diff --git a/.github/prompts/review.prompt.md b/.github/prompts/review.prompt.md index b912a41..aa87ef4 100644 --- a/.github/prompts/review.prompt.md +++ b/.github/prompts/review.prompt.md @@ -36,7 +36,7 @@ checks, or claim verification passed without evidence from the pull request. [docs/design/overview.md](../../docs/design/overview.md) changed alongside the code, and that the `_examples/` programs still pass the e2e suite. 5. If the diff touches `.github/workflows/**`, `.goreleaser.yaml`, - `.svu.yaml`, or `policies/agent-governance.json`, treat it as high risk: + `.svu.yml`, or `policies/agent-governance.json`, treat it as high risk: confirm every action is SHA-pinned with least-privilege permissions and that a human reviews it. 6. Report findings as review comments ordered by severity, labelled diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index dd82a1c..32d50e0 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -35,7 +35,7 @@ closes. --> -- [ ] Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yaml`, +- [ ] Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yml`, or `policies/agent-governance.json` are called out above as high risk (new actions SHA-pinned, least-privilege permissions) diff --git a/.svu.yaml b/.svu.yml similarity index 100% rename from .svu.yaml rename to .svu.yml diff --git a/AGENTS.md b/AGENTS.md index aa31795..2183ea6 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -215,7 +215,7 @@ std is a library: a release is a Git tag plus a GitHub release with a changelog — no binaries, packages, or archives. 1. The operator runs `make bump` on a clean, checked `main`: it runs `make - check`, asks [`svu next`](.svu.yaml) for the next semantic version from + check`, asks [`svu next`](.svu.yml) for the next semantic version from the Conventional Commit history (`v0` tags, `always: true`), creates an annotated tag, and pushes it. 2. The pushed tag triggers @@ -258,7 +258,7 @@ are operator acts (see Agent limits below). alongside `AGENTS.md`, `.agents/skills/`, and `docs/README.md`. Deny by default; read, write, and run-tests allowed; issues, pull requests, and follow-ups review-required; `.github/workflows/**` and the release surface - (`.goreleaser.yaml`, `.svu.yaml`, `.github/workflows/release.yml`) are + (`.goreleaser.yaml`, `.svu.yml`, `.github/workflows/release.yml`) are review-required at high risk. Change it only alongside the matching ADR or design change; it must validate against core's `organization/schemas/v1/repository-agent-governance.schema.json`. diff --git a/docs/design/overview.md b/docs/design/overview.md index d882908..7b32e05 100644 --- a/docs/design/overview.md +++ b/docs/design/overview.md @@ -40,7 +40,7 @@ ├── .memory/ # Corrections inbox (append-only corrections.jsonl) ├── .claude/ # settings.json (tool-layer limits), session-summary.md ├── .goreleaser.yaml # builds skipped; changelog grouped by commit type -├── .svu.yaml # svu (semantic version utility) config for `make bump` +├── .svu.yml # svu (semantic version utility) config for `make bump` ├── .golangci.yml # What `make lint` and CI run (v2, standard + gofmt) ├── .editorconfig ├── go.mod # Module: github.com/frostyard/std, Go 1.26 @@ -140,7 +140,7 @@ path — is described in [quality-loop.md](quality-loop.md). ## Release -`make bump` tags the next semver (svu, `.svu.yaml`) and pushes the tag; +`make bump` tags the next semver (svu, `.svu.yml`) and pushes the tag; `.github/workflows/release.yml` then runs GoReleaser Pro with `.goreleaser.yaml` — builds skipped, changelog grouped by Conventional Commit type, GitHub release under `frostyard/std` (`prerelease: auto`). Consumers diff --git a/docs/org-adrs.md b/docs/org-adrs.md index e614043..7f3f6dd 100644 --- a/docs/org-adrs.md +++ b/docs/org-adrs.md @@ -6,7 +6,7 @@ recorded as ADRs in The ones that bind std: - [ADR-0002 — Agent-portable instruction surface](https://github.com/frostyard/core/blob/main/docs/adr/0002-agent-portable-instruction-surface.md) — one canonical instruction file with tool-path symlinks; std's alias set is registered in [ADR-0001](adr/0001-acmm-conformance-via-canonical-aliases.md) -- [ADR-0012 — svu-derived versions, make bump, and the rolling dev prerelease](https://github.com/frostyard/core/blob/main/docs/adr/0012-svu-versioning-and-rolling-dev-prerelease.md) — `.svu.yaml` and `make bump` tag releases; the tag triggers `.github/workflows/release.yml`, a changelog-only GoReleaser run (`.goreleaser.yaml`, `builds: [{ skip: true }]`); as a library with no released binary, the rolling dev-prerelease half does not apply +- [ADR-0012 — svu-derived versions, make bump, and the rolling dev prerelease](https://github.com/frostyard/core/blob/main/docs/adr/0012-svu-versioning-and-rolling-dev-prerelease.md) — `.svu.yml` and `make bump` tag releases; the tag triggers `.github/workflows/release.yml`, a changelog-only GoReleaser run (`.goreleaser.yaml`, `builds: [{ skip: true }]`); as a library with no released binary, the rolling dev-prerelease half does not apply - [ADR-0018 — Org-wide agent instruction and knowledge surfaces](https://github.com/frostyard/core/blob/main/docs/adr/0018-org-wide-agent-instruction-and-knowledge-surfaces.md) — `AGENTS.md` is canonical; `CLAUDE.md`, `GEMINI.md`, `CONTRIBUTING.md`, `.cursorrules`, and `.github/copilot-instructions.md` are symlinks to it; `.memory/corrections.jsonl` and `.github/prompts/*.prompt.md` follow its shapes - [ADR-0019 — Governance as code and risk tiers](https://github.com/frostyard/core/blob/main/docs/adr/0019-governance-as-code-and-risk-tiers.md) — deny-by-default agent limits (`.claude/settings.json`, `policies/agent-governance.json`) and the `never_relax` guardrail in `.coverage-thresholds.json` - [ADR-0021 — SHA-pinned actions and least-privilege CI](https://github.com/frostyard/core/blob/main/docs/adr/0021-sha-pinned-actions-and-least-privilege-ci.md) — binds `.github/workflows/ci.yml` and `release.yml`; Dependabot's `github-actions` ecosystem keeps the pins current diff --git a/docs/specs/pr-review-rubric.md b/docs/specs/pr-review-rubric.md index 12abe8c..c0db56c 100644 --- a/docs/specs/pr-review-rubric.md +++ b/docs/specs/pr-review-rubric.md @@ -23,7 +23,7 @@ pass. | Docs housekeeping | `AGENTS.md`, `docs/design/overview.md`, and `docs/specs/*` reflect the behavior change; new docs start from their category `TEMPLATE.md`, are indexed in [docs/README.md](../README.md), and cross-link both ways; a new significant decision ⇒ ADR first, in the same change. | | Docs-integrity gate green | `node scripts/check-docs.mjs` passes: every doc indexed, every relative link resolving, every symlink alias intact (thresholds in `.coverage-thresholds.json`). | | Aliases untouched | Conformance aliases ([ADR-0001](../adr/0001-acmm-conformance-via-canonical-aliases.md)) are not edited directly; canonical targets are. | -| Protected boundaries | Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yaml`, or `policies/agent-governance.json` are called out as high risk and reviewed by a human (`policies/agent-governance.json`); new actions are SHA-pinned with least-privilege permissions. | +| Protected boundaries | Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yml`, or `policies/agent-governance.json` are called out as high risk and reviewed by a human (`policies/agent-governance.json`); new actions are SHA-pinned with least-privilege permissions. | | Conventional title | The PR title (or lone commit subject) is `type(scope): summary`, since the squash commit is what `svu` versions and the release changelog groups by. | | Agent limits respected | The PR was not merged, approved, released, or tagged by the agent that authored it; mechanically backed by `.claude/settings.json` and declared in `policies/agent-governance.json`. | diff --git a/policies/agent-governance.json b/policies/agent-governance.json index 48ef68f..b283d05 100644 --- a/policies/agent-governance.json +++ b/policies/agent-governance.json @@ -25,7 +25,7 @@ "minimum_risk_tier": "high", "paths": [ ".goreleaser.yaml", - ".svu.yaml", + ".svu.yml", ".github/workflows/release.yml" ], "detectors": []