Skip to content

feat(work-items): republish v2 plugin from post-seam provider-neutral core#121

Merged
kyle-sexton merged 8 commits into
mainfrom
feat/republish-work-items-v2
Jul 12, 2026
Merged

feat(work-items): republish v2 plugin from post-seam provider-neutral core#121
kyle-sexton merged 8 commits into
mainfrom
feat/republish-work-items-v2

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

What

Republishes the work-items plugin (0.1.0 → 0.2.0) from the post-seam
provider-neutral core. v1 was a GitHub-Issues skill with inline gh and a
label-based hold→verify→claim protocol; v2 routes every tracker operation through
the work-item-tracker seam (GitHub the bound adapter today).

Changes

  • Skill re-plumbed onto the seam. Coordination (create, claim, renew/reclaim
    lease, dependency links, sub-items, frontier selection, single-item fetch) calls
    tools/work-item-tracker/work-item-tracker.sh <verb>; provider mechanics
    (filtered listing, search, aggregation, close, label/comment edits) reference the
    bound adapter's operations doc. Zero inline gh in the skill core.
  • Claiming is now assignee + lease comment, race-safe via lease-comment
    identity, with an idempotent session-start reclaim. The status:considering /
    status:claimed label hold protocol is retired for claiming.
  • Standard publish de-couple transform (migration-gate step 3). Generalized
    every medley path/name/subsystem reference to the generic consumer-context forms
    v1 established: docs/adr/*, AGENTS.md, tools/shared/comment-hygiene/*,
    review/code-quality.md, recurring-issues.yml, .github/scripts/*,
    doc-drift-detector, .claude/rules/conversational-mechanics.md "Primitive N",
    UBIQUITOUS-LANGUAGE.md, DD* design-decision tags, concrete medley area: /
    category: / ecosystem: label values, team.yaml, and example usernames. Kept
    the consumer-convention seam paths (tools/work-item-tracker/…,
    .work-item-tracker.json) and the optional .github/recurring-schedule.json.
  • version 0.1.0 → 0.2.0; new CHANGELOG.md; provider-neutral plugin.json
    description/keywords, plugin README.md, root catalog row, and marketplace tags.
  • The agent-brief template ships at reference/agent-brief.md; the core's internal
    research/ tree is excluded.

Deliberate non-fixes (flagged, not bugs)

  1. Triage vs claim label inconsistency — carried faithfully from the core.
    triage.md still routes status:needs-triage → status:considering → status:claimed as triage states, while SKILL.md/start.md/done.md/evals
    describe those labels as retired for claiming. This contradiction lives in
    the post-seam core being republished from; done.md explicitly defers it to
    "the label-reconciliation migration, not here." Reconciling it here would redo
    that migration and diverge the plugin from its source core — out of scope for a
    republish.
  2. The seam is consumer-provided, not bundled. The plugin requires the consuming
    repo to supply tools/work-item-tracker/ and bind a provider in
    .work-item-tracker.json. Generic-consumer seam distribution is a deferred
    design item (the setup/config-wizard idea). Consequence: the migration-gate
    step-8 "works in a clean repo that isn't the source" proof is N/A pending seam
    distribution
    — not assumed-passed. medley (the sole consumer today, which keeps
    the seam) works now.

Validation

  • claude plugin validate --strict (catalog + plugin manifests) — pass
  • markdownlint-cli2, typos, offline lychee (0 dead links), scripts/validate-plugins.sh — pass
  • All files LF; JSON valid
  • run-plugin-tests.sh: nothing to run (skill-only plugin, no shell tests)

Refs melodic-software/medley#1340


Note

Medium Risk
Breaking 0.2.0 requires an external seam in every consumer repo and changes multi-agent claim semantics; misconfiguration or the triage vs claim label doc split could confuse agents until consumers adopt the seam.

Overview
Republishes work-items at 0.2.0 — the skill is no longer a GitHub-Issues layer with inline gh; tracker work goes through the consumer-provided work-item-tracker seam (work-item-tracker.sh verbs + bound adapter ops). Catalog, plugin.json, README, and new CHANGELOG document the breaking shift.

Claiming and selection change materially. The label hold→verify→claim flow is retired for work/start/audit in favor of assignee + lease comment, session-start reclaim, and list-frontier for auto-pick. gh allowed-tools and pre-computed dashboard blocks are removed; creates use create-item, and decompose can set native --blocked-by edges with needs-human vs agent-ready.

Docs are generalized to provider-neutral “work item” language, seam/adapter routing, and consumer paths (.work-item-tracker.json, optional .github/recurring-schedule.json). Checklists, evals, and integration hooks (/workflow, /pull-request, /retro) are updated to match.

Install caveat: the seam is not bundled — repos must supply tools/work-item-tracker/ themselves. triage.md still documents status:considering/status:claimed triage transitions while claiming docs say those labels are retired for claims (carried from source core, per PR notes).

Reviewed by Cursor Bugbot for commit 74ed92c. Bugbot is set up for automated code reviews on this repo. Configure here.

@
feat(work-items): republish v2 plugin from post-seam provider-neutral core

Re-plumbs the work-items plugin skill onto the provider-neutral
work-item-tracker seam (GitHub the bound adapter today), replacing the
v1 inline-gh, label-based hold->verify->claim implementation.

- Skill content synced from the post-seam core: coordination routes
  through `tools/work-item-tracker/work-item-tracker.sh <verb>` (create,
  claim, renew/reclaim lease, links, sub-items, frontier); provider
  mechanics reference the bound adapter. Zero inline gh in the core.
- Claiming is now assignee + lease comment, race-safe via lease-comment
  identity, with idempotent session-start reclaim. The status:considering
  / status:claimed hold protocol is retired for claiming.
- Applied the standard publish de-couple transform: stripped medley
  path/name coupling (docs/adr, AGENTS.md, tools/shared/comment-hygiene,
  review/code-quality, recurring-issues.yml, .github/scripts,
  doc-drift-detector, .claude/rules/conversational-mechanics Primitives,
  DD design-decision tags, concrete medley label values) to the generic
  consumer-context forms established by v1; kept the consumer-convention
  seam paths and the optional .github/recurring-schedule.json.
- version 0.1.0 -> 0.2.0; new CHANGELOG.md; provider-neutral plugin.json
  description/keywords, README, root catalog row, and marketplace tags.
- agent-brief template relocated to reference/; research/ excluded.

Refs melodic-software/medley#1340
@
@
chore(work-items): genericize example usernames in skill docs

De-couple prose-level examples (@kyle -> @agent1) to match the generic
placeholders used elsewhere in the skill.

Refs melodic-software/medley#1340
@
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_81d03327-e19b-4213-862c-ba09683dfc6c)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 5m 8s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Gather context (PR diff, changed files)
  • Review plugin manifest and catalog changes
  • Review skill files for correctness and seam alignment
  • Review evals, templates, and reference docs
  • Check security and repo-agnosticism compliance
  • Post final review

Overall

The seam abstraction is well-designed — routing every coordination operation through work-item-tracker.sh <verb> cleanly isolates provider mechanics and the new lease-based claim protocol is a real improvement over the three-phase label dance. The migration is internally consistent and the deliberate carry-overs (triage label state, seam distribution) are clearly flagged. A few correctness issues below.


Findings

1. start.mdorigin/main hardcoded in two branch suggestions (repo-agnosticism violation)

L55 and L59 both emit:

git checkout -b <type>/<N>-<slug> origin/main

v0.1.0 correctly used origin/<default-branch>. This is a direct violation of CLAUDE.md's "Repo-agnostic — no hardcoded paths, repo names, or project-specific values" rule; consuming repos using master, develop, or any other default branch will get incorrect checkout commands. work.md L95 delegates to start.md's branch protocol so this inherits the bug.

Fix this →


2. label-taxonomy.mdneeds-human label absent from Meta group

label-taxonomy.md L16 lists the Meta group members as:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is not listed. However decompose.md explicitly states that HITL slices must receive needs-human (not just omit agent-ready) because list-frontier --autonomous keys on the needs-human label to exclude items from autonomous pickup. The evals (evals.json L41) and SKILL.md's operation routing table both reference this label as a first-class gating mechanism.

Consequence: an agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, silently allowing HITL slices onto the autonomous frontier.

Fix this →


3. add.md — Body template header mismatches actual template body

add.md L8 (the "Defaults applied" section) promises:

"a ## Context paragraph (what observation surfaced this item, what's the cost of leaving it), a ## Proposed work bullet list (concrete next actions), ## Acceptance criteria (one verifiable assertion per bullet), and ## References"

The actual template at L42–58 delivers none of those sections — only ## Description and ## Metadata. An AI reading the "Defaults applied" summary will expect to populate a richer structure that the template doesn't provide. Either bring the template in line with what's described, or update the description.


4. add.md--body "{body}" in shell example removes shell-injection guidance

add.md L65:

tools/work-item-tracker/work-item-tracker.sh create-item \
  --title "[Maintenance] {title}" \
  --body "{body}" \
  --labels "type:chore,category:general"

v0.1.0 had an explicit note: "Pass the generated body via --body-file (never inline --body — generated text can contain quotes, backticks, or $() that the shell would interpret)" with a corresponding mktemp + Write tool pattern. The new example drops this and shows inline --body "{body}" with no guidance on safe handling. If an AI agent directly substitutes a multi-line body containing backticks or $(...) into this shell command, the result is code execution. The same pattern appears in decompose.md's create-item example. The seam contract should clarify whether create-item accepts --body-file, or the calling guidance needs to restate the safety note.


5. work.md<sort-by> placeholder in jq expression unexplained

work.md L41:

cat .github/recurring-schedule.json | jq --arg today "$(date +%Y-%m-%d)" \
  '[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L44 explains <where_expr> but <sort-by> is not documented. The selection priority description says tier 1 sorts by next_due ascending; tier 4 says "prefer closest to next_due" which also implies next_due. Both cases should be .next_due. This should either be inlined (as the old code did) or explicitly explained alongside <where_expr>.


6. triage.mdstatus:considering → status:claimed transition leads nowhere (acknowledged carry-over, minor sharpening possible)

The PR correctly flags this as a deliberate carry-over from the post-seam core. One additional nuance worth noting: not only does triage.md recommend status:considering as a triage output (L34), the state-transitions table (L67–68) shows status:considering → status:claimed — a transition that now requires the old label-hold protocol which start.md has retired. In a consuming repo that has completed the label-reconciliation migration, an agent following the triage state-machine would apply status:considering but have no path to promote it to status:claimed via labeling. The deferred migration note in done.md covers the intent, but a `` callout on the state-transitions block would help future contributors see why it contradicts the claim protocol.


7. done.md / work.md — Bare relative path to recurring schedule drops CWD safety

done.md L24 and work.md L40 both use:

cat .github/recurring-schedule.json | jq ...

v0.1.0 rooted this path safely:

SCHEDULE="${CLAUDE_PROJECT_DIR:-$(git rev-parse --show-toplevel)}/.github/recurring-schedule.json"

If an agent is in a subdirectory when the skill runs, the bare relative read silently produces an empty result (or an error), and a due-recurring item could be missed or a recurring close misidentified. The $CLAUDE_PROJECT_DIR anchor is available precisely for this.


Summary table

# Severity File Issue
1 High start.md L55, L59 origin/main hardcoded; repo-agnosticism violation
2 High label-taxonomy.md L16 needs-human not in Meta group; HITL exclusion silently broken
3 Medium add.md L8 vs L42 Template header describes sections the template doesn't produce
4 Medium add.md L65 --body "{body}" drops shell-injection safety guidance
5 Medium work.md L41 <sort-by> jq placeholder unexplained
6 Low triage.md L67–68 status:considering → status:claimed is a dead path post-seam (carry-over, add a callout)
7 Low done.md L24, work.md L40 Bare relative schedule path; drops $CLAUDE_PROJECT_DIR safety

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 77008926b5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/add.md Outdated
Comment thread plugins/work-items/skills/work-items/actions/add.md Outdated
Comment thread plugins/work-items/skills/work-items/actions/stats.md Outdated
- Shell-safe body on create-item: write the composed body to a temp file
  via the Write tool and pass it argv-safe (the file content is one literal
  argument, never re-parsed) instead of inlining generated text that could
  contain quotes, backticks, or command substitution. Restores v1's
  body-file safety since the seam create-item takes no body-file flag.
- Optional recurring schedule now degrades gracefully: guard every
  .github/recurring-schedule.json read with an existence check and root it
  at the project directory across stats/done/search/audit/work/due/recheck,
  so the default stats dashboard (and other actions) no longer fail in repos
  without recurring setup or when invoked from a subdirectory.
- Qualify command references to the installed plugin form
  /work-items:work-items <action> (the bare form does not route in plugin
  form; matches the plugin README).

Refs melodic-software/medley#1340
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_b6f1f259-1cee-4e72-82f0-41dca1b30abd)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 2m 36s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Gather context (new commit 22b27a2 fix(work-items): address Codex publish-review findings)
  • Check which previous findings were addressed
  • Review changed files against HEAD SHA 22b27a2
  • Post final review

What the latest commit fixed

22b27a2 addresses the three Codex findings and two of the seven prior Claude findings:

Finding Status
Codex P1 — --body "{body}" shell injection (add.md) ✅ Fixed — mktemp + Write-tool pattern
Codex P2 — unqualified /work-items <action> form ✅ Fixed — consistently /work-items:work-items <action>
Codex P2 — stats.md unconditional schedule read ✅ Fixed — existence check + $CLAUDE_PROJECT_DIR anchor
Claude #4add.md shell injection (same as Codex P1) ✅ Fixed
Claude #7 — bare .github/recurring-schedule.json path ✅ Fixed across stats, done, work, audit, search, due, recheck

Still open from the previous Claude review

1. start.md L55, L59 — origin/main still hardcoded (High)

Both checkout suggestions still emit:

git checkout -b <type>/<N>-<slug> origin/main

The latest commit only updated the usage header and the trailing Notes line; the actual branch-suggestion prose at L55 and L59 was not touched. Repos with master, develop, or any other default branch will receive an invalid checkout command.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

label-taxonomy.md L16 still lists Meta members as:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is referenced as a first-class exclusion mechanism in decompose.md (L95, L126), work.md L50–53 (list-frontier --autonomous honors it to exclude HITL items), and evals.json. An agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, potentially allowing HITL slices onto the autonomous frontier.

Fix this →


3. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Defaults applied" block at L8 promises ## Context, ## Proposed work, ## Acceptance criteria, and ## References. The actual template produced in step "Build body" (L42–58) contains ## Description and ## Metadata — neither matches. An agent reading the "Defaults applied" description will try to populate structure that the template doesn't include.

Fix this →


4. work.md L42 — <sort-by> jq placeholder unexplained (Medium)

work.md L42:

jq ... '[.items[] | select(...)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due; inlining .next_due directly (as v0.1.0 did) or adding a comment alongside <where_expr> would make this self-documenting.

Fix this →


5. decompose.md L96 — Shell-safe fix not propagated (Medium — new finding)

decompose.md L96:

tools/work-item-tracker/work-item-tracker.sh create-item --title "<slice title>" --body "<body>" \

add.md was updated to use the mktemp + Write-tool pattern, but decompose.md's create-item invocation still shows inline --body "<body>". A decomposed slice body (agent-brief format with prose, code snippets, acceptance criteria) is exactly the kind of generated text that can contain backticks or $(...). The same fix needs to land here.

Fix this →


Deliberate carry-over (no action needed)

triage.md L68status:considering → status:claimed transition that the new claim protocol makes a dead path is explicitly deferred to the label-reconciliation migration, as documented in done.md. No action expected in this PR.


Summary

The 22b27a2 fix commit is clean and squarely addresses the Codex findings. Five issues from the prior review remain open. Two are High (repo-agnosticism violation in start.md; needs-human missing from label taxonomy); three are Medium (template header mismatch in add.md; <sort-by> placeholder in work.md; shell-injection fix not propagated to decompose.md).

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 22b27a28ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/decompose.md Outdated
Comment thread plugins/work-items/skills/work-items/actions/add.md Outdated
Comment thread plugins/work-items/skills/work-items/actions/work.md Outdated
Comment thread plugins/work-items/skills/work-items/actions/due.md Outdated
- decompose: route the generated slice body through the same temp-file /
  argv-safe path as add, so plan/PRD text containing backticks or command
  substitution cannot be shell-expanded when publishing slices.
- work: guard the recurring-tier jq with an existence check so ordinary
  non-recurring pickup does not fail in repos without a recurring schedule
  (rooting alone still ran jq against a missing file).
- add: the create example now passes the resolved label list built in the
  Build-labels step (including the default priority) instead of a hardcoded
  type:chore,category:general, so flagged/default taxonomy labels are applied.
- due: the orphan pass now filters to due entries (next_due <= today) before
  flagging missing items, so a healthy future entry is not reported orphaned.
- checklist: align the add reminder with the argv-safe body-file pattern.

Refs melodic-software/medley#1340
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_8f6e9b34-81e6-443b-939f-744dbc7e1557)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 2m 25s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Gather context (new commit 59d05a7 fix(work-items): address second Codex review round)
  • Check which previous findings were addressed by the latest commit
  • Review changed files against HEAD SHA 59d05a7
  • Post final review

What the latest commit fixed

59d05a7 directly targets the second Codex review round (P1 + three P2s) and closes two of the four remaining Claude findings:

Finding Status
Codex P1 — decompose.md inline --body "<body>" shell injection ✅ Fixed — mktemp + Write-tool pattern, rm -f cleanup
Codex P2 — add.md --labels "type:chore,category:general" ignores resolved list ✅ Fixed — step 3 now builds {labels} and the create-item call uses it
Codex P2 — work.md recurring tier runs without guarding the schedule file ✅ Fixed — [[ -f "$SCHEDULE" ]] && guards the jq call
Codex P2 — due.md orphan check emits all entries, including future non-due rows ✅ Fixed — guard scoped to select(.next_due <= $today)
checklist.md — add action entry updated to match argv-safe body pattern ✅ Consistent

Still open

Four findings from the prior Claude review remain unaddressed.

1. start.md L55, L59 — origin/main hardcoded (High)

Both branch-suggestion lines still emit:

git checkout -b <type>/<N>-<slug> origin/main

This is unchanged across all four commits. Repos on master, develop, or any other default branch will receive an invalid checkout command, violating the CLAUDE.md repo-agnosticism rule. work.md Step 5 delegates to start.md's protocol verbatim, so it inherits the same defect.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

The Meta row at L16 still lists:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is not there. decompose.md (L46) now explicitly documents that needs-human is what keeps a HITL slice off the frontier — "merely omitting agent-ready does NOT" — making this omission from the taxonomy more visible and more impactful than before. An agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, leaving HITL slices eligible for autonomous pickup.

Fix this →


3. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Defaults applied" block at L8 still promises:

"a ## Context paragraph…, a ## Proposed work bullet list…, ## Acceptance criteria…, and ## References"

The actual template produced at L42–58 contains ## Description and ## Metadata. None of the four promised sections appear. An agent reading the "Defaults applied" description will try to populate structure that the template doesn't provide.

Fix this →


4. work.md L42 — <sort-by> jq placeholder unexplained (Medium)

L42 still emits:

'[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due (tier 1: "sorted by next_due"; tier 4: "prefer closest to next_due"). Inline .next_due directly — as v0.1.0 did — or add a where <sort-by> is .next_due note alongside the <where_expr> explanation.

Fix this →


Deliberate carry-over (no action needed)

triage.md L67–68 (status:considering → status:claimed dead path post-seam) remains explicitly deferred to the label-reconciliation migration per done.md. No change expected here.


Summary

59d05a7 cleanly lands the second Codex round: decompose shell injection, add label resolution, work schedule guard, and due orphan filter are all correct. Four findings from the prior Claude review remain open: two High (start.md origin/main hardcoded; needs-human missing from label taxonomy) and two Medium (template header mismatch in add.md; <sort-by> placeholder in work.md).

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 59d05a74cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/done.md
Comment thread plugins/work-items/skills/work-items/actions/start.md
Comment thread plugins/work-items/skills/work-items/actions/audit.md Outdated
Comment thread plugins/work-items/skills/work-items/templates/checklist.md
audit only flags a recurring entry as orphaned once next_due <= today, matching the due action, so healthy future entries are not false-flagged.

Refs melodic-software/medley#1340
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_01ad9fe2-7fb4-4df7-94b7-9d115741790d)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 3m 11s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Gather context (latest commit 2173737 fix(work-items): filter audit orphan check to due recurring entries)
  • Check which previous findings were addressed by the latest commit
  • Review changed files against HEAD SHA 2173737
  • Post final review

What 2173737 fixed

The latest commit addresses the last Codex P2 from the third review round:

Finding Status
Codex P2 — audit.md orphan check flagging healthy future entries ✅ Fixed — filter now scoped to select(.next_due != null and .next_due <= $today) before cross-referencing

The fix is correct and self-documenting: the inline prose update alongside the code change explains exactly why only due entries can be orphaned.


Still open

Six findings from prior rounds remain unaddressed across four commits.

1. start.md L55, L59 — origin/main hardcoded (High)

Both branch-suggestion lines still emit:

git checkout -b <type>/<N>-<slug> origin/main

This has been unchanged across all five commits. Repos on master, develop, or any other default branch will receive an invalid checkout command, violating CLAUDE.md's repo-agnosticism rule. work.md Step 5 delegates to start.md's branch protocol verbatim and inherits the defect. checklist.md L9 also hardcodes from origin/main in the work-action checklist.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

label-taxonomy.md L16 still lists Meta members as:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

decompose.md now explicitly states that needs-human is the HITL exclusion mechanism — "merely omitting agent-ready does NOT" — making this omission more impactful than before. An agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, leaving HITL slices eligible for list-frontier --autonomous pickup.

Fix this →


3. checklist.md L38–41 — Recheck section describes the retired v1 flow (Medium)

checklist.md L38–41:

## Action: recheck

- [ ] Search items with `recheck:` body lines older than threshold
- [ ] For each, evaluate trigger; close-with-comment OR re-open per outcome
- [ ] Update item body with re-check timestamp

recheck.md describes a completely different flow: find the entry in .github/recurring-schedule.json, update last_checked and next_due in the schedule file, then close the associated recurring item. The checklist's "search for recheck: body lines / update item body" path is the retired v1 protocol. An agent following the checklist will skip advancing next_due, leaving the recurring item perpetually due on every subsequent run.

Fix this →


4. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Body template" bullet at L8 still promises ## Context, ## Proposed work, ## Acceptance criteria, and ## References. The actual template at L42–58 produces ## Description, optional ## Context (only when --context is passed), optional ## Recurring, and ## Metadata. An agent reading "Defaults applied" will try to populate structure that the template doesn't deliver.

Fix this →


5. work.md L42 — <sort-by> placeholder unexplained (Medium)

work.md L42:

'[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due (tier 1: "sorted by next_due"; tier 4: "prefer closest to next_due"). Inline .next_due directly or add a note alongside the <where_expr> explanation.

Fix this →


6. Seam invocations relative to CWD, not project root (Low)

All seam invocations across start.md, work.md, add.md, audit.md, decompose.md etc. use:

tools/work-item-tracker/work-item-tracker.sh <verb>

Schedule file reads were fixed to use $CLAUDE_PROJECT_DIR (e.g. audit.md L28), but the seam script itself is still a relative path. If an agent is in a subdirectory when the skill runs, every seam call fails before the adapter is reached. The same CLAUDE_PROJECT_DIR-anchored pattern applied to the schedule reads should be documented for the seam path — either in each action or in a shared SKILL.md preamble note.


Deliberate carry-over (no action needed)

triage.md L67–68 (status:considering → status:claimed is a dead path post-seam) remains explicitly deferred to the label-reconciliation migration per done.md. No change expected here.


Summary table

# Severity File Issue
1 High start.md L55, L59; checklist.md L9 origin/main hardcoded; repo-agnosticism violation
2 High label-taxonomy.md L16 needs-human absent from Meta group; HITL exclusion silently broken
3 Medium checklist.md L38–41 Recheck section describes the retired recheck: body-lines v1 flow
4 Medium add.md L8 Template header describes sections the template doesn't produce
5 Medium work.md L42 <sort-by> jq placeholder unexplained
6 Low All skill action files Seam invocations relative to CWD; no $CLAUDE_PROJECT_DIR anchor

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 21737377ab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/add.md
Comment thread plugins/work-items/skills/work-items/actions/add.md
Comment thread plugins/work-items/skills/work-items/actions/add.md
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_09b04f6e-8c5c-47a7-9222-0de3dd9dec8d)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 45s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Identify what the latest merge commit eb29687 brought in
  • Check which prior open findings remain vs. are now fixed
  • Review current file state for all outstanding issues
  • Post final review

What eb29687 brought in

eb29687 is a pure merge from main (code-tidying setup skill + knowledge youtube skill). No plugins/work-items/ files were touched. All four outstanding findings from the prior review carry forward unchanged.


Still open

1. start.md L55, L59 + checklist.md L9 — origin/main hardcoded (High)

start.md L55 and L59 both still emit:

git checkout -b <type>/<N>-<slug> origin/main

checklist.md L9 also still reads:

- [ ] Branch — `git checkout -b <type>/<N>-<short-slug>` from origin/main

This is unchanged across all six commits. Consuming repos on master, develop, or any other default branch will receive invalid checkout commands — a direct violation of CLAUDE.md's repo-agnosticism rule.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

The Meta row at L16 still lists:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is the mechanism list-frontier --autonomous uses to exclude HITL slices (work.md L50–53 explicitly documents this). decompose.md now underscores it: "merely omitting agent-ready does NOT" keep a HITL item off the frontier. An agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, leaving HITL slices eligible for autonomous pickup.

Fix this →


3. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Body template" bullet at L8 still promises:

"a ## Context paragraph…, a ## Proposed work bullet list…, ## Acceptance criteria…, and ## References"

The actual template at L42–58 produces ## Description, optional ## Context (only when --context is passed), optional ## Recurring, and ## Metadata. None of the four promised sections match. An agent reading "Defaults applied" will try to populate structure that doesn't exist in the template.

Fix this →


4. work.md L42 — <sort-by> jq placeholder unexplained (Medium)

work.md L42:

'[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due. The placeholder should be inlined as .next_due or a companion explanation added alongside the <where_expr> note.

Fix this →


Deliberate carry-overs (no action needed)

  • checklist.md L38–41 — Recheck section describing recheck: body-lines v1 flow: PR author deferred this to a doc-accuracy follow-up, noting the authoritative flow in recheck.md is correct.
  • Relative seam paths (tools/work-item-tracker/... without $CLAUDE_PROJECT_DIR anchor): PR author deferred this as a core-seam pass out of scope for a mechanical republish, noting skills run with cwd at project root where it resolves.
  • triage.md L67–68 (status:considering → status:claimed dead path): explicitly deferred to label-reconciliation migration per done.md.

Summary

The eb29687 merge brings in unrelated main-branch changes; no work-items files were modified. Four findings from prior review rounds remain open: two High (origin/main hardcoded in start.md/checklist.md; needs-human missing from label taxonomy) and two Medium (template header mismatch in add.md; <sort-by> placeholder in work.md).

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb29687021

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/decompose.md
Comment thread plugins/work-items/skills/work-items/actions/due.md
Comment thread plugins/work-items/skills/work-items/actions/triage.md
Comment thread plugins/work-items/skills/work-items/actions/start.md
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_48f42e0d-d693-44c8-9fd8-5f9f4e6b5c23)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 43s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Identify what the latest merge commit 695f331 brought in
  • Verify state of all outstanding findings against current HEAD
  • Post final review

What 695f331 brought in

695f331 is a pure merge from main (discovery plugin: re-runnable setup skill for notes_dir seam). Only plugins/discovery/ files were touched — no plugins/work-items/ changes.


Still open

All four findings from the previous review carry forward unchanged.

1. start.md L55, L59 + checklist.md L9 — origin/main hardcoded (High)

start.md L55 and L59 both emit:

git checkout -b <type>/<N>-<slug> origin/main

checklist.md L9 also reads:

- [ ] Branch — `git checkout -b <type>/<N>-<short-slug>` from origin/main

Unchanged across all seven commits. Repos on master, develop, or any other default branch will receive invalid checkout commands — a direct violation of CLAUDE.md's repo-agnosticism rule. work.md Step 5 delegates to start.md's branch protocol and inherits the defect.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

The Meta row at label-taxonomy.md L16 still lists:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is the mechanism list-frontier --autonomous uses to exclude HITL slices (work.md L50–53). decompose.md now underscores it: "merely omitting agent-ready does NOT" keep a HITL item off the frontier. Omitting needs-human from the taxonomy means an agent that validates labels before calling create-item will reject it as unknown, leaving HITL slices eligible for autonomous pickup.

Fix this →


3. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Body template" bullet at add.md L8 still promises:

"a ## Context paragraph…, a ## Proposed work bullet list…, ## Acceptance criteria…, and ## References"

The actual template at L42–58 produces ## Description, optional ## Context (only when --context is passed), optional ## Recurring, and ## Metadata. None of the four promised sections match. An agent reading "Defaults applied" will try to populate structure that the template doesn't include.

Fix this →


4. work.md L42 — <sort-by> jq placeholder unexplained (Medium)

work.md L42:

'[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due (tier 1: "sorted by next_due"; tier 4: "prefer closest to next_due"). Inline .next_due directly or add a companion note alongside the <where_expr> explanation.

Fix this →


Deliberate carry-overs (no action needed)

  • checklist.md L38–41 — Recheck section describing retired recheck: body-lines v1 flow: deferred to a doc-accuracy follow-up per PR author; authoritative flow in recheck.md is correct.
  • Relative seam paths (tools/work-item-tracker/... without $CLAUDE_PROJECT_DIR anchor): deferred as a core-seam pass out of scope for a mechanical republish; skills run with cwd at project root where it resolves.
  • triage.md L67–68 (status:considering → status:claimed dead path): explicitly deferred to label-reconciliation migration per done.md.

Summary

695f331 is a pure merge from main (discovery plugin only). Four findings from prior review rounds remain open: two High (origin/main hardcoded in start.md/checklist.md; needs-human missing from label taxonomy) and two Medium (template header mismatch in add.md; <sort-by> placeholder in work.md).

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 695f331305

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/work.md
Comment thread plugins/work-items/skills/work-items/actions/decompose.md
@cursor

cursor Bot commented Jul 12, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_54878d02-1941-47df-8980-769ce1dfa040)

@claude

claude Bot commented Jul 12, 2026

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 1m 40s —— View job


PR Review: feat(work-items): republish v2 plugin from post-seam provider-neutral core

Tasks

  • Identify what merge commit 74ed92c brought in
  • Check state of all outstanding findings against current HEAD
  • Read the relevant files to verify findings
  • Post final review

What 74ed92c brought in

74ed92c is a pure merge from main (evals for discovery + memory-health skills, a Miro MCP plugin, guardrails block-hook-bypass hook). No plugins/work-items/ files were touched — all four outstanding findings carry forward unchanged.


Still open

1. start.md L55, L59 + checklist.md L9 — origin/main hardcoded (High)

start.md L55 and L59 both still emit:

git checkout -b <type>/<N>-<slug> origin/main

checklist.md L9 also reads:

- [ ] Branch — `git checkout -b <type>/<N>-<short-slug>` from origin/main

This has been unchanged across all eight commits. Consuming repos on master, develop, or any other default branch receive invalid checkout commands — a direct violation of CLAUDE.md's repo-agnosticism rule. work.md Step 5 delegates to start.md's branch protocol and inherits the same defect.

Fix this →


2. label-taxonomy.md L16 — needs-human absent from Meta group (High)

The Meta row at label-taxonomy.md L16 still lists:

`automated`, `recurring`, `agent-ready`, `good-first-issue`, `migrated`, `stale`

needs-human is the mechanism list-frontier --autonomous uses to exclude HITL slices (work.md L50–53). decompose.md explicitly states "merely omitting agent-ready does NOT" keep a HITL item off the frontier. An agent validating labels against the taxonomy before calling create-item will reject needs-human as unknown, leaving HITL slices eligible for autonomous pickup.

Fix this →


3. add.md L8 — Template header describes sections the template doesn't produce (Medium)

The "Body template" bullet at add.md L8 still promises:

"a ## Context paragraph…, a ## Proposed work bullet list…, ## Acceptance criteria…, and ## References"

The actual template produced at L42–58 contains ## Description, optional ## Context (only when --context is passed), optional ## Recurring, and ## Metadata. None of the four promised sections match. An agent reading "Defaults applied" will try to populate structure that the template doesn't include.

Fix this →


4. work.md L42 — <sort-by> jq placeholder unexplained (Medium)

work.md L42:

'[.items[] | select(.next_due != null and .next_due <where_expr> $today)] | sort_by(.<sort-by>)'

L45 explains <where_expr> but <sort-by> has no companion note. Both recurring tiers sort by next_due (tier 1: "sorted by next_due"; tier 4: "prefer closest to next_due"). Inline .next_due directly or add a companion note alongside the <where_expr> explanation at L45.

Fix this →


Deliberate carry-overs (no action needed)

  • checklist.md L38–41 — Recheck section describing retired recheck: body-lines v1 flow: deferred to a doc-accuracy follow-up per PR author; authoritative flow in recheck.md is correct.
  • Relative seam paths (tools/work-item-tracker/... without $CLAUDE_PROJECT_DIR anchor): deferred as a core-seam pass out of scope for a mechanical republish; skills run with cwd at project root where it resolves.
  • triage.md L67–68 (status:considering → status:claimed dead path): explicitly deferred to label-reconciliation migration per done.md.

Summary table

# Severity File Issue
1 High start.md L55, L59; checklist.md L9 origin/main hardcoded; repo-agnosticism violation
2 High label-taxonomy.md L16 needs-human absent from Meta group; HITL exclusion silently broken
3 Medium add.md L8 Template header describes sections the template doesn't produce
4 Medium work.md L42 <sort-by> jq placeholder unexplained

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: medium. Did not approve because Cursor Bugbot completed with skip status (usage limit reached), so the required automated review did not complete successfully. Human review is needed before merge; no reviewers were assigned because the PR author is the sole human repository contributor.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 74ed92c012

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/work-items/skills/work-items/actions/decompose.md
@kyle-sexton
kyle-sexton merged commit 1a7a9d3 into main Jul 12, 2026
41 of 43 checks passed
@kyle-sexton
kyle-sexton deleted the feat/republish-work-items-v2 branch July 12, 2026 22:43
kyle-sexton added a commit that referenced this pull request Jul 17, 2026
Route ccp's remaining GitHub-hosted control-plane lanes through the
governed runner selector to the self-hosted fleet, ending hosted-minute
spend on this private repo:

- ci.yml ci-status and pr-title.yml pr-title: the fail-closed required
  gateways route via the selector instead of a fixed ubuntu-24.04 runner
  (fail-closed on selector/fleet outage is the accepted tradeoff).
- pr-title validate-pr-title: bump semantic-pr to its runner-input
  variant, passing runner + prerequisite-result.
- link-check: migrate to the runner-input link-check reusable behind a
  select-runner job; retire the strict-policy pause.
- Add do-not-merge and pr-issue-linkage callers (ci-workflows#120/#121),
  both routed through the selector.
- Drop all .github/runner-policy.json hosted exceptions (now zero).

Refs melodic-software/github-iac#78.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K3QehVwmWzkBLpKokNCkkt

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Jul 17, 2026
Route ccp's remaining GitHub-hosted control-plane lanes through the
governed runner selector to the self-hosted fleet, ending hosted-minute
spend on this private repo:

- ci.yml ci-status and pr-title.yml pr-title: the fail-closed required
  gateways route via the selector instead of a fixed ubuntu-24.04 runner
  (fail-closed on selector/fleet outage is the accepted tradeoff).
- pr-title validate-pr-title: bump semantic-pr to its runner-input
  variant, passing runner + prerequisite-result.
- link-check: migrate to the runner-input link-check reusable behind a
  select-runner job; retire the strict-policy pause.
- Add do-not-merge and pr-issue-linkage callers (ci-workflows#120/#121),
  both routed through the selector.
- Drop all .github/runner-policy.json hosted exceptions (now zero).

Refs melodic-software/github-iac#78.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K3QehVwmWzkBLpKokNCkkt

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
kyle-sexton added a commit that referenced this pull request Jul 17, 2026
Wave 3 per-repo floor conversion (melodic-software/github-iac#78,
2026-07-16 owner override): converts every remaining hosted
control-plane lane to governed selector routing — claude-code-plugins
ends with ZERO runner-policy exceptions.

No linked issue.

## What

- `ci.yml`: ci-status aggregate routes with `if: ${{ !cancelled() }}`
(fails closed through execution on the hosted fallback, never by
skipping); the workflow-schema `files:` list gains the two new callers.
- `pr-title.yml`: the required-check status wrapper routes to the fleet;
semantic-pr pin bumped to `51012e2` with `prerequisite-result` (`if: ${{
always() }}` per the validator's fail-closed reporter contract).
- `link-check.yml`: select-runner added; pin bumped to the `3dfb184`
runner-input variant; retired the `CI_RUNNER_POLICY != self-hosted-only`
pause guard.
- New `do-not-merge` + `pr-issue-linkage` callers
(melodic-software/ci-workflows#120 / #121 rollout):
`pull_request_target` + `merge_group`; execute on the hosted fallback
until melodic-software/ci-workflows#130 admits those events.
- `runner-policy.json`: all 3 exceptions dropped → `"exceptions": {}`.

## Verification

- Local `runner-policy.mjs` run (CI env parity): clean; the two new
callers' contracts landed via the standards sync (#236) already merged
to main.
- actionlint clean; every converted `runs-on` keeps the `||
'ubuntu-24.04'` fallback (epic decision 4).

## Related

- melodic-software/github-iac#78 (epic — Wave 3)
- melodic-software/ci-workflows#120, melodic-software/ci-workflows#121,
melodic-software/ci-workflows#130

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K3QehVwmWzkBLpKokNCkkt

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant