aboutsummaryrefslogtreecommitdiffziptar.gz
diff options
context:
space:
mode:
authorgodosa <godosa@godosa.eu>2026-10-07 07:51:31 +0200
committergodosa <godosa@godosa.eu>2026-10-07 07:51:31 +0200
commit930d8e023b5a4ac2e179aa80a74951cd5452668e (patch)
tree5c6b35798563081b344d8d10e38864069f10d3a9
parent71d1b0d84d0a2c55a4698c83788fa1f9e901ea35 (diff)
downloadworkflow-930d8e023b5a4ac2e179aa80a74951cd5452668e.tar.gz
workflow-930d8e023b5a4ac2e179aa80a74951cd5452668e.zip
shared push rule: split projects push the public repo via their publish command only
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JEAjUkQRrCYX5MZhWxdtj2
-rw-r--r--CHANGES.md1
-rw-r--r--shared/CLAUDE.md3
2 files changed, 3 insertions, 1 deletions
diff --git a/CHANGES.md b/CHANGES.md
index e108b07..f5d93c1 100644
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -1,4 +1,5 @@
# Changes (newest first)
+- 2026-10-07 Shared push rule: in a split project the public `code_root` repo is pushed only via the project's publish command, never `git push home --all` (that pushes local review branches unscanned). Projects: split projects name their publish command in their CLAUDE.md.
- 2026-10-07 Denylist guard at commit time: `.githooks/pre-commit` (staged lines + paths) and `.githooks/commit-msg` run `scripts/denylist_check.py` against the git-ignored `publish-denylist.local` (worktree top + main tree, plus `git config denylist.file` lists; `word` / `!token` exemption / `#`, case-insensitive; output `word #<line>` only; no list → warning). Enable per clone: `git config core.hooksPath .githooks`; audit: `denylist_check.py tree`. `scripts/publish_snapshot.py` removed (history is public now). Projects: nothing.
- 2026-10-07 Tests use generic fixtures (/h/u, 10.0.0.x) instead of real home-dir and LAN paths (publish-scan clean). Projects: nothing.
diff --git a/shared/CLAUDE.md b/shared/CLAUDE.md
index 8e293cc..66b12f4 100644
--- a/shared/CLAUDE.md
+++ b/shared/CLAUDE.md
@@ -37,7 +37,8 @@ Orchestrator: `/wf-orchestrate` (never `wf next --as`, never implement). `wf-wor
1. `wf done <id> -m "<≤2-line entry>"` (or `wf finish`) → follow what it prints. New work → `wf add` now.
2. `wf check` 0 errors → commit explicit paths (never `add -A` / `commit -a` / `add .`). Commit ≠ merge ≠ push;
merge only your own task branch in worktree mode. Push only to remote `home` (if present):
- `git push home --all && git push home --tags`. Other remotes never unasked.
+ `git push home --all && git push home --tags`. Other remotes never unasked. Split project (`code_root` = a
+ public repo): push that repo only via its publish command (project CLAUDE.md), never `--all` there.
3. Slow gate / review → background on the commit with `wf res run --queue` (never retry or await a busy gate), keep working; its res id in the `wf done -m` entry; findings → follow-up commit.
## Several sessions