Skip to content

chore(dev-skills): bump .claude — /cso v1.1 Trinity-shape refresh#1594

Merged
dolho merged 1 commit into
devfrom
chore/bump-claude-cso-v1-1
Jul 14, 2026
Merged

chore(dev-skills): bump .claude — /cso v1.1 Trinity-shape refresh#1594
dolho merged 1 commit into
devfrom
chore/bump-claude-cso-v1-1

Conversation

@vybe

@vybe vybe commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Summary

Pointer bump of the private .claude submodule to trinity-dev 2bdd362 — the /cso security-audit skill refreshed against Trinity's current shape (architecture.md + TARGET_ARCHITECTURE.md).

Stale checks fixed (previously flagged intentional design or under-checked reality):

New-surface checks added:

Also adds the metadata.version/changelog block + what's-new banner (skill was previously unversioned).

Test plan

  • Skill structure verified intact after edits (all 15 phases, checklist, report format unchanged)
  • Submodule commit pushed to trinity-dev main (2bdd362)
  • Next /cso run confirms no false-fires on the setup-token / Redis / webhook checks

Docs-only skill change in the private submodule — no product code touched.

🤖 Generated with Claude Code

Pointer bump to trinity-dev 2bdd362: fixes stale audit checks (setup-token
removal ent#49, Redis ACL model, dual-track DB / two-network stack facts)
and adds checks for post-skill surfaces (agent-key self-boundaries
#307/#1083/#918, backend→agent auth #1159, webhook HMAC ent#77, vendored
parity Invariant #5, enumeration uniformity #186, MCP description leak
#846, backlog_metadata G-04 class, enterprise-docs-guard ent#45).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

⚠️ Nightly unit-suite check skipped — merge conflict against dev.

Resolve by running git merge dev locally and pushing the result. The next nightly run will re-test once the conflict is gone.

@dolho

dolho commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review — LGTM

Submodule pointer bump only (.claude 2228cfc72bdd362b). Confirmed locally that 2bdd362 is reachable and is the CSO v1.1 refactor commit (refactor(cso): Trinity-shape refresh — v1.1), so the pointer is not dangling. No product code touched; the skill doesn’t run in CI. CI green.

Standard submodule-bump caveat: the actual skill diff isn’t reviewable from the public repo (private trinity-dev), so the substance rides on the trinity-dev side. The stale-check corrections called out in the description (setup post-lockout instead of the removed bootstrap token ent#49, the real Redis ACL model + two-network invariant #589, dual-track SQLite+PG #1183, the by-design tokenless webhook ent#77) all match current architecture.md, so the refresh is pointed the right way.

Only open item is the unchecked box — a /cso run confirming no false-fires on the setup-token / Redis / webhook checks. Fine to land the pointer bump ahead of that.

@dolho
dolho merged commit 3cc3c6e into dev Jul 14, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants