Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions .github/floowgithub.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,17 @@
"base_branch": "main",
"branch_pattern": "^(feat|fix|docs|refactor|chore)/(\\d+)-[a-z0-9]+(?:-[a-z0-9]+)*$",
"issue_required": true,
"closing_keywords": ["Closes"],
"exactly_one_closing_reference": true
"issue_checklist_required": true,
"reference_keywords": [
"Refs",
"Closes"
],
"closing_keywords": [
"Closes"
],
"exactly_one_issue_reference": true,
"worktrees": {
"one_active_per_issue": true,
"require_clean_before_removal": true
}
}
5 changes: 3 additions & 2 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
## Related issue or private advisory

Closes #<!-- exactly one primary issue; bot dependency PRs are exempt. For a private security advisory, remove this line and use GitHub's private advisory link without exposing it here. -->
Refs #<!-- exactly one primary issue while work remains. Use Closes only when this merge completes the issue; bot dependency PRs are exempt. For a private security advisory, remove this line and use GitHub's private advisory link without exposing it here. -->

## Result

Expand All @@ -24,7 +24,8 @@ Closes #<!-- exactly one primary issue; bot dependency PRs are exempt. For a pri
## Checklist

- [ ] One coherent scope and one primary issue
- [ ] Branch and `Closes` agree, or an approved branch-name exception is explained
- [ ] Branch and issue reference agree, or an approved branch-name exception is explained
- [ ] `Closes` is used only if the issue checklist and QA are complete
- [ ] Acceptance criteria are satisfied
- [ ] No credentials, personal data, temporary evidence, or unintended files are included
- [ ] Tests, documentation, and embedded dashboard assets are current
Expand Down
5 changes: 3 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,9 @@ These instructions apply to the entire repository.

## Git and GitHub

- Read `docs/content/git-workflow.md` and use the installed `$floowgithub` skill for issue, branch, commit, pull request, review, and merge work.
- Use one primary issue per implementable branch and PR. Include exactly one matching `Closes #N`, except for bot dependency PRs and private security advisories.
- Read `docs/content/git-workflow.md` and use the installed `$floowgithub` skill for issue, branch, commit, pull request, QA, and merge work.
- Each issue is the task and owns its checklist, acceptance criteria, linked child issues, and PRs. Update checkboxes only against current evidence. QA includes code review, checks, and functional validation.
- Use one primary issue per implementable branch and PR. Include exactly one matching `Refs #N` while work remains, or `Closes #N` only when the merge completes the issue; bot dependency PRs and private security advisories are exceptions.
- Never commit directly to `main`. Create an isolated worktree from a verified `origin/main` and use `<category>/<issue>-<slug>` with `feat`, `fix`, `docs`, `refactor`, or `chore`.
- Preserve a branch name explicitly required by an accepted plan. Link its issue in the PR instead of rewriting published history.
- Keep one writer per worktree. Preserve user changes and never stash, reset, amend, rebase, force-push, or discard work you do not own.
Expand Down
15 changes: 9 additions & 6 deletions docs/content/git-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,17 +5,20 @@ weight: 42

# Git and GitHub delivery

ATENEA uses one primary GitHub issue for each reviewable implementation:
Each GitHub issue is the task and owns its acceptance checklist, child issues, and linked pull requests:

```text
issue -> branch/worktree -> implementation -> validation -> commit -> push
-> pull request -> checks/review -> authorized merge -> installation
issue -> branch/worktree -> implementation -> validation
-> commit -> push -> pull request -> QA
-> authorized merge -> issue closure -> installation
```

New branches use `<category>/<issue-number>-<slug>` with `feat`, `fix`, `docs`, `refactor`, or `chore`, start from a verified `origin/main`, and have one writer in an isolated worktree. A branch name explicitly fixed by an accepted earlier plan may remain unchanged when its PR records the exception and still links its primary issue.

Every non-bot PR targets `main`, includes exactly one `Closes #N`, states exact validation and evidence levels, and identifies unrun checks. A private security advisory is the sole exception: keep its reference private, use GitHub's private advisory link, and do not create or mention a public issue. A check or review applies only to the head SHA it inspected. Every push restarts readiness review.
Every non-bot PR targets `main`, links exactly one primary issue with `Refs #N` while work remains or `Closes #N` only when its merge completes the issue, states exact validation and evidence levels, and identifies unrun checks. A private security advisory is the sole exception: keep its reference private, use GitHub's private advisory link, and do not create or mention a public issue. QA evidence applies only to the head SHA it inspected. Every push restarts QA readiness.

Review checks, formal reviews, issue comments, inline comments, and unresolved threads. Verify automated findings in code. Readiness requires successful required checks, satisfied acceptance criteria, no actionable thread, and an unchanged reviewed SHA. Never self-approve or bypass protection. Merge, installation, release, migration, and deployment are distinct effects.
QA includes code review, automated checks, and functional validation. Inspect issue comments, inline comments, and unresolved threads; verify automated findings in code. Merge readiness requires successful required checks, satisfied relevant acceptance criteria, no actionable thread, and an unchanged reviewed SHA. Never self-approve or bypass protection. Merge, issue closure, installation, release, migration, and deployment are distinct effects.

Use the installed `$floowgithub` skill for the operational workflow and deterministic snapshot checker. ATENEA's machine-readable policy lives in `.github/floowgithub.json`; project-specific validation commands remain in `AGENTS.md`.
Use the installed `$floowgithub` skill for the operational workflow and deterministic snapshot checker. ATENEA's machine-readable policy lives in `.github/floowgithub.json`; repository-specific validation commands remain in `AGENTS.md`.

Update an issue checklist item when its observable result has current evidence; reopen it if that evidence is invalidated. Close a parent issue only after its checklist, child issues, required PRs, and QA are complete. Creating or merging a PR alone does not complete the issue.
10 changes: 8 additions & 2 deletions scripts/validate-floowgithub-policy.py
Original file line number Diff line number Diff line change
Expand Up @@ -36,10 +36,16 @@
errors.append("branch_pattern must reject master")
if policy.get("issue_required") is not True:
errors.append("ATENEA must require a primary issue")
if policy.get("issue_checklist_required") is not True:
errors.append("ATENEA must require an issue checklist")
if policy.get("reference_keywords") != ["Refs", "Closes"]:
errors.append("ATENEA must allow Refs and Closes issue references")
if policy.get("closing_keywords") != ["Closes"]:
errors.append("ATENEA must use the Closes keyword")
if policy.get("exactly_one_closing_reference") is not True:
errors.append("ATENEA must require exactly one closing reference")
if policy.get("exactly_one_issue_reference") is not True:
errors.append("ATENEA must require exactly one issue reference")
if "project" in policy or "tasks" in policy:
errors.append("ATENEA must not require GitHub Projects")

if errors:
print("\n".join(errors), file=sys.stderr)
Expand Down
Loading