diff --git a/AGENTS.md b/AGENTS.md index a95d6e6..177b3ea 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -10,7 +10,7 @@ This file is the project's committed home for project-intrinsic agent knowledge: - `cmd/writ` commands signal a specific process exit code (0 auto-mergeable, 1 needs human, 2 no writ open) by returning the unexported `exitCodeErr{code}` from `RunE`; `main()` unwraps it via `errors.As` before falling back to the default exit-1 path. Command tests that need a real repo `os.Chdir` into a `t.TempDir()` git repo, since `repoRoot()` shells out to `git rev-parse --show-toplevel` against the process cwd rather than taking a directory argument. - This repo is on the captain's **personal** GitHub account (`Laaaaksh`). The default `gh` login has changed between the personal and work profiles over time (as of 2026-08-22 the personal account is the default and `~/.config/gh-personal` no longer exists), so never assume either way: verify with `gh api user --jq .login` (must print `Laaaaksh`) before any GitHub CLI operation, and if it prints a work account, export `GH_CONFIG_DIR="$HOME/.config/gh-personal"` first — recreating that dir via `gh auth login` if needed. The default branch is `master`, not `main`. - A repo commit-identity guard hook requires the git author email to match the personal class (`laksh.sadhwani07@gmail.com`) for this remote — set via local (not global) `git config user.email` if a commit is rejected. -- Release packaging: `.github/workflows/ci.yml` (build/vet/test on PR and push to `master`), `.github/workflows/release.yml` (goreleaser on `v*` tag push), and `.goreleaser.yml` (darwin/linux amd64/arm64, publishing a Homebrew formula to `Laaaaksh/homebrew-writ` via `brews:`) mirror the sibling `Laaaaksh/vessel` repo's setup. Releasing requires a `HOMEBREW_TAP_TOKEN` repo secret — without it goreleaser falls back to `GITHUB_TOKEN`, which cannot write to the separate tap repo and the release fails (this is what broke vessel's first release). `.github/dependabot.yml` runs weekly `gomod` + `github-actions` version-update PRs on top of the GitHub-side Dependabot alerts/security-fixes toggles (those live in repo settings, not files); expect its PRs against `master`. `.github/workflows/codeql.yml` runs CodeQL code scanning (languages go,actions) on PRs, pushes to `master`, and a weekly cron — its status check is named `CodeQL`; activity is proven by `/code-scanning/analyses` entries, not default-setup state. +- Release packaging: `.github/workflows/ci.yml` (build/vet/test on PR and push to `master`), `.github/workflows/release.yml` (goreleaser on `v*` tag push), and `.goreleaser.yml` (darwin/linux amd64/arm64, publishing a Homebrew formula to `Laaaaksh/homebrew-writ` via `brews:`) mirror the sibling `Laaaaksh/vessel` repo's setup. Releasing requires a `HOMEBREW_TAP_TOKEN` repo secret — without it goreleaser falls back to `GITHUB_TOKEN`, which cannot write to the separate tap repo and the release fails (this is what broke vessel's first release). The tap repo's README.md is hand-maintained (goreleaser writes only `Formula/`), so when writ's README install instructions change, mirror them there too — it kept serving a stale broken one-liner for releases after the main README was fixed (corrected 2026-08-22). `.github/dependabot.yml` runs weekly `gomod` + `github-actions` version-update PRs on top of the GitHub-side Dependabot alerts/security-fixes toggles (those live in repo settings, not files); expect its PRs against `master`. `.github/workflows/codeql.yml` runs CodeQL code scanning (languages go,actions) on PRs, pushes to `master`, and a weekly cron — its status check is named `CodeQL`; activity is proven by `/code-scanning/analyses` entries, not default-setup state. - `go.mod`'s `go` directive is the single source of the Go toolchain for CI and releases: both workflows pass `go-version-file: go.mod` to actions/setup-go, so that line decides which compiler (and which stdlib security patches) ship inside released binaries — v0.2.x shipped go1.22.12, EOL since Feb 2025, before the directive was bumped to a supported line. Audit it against the two-current-versions support policy whenever cutting a release. - `master` is branch-protected: required `Test` status check (strict), enforced for admins, conversation resolution required, no direct pushes — land every change through a PR and wait for its `Test` check (`gh pr merge` honors the rules); `CONTRIBUTING.md` documents the contributor-facing flow. Repo settings keep `delete_branch_on_merge` on: after any PR merges (including this run's own gnhf branch PRs), GitHub deletes that head branch from origin — re-push the local branch to recreate it; don't misread the vanished origin ref as data loss. Wiki/Projects tabs are deliberately disabled; don't re-enable them when auditing settings. - `cmd/writ/main.go`'s `version`, `commit`, and `date` must stay package-level `var`s (with `default*` const placeholders), never `const` — goreleaser's `-X main.version=...` ldflags silently no-op against a `const` string, so every released binary would misreport itself. `versionString` is the single place that renders them; it omits the `(commit ..., built ...)` suffix when both are still at their defaults.