Skip to content

fix: foundry correctness pass (review findings) - #45

Open
CMaintz wants to merge 1 commit into
mainfrom
fix/foundry-correctness
Open

CMaintz wants to merge 1 commit into
mainfrom
fix/foundry-correctness

Conversation

@CMaintz

@CMaintz CMaintz commented Oct 1, 2026

Copy link
Copy Markdown
Owner

A correctness sweep (from a full read of the workflows, templates, scripts, tests, docs). By severity:

Critical

  • cut-release.sh — group() returned 1 on an empty changelog section, so under set -e a bare group call aborted the whole release on a patch with no feat commits (v2.4.0 only survived because it happened to have both feat+fix). Now uses if, so an empty section returns 0. Verified.

Should-fix

  • mise/dotnet.toml — audit fed dotnet list into a negated grep, so a dotnet list error passed green (the fail-green class). Now captures output, fails on non-zero dotnet list, then greps.
  • _ts.yml habits — added the baseline-present guard + pinned setup-python the other stacks have (a TS repo with no snooze.json hard-errored instead of skipping; ran against the runner's default Python).
  • gate.yml — forwards habit_hooks_plugin (declared on every internal, never exposed on the facade) with a per-stack fallback; stack description now includes dotnet.
  • foundry-init.sh — fetches template-consumed scripts into $WD/scripts not repo-root scripts/, so a monorepo (WD=backend) can find them via {{config_root}}/scripts.
  • _java/_php/_ts.yml — corrected the smell-summary doc path to presets/agent/code-standards.md.

Minor

  • lint-workflows.yml shellchecks the extensionless foundry-verb-wrap; commitlint.yml comment now references cut-release.sh not release-please; foundry-init also fetches foundry-flaky for the opt-in test:flaky verb.

Left as-is: the semgrep/cache pinned-SHA skews — each internally consistent, likely deliberate; flagged not changed.

From a full review. Most impactful first:

- cut-release.sh: group() returned 1 on an empty changelog section, so under `set -e`
  a bare `group` call aborted the whole release on a patch with no feat commits (v2.4.0
  only survived by having both feat+fix). Use `if` so an empty section returns 0.
- mise/dotnet.toml: the `audit` verb piped `dotnet list` straight into a negated grep,
  so if `dotnet list` itself errored the negation passed GREEN. Capture output, fail on
  a non-zero `dotnet list`, then grep.
- _ts.yml habits: add the baseline-present guard + pinned setup-python the other three
  stacks have — a TS repo with no snooze.json got a hard error instead of a graceful skip,
  and ran against the runner's default Python.
- gate.yml: forward `habit_hooks_plugin` (declared on every internal, never exposed on
  the facade) with a per-stack fallback; fix the stale "java | ts | php" description to
  include dotnet.
- foundry-init.sh: fetch the mise-template-consumed scripts (foundry-verb-wrap,
  foundry-loop-report, npm-audit-ratchet.mjs, foundry-flaky) into $WD/scripts, not repo-
  root scripts/ — a monorepo (WD=backend) couldn't find them via {{config_root}}/scripts.
- _java/_php/_ts.yml: fix the smell summary's doc path (presets/agent/code-standards.md).
- lint-workflows.yml: shellcheck the extensionless foundry-verb-wrap too.
- commitlint.yml: comment referenced release-please (now cut-release.sh).

Left as-is: the semgrep/cache pinned-SHA skews (#11) — each internally consistent and
likely deliberate; flagged, not changed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant