Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/prompts/review.prompt.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ checks, or claim verification passed without evidence from the pull request.
[docs/design/overview.md](../../docs/design/overview.md) changed alongside
the code, and that the `_examples/` programs still pass the e2e suite.
5. If the diff touches `.github/workflows/**`, `.goreleaser.yaml`,
`.svu.yaml`, or `policies/agent-governance.json`, treat it as high risk:
`.svu.yml`, or `policies/agent-governance.json`, treat it as high risk:
confirm every action is SHA-pinned with least-privilege permissions and
that a human reviews it.
6. Report findings as review comments ordered by severity, labelled
Expand Down
2 changes: 1 addition & 1 deletion .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ closes. -->

<!-- Delete if the PR touches none of these. -->

- [ ] Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yaml`,
- [ ] Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yml`,
or `policies/agent-governance.json` are called out above as high risk
(new actions SHA-pinned, least-privilege permissions)

Expand Down
File renamed without changes.
4 changes: 2 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -215,7 +215,7 @@ std is a library: a release is a Git tag plus a GitHub release with a
changelog — no binaries, packages, or archives.

1. The operator runs `make bump` on a clean, checked `main`: it runs `make
check`, asks [`svu next`](.svu.yaml) for the next semantic version from
check`, asks [`svu next`](.svu.yml) for the next semantic version from
the Conventional Commit history (`v0` tags, `always: true`), creates an
annotated tag, and pushes it.
2. The pushed tag triggers
Expand Down Expand Up @@ -258,7 +258,7 @@ are operator acts (see Agent limits below).
alongside `AGENTS.md`, `.agents/skills/`, and `docs/README.md`. Deny by
default; read, write, and run-tests allowed; issues, pull requests, and
follow-ups review-required; `.github/workflows/**` and the release surface
(`.goreleaser.yaml`, `.svu.yaml`, `.github/workflows/release.yml`) are
(`.goreleaser.yaml`, `.svu.yml`, `.github/workflows/release.yml`) are
review-required at high risk. Change it only alongside the matching ADR
or design change; it must validate against core's
`organization/schemas/v1/repository-agent-governance.schema.json`.
Expand Down
4 changes: 2 additions & 2 deletions docs/design/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@
├── .memory/ # Corrections inbox (append-only corrections.jsonl)
├── .claude/ # settings.json (tool-layer limits), session-summary.md
├── .goreleaser.yaml # builds skipped; changelog grouped by commit type
├── .svu.yaml # svu (semantic version utility) config for `make bump`
├── .svu.yml # svu (semantic version utility) config for `make bump`
├── .golangci.yml # What `make lint` and CI run (v2, standard + gofmt)
├── .editorconfig
├── go.mod # Module: github.com/frostyard/std, Go 1.26
Expand Down Expand Up @@ -140,7 +140,7 @@ path — is described in [quality-loop.md](quality-loop.md).

## Release

`make bump` tags the next semver (svu, `.svu.yaml`) and pushes the tag;
`make bump` tags the next semver (svu, `.svu.yml`) and pushes the tag;
`.github/workflows/release.yml` then runs GoReleaser Pro with
`.goreleaser.yaml` — builds skipped, changelog grouped by Conventional Commit
type, GitHub release under `frostyard/std` (`prerelease: auto`). Consumers
Expand Down
2 changes: 1 addition & 1 deletion docs/org-adrs.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ recorded as ADRs in
The ones that bind std:

