Skip to content

Add standards engine, scaffolds and SSH-config layer - #2

Merged
imanimanyara merged 9 commits into
mainfrom
feat/session-wip-2026-05
Oct 2, 2026
Merged

imanimanyara merged 9 commits into
mainfrom
feat/session-wip-2026-05

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Commits work from the May 2026 session that was sitting uncommitted in the local checkout, grouped by concern, plus the follow-up fixes found while verifying it.

Feature commits (committed as found, no logic changes)

  • Add SSH-config awareness layer and multi-forge providers: gendia/ssh/ (config parser, forge registry, key auditor, account synthesiser), Gitea / Azure DevOps / Bitbucket Server providers, GitHub Enterprise host support, generate / scan / convert, gendia ssh, setup --from-ssh, ssh-keys section in doctor, manual_repos / forges_file config keys.
  • Add JSON-driven standards engine with rule packs and autofix: standards.py, 16 rule packs, 7 check kinds, 21 fix kinds behind conventions --fix [--dry-run]. Legacy checks still run unless --no-legacy.
  • Add init --scaffold with 13 bundled project templates: scaffolds.py, 13 scaffolds, new init flags.
  • Add interactive menu, compose targets and CI smoke steps: bin/gendia-menu, Makefile check / menu / compose targets, Dockerfile ships the menu, .dockerignore, smoke steps for bundled packs and scaffolds.
  • Document the standards engine, scaffolds and SSH layer: README and CHANGELOG [Unreleased].

Each feature commit was checked out on its own and passes pytest, ruff and mypy at that point (195 / 333 / 408 tests).

Follow-ups

  • Stop the changelog claiming design docs ship in docs/: those two files are planning artifacts and are not in this PR.
  • Run tests on pull_request and workflow_dispatch, not push: matches the org rule. CI no longer runs on push to main.
  • Merge origin/main: brings in the SECURITY.md routing change (Route vulnerability reports through private reporting and security@ #1). No conflicts.
  • Fix wheel build failing on duplicated bundled data: the new force-include block added every data file twice, so pip wheel (and therefore docker build and a release) failed with "A second file is being added to the wheel archive". packages = ["src/gendia"] already ships all 114 data files, so the redundant block is gone. A new smoke step builds the wheel and checks the data is inside. Editable installs never build a wheel, which is why CI did not catch this.

Intentionally left uncommitted

  • docs/repo-standards-and-audit.md (2,822 lines, the v3.0 design and integration plan) and docs/status.md (phase tracker). Both are design and audit artifacts. They stay untracked locally, listed in .git/info/exclude.
  • CLAUDE.md and .claude/: local agent config. Already ignored by the global gitignore.
  • .venv/, dist/, caches, .DS_Store, __pycache__/: already in .gitignore.

gitleaks finds nothing real. Its hits are key-header string constants in ssh/inspector.py and example commit SHAs in the excluded design doc.

Local verification

pytest 408 passed · ruff check and format clean · mypy --strict clean (71 files) · shellcheck clean · CLI smoke steps reproduced with a clean $HOME · wheel builds with all data files.

gendia only knew the forges it had a hand-written provider for, and the
accounts it could reach had to be typed into gendia.json by hand. Most
users already describe their forges in ~/.ssh/config, so reading that
file removes the double bookkeeping and lets gendia absorb the
standalone git-helpers script.

This adds the ssh/ package (config parser, JSON forge registry, key
auditor, account synthesiser), Gitea, Azure DevOps and Bitbucket Server
providers, GitHub Enterprise host support, the generate / scan / convert
operations, the `gendia ssh` command group, `setup --from-ssh`, an ssh
keys section in `doctor`, and the manual_repos / forges_file config keys.
The ten hardcoded checks in `gendia conventions` could only be extended
by editing Python. Declaring rules in JSON packs lets an org add or
override checks without a release, and lets the same rules drive fixes.

Adds standards.py with seven check kinds, a module:function plugin hook,
16 bundled rule packs, and 21 idempotent fix kinds behind
`conventions --fix [--dry-run]`. The legacy checks keep running unless
`--no-legacy` is passed, so existing callers see no change.
Starting a repo that already passes the standards packs meant copying
files from an older project. Scaffolds render a known-good layout per
ecosystem and can run the audit as a post-action, so a new repo starts
clean instead of being fixed afterwards.

Adds scaffolds.py (${var} rendering, git_init / license_text / audit
post-actions, path-traversal and symlink refusal), 13 bundled scaffolds
with 17 licence texts, and the --scaffold / --list-scaffolds / --var /
--target / --merge / --dry-run flags on `gendia init`. The data
directories are force-included in the wheel so installed copies find
them.
Eighteen verbs are hard to discover from --help alone. bin/gendia-menu
groups them by category and ships in the Docker image, and the Makefile
gains `check` (the CI gates in one target), `menu`, and compose
lifecycle targets. PYTHON now prefers 3.12+ because some hosts resolve
python3 to 3.10 without the dev tools.

The CI smoke job now asserts the bundled rule packs and scaffolds are
present in the installed wheel and that `--fix --dry-run` and the menu
still work, which catches a dropped force-include. .dockerignore trims
the build context.
Records the new verbs and flags in the README and an Unreleased section
in the CHANGELOG, so the next release notes can be cut from it.
The driver doc and phase tracker are planning artifacts and were not
committed, so the Unreleased entry pointed readers at files that are not
in the repository.
A push trigger on main runs after a change has landed and double-runs
every merge. CI belongs on the pull request, with workflow_dispatch so a
maintainer can re-run it by hand.
`packages = ["src/gendia"]` already ships every file under
src/gendia/data, so the force-include block added each data file a
second time and hatchling refused to build: "A second file is being
added to the wheel archive at the same path". The editable install CI
uses never builds a wheel, so this only surfaced in `pip wheel`, which
is what the Dockerfile builder stage and a release run.

Drop the redundant force-include (the wheel still carries all 114 data
files) and add a smoke step that builds the wheel and asserts the data
directory is inside, so the failure is caught on the pull request.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 13:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 898455f into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants