From 50d6dfa53e0e5d750b7d89539352b005ef2d6686 Mon Sep 17 00:00:00 2001 From: Kyle Sexton <153232337+kyle-sexton@users.noreply.github.com> Date: Sat, 3 Oct 2026 02:05:19 -0400 Subject: [PATCH 1/2] docs: add Code Review Rules section for Codex review Give the Codex PR reviewer this repository's review rules through a pointer-only "## Code Review Rules" section in the root AGENTS.md, per the melodic-software/standards code-review-rules convention (standards#656). Each line names a rule CI does not enforce and links the file that owns it. Co-Authored-By: Claude Opus 5.5 --- AGENTS.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/AGENTS.md b/AGENTS.md index e69de29b..43637550 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -0,0 +1,18 @@ +## Code Review Rules + +Each line names a rule CI does not enforce; the linked file states it in full. + +- Org-wide criteria: [`REVIEW.md`](REVIEW.md), synced from `melodic-software/standards`. +- Claude lane security model (`pull_request` only, no PR-authored code run in a review lane, + least-privilege token, logs kept clean): [`claude-review.yml`](.github/workflows/claude-review.yml) + and [`claude-security-review.yml`](.github/workflows/claude-security-review.yml) `SECURITY MODEL` headers. +- Claude lane checks stay advisory, never required: + [rule](README.md#claude-lanes--shared-consumption-contract). +- Configurable, not forkable: repository-specific scope goes through typed inputs with standard + defaults: [contract](README.md#contract). +- Policy is authored in `melodic-software/standards`; `fixtures/` configs only exercise contracts: + [policy ownership](README.md#policy-ownership-and-action-inputs). +- Local-lane guard wrappers keep parity with the standards component, never fork its policy: + [local-lane guards](docs/topics/local-lane-guards.md). +- Lanes consolidate as composite actions; `ci-status` stays the single required check, with no + workflow-level `paths:` on a required workflow: [ADR](docs/topics/ci-fanout-consolidation/ADR.md#decisions-locked). From f62a7a715771236424f78436613ab5d59dd06457 Mon Sep 17 00:00:00 2001 From: Kyle Sexton <153232337+kyle-sexton@users.noreply.github.com> Date: Sat, 3 Oct 2026 02:07:05 -0400 Subject: [PATCH 2/2] docs: make Code Review Rules lines pointer-only Drop the security-model parenthetical, which named a rule the SECURITY MODEL headers do not state, and the paraphrased qualifiers on the other lines. Each per-repository line now uses the convention's slot form and ends at its link. Co-Authored-By: Claude Opus 5.5 --- AGENTS.md | 24 +++++++++++------------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 43637550..7de7d206 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -3,16 +3,14 @@ Each line names a rule CI does not enforce; the linked file states it in full. - Org-wide criteria: [`REVIEW.md`](REVIEW.md), synced from `melodic-software/standards`. -- Claude lane security model (`pull_request` only, no PR-authored code run in a review lane, - least-privilege token, logs kept clean): [`claude-review.yml`](.github/workflows/claude-review.yml) - and [`claude-security-review.yml`](.github/workflows/claude-security-review.yml) `SECURITY MODEL` headers. -- Claude lane checks stay advisory, never required: - [rule](README.md#claude-lanes--shared-consumption-contract). -- Configurable, not forkable: repository-specific scope goes through typed inputs with standard - defaults: [contract](README.md#contract). -- Policy is authored in `melodic-software/standards`; `fixtures/` configs only exercise contracts: - [policy ownership](README.md#policy-ownership-and-action-inputs). -- Local-lane guard wrappers keep parity with the standards component, never fork its policy: - [local-lane guards](docs/topics/local-lane-guards.md). -- Lanes consolidate as composite actions; `ci-status` stays the single required check, with no - workflow-level `paths:` on a required workflow: [ADR](docs/topics/ci-fanout-consolidation/ADR.md#decisions-locked). +- Claude lane security model (`SECURITY MODEL` headers): + [`claude-review.yml`](.github/workflows/claude-review.yml) and + [`claude-security-review.yml`](.github/workflows/claude-security-review.yml). +- Claude lane checks stay advisory: [rule](README.md#claude-lanes--shared-consumption-contract). +- Configurable, not forkable: [rule](README.md#contract). +- Policy is authored in standards; `fixtures/` configs only exercise contracts: + [rule](README.md#policy-ownership-and-action-inputs). +- Local-lane guard wrappers keep parity with the standards component: + [rule](docs/topics/local-lane-guards.md). +- Lanes consolidate as composite actions; `ci-status` stays the single required check: + [rule](docs/topics/ci-fanout-consolidation/ADR.md#decisions-locked).