diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index c0bc85ee..f5939dd8 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -55,8 +55,8 @@ Use squash merges unless the repository documents another strategy. Re-align `st ### Toolchain 1. Install [mise](https://mise.jdx.dev/). -2. Run `bash .github/scripts/bootstrap.sh` to install the pinned toolchain, enable hooks, and validate the checkout. -3. Use `bash .github/scripts/doctor.sh` when setup, lockfiles, or hooks appear out of sync. +2. Run `npx code-foundry init` to install the pinned toolchain, enable hooks, and validate the checkout. +3. Use `npx code-foundry doctor` when setup, lockfiles, or hooks appear out of sync. 4. Use the repository's existing package manager and lockfile. Do not introduce a second package manager. 5. Copy `.env.example` to the appropriate local environment file when provided. Never commit the copy. @@ -85,7 +85,7 @@ bash .github/scripts/ci.sh unit bash .github/scripts/ci.sh integration bash .github/scripts/ci.sh e2e bash .github/scripts/ci.sh smoke -bash .github/scripts/security.sh +Security and dependency audits run through the GitHub Security workflow. ``` Run the checks relevant to the change. For a release or security-sensitive change, run the complete set. Record the commands and results in the pull request. diff --git a/.github/code-foundry.yml.example b/.github/code-foundry.yml.example deleted file mode 100644 index d8235005..00000000 --- a/.github/code-foundry.yml.example +++ /dev/null @@ -1,41 +0,0 @@ -# `npx code-foundry init` creates this file automatically. Edit it and run -# `npx code-foundry sync` whenever you want to change the baseline. -# Omitted keys use automatic detection and the standard defaults. See -# docs/CONFIGURATION.md for the complete visual reference. - -version: 1 - -# Repository shape and supported languages. -profile: auto # auto, application, monorepo, minimal -languages: auto # auto or typescript,rust,python,solidity -package_manager: auto # auto, bun, pnpm, yarn, npm - -# Standard callers to install. Use `all` or a comma-separated selection. -features: all # ci, codeql, security, test, draft-pr, release-pr, release, dependabot - -# Runtime source. Leave blank to infer it from the template source. -runtime_repository: # OWNER/REPO, or leave blank to infer -runtime_ref: # tag or branch, or leave blank for default - -# Release and licensing behavior. -release_type: auto # auto, node, python, rust, simple, none -npm_publish: false -license: preserve # agpl-3.0-or-later, mit, preserve, none -# license_file: ./legal/LICENSE.txt - -# Runner policy. Each workflow caller receives its selected runner. -runner: ubuntu-latest -unit_runner: ubuntu-slim -ci_runner: ubuntu-latest -test_runner: ubuntu-latest -security_runner: ubuntu-slim -codeql_runner: ubuntu-latest -pr_runner: ubuntu-slim -release_runner: ubuntu-slim -prune_standard: false # remove disabled standard workflows during sync - -# Cache and quality policy. -cache_packages: auto # auto, true, false -cache_build: auto # auto, true, false -coverage_minimum: 80 -turbo_remote: auto # auto, true, false diff --git a/.github/scripts/doctor.sh b/.github/scripts/doctor.sh index 1faea3bf..b2f3a03f 100755 --- a/.github/scripts/doctor.sh +++ b/.github/scripts/doctor.sh @@ -66,11 +66,7 @@ if [ -f package.json ]; then fi if [ -f bunfig.toml ] && node -e 'const p=require("./package.json"); process.exit(p.scripts?.["test:coverage"] ? 0 : 1)' 2>/dev/null; then if ! grep -q 'coverageThreshold' bunfig.toml; then - if [ -x .github/scripts/ci.sh ]; then - printf '%s\n' "INFO: shared CI enforces the Bun aggregate coverage threshold" - else - error "Bun coverage is enabled by test:coverage but no coverage policy is configured" - fi + printf '%s\n' "INFO: shared CI enforces the Bun aggregate coverage threshold" fi fi fi @@ -92,11 +88,7 @@ for workflow in ci codeql security test draft-pr release-pr release; do fi done -for script in ci.sh profile.sh doctor.sh bootstrap.sh sync-template.sh init-repo.sh sync-protection.sh sync-codeowners.sh; do - [ -x ".github/scripts/$script" ] || error "missing executable script: .github/scripts/$script" -done - -printf '%s\n' 'Remote CI, Test, Security, and CodeQL runtimes are loaded by reusable workflow wrappers.' +printf '%s\n' 'Remote CI, Test, Security, CodeQL, and release runtimes are loaded by reusable workflow wrappers.' if [ "$errors" -gt 0 ]; then printf '%s\n' "Repository doctor found $errors error(s)." >&2 diff --git a/.github/scripts/init-repo.sh b/.github/scripts/init-repo.sh index 9f8a6272..7dcb8a5f 100755 --- a/.github/scripts/init-repo.sh +++ b/.github/scripts/init-repo.sh @@ -252,7 +252,9 @@ if [ "$bootstrap" = false ]; then exit 0 fi -bash .github/scripts/bootstrap.sh +bootstrap_script="$script_dir/bootstrap.sh" +[ -x "$bootstrap_script" ] || { echo "Package is missing bootstrap.sh" >&2; exit 1; } +bash "$bootstrap_script" if [ "$protection" = true ]; then remote="$(git remote get-url origin 2>/dev/null || true)" diff --git a/.github/scripts/sync-template.sh b/.github/scripts/sync-template.sh index bca4f451..8a557eef 100755 --- a/.github/scripts/sync-template.sh +++ b/.github/scripts/sync-template.sh @@ -313,7 +313,6 @@ files=( ruff.toml .prettierrc .github/CODEOWNERS - .github/code-foundry.yml.example .github/CODE_OF_CONDUCT.md .github/CONTRIBUTING.md .github/PULL_REQUEST_TEMPLATE.md @@ -322,18 +321,13 @@ files=( .github/ISSUE_TEMPLATE/bug_report.yml .github/ISSUE_TEMPLATE/config.yml .github/ISSUE_TEMPLATE/feature_request.yml + # Keep only the small local hook runner and its language-aware formatter. + # Full CI, security, CodeQL, and release implementations are loaded from + # the reusable runtime and are not copied into consumer repositories. .github/scripts/profile.sh - .github/scripts/bootstrap.sh - # Keep the small local hook runner and its changed-file helper; the full - # CI/security implementations used by Actions are loaded from the runtime. .github/scripts/changed-files.sh .github/scripts/ci.sh - .github/scripts/doctor.sh .github/scripts/pre-commit.sh - .github/scripts/sync-template.sh - .github/scripts/init-repo.sh - .github/scripts/sync-codeowners.sh - .github/scripts/sync-protection.sh .github/workflows/ci.yml .github/workflows/codeql.yml .github/workflows/draft-pr.yml @@ -358,6 +352,36 @@ for file in "${files[@]}"; do esac done files=("${filtered_files[@]}") +changed=0 + +# These files belonged to older Code Foundry layouts. They are intentionally +# removed now that the npm CLI owns initialization and synchronization. +removed_files=( + .github/code-foundry.yml.example + .github/template.yml + .github/template.yml.example + .github/scripts/bootstrap.sh + .github/scripts/codeql-languages.sh + .github/scripts/doctor.sh + .github/scripts/init-repo.sh + .github/scripts/security.sh + .github/scripts/sync-codeowners.sh + .github/scripts/sync-protection.sh + .github/scripts/sync-template.sh + .github/scripts/sitecustomize.py + .github/scripts/turbo-cache-probe.sh +) +for file in "${removed_files[@]}"; do + if [ -e "$file" ]; then + changed=$((changed + 1)) + if [ "$mode" = "check" ]; then + printf 'Would remove legacy managed file %s\n' "$file" + else + rm -f "$file" + printf 'Removed legacy managed file %s\n' "$file" + fi + fi +done # Workflows outside the standard baseline are repository-owned extensions. # The sync operation never deletes or replaces them; surface them explicitly @@ -390,7 +414,6 @@ if [ "${#custom_workflows[@]}" -gt 0 ]; then printf 'Preserving custom workflows: %s\n' "${custom_workflows[*]}" fi -changed=0 for file in "${files[@]}"; do template_file="$template_root/$file" # npm renames .gitignore to .npmignore when installing a package. Treat the @@ -629,11 +652,11 @@ initialize_mise_lock() { initialize_mise_lock -if [ -x .github/scripts/sync-codeowners.sh ]; then +if [ -x "$template_root/.github/scripts/sync-codeowners.sh" ]; then if [ "$mode" = "check" ]; then - bash .github/scripts/sync-codeowners.sh --check + bash "$template_root/.github/scripts/sync-codeowners.sh" --check else - bash .github/scripts/sync-codeowners.sh --apply + bash "$template_root/.github/scripts/sync-codeowners.sh" --apply fi fi diff --git a/AGENTS.md b/AGENTS.md index 62d7d2fb..abe7e84d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -62,7 +62,7 @@ Ask for clarification when a missing decision would materially change the implem 2. Inspect before editing; preserve unrelated work. 3. Plan the smallest coherent change. 4. Implement with existing project patterns. -5. Run bash .github/scripts/bootstrap.sh for a new checkout, or bash .github/scripts/doctor.sh to diagnose setup drift. +5. Run `npx code-foundry init` for a new checkout, or `npx code-foundry doctor` to diagnose setup drift. 6. Run focused checks while iterating. 7. Inspect the final diff for accidental changes, secrets, formatting, and generated files. 8. Run the broadest applicable validation available. @@ -96,7 +96,7 @@ bash .github/scripts/ci.sh unit bash .github/scripts/ci.sh integration bash .github/scripts/ci.sh e2e bash .github/scripts/ci.sh smoke -bash .github/scripts/security.sh +Security and dependency audits run through the GitHub Security workflow. ``` Run focused tests first, then the complete applicable set for release, security, workflow, dependency, and configuration changes. diff --git a/docs/INITIALIZATION.md b/docs/INITIALIZATION.md index 2e5775a6..f7acc387 100644 --- a/docs/INITIALIZATION.md +++ b/docs/INITIALIZATION.md @@ -37,6 +37,7 @@ Sync updates standard Code Foundry files only. It preserves application code, authored documentation, existing `.mise.toml` selections, and custom workflows such as deployment, search, Slither, or monitoring workflows. -The environment bootstrap installs or reuses mise-managed tools, enables the -repository hooks, and runs the repository doctor. Re-run -`bash .github/scripts/bootstrap.sh` if local tools need to be repaired. +The environment bootstrap installs or reuses mise-managed tools and enables +the repository hooks. Use `npx code-foundry doctor` when local setup needs to +be checked; the CLI supplies the implementation without adding maintenance +scripts to the consumer repository. diff --git a/docs/WORKFLOWS.md b/docs/WORKFLOWS.md index c28236c9..5a803f08 100644 --- a/docs/WORKFLOWS.md +++ b/docs/WORKFLOWS.md @@ -54,12 +54,11 @@ analysis. ## Branch protection -Use the initializer's protection helper after reviewing the repository's -enabled features: +Use the repository's GitHub settings or the maintainer's branch-protection +automation after reviewing the repository's enabled features: ```bash -Use the repository's GitHub settings or the maintainer's branch-protection -automation to apply required checks after initialization. +Apply only checks for enabled workflows. ``` Keep strict status checks, linear history, and conversation resolution enabled.