Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
fcc7ef0
chore(repo): enforce conventional commits and record release ADR
serialexperimentslainnnn Aug 5, 2026
9dd6c3e
feat(licensing): ship third-party attribution inside the artifact
serialexperimentslainnnn Aug 5, 2026
0e40116
feat(a11y): announce turn state and give keyboard focus a visible ring
serialexperimentslainnnn Aug 5, 2026
4b306a1
fix(deps): declare the protocol SDK as build tooling, not a dependency
serialexperimentslainnnn Aug 5, 2026
6eda134
docs(security): write down the adversary SensitiveGuard defends against
serialexperimentslainnnn Aug 5, 2026
3911662
build: mechanise the quality bar and enforce it on protected branches
serialexperimentslainnnn Aug 5, 2026
a7a5c18
feat: surface plan limits, and fix the defects the new tooling exposed
serialexperimentslainnnn Aug 5, 2026
6eea820
docs: record the 5.0.0 standards work, its gaps and what was measured
serialexperimentslainnnn Aug 5, 2026
26c4000
docs: record merge-commit-only, and why it is a signing decision
serialexperimentslainnnn Aug 5, 2026
b497b85
fix(test): parse shell.html with a parser, not regexes
serialexperimentslainnnn Aug 5, 2026
ffd0b87
fix: repair the tab-killing NPE and the silences it hid
serialexperimentslainnnn Aug 5, 2026
1d633a6
build: keep checkDrift out of the coverage graph
serialexperimentslainnnn Aug 5, 2026
4a86da6
build: revert the platform plugin bump, it hangs the headless suite
serialexperimentslainnnn Aug 5, 2026
33c1c9b
Merge pull request #16 from serialexperimentslainnnn/feature/release-…
serialexperimentslainnnn Aug 5, 2026
b5f97ab
feat(ci): release on merge to main, version read from the code
serialexperimentslainnnn Aug 5, 2026
9ad75f5
ci: enforce the zero-deprecation rule and stop duplicating work
serialexperimentslainnnn Aug 5, 2026
79aee8b
build(deps): group Dependabot updates instead of one PR per bump
serialexperimentslainnnn Aug 5, 2026
c820ea3
style: format the failureLevel assignment per ktlint
serialexperimentslainnnn Aug 5, 2026
d686836
Merge remote-tracking branch 'origin/develop' into feature/update-pip…
serialexperimentslainnnn Aug 5, 2026
a1997de
Merge pull request #26 from serialexperimentslainnnn/feature/update-p…
serialexperimentslainnnn Aug 5, 2026
f5bca7d
build(deps): bump org.junit:junit-bom from 5.11.4 to 6.1.2
dependabot[bot] Aug 5, 2026
adac8f8
build(deps): bump actions/download-artifact in the actions group
dependabot[bot] Aug 5, 2026
2af4aac
Merge pull request #29 from serialexperimentslainnnn/dependabot/githu…
serialexperimentslainnnn Aug 5, 2026
573054c
Merge branch 'develop' into dependabot/gradle/org.junit-junit-bom-6.1.2
serialexperimentslainnnn Aug 5, 2026
57a9456
ci: stop re-running every PR on each merge, and cache on topic branches
serialexperimentslainnnn Aug 5, 2026
9398de2
ci: run the verifier only on develop and main
serialexperimentslainnnn Aug 6, 2026
20184bd
ci: put the exhaustive gate on the develop -> main door
serialexperimentslainnnn Aug 6, 2026
c66700b
ci: only the two test suites gate a branch; everything gates main
serialexperimentslainnnn Aug 6, 2026
3ab2e94
Merge pull request #28 from serialexperimentslainnnn/dependabot/gradl…
serialexperimentslainnnn Aug 6, 2026
b518a21
Merge pull request #31 from serialexperimentslainnnn/feature/update-p…
serialexperimentslainnnn Aug 6, 2026
30a80b8
ci: trigger on pull requests only, never on push
serialexperimentslainnnn Aug 6, 2026
a0e8a9a
ci: run the Gradle and Node jobs in the prebuilt image
serialexperimentslainnnn Aug 6, 2026
fbfb64d
ci: pull the private image with the run's own token
serialexperimentslainnnn Aug 6, 2026
1249fbb
fix(ci-image): bake the npm cache, not node_modules
serialexperimentslainnnn Aug 6, 2026
2fad4bc
ci: run every job in the CI image and drop the caching action
serialexperimentslainnnn Aug 6, 2026
a3eb5d6
Merge branch 'develop' of github.com:serialexperimentslainnnn/claude-…
serialexperimentslainnnn Aug 6, 2026
04957a8
ci: drop the verifier IDEs from the image and fix the warm-up
serialexperimentslainnnn Aug 6, 2026
d37cb4b
Merge pull request #33 from serialexperimentslainnnn/feature/update-p…
serialexperimentslainnnn Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Build context filter for .github/ci-image/Dockerfile.
#
# The `verify` stage does a `COPY . .` because `verifyPlugin` needs the real sources to resolve which IDEs
# to download. Without this file that COPY was a 2.09 GB layer: it swept in node_modules, build/ and .git,
# none of which the warm-up reads, and all of which stay in the image forever — a later `rm -rf` adds a
# layer, it never reclaims one.
#
# Anything the Gradle build genuinely needs must NOT be listed here. When in doubt, leave it in: a missing
# source file makes the warm-up silently resolve a different IDE set, which is the failure mode that looks
# like the cache "just not working".

# Reproduced from the lockfile by `npm ci` inside the image, and it MUST match the lockfile of whatever
# commit CI checks out rather than the one current when the image was cut.
node_modules/

# Outputs, not inputs.
build/
out/
.gradle/

# History is not a build input, and it is the single largest thing here after node_modules.
.git/
.github/ci-image/

# Local IDE and editor state.
.idea/
*.iml

# Never let a local secret or env file reach a layer.
.env
.env.*
*.log
51 changes: 51 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Line endings and binary handling (git-workflow-standards §5.2, §5.3).
#
# This repository is developed on Linux but SHIPS AND IS TESTED ON WINDOWS (ClaudeBinaryLocator resolves npm,
# scoop, volta and chocolatey install paths; TerminalLauncher emits a PowerShell call operator). Without an
# explicit policy, a contributor cloning on Windows with core.autocrlf=true rewrites every checked-in file's
# line endings, which turns a one-line change into a whole-file diff and silently breaks anything that is
# byte-sensitive. Normalisation is declared here so it does not depend on each developer's local git config.

# Default: let Git decide what is text, and store text as LF in the repository.
* text=auto eol=lf

# --- Scripts whose line endings are load-bearing -----------------------------------------------------------
# A shell script or the Gradle wrapper with CRLF fails at exec time with a confusing "bad interpreter" error.
*.sh text eol=lf
gradlew text eol=lf
bin/fake-claude text eol=lf

# Windows-native scripts must keep CRLF or cmd.exe/PowerShell can misparse them.
*.bat text eol=crlf
*.cmd text eol=crlf
*.ps1 text eol=crlf

# --- Binary: never diffed, never line-ending-converted ------------------------------------------------------
# Plugin distribution artifacts and their detached signatures: a single byte of mangling invalidates the
# GPG signature and the SHA-256 the release publishes.
*.zip binary
*.jar binary
*.asc binary
*.gpg binary
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.ico binary
*.svg text eol=lf
*.woff binary
*.woff2 binary

# --- Diff readability --------------------------------------------------------------------------------------
# Vendored frontend libraries (marked, DOMPurify, highlight.js) are minified single-line bundles. Marking them
# linguist-vendored keeps them out of the language stats, and -diff stops a bundle bump from rendering as an
# unreadable multi-thousand-column diff nobody can review.
src/main/resources/jcef/marked.min.js linguist-vendored -diff
src/main/resources/jcef/purify.min.js linguist-vendored -diff
src/main/resources/jcef/highlight.min.js linguist-vendored -diff

# Lockfiles are generated: reviewers should read the manifest change, not the lockfile churn.
package-lock.json -diff linguist-generated

# The SDK reference is protocol documentation we vendor but do not author or ship.
node_modules/** linguist-vendored
64 changes: 64 additions & 0 deletions .githooks/commit-msg
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
#!/usr/bin/env bash
# Conventional Commits gate (git-workflow-standards §3.2). Local, because this repo has no CI gate yet.
#
# Enable once per clone: git config core.hooksPath .githooks
# The hook is VERSIONED so the rule travels with the repository instead of living in one laptop's .git/hooks,
# where it is invisible to everyone else and lost on the next clone.
#
# Design rule: this hook may block a BAD MESSAGE, but it must never block because the tool itself is broken.
# Those two failures are indistinguishable from an exit code, so the hook SELF-TESTS first against a message
# known to be valid. If that self-test fails, commitlint (or its runtime) is at fault, not the author — warn
# and let the commit through. A hook that fails closed on its own bugs gets bypassed with --no-verify within a
# day, and after that it protects nothing.
set -uo pipefail

msg_file="$1"
cli="node_modules/.bin/commitlint"

[ -x "$cli" ] || {
echo "commit-msg: commitlint not installed (npm install) — Conventional Commits check skipped." >&2
exit 0
}

run_lint() {
"$cli" --edit "$1" 2>&1
}

# --- self-test: can the tool validate a message we know is well-formed? -------------------------------------
# This decides TWO things at once: whether commitlint works at all, and — because Node 24 aborts on some
# hosts' system OpenSSL config (a documented local quirk, absent from clean images) — whether this host needs
# OPENSSL_CONF neutralised. Settling that here, on a message known to be valid, means the real check below
# runs exactly ONCE. Retrying the real check instead would print the whole failure report twice.
probe="$(mktemp)"; trap 'rm -f "$probe"' EXIT
printf 'chore: commitlint self-test\n' > "$probe"
if ! run_lint "$probe" >/dev/null 2>&1; then
export OPENSSL_CONF=/dev/null
if ! run_lint "$probe" >/dev/null 2>&1; then
echo "commit-msg: commitlint could not run (toolchain issue, not your message) — check skipped." >&2
exit 0
fi
fi

# --- the real check ----------------------------------------------------------------------------------------
if output="$(run_lint "$msg_file")"; then
exit 0
fi

echo "$output" >&2
cat >&2 <<'EOF'

The commit message is not a Conventional Commit.

<type>[optional scope]: <description>

feat: a user-visible capability -> minor
fix: a user-visible bug fix -> patch
docs, refactor, perf, test, build, ci, chore -> no version bump
Breaking: add ! after the type, or a "BREAKING CHANGE:" footer -> major

This is not style policing: the CHANGELOG and the version bump are derived from these
messages, and the release tooling SILENTLY SKIPS what it cannot parse. An unparseable
message is a change that never appears in a release note.

EOF
exit 1
8 changes: 3 additions & 5 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,10 +3,8 @@
blank_issues_enabled: false

contact_links:
# TODO: replace with the actual JetBrains Marketplace URL once the listing
# short-link is confirmed.
- name: JetBrains Marketplace review
url: https://plugins.jetbrains.com/plugin/dev.lain.claude-code-for-jetbrains
url: https://plugins.jetbrains.com/plugin/31965-claude-code-native/reviews
about: Leave a rating or short review on the Marketplace listing.

# TODO: replace with the GitHub Discussions URL once enabled for the repo.
Expand All @@ -15,5 +13,5 @@ contact_links:
about: Ask a question, share a workflow, or discuss ideas before filing an issue.

- name: Security vulnerability
url: https://github.com/serialexperimentslainnnn/claude-code-for-jetbrains/security/policy
about: Do NOT open a public issue. See SECURITY.md and email lain.agent604@passmail.com.
url: https://github.com/serialexperimentslainnnn/claude-code-for-jetbrains/security/advisories/new
about: Do NOT open a public issue. Report it privately here; see SECURITY.md.
39 changes: 32 additions & 7 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,28 +16,53 @@ Closes #<issue-number> <!-- or "Refs #..." / "n/a" -->
- [ ] Docs / build / CI
- [ ] Security fix

## Risk and rollback

**Risk:** what breaks if this is wrong, and for whom? (`none` is a valid
answer for docs-only changes — say so rather than leaving it blank.)

**Rollback:** how is this undone once released? Reverting the commit is not a
rollback for a published plugin — a user on the bad version stays there until
they update. If the change touches persisted settings, the transcript format,
or the permission surface, say what happens to a user who already ran it.

## Checklist

- [ ] PR targets the `develop` branch (or `main` only for hotfixes).
- [ ] Commits follow Conventional Commits (the `commit-msg` hook enforces it —
install once with `git config core.hooksPath .githooks`).
- [ ] `./gradlew test verifyPlugin buildPlugin` passes locally.
- [ ] `verifyPlugin` is **Compatible** with IU-261 and IU-262 and reports
no new internal-API usage (`@ApiStatus.Internal`).
- [ ] `verifyPlugin` is **Compatible** across the declared range (251 → 263.\*)
and reports no new internal-API usage (`@ApiStatus.Internal`).
The CDN download is unreliable here; use
`-PlocalIdePath=<dir>[,<dir>…]` with locally-extracted IDEs.
- [ ] No new deprecated or scheduled-for-removal IntelliJ Platform APIs.
- [ ] Tests added or updated under `src/test/kotlin/...` for the new
behaviour.
- [ ] Tests added or updated for the new behaviour — `src/test/kotlin/…` for
Kotlin, `src/test/frontend/…` (`npm test`) for anything under
`src/main/resources/jcef/`.
- [ ] Protocol changes: `./gradlew checkDrift` is green and the baseline in
`scripts/drift-baseline.properties` matches what was verified.
- [ ] New dependency? Its licence is compatible with GPL-3.0-only and it is
recorded in [`THIRD-PARTY-NOTICES.md`](../THIRD-PARTY-NOTICES.md) if it
ships in the artifact.
- [ ] User-visible changes are documented in [`CHANGELOG.md`](../CHANGELOG.md)
and [`RELEASE_NOTES.md`](../RELEASE_NOTES.md) under `Unreleased`.
- [ ] No secrets, tokens, conversation transcripts, or personal absolute
paths in the diff or commit messages.
- [ ] Follows the conventions in [`CONTRIBUTING.md`](../CONTRIBUTING.md)
and the architectural contract in [`CLAUDE.md`](../CLAUDE.md).
- [ ] Follows the conventions in [`CONTRIBUTING.md`](../CONTRIBUTING.md), the
architectural contract in [`CLAUDE.md`](../CLAUDE.md), and the recorded
decisions in [`docs/adr/`](../docs/adr/README.md).

## How was this tested?

- [ ] Unit tests (`./gradlew test`)
- [ ] Unit tests (`./gradlew test`) and frontend tests (`npm test`)
- [ ] Manual sandbox (`./gradlew runIde`) — describe the scenarios you
exercised.
- [ ] Smoke test on a real IDE install — describe.
- [ ] **UI changes only:** driven with the keyboard alone, with the focus ring
visible on every control touched. Automated checks catch roughly half of
real accessibility barriers and none of the judgement calls, so this one
is not delegable to a tool.

## Notes for reviewers

Expand Down
Loading
Loading