feat(config): estate canon — rulesets, gates map, repo settings, allowlist, autolink profiles (step 1 of #715) - #716
Conversation
…ngs, allowlist, autolink profiles (step 1 of #715) Machine-readable single source of truth for repo configuration: config/rulesets/{base,gates,gates-only,immutable-tags}.json, config/settings/{repo,actions-allowlist}.json, config/autolinks/*.json, config/README.adoc. Tier doc gains the ratified MUST list, the caller naming convention and two invariants. Spec gains §13 amendments. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ked hygiene (O12), gates never_required split by kind - ADR files are ADR-<num>-<slug>.adoc; the copied template ADR-<num>.adoc returned 404 on every repo (verified on standards). Canon now uses a code-search URL that keeps <num>. - verified_allowed=true means verified creators bypass patterns_allowed; the 118->92 prune is hygiene, R1 is enforced by deleting workflows. Flipping verified_allowed is O12, after a uses: census. - gates.json: never_required_workflows vs never_required_contexts so the applier never globs a context string. - README + spec §13 amended; direct-push consequence recorded.
|
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (14)
📝 SummarySummary by CodeRabbit
WalkthroughAdds canonical repository settings, Actions permissions, autolink profiles, branch and tag rulesets, gate-context derivation rules, and supporting CI/CD governance documentation. ChangesEstate CI/CD configuration canon
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant ConfigApplier
participant GitHubRepositoryAPI
participant DefaultBranchWorkflow
participant RulesetVerifier
ConfigApplier->>GitHubRepositoryAPI: Apply repository settings and permissions
ConfigApplier->>DefaultBranchWorkflow: Read latest default-branch check runs
DefaultBranchWorkflow-->>ConfigApplier: Return workflow check-run names
ConfigApplier->>GitHubRepositoryAPI: Apply derived branch and tag rulesets
ConfigApplier->>RulesetVerifier: Verify configuration
RulesetVerifier-->>ConfigApplier: Return verification status
Poem
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |



Step 1 of the CI/CD regularisation (spec: docs/superpowers/specs/2026-09-02-cicd-regularisation-design.md, owner batch #715).
Adds
config/:rulesets/base.json— branch ruleset (identity = target branch +~DEFAULT_BRANCH);gates-only.json(O6 option);immutable-tags.jsonrulesets/gates.json— which canonical callers are GATE per repo type; contexts are derived from the latest run, never typedsettings/repo.json,settings/actions-allowlist.json(118 → 92, hygiene; applied at the tail of the sweep)autolinks/{base,rust,proof,julia,elixir}.json— from a 428-repo audit; ADR- template fixed (live one 404s on every repo)README.adoc— what each file is, what base drops from live and why, apply orderAlso: MUST list + naming convention appended to
docs/CICD-SIGNAL-DISCIPLINE.adoc; spec §13 amendments (findings that changed the plan: no App credential on standards → O11; rulesets work on private Free → P-priv dropped;updaterule dropped; O12 allowlist enforcement).Nothing here is applied to any repo. The applier is step 3.
🤖 Generated with Claude Code