Skip to content

🤖 docs: add pre-PR checklist and review guidance to AGENTS.md - #7897

Merged
wpfleger96 merged 6 commits into
mainfrom
wpfleger/agents-md-review-checklist
Sep 25, 2026
Merged

wpfleger96 merged 6 commits into
mainfrom
wpfleger/agents-md-review-checklist

Conversation

@wpfleger96

@wpfleger96 wpfleger96 commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Adds a "Before opening a PR" checklist and "Reviewing" guidance to AGENTS.md, and makes the Review-Proven Rules the shared reviewer checklist.

PRs stay in draft until an agent review has run, an agent has exercised the change on the affected surface, and a human has tested it. The review-completed passphrase goes in the description only once that checklist holds for the current change, and comes out if later edits change behavior. Docs-only changes use the light path: content, link, and diff checks plus human confirmation.

Reviews read VISION.md and the surface's VISION_*.md first, check the change against the Review-Proven Rules, recommend blocking only for concrete correctness, security, or contract defects with a realistic failure, label everything else optional, and put all findings in the first pass. Agents comment and never use Request Changes; humans decide which findings must be fixed.

Related: block/buzz-app#268

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
Duncan and others added 4 commits September 25, 2026 12:59
Surface guidance now sits beside the code it governs. CLAUDE.md symlinks let Claude Code load each nested file, since the root CLAUDE.md turns off its AGENTS.md fallback; root pointers cover harnesses that only walk from the repo root to the working directory.

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
The rules already capture the defects reviewers here find most often, so Reviewing names them as the shared checklist instead of leaving them author-only.

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
…tcha

Mobile-only work never reaches desktop/AGENTS.md, so the root links the screenshot-hosting rule directly. The React render-perf gotcha is desktop-only guidance.

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
Nested guides would drift from the root file; restore the moved sections to root and drop the CLAUDE.md symlinks.

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>

@baxen baxen left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread AGENTS.md
@wpfleger96
wpfleger96 marked this pull request as ready for review September 25, 2026 18:09
@wpfleger96
wpfleger96 requested a review from a team as a code owner September 25, 2026 18:09
Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Sep 25, 2026
@github-actions

Copy link
Copy Markdown

🔐 Codex Security Review

Note: This is an automated, security-focused review generated by Codex.
Use it as a supplement to human review; false positives are possible.

Scope

  • Exact PR diff: 9263cda8455b8fd27f4491e5e4fc0ebc2ce2e8bc...0a13bc88f1d4da7fca6f05c7ad4eb822060f6d83
  • Model: gpt-5.6-sol

💡 Click "edited" above to see earlier reviews for this PR.


Review Summary

Overall Risk: NONE

The PR only changes contributor guidance in AGENTS.md. No concrete security, correctness, or reliability defect was found in the changed hunks.

Findings

No concrete security, correctness, or reliability findings were identified.

Notes

  • No in-repository automation consumes the newly documented buzz-review-completed marker, so any external review-skipping behavior could not be validated from the authorized checkout.

Generated by Codex Security Review |
Requested by: @wpfleger96 |
Workflow run

@wpfleger96
wpfleger96 enabled auto-merge (squash) September 25, 2026 18:33
@wpfleger96
wpfleger96 merged commit 9c7687c into main Sep 25, 2026
36 checks passed
@wpfleger96
wpfleger96 deleted the wpfleger/agents-md-review-checklist branch September 25, 2026 18:41
wpfleger96 pushed a commit that referenced this pull request Sep 25, 2026
…rcement

* origin/main:
  fix(ci): run the admin disabled-mode DB test in the PostgreSQL lane (#7900)
  🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#7897)

Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>

# Conflicts:
#	Justfile
brow added a commit that referenced this pull request Sep 25, 2026
…ivery

* origin/main:
  feat(relay): enforce NIP-FI assertion+NIP-98 pairing on HTTP ingress (#7264)
  fix(ci): run the admin disabled-mode DB test in the PostgreSQL lane (#7900)
  🤖 docs: add pre-PR checklist and review guidance to AGENTS.md (#7897)
  docs: specify durable data backfills (#7326)
  docs(vision): add /buzz/v1 read endpoints to the protocol contract (#7879)
  🤖 fix(justfile): point just staging at the current staging relay (#7881)
  fix(relay-admin): make thread deletions atomic and fence expired action leases under row lock (#7853)
  feat(desktop): relay admin console for the /api/admin/v1 operator surface (#4768)
  fix(mobile): keep retired sections manager out of successor cache (#7873)

Signed-off-by: Tom Brow <tomb@block.xyz>

This branch was successfully deployed

1 active deployment
codex-review — 0a13bc88 Deployed Sep 25, 2026 by wpfleger96 via Run Codex Security Review #5729
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex-security-review-current The posted Codex security review matches its recorded range.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants