Skip to content

Release v1.1.1 - #59

Merged
skoonin merged 6 commits into
mainfrom
release/1.1.1
Jul 6, 2026
Merged

skoonin merged 6 commits into
mainfrom
release/1.1.1

Conversation

@skoonin

@skoonin skoonin commented Jul 6, 2026

Copy link
Copy Markdown
Owner

Release v1.1.1. Finalizes __version__ 1.1.1-dev → 1.1.1 and dates the CHANGELOG section.

Since 1.1.0 the changes are repository/CI hardening rather than CLI behavior:

Per the release process, a merge into main is expected to conflict on the version/changelog lines; resolve by taking the release branch's versions. After merge, dispatch cd-release.yaml from main to tag v1.1.1 and publish the Release, then bump dev to 1.1.2-dev.

skoonin and others added 6 commits December 2, 2025 09:45
* fix makefiles

* update changelog

* DEBUG TEST

* Revert "DEBUG TEST"

This reverts commit b2a6a01.

* chore: prepare repository for public release

Add LICENSE.md (Apache 2.0), CONTRIBUTING.md, update author metadata, add CD badge

* docs: clean up CHANGELOG version sections
…#41)

## What

Pin all GitHub Actions in both workflows to full-length commit SHAs
(with a `# vX.Y.Z` comment), and enable Dependabot to keep them current.

### Action pins (latest releases)

| Action | Was | Now | Version |
|---|---|---|---|
| `actions/checkout` | `@v4` |
`df4cb1c069e1874edd31b4311f1884172cec0e10` | v6.0.3 |
| `actions/setup-python` | `@v5` |
`a309ff8b426b58ec0e2a45f0f869d46889d02405` | v6.2.0 |
| `actions/cache` | `@v4` | `27d5ce7f107fe9357f9df03efb73ab90386fccae` |
v5.0.5 |

Applied across `ci-code.yaml` and `cd-release.yaml`.

### Dependabot

Added a `github-actions` ecosystem block to `.github/dependabot.yml`
(weekly). It reads the `# vX.Y.Z` comments and opens PRs that bump both
the SHA and the comment together. Created the `dependencies`, `python`,
and `github-actions` repo labels referenced by the config (none existed
previously).

## Why

SHA pinning protects against a moving/compromised tag; Dependabot
removes the manual upkeep that pinning otherwise requires.

## Notes

- These are major-version jumps (checkout v4->v6, cache v4->v5,
setup-python v5->v6). None of the documented breaking changes affect
this repo's usage (all runners are ubuntu-24.04 / macos-15 on Node 24).
- `.github/dependabot.yml` stays `.yml` by GitHub requirement;
everything else uses `.yaml`.
Rewires the auto-review workflow (added in #172) to run a committed,
CI-adapted version of the local `sk-review` orchestration instead of a
single-pass prompt, and points both Claude workflows at the `dev`
environment's `CC_API_KEY`.

## Review workflow — trimmed sk-review roster

`.claude/commands/sk-review-ci.md` drives the run:
1. **Context** — orchestrator gets the PR diff/base via `gh`, reads
CLAUDE.md conventions.
2. **Parallel review** — `code-reviewer`
(bugs/security/convention/data-loss) and `code-quality-pragmatist`
(over-engineering/YAGNI) run concurrently.
3. **Reality check** — `reality-check-manager` verifies each finding
against the actual code; rejected findings are dropped.
4. **Post** — inline comments for verified findings + one summary
comment.

This keeps sk-review's multi-perspective + anti-hallucination structure
at ~3 agents instead of the full 8, to bound per-PR cost.

## Vendored agents (`.claude/agents/`)

`/sk-review` and its agents live in personal `~/.claude/` and plugins —
absent from a CI checkout. The three needed agents are vendored into the
repo, CI-adapted:
- `code-reviewer` — from the feature-dev plugin, already read-only.
- `code-quality-pragmatist` — trimmed to Read/Grep/Glob.
- `reality-check-manager` — **`Edit`/`Write` removed** so it verifies,
not fixes.

Plugin namespaces (`@agent-feature-dev:...`) are rewritten to the
repo-local names. Files are `git add -f`'d because `.gitignore` ignores
`.claude/` — same precedent as the #172 workflow files.

## Auth / environment

Both workflows now read `anthropic_api_key: ${{ secrets.CC_API_KEY }}`
and declare `environment: dev`.

- Env secrets are only readable by a job that declares the environment —
hence the `environment: dev` line.
- **Caveat:** if the `dev` environment has required-reviewer or
wait-timer protection rules, both jobs (including the interactive
@claude responder) will *wait on those rules* before running. Noted in
an in-file comment. If that's undesirable for @claude, a plain repo
secret avoids it.

Still gated behind `CLAUDE_REVIEW_ENABLED` (off by default),
`opened`/`ready_for_review` only, same-repo guard, non-draft.
`--max-turns 40`, tools restricted to read + `gh pr` + inline-comment
(no Edit/Write/push).

## Not yet verified live

Headless subagent fan-out (the `Task` tool in the action runner) isn't
documented; the first live run should be watched to confirm the parallel
agents actually spawn. Safe to merge while gated off.
@skoonin
skoonin merged commit 245cdf3 into main Jul 6, 2026
18 checks passed
@skoonin
skoonin deleted the release/1.1.1 branch July 6, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant