Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
108 commits
Select commit Hold shift + click to select a range
ec6818f
Add multi-agent isolation strategy using git worktrees (#2)
don-petry Mar 28, 2026
5fd40b2
Add workflow, environment, and orchestration guidance (#4)
don-petry Mar 29, 2026
a0c0781
Add stacked PR strategy and Epic-level workflow guidance (#5)
don-petry Mar 29, 2026
f159c85
feat: add Structured Logging and CQRS standards (#6)
don-petry Mar 31, 2026
6d825c1
feat: add weekly compliance audit workflow (#12)
don-petry Apr 5, 2026
5cd367e
chore: run compliance audit every Friday at noon UTC
Apr 5, 2026
35ea6fc
feat: add full CI pipeline for .github repo (#15)
don-petry Apr 5, 2026
3c5af80
fix: resolve all markdown lint violations and enable enforced rules (…
don-petry Apr 5, 2026
b146d56
feat: extend compliance audit with CI/automation health survey (#13)
don-petry Apr 6, 2026
f81f69c
feat: add dependabot-rebase workflow standard (#52)
don-petry Apr 6, 2026
16d0450
chore(deps): Bump anthropics/claude-code-action from 1.0.83 to 1.0.89…
dependabot[bot] Apr 6, 2026
ba9fb97
feat: split Claude workflow into interactive + issue automation jobs …
don-petry Apr 6, 2026
d102f09
feat: require GitHub Discussions on all repos (#53)
don-petry Apr 6, 2026
b48989a
fix: grant claude-issue job tools to create PRs and check CI (#55)
don-petry Apr 6, 2026
816f516
fix: add concurrency guard and comment tools to claude-issue job
Apr 6, 2026
7f03866
fix: add claude.yml template + checkout audit check (#63)
claude[bot] Apr 6, 2026
fc5b6bf
fix: auto-create required labels during compliance audit (#67)
claude[bot] Apr 6, 2026
93d1c84
feat: prevent duplicate agent PRs via in-progress labels and umbrella…
claude[bot] Apr 6, 2026
4641965
feat: reusable Claude Code workflow with workflows write permission (…
don-petry Apr 6, 2026
3f58420
Add Feature Ideation workflow as standard for BMAD-enabled repos (#81)
don-petry Apr 7, 2026
55cc6e4
fix: pass GH_PAT_WORKFLOWS to actions/checkout so git push uses workf…
don-petry Apr 7, 2026
edfd810
fix: encode compliance-fix learnings into standards and Claude prompt…
don-petry Apr 8, 2026
00b18cd
feat(workflows): centralize standards via reusable workflows (#87)
don-petry Apr 8, 2026
fa1bbc3
feat(workflows): pin reusable callers to @v1 and document tier model …
don-petry Apr 8, 2026
03e7119
feat(security): add codeql.yml for SAST scanning (#100)
don-petry Apr 8, 2026
efa84ef
Replace per-repo CodeQL workflows with GitHub default setup (#103)
don-petry Apr 9, 2026
13c982b
Auto-respond to all PR review comments without @claude mention (#123)
don-petry Apr 10, 2026
ae65d7e
fix(ci): move Dependabot exclusion to job-level if in claude-code-reu…
don-petry Apr 16, 2026
8c3597c
fix(dependabot): use correct ecosystem value github_actions (undersco…
don-petry Apr 16, 2026
a2841a2
chore(deps): Bump anthropics/claude-code-action from 1.0.89 to 1.0.93…
dependabot[bot] Apr 16, 2026
c61c152
feat(claude): trigger Claude to fix CI failures on PRs (#148)
don-petry Apr 17, 2026
8c693ae
feat(feature-ideation): add curated reputable source list for Mary (#…
don-petry Apr 17, 2026
0956de8
fix: correct reusable workflow path syntax (remove duplicate .github)…
don-petry Apr 21, 2026
efefc70
fix(claude-ci-fix): resolve PR via API when check_run payload is empty
don-petry Apr 21, 2026
c8ac884
feat: add auto-rebase workflow for non-Dependabot PRs
don-petry Apr 21, 2026
78f76fc
docs: document OIDC immutability constraint and exempt claude.yml fro…
don-petry Apr 25, 2026
aba6c37
fix: restore double .github path in agent-shield and claude reusable …
don-petry May 3, 2026
8e2e95d
chore: add bot accounts to CODEOWNERS + define org standard
don-petry May 3, 2026
ccbc52a
fix: add dedup pre-flight to claude-issue to prevent duplicate PRs (#…
don-petry May 3, 2026
06a2060
docs: apply learnings from CODEOWNERS auto-merge fix
don-petry May 3, 2026
14273e7
docs: update standards with Dependabot auto-merge learnings (#187)
don-petry May 4, 2026
ab3f953
fix: use @dependabot rebase instead of update-branch to trigger CI (#…
don-petry May 4, 2026
8cfc76a
docs: rewrite update-branch workflow section with v2 learnings
don-petry May 5, 2026
d29680b
chore: finalize CODEOWNERS standard as Required + add enforcement (#193)
don-petry May 6, 2026
3c16cac
feat: trigger Claude on CodeRabbit and Copilot review comments (#198)
don-petry May 6, 2026
f0fa24b
chore(deps): Bump anthropics/claude-code-action from 1.0.97 to 1.0.11…
dependabot[bot] May 7, 2026
5284a97
chore(deps): Bump anthropics/claude-code-action from 1.0.115 to 1.0.1…
dependabot[bot] May 10, 2026
7ffd60c
chore: deprecate pr-review-agent — remove all traces
don-petry May 11, 2026
39f8869
feat: make pr-review-mention an org standard (#237)
don-petry May 11, 2026
2b75b76
fix(claude): add copilot-pull-request-reviewer and gemini-code-assist…
don-petry May 11, 2026
917bf48
fix(feature-ideation): address Copilot + CodeRabbit review on PR #85 …
don-petry May 12, 2026
757a802
feat(claude): add claude-fix-review-comments job for bot review respo…
don-petry May 13, 2026
67ee8ab
feat(auto-rebase): add claude-rebase agentic fallback for merge confl…
don-petry May 14, 2026
9e08945
chore(dev-lead): deprecate claude.yml in ci-standards, promote dev-le…
don-petry May 16, 2026
a499219
chore(deps): Bump actions/upload-artifact from 4.6.2 to 7.0.1 (#303)
dependabot[bot] May 17, 2026
94d06fb
chore(deps): Bump anthropics/claude-code-action from 1.0.119 to 1.0.1…
dependabot[bot] May 17, 2026
00e8531
chore: remove claude-code-reusable.yml and update auto-rebase references
don-petry May 17, 2026
59bf9cf
feat: implement issue #299 — Compliance audit — 2026-05-15 (#336)
don-petry May 21, 2026
d546244
feat(workflows): add Initiatives project auto-add workflow (#388)
don-petry Jun 7, 2026
77451dc
fix(dependabot-rebase): handle 404 from compare API — skip PR when br…
don-petry Jun 8, 2026
71efcff
fix(ci): downgrade pnpm/action-setup to v5 in dependency-audit reusab…
don-petry Jun 8, 2026
2533bf9
fix(compliance): unbreak daily re-trigger sweep + throttle to one iss…
don-petry Jun 10, 2026
17c0b83
fix(compliance): secret-scan job, pin dtolnay action, exempt internal…
don-petry Jun 10, 2026
ae51693
fix(ci): add gitleaks secret-scan job to satisfy compliance check (#219)
don-petry Jun 11, 2026
859da96
chore: remove deprecated claude.yml from standards (#379)
don-petry Jun 11, 2026
171391d
fix: enable delete_branch_on_merge on .github repo (#222)
don-petry Jun 11, 2026
a7455e1
feat(claude-code-reusable): enable rebases in interactive job (#235)
don-petry Jun 11, 2026
5f0fa65
feat(feature-ideation): auto-enhance new Ideas Discussions on creatio…
don-petry Jun 13, 2026
018c1fd
chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3 (#459)
dependabot[bot] Jun 14, 2026
b5033ba
feat(add-to-project): reusable workflow + reconcile parity (#415) (#466)
don-petry Jun 15, 2026
7b9fef0
fix(ci): pin claude-code-reusable.yml ref to @v1 (#218)
don-petry Jun 15, 2026
8241aab
feat: implement issue #478 — deploy standard workflows via PRs, not d…
don-petry Jun 18, 2026
d9d6608
feat(deploy): batch per-repo stub sync into one PR (#482) (#493)
don-petry Jun 19, 2026
4e24f21
feat: enroll .github in the idea→initiative pipeline + document calle…
don-petry Jun 21, 2026
c319b7f
chore(deps): Bump actions/checkout from 6.0.3 to 7.0.0 (#512)
dependabot[bot] Jun 21, 2026
5ff038e
feat(standards): per-repo initiative-driver caller stub (#884) (#523)
don-petry Jun 22, 2026
9734c03
feat(audit): make centralized-stub check ring-aware (#870) (#529)
don-petry Jun 25, 2026
48769e9
fix: share canary-ring pin model between audit and deploy sweep (#482…
don-petry Jun 25, 2026
6f612b6
docs(ci-standards): feature-ideation backlog enhancement (backfill) +…
don-petry Jun 26, 2026
d6a2943
docs(ci-standards): gate-label creation in the enrollment checklist (…
don-petry Jun 28, 2026
2745921
docs+ci: inline S7635 NOSONAR marker for idea-pipeline caller stubs (…
don-petry Jul 1, 2026
529e0fb
fix(ci): remediate .github compliance findings — 2026-04-17 audit (#147)
don-petry Jul 1, 2026
f5fd51b
feat: implement issue #509 — [Phase 3] Document the PR-limits standar…
don-petry Jul 2, 2026
0054456
fix(feature-ideation): route caller inputs through a prep job (#571) …
don-petry Jul 4, 2026
560e207
feat(add-to-project): track all issues + retire Discussion drafts + C…
don-petry Jul 8, 2026
5f398bf
feat(#613): relocate canary-rollout engine + bootstrap into .github (…
don-petry Jul 9, 2026
934675b
docs(#631): de-duplicate versioning.md (.github-private is authoritat…
don-petry Jul 9, 2026
643229d
feat(#1008): onboard initiative-planner + idea-triage (organic-traffi…
don-petry Jul 10, 2026
f981bda
feat(#1159): register ci-failure-analyst in canary-rings.json (PR-2) …
don-petry Jul 11, 2026
77160d6
feat(#515): register idea-enhancer in canary-rings.json (PR-B) (#660)
don-petry Jul 11, 2026
76bc60e
feat(#614): register feature-ideation in canary-rings.json — fleet dr…
don-petry Jul 11, 2026
3581443
chore(#665): decommission claude-code — retire reusable + drop from u…
don-petry Jul 11, 2026
8a9534d
feat(canary): differs-aware benign classes (version_independent) — #6…
don-petry Jul 12, 2026
1b0175b
feat: implement issue #680 — pr-auto-review ready-check counts non-re…
don-petry Jul 12, 2026
4cb4786
feat: implement issue #694 — F3: ring-pins.sh major-aware canonical-r…
don-petry Jul 13, 2026
fa4582b
docs: refresh org READMEs (automated) (#731)
don-petry Jul 14, 2026
6f8314d
docs: refresh org READMEs (automated) (#737)
don-petry Jul 16, 2026
f1577d3
feat: implement issue #756 — Provision <id>:hands-off labels so perso…
don-petry Jul 17, 2026
68cb689
feat: implement issue #844 — Standard: require feature-ideation / pr-…
don-petry Jul 21, 2026
1202fbb
chore: sync 1 org-standard workflow stub(s) from petry-projects/.gith…
don-petry Jul 21, 2026
b31ee87
chore: sync 1 org-standard workflow stub(s) from petry-projects/.gith…
don-petry Jul 21, 2026
fec4636
chore: sync 1 org-standard workflow stub(s) from petry-projects/.gith…
don-petry Aug 6, 2026
ca4ae6e
feat: implement issue #1023 — canary autocut: scope bump signals to w…
donpetry-bot Aug 31, 2026
8b27caf
fix(reviews): address review comments [skip ci-relay]
donpetry-bot Aug 31, 2026
30375c5
fix(bot): address bot feedback [skip ci-relay]
donpetry-bot Aug 31, 2026
663a334
fix(reviews): address review comments [skip ci-relay]
donpetry-bot Aug 31, 2026
9cae3d9
Merge branch 'main' into dev-lead/issue-1023-20260831-1146
don-petry Aug 31, 2026
5257554
Merge branch 'main' into dev-lead/issue-1023-20260831-1146
don-petry Sep 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions .github/workflows/canary-rollout.yml
Original file line number Diff line number Diff line change
Expand Up @@ -258,6 +258,11 @@ jobs:
# One TSV line per real promotion (agent, ring, sha, owning-repo) so the deployment
# step records a deployment for EVERY move in a promote-all run, on the right host.
CANARY_PROMOTIONS_LOG: ${{ runner.temp }}/promotions.tsv
# Sibling log of FAILED tag writes (agent, ring, sha, host, reason) — an UNEXPECTED
# write rejection, distinct from an expected gate-block (#1023 defect 2). The
# sync-promotion-failures step below turns a repeatedly-failing write into a durable,
# escalating tracking issue instead of a scrolling run-log line.
CANARY_PROMOTIONS_FAILED_LOG: ${{ runner.temp }}/promotions-failed.tsv
run: |
set -euo pipefail
args=()
Expand Down Expand Up @@ -339,6 +344,23 @@ jobs:
set -uo pipefail
bash scripts/canary-rollout.sh sync-issues || echo "::warning::issue sync failed (non-fatal)"

# Escalate FAILED tag writes (#1023 defect 2). A gate-blocked promotion is expected and
# tracked by the step above; a rejected tag WRITE is UNEXPECTED and, before this, left only
# a run-log line. Reconcile this run's success/failure logs into a durable per-agent
# tracking issue whose consecutive-failure streak escalates to needs-human + dev-lead, and
# auto-closes when a write recovers. Best-effort + always(): promote-all returns non-zero
# when an agent's write failed, so this must run even after that step "fails".
- name: Escalate failed promotion tag-writes
if: always() && github.event_name == 'schedule'
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
ISSUE_REPO: ${{ github.repository }}
CANARY_PROMOTIONS_LOG: ${{ runner.temp }}/promotions.tsv
CANARY_PROMOTIONS_FAILED_LOG: ${{ runner.temp }}/promotions-failed.tsv
run: |
set -uo pipefail
bash scripts/canary-rollout.sh sync-promotion-failures || echo "::warning::promotion-failure escalation failed (non-fatal)"

# Reusable-registry drift audit (#1082): the registry (.agents{}) is the MANUAL source
# of truth for what this pipeline manages — a *-reusable.yml added/renamed on a host but
# never registered ships with ZERO staged rollout (no cut/soak/gate/dashboard) until a
Expand Down
49 changes: 39 additions & 10 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,15 +142,13 @@ E2E tests validate real functional requirements through the full stack. They exi

### What E2E Tests MUST Do

1. **Full round-trip verification.** Action → API call → database mutation → response → frontend reflects new state. Not a subset — the whole chain.
2. **Multi-layer assertions.** The frontend shows correct data AND the database contains the correct record AND side effects occurred (events published, notifications queued, cache invalidated).
3. **Verify at the data layer.** After a form submission, query the database directly to verify the record exists with correct fields.
1. **Verify at the data layer.** After a form submission, query the database directly to verify the record exists with correct fields.
After a delete, verify it's gone. After auth, verify the token's claims and scopes. Do NOT stop at "success toast appeared."
4. **Test error paths.** For every happy-path test, write corresponding tests for:
2. **Test error paths.** For every happy-path test, write corresponding tests for:
invalid input, unauthorized access, conflict/duplicate states, and not-found resources.
5. **Test authorization boundaries.** Verify user A cannot access user B's resources. Verify regular users cannot hit admin endpoints. Verify expired/revoked tokens are rejected.
6. **Use realistic data.** Factories that produce production-realistic data (unicode names, long strings, special characters, realistic cardinalities) — not `"test"` and `"foo"`.
7. **Deterministic waits.** Wait for specific conditions (element visible, API response received, database row present) using polling with timeouts — never arbitrary sleeps.
3. **Test authorization boundaries.** Verify user A cannot access user B's resources. Verify regular users cannot hit admin endpoints. Verify expired/revoked tokens are rejected.
4. **Use realistic data.** Factories that produce production-realistic data (unicode names, long strings, special characters, realistic cardinalities) — not `"test"` and `"foo"`.
5. **Deterministic waits.** Wait for specific conditions (element visible, API response received, database row present) using polling with timeouts — never arbitrary sleeps.

### Forbidden Patterns

Expand Down Expand Up @@ -230,6 +228,8 @@ assert getText("[test-id='order-id']") contains dbOrder.orderId

### Frontend E2E (Web and Mobile)

- **Full round-trip verification.** Action → API call → database mutation → response → frontend reflects new state. Not a subset — the whole chain.
- **Multi-layer assertions.** The frontend shows correct data AND the database contains the correct record AND side effects occurred (events published, notifications queued, cache invalidated).
- **Run against the real backend** — not a mocked API layer. The frontend E2E test environment connects to a real API backed by a real (test) database.
- **Test full navigation flows** — deep links, back navigation, tab switching with state preservation, modal dismissal.
- **Test offline/online transitions** (mobile) — disable network, verify cached data displays and writes queue, re-enable, verify sync.
Expand Down Expand Up @@ -784,8 +784,10 @@ Before starting work on **any** GitHub issue, an agent MUST:
2. **Check for an open PR referencing the issue.** If one exists, skip the issue or comment on the PR instead.

```bash
gh pr list --repo <owner>/<repo> --state open --search "closes #<issue-number>" --json number | \
jq 'length > 0'
for kw in close closes closed fix fixes fixed resolve resolves resolved; do
gh pr list --repo <owner>/<repo> --state open --limit 1000 \
--search "$kw #<issue-number>" --json number --jq '.[].number'
done | sort -nu | jq -sR 'split("\n") | map(select(. != "")) | length > 0'
```

3. **Claim the issue immediately** by adding the `in-progress` label — before writing any code.
Expand All @@ -809,7 +811,7 @@ If found, comment on the existing PR rather than creating a competing one.

```bash
# Check if any open PR already creates the target file
gh pr list --repo <owner>/<repo> --state open --json files \
gh pr list --repo <owner>/<repo> --state open --limit 1000 --json files \
--jq '.[].files[].path' | grep -qx "<path/to/file>" && echo "FILE ALREADY IN OPEN PR"
```

Expand Down Expand Up @@ -1086,6 +1088,33 @@ Before starting a stacked Epic/Feature workflow, verify:
- **CI runs on each PR independently.** Ensure CI is configured to run against the PR's base branch, not just `main`. Most CI systems (GitHub Actions, etc.) handle this correctly by default.
- **PR review is incremental.** Reviewers see only the diff between the Epic/Feature branch and its parent — not the entire stack. This keeps reviews focused and manageable.

#### Pull Request Limits (automation open-PR cap)

The org enforces a **soft ceiling on concurrent open, non-draft automation PRs
org-wide** so automation cannot outrun merge throughput and inflate the
auto-rebase fan-out. Full standard, rationale, and operator runbook:
[`standards/pr-limits.md`](https://github.com/petry-projects/.github/blob/main/standards/pr-limits.md).

- **GitHub has no native "max open PRs" surface** (no repo setting, org setting,
or ruleset rule — verified in the [ADR](https://github.com/petry-projects/.github/blob/main/docs/initiatives/pull-request-limits-adr.md)),
so this is enforced **source-side** by [`scripts/lib/pr-limit-gate.sh`](https://github.com/petry-projects/.github/blob/main/scripts/lib/pr-limit-gate.sh):
a PR-creating workflow asks the gate before opening a PR and **defers** (never
fails or closes) when the queue is at the cap. Live-path wiring is Story 3 (#508).
- **The configured value lives only in [`standards/pr-limits.json`](https://github.com/petry-projects/.github/blob/main/standards/pr-limits.json)** —
the single source of truth. Read it with `jq`; never hardcode or restate it.

> **Exempt actors are sanctioned policy, not drift.** `dependabot[bot]`,
> `OrganizationAdmin`, `@petry-projects/org-leads`, the `dependabot-automerge-petry`
> app, and `security`-labeled PRs are on the cap's exempt list — never blocked
> and never counted. This mirrors the ruleset bypass-actor allowance (see
> [Ruleset remediation](https://github.com/petry-projects/.github/blob/main/standards/ruleset-remediation-runbook.md)):
> `dependabot[bot]` is already bounded by its own per-ecosystem
> `open-pull-requests-limit` (so counting it here would double-cap and could
> starve a security PR), the human/admin actors are break-glass and maintainer
> traffic, and the app only operates on existing PRs. A compliance audit should
> treat these as intentional exemptions. To change the cap or the exempt list,
> follow the runbook in [`standards/pr-limits.md`](https://github.com/petry-projects/.github/blob/main/standards/pr-limits.md).

---

## Agent Operation Guidance
Expand Down
Loading
Loading