Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,18 @@ INITIAL_PASSWORD=CHANGEME
# Encryption key for SQLite database encryption at rest.
# Used by: src/lib/db/encryption.ts — encrypts the entire SQLite database.
# Generate: openssl rand -hex 32 | Leave empty to disable DB encryption.
#
# ── Fail-closed behaviour (encryption-failclosed) ──
# When STORAGE_ENCRYPTION_KEY is set but the crypto layer fails (e.g. broken
# native bindings, key length drift after a Node upgrade, randomBytes OOM),
# OmniRoute refuses to write plaintext and surfaces:
# - EncryptionRuntimeError — runtime calls (encrypt() / encryptConnectionFields);
# surfaces as 500 to the user.
# - StartupEncryptionError — startup-canary in src/instrumentation-node.ts
# runs validateEncryptionAtStartup() at boot;
# process exits non-zero.
# Grep for these names in the logs to diagnose. Regenerate the key with:
# openssl rand -base64 32
STORAGE_ENCRYPTION_KEY=

# Version tag for the encryption key — allows future key rotation.
Expand Down
171 changes: 49 additions & 122 deletions .mergify.yml
Original file line number Diff line number Diff line change
@@ -1,59 +1,51 @@
# Mergify Configuration — Optimized for multi-language monorepos
# Docs: https://docs.mergify.com/
# Mergify merge queue — WS3.4/D5 of the v3.8.49 quality/velocity master plan.
#
# WHY: ~85-100 active PR authors/month and 300+ PRs/week peaks, all merged by ONE
# identity. The manual merge-train validated batches by hand; this queue automates
# it with batching + automatic batch bisection (a red batch of N costs ~log2(N)
# revalidations instead of N). Mergify Open Source plan: free, unlimited, public repo.
#
# GOVERNANCE (non-negotiable, mirrors CLAUDE.md Hard Rules #21/#22 + the owner's
# pre-merge ⭐ gate):
# • A PR enters the queue ONLY via the `queue` label — applied by the owner (or a
# session acting for the owner) AFTER the pre-merge ⭐ report/decision. The label
# IS the merge approval; Mergify only executes it.
# • During a release-freeze (open issue labeled `release-freeze`), do NOT label PRs
# targeting the frozen branch — the freeze is a human-honored coordination signal
# the queue cannot see. Retarget to the active release/vX+1 first (Hard Rule #21).
# • Never label a PR another session is actively working (Hard Rule #22b).
# • Fallback path if Mergify misbehaves or the OSS plan changes: the manual
# merge-train runbook (docs/ops/MERGE_TRAIN.md) — remove labels, proceed by hand.

pull_request_rules:
# Auto-merge when all CI checks pass and PR is approved
- name: Auto-merge when approved + CI green
conditions:
- "#review-requested=0"
- "#approved-reviews-by>=1"
- check-success=ci
- check-success=lint
- check-success=typecheck
- check-success=test
- -conflict
- -closed
actions:
merge:
method: squash
commit_message_template: |
{{ title }} (#{{ number }})

Co-authored-by: {{ author }}

# Auto-merge dependabot/Renovate PRs when CI passes
- name: Auto-merge dependency updates
conditions:
- or:
- author = dependabot[bot]
- author = renovate[bot]
- check-success=ci
- -conflict
- -closed
actions:
merge:
method: squash
commit_message_template: |
{{ title }} (#{{ number }})

Co-authored-by: {{ author }}

# Auto-merge bot PRs (CI configs, formatting) when CI passes
- name: Auto-merge bot housekeeping PRs
conditions:
- or:
- author = trunk-io[bot]
- author = mergify[bot]
- author = github-actions[bot]
- check-success=ci
- check-success=lint
queue_rules:
- name: release
# Any current or future release branch — the reason GitHub's native queue was
# rejected (no wildcard support on personal-account repos).
queue_conditions:
- base~=^release/v\d+\.\d+\.\d+$
- label=queue
- -draft
- -conflict
- -closed
actions:
merge:
method: squash
# "Everything that ran is green, nothing still running, AND the always-on
# anchor check succeeded" — robust to the path-filtered fast-gates (docs-only
# PRs skip code jobs; matrix shard names vary) while never fail-open: a PR with
# zero checks cannot vacuously merge, because `Merge integrity` runs on EVERY
# non-draft PR (quality.yml) and must be an affirmative success. Review approval
# is intentionally NOT a condition here: the owner-applied `queue` label IS the
# approval in this repo's single-maintainer model (see governance header).
merge_conditions:
- "#check-failure=0"
- "#check-pending=0"
- "#check-success>=1"
- "check-success=Merge integrity (changelog + generated skills)"
# Batching: validate up to 10 queued PRs together (the manual train's sweet spot);
# don't hold a lone PR hostage waiting for siblings.
batch_size: 10
batch_max_wait_time: 5 min
# Squash keeps the one-commit-per-PR history the CHANGELOG reconciliation expects.
merge_method: squash

# Add reviewers based on changed paths
pull_request_rules:
- name: Request review from team
conditions:
- -closed
Expand All @@ -64,75 +56,10 @@ pull_request_rules:
users:
- KooshaPari

# Label PRs based on changed files
- name: Label Python changes
conditions:
- files~=\.py$
actions:
label:
add:
- python

- name: Label Rust changes
conditions:
- files~=\.rs$|Cargo\.
actions:
label:
add:
- rust

- name: Label Go changes
conditions:
- files~=\.go$|go\.
actions:
label:
add:
- go

- name: Label TypeScript changes
conditions:
- files~=\.ts$|\.tsx$|package\.json
actions:
label:
add:
- typescript

# Close stale PRs after 30 days
- name: Close stale PRs
- name: clean up the queue label after merge
conditions:
- -closed
- -draft
- created-at <= 30 days ago
- "#review-requested=0"
actions:
comment:
message: >
This PR has been automatically closed after 30 days of inactivity.
Feel free to reopen if still relevant.
close: {}

# Warn on large PRs
- name: Warn on large PRs
conditions:
- -closed
- -draft
- "#files>20"
actions:
comment:
message: >
**Large PR Alert**: This PR touches {{ number }} files.
Consider splitting into smaller PRs for easier review.

# Add ready-to-merge label when all checks pass
- name: Add ready-to-merge label
conditions:
- -closed
- -draft
- check-success=ci
- check-success=lint
- check-success=test
- "#approved-reviews-by>=1"
- merged
actions:
label:
add:
- ready-to-merge
remove:
- queue
2 changes: 1 addition & 1 deletion electron/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
},
"publish": {
"provider": "github",
"owner": "diegosouzapw",
"owner": "KooshaPari",
"repo": "OmniRoute"
},
"files": [
Expand Down
Loading