All notable changes to the org-wide governance in this repository are documented here. Consuming repos pin a released version of this governance (recorded in their .governance-version file) and adopt new versions deliberately.
The format is based on Keep a Changelog, and versions follow Semantic Versioning: a major bump means a rule change that can newly block merges in consuming repos; minor adds rules or tooling that are backwards-compatible; patch is clarification only.
apply_rulesets.shnow refuses to apply the required-checks ruleset to a repo untilcla.ymlexists on that repo's default branch, instead of creating a merge deadlock (the same bootstrapping bug already fixed once for this repo itself in 1.0.1/1.0.2, reintroduced when retrofitting a new repo —claude-skills— without following the documented sequencing)docs/runbook.md: repo onboarding steps for existing repos now state the merge-then-ruleset ordering explicitly
reusable-dependabot-hygiene.yml— fills Dependabot PR bodies with the required hygiene sections, declaring the governing specs actually matched by the changed files, so dependency PRs stop perma-blocking on body-section gates while repo CI still validates the bump. Repos opt in by adding one job to theircla.ymlcaller (already onpull_request_target).docs/runbook.md— operations runbook: release process, repo onboarding, failure playbook (rerun snapshot-pinning, CLA recheck, secret visibility, empty-commit retrigger), and environment constraints.
- Baseline gate: the spec-alignment wiring requirement now applies only once a repo has approved specs — the gate script refuses an empty registry, so templates and brand-new repos could never satisfy it
- Baseline gate: the doc-duplication warning accepts a substantial AGENTS.md that declares CLAUDE.md canonical (coordination-only content)
- Token-discipline rules in
docs/ai-agent-hardening.md: single canonical agent doc (CLAUDE.md canonical, AGENTS.md = pointer + tool-coordination only), no version numbers in prose (point at.governance-version), no state snapshots in docs (live queries instead),.claudeignorerequired, lazy doc-reading map, PR-body section superset, boundedghqueries, org-wide lean-implementation ladder and claim-before-you-code rule - Baseline gate emits warnings (non-blocking) for: missing
.claudeignore, hardcoded governance versions that drift from.governance-version, substantial CLAUDE.md+AGENTS.md duplication, CLAUDE.md over 8KB. These become blocking checks in the next major release.
- CLA gate degrades gracefully while
CLA_ASSISTANT_PATis unset: allowlisted authors (owner and*[bot]) pass with a warning instead of everyone failing at action startup; non-allowlisted authors still fail closed. Withcla / clanow a required check org-wide, the previous behavior blocked every PR including the owner's and Dependabot's. - CLA allowlist covers the owner's coding-agent identities (
claude,cursoragent, and the owner's unlinked local git identity) so agent-authored PRs aren't asked to sign the owner's own CLA.
reusable-governance.ymlno longer executes the vendored spec-alignment script directly (it needs PR-context inputs and runs in each repo's own CI); it now verifies the script is wired into a workflow instead- Org scripts made portable to the bash 3.2 shipped with macOS (no
mapfile) rollout_governance.shnow declares governing specs in the PR body and links a tracking issue, satisfying consuming repos' spec-alignment and traceability gates
- Caller workflows reference the reusable workflows at this repo's default branch instead of a moving
v1tag; release tags (vX.Y.Z) remain the pin points for adopted governance content - CODEOWNERS is no longer a required governance file (solo-maintainer, agent-driven mode): removed from the baseline gate, the audit, and the rollout. Human-approval requirements stay at zero; enforcement is automated checks only. Reintroduce CODEOWNERS when a second maintainer joins.
governance/rulesets/required-checks-ruleset.json— requiresbaseline / governance-baselineandcla / claon default branches, so auto-merge waits for the gates; apply only after every repo carries the caller workflows (see docs/owner-setup.md)apply_rulesets.shapplies every ruleset JSON ingovernance/rulesets/(or a single one via-f)
First versioned governance release.
- Constitution, quality standards, antipatterns, compatibility policy, exception process, AI-agent hardening rules
- Contributor License Agreement (
CLA.md) with automated enforcement via the reusable CLA workflow - Governance and ownership model (
GOVERNANCE.md) - Trademark policy (
TRADEMARK.md) and Apache-2.0NOTICE - Org-wide community health defaults:
CODE_OF_CONDUCT.md(Contributor Covenant 2.1),SECURITY.md,SUPPORT.md, issue/PR templates - Reusable workflows:
reusable-cla.yml,reusable-governance.yml - Scheduled org-wide compliance audit (
org-audit.yml+scripts/org/audit_compliance.sh) - Canonical baseline branch ruleset (
governance/rulesets/baseline-branch-ruleset.json) andscripts/org/apply_rulesets.sh - Governance rollout script for consuming repos (
scripts/org/rollout_governance.sh) - Workflow templates for new repos (
workflow-templates/) - Canonical spec-alignment CI gate script (
scripts/ci/spec_alignment_check.sh)