Skip to content

feat(house): issue forms, token split, dependency auto-merge and CodeQL languages - #32

Merged
TGTGamer merged 8 commits into
mainfrom
claude/batch-2026-09-27-house
Sep 28, 2026
Merged

TGTGamer merged 8 commits into
mainfrom
claude/batch-2026-09-27-house

Conversation

@TGTGamer

Copy link
Copy Markdown
Member

What changed and why

A batch of one signed commit per issue, for an owner fast-forward after approval.

  • feat(house): documentation and performance issue forms, matching the Linear templates - SMC-132: new documentation.yml and performance.yml forms, and an environment field on the bug form, matching the Linear templates; CONTRIBUTING, docs/synced-files.md and the ai-docs describe all four
  • fix(house): say that a stale graph on a pull request needs no action - SMC-131: the Graphify check prints the drift once as a notice and job summary saying no action is needed, and the refresh job is named refresh (default branch only)
  • ci(smartcloud): keep review bot checks out of the required aggregate - SMC-130: required.ignore for CodeRabbit and the Cursor agents in this repository's own config, with docs/preset.md telling every house repository to do the same (the locked preset cannot set a list repositories extend)
  • ci(house): scan the languages a change adds, not only the default branch's - SMC-126 part 1: CodeQL's languages job adds the languages of the files a pull request or merge queue entry changes (compare API), skipping vendored paths, and falls back with a warning if the comparison fails
  • feat(house): split smartcloud's tokens so the app token never reaches .github from a leaf repository - SMC-128: the house template mints a read-only houseToken for .github and the repo-scoped app token only on push, schedule, dispatch and a merged same-repository pull request; docs/access.md explains the three tokens
  • feat(house): let dependency patch and minor updates merge themselves - SMC-115: an autoMerge rule in the preset for Dependabot and Renovate patch and minor updates, and contents: write on the synced smartcloud job so the workflow token can turn auto-merge on in Dependabot's runs (the job runs the published action, never the pull request's code)
  • docs(ci): add the release preview pattern to the CI standards - SMC-109
  • docs(house): point other organisations at the smartcloud setup guides - SMC-147

Every change has ELI5 human docs and ai-docs in its own commit.

Land after Resnovas/smartcloud#714 and the next nightly v2. The token split template passes houseToken and relies on the new action; an older action ignores the unknown input but would run with a repository-only app token. The autoMerge preset key is ignored with a warning by an action that does not know it yet, so it cannot break runs.

#31 (AI disclosure) also regenerates LLMS.md; whichever lands second needs node tools/ai-docs/docgen.mjs rerun.

Evidence

Each commit was checked on its own tree: node scripts/render.mjs --check and node tools/ai-docs/docgen.mjs --check pass at every commit, and node --run test passes 61 of 61 in the workspace. actionlint and zizmor are clean on the changed workflows. The CodeQL language detection and the Graphify notice were run locally against stubbed inputs (new .py file adds Python; vendored .rb skipped; removed .go skipped; failed comparison warns and falls back). The house preset validates with the smartcloud CLI built from #714. node --run check locally flags only .mcp.json, an uncommitted local edit that is not part of this batch.

Decisions for review

  • SMC-126 part 2 (default-setup rollout order) is left as a decision on the issue.
  • SMC-130: whether the Graphify gate should be required is open on the issue; freshness stays advisory.
  • SMC-128: the template gains backport's mint condition but not the closed trigger, since the house configures no backports.

Closes SMC-132
Closes SMC-131
Closes SMC-130
Part of SMC-126 (part 2 needs a decision)
Closes SMC-128
Closes SMC-115
Closes SMC-109
Closes SMC-147

AI disclosure

AI level: autonomous
AI tools: Claude Code (claude-opus-5-5)
Accountable human:
Human review:

TGTGamer and others added 8 commits September 27, 2026 19:25
…Linear templates

Every repository had only bug and feature forms, with blank issues off, so a
documentation or performance problem had nowhere to go. Add a documentation
form (modelled on the Linear Documentation review template) and a performance
form that asks for repeatable measurements, give the bug form the environment
field the Linear Bug report template has, and describe all four in
CONTRIBUTING, the synced-files reference and the ai-docs.

Refs: SMC-132

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
The Graphify check told pull request authors their graph was stale and to
update and commit it, printed twice, while the refresh job showed as
skipped, which read as a broken workflow. A graph one commit behind is
expected: refresh rebuilds it on the default branch after merge. The check
now prints the drift once as a notice and a job summary that says no action
is needed and what happens next, and the refresh job is named for why it is
skipped on pull requests. The workflows guide gains the common problems.

Refs: SMC-131

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
The aggregate smartcloud check waited for CodeRabbit and the Cursor agents
too, so a slow or neutral bot run could hold a merge, and the Cursor
approval agent, which waits for the checks, could deadlock with it. Review
bots only advise; the findings that block (AP-31) arrive as review comments
or the Graphify check, which still counts. The list goes in the
repository's own config rather than the house preset, because a list the
locked preset set could never be added to.

Refs: SMC-130

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
…nch's

CodeQL's language list came from GitHub's repository languages, which
describe the default branch, so a pull request that brought a repository's
first file in a new language went unscanned for it until after merge. The
languages job now adds the languages of the files a pull request or merge
queue entry adds or changes, by extension, skipping vendored and build paths
where a language with nothing to analyse would fail its job. A failed
comparison warns and falls back to the repository's languages.

Refs: SMC-126

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
… .github from a leaf repository

The synced smartcloud workflow minted the Resnovas Bot token with the app's
full permission set for the repository and Resnovas/.github on every
non-fork event, pull requests included, so a changed workflow in any
repository could write to the house repository.

It now mints a read-only token (permission-contents: read, repositories:
.github) on every trusted run, passed as houseToken for the preset and sync
templates, and the full app token, scoped to the repository alone, only on
push, schedule and dispatch runs of the default branch and on a merged
same-repository pull request's closed event, so backport pull requests
start CI. Fork and Dependabot runs mint neither and stay restricted. An
older smartcloud ignores the new input. Resnovas/.github is public, so the
docs no longer call it private; the house token stays so no privileged
token touches it and its reads use the app's rate limit. Access, workflows,
sync and troubleshooting docs and ai-docs describe the model.

Refs: SMC-128

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Routine Dependabot and Renovate updates waited for someone to press merge
even when CI was green. The house preset now has an autoMerge rule that
turns on GitHub auto-merge for patch and minor updates, so they land through
the merge queue once the required checks pass; major updates still wait for
a person. Turning auto-merge on needs the right to merge, so the synced
smartcloud job asks for contents: write; it runs the published action, never
the pull request's code, and a fork's token stays read-only.

Refs: SMC-115

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Describes how a repository that releases from conventional commits previews
the next release on each pull request: rebuild the squash commit, dry-run the
release tool with a read-only token, post one updated comment from a separate
job with only pull-requests: write, and never fail the pull request. It is a
report, not a check, so it needs no merge_group and stays out of the
aggregate. smartcloud is the worked example.

Refs: SMC-109

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Anyone reading this repository as an example had no route to a guide for
building the same kind of hub for their own organisation. The README's
start table and getting-started now link to the new smartcloud guides (an
organisation's own sync hub, recommended setups, building the settings
file), and name the files here that serve as the full-size example.

Refs: SMC-147

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: claude-code:claude-opus-5-5
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Copilot AI lite review requested due to automatic review settings September 27, 2026 19:24
@linear-code
linear-code Bot marked this pull request as ready for review September 27, 2026 19:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@linear-code

linear-code Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

smartcloud found 0 error(s), 2 warning(s).

Level Rule Where Finding
warning AI-21 "Accountable human:" must be the pull request author, @TGTGamer.
warning AI-21 "Human review:" is empty. State what you personally reviewed and ran before marking this ready.

This comment updates itself when you push a fix.

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

Splits contribution intake by adding dedicated Documentation and Performance issue templates and a required Environment field on bug reports, with the performance form demanding version, reproducible workload, and multi-run measurements before a report is actionable. Extends the CodeQL workflow to detect languages from the files a PR or merge-queue entry changes—by extension, skipping vendored and generated paths—so a newly introduced language is scanned before merge, falling back to the repository's default-branch languages when the compare API fails rather than stopping the scan. Tells SmartCloud to ignore CodeRabbit and Cursor status checks so their advisory runs never gate the aggregate and can't deadlock the approval agent.

Worth a look

  • Full app token can be minted on non-default branch pushes — .github/workflows/smartcloud.yml:100 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • Changed-file language detection misses files beyond compare API cap — .github/workflows/codeql.yml:55 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 197 functions depend on the 197 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 197 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 197 function(s) in the blast radius were not formally verified this run

Risky patterns (advisory)

  • medium no-stderr-to-stdout in .github/workflows/graphify.yml:61: stderr redirected to stdout: if out=$(sh tools/graphify/graphify check 2>&1); then

@TGTGamer
TGTGamer added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 86d060c Sep 28, 2026
32 of 33 checks passed
@TGTGamer
TGTGamer deleted the claude/batch-2026-09-27-house branch September 28, 2026 14:56
TGTGamer added a commit that referenced this pull request Sep 28, 2026
Main gained the issue forms and token split (#32), the disclosure
wording (#31) and a quoted 'none' option in the rendered bug report
form. The rewritten AGENTS.md and house-standards ai-docs keep the
one-trailer AI-02 wording of this batch, with the pull request
disclosure bullet from #31 folded in, and the documentation and
performance forms take the unassisted level like the other two, which
removes the reserved word instead of quoting it.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants