diff --git a/README.md b/README.md index 0856636..19c8ace 100644 --- a/README.md +++ b/README.md @@ -32,7 +32,7 @@ The spec in this repo is implemented across several other repositories. None of | [`smartwatermelon/claude-config`](https://github.com/smartwatermelon/claude-config) | The actual Claude Code hooks: `pre-merge-review.sh`, `run-review.sh`, `merge-lock.sh`, `lib-review-issues.sh`. Symlinked into `~/.claude/` on each machine. | | [`smartwatermelon/claude-wrapper`](https://github.com/smartwatermelon/claude-wrapper) | Bash wrapper around the `claude` CLI, symlinked to `~/.local/bin/claude` so it shadows the real binary in `$PATH`. Resolves per-project 1Password secrets via `op inject`, injects `--remote-control` session names for interactive sessions, and validates binary ownership/permissions before `exec`. | | [`smartwatermelon/dotfiles`](https://github.com/smartwatermelon/dotfiles) | The global git hooks (`pre-commit`, `pre-push`, `commit-msg`, etc.) at `git/hooks/`, symlinked from `~/.config/git/hooks/`. Also hosts shared shell utilities like `lint-shell.sh`. | -| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The reusable GitHub Actions workflows (`claude-blocking-review.yml`, `claude-assistant.yml`) called by every owned repo's `.github/workflows/` caller. Plus `claude-review-audit.sh` for fleet-wide configuration auditing. | +| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The live reusable GitHub Actions workflows (`standards-check.yml`, `claude-assistant.yml`) called by owned repos' `.github/workflows/` callers. `claude-blocking-review.yml` remains only as a deprecated workflow. | | [`smartwatermelon/ralph-burndown`](https://github.com/smartwatermelon/ralph-burndown) | The tech-debt burndown tool that picks up non-blocking issues filed by the local Phase 2 review and works through them overnight. | The global pre-commit framework config lives at `~/.config/pre-commit/config.yaml` (sourced from the pre-commit setup, not currently in any repo by itself). @@ -41,7 +41,7 @@ The global pre-commit framework config lives at `~/.config/pre-commit/config.yam ## The system in one paragraph -Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs only the *focused summarizer review* (the reusable `claude-blocking-review.yml` workflow), tests, and deploys — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block. +Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs the deterministic `standards-check`, tests, and deploys; no Claude judgment reviewer runs in CI — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block. For the full architecture, see [`docs/WORKFLOW-DEEP-DIVE.md`](./docs/WORKFLOW-DEEP-DIVE.md). For the journey that produced it, see [`docs/local-first-code-quality-epic.md`](./docs/local-first-code-quality-epic.md). diff --git a/docs/token-rotation.md b/docs/token-rotation.md index aaf7847..6ef16d3 100644 --- a/docs/token-rotation.md +++ b/docs/token-rotation.md @@ -76,13 +76,18 @@ between. Paste when prompted. -3. Re-run one Claude workflow on a repo in that scope and read the log: the - `claude-code-action` step must authenticate, not skip. +3. Re-run one Claude workflow on a repo in that scope that still has a + `claude.yml` caller (for example `smartwatermelon/scripts`) and read the + log: the `claude-code-action` step must authenticate, not skip. Trigger + it with an `@claude` mention on an issue, or re-run the latest run: ```bash - gh run list -R smartwatermelon/dev-env --workflow claude-blocking-review.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/dev-env + gh run list -R smartwatermelon/scripts --workflow claude.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/scripts ``` + `dev-env` has no `claude.yml` and no longer holds the secret. It was + deleted on 2026-10-01, after the CI reviewer that used it was retired. + 4. Update the table row (minted date, expiry = minted + the lifetime `setup-token` printed, machine).