- [ADR-0002 — Agent-portable instruction surface](https://github.com/frostyard/core/blob/main/docs/adr/0002-agent-portable-instruction-surface.md) — one canonical instruction file with tool-path symlinks; std's alias set is registered in [ADR-0001](adr/0001-acmm-conformance-via-canonical-aliases.md)
- [ADR-0012 — svu-derived versions, make bump, and the rolling dev prerelease](https://github.com/frostyard/core/blob/main/docs/adr/0012-svu-versioning-and-rolling-dev-prerelease.md) — `.svu.yaml` and `make bump` tag releases; the tag triggers `.github/workflows/release.yml`, a changelog-only GoReleaser run (`.goreleaser.yaml`, `builds: [{ skip: true }]`); as a library with no released binary, the rolling dev-prerelease half does not apply
- [ADR-0012 — svu-derived versions, make bump, and the rolling dev prerelease](https://github.com/frostyard/core/blob/main/docs/adr/0012-svu-versioning-and-rolling-dev-prerelease.md) — `.svu.yml` and `make bump` tag releases; the tag triggers `.github/workflows/release.yml`, a changelog-only GoReleaser run (`.goreleaser.yaml`, `builds: [{ skip: true }]`); as a library with no released binary, the rolling dev-prerelease half does not apply
- [ADR-0018 — Org-wide agent instruction and knowledge surfaces](https://github.com/frostyard/core/blob/main/docs/adr/0018-org-wide-agent-instruction-and-knowledge-surfaces.md) — `AGENTS.md` is canonical; `CLAUDE.md`, `GEMINI.md`, `CONTRIBUTING.md`, `.cursorrules`, and `.github/copilot-instructions.md` are symlinks to it; `.memory/corrections.jsonl` and `.github/prompts/*.prompt.md` follow its shapes
- [ADR-0019 — Governance as code and risk tiers](https://github.com/frostyard/core/blob/main/docs/adr/0019-governance-as-code-and-risk-tiers.md) — deny-by-default agent limits (`.claude/settings.json`, `policies/agent-governance.json`) and the `never_relax` guardrail in `.coverage-thresholds.json`
- [ADR-0021 — SHA-pinned actions and least-privilege CI](https://github.com/frostyard/core/blob/main/docs/adr/0021-sha-pinned-actions-and-least-privilege-ci.md) — binds `.github/workflows/ci.yml` and `release.yml`; Dependabot's `github-actions` ecosystem keeps the pins current
Expand Down
2 changes: 1 addition & 1 deletion docs/specs/pr-review-rubric.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ pass.
| Docs housekeeping | `AGENTS.md`, `docs/design/overview.md`, and `docs/specs/*` reflect the behavior change; new docs start from their category `TEMPLATE.md`, are indexed in [docs/README.md](../README.md), and cross-link both ways; a new significant decision ⇒ ADR first, in the same change. |
| Docs-integrity gate green | `node scripts/check-docs.mjs` passes: every doc indexed, every relative link resolving, every symlink alias intact (thresholds in `.coverage-thresholds.json`). |
| Aliases untouched | Conformance aliases ([ADR-0001](../adr/0001-acmm-conformance-via-canonical-aliases.md)) are not edited directly; canonical targets are. |
| Protected boundaries | Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yaml`, or `policies/agent-governance.json` are called out as high risk and reviewed by a human (`policies/agent-governance.json`); new actions are SHA-pinned with least-privilege permissions. |
| Protected boundaries | Changes under `.github/workflows/**`, `.goreleaser.yaml`, `.svu.yml`, or `policies/agent-governance.json` are called out as high risk and reviewed by a human (`policies/agent-governance.json`); new actions are SHA-pinned with least-privilege permissions. |
| Conventional title | The PR title (or lone commit subject) is `type(scope): summary`, since the squash commit is what `svu` versions and the release changelog groups by. |
| Agent limits respected | The PR was not merged, approved, released, or tagged by the agent that authored it; mechanically backed by `.claude/settings.json` and declared in `policies/agent-governance.json`. |

Expand Down
2 changes: 1 addition & 1 deletion policies/agent-governance.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
"minimum_risk_tier": "high",
"paths": [
".goreleaser.yaml",
".svu.yaml",
".svu.yml",
".github/workflows/release.yml"
],
"detectors": []
Expand Down
Loading