chore(memory): job9 — commit-changer trailer fix + J4-16 cross-check follow-up
This commit is contained in:
@@ -364,4 +364,4 @@ rules:
|
||||
- **Part 1** (4 commits, `0ede52c`..`5ab6c21`): commit-changer drop unused `Agent`; verifier + security-auditor + plugin-advisor pinned `model: sonnet`. Gate = real dispatch smoke on sonnet: verifier `CONFORME`, security-auditor `BLOCK(2)` (checklist caught planted hardcoded-secret + SQLi that semgrep 1.168.0 missed), plugin-advisor `ACTION REQUIRED` — verdict grammar intact, mode honored, no revert.
|
||||
- **Part 2** (`a5a7b54`/`6df42e4`/`c498b93`/`70fb3b4` + hardening `212f9aa`): seo/geo analyzers re-architected to fix-bundle→L1 (validator-analyzer contract), `Agent` dropped from both `tools:`; `/seo` new STEP 1.5 applies at L1 (serial by ownership, dissolves the parallel-edit race), `/geo` → dispatch+apply orchestrator, `/harden` already end-to-end path-b (untouched), `/onboard` audit-only (untouched). [[BDR-060]] version floor + [[BDR-061]] path-b doctrine. 4 real smokes green: analyzer emits bundle + edits nothing (md5 unchanged, no files created); AUTO fix LANDS on disk via L1 hotfixer with no confirmation (the exact previously-broken path — *report but zero fix* → resolved); GATED withheld pre-accord then applied post-accord (new tier, first test); /onboard writes only the report, zero source files.
|
||||
- **Part 3** (`87d63bf`/`af9656f`): H2 "Load and follow" idiom → **INLINE-LOAD** verb at code-cleaner + scaffolder (main-loop-BECOMES-agent, `Agent` not involved), drop unused `Agent` from code-cleaner; H1 code-cleaner→refactorer handoff now a named artifact `.claude/audits/CODE-CLEAN-SCOPE.md`. Tight scope per user (2 cited sites, no 40-site rewrite).
|
||||
- Branch unmerged, human gate. **Latent (out of scope, flagged not fixed)**: `commit-changer.md:109` commit-message template still carries `Co-Authored-By: Claude <noreply@anthropic.com>` — contradicts the hard no-attribution ban ([[no-commit-attribution]]); needs a separate fix.
|
||||
- Branch unmerged, human gate. **Fixed** (`5a3de92`, isolated): stripped `Co-Authored-By: Claude` from `commit-changer.md` message template — it contradicted [[no-commit-attribution]] since the template's creation (the settings.json backstop caught real commits, but the template itself would keep re-seeding the trailer). Only banned trailer in the file (no Claude-Session/--trailer). FOLLOW-UP next cycle: cross with J4-16 (lib-layer lock) to verify no other agent template carries the same trailer.
|
||||
|
||||
@@ -30,8 +30,11 @@ PART 3 — IMPLICIT-HANDOFF (tight scope, 2 sites) — DONE:
|
||||
- [x] 8 — H1 code-cleaner→refactorer named artifact .claude/audits/CODE-CLEAN-SCOPE.md
|
||||
|
||||
Capitalize DONE: LRN-112 (nesting) + BDR-060 (floor) + BDR-061 (path-b) + journal.
|
||||
LATENT (flagged, out of scope): commit-changer.md:109 template still has
|
||||
Co-Authored-By: Claude → contradicts no-attribution ban, needs separate fix.
|
||||
- [x] commit-changer template Co-Authored-By stripped (5a3de92, isolated) —
|
||||
contradicted no-attribution ban since creation
|
||||
- [ ] FOLLOW-UP next cycle: cross with J4-16 (lib-layer lock) — verify no other
|
||||
agent/template carries a banned attribution trailer (Co-Authored-By/
|
||||
Claude-Session/--trailer)
|
||||
Branch unmerged, human gate.
|
||||
|
||||
## 2026-07-07 — job8 third-party security hardening (chore/job8-hardening)
|
||||
|
||||
Reference in New Issue
Block a user