From fe6ac613b1a324fb640027c7c7f2cadb69d56bd2 Mon Sep 17 00:00:00 2001 From: Alex Garcia Date: Sun, 4 Oct 2026 01:33:02 -0700 Subject: [PATCH] chore: stop tracking local editor configuration --- .claude/hooks/post-edit.sh | 23 ----- .claude/settings.json | 15 --- .claude/skills/add-repo-override/SKILL.md | 34 ------- .claude/skills/audit/SKILL.md | 28 ----- .claude/skills/exclude-repo/SKILL.md | 27 ----- .github/workflows/quality-checks.yml | 2 +- .gitignore | 2 +- CLAUDE.md | 119 ---------------------- README.md | 13 --- config/baseline.json | 1 - 10 files changed, 2 insertions(+), 262 deletions(-) delete mode 100755 .claude/hooks/post-edit.sh delete mode 100644 .claude/settings.json delete mode 100644 .claude/skills/add-repo-override/SKILL.md delete mode 100644 .claude/skills/audit/SKILL.md delete mode 100644 .claude/skills/exclude-repo/SKILL.md delete mode 100644 CLAUDE.md diff --git a/.claude/hooks/post-edit.sh b/.claude/hooks/post-edit.sh deleted file mode 100755 index 5d58ca7..0000000 --- a/.claude/hooks/post-edit.sh +++ /dev/null @@ -1,23 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -# Post-edit hook: auto-format shell scripts and markdown after Edit/Write. -# Called by Claude Code via .claude/settings.json PostToolUse hook. - -FILE="$TOOL_INPUT_FILE_PATH" - -case "$FILE" in - *.sh) - if command -v shellharden > /dev/null 2>&1; then - shellharden --replace "$FILE" 2>/dev/null || true - fi - if [ -f "$FILE" ] && head -1 "$FILE" | grep -q '^#!'; then - chmod +x "$FILE" - fi - ;; - *.md) - if command -v markdownlint > /dev/null 2>&1; then - markdownlint --fix "$FILE" 2>/dev/null || true - fi - ;; -esac diff --git a/.claude/settings.json b/.claude/settings.json deleted file mode 100644 index 7ba0d98..0000000 --- a/.claude/settings.json +++ /dev/null @@ -1,15 +0,0 @@ -{ - "hooks": { - "PostToolUse": [ - { - "matcher": "Edit|Write", - "hooks": [ - { - "type": "command", - "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/post-edit.sh" - } - ] - } - ] - } -} diff --git a/.claude/skills/add-repo-override/SKILL.md b/.claude/skills/add-repo-override/SKILL.md deleted file mode 100644 index 6251a12..0000000 --- a/.claude/skills/add-repo-override/SKILL.md +++ /dev/null @@ -1,34 +0,0 @@ ---- -name: add-repo-override -description: >- - Add a per-repo settings override to overrides.json so a specific - repository can deviate from the baseline. Use this skill whenever the - user wants to customize settings for one repo, add an exception, or - says "this repo needs different branch protection" or "override the - wiki setting for this repo". -disable-model-invocation: true -user-invocable: true -argument-hint: " " ---- - -# Add Repository Override - -Add a per-repo exception to `config/overrides.json`. - -## Arguments - -`$ARGUMENTS` should be in the format: ` ` - -Examples: - -- `my-repo branch_protection.required_status_checks.contexts '["Build","Test"]'` -- `my-repo repo_settings.has_wiki true` - -## Steps - -1. Read the current `config/overrides.json` -2. Parse `$ARGUMENTS` to extract repo name, setting path, and value -3. Add or update the override for the specified repo -4. Validate the resulting JSON with `jq empty` -5. Show the diff of what changed -6. Remind the user to create a PR for the change diff --git a/.claude/skills/audit/SKILL.md b/.claude/skills/audit/SKILL.md deleted file mode 100644 index 20429a7..0000000 --- a/.claude/skills/audit/SKILL.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -name: audit -description: >- - Run a dry-run settings audit across all repositories to detect drift - from baseline. Use this skill whenever the user wants to check repo - settings, find drift, audit governance, or says "are all repos in - sync?" or "check settings across the org". -disable-model-invocation: true -user-invocable: true ---- - -# Audit Repository Settings - -Run a dry-run sync to check for drift without applying changes. - -## Steps - -1. Run the sync script in dry-run mode: - -```bash -./scripts/sync-repo-settings.sh --dry-run -``` - -1. Display the report: - -```bash -cat reports/sync-report.md -``` diff --git a/.claude/skills/exclude-repo/SKILL.md b/.claude/skills/exclude-repo/SKILL.md deleted file mode 100644 index d2559e8..0000000 --- a/.claude/skills/exclude-repo/SKILL.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -name: exclude-repo -description: >- - Exclude a repository from settings governance so the sync script - skips it entirely. Use this skill whenever the user wants to remove - a repo from governance, stop syncing a repo, or says "don't manage - this repo" or "exclude my-fork from settings sync". -disable-model-invocation: true -user-invocable: true -argument-hint: "" ---- - -# Exclude Repository - -Add a repository to the exclusion list in `config/overrides.json`. - -## Arguments - -`$ARGUMENTS` should be the repository name to exclude. - -## Steps - -1. Read the current `config/overrides.json` -2. Add `$ARGUMENTS` to the `excluded` array (if not already present) -3. Validate the resulting JSON with `jq empty` -4. Show the updated exclusion list -5. Remind the user to create a PR for the change diff --git a/.github/workflows/quality-checks.yml b/.github/workflows/quality-checks.yml index 4c4ab23..896d408 100644 --- a/.github/workflows/quality-checks.yml +++ b/.github/workflows/quality-checks.yml @@ -61,7 +61,7 @@ jobs: run: | MISSING=0 for file in LICENSE README.md .gitignore CODEOWNERS CONTRIBUTING.md \ - SECURITY.md CLAUDE.md .pre-commit-config.yaml \ + SECURITY.md .pre-commit-config.yaml \ .coderabbit.yaml .github/copilot-instructions.md \ .github/dependabot.yml .github/PULL_REQUEST_TEMPLATE.md \ config/baseline.json config/overrides.json; do diff --git a/.gitignore b/.gitignore index f82fde4..af6be3d 100644 --- a/.gitignore +++ b/.gitignore @@ -22,7 +22,7 @@ Thumbs.db *.log logs/ -# Claude Code +# Editor session files *.conversation # Generated reports (kept in CI artifacts, not committed) diff --git a/CLAUDE.md b/CLAUDE.md deleted file mode 100644 index 49e0285..0000000 --- a/CLAUDE.md +++ /dev/null @@ -1,119 +0,0 @@ -# GitHub Organization Settings — Project Instructions - -## Repository Overview - -Automated governance for GitHub repository settings across the -`gamaware` organization. Contains shell scripts, composite GitHub -Actions, and workflows that discover repos, compare settings against -a baseline, apply corrections, and report drift via GitHub Issues. - -## Repository Structure - -- `scripts/` — Shell scripts for syncing settings and generating reports -- `config/` — Baseline settings JSON and per-repo overrides -- `.github/workflows/` — CI/CD and scheduled sync workflows -- `.github/actions/` — Composite actions (security-scan, sync-settings, - update-pre-commit-composite) -- `.claude/skills/` — Reusable skills (`/audit`, `/add-repo-override`, - `/exclude-repo`) -- `docs/architecture.md` — System architecture overview -- `docs/adr/` — Architecture Decision Records -- `docs/runbooks/` — Operational procedures (exclude repo, add setting, - handle drift, onboard repo) - -## Git Workflow - -- Conventional commits required (`type: description`) -- Types: `fix`, `feat`, `docs`, `chore`, `ci`, `refactor`, `test` -- Never commit directly to `main` — use feature branches and PRs -- Squash merge only; PR title becomes commit title -- No AI attribution in commits, code, or content - -## Pre-commit Hooks - -General, secrets, shell, markdown, prose (Vale), GitHub Actions -(actionlint, zizmor), and conventional commit hooks — see -`.pre-commit-config.yaml` for the full list. - -## Claude Code Hooks - -- **PostToolUse** on `Edit|Write`: auto-format shell scripts - (`shellharden --replace`, `chmod +x`) and markdown - (`markdownlint --fix`) -- Hooks defined in `.claude/settings.json`, scripts in `.claude/hooks/` - -## Linting Policy - -- All default rules enforced — NO suppressions -- Fix violations directly instead of adding ignore comments -- Markdownlint: MD013 line length 120, tables exempt -- Table separators: `| --- |` with spaces (MD060) - -## Shell Scripts - -- Must pass `shellcheck` and `shellharden` -- Quote all variables: `"$VAR"` (braces only when needed) -- Scripts must have shebangs and executable permissions -- The Edit tool can strip executable permissions — verify and restore - -## Content Rules - -- English only -- No hardcoded credentials or account IDs -- Use placeholder values (`YOUR_GITHUB_TOKEN`, etc.) - -## CI/CD Pipelines - -- `sync-settings.yml` — weekly settings sync + GitHub Issue reports -- `quality-checks.yml` — markdown, YAML, shell, structure, JSON - schema validation, link checking, zizmor (Actions security), - Vale (prose linting) -- `security.yml` — Semgrep SAST + Trivy SCA (via composite action) -- `update-pre-commit-hooks.yml` — weekly auto-update via PR (via - composite action) -- `auto-merge-bot-prs.yml` — hourly scheduled job that squash-merges - Dependabot and pre-commit PRs with admin bypass once every check is - green (no approval step; GitHub rejects self-approval with the - owner's PAT) - -## Composite Actions - -- `.github/actions/security-scan/` — reusable Semgrep + Trivy scan -- `.github/actions/sync-settings/` — reusable settings sync with - outputs for drift detection -- `.github/actions/update-pre-commit-composite/` — reusable - pre-commit autoupdate + PR creation - -## Claude Code Skills - -- `/audit` — run a dry-run settings check across all repos -- `/add-repo-override` — add a per-repo exception to overrides.json -- `/exclude-repo` — exclude a repository from governance -- `/ship-it [PR-number]` — end-to-end PR lifecycle: update docs, commit, - create PR, monitor CI, address reviews (CodeRabbit + Copilot), merge, - clean up stale branches. Uses global skill. - -## Code Review - -- CodeRabbit auto-review via `.coderabbit.yaml` -- GitHub Copilot auto-review via ruleset -- Both reviewers run on every PR - -## Settings Sync Details - -The sync script (`scripts/sync-repo-settings.sh`) enforces: - -1. **Repo settings**: merge strategy, features, auto-merge, branch - cleanup -2. **Security**: secret scanning, push protection, vulnerability - alerts -3. **Branch protection**: reviews, CODEOWNERS, linear history, - conversation resolution -4. **Rulesets**: Copilot code review ruleset on default branch -5. **Labels**: standard issue labels across all repos -6. **Default branch**: ensures all repos use `main` -7. **Metadata**: flags missing descriptions and topics (advisory) -8. **Required files**: LICENSE, README, CODEOWNERS, etc. - -Configuration lives in `config/baseline.json` with per-repo -overrides in `config/overrides.json`. diff --git a/README.md b/README.md index 2dd809f..51816af 100644 --- a/README.md +++ b/README.md @@ -137,7 +137,6 @@ report (not auto-created, since content is repo-specific). | `CODEOWNERS` | Assign default reviewers | | `CONTRIBUTING.md` | Contribution guidelines | | `SECURITY.md` | Vulnerability disclosure policy | -| `CLAUDE.md` | Claude Code project instructions | | `.pre-commit-config.yaml` | Local linting and validation | | `.coderabbit.yaml` | CodeRabbit auto-review configuration | | `.github/copilot-instructions.md` | Copilot code review instructions | @@ -159,17 +158,6 @@ corrected in `--apply` mode. ```text github-org-settings/ -├── .claude/ -│ ├── settings.json # Claude Code hooks config -│ ├── hooks/ -│ │ └── post-edit.sh # Auto-format on edit -│ └── skills/ -│ ├── audit/ # /audit — dry-run settings check -│ │ └── SKILL.md -│ ├── add-repo-override/ # /add-repo-override — add exception -│ │ └── SKILL.md -│ └── exclude-repo/ # /exclude-repo — exclude a repo -│ └── SKILL.md ├── .github/ │ ├── actions/ │ │ ├── security-scan/ # Composite: Semgrep + Trivy @@ -215,7 +203,6 @@ github-org-settings/ ├── .pre-commit-config.yaml ├── .secrets.baseline ├── zizmor.yml # GitHub Actions security config -├── CLAUDE.md # Claude Code project instructions ├── CODEOWNERS ├── CONTRIBUTING.md ├── LICENSE diff --git a/config/baseline.json b/config/baseline.json index 8ff4071..38e4425 100644 --- a/config/baseline.json +++ b/config/baseline.json @@ -97,7 +97,6 @@ "CODEOWNERS", "CONTRIBUTING.md", "SECURITY.md", - "CLAUDE.md", ".pre-commit-config.yaml", ".coderabbit.yaml", ".github/copilot-instructions.md",