Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ The spec in this repo is implemented across several other repositories. None of
| [`smartwatermelon/claude-config`](https://github.com/smartwatermelon/claude-config) | The actual Claude Code hooks: `pre-merge-review.sh`, `run-review.sh`, `merge-lock.sh`, `lib-review-issues.sh`. Symlinked into `~/.claude/` on each machine. |
| [`smartwatermelon/claude-wrapper`](https://github.com/smartwatermelon/claude-wrapper) | Bash wrapper around the `claude` CLI, symlinked to `~/.local/bin/claude` so it shadows the real binary in `$PATH`. Resolves per-project 1Password secrets via `op inject`, injects `--remote-control` session names for interactive sessions, and validates binary ownership/permissions before `exec`. |
| [`smartwatermelon/dotfiles`](https://github.com/smartwatermelon/dotfiles) | The global git hooks (`pre-commit`, `pre-push`, `commit-msg`, etc.) at `git/hooks/`, symlinked from `~/.config/git/hooks/`. Also hosts shared shell utilities like `lint-shell.sh`. |
| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The reusable GitHub Actions workflows (`claude-blocking-review.yml`, `claude-assistant.yml`) called by every owned repo's `.github/workflows/` caller. Plus `claude-review-audit.sh` for fleet-wide configuration auditing. |
| [`smartwatermelon/github-workflows`](https://github.com/smartwatermelon/github-workflows) | The live reusable GitHub Actions workflows (`standards-check.yml`, `claude-assistant.yml`) called by owned repos' `.github/workflows/` callers. `claude-blocking-review.yml` remains only as a deprecated workflow. |
| [`smartwatermelon/ralph-burndown`](https://github.com/smartwatermelon/ralph-burndown) | The tech-debt burndown tool that picks up non-blocking issues filed by the local Phase 2 review and works through them overnight. |

The global pre-commit framework config lives at `~/.config/pre-commit/config.yaml` (sourced from the pre-commit setup, not currently in any repo by itself).
Expand All @@ -41,7 +41,7 @@ The global pre-commit framework config lives at `~/.config/pre-commit/config.yam

## The system in one paragraph

Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs only the *focused summarizer review* (the reusable `claude-blocking-review.yml` workflow), tests, and deploys — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block.
Every commit goes through a global git pre-commit hook that runs format/lint/security checks (`prettier`, `eslint` where local, `shellcheck`, `yamllint`, `markdownlint`, `html-tidy`, `black`, `flake8`, `semgrep`, plus per-repo overrides) followed by two Claude-powered review agents (`code-reviewer` and `adversarial-reviewer`, with elevated scrutiny for security-critical files). Every push goes through a pre-push hook that runs Claude in two more modes — full-diff review and whole-codebase review with full filesystem access — and files non-blocking findings as GitHub issues for the burndown tool. Every merge is gated by `pre-merge-review.sh`, which fetches PR comments, CI status, and inline review threads, and uses Claude to produce a `SAFE_TO_MERGE` / `BLOCK_MERGE` verdict. CI on the GitHub side runs the deterministic `standards-check`, tests, and deploys; no Claude judgment reviewer runs in CI — every other CI lint job has been removed because it was duplicating local enforcement. Sentry/Seer findings flow through as advisory inline-comment input but never block.

For the full architecture, see [`docs/WORKFLOW-DEEP-DIVE.md`](./docs/WORKFLOW-DEEP-DIVE.md). For the journey that produced it, see [`docs/local-first-code-quality-epic.md`](./docs/local-first-code-quality-epic.md).

Expand Down
11 changes: 8 additions & 3 deletions docs/token-rotation.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,13 +76,18 @@ between.

Paste when prompted.

3. Re-run one Claude workflow on a repo in that scope and read the log: the
`claude-code-action` step must authenticate, not skip.
3. Re-run one Claude workflow on a repo in that scope that still has a
`claude.yml` caller (for example `smartwatermelon/scripts`) and read the
log: the `claude-code-action` step must authenticate, not skip. Trigger
it with an `@claude` mention on an issue, or re-run the latest run:

```bash
gh run list -R smartwatermelon/dev-env --workflow claude-blocking-review.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/dev-env
gh run list -R smartwatermelon/scripts --workflow claude.yml --limit 1 --json databaseId --jq '.[0].databaseId' | xargs -I{} gh run rerun {} -R smartwatermelon/scripts
```

`dev-env` has no `claude.yml` and no longer holds the secret. It was
deleted on 2026-10-01, after the CI reviewer that used it was retired.

4. Update the table row (minted date, expiry = minted + the lifetime
`setup-token` printed, machine).

Expand Down
Loading