diff --git a/.agents/pm/history/_workspace.jsonl b/.agents/pm/history/_workspace.jsonl index 0ef9495..250cb08 100644 --- a/.agents/pm/history/_workspace.jsonl +++ b/.agents/pm/history/_workspace.jsonl @@ -37,3 +37,5 @@ {"hash_algorithm":"sha256","ts":"2026-09-25T08:32:14.966Z","author":"fleet-wave-script","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"e0d15f3cda6eb998be619306","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"xhigh","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.282","source":"probe"}},"op":"policy_refused","patch":[],"before_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","after_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","item_hash_version":3,"message":"Workflow policy refused a proposed item mutation.","context":{"item_id":"ops-ssnr","operation":"close","workflow_policies":[{"policy_id":"completeness-issue","policy_fingerprint":"29451c1f80adfbacaeaa7936a6a7f69fe058f29da602f3dfbc941152e36a7130","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["repro_steps","expected_result"],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["resolution"],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"1ab8885d5d257ae2507ba65a69fc1ef27bef60512535254e282a74ea5618e056"} {"hash_algorithm":"sha256","ts":"2026-09-25T09:08:31.010Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"e0d15f3cda6eb998be619306","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"xhigh","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.282","source":"probe"}},"op":"policy_refused","patch":[],"before_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","after_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","item_hash_version":3,"message":"Workflow policy refused a proposed item mutation.","context":{"item_id":"ops-eyi8","operation":"close","workflow_policies":[{"policy_id":"completeness-issue","policy_fingerprint":"29451c1f80adfbacaeaa7936a6a7f69fe058f29da602f3dfbc941152e36a7130","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["repro_steps"],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"0b127f6a676561ef8a7811d6f4a48172b41e45e5786d7ade2ec1dfaf836b0817"} {"hash_algorithm":"sha256","ts":"2026-09-28T05:27:33.014Z","author":"claude-hub","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"acec329f9c06ecc0d6dbecd4","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.283","source":"probe"}},"op":"policy_refused","patch":[],"before_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","after_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","item_hash_version":3,"message":"Workflow policy refused a proposed item mutation.","context":{"item_id":"ops-jzp5","operation":"close","workflow_policies":[{"policy_id":"completeness-issue","policy_fingerprint":"29451c1f80adfbacaeaa7936a6a7f69fe058f29da602f3dfbc941152e36a7130","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["repro_steps","expected_result"],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["resolution"],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a5c6652d313d2ed3fb3a672bc16456d5f7851c457114591ce6b136d81d556284"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.317Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"policy_refused","patch":[],"before_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","after_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","item_hash_version":3,"message":"Workflow policy refused a proposed item mutation.","context":{"item_id":"ops-k1lf","operation":"close","workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["resolution"],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"209d68e6cb26d61644e094107949ebb57d0468f6a0d54064261ec6e5e5f5f671"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:02:04.014Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"policy_refused","patch":[],"before_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","after_hash":"316b3153ae19030ba63b9440fcf07d26200698b54ef8b936da54442254e86ec8","item_hash_version":3,"message":"Workflow policy refused a proposed item mutation.","context":{"item_id":"ops-k1lf","operation":"close","workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":false,"missing_fields":["resolution"],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"9142d4488d5cbaa0d86e9391588fc4107dca01aab9cbd3b96b5ba0dfd5b00ed4"} diff --git a/.agents/pm/history/ops-k1lf.jsonl b/.agents/pm/history/ops-k1lf.jsonl new file mode 100644 index 0000000..1a59789 --- /dev/null +++ b/.agents/pm/history/ops-k1lf.jsonl @@ -0,0 +1,8 @@ +{"hash_algorithm":"sha256","ts":"2026-10-04T16:55:22.055Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"ops-k1lf"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:55:22.055Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:55:22.055Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:55:22.055Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"1cdcc94986dd6874460cb89872130e9f5ab7e5594627723fd48a7b239fc18cc0","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"a96eb8ae55abb71b3ddd4564c00a1f3db7a3126a0c985305eac5cd889f8621de"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:55:22.955Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:55:22.955Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"1cdcc94986dd6874460cb89872130e9f5ab7e5594627723fd48a7b239fc18cc0","after_hash":"a7c921e0db1ad5b3361e5c8d6d1d811c5fae5d4d4add969a08a16babdeb48420","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"1947f70015fdc313cfa6fce2af3269c224657e8a276c775ba9e4f53ca74ad2de"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:55:23.504Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:55:23.504Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"a7c921e0db1ad5b3361e5c8d6d1d811c5fae5d4d4add969a08a16babdeb48420","after_hash":"8160b7a7fa3860b74f3ef3d6d213f8c8774c0e7b6914e0398a5b67c996bc5523","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"84858f1341d7ab1fde0913994b330823d065544500cec94f447fd0077820f076"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:02:10.967Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:02:10.967Z"},{"op":"add","path":"/metadata/resolution","value":"completed"}],"before_hash":"8160b7a7fa3860b74f3ef3d6d213f8c8774c0e7b6914e0398a5b67c996bc5523","after_hash":"fe890d75d5155202a561066e2188b2ff4eac875bc79a8484b6e080a6b6d4b4a3","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"91dccd5daaf5770e26ac5392d3ade61145cf64a8cd897eaab1833fcb266c3735"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:02:11.868Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:02:11.868Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T17:02:11.853Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T17:02:11.853Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"fe890d75d5155202a561066e2188b2ff4eac875bc79a8484b6e080a6b6d4b4a3","after_hash":"758abaa4b2c23e4322d969359d1a38e10cc2913904d5a1cc33704970e7ea1f0c","item_hash_version":3,"context":{"workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"6af8c5cf258b579379f500a4105b8a95f7e2beb51cdf9313437db73a1894e1e0"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:02:19.480Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:02:19.480Z"}],"before_hash":"758abaa4b2c23e4322d969359d1a38e10cc2913904d5a1cc33704970e7ea1f0c","after_hash":"14eb61a16ba4ab8c8e8d2d7664761a1606c2604d9565e390ec8654a342b64f47","item_hash_version":3,"context":{"workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"1bc36fed2c44cff2490f09f3769560431603961d2f6d5cc61f6840031d9ea12d"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:34.242Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:34.242Z"}],"before_hash":"14eb61a16ba4ab8c8e8d2d7664761a1606c2604d9565e390ec8654a342b64f47","after_hash":"6975c7fb30a4cc7378cb969b3d4f109159c07be6096d5a80c4b757846fc91b87","item_hash_version":3,"context":{"workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"5ab5374e782cd675d85ab9cd0d8b962a03881b07dd95ca3c3510352431f68248"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:41.363Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-04T17:20:41.358Z","author":"claude-orchestrator","text":"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:41.363Z"}],"before_hash":"6975c7fb30a4cc7378cb969b3d4f109159c07be6096d5a80c4b757846fc91b87","after_hash":"bda5ede82d2246cae7d4a8a1a0f9172a7ec318c92f5e672f1a79bfea8db3fc1c","item_hash_version":3,"context":{"workflow_policies":[{"policy_id":"completeness-task","policy_fingerprint":"5707ce9fab232f6d4a5baae932cfadbccf3029f18b385032e967aa22a9c069db","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."},{"policy_id":"fleet-closed-resolution","policy_fingerprint":"e13f80d0b1fcef3c8ead9b5e9a32723dc589cc189ef68aa23badea68dace3a17","rule":"require_fields","effect":"refuse","satisfied":true,"missing_fields":[],"remediation":"Supply the declared required fields before this lifecycle transition."}],"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fda1e55f64029019a665c9e1f2b3a7884eaade5f78330f8dc64b19a711c834fc"} diff --git a/.agents/pm/tasks/ops-k1lf.toon b/.agents/pm/tasks/ops-k1lf.toon new file mode 100644 index 0000000..e5df592 --- /dev/null +++ b/.agents/pm/tasks/ops-k1lf.toon @@ -0,0 +1,26 @@ +id: ops-k1lf +title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR +description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118." +type: Task +status: closed +priority: 2 +tags[3]: automation,ci,dependencies +created_at: "2026-10-04T16:55:22.055Z" +updated_at: "2026-10-04T17:20:41.363Z" +deadline: "2026-10-06T00:00:00.000Z" +closed_at: "2026-10-04T17:02:11.853Z" +completed_at: "2026-10-04T17:02:11.853Z" +author: claude-orchestrator +estimated_minutes: 15 +acceptance_criteria: "dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge" +resolution: completed +comments[2]{created_at,author,text}: + "2026-10-04T16:55:22.055Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118. + "2026-10-04T17:20:41.358Z",claude-orchestrator,"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)." +files[2]{path,scope}: + .github/dependabot.yml,project + .github/workflows/dependabot-auto-merge.yml,project +docs[1]{path,scope}: + .github/workflows/dependabot-auto-merge.yml,project +close_reason: "Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled." +body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05. diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7f84afe..928675d 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,8 +3,29 @@ updates: - package-ecosystem: "npm" directory: "/" schedule: - interval: "weekly" + interval: "daily" open-pull-requests-limit: 5 + groups: + # The pm CLI, its SDK-bearing packages and the fleet gates move together + # in one pull request per day; dependabot-auto-merge.yml merges it as soon + # as the required checks pass, so a release bump needs no manual work. + # No update-types filter: pm uses calendar versions, so a year rollover + # (2026.x -> 2027.x) is a semver major that must still land unattended. + pm-toolchain: + patterns: + - "@unbrained/pm-cli" + - "pm-*" + dependencies: + # Every other npm dependency, disjoint from pm-toolchain, so a pm + # package can never be bumped here (and capped by update-types). + patterns: + - "*" + exclude-patterns: + - "@unbrained/pm-cli" + - "pm-*" + update-types: + - "minor" + - "patch" - package-ecosystem: "github-actions" directory: "/" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..85d4c77 --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,33 @@ +name: dependabot-auto-merge + +# Version bumps are mechanical: every non-major Dependabot pull request gets +# GitHub auto-merge, so it lands the moment the required checks pass. Branch +# protection still gates the merge; a failing bump stays open as a defect. +on: pull_request + +permissions: {} + +jobs: + enable-auto-merge: + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind' + runs-on: ubuntu-latest + # `gh pr merge --auto` needs pull-requests: write to enable auto-merge + # and contents: write for the squash merge GitHub performs once the + # required checks pass. Nothing is checked out or executed from the PR. + permissions: + contents: write + pull-requests: write + steps: + - id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + # pm-toolchain is calendar-versioned (a new year reads as semver-major), + # so it always auto-merges. Anything else must be classified minor or + # patch; a major or unclassified update waits for a person. + - if: >- + steps.metadata.outputs.dependency-group == 'pm-toolchain' || + steps.metadata.outputs.update-type == 'version-update:semver-minor' || + steps.metadata.outputs.update-type == 'version-update:semver-patch' + run: gh pr merge --auto --squash "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/CHANGELOG.md b/CHANGELOG.md index 7365532..ed73440 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## Unreleased + +### Other + +- Auto-merge green Dependabot updates and group the pm toolchain into one daily PR ([ops-k1lf](https://github.com/unbraind/pm-ops/blob/main/.agents/pm/tasks/ops-k1lf.toon)) + ## 2026.9.29 - 2026-09-29 ### Fixed