Skip to content

sync: dev -> master - #8

Merged
xormania merged 16 commits into
masterfrom
dev
Sep 1, 2026
Merged

sync: dev -> master#8
xormania merged 16 commits into
masterfrom
dev

Conversation

@xor-machine

Copy link
Copy Markdown
Contributor

Stable sync per the master-through-dev topology (owner order, 2026-09-01): master receives dev's merged state by PR, never by direct push.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ

xormania and others added 8 commits September 1, 2026 12:07
…Claude pointer

AGENTS.md replaces the total git/GitHub prohibition with the
maintainer-directed lane (org CONTRIBUTING.md, decision of
2026-09-01): agents branch, commit, push, and open draft PRs under
maintainer direction with origin trailers; merging, releasing, and
settings remain the maintainer's. Content boundaries, supply-chain,
secret, naming, and positioning rules are preserved; the file no
longer names a server runtime, per the runtime supersession. Root
CLAUDE.md is added because Claude Code does not load AGENTS.md on
its own. .codex/config.toml drops its model pins: the model is
supplied at dispatch, never by repository config. README gains the
boundary/contribution-posture unsplice (the posture paragraphs had
been inserted mid-list, orphaning the closing line). Skills: the
inspect-first pair aligns its git rule with the lane; the
safe-repo-change pair stops naming a server runtime.

Source: owner 2026-09-01
Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
8.0 left maintenance in 07/2026; the pin dated from the repository's
May 2026 creation. Measured on the workbench's first boot from this
skeleton: bin/console about reported v8.0.15 end-of-maintenance
expired; with 8.1.* the same app resolves v8.1.6, maintained to
01/2027.

Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
Tracked .serena/project.yml and .mcp.json, uniform across the
MinSpec org, so every checkout and worktree of this repository is a
Serena-served agent workspace with identical scope. The PHP backend
is Phpactor (PHAR-managed, no Node). Mate is deliberately absent:
it is application-scoped by nature and lives in minspec/workbench,
the org's application host.

Source: owner 2026-09-01
Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
agents: adopt the maintainer-directed lane; unpin the model; add the Claude pointer
repo: bump the Flex pin to Symfony 8.1
repo: register Serena for agent sessions
CI on pull requests and on pushes to dev and the stable branch:
composer validate for PHP manifests, the create-project end-to-end
oracle where this repo is the skeleton, JSON/YAML validity
elsewhere. Public repo: GitHub-hosted runners are free; the check
name "ci" is the required context the dev ruleset will pin.

Source: owner 2026-09-01
Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
repo: real CI — the ci workflow on dev
xormania and others added 8 commits September 1, 2026 13:43
Findings applied from the independent audit (CHANGES verdict):
workflow-level permissions contents:read; persist-credentials false
on checkout; every action pinned to a reviewed commit SHA with its
tag in a comment; Serena pinned in .mcp.json to the audited git
commit instead of floating uvx resolution.

Finding: [P1] workflows ran with default token permissions
Finding: [P1] .mcp.json launched unversioned uvx serena
Finding: [P2] mutable action tags across all repositories
Verified: python yaml.safe_load + json.load on the changed files

Source: original
Co-Authored-By: GPT-5 Codex <noreply@openai.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reviewed-by: GPT-5 Codex <noreply@openai.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
First real CI run on this repo: composer validate --strict rejects
flex-require as outside the publish schema, but flex-require is how
a Flex seed declares its composition and the create-project step is
this repo's real oracle. Plain validate keeps schema checking
without denying the seed its mechanism.

Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
Plain validate still exits 2 on publish-schema errors, and
flex-require is exactly a publish-schema complaint. The flag skips
only that check; schema and structure checks remain, and
create-project stays the real oracle.

Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
repo: workflow and MCP hardening from the security audit
The skeleton is the road's first mile; its PRs now run the
canonical e2e from minspec/workbench via workflow_call — this PR's
code in the skeleton slot, siblings at dev. One test, owned in one
place, never copied.

Source: owner 2026-09-01 ("make it a real test and stick to it")
Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
repo: call the org road test on every change here
The maintainer's call: flex-require causes issues and is not proper.
The seed now declares its composition as plain require entries
pinned to the symfony line (8.1.*), which the publish schema
accepts, so composer validate --strict is restored in CI — the
earlier exemption fixed the oracle when the manifest was the defect.
Proven before push: create-project from this tree resolves and
boots v8.1.6.

Source: owner 2026-09-01 ("flex causes issues - its not proper")
Source: original
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XehTac5TJNmPAskwrPp7rJ
repo: proper require — flex-require retired
@xormania

xormania commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

@codex security review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review Completed 2026-09-01T21:23:32.431480Z 6b45bbe Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Security review completed. No security issues were found in this pull request.

Reviewed commit: 6b45bbe906

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@xormania
xormania merged commit 23913c7 into master Sep 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants