Skip to content

feat(tooling): let every repository keep itself on the standard - #55

Merged
WillieCubed merged 2 commits into
mainfrom
feat/self-updating-standard
Sep 28, 2026
Merged

WillieCubed merged 2 commits into
mainfrom
feat/self-updating-standard

Conversation

@WillieCubed

Copy link
Copy Markdown
Contributor

TL;DR

Every LVBT repository now keeps itself on the latest standard. A daily workflow in each repository
opens the update pull request using only that workflow's own token, so there is no bot and no
credential to set up. Patch updates merge themselves once Validate passes; minor updates wait for
a maintainer. The drift the audit found is reported as warnings now and enforced in v0.6.0.

Overview of Changes

Why this replaces #54

#54 pushed each release from repository-tooling into every other repository. A workflow's own token
can't write to other repositories, so that design needed a GitHub App, which is one more credential
for a volunteer organization to create, install, and keep working. This pull request turns it around.
Each repository runs its own Standard update workflow and only ever changes itself. The two
workflows #54 added depend on that App, and they are disabled on main until this merges.
Publish standard is deleted here, and Standard status now runs on its own token.

How a repository updates itself

The examples, and so every template and every new repository, now carry
.github/workflows/standard-update.yml. Once a day it runs the vendored
standards/self-update.ts, which does the following:

  1. It reads the newest release tag of repository-tooling, which needs no credentials.
  2. If that tag is newer than the vendored release, it applies the release with the release's own
    updater, or regenerates a template from its example.
  3. It opens one pull request on automation/repository-standard-<tag>.
  4. Pull requests opened with a workflow token don't start other workflows, so it dispatches ci.yml
    on the branch; GitHub always runs a dispatched workflow. That puts Validate on the pull request.
  5. It turns on auto-merge only when the step is a patch release. A minor release can change how a
    repository works, so a maintainer merges it after reading the notes.
  6. It closes update pull requests that a newer release or an earlier merge made unnecessary. An
    update branch someone pushed a fix to is left alone.

A workflow token may not edit workflow files. If a release changes one, the pull request goes out
without it, and the run fails and names the file to copy by hand. The Standard update workflow
itself is only added when missing, never rewritten, so it can't block its own updates.

Warnings before enforcement

Other contributors depend on the standard staying predictable, so nothing in v0.5.0 changes how
anyone's repository works beyond adding the workflow and updating the plugin ref. Three rules the
audit motivated only warn for now:

  • standards:check warns about edited copies of the files the standard owns (hooks, Codex and agent
    plugin files, the setup action, .editorconfig), and about a .prettierrc that replaces
    prettier.config.js.
  • lvbt check contract warns about shared catalog entries pinned to another version.
  • The commit hook warns about ci as a type or scope; it behaved exactly like chore everywhere.

The release notes say v0.6.0 enforces them, which gives every repository a release cycle to fix
what its own checks report. The enforcement code is ready on a separate branch for that release.

Rollout, after approval to tag

The release process now documents patch-only auto-merge and warn-before-enforce. Once v0.5.0 is
tagged, I'll bring labs over first with the maintainer script (standards/propose.ts), since a
repository has to receive its first standard-update.yml from a person. I'll run its workflow by
hand and watch it, then do the other repositories. Each of those v0.5.0 pull requests waits for a
maintainer, because this is a minor release.

Testing

pnpm check passes: 247 node tests and the web-platform suite. New tests cover:

  • the self-update entry mapping for templates and consumers;
  • the patch-only auto-merge rule;
  • keeping workflow files out of a self-update's commit;
  • seeding the workflow once without ever rewriting it;
  • plugin-ref sync and every warning;
  • the catalog warning in the contract check;
  • the deprecated ci type and scope.

A dry run of the update against fresh clones of labs and week-without-driving produced the expected
changes and nothing else.

Follow-ups

  • Tag and roll out v0.5.0 (labs first), then re-enable Standard status.
  • Release v0.6.0, which enforces the three warned rules, once every repository reports clean.
  • Converge website, transit-mapper, and .github onto the standard's layout through reviewed pull
    requests, one repository at a time.

🤖 Generated with Claude Code

WillieCubed and others added 2 commits September 27, 2026 22:40
Repositories drifted because nothing moved them to new releases. This
makes each repository update itself, with no credential beyond its own
workflow token, and warns about the drift the audit found without yet
failing anyone's checks.

Every example now carries a daily Standard update workflow. It runs the
vendored self-update script, which applies the latest release with the
release's own updater, opens one pull request, dispatches ci.yml so
Validate runs on a pull request the workflow token opened, and closes
update pull requests a newer release or an earlier merge made
unnecessary. A patch release's pull request merges itself once Validate
passes; a minor release's waits for a maintainer. The central Publish
standard workflow and its GitHub App are gone, and Standard status reads
every public repository with its own token.

The updater now adds the Standard update workflow when a repository
lacks it and points .claude/settings.json at the installed release.

These only warn until v0.6.0, which will enforce them:
- standards:check reports hooks, Codex and agent plugin files, the setup
  action, and .editorconfig that differ from the release, and a
  .prettierrc that shadows prettier.config.js;
- lvbt check contract reports shared catalog entries pinned to another
  version;
- the commit hook reports ci as a type or scope, which behaved exactly
  like chore in every changelog and release tool.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Publish self-updating repositories and the warnings that precede v0.6.0
enforcement as a minor release of the shared web standard.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@WillieCubed
WillieCubed merged commit cc7458f into main Sep 28, 2026
1 check passed
@WillieCubed
WillieCubed deleted the feat/self-updating-standard branch September 28, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant