Release v1.1.1 - #59
Merged
Merged
Conversation
* fix makefiles * update changelog * DEBUG TEST * Revert "DEBUG TEST" This reverts commit b2a6a01. * chore: prepare repository for public release Add LICENSE.md (Apache 2.0), CONTRIBUTING.md, update author metadata, add CD badge * docs: clean up CHANGELOG version sections
…#41) ## What Pin all GitHub Actions in both workflows to full-length commit SHAs (with a `# vX.Y.Z` comment), and enable Dependabot to keep them current. ### Action pins (latest releases) | Action | Was | Now | Version | |---|---|---|---| | `actions/checkout` | `@v4` | `df4cb1c069e1874edd31b4311f1884172cec0e10` | v6.0.3 | | `actions/setup-python` | `@v5` | `a309ff8b426b58ec0e2a45f0f869d46889d02405` | v6.2.0 | | `actions/cache` | `@v4` | `27d5ce7f107fe9357f9df03efb73ab90386fccae` | v5.0.5 | Applied across `ci-code.yaml` and `cd-release.yaml`. ### Dependabot Added a `github-actions` ecosystem block to `.github/dependabot.yml` (weekly). It reads the `# vX.Y.Z` comments and opens PRs that bump both the SHA and the comment together. Created the `dependencies`, `python`, and `github-actions` repo labels referenced by the config (none existed previously). ## Why SHA pinning protects against a moving/compromised tag; Dependabot removes the manual upkeep that pinning otherwise requires. ## Notes - These are major-version jumps (checkout v4->v6, cache v4->v5, setup-python v5->v6). None of the documented breaking changes affect this repo's usage (all runners are ubuntu-24.04 / macos-15 on Node 24). - `.github/dependabot.yml` stays `.yml` by GitHub requirement; everything else uses `.yaml`.
Rewires the auto-review workflow (added in #172) to run a committed,
CI-adapted version of the local `sk-review` orchestration instead of a
single-pass prompt, and points both Claude workflows at the `dev`
environment's `CC_API_KEY`.
## Review workflow — trimmed sk-review roster
`.claude/commands/sk-review-ci.md` drives the run:
1. **Context** — orchestrator gets the PR diff/base via `gh`, reads
CLAUDE.md conventions.
2. **Parallel review** — `code-reviewer`
(bugs/security/convention/data-loss) and `code-quality-pragmatist`
(over-engineering/YAGNI) run concurrently.
3. **Reality check** — `reality-check-manager` verifies each finding
against the actual code; rejected findings are dropped.
4. **Post** — inline comments for verified findings + one summary
comment.
This keeps sk-review's multi-perspective + anti-hallucination structure
at ~3 agents instead of the full 8, to bound per-PR cost.
## Vendored agents (`.claude/agents/`)
`/sk-review` and its agents live in personal `~/.claude/` and plugins —
absent from a CI checkout. The three needed agents are vendored into the
repo, CI-adapted:
- `code-reviewer` — from the feature-dev plugin, already read-only.
- `code-quality-pragmatist` — trimmed to Read/Grep/Glob.
- `reality-check-manager` — **`Edit`/`Write` removed** so it verifies,
not fixes.
Plugin namespaces (`@agent-feature-dev:...`) are rewritten to the
repo-local names. Files are `git add -f`'d because `.gitignore` ignores
`.claude/` — same precedent as the #172 workflow files.
## Auth / environment
Both workflows now read `anthropic_api_key: ${{ secrets.CC_API_KEY }}`
and declare `environment: dev`.
- Env secrets are only readable by a job that declares the environment —
hence the `environment: dev` line.
- **Caveat:** if the `dev` environment has required-reviewer or
wait-timer protection rules, both jobs (including the interactive
@claude responder) will *wait on those rules* before running. Noted in
an in-file comment. If that's undesirable for @claude, a plain repo
secret avoids it.
Still gated behind `CLAUDE_REVIEW_ENABLED` (off by default),
`opened`/`ready_for_review` only, same-repo guard, non-draft.
`--max-turns 40`, tools restricted to read + `gh pr` + inline-comment
(no Edit/Write/push).
## Not yet verified live
Headless subagent fan-out (the `Task` tool in the action runner) isn't
documented; the first live run should be watched to confirm the parallel
agents actually spawn. Safe to merge while gated off.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release v1.1.1. Finalizes
__version__1.1.1-dev→1.1.1and dates the CHANGELOG section.Since 1.1.0 the changes are repository/CI hardening rather than CLI behavior:
mainanddev(ci: Claude workflows (@claude + on-request review) and CodeQL #56)@clauderesponder on PRs, and apr-review-label-triggered automated review (ci: Claude workflows (@claude + on-request review) and CodeQL #56)Per the release process, a merge into
mainis expected to conflict on the version/changelog lines; resolve by taking the release branch's versions. After merge, dispatchcd-release.yamlfrommainto tagv1.1.1and publish the Release, then bumpdevto1.1.2-dev.