feat(tooling): let every repository keep itself on the standard - #55
Merged
Merged
Conversation
Repositories drifted because nothing moved them to new releases. This makes each repository update itself, with no credential beyond its own workflow token, and warns about the drift the audit found without yet failing anyone's checks. Every example now carries a daily Standard update workflow. It runs the vendored self-update script, which applies the latest release with the release's own updater, opens one pull request, dispatches ci.yml so Validate runs on a pull request the workflow token opened, and closes update pull requests a newer release or an earlier merge made unnecessary. A patch release's pull request merges itself once Validate passes; a minor release's waits for a maintainer. The central Publish standard workflow and its GitHub App are gone, and Standard status reads every public repository with its own token. The updater now adds the Standard update workflow when a repository lacks it and points .claude/settings.json at the installed release. These only warn until v0.6.0, which will enforce them: - standards:check reports hooks, Codex and agent plugin files, the setup action, and .editorconfig that differ from the release, and a .prettierrc that shadows prettier.config.js; - lvbt check contract reports shared catalog entries pinned to another version; - the commit hook reports ci as a type or scope, which behaved exactly like chore in every changelog and release tool. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Publish self-updating repositories and the warnings that precede v0.6.0 enforcement as a minor release of the shared web standard. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
Every LVBT repository now keeps itself on the latest standard. A daily workflow in each repository
opens the update pull request using only that workflow's own token, so there is no bot and no
credential to set up. Patch updates merge themselves once
Validatepasses; minor updates wait fora maintainer. The drift the audit found is reported as warnings now and enforced in v0.6.0.
Overview of Changes
Why this replaces #54
#54 pushed each release from repository-tooling into every other repository. A workflow's own token
can't write to other repositories, so that design needed a GitHub App, which is one more credential
for a volunteer organization to create, install, and keep working. This pull request turns it around.
Each repository runs its own
Standard updateworkflow and only ever changes itself. The twoworkflows #54 added depend on that App, and they are disabled on
mainuntil this merges.Publish standardis deleted here, andStandard statusnow runs on its own token.How a repository updates itself
The examples, and so every template and every new repository, now carry
.github/workflows/standard-update.yml. Once a day it runs the vendoredstandards/self-update.ts, which does the following:updater, or regenerates a template from its example.
automation/repository-standard-<tag>.ci.ymlon the branch; GitHub always runs a dispatched workflow. That puts
Validateon the pull request.repository works, so a maintainer merges it after reading the notes.
update branch someone pushed a fix to is left alone.
A workflow token may not edit workflow files. If a release changes one, the pull request goes out
without it, and the run fails and names the file to copy by hand. The Standard update workflow
itself is only added when missing, never rewritten, so it can't block its own updates.
Warnings before enforcement
Other contributors depend on the standard staying predictable, so nothing in v0.5.0 changes how
anyone's repository works beyond adding the workflow and updating the plugin ref. Three rules the
audit motivated only warn for now:
standards:checkwarns about edited copies of the files the standard owns (hooks, Codex and agentplugin files, the setup action,
.editorconfig), and about a.prettierrcthat replacesprettier.config.js.lvbt check contractwarns about shared catalog entries pinned to another version.cias a type or scope; it behaved exactly likechoreeverywhere.The release notes say v0.6.0 enforces them, which gives every repository a release cycle to fix
what its own checks report. The enforcement code is ready on a separate branch for that release.
Rollout, after approval to tag
The release process now documents patch-only auto-merge and warn-before-enforce. Once v0.5.0 is
tagged, I'll bring labs over first with the maintainer script (
standards/propose.ts), since arepository has to receive its first
standard-update.ymlfrom a person. I'll run its workflow byhand and watch it, then do the other repositories. Each of those v0.5.0 pull requests waits for a
maintainer, because this is a minor release.
Testing
pnpm checkpasses: 247 node tests and the web-platform suite. New tests cover:citype and scope.A dry run of the update against fresh clones of labs and week-without-driving produced the expected
changes and nothing else.
Follow-ups
Standard status..githubonto the standard's layout through reviewed pullrequests, one repository at a time.
🤖 Generated with Claude Code