feat(house): issue forms, token split, dependency auto-merge and CodeQL languages - #32
Conversation
…Linear templates Every repository had only bug and feature forms, with blank issues off, so a documentation or performance problem had nowhere to go. Add a documentation form (modelled on the Linear Documentation review template) and a performance form that asks for repeatable measurements, give the bug form the environment field the Linear Bug report template has, and describe all four in CONTRIBUTING, the synced-files reference and the ai-docs. Refs: SMC-132 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
The Graphify check told pull request authors their graph was stale and to update and commit it, printed twice, while the refresh job showed as skipped, which read as a broken workflow. A graph one commit behind is expected: refresh rebuilds it on the default branch after merge. The check now prints the drift once as a notice and a job summary that says no action is needed and what happens next, and the refresh job is named for why it is skipped on pull requests. The workflows guide gains the common problems. Refs: SMC-131 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
The aggregate smartcloud check waited for CodeRabbit and the Cursor agents too, so a slow or neutral bot run could hold a merge, and the Cursor approval agent, which waits for the checks, could deadlock with it. Review bots only advise; the findings that block (AP-31) arrive as review comments or the Graphify check, which still counts. The list goes in the repository's own config rather than the house preset, because a list the locked preset set could never be added to. Refs: SMC-130 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
…nch's CodeQL's language list came from GitHub's repository languages, which describe the default branch, so a pull request that brought a repository's first file in a new language went unscanned for it until after merge. The languages job now adds the languages of the files a pull request or merge queue entry adds or changes, by extension, skipping vendored and build paths where a language with nothing to analyse would fail its job. A failed comparison warns and falls back to the repository's languages. Refs: SMC-126 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
… .github from a leaf repository The synced smartcloud workflow minted the Resnovas Bot token with the app's full permission set for the repository and Resnovas/.github on every non-fork event, pull requests included, so a changed workflow in any repository could write to the house repository. It now mints a read-only token (permission-contents: read, repositories: .github) on every trusted run, passed as houseToken for the preset and sync templates, and the full app token, scoped to the repository alone, only on push, schedule and dispatch runs of the default branch and on a merged same-repository pull request's closed event, so backport pull requests start CI. Fork and Dependabot runs mint neither and stay restricted. An older smartcloud ignores the new input. Resnovas/.github is public, so the docs no longer call it private; the house token stays so no privileged token touches it and its reads use the app's rate limit. Access, workflows, sync and troubleshooting docs and ai-docs describe the model. Refs: SMC-128 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Routine Dependabot and Renovate updates waited for someone to press merge even when CI was green. The house preset now has an autoMerge rule that turns on GitHub auto-merge for patch and minor updates, so they land through the merge queue once the required checks pass; major updates still wait for a person. Turning auto-merge on needs the right to merge, so the synced smartcloud job asks for contents: write; it runs the published action, never the pull request's code, and a fork's token stays read-only. Refs: SMC-115 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Describes how a repository that releases from conventional commits previews the next release on each pull request: rebuild the squash commit, dry-run the release tool with a read-only token, post one updated comment from a separate job with only pull-requests: write, and never fail the pull request. It is a report, not a check, so it needs no merge_group and stays out of the aggregate. smartcloud is the worked example. Refs: SMC-109 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Anyone reading this repository as an example had no route to a guide for building the same kind of hub for their own organisation. The README's start table and getting-started now link to the new smartcloud guides (an organisation's own sync hub, recommended setups, building the settings file), and name the files here that serve as the full-size example. Refs: SMC-147 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: claude-code:claude-opus-5-5 Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
|
smartcloud found 0 error(s), 2 warning(s).
This comment updates itself when you push a fix. |
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.
Graphify review — findings
Splits contribution intake by adding dedicated Documentation and Performance issue templates and a required Environment field on bug reports, with the performance form demanding version, reproducible workload, and multi-run measurements before a report is actionable. Extends the CodeQL workflow to detect languages from the files a PR or merge-queue entry changes—by extension, skipping vendored and generated paths—so a newly introduced language is scanned before merge, falling back to the repository's default-branch languages when the compare API fails rather than stopping the scan. Tells SmartCloud to ignore CodeRabbit and Cursor status checks so their advisory runs never gate the aggregate and can't deadlock the approval agent.
Worth a look
- Full app token can be minted on non-default branch pushes —
.github/workflows/smartcloud.yml:100· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- Changed-file language detection misses files beyond compare API cap —
.github/workflows/codeql.yml:55· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 197 functions depend on the 197 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 197 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 197 function(s) in the blast radius were not formally verified this run
Risky patterns (advisory)
- medium
no-stderr-to-stdoutin.github/workflows/graphify.yml:61: stderr redirected to stdout: if out=$(sh tools/graphify/graphify check 2>&1); then
Main gained the issue forms and token split (#32), the disclosure wording (#31) and a quoted 'none' option in the rendered bug report form. The rewritten AGENTS.md and house-standards ai-docs keep the one-trailer AI-02 wording of this batch, with the pull request disclosure bullet from #31 folded in, and the documentation and performance forms take the unassisted level like the other two, which removes the reserved word instead of quoting it. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
What changed and why
A batch of one signed commit per issue, for an owner fast-forward after approval.
feat(house): documentation and performance issue forms, matching the Linear templates- SMC-132: newdocumentation.ymlandperformance.ymlforms, and an environment field on the bug form, matching the Linear templates; CONTRIBUTING,docs/synced-files.mdand the ai-docs describe all fourfix(house): say that a stale graph on a pull request needs no action- SMC-131: the Graphify check prints the drift once as a notice and job summary saying no action is needed, and the refresh job is namedrefresh (default branch only)ci(smartcloud): keep review bot checks out of the required aggregate- SMC-130:required.ignorefor CodeRabbit and the Cursor agents in this repository's own config, withdocs/preset.mdtelling every house repository to do the same (the locked preset cannot set a list repositories extend)ci(house): scan the languages a change adds, not only the default branch's- SMC-126 part 1: CodeQL's languages job adds the languages of the files a pull request or merge queue entry changes (compare API), skipping vendored paths, and falls back with a warning if the comparison failsfeat(house): split smartcloud's tokens so the app token never reaches .github from a leaf repository- SMC-128: the house template mints a read-onlyhouseTokenfor.githuband the repo-scoped app token only on push, schedule, dispatch and a merged same-repository pull request;docs/access.mdexplains the three tokensfeat(house): let dependency patch and minor updates merge themselves- SMC-115: anautoMergerule in the preset for Dependabot and Renovate patch and minor updates, andcontents: writeon the synced smartcloud job so the workflow token can turn auto-merge on in Dependabot's runs (the job runs the published action, never the pull request's code)docs(ci): add the release preview pattern to the CI standards- SMC-109docs(house): point other organisations at the smartcloud setup guides- SMC-147Every change has ELI5 human docs and ai-docs in its own commit.
Land after Resnovas/smartcloud#714 and the next nightly
v2. The token split template passeshouseTokenand relies on the new action; an older action ignores the unknown input but would run with a repository-only app token. TheautoMergepreset key is ignored with a warning by an action that does not know it yet, so it cannot break runs.#31 (AI disclosure) also regenerates
LLMS.md; whichever lands second needsnode tools/ai-docs/docgen.mjsrerun.Evidence
Each commit was checked on its own tree:
node scripts/render.mjs --checkandnode tools/ai-docs/docgen.mjs --checkpass at every commit, andnode --run testpasses 61 of 61 in the workspace. actionlint and zizmor are clean on the changed workflows. The CodeQL language detection and the Graphify notice were run locally against stubbed inputs (new.pyfile adds Python; vendored.rbskipped; removed.goskipped; failed comparison warns and falls back). The house preset validates with the smartcloud CLI built from #714.node --run checklocally flags only.mcp.json, an uncommitted local edit that is not part of this batch.Decisions for review
closedtrigger, since the house configures no backports.Closes SMC-132
Closes SMC-131
Closes SMC-130
Part of SMC-126 (part 2 needs a decision)
Closes SMC-128
Closes SMC-115
Closes SMC-109
Closes SMC-147
AI disclosure
AI level: autonomous
AI tools: Claude Code (claude-opus-5-5)
Accountable human:
Human review: