...
  • 4f9cdda test(dev-lead): runtime-build PEM markers in writer redaction test (#377)
  • See full diff in compare view

Updates petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml from 1 to 2

Commits
  • 376a4fc feat: auto-trigger PR review when all readiness criteria are met (#323)
  • 6306793 feat(concurrency): add per-repo serialized concurrency to dev-lead stubs (#322)
  • 0765a60 fix(compliance): track per-workflow version tags in stub checker (#302)
  • 66c4866 chore: remove claude-code-reusable.yml and update auto-rebase references
  • f666f32 Merge pull request #320 from petry-projects/feat/harden-scorecard-workflow
  • 9c9cdd3 feat: harden scorecard workflow to report malformed YAML as findings
  • f88d254 Merge pull request #319 from petry-projects/fix/scorecard-summary-score
  • 57c1c5e fix: update aggregate score extraction key for scorecard v5.5.0
  • 6fd676b Merge pull request #312 from petry-projects/fix/scorecard-workflow-v2
  • b1b947e fix: resolve jq parse error by iterating with index
  • Additional commits viewable in compare view

Updates petry-projects/.github/.github/workflows/dependency-audit-reusable.yml from 1 to 2

Commits
  • 376a4fc feat: auto-trigger PR review when all readiness criteria are met (#323)
  • 6306793 feat(concurrency): add per-repo serialized concurrency to dev-lead stubs (#322)
  • 0765a60 fix(compliance): track per-workflow version tags in stub checker (#302)
  • 66c4866 chore: remove claude-code-reusable.yml and update auto-rebase references
  • f666f32 Merge pull request #320 from petry-projects/feat/harden-scorecard-workflow
  • 9c9cdd3 feat: harden scorecard workflow to report malformed YAML as findings
  • f88d254 Merge pull request #319 from petry-projects/fix/scorecard-summary-score
  • 57c1c5e fix: update aggregate score extraction key for scorecard v5.5.0
  • 6fd676b Merge pull request #312 from petry-projects/fix/scorecard-workflow-v2
  • b1b947e fix: resolve jq parse error by iterating with index
  • Additional commits viewable in compare view

Updates petry-projects/.github/.github/workflows/feature-ideation-reusable.yml from 1 to 2

Commits
  • 376a4fc feat: auto-trigger PR review when all readiness criteria are met (#323)
  • 6306793 feat(concurrency): add per-repo serialized concurrency to dev-lead stubs (#322)
  • 0765a60 fix(compliance): track per-workflow version tags in stub checker (#302)
  • 66c4866 chore: remove claude-code-reusable.yml and update auto-rebase references
  • f666f32 Merge pull request #320 from petry-projects/feat/harden-scorecard-workflow
  • 9c9cdd3 feat: harden scorecard workflow to report malformed YAML as findings
  • f88d254 Merge pull request #319 from petry-projects/fix/scorecard-summary-score
  • 57c1c5e fix: update aggregate score extraction key for scorecard v5.5.0
  • 6fd676b Merge pull request #312 from petry-projects/fix/scorecard-workflow-v2
  • b1b947e fix: resolve jq parse error by iterating with index
  • Additional commits viewable in compare view

Updates anthropics/claude-code-action from 1.0.133 to 1.0.148

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.148

Full Changelog: anthropics/claude-code-action@v1...v1.0.148

v1.0.147

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.147

v1.0.146

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.146

v1.0.145

Full Changelog: anthropics/claude-code-action@v1...v1.0.145

v1.0.144

Full Changelog: anthropics/claude-code-action@v1...v1.0.144

v1.0.143

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.143

... (truncated)

Commits
  • d5726de chore: bump Claude Code to 2.1.177 and Agent SDK to 0.3.177
  • 56fa348 chore: bump Claude Code to 2.1.176 and Agent SDK to 0.3.176
  • 82d95d4 Add pr-stamp-sweep review workflow (#1409)
  • 0cb4f3e chore: bump Claude Code to 2.1.175 and Agent SDK to 0.3.175
  • 8551f4b fix(image-downloader): detect image type from magic bytes (#1396)
  • eba921f docs: fix execution file parsing example (#1297)
  • 36617bd fix(sanitizer): match attribute quotes by type to avoid mangling content (#1371)
  • 24b9156 Include labels in formatContext() output for issues and PRs (#1298)
  • 9441a7f fix: clear stale claude-prompts dir before each write (#1288)
  • b371255 pin setup-bun path for post steps (#1365)
  • Additional commits viewable in compare view

Updates SonarSource/sonarqube-scan-action from 8.1.0 to 8.2.0

Release notes

Sourced from SonarSource/sonarqube-scan-action's releases.

v8.2.0

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8...v8.2.0

Commits
  • 7138816 SQSCANGHA-127 Rename downloaded file to .zip before extraction on Windows (#251)
  • 3581139 SQSCANGHA-135 Fix scanner binaries always re-downloaded due to incompatible 4...
  • c9d327c SQSCANGHA-84 Remove outdated wget/curl references
  • b243e51 SQSCANGHA-88 Deprecate the SONARCLOUD_URL env variable support
  • 375c3f5 SQSCANGHA-149 Add scannerBinariesAuthHeader input for authenticated binary do...
  • 9c78323 SQSCANGHA-144 Add gate jobs to QA workflows for branch protection
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Dependency update PRs security Security-related PRs and issues labels Jun 11, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 11, 2026 21:38
@dependabot dependabot Bot added security Security-related PRs and issues dependencies Dependency update PRs labels Jun 11, 2026
@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot enabled auto-merge (squash) June 11, 2026 21:38
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-f3a151d1ad branch from 20bd72f to 5da0149 Compare June 11, 2026 22:50
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-f3a151d1ad branch from 5da0149 to 75ba2f6 Compare June 12, 2026 01:55
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-f3a151d1ad branch from 75ba2f6 to d25a75b Compare June 12, 2026 02:19
Bumps the actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `6.0.3` |
| [petry-projects/.github-private/.github/workflows/ci-failure-analyst-reusable.yml](https://github.com/petry-projects/.github-private) | `db60a41eb00b127f201c7294c529c7c599324e4e` | `0ef7b6150516c4fa447700b4902e8ed406bcfb99` |
| [petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml](https://github.com/petry-projects/.github) | `1` | `2` |
| [petry-projects/.github/.github/workflows/dependency-audit-reusable.yml](https://github.com/petry-projects/.github) | `1` | `2` |
| [petry-projects/.github/.github/workflows/feature-ideation-reusable.yml](https://github.com/petry-projects/.github) | `1` | `2` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.133` | `1.0.148` |
| [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `8.1.0` | `8.2.0` |



Updates `actions/checkout` from 6.0.2 to 6.0.3
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6.0.2...df4cb1c)

Updates `petry-projects/.github-private/.github/workflows/ci-failure-analyst-reusable.yml` from db60a41 to 0ef7b61
- [Commits](db60a41...0ef7b61)

Updates `petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml` from 1 to 2
- [Commits](petry-projects/.github@v1...v2)

Updates `petry-projects/.github/.github/workflows/dependency-audit-reusable.yml` from 1 to 2
- [Commits](petry-projects/.github@v1...v2)

Updates `petry-projects/.github/.github/workflows/feature-ideation-reusable.yml` from 1 to 2
- [Commits](petry-projects/.github@d3d768d...376a4fc)

Updates `anthropics/claude-code-action` from 1.0.133 to 1.0.148
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@787c5a0...d5726de)

Updates `SonarSource/sonarqube-scan-action` from 8.1.0 to 8.2.0
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](SonarSource/sonarqube-scan-action@7006c44...7138816)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.144
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: petry-projects/.github-private/.github/workflows/ci-failure-analyst-reusable.yml
  dependency-version: 0ef7b61
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/dependabot-automerge-reusable.yml
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/dependency-audit-reusable.yml
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: petry-projects/.github/.github/workflows/feature-ideation-reusable.yml
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 8.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-f3a151d1ad branch from d25a75b to b3bce2e Compare June 13, 2026 12:55
@dependabot @github

dependabot Bot commented on behalf of github Jun 13, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 13, 2026
auto-merge was automatically disabled June 13, 2026 13:04

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-f3a151d1ad branch June 13, 2026 13:04
don-petry added a commit that referenced this pull request Jul 3, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 18, 2026
…source (#575) (#1013)

* chore(rulesets): repoint apply-rulesets + bootstrap to fleet source in .github (#575)

The org-wide fleet rulesets (code-quality, pr-quality) now live in
petry-projects/.github (standards/rulesets/, relocated there in the companion PR).
Repoint the codified applier and the bootstrap orchestrator to source them from
there, and remove the local copies. release-channel-tags stays repo-local.

apply-rulesets.sh:
- Default is now "fleet mode": when RULESETS_DIR is unset, materialize the fleet
  rulesets from STANDARDS_REPO (default petry-projects/.github) — via a local
  FLEET_RULESETS_DIR checkout when provided, else a gh contents-API fetch into a
  temp dir (mirrors seed-repo-template.sh's _fetch_standard model).
- The repo-local release-channel-tags is applied by pointing RULESETS_DIR at this
  repo's own .github/rulesets (unchanged mechanism).
- Remove the now-dead SCRIPT_DIR-based local default.

bootstrap-new-repo.sh:
- step_rulesets now applies exactly the two fleet rulesets to a new repo (fleet
  mode). release-channel-tags is NO LONGER applied to bootstrapped repos — it
  protects .github-private's own pr-review/** + dev-lead/** release tags only, so
  it is repo-local by the #575/#576 boundary. (Previously all 3 were applied.)

Remove .github/rulesets/{code-quality,pr-quality}.json (moved to .github).

Tests:
- test_apply_rulesets.bats: pass RULESETS_DIR explicitly for release-channel-tags;
  add fleet-mode coverage (2 rulesets applied, never release-channel-tags;
  dry-run no-writes; missing FLEET_RULESETS_DIR errors).
- test_bootstrap_new_repo.bats: provision a fleet fixture in setup so the real
  apply-rulesets resolves offline; drop the pr-quality/code-quality JSON *shape*
  assertions (that content is now owned + validated in .github); assert bootstrap
  applies exactly 2 fleet rulesets and not release-channel-tags.
- new-repo-validation.md: 3 -> 2 ruleset(s); source-of-truth now petry-projects/.github.

Migration safety (AC): relocated JSONs are byte-identical to the pre-move copies;
a live --dry-run against petry-projects/.github-private resolves them and UPDATES
the existing rulesets in place (PUT by id, not delete/recreate). code-quality is a
live no-op. NOTE: pr-quality shows a PRE-EXISTING file-vs-live delta on
.github-private (live require_last_push_approval=true vs file false) — identical
before/after this move (the origin/main file carries the same value), so the move
introduces no new drift. Flagged as an out-of-scope follow-up.

Depends on the companion petry-projects/.github PR (must merge first).
Part of #575. Follows #576.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency update PRs security Security-related PRs and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants