Skip to content

feat(governance): harden governance rules, hook guards, and CI pipeline for epic branching (#17) - #18

Merged
nicolasvd merged 1 commit into
epic/issue-12-jit-sealing-epic-protocolfrom
feat/issue-17-harden-governance-rules
Sep 25, 2026
Merged

nicolasvd merged 1 commit into
epic/issue-12-jit-sealing-epic-protocolfrom
feat/issue-17-harden-governance-rules

Conversation

@nicolasvd

Copy link
Copy Markdown
Owner

Closes #17

📌 Summary

Branch: feat/issue-17-harden-governance-rules → epic/issue-12-jit-sealing-epic-protocol
Type: feat(governance)
Related Issue: #17 feat(governance): harden governance rules, hook guards, and CI pipeline for epic branching
Parent Epic: #12 epic(governance): establish just-in-time issue sealing, native project metadata sync, and isolated epic branching protocol

  • Governance Rules & Personas: Formalized Rule 0 (JIT Issue Sealing at Gate 1.4) and Rule 0.1 (Epic Branch Isolation Protocol) across AGENTS.md, agent.md, agent-lifecycle.md, backlog-planner.md, git-workflow.md, p1-product-planner.md, p4-system-architect.md, and skills plan-issue / open-pr.
  • Runtime Hook Safeguards: Hardened .agent/hooks/branch-guard.mjs and plan-guard.mjs to block direct writes, commits, and merges on epic/* integration branches while permitting child task branching and upstream initial pushes.
  • Dynamic Post-Merge Synchronization: Upgraded .agent/hooks/post-merge-dual-sync.sh to dynamically query the PR target base branch (epic/** or main), check it out, pull latest commits, and prune merged branches.
  • Pre-Invocation Context Anchor: Enhanced .agent/hooks/pre-invocation-anchor.sh to contextually recognize epic/* integration containers.
  • Dynamic CI Diff Detection: Updated .github/workflows/delivery-pipeline.yml to trigger on pull_request: [main, 'epic/**'] and compare changed files dynamically against origin/${{ github.base_ref || 'main' }}...HEAD.
  • CLI Sync & Seal Robustness: Inlined singleSelectOptionId in scripts/sync-project-metadata.mjs to eliminate GraphQL type coercion errors, and added conventional commit type mapping in scripts/seal-issue.sh.

📂 Affected Files

File Diff Role
AGENTS.md (and agent.md) +14 / -10 Micro-kernel protocol, state machine & Rule 0 / 0.1
.agent/rules/agent-lifecycle.md +26 / -33 3-Phase lifecycle, JIT sealing hand-off, base resolution
.agent/rules/backlog-planner.md +23 / -26 Rule 0, Rule 0.1, Rule 3 native metadata, Rule 5
.agent/rules/git-workflow.md +14 / -24 Branch conventions, base branch targeting, dual-sync
.agent/personas/p1-product-planner.md +8 / -14 Manifest JIT Sealing and Project v2 sync
.agent/personas/p4-system-architect.md +4 / -3 Manifest Epic Branch Isolation & decomposition
.agent/skills/plan-issue/SKILL.md +19 / -34 JIT Sealing recipe with ./scripts/seal-issue.sh
.agent/skills/open-pr/SKILL.md +6 / -5 Dynamic base branch targeting & post-merge sync
.agent/hooks/branch-guard.mjs +5 / -7 Direct write block on epic/* integration branches
.agent/hooks/plan-guard.mjs +6 / -5 Direct commit & merge block on epic/* branches
.agent/hooks/post-merge-dual-sync.sh +15 / -0 Dynamic PR base branch checkout & cleanup
.agent/hooks/pre-invocation-anchor.sh +7 / -1 Contextual recognition of epic/* branches
scripts/sync-project-metadata.mjs +1 / -4 Inlined singleSelectOptionId mutation
scripts/seal-issue.sh +8 / -1 Conventional commit type to label mapping
scripts/test-runtime-guardrails.mjs +20 / -0 Epic branch rejection assertions (31/31 passed)
.github/workflows/delivery-pipeline.yml +4 / -2 epic/** trigger & dynamic base_ref diffing

✅ Quality Airbag — Pre-Commit & Local Verification

Check Result
./scripts/validate-docs.sh ✅ 40/40 contracts valid & strictly within byte budget
./scripts/test-runtime-guardrails.mjs ✅ 31/31 assertions passed (PoLP, plan guard, branch guard)
./scripts/quality-check.sh ✅ 0 errors · 0 lint warnings · 100% tests passed (503ms)
Pre-commit airbag hook ✅ Validated commit conventions & doc boundaries

📸 UI Snapshots / Roborazzi Visual Diffs

N/A — No UI composable or visual changes in this governance hardening feature.


Caution

Zero Auto-Merge — Explicit approval required (Gate 3.5).
This PR targets the Epic integration branch epic/issue-12-jit-sealing-epic-protocol.
Persona 6 presents this PR link and stops. Merge is a deliberate human action.

@nicolasvd nicolasvd added skip-release Skip APK artifact release and distribution governance Governance, lifecycle, and metadata policies labels Sep 25, 2026
@nicolasvd
nicolasvd merged commit d199362 into epic/issue-12-jit-sealing-epic-protocol Sep 25, 2026
3 checks passed
@nicolasvd
nicolasvd deleted the feat/issue-17-harden-governance-rules branch September 25, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

governance Governance, lifecycle, and metadata policies skip-release Skip APK artifact release and distribution

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant