chore: sync 1 org-standard workflow stub(s) from petry-projects/.github - #474
Conversation
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
Next review available in: 1 minute Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
There was a problem hiding this comment.
Pull request overview
This PR syncs the org-standard GitHub Actions caller stub for the “initiative driver” workflow, keeping this repository aligned with the centralized initiative automation in petry-projects/.github-private.
Changes:
- Update the scheduled cron entry quoting in the workflow stub.
- Allow
GH_TOKENto be sourced fromGH_PAT_DON_PETRYwith a fallback toGH_PAT_WORKFLOWSfor dispatching the central workflow.
Comments suppressed due to low confidence (1)
.github/workflows/initiative-driver.yml:80
- The PAT guard now allows either
GH_PAT_DON_PETRYorGH_PAT_WORKFLOWS, but the emitted error still says onlyGH_PAT_WORKFLOWSis required. This is misleading when troubleshooting missing secrets.
GH_TOKEN: ${{ secrets.GH_PAT_DON_PETRY || secrets.GH_PAT_WORKFLOWS }}
run: |
if [ -z "${GH_TOKEN}" ]; then
echo "::error::GH_PAT_WORKFLOWS is required — a workflow_dispatch fired with GITHUB_TOKEN never starts a run."
exit 1
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Fixed the misleading error message in . The error now correctly indicates that either |
Dev-Lead — fix-bot-comment (applied)Changes committed and pushed. |
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: f4627ce893cd125421d1966eae2df931f1c93537
Cascade: triage → audit (triage: haiku 4.5 → deep: opus 4.8 + duck: o4-mini → audit: fable 5)
Summary
Standards-sync PR verified byte-for-byte against the upstream template in petry-projects/.github (standards/workflows/initiative-driver.yml): the GH_PAT_DON_PETRY || GH_PAT_WORKFLOWS fallback that triggered escalation exists verbatim in the org standard and was NOT injected in this PR, ruling out the credential-tampering hypothesis. The only divergence is a benign one-line error-message improvement (commit c838351), and the fast-uri 3.1.4 dev-dependency bump's integrity hash matches the npm registry exactly. All status checks (CodeQL, gitleaks, AgentShield, dependency-audit, tests) are now SUCCESS; the personal-PAT-primary pattern remains a real least-privilege concern but lives in the upstream standard and cannot be remediated by blocking this faithful sync.
Findings
- MINOR: GH_TOKEN prefers secrets.GH_PAT_DON_PETRY (personal PAT) over the shared secrets.GH_PAT_WORKFLOWS. Verified this fallback is copied verbatim from the org standard petry-projects/.github standards/workflows/initiative-driver.yml, so it is an intentional org-wide pattern, not an injection in this PR. Advisory: remediate upstream — a personal PAT ties org automation to one individual (offboarding/rotation risk, run attribution) versus a dedicated fine-grained workflow PAT or GitHub App installation token scoped to actions:write on petry-projects/.github-private. (
.github/workflows/initiative-driver.yml:76) - MINOR: The synced stub now diverges from the upstream template by one line: commit c838351 improved the guard error message ('Either GH_PAT_DON_PETRY or GH_PAT_WORKFLOWS is required') but the upstream standard still has the stale message. The next standards-sync run will flag or revert this drift. Upstream the fix to petry-projects/.github standards/workflows/initiative-driver.yml. (
.github/workflows/initiative-driver.yml:79) - MINOR: Commit f4627ce (dev-lead bot) bumped package-lock.json fast-uri 3.1.2 -> 3.1.4 inside a PR whose body claims workflow stubs are 'deployed verbatim' — unrelated scope creep by automation. The bump itself is safe: integrity sha512-8Jnbk... matches the npm registry record for fast-uri@3.1.4 (official Fastify package, published 2026-07-19, dev-only transitive), and npm audit passed. (
package-lock.json:3926) - INFO: Workflow security posture is sound: permissions restricted to contents: read, no pull_request_target, no untrusted expression interpolation into run blocks (only server-controlled github.repository), label filter only in the if: condition, concurrency guard present, 5-minute timeout. (
.github/workflows/initiative-driver.yml) - INFO: All status checks are SUCCESS at audit time (CodeQL x3, build-and-test, coverage, Node.js Tests, Playwright, AgentShield, gitleaks, dependency-audit, SonarCloud quality gate). The deep review's 'CI not green' finding reflected an in-progress snapshot and is now stale. mergeStateStatus BLOCKED solely reflects the pending required review.
Reviewed by the PR-review cascade (triage: haiku 4.5 → deep: opus 4.8 + duck: o4-mini → audit: fable 5). Reply if you need a human review.
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: c8383517e47f4534f259210370ce7f734b0045b9
Review mode: triage-approved (single reviewer)
Summary
Triage-approved confirmation review of a standards-sync PR. Independently re-verified: (1) the GH_PAT_DON_PETRY || GH_PAT_WORKFLOWS token fallback and double-quoted cron exist verbatim in the upstream org standard petry-projects/.github standards/workflows/initiative-driver.yml — not injected in this PR; (2) the fast-uri 3.1.4 lockfile bump's integrity hash matches the npm registry exactly (dev-only transitive dep). The only upstream divergence is a one-line error-message correction (commit c838351) that makes the guard message match the actual fallback logic. All CI checks green (CodeQL x3, gitleaks, AgentShield, dependency-audit/npm audit, tests, SonarCloud); the only in-progress check is this review run itself. Prior full cascade approved this same SHA at MEDIUM risk. Confirms the triage assessment.
Linked issue analysis
No linked issues — expected for an automated standards-sync PR opened by scripts/deploy-standard-workflows.sh. The PR body accurately describes the change.
Findings
- MINOR (advisory, upstream):
GH_TOKENprefers a personal PAT (GH_PAT_DON_PETRY) over the sharedGH_PAT_WORKFLOWS. Verified verbatim in the org standard, so it is the sanctioned pattern, not an injection — but it ties org automation to one individual (offboarding/rotation risk). Remediate upstream inpetry-projects/.github, not by blocking this sync. (.github/workflows/initiative-driver.yml:76) - MINOR (advisory, upstream): The corrected guard error message ("Either GH_PAT_DON_PETRY or GH_PAT_WORKFLOWS is required") is a genuine improvement but now diverges by one line from the upstream template, which still has the stale message. The next standards-sync run may revert it — upstream the fix. (
.github/workflows/initiative-driver.yml:79) - INFO:
fast-uri3.1.2 → 3.1.4 lockfile bump verified: integritysha512-8JnbkQ4j...matches the npm registry record for the official package; dev-only transitive; npm audit passed. - INFO: Workflow security posture sound:
permissions: contents: read, nopull_request_target, no untrusted expression interpolation, concurrency guard, 5-minute timeout. - NOTE:
run_secret_scanningMCP tool unavailable in this environment; gitleaks CI check passed (SUCCESS).
CI status
All completed checks SUCCESS: CodeQL (actions, javascript-typescript, python), build-and-test, coverage, Node.js Tests, Playwright UI Tests, AgentShield, gitleaks secret scan, dependency-audit (npm audit), SonarCloud quality gate, CodeRabbit. Non-applicable ecosystem audits SKIPPED. Only in-progress check is this review workflow run itself.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
…ub (#474) * chore: sync 1 org-standard workflow stub(s) from petry-projects/.github * chore: dev-lead update (review-changes) [skip ci-relay] * fix(bot): address bot feedback [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
… code (#465) * Create README.md * Create code.gs * Create config.gs * Update README.md * Update README.md * enhanced Readme * ci: add CodeQL analysis workflow for PRs * feat(tests): add Jest tests, mocks, setup, and CI workflow * docs: add agents.md (canonical AGENTS.md guidance adapted) * docs: normalize to AGENTS.md and add canonical guidance * feat(calendar-to-sheets): add package implementation, tests, and README * chore(calendar-to-sheets): add GAS wrapper (code.gs) and config (config.gs); document files in README * Move scripts into src/, update tests/README/jest config, regenerate coverage * calendar-to-sheets: export GAS wrapper for testing; add test for syncAllCalendarsToSheetsGAS to handle multiple configs * Initial plan * Initial plan * Initial plan * Initial plan * Initial plan * Initial plan * Initial plan * Handle missing or malformed config gracefully - Modified getConfigs() to return legacy/default config when SYNC_CONFIGS is empty array - Added null checks in getCheckpointKey() to handle null cfg - Added null checks in syncAllCalendarsToSheetsGAS() error logging - Added comprehensive tests for empty and malformed SYNC_CONFIGS scenarios - All tests passing Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Initial plan * feat(codeql): upgrade CodeQL action versions to v3 for improved analysis * feat(tests): add tests for full resync functionality and error handling in calendar sync * Initial plan * fix: remove empty lines after unused variable cleanup Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Initial plan * Initial plan * Initial plan * Initial plan * fix(calendar-to-sheets): improve regex to catch leading whitespace/control chars before formula injection Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * test(calendar-to-sheets): cover ensureHeader path * Initial plan * Issue #24 - Add document rebuild capability to gmail-to-drive-by-labels (#25) * Initial plan * Add rebuild doc functionality to gmail-to-drive-by-labels Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Address code review feedback and improve documentation clarity Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Use setText('') for more efficient document clearing Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Update test-utils/mocks.js Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update src/gmail-to-drive-by-labels/tests/rebuild.test.js Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Address code review feedback: fix imports, comments, and add error handling tests Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Implement batching and resumable state for rebuild to handle large labels Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix logging message for remaining threads calculation Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix syntax error in mocks.js - add missing comma after setText Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Add comprehensive tests for gmail-to-drive-by-labels/code.gs functions Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Improve test coverage with additional edge case tests - 99.48% lines Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Add istanbul ignore comments for uncoverable defensive error handling Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Make rebuild batch size configurable with default of 250 Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Remove istanbul ignore comments and adjust coverage threshold to 99% Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Add rule to AGENTS.md prohibiting coverage ignore comments Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * chore: add pre-commit config, commitlint, and husky hooks for code quality (#35) * Initial plan * Add TypeScript, ESLint, Prettier with CI Pipeline Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix CI: upgrade Node.js from 18 to 20 (ESLint 10 requires Node 20+) Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix prettier formatting in AGENTS.md Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix createThread addLabel using arrow function with this Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Update package.json Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update test-utils/mocks.js Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update .github/workflows/ci.yml Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update src/calendar-to-sheets/code.gs Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Upgrade jest to v30 to align with @types/jest v30 Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Fix prettier CI failure, add husky pre-commit hook with shared check script Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * chore: add .pre-commit-config.yaml with check-merge-conflict and check-yaml hooks Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * Also enable typecheck in pre-commit hook Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> * chore: add commitlint with conventional commits config and commit-msg hook Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: don-petry <36422719+don-petry@users.noreply.github.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * chore(deps): bump github/codeql-action from 3 to 4 (#41) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/checkout from 4 to 6 (#43) Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs(agents): add guidance to resolve PR review threads after addressing comments Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Claude Code GitHub Action (#81) * Add Claude Code GitHub Action for PR reviews * fix: address review feedback on Claude Code workflow - Restrict issue_comment trigger to PR comments only - Add author-association check (OWNER/MEMBER/COLLABORATOR) - Add pull_request_review_comment trigger - Add timeout-minutes to prevent runaway jobs Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: use CLAUDE_CODE_OAUTH_TOKEN org secret Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add id-token: write permission for OAuth auth Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address remaining review comments - Pin claude-code-action to commit SHA for supply-chain safety - Add fork PR guard (secrets unavailable for fork PRs) - Scope pull_request trigger to main branch - Use >- folded scalar for if expression Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: DJ <dj@Rachels-Air.localdomain> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address OpenSSF Scorecard findings (#91) * fix: address OpenSSF Scorecard findings - Add SECURITY.md (#85) - Scope workflow token permissions to least privilege (#86) - Pin all GitHub Action dependencies to commit SHAs (#87) - Update vulnerable dependencies via npm audit fix (#88) - Add schedule trigger to CodeQL for full SAST coverage (#89) - Ensure CI and SAST run on all pushes and PRs (#90) Closes #85, #86, #87, #88, #89, #90 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address PR review comments - Replace permissions: read-all with permissions: {} (deny-by-default) - Use concrete version target (main branch) in SECURITY.md Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add actions: write permission for cache and artifact jobs Jobs using actions/cache and actions/upload-artifact need actions: write permission at the job level to function correctly with deny-by-default workflow permissions. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * chore(ci): apply prettier/eslint auto-fixes * chore: re-trigger CI checks * fix: use claude_code_oauth_token instead of anthropic_api_key The action has separate inputs for API keys vs OAuth tokens. CLAUDE_CODE_OAUTH_TOKEN is an OAuth token, not an API key. --------- Co-authored-by: DJ <dj@Rachels-Air.localdomain> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * chore(deps): bump anthropics/claude-code-action from 1.0.80 to 1.0.82 (#96) Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.80 to 1.0.82. - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@094bd24...88c168b) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.82 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * ci: skip Claude Code reviewer on Dependabot PRs (#100) * ci: skip Claude Code reviewer on Dependabot PRs The claude workflow fails on Dependabot PRs because secrets (CLAUDE_CODE_OAUTH_TOKEN) are not available to the dependabot actor. This blocks the dependabot auto-merge automation when claude is a required status check. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: use PR author login instead of github.actor for Dependabot check github.actor reflects who triggered the workflow run (e.g. a maintainer reopening), not the PR author. Use github.event.pull_request.user.login for reliable Dependabot detection, consistent with dependabot-automerge.yml. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: DJ <dj@Rachels-Air.localdomain> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: move Dependabot exclusion to step-level in Claude workflow (#101) * ci: move Dependabot exclusion to step-level in Claude workflow Move the dependabot[bot] check from job-level `if` to step-level `if` so the claude job runs and reports SUCCESS (with a skipped step) instead of being skipped entirely. A skipped job doesn't satisfy required status checks in branch protection, but a successful job with a skipped step does. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: guard step-level Dependabot check for pull_request events only The step-level if needs to handle issue_comment and pull_request_review_comment events where github.event.pull_request is not present. Use event_name guard to avoid null dereference. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: DJ <dj@Rachels-Air.localdomain> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * chore: enable Claude issue trigger per org CI standard (#119) Add issues:[labeled] event trigger and claude label support so Claude can work issues autonomously — reading the issue, creating a branch, implementing the fix, and opening a PR. Changes: - Add issues:[labeled] trigger to on: block - Add issue label condition to job if: guard - Upgrade contents permission to write (needed for branch creation) - Pin claude-code-action to v1.0.89 (6e2bd528) - Add label_trigger: "claude" input - Add dependabot skip condition on step - Add permission comment for contents: write Matches the standard defined in petry-projects/.github#24. Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add checkout step to Claude workflow for issue-triggered mode (#120) * fix: add checkout step to Claude workflow for issue-triggered mode The claude-code-action runs git fetch/checkout internally during branch setup but requires the repository to already be cloned on the runner. Without actions/checkout, issue-triggered runs fail with: fatal: not a git repository Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * style: apply prettier formatting to claude.yml Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add concurrency group to dependabot update workflow (#130) Prevents overlapping runs when multiple pushes to main happen in quick succession. Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: split Claude workflow into interactive + issue automation jobs (#132) * feat: split Claude workflow into interactive + issue automation jobs Align with org CI standard. The single `claude` job is now split into: - `claude`: interactive mode for PR reviews and @claude mentions - `claude-issue`: automation mode triggered by the `claude` label on issues, with explicit allowed tools, progress tracking, and a structured prompt that implements, opens a PR, self-reviews, checks CI, and notifies owners. Adds `actions: read` and `checks: read` permissions to both jobs. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add concurrency guard and comment tools to claude-issue job - Add concurrency group keyed on issue number to prevent duplicate runs - Add gh pr comment and gh issue comment to allowedTools for review replies, thread resolution, and code owner tagging - Remove Bash(cat:*) since the Read tool already covers file reads Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * style: use single quotes for prettier consistency Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: switch to org-level reusable Claude Code workflow (#134) * chore: add CODEOWNERS file for code owner review enforcement Resolves missing-codeowners compliance finding by adding .github/CODEOWNERS with @don-petry as the default owner for all files in the repository. Closes #113 Co-authored-by: don-petry <don-petry@users.noreply.github.com> * chore(workflows): adopt centralized stubs from petry-projects/.github (#149) Replace inline copies of standardized workflows with the canonical thin caller stubs from petry-projects/.github/standards/workflows/. Each stub delegates to a versioned reusable workflow at petry-projects/.github/.github/workflows/<name>-reusable.yml@v1, so future updates to the standard propagate automatically and drift is caught by the org-wide compliance audit. See petry-projects/.github#87, #88, #89 for context. Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: add codeql.yml with javascript-typescript and actions scanning (#153) Renames codeql-analysis.yml → codeql.yml to satisfy the compliance requirement (issue #103). Updates the configuration to match org standards: - Use javascript-typescript language (required for repos with package.json) - Add actions language (required for repos with .github/workflows/*.yml) - Multi-language matrix strategy with per-language category tags - Weekly schedule aligned to org standard (Friday 17:00 UTC) Closes #103 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: don-petry <don-petry@users.noreply.github.com> * ci: add auto-rebase workflow and check_run trigger to claude.yml * add check_run trigger to claude.yml * add auto-rebase.yml workflow * chore: add bot accounts to CODEOWNERS for auto-merge support Add @petry-projects-pr-review-agent and @dependabot-automerge-petry as co-owners so their approvals satisfy require_code_owner_review in the pr-quality ruleset. * chore(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (#244) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.1 to 4.35.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@c10b806...e46ed2c) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.35.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: standardize CODEOWNERS on @petry-projects/org-leads (#252) Per the org-wide standard defined in petry-projects/.github (standards/codeowners-standard.md), replace individual user/bot listings with the @petry-projects/org-leads team. Closes the CODEOWNERS gap from pr-review-agent#27. Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> * chore(dev-lead): remove claude.yml — replaced by dev-lead.yml (#277) * chore: ignore .dev-lead directory (#291) feat: implement issue #255 — Compliance: codeowners-no-catchall Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> * ci: remove drift codeql.yml and enable GitHub-managed default setup (#216) Per ci-standards §2, the GitHub-managed default setup is the required approach for CodeQL scanning. A per-repo codeql.yml is treated as drift by the compliance audit and causes double CI billing when both run. Enabled default setup via API (state=configured, query_suite=default, run_id=24189972152). Removes the inline codeql.yml workflow file. Closes #168 Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: don-petry <don-petry@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * chore(deps-dev): bump fast-uri from 3.1.1 to 3.1.2 in the npm_and_yarn group across 1 directory (#263) chore(deps-dev): bump fast-uri Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri). Updates `fast-uri` from 3.1.1 to 3.1.2 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.1...v3.1.2) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com> * feat: implement issue #254 — Compliance: codeowners-org-leads-not-first (#300) * feat: implement issue #254 — Compliance: codeowners-org-leads-not-first * ci: trigger CI for compliance PR #300 --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * feat: implement issue #258 — Compliance: check-suite-auto-trigger-347564 (#307) Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> * feat: implement issue #442 — SonarCloud modernization (1/3): src/ app code * chore: dev-lead update (review-changes) [skip ci-relay] * chore: sync 1 org-standard workflow stub(s) from petry-projects/.github (#474) * chore: sync 1 org-standard workflow stub(s) from petry-projects/.github * chore: dev-lead update (review-changes) [skip ci-relay] * fix(bot): address bot feedback [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> * chore(deps-dev): bump fast-uri from 3.1.2 to 3.1.4 in the npm_and_yarn group across 1 directory (#469) chore(deps-dev): bump fast-uri Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri). Updates `fast-uri` from 3.1.2 to 3.1.4 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.2...v3.1.4) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: petry-projects-dependabot-automrg[bot] <270452309+petry-projects-dependabot-automrg[bot]@users.noreply.github.com> * chore: sync 4 org-standard workflow stub(s) from petry-projects/.github (#479) * chore: sync 4 org-standard workflow stub(s) from petry-projects/.github * chore: sync 4 org-standard workflow stub(s) from petry-projects/.github * chore: sync 4 org-standard workflow stub(s) from petry-projects/.github * chore: sync 4 org-standard workflow stub(s) from petry-projects/.github * chore: sync 1 org-standard workflow stub(s) from petry-projects/.github (#489) * chore: dev-lead update (review-changes) [skip ci-relay] * chore: dev-lead update (review-changes) [skip ci-relay] --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Don Petry <don.petry@gmail.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: DJ <dj@Rachels-MacBook-Air.local> Co-authored-by: DJ <dj@Rachels-Air.localdomain> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: don-petry <don-petry@users.noreply.github.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot-automerge-petry[bot] <270452309+dependabot-automerge-petry[bot]@users.noreply.github.com> Co-authored-by: petry-projects-dependabot-automrg[bot] <270452309+petry-projects-dependabot-automrg[bot]@users.noreply.github.com>



Syncs the following org-standard workflow stub(s) from
petry-projects/.github(standards/workflows/), deployed verbatim:initiative-driver.ymlOpened by
scripts/deploy-standard-workflows.sh. Stubs are thin callers; all behaviour lives in the reusables. Seestandards/ci-standards.md. Labeledstandards-syncand left for the normal review/auto-merge pipeline — the deploy script never merges directly.