Repository navigation
chore: build against a local SDK; the pre-push hook runs unit tests; AGENTS.md only - #490
Conversation
…AGENTS.md only - make sdk-local / sdk-pinned / sdk-status (scripts/sdk-workspace.sh) point the build at a local bomly-sdk checkout through an ignored go.work, and CI fails if go.work is committed. - The plugin fixture builds learn the workspace: they replace the SDK with the local checkout instead of failing with "pinned bomly-sdk version is empty", and build with GOWORK=off. The SDK's make cli-test and CLI compatibility job rely on this. - .githooks/pre-push runs make test instead of requiring a make verify stamp; scripts/verify-snapshot.sh and the stamp are gone. make verify stays as an optional local run of the CI checks. - AGENTS.md documents the SDK workflow, says not to run smoke locally (dispatch update-smoke-goldens.yml instead), and carries the AI review triage rules shared with bomly-sdk. dev-docs/CI.md names Smoke's real triggers. - CLAUDE.md is removed: Claude Code reads AGENTS.md directly, but only while no CLAUDE.md or CLAUDE.local.md exists; TestGuidanceLivesInAgentsMD guards against either reappearing. Co-Authored-By: Claude Opus 5.5 <[email protected]>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 14 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (17)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bomly Diff SummaryCompared Overview
Dependency ChangesSummary: 1 added, 0 version changed, 0 detail changes, 0 removed. Added Dependencies
Vulnerabilities✅ No vulnerability changes. License Changes✅ No license changes. Project Posture✅ No project posture changes ( Policy FindingsSummary: 1 introduced, 0 persisted, 0 resolved. Introduced Findings
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ee767946f1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Smoke ran only from a merge_group trigger, and the repository uses no merge queue, so it ran nightly and never on a pull request. It now runs on an approving review and posts a `Smoke` commit status on the head commit: pending at the start, then success or failure from the slices. Required by the main ruleset, that status keeps a pull request waiting until it is approved and the suite has passed. A job name could not be the gate, since a comment-only review also fires pull_request_review and a skipped job counts as passing. The merge_group trigger goes. Co-Authored-By: Claude Opus 5.5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b019a78897
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- A comment-only review no longer shares the approval run's concurrency group, so it cannot cancel a smoke run in progress. - The `Smoke` status is posted by a new workflow_run workflow (smoke-status) from the run's result: it runs from the default branch with a write token and executes no pull request code, so a fork pull request's read-only token no longer leaves its required status unpostable. Smoke itself holds no write permission. - make sdk-local quotes the SDK path; sdk-workspace.sh reports the workspace the go command actually uses and refuses `off` while an ancestor go.work or GOWORK still applies. Co-Authored-By: Claude Opus 5.5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c7f75ed2bd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…estor go.work go env reports GOWORK=off literally, which meant disabled, not an ambient workspace; and go work init now runs with discovery off, so a checkout nested below another go.work gets its own instead of 'already exists'. Co-Authored-By: Claude Opus 5.5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1d6d205c0a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
main's #490 made AGENTS.md the only guidance file, moved Smoke onto a pull-request-approval trigger with a separate status workflow, added the local SDK workspace targets, and replaced the pre-push verify stamp with a test run. - CLAUDE.md is deleted, as on main. Everything this branch had added to it was already mirrored in AGENTS.md, which merged cleanly and keeps the assurance sections; `TestGuidanceLivesInAgentsMD` would fail otherwise. - Makefile: main's version, with `evidence` still replaced by `assurance-catalog` and `assurance-report`, and `benchmark-samples` pointing at `internal/assurance/perfrun`. - dev-docs/CI.md: main's rows, including the new `Smoke status` workflow and Smoke's real triggers, plus this branch's `Release prerequisites` row and `workflow_call` on Smoke. Smoke's approval gate and this branch's `workflow_call` path merged without overlap: the job guard only skips non-approving reviews, and the status workflow only acts on approval-triggered runs, so a run called by the release prerequisites stage is unaffected. `make verify` and actionlint pass. Co-Authored-By: Claude Fable 5.1 <[email protected]>
Why
Development on the scan-record work was slow for four reasons:
make verifystamp.The companion SDK PR is bomly-dev/bomly-sdk#107.
What
Local SDK workspace.
make sdk-local SDK=<dir>points the build at a local SDK checkout through an ignoredgo.work; a worktree path works.make sdk-pinnedundoes it, andmake sdk-statusreports which SDK is in use.go.workis committed.Fixture builds work under a workspace.
TestExamplePluginFixtureCompiles,TestExampleAnalyzerPluginFixtureCompilesand the smoke-tagged plugin builders now replace the SDK with the local checkout. Before this, they failed with "pinned bomly-sdk version is empty".GOWORK=off.Pre-push runs
make test. Themake verifystamp andscripts/verify-snapshot.share removed.make verifyremains as an optional local run of the CI checks.AGENTS.md gains three things:
update-smoke-goldens.ymlon your branch";CLAUDE.md removed. Claude Code reads
AGENTS.mdnatively, but only when noCLAUDE.md/CLAUDE.local.mdexists.TestGuidanceLivesInAgentsMDguards against either file coming back.dev-docs/CI.mdlists Smoke's triggers.Smoke runs on approval.
smoke.ymldropsmerge_group, because the repo doesn't use a merge queue, and triggers onpull_request_review.Smokecommit status on the PR head: pending when it starts, then success or failure from the slices' real result.if:counts as passing.After merge (repository setting)
Add
Smoketo the required status checks of themain protection rulesruleset. PRs then show it as Expected until approved, and wait for the suite after approval.Testing
make testpasses pinned to v0.14.6.go test ./test/smokealso passes undermake sdk-local.go vetpasses with and without-tags smoke.make lintpasses.make cli-testfrom bomly-sdk#107 against this branch passes: full CLI build, vet and unit suite against the local SDK.--no-verify. The installed hook is the old stamp check, and this branch deletes the script it depends on. The new hook's gate,make test, was run by hand first.🤖 Generated with Claude Code