From aa73793b900ca9dc5745e9a29181da79f0ddf81e Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Wed, 8 Jul 2026 13:10:10 +0200 Subject: [PATCH] =?UTF-8?q?chore(memory):=20job9=20=E2=80=94=20commit-chan?= =?UTF-8?q?ger=20trailer=20fix=20+=20J4-16=20cross-check=20follow-up?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/memory/journal.md | 2 +- .claude/tasks/TODO.md | 7 +++++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/.claude/memory/journal.md b/.claude/memory/journal.md index ff8a831..55614c0 100644 --- a/.claude/memory/journal.md +++ b/.claude/memory/journal.md @@ -364,4 +364,4 @@ rules: - **Part 1** (4 commits, `0ede52c`..`5ab6c21`): commit-changer drop unused `Agent`; verifier + security-auditor + plugin-advisor pinned `model: sonnet`. Gate = real dispatch smoke on sonnet: verifier `CONFORME`, security-auditor `BLOCK(2)` (checklist caught planted hardcoded-secret + SQLi that semgrep 1.168.0 missed), plugin-advisor `ACTION REQUIRED` — verdict grammar intact, mode honored, no revert. - **Part 2** (`a5a7b54`/`6df42e4`/`c498b93`/`70fb3b4` + hardening `212f9aa`): seo/geo analyzers re-architected to fix-bundle→L1 (validator-analyzer contract), `Agent` dropped from both `tools:`; `/seo` new STEP 1.5 applies at L1 (serial by ownership, dissolves the parallel-edit race), `/geo` → dispatch+apply orchestrator, `/harden` already end-to-end path-b (untouched), `/onboard` audit-only (untouched). [[BDR-060]] version floor + [[BDR-061]] path-b doctrine. 4 real smokes green: analyzer emits bundle + edits nothing (md5 unchanged, no files created); AUTO fix LANDS on disk via L1 hotfixer with no confirmation (the exact previously-broken path — *report but zero fix* → resolved); GATED withheld pre-accord then applied post-accord (new tier, first test); /onboard writes only the report, zero source files. - **Part 3** (`87d63bf`/`af9656f`): H2 "Load and follow" idiom → **INLINE-LOAD** verb at code-cleaner + scaffolder (main-loop-BECOMES-agent, `Agent` not involved), drop unused `Agent` from code-cleaner; H1 code-cleaner→refactorer handoff now a named artifact `.claude/audits/CODE-CLEAN-SCOPE.md`. Tight scope per user (2 cited sites, no 40-site rewrite). -- Branch unmerged, human gate. **Latent (out of scope, flagged not fixed)**: `commit-changer.md:109` commit-message template still carries `Co-Authored-By: Claude ` — contradicts the hard no-attribution ban ([[no-commit-attribution]]); needs a separate fix. +- Branch unmerged, human gate. **Fixed** (`5a3de92`, isolated): stripped `Co-Authored-By: Claude` from `commit-changer.md` message template — it contradicted [[no-commit-attribution]] since the template's creation (the settings.json backstop caught real commits, but the template itself would keep re-seeding the trailer). Only banned trailer in the file (no Claude-Session/--trailer). FOLLOW-UP next cycle: cross with J4-16 (lib-layer lock) to verify no other agent template carries the same trailer. diff --git a/.claude/tasks/TODO.md b/.claude/tasks/TODO.md index afc8469..fa5a217 100644 --- a/.claude/tasks/TODO.md +++ b/.claude/tasks/TODO.md @@ -30,8 +30,11 @@ PART 3 — IMPLICIT-HANDOFF (tight scope, 2 sites) — DONE: - [x] 8 — H1 code-cleaner→refactorer named artifact .claude/audits/CODE-CLEAN-SCOPE.md Capitalize DONE: LRN-112 (nesting) + BDR-060 (floor) + BDR-061 (path-b) + journal. -LATENT (flagged, out of scope): commit-changer.md:109 template still has -Co-Authored-By: Claude → contradicts no-attribution ban, needs separate fix. +- [x] commit-changer template Co-Authored-By stripped (5a3de92, isolated) — + contradicted no-attribution ban since creation +- [ ] FOLLOW-UP next cycle: cross with J4-16 (lib-layer lock) — verify no other + agent/template carries a banned attribution trailer (Co-Authored-By/ + Claude-Session/--trailer) Branch unmerged, human gate. ## 2026-07-07 — job8 third-party security hardening (chore/job8-hardening)