From 96340bab5066d134fe06cdbb1ce4adf415e9950e Mon Sep 17 00:00:00 2001 From: Claude Code Bot Date: Thu, 1 Oct 2026 20:25:51 -0700 Subject: [PATCH 1/2] docs: drop retired CI reviewer references Advances smartwatermelon/github-workflows#154. --- README.md | 4 ++-- docs/token-rotation.md | 12 +++++++++--- 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 0856636..19c8ace 100644 --- a/README.md +++ b/README.md @@ -32,7 +32,7 @@ The spec in this repo is implemented across several other repositories. None of | [`smartwatermelon/claude-config`](https://github.com/smartwatermelon/claude-config) | The actual Claude Code hooks: `pre-merge-review.sh`, `run-review.sh`, `merge-lock.sh`, `lib-review-issues.sh`. Symlinked into `~/.claude/` on each machine. | | [`smartwatermelon/claude-wrapper`](https://github.com/smartwatermelon/claude-wrapper) | Bash wrapper around the `claude` CLI, symlinked to `~/.local/bin/claude` so it shadows the real binary in `$PATH`. Resolves per-project 1Password secrets via `op inject`, injects `--remote-control` session names for interactive sessions, and validates binary ownership/permissions before `exec`. | | [`smartwatermelon/dotfiles`](https://github.com/smartwatermelon/dotfiles) | The global git hooks (`pre-commit`, `pre-push`, `commit-msg`, etc.) at `git/hooks/`, symlinked from `~/.config/git/hooks/`. Also hosts shared shell utilities like `lint-shell.sh`. | -| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The reusable GitHub Actions workflows (`claude-blocking-review.yml`, `claude-assistant.yml`) called by every owned repo's `.github/workflows/` caller. Plus `claude-review-audit.sh` for fleet-wide configuration auditing. | +| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The live reusable GitHub Actions workflows (`standards-check.yml`, `claude-assistant.yml`) called by owned repos' `.github/workflows/` callers. `claude-blocking-review.yml` remains only as a deprecated workflow. | | [`smartwatermelon/ralph-burndown`](https://github.com/smartwatermelon/ralph-burndown) | The tech-debt burndown tool that picks up non-blocking issues filed by the local Phase 2 review and works through them overnight. | The global pre-commit framework config lives at `~/.config/pre-commit/config.yaml` (sourced from the pre-commit setup, not currently in any repo by itself). @@ -41,7 +41,7 @@ The global pre-commit framework config lives at `~/.config/pre-commit/config.yam ## The system in one paragraph -Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs only the *focused summarizer review* (the reusable `claude-blocking-review.yml` workflow), tests, and deploys — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block. +Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs the deterministic `standards-check`, tests, and deploys; no Claude judgment reviewer runs in CI — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block. For the full architecture, see [`docs/WORKFLOW-DEEP-DIVE.md`](./docs/WORKFLOW-DEEP-DIVE.md). For the journey that produced it, see [`docs/local-first-code-quality-epic.md`](./docs/local-first-code-quality-epic.md). diff --git a/docs/token-rotation.md b/docs/token-rotation.md index aaf7847..194cccb 100644 --- a/docs/token-rotation.md +++ b/docs/token-rotation.md @@ -76,13 +76,19 @@ between. Paste when prompted. -3. Re-run one Claude workflow on a repo in that scope and read the log: the - `claude-code-action` step must authenticate, not skip. +3. Re-run one Claude workflow on a repo in that scope that still has a + `claude.yml` caller (for example `smartwatermelon/scripts`) and read the + log: the `claude-code-action` step must authenticate, not skip. Trigger + it with an `@claude` mention on an issue, or re-run the latest run: ```bash - gh run list -R smartwatermelon/dev-env --workflow claude-blocking-review.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/dev-env + gh run list -R smartwatermelon/scripts --workflow claude.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/scripts ``` + `dev-env` has no `claude.yml`, so it cannot verify a rotation. Its copy + of the secret is pending deletion by hand (the CI reviewer that used it + is retired). + 4. Update the table row (minted date, expiry = minted + the lifetime `setup-token` printed, machine). From b5a17672fcbc23ce2c377c99b3486061da149074 Mon Sep 17 00:00:00 2001 From: Claude Code Bot Date: Thu, 1 Oct 2026 20:28:31 -0700 Subject: [PATCH 2/2] docs: record the dev-env secret deletion Advances smartwatermelon/github-workflows#154. --- docs/token-rotation.md | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/docs/token-rotation.md b/docs/token-rotation.md index 194cccb..6ef16d3 100644 --- a/docs/token-rotation.md +++ b/docs/token-rotation.md @@ -85,9 +85,8 @@ between. gh run list -R smartwatermelon/scripts --workflow claude.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/scripts ``` - `dev-env` has no `claude.yml`, so it cannot verify a rotation. Its copy - of the secret is pending deletion by hand (the CI reviewer that used it - is retired). + `dev-env` has no `claude.yml` and no longer holds the secret. It was + deleted on 2026-10-01, after the CI reviewer that used it was retired. 4. Update the table row (minted date, expiry = minted + the lifetime `setup-token` printed, machine).