Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,8 +55,8 @@ Use squash merges unless the repository documents another strategy. Re-align `st
### Toolchain

1. Install [mise](https://mise.jdx.dev/).
2. Run `bash .github/scripts/bootstrap.sh` to install the pinned toolchain, enable hooks, and validate the checkout.
3. Use `bash .github/scripts/doctor.sh` when setup, lockfiles, or hooks appear out of sync.
2. Run `npx code-foundry init` to install the pinned toolchain, enable hooks, and validate the checkout.
3. Use `npx code-foundry doctor` when setup, lockfiles, or hooks appear out of sync.
4. Use the repository's existing package manager and lockfile. Do not introduce a second package manager.
5. Copy `.env.example` to the appropriate local environment file when provided. Never commit the copy.

Expand Down Expand Up @@ -85,7 +85,7 @@ bash .github/scripts/ci.sh unit
bash .github/scripts/ci.sh integration
bash .github/scripts/ci.sh e2e
bash .github/scripts/ci.sh smoke
bash .github/scripts/security.sh
Security and dependency audits run through the GitHub Security workflow.
```

Run the checks relevant to the change. For a release or security-sensitive change, run the complete set. Record the commands and results in the pull request.
Expand Down
41 changes: 0 additions & 41 deletions .github/code-foundry.yml.example

This file was deleted.

12 changes: 2 additions & 10 deletions .github/scripts/doctor.sh
Original file line number Diff line number Diff line change
Expand Up @@ -66,11 +66,7 @@ if [ -f package.json ]; then
fi
if [ -f bunfig.toml ] && node -e 'const p=require("./package.json"); process.exit(p.scripts?.["test:coverage"] ? 0 : 1)' 2>/dev/null; then
if ! grep -q 'coverageThreshold' bunfig.toml; then
if [ -x .github/scripts/ci.sh ]; then
printf '%s\n' "INFO: shared CI enforces the Bun aggregate coverage threshold"
else
error "Bun coverage is enabled by test:coverage but no coverage policy is configured"
fi
printf '%s\n' "INFO: shared CI enforces the Bun aggregate coverage threshold"
fi
fi
fi
Expand All @@ -92,11 +88,7 @@ for workflow in ci codeql security test draft-pr release-pr release; do
fi
done

for script in ci.sh profile.sh doctor.sh bootstrap.sh sync-template.sh init-repo.sh sync-protection.sh sync-codeowners.sh; do
[ -x ".github/scripts/$script" ] || error "missing executable script: .github/scripts/$script"
done

printf '%s\n' 'Remote CI, Test, Security, and CodeQL runtimes are loaded by reusable workflow wrappers.'
printf '%s\n' 'Remote CI, Test, Security, CodeQL, and release runtimes are loaded by reusable workflow wrappers.'

if [ "$errors" -gt 0 ]; then
printf '%s\n' "Repository doctor found $errors error(s)." >&2
Expand Down
4 changes: 3 additions & 1 deletion .github/scripts/init-repo.sh
Original file line number Diff line number Diff line change
Expand Up @@ -252,7 +252,9 @@ if [ "$bootstrap" = false ]; then
exit 0
fi

bash .github/scripts/bootstrap.sh
bootstrap_script="$script_dir/bootstrap.sh"
[ -x "$bootstrap_script" ] || { echo "Package is missing bootstrap.sh" >&2; exit 1; }
bash "$bootstrap_script"

if [ "$protection" = true ]; then
remote="$(git remote get-url origin 2>/dev/null || true)"
Expand Down
49 changes: 36 additions & 13 deletions .github/scripts/sync-template.sh
Original file line number Diff line number Diff line change
Expand Up @@ -313,7 +313,6 @@ files=(
ruff.toml
.prettierrc
.github/CODEOWNERS
.github/code-foundry.yml.example
.github/CODE_OF_CONDUCT.md
.github/CONTRIBUTING.md
.github/PULL_REQUEST_TEMPLATE.md
Expand All @@ -322,18 +321,13 @@ files=(
.github/ISSUE_TEMPLATE/bug_report.yml
.github/ISSUE_TEMPLATE/config.yml
.github/ISSUE_TEMPLATE/feature_request.yml
# Keep only the small local hook runner and its language-aware formatter.
# Full CI, security, CodeQL, and release implementations are loaded from
# the reusable runtime and are not copied into consumer repositories.
.github/scripts/profile.sh
.github/scripts/bootstrap.sh
# Keep the small local hook runner and its changed-file helper; the full
# CI/security implementations used by Actions are loaded from the runtime.
.github/scripts/changed-files.sh
.github/scripts/ci.sh
.github/scripts/doctor.sh
.github/scripts/pre-commit.sh
.github/scripts/sync-template.sh
.github/scripts/init-repo.sh
.github/scripts/sync-codeowners.sh
.github/scripts/sync-protection.sh
.github/workflows/ci.yml
.github/workflows/codeql.yml
.github/workflows/draft-pr.yml
Expand All @@ -358,6 +352,36 @@ for file in "${files[@]}"; do
esac
done
files=("${filtered_files[@]}")
changed=0

# These files belonged to older Code Foundry layouts. They are intentionally
# removed now that the npm CLI owns initialization and synchronization.
removed_files=(
.github/code-foundry.yml.example
.github/template.yml
.github/template.yml.example
.github/scripts/bootstrap.sh
.github/scripts/codeql-languages.sh
.github/scripts/doctor.sh
.github/scripts/init-repo.sh
.github/scripts/security.sh
.github/scripts/sync-codeowners.sh
.github/scripts/sync-protection.sh
.github/scripts/sync-template.sh
.github/scripts/sitecustomize.py
.github/scripts/turbo-cache-probe.sh
)
for file in "${removed_files[@]}"; do
if [ -e "$file" ]; then
changed=$((changed + 1))
if [ "$mode" = "check" ]; then
printf 'Would remove legacy managed file %s\n' "$file"
else
rm -f "$file"
printf 'Removed legacy managed file %s\n' "$file"
fi
fi
done

# Workflows outside the standard baseline are repository-owned extensions.
# The sync operation never deletes or replaces them; surface them explicitly
Expand Down Expand Up @@ -390,7 +414,6 @@ if [ "${#custom_workflows[@]}" -gt 0 ]; then
printf 'Preserving custom workflows: %s\n' "${custom_workflows[*]}"
fi

changed=0
for file in "${files[@]}"; do
template_file="$template_root/$file"
# npm renames .gitignore to .npmignore when installing a package. Treat the
Expand Down Expand Up @@ -629,11 +652,11 @@ initialize_mise_lock() {

initialize_mise_lock

if [ -x .github/scripts/sync-codeowners.sh ]; then
if [ -x "$template_root/.github/scripts/sync-codeowners.sh" ]; then
if [ "$mode" = "check" ]; then
bash .github/scripts/sync-codeowners.sh --check
bash "$template_root/.github/scripts/sync-codeowners.sh" --check
else
bash .github/scripts/sync-codeowners.sh --apply
bash "$template_root/.github/scripts/sync-codeowners.sh" --apply
fi
fi

Expand Down
4 changes: 2 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ Ask for clarification when a missing decision would materially change the implem
2. Inspect before editing; preserve unrelated work.
3. Plan the smallest coherent change.
4. Implement with existing project patterns.
5. Run bash .github/scripts/bootstrap.sh for a new checkout, or bash .github/scripts/doctor.sh to diagnose setup drift.
5. Run `npx code-foundry init` for a new checkout, or `npx code-foundry doctor` to diagnose setup drift.
6. Run focused checks while iterating.
7. Inspect the final diff for accidental changes, secrets, formatting, and generated files.
8. Run the broadest applicable validation available.
Expand Down Expand Up @@ -96,7 +96,7 @@ bash .github/scripts/ci.sh unit
bash .github/scripts/ci.sh integration
bash .github/scripts/ci.sh e2e
bash .github/scripts/ci.sh smoke
bash .github/scripts/security.sh
Security and dependency audits run through the GitHub Security workflow.
```

Run focused tests first, then the complete applicable set for release, security, workflow, dependency, and configuration changes.
Expand Down
7 changes: 4 additions & 3 deletions docs/INITIALIZATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ Sync updates standard Code Foundry files only. It preserves application code,
authored documentation, existing `.mise.toml` selections, and custom workflows
such as deployment, search, Slither, or monitoring workflows.

The environment bootstrap installs or reuses mise-managed tools, enables the
repository hooks, and runs the repository doctor. Re-run
`bash .github/scripts/bootstrap.sh` if local tools need to be repaired.
The environment bootstrap installs or reuses mise-managed tools and enables
the repository hooks. Use `npx code-foundry doctor` when local setup needs to
be checked; the CLI supplies the implementation without adding maintenance
scripts to the consumer repository.
7 changes: 3 additions & 4 deletions docs/WORKFLOWS.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,12 +54,11 @@ analysis.

## Branch protection

Use the initializer's protection helper after reviewing the repository's
enabled features:
Use the repository's GitHub settings or the maintainer's branch-protection
automation after reviewing the repository's enabled features:

```bash
Use the repository's GitHub settings or the maintainer's branch-protection
automation to apply required checks after initialization.
Apply only checks for enabled workflows.
```

Keep strict status checks, linear history, and conversation resolution enabled.
Expand Down