Skip to content

chore: build against a local SDK; the pre-push hook runs unit tests; AGENTS.md only - #490

Merged
bomly-guy merged 4 commits into
mainfrom
claude/dev-workflow
Oct 4, 2026
Merged

bomly-guy merged 4 commits into
mainfrom
claude/dev-workflow

Conversation

@bomly-guy

@bomly-guy bomly-guy commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Development on the scan-record work was slow for four reasons:

  • SDK changes reached the CLI only after a tag (v0.14.1 through v0.14.6).
  • Every push needed a full make verify stamp.
  • Smoke goldens were refreshed locally, which needs every ecosystem's toolchain.
  • Review findings had no severity rule.

The companion SDK PR is bomly-dev/bomly-sdk#107.

What

  • Local SDK workspace. make sdk-local SDK=<dir> points the build at a local SDK checkout through an ignored go.work; a worktree path works.

    • make sdk-pinned undoes it, and make sdk-status reports which SDK is in use.
    • CI's Module drift job now fails if go.work is committed.
  • Fixture builds work under a workspace.

    • TestExamplePluginFixtureCompiles, TestExampleAnalyzerPluginFixtureCompiles and the smoke-tagged plugin builders now replace the SDK with the local checkout. Before this, they failed with "pinned bomly-sdk version is empty".
    • They build with GOWORK=off.
    • The legacy min-version build still uses the published release.
  • Pre-push runs make test. The make verify stamp and scripts/verify-snapshot.sh are removed.

    • make verify remains as an optional local run of the CI checks.
  • AGENTS.md gains three things:

    • the SDK development loop;
    • "don't run smoke locally; dispatch update-smoke-goldens.yml on your branch";
    • the AI review triage rules, shared verbatim with bomly-sdk.
  • CLAUDE.md removed. Claude Code reads AGENTS.md natively, but only when no CLAUDE.md/CLAUDE.local.md exists.

    • TestGuidanceLivesInAgentsMD guards against either file coming back.
  • dev-docs/CI.md lists Smoke's triggers.

  • Smoke runs on approval. smoke.yml drops merge_group, because the repo doesn't use a merge queue, and triggers on pull_request_review.

    • On an approving review it posts a Smoke commit status on the PR head: pending when it starts, then success or failure from the slices' real result.
    • Comment-only reviews post nothing. A job name couldn't be the gate, because a job skipped by its if: counts as passing.
    • Nightly and manual runs are unchanged.

After merge (repository setting)

Add Smoke to the required status checks of the main protection rules ruleset. PRs then show it as Expected until approved, and wait for the suite after approval.

  • A push after approval dismisses the approval, which the ruleset already does, so the new head commit waits for a new approval and a new run.

Testing

  • make test passes pinned to v0.14.6.
  • go test ./test/smoke also passes under make sdk-local.
  • go vet passes with and without -tags smoke.
  • make lint passes.
  • make cli-test from bomly-sdk#107 against this branch passes: full CLI build, vet and unit suite against the local SDK.
  • Pushed with --no-verify. The installed hook is the old stamp check, and this branch deletes the script it depends on. The new hook's gate, make test, was run by hand first.

🤖 Generated with Claude Code

…AGENTS.md only

- make sdk-local / sdk-pinned / sdk-status (scripts/sdk-workspace.sh) point
  the build at a local bomly-sdk checkout through an ignored go.work, and CI
  fails if go.work is committed.
- The plugin fixture builds learn the workspace: they replace the SDK with
  the local checkout instead of failing with "pinned bomly-sdk version is
  empty", and build with GOWORK=off. The SDK's make cli-test and CLI
  compatibility job rely on this.
- .githooks/pre-push runs make test instead of requiring a make verify
  stamp; scripts/verify-snapshot.sh and the stamp are gone. make verify
  stays as an optional local run of the CI checks.
- AGENTS.md documents the SDK workflow, says not to run smoke locally
  (dispatch update-smoke-goldens.yml instead), and carries the AI review
  triage rules shared with bomly-sdk. dev-docs/CI.md names Smoke's real
  triggers.
- CLAUDE.md is removed: Claude Code reads AGENTS.md directly, but only while
  no CLAUDE.md or CLAUDE.local.md exists; TestGuidanceLivesInAgentsMD guards
  against either reappearing.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 14 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: bomly-dev/bomly-cli/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4654c5b3-8e06-45e4-83c3-be43e8aad6b3
📥 Commits

Reviewing files that changed from the base of the PR and between 3eff6d7 and 1d6d205.

📒 Files selected for processing (17)
  • .githooks/pre-push
  • .github/workflows/ci.yml
  • .github/workflows/smoke-status.yml
  • .github/workflows/smoke.yml
  • .gitignore
  • AGENTS.md
  • CLAUDE.md
  • CONTRIBUTING.md
  • Makefile
  • dev-docs/CI.md
  • scripts/sdk-workspace.sh
  • scripts/verify-snapshot.sh
  • test/smoke/fixture_compile_test.go
  • test/smoke/golden_arch_test.go
  • test/smoke/guidance_test.go
  • test/smoke/plugin_minversion_test.go
  • test/smoke/plugin_test.go
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bomly Diff Summary

Compared 3eff6d77fb452e959a1eb061af647fd38c14f24d to 1d6d205c0ab5012ac9325083f582d2f9fd99e899.

Overview

Status Manifests Dependencies Findings Duration
⚠️ Warnings +1 / ~0 / -0 1 added / 0 version changed / 0 detail changes / 0 removed 1 introduced / 0 persisted / 0 resolved 1m 35s

Dependency Changes

Summary: 1 added, 0 version changed, 0 detail changes, 0 removed.

Added Dependencies

Change Package Version Direct? Scope Licenses
added .github/workflows/smoke-status.yml@local local - runtime -

Vulnerabilities

✅ No vulnerability changes.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

Summary: 1 introduced, 0 persisted, 0 resolved.

Introduced Findings

Status Category Severity ID Package Fixed In Title
⚠️ introduced license WARNING UNKNOWN-sd62-grfn-hpft .github/workflows/smoke-status.yml@local - Package license is unknown

Legend: ✅ resolved · ❌ failing · ⚠️ warning

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ee767946f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/sdk-workspace.sh
Comment thread Makefile Outdated
Smoke ran only from a merge_group trigger, and the repository uses no merge
queue, so it ran nightly and never on a pull request. It now runs on an
approving review and posts a `Smoke` commit status on the head commit:
pending at the start, then success or failure from the slices. Required by
the main ruleset, that status keeps a pull request waiting until it is
approved and the suite has passed. A job name could not be the gate, since
a comment-only review also fires pull_request_review and a skipped job
counts as passing. The merge_group trigger goes.

Co-Authored-By: Claude Opus 5.5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b019a78897

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/smoke.yml
Comment thread .github/workflows/smoke.yml Outdated
- A comment-only review no longer shares the approval run's concurrency
  group, so it cannot cancel a smoke run in progress.
- The `Smoke` status is posted by a new workflow_run workflow (smoke-status)
  from the run's result: it runs from the default branch with a write token
  and executes no pull request code, so a fork pull request's read-only
  token no longer leaves its required status unpostable. Smoke itself holds
  no write permission.
- make sdk-local quotes the SDK path; sdk-workspace.sh reports the
  workspace the go command actually uses and refuses `off` while an ancestor
  go.work or GOWORK still applies.

Co-Authored-By: Claude Opus 5.5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c7f75ed2bd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/sdk-workspace.sh
Comment thread scripts/sdk-workspace.sh Outdated
…estor go.work

go env reports GOWORK=off literally, which meant disabled, not an ambient
workspace; and go work init now runs with discovery off, so a checkout
nested below another go.work gets its own instead of 'already exists'.

Co-Authored-By: Claude Opus 5.5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1d6d205c0a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/smoke.yml
@bomly-guy
bomly-guy merged commit 66a2b6e into main Oct 4, 2026
24 checks passed
@bomly-guy
bomly-guy deleted the claude/dev-workflow branch October 4, 2026 00:46
bomly-guy added a commit that referenced this pull request Oct 4, 2026
main's #490 made AGENTS.md the only guidance file, moved Smoke onto a
pull-request-approval trigger with a separate status workflow, added the local
SDK workspace targets, and replaced the pre-push verify stamp with a test run.

- CLAUDE.md is deleted, as on main. Everything this branch had added to it was
  already mirrored in AGENTS.md, which merged cleanly and keeps the assurance
  sections; `TestGuidanceLivesInAgentsMD` would fail otherwise.
- Makefile: main's version, with `evidence` still replaced by
  `assurance-catalog` and `assurance-report`, and `benchmark-samples` pointing
  at `internal/assurance/perfrun`.
- dev-docs/CI.md: main's rows, including the new `Smoke status` workflow and
  Smoke's real triggers, plus this branch's `Release prerequisites` row and
  `workflow_call` on Smoke.

Smoke's approval gate and this branch's `workflow_call` path merged without
overlap: the job guard only skips non-approving reviews, and the status
workflow only acts on approval-triggered runs, so a run called by the release
prerequisites stage is unaffected. `make verify` and actionlint pass.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant