Skip to content

chore: repo hygiene sweep 2026-09-26 - #153

Merged
kyle-sexton merged 17 commits into
mainfrom
chore/repo-sweep-hygiene-20260926
Sep 29, 2026
Merged

kyle-sexton merged 17 commits into
mainfrom
chore/repo-sweep-hygiene-20260926

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

No related issue: repo hygiene sweep

Summary

Runs every entry of the hygiene playbook against this repository. An entry whose results show it does not apply here is ticked no findings and skipped.

  • dead-code: code-tidying:audit-dead-code@0.23.2, no findings
  • batch-simplify: code-tidying:batch-simplify@0.23.2, committed 5ef303f
  • residue-dissolve: code-tidying:audit-comment-residue@0.23.2, code-tidying:dissolve-comments@0.23.2, committed f1af78e
  • testing-audit: testing:audit@0.9.2, no findings
  • scan-todos: work-items:scan-todos@0.40.26, no findings
  • tidy: code-tidying:tidy@0.23.2, committed 5fc82af
  • derivability: docs-hygiene:audit-derivability@0.23.1, no findings
  • provenance: provenance:audit@0.5.15, no findings
  • codebase-health: codebase-health:audit@0.10.0, committed 56809ef
  • overengineering: overengineering:audit@0.4.13, overengineering:realign@0.4.13, committed 8d73b6d
  • native-overlap: claude-ops:audit-native-overlap@0.62.3, no findings
  • claude-config: claude-config:audit@0.48.2, committed 579617a
  • prompt-audit: claude-api@builtin, no findings
  • audit-instructions: claude-config:audit-instructions@0.48.2, committed 4e27d19
  • claude-memory: claude-memory:audit@0.13.3, committed 10e1a51
  • prompting-postures: claude-config:audit-prompting-postures@0.48.2, no findings
  • mcp-tools: mcp-tools:audit@0.4.1, no findings
  • audit-noise: docs-hygiene:audit-noise@0.23.1, committed 25f41ec
  • extract-ssot: docs-hygiene:extract-ssot@0.23.1, no findings
  • instruction-placement: instruction-placement:audit@0.15.5, instruction-placement:check@0.15.5, no findings
  • progressive-disclosure: docs-hygiene:audit-progressive-disclosure@0.23.1, no findings
  • encapsulation: docs-hygiene:audit-encapsulation@0.23.1, no findings
  • file-names: docs-hygiene:audit-file-names@0.23.1, docs-hygiene:realign-file-names@0.23.1, no findings
  • coupling: coupling:reduce@0.2.0, committed 7c794ea
  • be-concise: writing:be-concise@0.1.1, committed 5ebec0e
  • compress: docs-hygiene:compress@0.23.1, no findings
  • ai-slop: ai-slop:audit@0.10.0, no findings
  • lint: toolchain:lint@0.13.17, committed df02ccd
  • skill-quality: skill-quality:check@0.24.3, no findings
  • evals-validate: evals:validate not run (repo has no skills), no findings
  • verify: verification:confirm@0.6.9, committed a0b83b9

Fix

Runs the hygiene playbook one step per commit. Each step commit carries a Scope decisions: section and Playbook-Step: trailers naming the skill versions that ran. Synced root dotfiles owned by standards are excluded from every edit.

Verification

The last step runs verification:confirm. Each step's findings were reviewed before its fix.

Related

Playbook: /playbooks:repo-sweep, catalog hygiene. First sweep in the org rollout; later repos follow alphabetically, dotfiles last.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EYihoan7ULtdu32i34NaTq

kyle-sexton and others added 2 commits September 26, 2026 11:51
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EYihoan7ULtdu32i34NaTq
Repo-wide batch-simplify sweep (code and docs tiers). Each group was
checked by a separate verifier that tried to find a behavior change.

- .cursor/install.sh: one install_release helper for the six tarball
  installers and one ensure check for pinned versions. typos 1.50.1 and
  editorconfig-checker 3.11.2 now match the ci-workflows v0.29.1
  defaults (SHA256s confirmed against the downloaded assets).
- .cursor/check.sh: one run_lane runner. lane_eol now fails when git
  diff, mktemp, rev-parse or cp fails instead of reporting a clean
  index, and the script exits 1 outside a git checkout instead of
  passing lanes with nothing to check.
- .github/workflows/ci.yml: every ci-workflows ref moved from v0.27.1
  to v0.29.1; only comments changed in the actions this repo calls.
- .github/scripts/pr-section-drift.mjs: tidied; exit codes, output and
  exports unchanged. Two duplicate tests merged (25 tests).
- .gitignore: dropped a line the .claude/*.local.* glob already covered.
- SECURITY.md, PULL_REQUEST_TEMPLATE.md: current GitHub docs URLs and
  the renamed "Security and quality" tab.
- Em dashes removed from every file this repo owns.

Scope decisions:
- Which groups to run: code groups and the docs tier, all on Opus.
- Tool versions: match the latest ci-workflows release (v0.29.1);
  versions past its defaults belong in ci-workflows.
- Pre-existing lane_eol false pass: fix in this step.
- ai-slop.json list-idiom history sentence: remove.
- export PATH in check.sh: remove (no effect when PATH is exported).
- Em dashes: remove from every repo-owned file; synced files change
  upstream in standards.
- pr-body-contract.md sync status missing from README: left for a later
  docs step.

Playbook: hygiene
Playbook-Step: code-tidying:batch-simplify@0.23.2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EYihoan7ULtdu32i34NaTq
kyle-sexton and others added 2 commits September 26, 2026 13:37
Removes out-of-context residue from comments in ci.yml: two bare
"(issue #58)" back-references, the "exactly as before" and "the value
this repo has always used" history asides, and "no longer queues"
reworded to present tense. Comment-only, certified COMMENT-ONLY by the
dissolve-comments change-shape proof.

Scope decisions:
- Fix the residue in ci.yml (lines 23, 46-47, 50, 83, 315)?: yes, via
  dissolve-comments on ci.yml only (CI workflow HARD exclusion lifted by
  explicit user approval)
- Keep the (ADR-0008) reference?: yes, a durable decision record, not a
  ticket
- Residue in .claude/cloud-bootstrap.sh and managed-files-guard.yml?:
  skipped, both are synced from standards; fix upstream

Playbook: hygiene
Playbook-Step: code-tidying:audit-comment-residue@0.23.2
Playbook-Step: code-tidying:dissolve-comments@0.23.2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EYihoan7ULtdu32i34NaTq
Runs the tidy lanes over the shell tooling, the pr-section-drift
script, and the tracked markdown. Every change reorders or restructures
without changing behavior or meaning:

- pr-section-drift.mjs: name the retry count FETCH_ATTEMPTS, move
  CONTRACT_FOOTER up with the module constants, and drop export from
  contentsUrl and runLiveCheck, which nothing imports.
- pr-section-drift.test.mjs: match the source-of-truth text with
  includes() instead of a hand-escaped RegExp.
- .cursor/check.sh: drop a history sentence; .cursor/install.sh: point
  the header at the Pins block instead of repeating the pin.
- SUPPORT.md: put the override paragraph under the title, as the other
  policy files do.
- PULL_REQUEST_TEMPLATE.md: move the advisory-linkage sentences into
  the linkage paragraph.
- README.md: state the pr-contract step before the pr-section-drift
  lane that refers to it; make the Dependabot pin-comment rule its own
  bullet.
- CONTRIBUTING.md: split step 4's title and ci-status rules into a
  sub-list.

Verified: node --test (25/25), live pr-section-drift run, shellcheck,
markdownlint-cli2, and .cursor/check.sh (editorconfig lane skipped
locally for a missing ec binary; npx editorconfig-checker clean).

Scope decisions:
- Which lanes?: all of them (shell-tooling, docs-prose, and an ad hoc
  lane for .github/scripts/*.mjs), one dry-run subagent per lane
- Which findings to apply?: the 11 recommended; skipped the ${SHA}
  rewrite at test line 201 (the only hardcoded-string check), the shfmt
  case-arm outdent (no shfmt CI lane), deleting README's closing
  org-wide reminder (may be a deliberate warning), and the CLAUDE.md
  github-iac shortening (a later instruction step covers CLAUDE.md)
- Ship the org-wide SUPPORT.md, PR template, and CONTRIBUTING.md
  reorders in this sweep?: yes, reorder only
- .claude/cloud-bootstrap.sh, .claude/rules/pr-body-contract.md,
  CODE_OF_CONDUCT.md?: excluded, synced from standards or verbatim
  Contributor Covenant

Playbook: hygiene
Playbook-Step: code-tidying:tidy@0.23.2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EYihoan7ULtdu32i34NaTq
A codebase-health audit of the documentation and configuration
dimensions checked every factual claim against the repo and the pinned
ci-workflows actions. Five claims had drifted:

- README.md: Dependabot keeps actions/checkout current, not the
  ci-workflows composites, which dependabot.yml ignores and which move
  by hand; the pin-comment rule now covers every action pin.
- README.md: the inventory claims to cover every tracked file but
  omitted .claude/rules/pr-body-contract.md and .claude/ai-slop.json.
- ci.yml shellcheck comment: .shellcheckrc carries enable= directives,
  not disable= ones.
- ci.yml lychee comment: drop the "7 of 9 Markdown files" count, which
  went stale as files were added.
- CLAUDE.md: the lane-wiring rule sits in ci.yml's header comment above
  jobs:, not beside the ci-status job.

Verified: markdownlint-cli2 on README.md and CLAUDE.md, actionlint,
and .cursor/check.sh lanes (markdown and editorconfig red only on
untracked .work/ scratch and a missing local ec binary).

Scope decisions:
- Which findings to fix?: all five confirmed findings
- Dependabot wording?: Dependabot keeps actions/checkout current;
  ci-workflows pins move by hand; pin-comment bullet retargeted to
  every action pin
- Stale Markdown count in the lychee comment?: drop the counts rather
  than update them
- Needs-review items (PR template reason requirement,
  recurring-schedule.json schema, synced cloud-bootstrap header) and
  codebase-health:setup persist?: skipped

Playbook: hygiene
Playbook-Step: codebase-health:audit@0.10.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
kyle-sexton and others added 2 commits September 27, 2026 13:51
An overengineering audit of the enforcement surface found two
mechanisms whose carry cost outruns what they protect, plus two
drifted claims:

- ci.yml: pr-section-drift leaves the ci-status needs: roster. It is a
  network-dependent lane that text-parses another repo's run.sh, yet
  the PR-body contract it guards is advisory, and it has had 0 failures
  since landing. It still runs and reports; re-adding it to needs:
  restores the gate. Header and job comments say so.
- .github/recurring-schedule.json: deleted. It has held an empty items
  list since it was added; README no longer mentions it.
- ci.yml shellcheck comment: the bootstrap is not the lane's only
  input; the .cursor/ scripts are discovered too.
- README.md: .claude/settings.json enables no plugins (enabledPlugins
  is empty on purpose), so drop that claim.

Verified: actionlint on ci.yml, markdownlint-cli2 on README.md.

Scope decisions:
- pr-section-drift?: make advisory (drop from needs:), not delete
- recurring-schedule.json?: delete it and its README mention
- ci.yml cleanups?: fix the wrong shellcheck comment only; skip the
  YAML-anchor dedupe of the 10 repeated job if: predicates
- .cursor/check.sh?: keep
- README enabledPlugins claim?: fix
- .shellcheckrc sync, GitGuardian overlap, org apps, rulesets, plugin
  hooks, and other out-of-repo findings?: left in the findings artifact,
  no action this step

Playbook: hygiene
Playbook-Step: overengineering:audit@0.4.13
Playbook-Step: overengineering:realign@0.4.13
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
Adds the audit baseline's seven secret-file Read denies to
.claude/settings.json so cloud sessions, which do not load the
operator's user-scope settings, carry them too. A Read deny covers the
built-in file tools and the Bash file commands Claude Code recognizes,
not a subprocess that opens the path itself.

Scope decisions:
- Secret-file Read denies: add all seven to this repo's project
  settings.
- git push ask rule: not added. An ask rule prompts even in auto mode
  and is denied in dontAsk mode, which would stall autonomous lanes
  that push and open PRs. No audit-pass suppression record written;
  the warning recurs on later audits.
- Force-push and reset --hard denies: not added here; user-scope
  denies and the guardrails hook already block them.
- Scope: this repo only; no standards issue for an org-wide rollout.
- Dropped as out of scope (user or machine scope):
  skipWorkflowUsageWarning, allow-completeness rows, plugin cache
  divergence, new-upstream plugin rows (enabledPlugins stays {} by
  design).

Playbook: hygiene
Playbook-Step: claude-config:audit@0.48.2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
kyle-sexton and others added 2 commits September 27, 2026 15:09
"That job" had no antecedent, and pr-section-drift is deliberately
left out of ci-status's needs:, so the rule applies to gating lanes.

Scope decisions:
- Apply the CLAUDE.md:30 wording fix (outside the catalog, a
  repo-scope rewrite): yes.
- Leave the duplicated "ci-status is the single required check" line
  to the claude-memory step: yes.

Playbook: hygiene
Playbook-Step: claude-config:audit-instructions@0.48.2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
… repeats

CLAUDE.md stated no way to verify a change. It now names
.cursor/check.sh, the local mirror of every CI lane. The "Opening a PR
here" section restated two facts that .claude/rules/pr-body-contract.md
already carries in every session; it keeps only the pointers.

Scope decisions:
- Add the missing check command (C9), an addition outside the step's delete-and-rewrite scope: yes, one line naming bash .cursor/check.sh.
- Cut the two CLAUDE.md sentences that restate .claude/rules/pr-body-contract.md (R1): yes, keep the pointers.

Playbook: hygiene
Playbook-Step: claude-memory:audit@0.13.3
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
kyle-sexton added a commit to melodic-software/ci-workflows that referenced this pull request Sep 27, 2026
Refs #628

## Summary

Bumps two of the four tool defaults named in #628. The other two are
deferred and need a decision.

| Tool | From | To | Status |
|---|---|---|---|
| typos | 1.50.1 | 1.50.3 | bumped |
| check-jsonschema | 0.38.0 | 0.38.2 | bumped |
| markdownlint-cli2 | 0.23.2 | 0.23.3 | deferred:
`.github/actions/markdown/action.yml` says to follow
`melodic-software/standards`' pin and never go past it.
`standards/package.json` still pins 0.23.2. |
| editorconfig-checker | 3.11.2 | 4.0.2 | deferred: 4.x breaks the
install step and changes what consumers see (details below) |

## Fix

- `.github/actions/typos/action.yml`: `version` is now 1.50.3. `sha256`
is now
`aca6b5d546307092b8d0a8e0a89dd80f9da51f2f7617c5e45c5607c1684ffbf2`,
computed with `sha256sum` on the downloaded
`typos-v1.50.3-x86_64-unknown-linux-musl.tar.gz`. `./typos` is still the
archive member.
- `.github/actions/check-jsonschema/action.yml`: `version` is now
0.38.2.

editorconfig-checker 4.x, from the v4.0.0 release notes:
- "rename ec to editorconfig-checker (#371)". The v4.0.2 asset is now
`editorconfig-checker-linux-amd64.tar.gz`, and the old
`ec-linux-amd64.tar.gz` URL returns 404. The archive now holds the
binary as `editorconfig-checker` instead of `bin/ec-linux-amd64`. The
action's `URL`, `ARCHIVE_MEMBER`, `BIN`, and `ec` call all need to
change, so passing a 4.x `version` to this action fails today.
- "auto-detect `github-actions` output format in CI (#606)". An empty
`format` input changes output for consumers.
- "stop accepting latin1 files as utf-8 (#598)". Consumers may see new
failures.
- "`SpacesAftertabs` configuration key has been removed" and "`.ecrc` is
no longer discovered". Consumer configs that use either one break.

v4.0.1 and v4.0.2 contain bug fixes only.

## Verification

- typos 1.50.3 against this repo with `--config _typos.toml`: exit 0.
- check-jsonschema 0.38.2 against the same inputs ci.yml passes,
`vendor.github-workflows` on `.github/workflows/*.yml` and
`vendor.github-actions` on `.github/actions/*/action.yml`: both `ok --
validation done`.
- actionlint on `.github/workflows/*.yml`: clean. This PR changes no
shell files.

## Related

- #628
- melodic-software/.github#153, the hygiene sweep that found the drift.
- The markdownlint-cli2 bump starts in `melodic-software/standards`
(`package.json`, lockfile, schema pin). This repo then updates the
action default and the `$schema` URL in `.markdownlint-cli2.jsonc`
together.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_011brT5H7FqoT9C8JbGFv76L

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit to melodic-software/standards that referenced this pull request Sep 28, 2026
Closes #627

## Summary

The fleet's ai-slop rule bans em dashes (U+2014).
`melodic-software/.github` receives synced copies of these files and
cannot edit them (managed-files-guard reverts hand edits on the next
sync), so the fix has to land at the source here.

## Fix

Replaced every em dash with a colon, semicolon, comma, parentheses, or a
split sentence (never `--` or an en dash) in each source file mapped
from the issue's downstream table via `distribution/sync-manifest.yml`:

| Source file | Em dashes removed |
|---|---|
| `_typos.toml` | 20 |
| `components/cloud-bootstrap/cloud-bootstrap.sh` | 17 |
| `.shellcheckrc` | 12 |
| `lychee.toml` | 11 |
| `.editorconfig` | 7 |
| `.gitattributes` | 5 |
| `components/managed-files-guard/managed-files-guard.yml` | 3 |
| `.markdownlint-cli2.jsonc` | 3 |
| `.editorconfig-checker.json` | 2 (issue listed 1; the source carried
2) |
| `.gitleaks.toml` | 1 |

Also re-materialized `.claude/cloud-bootstrap.sh` (this repo's own
synced copy of `components/cloud-bootstrap/cloud-bootstrap.sh`) to keep
it byte-identical, as required by `cloud-bootstrap.test.sh`.

## Verification

- `grep` for U+2014 confirms 0 occurrences remain in all 11 touched
files.
- `npm ci` (root) and `npm ci --prefix distribution` / `npm ci --prefix
components/runner-policy` (nested test dependencies) succeeded.
- `harness/shell/run-tests.sh` full suite: 35 files pass, aside from two
pre-existing failures unrelated to this change (`components/go-analysis`
pinned golangci-lint version drift on this host;
`distribution/check-claude-settings-targets.test.sh` fails only when
`jq` is resolved via `command -p -v jq`, which misses this host's
mise-managed `jq`).
- `node --test components/runner-policy/runner-policy.test.mjs`: 260/260
pass, including the managed-files-guard caller checks.
- Lefthook pre-commit hooks (editorconfig, typos, shellcheck, biome,
gitleaks) ran clean on commit.

## Related

Closes #627. Found during the hygiene sweep in
melodic-software/.github#153.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01LCEBhuXxZAT8K619tC6T5f

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ci.yml keeps pr-section-drift out of the ci-status needs: list, so a
drift report never fails CI. check.sh still counted it toward its
aggregate, so a local run failed where CI passed. The lane now runs and
prints its result without affecting the exit status.

The coupling pass found three couplings for a human to decide on:
check.sh copying the ci.yml lane list, install.sh restating the
ci-workflows tool pins, and the contract-only predicate repeated in
ci.yml. They stay in the local ledger and were not filed.

Scope decisions:
- Make pr-section-drift advisory in check.sh: yes
- Route the three routed couplings: record in the ledger only, no tracker items

Playbook: hygiene
Playbook-Step: coupling:reduce@0.2.0
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
kyle-sexton and others added 4 commits September 28, 2026 15:23
The "a repository may override this default" sentence in
CONTRIBUTING, GOVERNANCE, SECURITY, and SUPPORT is now one clause,
each keeping its qualifier. CONTRIBUTING drops its thank-you opener
and tightens the branch-naming step and the PR-title bullet. README
merges the fallback and github-iac paragraphs and shortens the
.shellcheckrc exception. 1169 words become 1070; no decision, link,
or warning is dropped.

Scope decisions:
- Apply the proposed cuts to the override sentences, CONTRIBUTING, and README?: yes
- Keep or drop the CONTRIBUTING "Thanks" opener?: drop
- Reshape CODE_OF_CONDUCT.md, PULL_REQUEST_TEMPLATE.md, profile/README.md?: no; standard adopted text, gate-bound template, already concise

Playbook: hygiene
Playbook-Step: writing:be-concise@0.1.1
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
The concision pass reworded the override sentence as "overrides this
default when its process differs", which reads as a condition on the
file's content. GitHub applies a repository's own file whenever it
exists, as the original "that file takes precedence" said.

Scope decisions:
- Fix the conditional override wording found in review?: yes, as a follow-up commit
- File issues against the skill or catalog?: no

Playbook: hygiene
Playbook-Step: writing:be-concise@0.1.1
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
The markdown lane passed "**/*.md" to markdownlint-cli2, which also
matched gitignored scratch files under .work/ and failed locally on 870
issues that CI's clean checkout never sees. The lane now lints the
output of git ls-files '*.md', matching what CI checks.

Scope decisions:
- Markdown lane scans gitignored .work/: fix in check.sh; the synced .markdownlint-cli2.jsonc is left alone
- ec missing locally (mise installs it as editorconfig-checker): machine setup gap, check.sh unchanged

Playbook: hygiene
Playbook-Step: toolchain:lint@0.13.17
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
The links lane globbed "**/*.md", so lychee also scanned gitignored
scratch files under .work/. It now reads git ls-files '*.md', like the
markdown lane, which also covers .claude/ and .github/ without naming
them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
CLAUDE.md and README.md said check.sh fails on any lane and counts
pr-section-drift toward ci-status. Since pr-section-drift became
advisory, check.sh exits non-zero only when a gating lane fails; both
files now say so. README.md also now notes that .claude/settings.json
denies Read on secret files.

Scope decisions:
- Fix all three verifier doc findings (CLAUDE.md:36, README.md:54, README.md:73)?: yes, all three
- Make check.sh fall back to editorconfig-checker when ec is absent?: no, install.sh installs it as ec; out of sweep scope

Playbook: hygiene
Playbook-Step: verification:confirm@0.6.9
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S5b57FoPJkJMe1BDwhExiG
…ene-20260926

# Conflicts:
#	.cursor/install.sh
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 00:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T00:44:58.036585Z 486a966 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 486a96690c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread SECURITY.md
@kyle-sexton
kyle-sexton merged commit 54e5182 into main Sep 29, 2026
14 checks passed
@kyle-sexton
kyle-sexton deleted the chore/repo-sweep-hygiene-20260926 branch September 29, 2026 00:55
kyle-sexton added a commit to melodic-software/claude-code-plugins that referenced this pull request Sep 29, 2026
…ding as stamp years (#5256)

Refs: #4580
Refs: #4577
Refs: #3465

## Summary

Follow-up to #4858 for the attribution audit findings on #4577 and
#4580. #4858 replaced the compound `--show-config` pre-compute probes
with plain pipes, which dropped the `detector unavailable` guard added
in 0.1.1. Both issues stay closed; the PR carries no closing keyword
because one acceptance point (the probes rendering in a
worktree-isolated session) cannot be checked from this repo.

## Fix

- `list-corpus.sh` and `check-stamps.sh`: when `lib.sh` is not readable,
`--show-config` prints `detector unavailable` on stdout and exits 0; any
other invocation prints the reason on stderr and exits 2.
- `audit/SKILL.md`: one sentence under the pre-computed lines says an
empty config line or `detector unavailable` means the detector did not
run and is reported as such. The plain-pipe probe shape is unchanged. A
script file that is missing entirely cannot print anything, so that case
is covered by the SKILL.md sentence, not by the script.
- `audit/reference/rubric.md`: carve-out 4 Basis is now `judgment` (with
its recheck trigger) instead of pointing back at #4577: no checkable
source shows the sibling-org carve-out behavior, and
`melodic-software/.github#153` does not, so it is not cited. The earlier
"five files" count is dropped. No golden case was added: a new case
changes the judged panel and needs its own measurement.
- `check-stamps.sh` and `extract-breadcrumbs.sh` (#3465 slice A,
requested by the decisions-docs group): four digits that are not a date
no longer count as a stamp year. A year must stand alone (not inside
`SC2034` or `20260901T100000Z`) and be the first number after the
keyword (`verified real (Issue 9, 2025`), and `read` inside an
identifier (`cache_read_input_tokens`) is not the verb. A `2026-07`
stamp now declines as `year and month only, no day` instead of `bare
year, no month or day` (`billing.md:140`). Each of the four reported
sites reproduced on origin/main before the change. Slice D (resume
semantics) is not touched; it waits for the owner's approval of the
split on #3465.
- `attribution` 0.6.1 to 0.6.2 with a CHANGELOG entry that also covers
the stamp-year change.

## Verification

- `bash
plugins/attribution/skills/audit/scripts/{list-corpus,check-stamps,emit-findings,extract-breadcrumbs,fingerprint,score-golden}.test.sh`
and `node .../fingerprint.test.mjs`: all pass (67, 87, 389, 67, 40, 41,
40 assertions, 0 failed).
- `shellcheck` on the two edited scripts: clean.
- `bash scripts/check-changelog-parity.sh --check --check-order`: pass.
- `bash scripts/validate-plugins.sh`: all manifests and the catalog
validate.
- `bash scripts/check-changed-skills.sh origin/main`: PASS, 0 errors.
`bash scripts/check-skill-portability.sh origin/main`: no coupling
tokens. `bash scripts/check-detector-eval-coverage.sh`: all covered.
- `markdownlint-cli2` on the edited markdown: 0 issues.
- Stamp-year change: `check-stamps` (87) and `extract-breadcrumbs` (67)
suites pass under gawk and mawk, and the new year-shapes cases fail on
the old script (6 failures). Over 1,623 files (run date 2026-09-29)
candidates go 1,195 to 1,172 and declined 51 to 28, with `parsed`
(1,144) and `findings` (268) unchanged, so no parsed stamp was
reclassified. `list-corpus`, `emit-findings`, `score-golden` and
`fingerprint` suites still pass; shellcheck clean.
- Not verified here: that both pre-compute lines render in a `claude
--worktree` session running `/attribution:audit`. Reopen #4580 only if
that check fails.

## Related

- Audit report: `.work/audit/REPORT.md` (local, not tracked), findings
for #4577 (regression, rubric Basis) and row 3c for #4577/#4858.
- #4578 and #4579 (delivered by #4858) were checked on main and need no
change.
- #3465 (open, sweep sub-topic): this PR is slice A only. Remaining
bare-year declines that are real publication or product years
(`Cyberpunk 2077`, `(2011)` after a book title) are not changed: telling
them from a stamp needs meaning, not a pattern.
- Cross-group request to `conventions`: finding on #3412 (14 inline
`make_sink()` suites lack the one-line pointer that
`docs/conventions/shell-test-helpers/README.md:106-107` requires). It
belongs in the #3412 owner decision packet as a consequence of Option 2;
not changed here.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit to melodic-software/claude-code-plugins that referenced this pull request Sep 29, 2026
Closes #5201

## Summary

The `lint` entry in the `repo-sweep` hygiene catalog passed only `--fix`
to `toolchain:lint`. With no ecosystem filter, that skill lints the
changed files, which on a clean sweep tree are only the files earlier
sweep steps touched. The step never covered the rest of the repository.

## Fix

`plugins/playbooks/skills/repo-sweep/catalogs/hygiene.md`: the `###
lint` entry now has `- args: all --fix` and a Notes block directing a
following `/toolchain:lint all` check-mode run (`--fix` runs only format
commands). The `claude-config` entry is unchanged. `playbooks` is bumped
to 0.14.1 with a CHANGELOG entry.

## Verification

- `plugins/playbooks/skills/repo-sweep/scripts/catalog.test.sh`,
`render.test.sh`, `state.test.sh`: all passed.
- `scripts/check-changelog-parity.sh --check --check-order`: passed.
- `scripts/validate-plugins.sh`: all manifests and the catalog
validated.
- Whole-repo coverage of `/toolchain:lint all` on a clean tree with a
non-empty branch diff (the acceptance criterion): every ecosystem
widens, so no toolchain issue was needed.
- bash: shellcheck and shfmt ran over 1104 tracked `*.sh` files
(diff-only would be 0).
- markdown: markdownlint-cli2 linted 1767 files (diff-only would be 1).
- python, typescript, go, powershell: the check commands use `.`,
`./...`, or `-Path . -Recurse`.
- yaml: actionlint discovers all workflows. typos, gitleaks,
editorconfig and lychee take no `<files>` list.
- Basis: `toolchain:lint` SKILL.md step 1 computes no changed-file list
under `all`.

## Related

- Issue #5201; observed in melodic-software/.github#153.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
kyle-sexton added a commit to melodic-software/claude-code-plugins that referenced this pull request Sep 29, 2026
Closes #5206

## Summary

`/playbooks:repo-sweep next` pushed a commit per step without noticing
that the sweep PR had become `mergeable: CONFLICTING`. GitHub runs no
`pull_request` workflows on a conflicting PR, so those step commits got
no CI.

## Fix

- `state.sh` requests `mergeable` in its existing `gh pr list` call and
prints `mergeable CONFLICTING` for an open PR that conflicts.
`MERGEABLE` and `UNKNOWN` print nothing. No new exit code.
- `reference/next.md` section 1 stops before any step when that line is
present and asks the user to merge the base branch into the sweep
branch, push, and rerun `next`. `UNKNOWN` never stops.
- `SKILL.md` lists the new line; `evals/evals.json` has a case for the
stop.
- `state.test.sh` covers CONFLICTING (line printed, normal exit code),
MERGEABLE and UNKNOWN (no line), and a merged PR (exit 11, no line).
- playbooks 0.14.1 -> 0.14.2 with a CHANGELOG entry.

## Verification

- `bash plugins/playbooks/skills/repo-sweep/scripts/state.test.sh`: all
passed
- `scripts/check-changelog-parity.sh --check --check-order`: passed
- `scripts/validate-plugins.sh`: all manifests and the catalog validated
- `evals.json` parses as JSON

## Related

Found in melodic-software/.github#153, where the last six step commits
got no CI run.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant