-
Notifications
You must be signed in to change notification settings - Fork 1
feat: implement issue #361 — Compliance: non-stub-feature-ideation.yml #362
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
89 commits
Select commit
Hold shift + click to select a range
a853492
feat: initial BMad Operations Suite module
30d90f5
refactor: rename module from ops to bmad-bgreat-suite (bgr)
7007ad0
feat: enhance workflow output templates with advanced operational sec…
b34744f
Fix PR review feedback: table formatting, code fence tag, duplicate s…
74bd8bb
fix: resolve markdown formatting issues flagged in review
56c819b
fix: add language tag to remaining fenced code block in observability…
1cfea7f
feat: add CI workflows, dependabot config, and CODEOWNERS (#29)
don-petry 09a41d6
chore: add Claude Code workflow per org CI standard (#39)
don-petry a8a6aad
feat: split Claude workflow into interactive + issue automation jobs …
don-petry c08e8e3
feat: harden Riley DevOps enforcement — zero manual changes, environm…
don-petry 2cfc82a
feat: switch to org-level reusable Claude Code workflow
don-petry 55c1c1e
chore(workflows): adopt centralized stubs from petry-projects/.github…
don-petry 8a3e7ec
chore(workflows): adopt centralized claude.yml stub (#81)
don-petry 12e8fcd
ci: add auto-rebase workflow and check_run trigger to claude.yml (#126)
don-petry 5007e9a
chore(dev-lead): remove claude.yml — replaced by dev-lead.yml (#151)
don-petry 30a59b7
chore: remove stray codeql.yml workflow (#96)
don-petry f3d78a8
chore: remove stray codeql.yml (CodeQL via default setup) (#105)
don-petry 27ea9f9
feat: implement issue #146 — Compliance: secret_scanning_non_provider…
don-petry ae6f0ae
feat: implement issue #84 — Compliance: unpinned-actions-claude.yml (…
don-petry 61dd9e6
feat: implement issue #83 — Compliance: unpinned-actions-agent-shield…
don-petry 5bb76da
feat: implement issue #85 — Compliance: unpinned-actions-dependabot-a…
don-petry f80a6b7
feat: implement issue #86 — Compliance: unpinned-actions-dependency-a…
don-petry 3db971e
feat: implement issue #140 — Compliance: check-suite-auto-trigger-347…
don-petry bbbfde9
feat: implement issue #200 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 7e06961
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] f195067
chore(compliance): add in-progress label to labels.yml (#117)
don-petry 4c5aaa6
rollout: deploy pr-review-mention standard workflow (#236)
don-petry f1c08b1
chore(deps): bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 (#235)
dependabot[bot] 523d067
feat: add pr-auto-review.yml workflow (compliance automation Phase 2)…
don-petry 86c7f90
chore(deps): bump petry-projects/.github/.github/workflows/pr-review-…
dependabot[bot] 1aac672
fix: correct pr-auto-review reusable workflow reference (#238)
don-petry 1e42a03
feat: implement issue #216 — Compliance: copilot-instructions-missing…
don-petry b225555
chore(deps): bump SonarSource/sonarqube-scan-action from 7.1.0 to 8.0…
dependabot[bot] 2cbc4eb
feat: implement issue #83 — Compliance: unpinned-actions-agent-shield…
don-petry 75a490d
feat: implement issue #212 — Compliance: non-stub-agent-shield.yml (#…
don-petry 5fcfc40
feat: implement issue #91 — Compliance: stray-codeql-workflow (#241)
don-petry a07fd99
feat: implement issue #84 — Compliance: unpinned-actions-claude.yml (…
don-petry 7507a68
feat: implement issue #90 — Compliance: codeql-default-setup-not-conf…
don-petry cded0f3
feat: implement issue #219 — Compliance: secret_scanning_non_provider…
don-petry bcc9ad9
feat: implement issue #314 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 8db8d39
feat: implement issue #184 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 6940b71
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] 967c613
feat: implement issue #141 — Compliance: secret_scan_ci_job_present (…
don-petry 2739722
feat: implement issue #305 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 2e6a8bd
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] 4c4bc5d
ci: remove deprecated claude.yml (decommission claude-code, #665) (#365)
don-petry 9826e98
feat: initial BMad Operations Suite module
80cdab4
refactor: rename module from ops to bmad-bgreat-suite (bgr)
b8bca8d
feat: enhance workflow output templates with advanced operational sec…
b408529
Fix PR review feedback: table formatting, code fence tag, duplicate s…
3d4da30
feat: add CI workflows, dependabot config, and CODEOWNERS (#29)
don-petry 329a5ac
chore: add Claude Code workflow per org CI standard (#39)
don-petry a761969
feat: split Claude workflow into interactive + issue automation jobs …
don-petry cfa8eb4
feat: switch to org-level reusable Claude Code workflow
don-petry 19f9a4d
chore(workflows): adopt centralized stubs from petry-projects/.github…
don-petry dfb4a18
chore(workflows): adopt centralized claude.yml stub (#81)
don-petry 7be977f
ci: add auto-rebase workflow and check_run trigger to claude.yml (#126)
don-petry fe9969d
chore(dev-lead): remove claude.yml — replaced by dev-lead.yml (#151)
don-petry c3cceed
chore: remove stray codeql.yml workflow (#96)
don-petry 8b51047
chore: remove stray codeql.yml (CodeQL via default setup) (#105)
don-petry 782c48f
feat: implement issue #146 — Compliance: secret_scanning_non_provider…
don-petry 240929a
feat: implement issue #84 — Compliance: unpinned-actions-claude.yml (…
don-petry cd073cb
feat: implement issue #83 — Compliance: unpinned-actions-agent-shield…
don-petry e2b7bc6
feat: implement issue #85 — Compliance: unpinned-actions-dependabot-a…
don-petry a9ce688
feat: implement issue #86 — Compliance: unpinned-actions-dependency-a…
don-petry f027103
feat: implement issue #140 — Compliance: check-suite-auto-trigger-347…
don-petry f8633b9
feat: implement issue #200 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry f517719
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] d70616b
chore(compliance): add in-progress label to labels.yml (#117)
don-petry 4083080
rollout: deploy pr-review-mention standard workflow (#236)
don-petry d337a0d
chore(deps): bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 (#235)
dependabot[bot] 9fa1e75
feat: add pr-auto-review.yml workflow (compliance automation Phase 2)…
don-petry 1dfb561
chore(deps): bump petry-projects/.github/.github/workflows/pr-review-…
dependabot[bot] b4c0229
fix: correct pr-auto-review reusable workflow reference (#238)
don-petry 5938f60
feat: implement issue #216 — Compliance: copilot-instructions-missing…
don-petry 65fcd74
chore(deps): bump SonarSource/sonarqube-scan-action from 7.1.0 to 8.0…
dependabot[bot] 8d55001
feat: implement issue #83 — Compliance: unpinned-actions-agent-shield…
don-petry bcb3c7e
feat: implement issue #212 — Compliance: non-stub-agent-shield.yml (#…
don-petry a5cd081
feat: implement issue #91 — Compliance: stray-codeql-workflow (#241)
don-petry e4b76aa
feat: implement issue #84 — Compliance: unpinned-actions-claude.yml (…
don-petry 49d7589
feat: implement issue #184 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 6789d36
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] f5eefbd
feat: implement issue #305 — [Fleet Monitor] petry-projects/bmad-bgre…
don-petry 792d5bb
chore(deps): bump petry-projects/.github/.github/workflows/claude-cod…
dependabot[bot] 051bc8e
fix: remove duplicate code blocks in test-repo-settings.sh
donpetry-bot c4e2992
fix: remove github.event.discussion.user.type check in feature-ideati…
donpetry-bot e60f146
fix(bot): address bot feedback [skip ci-relay]
donpetry-bot e1a0fee
Merge branch 'main' into dev-lead/issue-361-20260710-1444
don-petry 4200daf
chore: dev-lead update (review-changes) [skip ci-relay]
donpetry-bot File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,68 @@ | ||
| # ───────────────────────────────────────────────────────────────────────────── | ||
| # SOURCE OF TRUTH: petry-projects/.github/standards/workflows/claude.yml | ||
| # Standard: petry-projects/.github/standards/ci-standards.md#4-claude-code-claudeyml | ||
| # Reusable: petry-projects/.github/.github/workflows/claude-code-reusable.yml | ||
| # | ||
| # AGENTS — READ BEFORE EDITING: | ||
| # • This file is a THIN CALLER STUB. All Claude Code logic, the prompt, | ||
| # allowedTools, and trigger gating live in the reusable workflow above. | ||
| # • You MAY change: nothing in this file in normal use. Adopt verbatim. | ||
| # • You MUST NOT change: trigger events, job permissions, the `uses:` line, | ||
| # or `secrets: inherit`. These are required for the reusable to work. | ||
| # • If you need different behaviour, open a PR against the reusable in the | ||
| # central repo. The change will propagate everywhere on next run. | ||
| # | ||
| # WHY THIS FILE IS IMMUTABLE (agents: read before opening any PR here): | ||
| # Anthropic's OIDC token endpoint validates that this file on a PR branch | ||
| # is byte-for-byte identical to the file on the default branch. Any diff — | ||
| # even a whitespace or comment change — causes the token exchange to fail: | ||
| # "401 Unauthorized — Workflow validation failed" | ||
| # Claude Code will not run on that PR. Do not open compliance PRs against | ||
| # this file. Do not SHA-pin the `uses:` line — internal reusable workflow | ||
| # refs are exempt from the Action Pinning Policy (ci-standards.md | ||
| # §Action Pinning Policy). The @v1 tag is the correct, stable reference. | ||
| # | ||
| # NARROW GUARD: The paths-ignore setting (lines 38-39) under pull_request | ||
| # prevents the workflow from triggering only when the PR's entire changeset | ||
| # is limited to claude.yml alone. PRs that modify claude.yml *plus other | ||
| # files* will still trigger the workflow and hit the 401 error at token | ||
| # exchange. Other triggers (issue_comment, pull_request_review_comment, | ||
| # issues, check_run) are unaffected by paths-ignore and run as configured. | ||
| # ───────────────────────────────────────────────────────────────────────────── | ||
| # | ||
| # Claude Code — thin caller that delegates to the org-level reusable workflow. | ||
| # To adopt: copy this file to .github/workflows/claude.yml in your repo. | ||
| # Required org/repo secret: CLAUDE_CODE_OAUTH_TOKEN | ||
| # Optional org/repo secret: GH_PAT_WORKFLOWS (PAT with `workflow` scope — | ||
| # required if Claude needs to push changes to .github/workflows/*.yml) | ||
|
|
||
| name: Claude Code | ||
|
|
||
| on: | ||
| pull_request: | ||
| branches: [main] | ||
| types: [opened, reopened, synchronize] | ||
| paths-ignore: | ||
| - '.github/workflows/claude.yml' # OIDC invariant — see header above | ||
| issue_comment: | ||
| types: [created] | ||
| pull_request_review_comment: | ||
| types: [created] | ||
| issues: | ||
| types: [labeled] | ||
| check_run: | ||
| types: [completed] | ||
|
|
||
| permissions: {} | ||
|
|
||
| jobs: | ||
| claude-code: | ||
| uses: petry-projects/.github/.github/workflows/claude-code-reusable.yml@v2 | ||
|
don-petry marked this conversation as resolved.
|
||
| secrets: inherit | ||
|
github-advanced-security[bot] marked this conversation as resolved.
Fixed
don-petry marked this conversation as resolved.
|
||
| permissions: | ||
| contents: write | ||
| id-token: write | ||
| pull-requests: write | ||
| issues: write | ||
| actions: read | ||
| checks: read | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.