1 Commits
Author SHA1 Message Date
sneak 6d7c39cdd8 Fold the August fleet findings into the policies, or drop them (closes #62)
check / check (push) Failing after 1s
Two findings from 2026-08-09 were rules a repository must follow that
`prompts/REPO_POLICIES.md` did not yet state, and are now added where a
reader would look: a new or changed check is proven by planting a defect
it must catch; and a change to a separate workflow limited to `main` by
a `branches` list is first run from the feature branch, added to that
list and removed again before merging. The issue records why every
other finding was dropped, including the warning against
`golangci-lint config verify`: the pinned release checks against a
schema built into it and fetches nothing.

Model: opus-5-5
2026-10-04 10:04:31 +00:00
2 changed files with 14 additions and 13 deletions
+8 -6
View File
@@ -22,12 +22,14 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-04: Went through the fleet findings recorded on 2026-08-09 (issue 62)
and added the three rules `REPO_POLICIES.md` did not yet state:
`golangci-lint config verify` is never run from `make lint`, the lint phase or
CI; a new or changed check is proven by planting a defect it must catch; and a
workflow step that runs only on `main` is first run from the feature branch.
The other findings were already stated, replaced by `--no-cache`, about git
worktrees, or about how agents work together; the issue gives each reason.
and added the two rules `REPO_POLICIES.md` did not yet state: a new or changed
check is proven by planting a defect it must catch; and a change to a separate
workflow limited to `main` is first run from the feature branch, added to that
workflow's `branches` list and removed again before merging. The other
findings were already stated, replaced by `--no-cache`, about git worktrees,
about how agents work together, or no longer true (the pinned golangci-lint
checks `config verify` against a schema built into it and fetches nothing);
the issue gives each reason.
- 2026-10-04: The note under the canonical Go `Dockerfile` example in
`REPO_POLICIES.md` now installs lint-phase system libraries with `apt-get`
under their Debian package names (issue 83). The `golangci/golangci-lint`
+6 -7
View File
@@ -277,10 +277,12 @@ style conventions are in separate documents:
carry the same guarantee, because its gate phases may come from the cache. The
image build is uncached and so runs the gate phases a second time. That is the
price of the rule above, and it is worth paying: the image that ships is built
from a run of its own gates rather than from a cache entry. A workflow step
that runs only on `main` cannot be checked by review. Before merging it,
temporarily add the feature branch to its trigger and push, keeping any job
that publishes behind `if: github.ref_name == 'main'`.
from a run of its own gates rather than from a cache entry. A separate
workflow limited to `main` by a `branches` list under `on: push` cannot be
checked by review: to try a change to it, add the feature branch to that list
and push, then remove the branch from the list again before merging. Keep any
job in it that publishes behind `if: github.ref_name == 'main'`, so the run
from the feature branch publishes nothing.
- Use platform-standard formatters: `black` for Python, `prettier` for
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
@@ -488,9 +490,6 @@ style conventions are in separate documents:
the two prompted the change: the canonical copy can name linters that an older
golangci-lint rejects, and a newer golangci-lint can add linters that
`default: all` switches on until the canonical copy disables them.
`golangci-lint config verify` is never run from `make lint`, the lint phase or
CI: it fetches the schema it checks against over the network, unpinned, on
every run.
- **`script/bootstrap` installs a pinned tool by comparing versions, never by
testing presence.** An `if ! command -v <tool>; then install; fi` guard tests