Skip to content

ci: hold pull request titles to Conventional Commits - #55

Merged
AdeGneus merged 1 commit into
mainfrom
ci/conventional-pr-title
Oct 1, 2026
Merged

AdeGneus merged 1 commit into
mainfrom
ci/conventional-pr-title

Conversation

@AdeGneus

@AdeGneus AdeGneus commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Holds pull request titles to Conventional Commits, as the runtime and gateway do. GitHub squash merge uses the title as the commit message whenever a pull request carries more than one commit, so a prose title lands a non-conventional commit on main after every commit-level gate has passed.

Adds scripts/check_conventional_subject.py and a PR title workflow, the same port as the gateway: the title is read from the environment rather than interpolated, actions are SHA-pinned, and the job runs on step-security/harden-runner. The commit types match this repository's commit-msg hook.

Left for the maintainer: adding Conventional commit format to the required checks on main.

Type of change

  • feat - new CLI command, output mode, bridge integration, or operator workflow
  • fix - bug fix or command behavior correction
  • docs - documentation only
  • test - tests only
  • refactor - no behavior change
  • security - touches tokens, deploy keys, credentials, or local runtime authority
  • contract-change - changes bridge, output JSON, cloud, Hub, or SDK contract usage

Required checklist

  • Linked issue is included below and acceptance criteria are addressed
  • go test ./... passes
  • go vet ./... passes
  • Pre-commit passes for changed files
  • Every new .go file has the Apache-2.0 license header
  • Command help text is updated for new or changed flags
  • JSON output is deterministic and tested when --output json is supported

CLI authority and safety checklist

  • Runtime-owned behavior delegates through the runtime bridge; the CLI does not parse ori.yaml independently
  • State queries go through the bridge; the CLI does not open runtime SQLite directly
  • Deploy keypairs are generated on-device; private keys never leave the device
  • Token commands never print raw token material except the explicit one-time generate result
  • Text output is operator-readable and error output is clear on stderr

External integration checklist

Complete if this PR touches runtime bridge, cloud, Hub, or SDK integrations.

  • Timeout, malformed JSON, auth failure, and unavailable service paths are tested
  • Secrets and private keys never appear in logs or errors
  • Noninteractive behavior is documented and tested if added

If you used AI assistance

  • I can explain every line of AI-generated code in this PR
  • I have read and understood every file I modified
  • I am not submitting code I cannot defend in review

Related issue

None.

Testing notes

pre-commit run --files on both files and the supply-chain guard pass; the script accepts ci: hold pull request titles to Conventional Commits and rejects Add stuff.

@AdeGneus AdeGneus self-assigned this Oct 1, 2026
@AdeGneus
AdeGneus merged commit 22a6aa6 into main Oct 1, 2026
5 checks passed
@AdeGneus
AdeGneus deleted the ci/conventional-pr-title branch October 1, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant