Skip to content

chore(repo): the FerroHEALTH organisation setup (#704) - #705

Merged
rubentalstra merged 5 commits into
mainfrom
chore/ferrohealth-org-setup
Oct 5, 2026
Merged

rubentalstra merged 5 commits into
mainfrom
chore/ferrohealth-org-setup

Conversation

@rubentalstra

@rubentalstra rubentalstra commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

What changed and why

FerroTERM moves onto the FerroHEALTH organisation model that FerroFED already runs (FerroHEALTH/FerroFED#154, FerroHEALTH/FerroFED#598, FerroHEALTH/FerroFED#605).

  • Native issue type and fields. scripts/gh/fields.sh sets and reads the type (Bug, Feature, Task), the Priority and the Effort of an issue and files new issues with all three. scripts/gh/migrate-fields.sh moves the open issues off the bug, enhancement and P0 to P3 labels and gives each a judged effort. Closed issues stay as they are (owner decision), so they lose their type and priority labels when labels.sh deletes them. scripts/gh/labels.sh retires those six labels plus blocked (the native blocked-by edge carries it) and adds no-changelog. A new tracker-helpers CI job runs the --self-test of fields.sh, labels.sh, migrate-fields.sh and rel.sh.
  • Merge queue. ci.yml already runs on merge_group; it now also reruns on labeled/unlabeled. The docs, memory and .claude/settings.json arm pull requests with gh pr merge <n> --auto and deny --admin and -R.
  • Changelog fragments. changelog.d/, scripts/release/changelog.sh (--check, --assemble), scripts/checks/changelog-guard.sh, and the changelog and changelog-guard jobs. The release checklist assembles the fragments, so pull requests stop conflicting on [Unreleased]. I trial-ran --assemble against this repository's CHANGELOG.md in a scratch clone and it produced a clean section and link references.
  • Board helper. project.sh points at the organisation board, adds transfer/transferred, and reads status updates through organization(...).
  • SonarQube Cloud. The analysis moves to FerroHEALTH_FerroTERM in the ferrohealth organization, as FerroFED and FerroEHR (ci(sonar): point SonarQube Cloud at the FerroHEALTH project and list it as a code-scanning tool FerroFED#387). That project existed but had never been analyzed. sonar-project.properties, the README badges, .mcp.json, the review rule and docs/ci-cd.md name it. After each analysis of main, scripts/sonar/sarif.sh converts the open issues to SARIF and sonar.yml uploads them to code scanning under sonarqube-cloud.
  • Claude configuration. Adds the block_dangerous and versions_guard hooks. The port is hardened: each command of a compound line is judged on its own, --recursive/--force count, and a push that deletes main is refused. The SessionStart dump and /phase-status print <Type/Priority>, and /next-task orders by priority. Every reader of an issue uses gh issue view --json, because on gh 2.101.0 --comments prints nothing for an issue without comments. The rules, agents, issue forms, PR template and release-note categories follow the new model.

No specification governs any of this; it is our own design.

Part of #704. Its remaining criteria are tracker-side steps (the migration apply, the label retirement, the ruleset's merge queue and the board), and the issue closes once they are done.

Licensing of contributions

  • I accept the terms in CONTRIBUTING.md § Licensing of contributions: I have the right to submit this work, I license it under the project licence of the version it lands in, and I grant the Licensor the relicensing right stated there.

Checklist

  • Local gates pass: no Rust changed. shellcheck --severity=style, actionlint and zizmor --min-severity=low .github/ are clean apart from the dependabot cooldown finding already on main. comment-style.sh, versions.sh and repo-map.sh pass.
  • The --self-test of every scripts/gh/ helper and scripts/ guard the change touched passes.
  • A changelog fragment, changelog.d/704-changelog-fragments.changed.md, records the change.
  • Docs are updated.
  • Every commit is signed.
  • No AI or assistant attribution anywhere in the commits or this PR.

FerroTERM moves onto the organisation model FerroFED runs.

- The type, priority and effort of an issue are the organisation's native
  issue type and its Priority and Effort issue fields. scripts/gh/fields.sh
  sets and reads them and files new issues with all three;
  scripts/gh/migrate-fields.sh moves every issue off the bug, enhancement
  and P0 to P3 labels (plan, apply, verify); scripts/gh/labels.sh retires
  those six and `blocked`, and adds no-changelog. A tracker-helpers CI job
  runs every helper's --self-test.
- main merges through the merge queue: CI reruns on label changes, and the
  docs, memory and settings arm pull requests with gh pr merge <n> --auto
  and deny --admin.
- Changelog fragments under changelog.d/, checked by
  scripts/release/changelog.sh --check and changelog-guard, and assembled
  into CHANGELOG.md at the release cut.
- project.sh gains transfer/transferred and points at the organisation
  board; rel.sh gains a --self-test.
- The block_dangerous and versions_guard hooks, the SessionStart dump and
  /phase-status print <Type/Priority>, /next-task orders by priority, and
  every reader of an issue uses gh issue view --json.
@rubentalstra
rubentalstra enabled auto-merge (squash) October 5, 2026 17:11
…hook (#704)

The hook ported from FerroFED let a /tmp delete clear every other delete on
the same line, missed --recursive and --force, and allowed deleting main
on a remote. It now tokenizes each command of a compound line, refuses a
recursive forced delete unless every path sits under /tmp with no '..',
and refuses a push that deletes main or master, or mirrors. The merge
deny rule also catches -R glued to its value.
…it as a code-scanning tool (#704)

The project is FerroHEALTH_FerroTERM in the ferrohealth organization, as
FerroFED and FerroEHR. sonar-project.properties, the README badges,
.mcp.json, the review rule, docs/ci-cd.md and the org-move memory name it.
After each analysis of main, scripts/sonar/sarif.sh converts the open
issues to SARIF and the workflow uploads them to code scanning under the
category sonarqube-cloud, as FerroFED does (FerroHEALTH/FerroFED#387).
#704)

The per-command rewrite judged rm only as the command word, so xargs rm,
then rm, bash -c "rm ..." and \\rm passed where the original pattern
refused them. Each command is now scanned for an rm word with quotes and
backslashes stripped.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

… are (#704)

Owner decision 2026-10-05: migrate-fields.sh skips a closed issue, which
keeps no type or priority once labels.sh deletes the old labels. The
self-test pins that a closed issue gets no write.
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

@rubentalstra
rubentalstra disabled auto-merge October 5, 2026 17:27
@rubentalstra
rubentalstra merged commit ede4192 into main Oct 5, 2026
42 checks passed
@rubentalstra
rubentalstra deleted the chore/ferrohealth-org-setup branch October 5, 2026 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants