Scope clarification from the full audit (2026-09-13)
Closure records the no-CI policy retirement and the specific prior local validation evidence from PR #276. It is not certification that every Make target, every test tier or clean-environment setup is complete. Newly source-confirmed defects (missing make test target file, omitted security/performance tiers, out-of-lock browser dependency and sandbox gaps) are explicitly tracked in #281. Agent and safe-tool completion are #282/#283. Keep this historical policy milestone closed while those concrete acceptance tasks remain open; do not copy its result counts as a new run.
Parent roadmap: #252
Current policy (2026-09-13)
No CI checks. Everything is validated locally. This includes code review,
formatting, lint, type checks, migrations, all test tiers, security scans,
artifact checks and mobile validation. Do not add hosted jobs, required CI
statuses, synthetic success checks or an Ollama reviewer. GitHub is for source,
PRs, issues and publication, not validation.
Record commands, environment, results, limitations and reviewed head/base SHAs.
Builders merge only with completed local evidence and GitHub mergeability;
reviewer agents never merge. Real staging/provider/device acceptance remains
required where applicable, driven by authorized local operator tools.
Historical evidence and older comments do not override this policy.
Scope
Replace the obsolete hosted AI/CI gate task with a reproducible local validation
and review process. No AI provider, GitHub secret, workflow or required status
is needed for code review. Do not restore the retired gate.
Implementation plan
- Remove/disable backend static CI, mobile analysis CI, hosted AI review and legacy
E2E workflows. Keep Pages publication separate from validation.
- Align agent instructions, current guides, roadmap children and README. Remove
the retired CI badge and all active prerequisites for hosted checks.
- Guard the workflow inventory with local regression tests.
- Record final-source local review and test evidence, then use normal PR merging
only when GitHub says mergeable. Reviewer agents must not merge.
- Verify no stale required checks remain. If future settings conflict, report them
for a policy-aligned administrative correction; do not bypass or fake success.
Acceptance criteria
Validation
Run all applicable validation locally, including make test-all. Inspect live
workflow/protection state read-only. The latest protection checks returned 404
and an empty ruleset list; no protection changes are needed.
Historical context
The original AI-gate implementation and provider diagnosis in older comments are
superseded, not rollout instructions. PR #272 and #275 are merged. The earlier
90-error scoped-mypy result in a borrowed virtualenv was not a confirmed source
blocker: a clean locked environment passed. Keep actual full-API typing debt and
current environment verification separate.
Completed
PR #276 merged as 21a4a80 after recorded local
review and validation. GitHub reported mergeable with no status checks.
Local main is synchronized. All 21 open roadmap issues were reconciled with
this policy; remaining security/release work is not closed by this ticket.
See PR #276 for commands, source SHA, actual outcomes and limitations.
Scope clarification from the full audit (2026-09-13)
Closure records the no-CI policy retirement and the specific prior local validation evidence from PR #276. It is not certification that every Make target, every test tier or clean-environment setup is complete. Newly source-confirmed defects (missing make test target file, omitted security/performance tiers, out-of-lock browser dependency and sandbox gaps) are explicitly tracked in #281. Agent and safe-tool completion are #282/#283. Keep this historical policy milestone closed while those concrete acceptance tasks remain open; do not copy its result counts as a new run.
Parent roadmap: #252
Current policy (2026-09-13)
No CI checks. Everything is validated locally. This includes code review,
formatting, lint, type checks, migrations, all test tiers, security scans,
artifact checks and mobile validation. Do not add hosted jobs, required CI
statuses, synthetic success checks or an Ollama reviewer. GitHub is for source,
PRs, issues and publication, not validation.
Record commands, environment, results, limitations and reviewed head/base SHAs.
Builders merge only with completed local evidence and GitHub mergeability;
reviewer agents never merge. Real staging/provider/device acceptance remains
required where applicable, driven by authorized local operator tools.
Historical evidence and older comments do not override this policy.
Scope
Replace the obsolete hosted AI/CI gate task with a reproducible local validation
and review process. No AI provider, GitHub secret, workflow or required status
is needed for code review. Do not restore the retired gate.
Implementation plan
E2E workflows. Keep Pages publication separate from validation.
the retired CI badge and all active prerequisites for hosted checks.
only when GitHub says mergeable. Reviewer agents must not merge.
for a policy-aligned administrative correction; do not bypass or fake success.
Acceptance criteria
Validation
Run all applicable validation locally, including make test-all. Inspect live
workflow/protection state read-only. The latest protection checks returned 404
and an empty ruleset list; no protection changes are needed.
Historical context
The original AI-gate implementation and provider diagnosis in older comments are
superseded, not rollout instructions. PR #272 and #275 are merged. The earlier
90-error scoped-mypy result in a borrowed virtualenv was not a confirmed source
blocker: a clean locked environment passed. Keep actual full-API typing debt and
current environment verification separate.
Completed
PR #276 merged as 21a4a80 after recorded local
review and validation. GitHub reported mergeable with no status checks.
Local main is synchronized. All 21 open roadmap issues were reconciled with
this policy; remaining security/release work is not closed by this ticket.
See PR #276 for commands, source SHA, actual outcomes and limitations.