Skip to content

docs: harmonize governance and contribution authority - #18

Open
logbie wants to merge 4 commits into
devfrom
docs/sawako-log-19-governance
Open

logbie wants to merge 4 commits into
devfrom
docs/sawako-log-19-governance

Conversation

@logbie

@logbie logbie commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Align contribution governance with Brad's approved LOG-10 policy and dev/CEO delegations, tracked by Paperclip LOG-19. Feature branches target dev; Yomi reviews the current revision and exact-commit CI remains required.

Changes

  • Add identical versioned common contribution policy and reconcile contributor, agent, testing, security and AI guidance.
  • Add the PR evidence checklist; preserve project-specific technical and Apache-2.0 guidance.
  • Keep existing policy and technical contracts; replace contradictory authority wording.

Compatibility and risk

Documentation change is R0. No language/runtime, palette, licensing or product behavior changes in this documentation commit.
This PR is stacked on unmerged CI PR 17, and targets dev. Review the documentation commit separately from that dependency; the full base diff still includes its independently reviewed CI work. Do not merge either past its review/control gates.

Independent GitHub approval identity is deferred: shared logbie cannot approve its own PR. Yomi review and protected-branch requirements remain binding. No bypass.

Validation

Documentation commit: dbe485e992877192ff354dbab887e27c5e0f6947.
Behavior tests N/A — the new commit edits prose and PR guidance only; required Actions are not waived.
Local git diff --check, changed-Markdown local-path checks and common-policy equality checks passed. Repository hygiene passed.
External URLs and heading anchors were not network-validated. Actions on this new SHA are pending; no old-head pass is claimed.

Checklist

  • Owned documentation branch targets dev; no direct protected-branch push.
  • Scope, local checks, documentation-only exception and dependency are explicit.
  • No new credential, workflow, runtime or production changes in the documentation commit.
  • Current-SHA required Actions all passed; skipped/unrun checks explicitly recorded.
  • Yomi reviewed this revision and all triggered bot feedback is dispositioned.
  • Immediately-before-merge checks/reviews and independent approval controls satisfied.

The owner tracks pending Actions/bot feedback on Paperclip LOG-19 with a scheduled monitor. Main/release/tag/deploy decisions follow GOVERNANCE.md; this PR grants no merge permission.


Devin Review

Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c7004e99-a420-4dde-baa1-87d57b208af0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 5 potential issues.

Devin Review

Comment thread CONTRIBUTING.md
git clone --recurse-submodules https://github.com/YOUR-USERNAME/Scriptorium.git
cd Scriptorium
git switch -c fix/describe-the-change
git switch -c fix/describe-the-change origin/dev

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Checkout fails for main-only forks

For a main-only fork, git switch fails because origin/dev is absent. Contributors cannot create the documented feature branch.

Learn more

GitHub forks can contain only the default branch. The clone command here clones the contributor's fork as origin; it does not add the upstream Scriptorium repository as a remote. When that fork has no dev branch, the next command cannot resolve origin/dev and exits before creating the feature branch.

Example: Alice forks only main, clones her fork, and runs git switch -c fix/typo origin/dev. Git reports that origin/dev is not a commit, although the upstream repository has dev.

Recommended fix: Add the upstream repository as a remote, fetch its dev branch, and create the branch from that fetched ref; alternatively document how to create a fork that includes dev and verify it exists before using origin/dev.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread GOVERNANCE.md
Comment on lines +25 to +27
- Start a short-lived feature, fix or documentation branch from current `dev`;
open its PR into `dev`. Never push directly to `dev`, `main` or a release
branch, or force-push shared branches. Promotion is `dev → main` by PR.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Dependency updates still target main directly

When the scheduled updater opens a Scribe bump, gh pr create still targets main in the updater. Those updates bypass the new dev staging path.

Learn more

The new branch policy requires proposed changes to enter dev, then promote dev into main through a separate PR. The scheduled updater still creates dependency-bump PRs with --base main, and its branch is created from the default checkout rather than dev. This leaves an active automated contributor using the old submission path whenever a new Scribe revision appears.

Example: A new Scribe release triggers the weekly updater. Its PR goes from chore/update-scribe-* straight into main, rather than being reviewed and merged into dev first.

Recommended fix: Update the updater to check out current dev and create PRs against dev; also adjust any generated guidance that assumes the old target.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

branches: [main]
pull_request:
branches: [main]
branches: [main, dev]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Pull request checks use a different SHA

For dev PRs, actions/checkout tests GitHub's merge commit, not the reviewed head SHA. The new exact-commit evidence gate cannot use these checks as head-SHA results.

Learn more

A pull_request workflow checks out GitHub's generated merge ref by default. Both Governance checkout and WFL checkout omit an explicit head ref. The workflow summaries also report the checked-out SHA. This conflicts with the new exact-commit gate when reviewers compare required-check results with the PR head or release candidate commit.

Example: A PR's reviewed head is A, while GitHub creates merge commit M from A and current dev. The jobs pass on M; the policy requires individual passing results on A before the author merges it.

Recommended fix: Decide whether the policy accepts a PR merge commit tied to a specific head SHA and base revision. If it requires checks directly on the head SHA, explicitly check out github.event.pull_request.head.sha for PR jobs and record that SHA in the evidence.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread testing.md
Comment on lines +265 to +266
`blacksmith-2vcpu-ubuntu-2404`. Both workflows run for pushes to `main`, pull requests to `main` and `dev`,
and manual dispatch.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Risk classification depends on the stacked CI PR

The R0 description covers the final documentation commit, not this PR’s full base diff, which also changes CI triggers. Confirm that the stacked CI work receives its own review and required test-infrastructure evidence before merging this PR.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread CLAUDE.md
Comment on lines +3 to +5
Contribution authority, feature → `dev` PRs, exact-commit CI, Yomi review,
bot feedback, secrets and production boundaries follow
[GOVERNANCE.md](GOVERNANCE.md#common-contribution-policy--version-10-2026-09-27).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Shared governance anchor needs validation

Five policies now link to the versioned governance heading. The PR records no heading-anchor validation, so confirm the link resolves before treating it as their shared authority reference.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants