Repository navigation
chore(repo): the FerroHEALTH organisation setup (#704) - #705
Merged
Merged
Conversation
FerroTERM moves onto the organisation model FerroFED runs. - The type, priority and effort of an issue are the organisation's native issue type and its Priority and Effort issue fields. scripts/gh/fields.sh sets and reads them and files new issues with all three; scripts/gh/migrate-fields.sh moves every issue off the bug, enhancement and P0 to P3 labels (plan, apply, verify); scripts/gh/labels.sh retires those six and `blocked`, and adds no-changelog. A tracker-helpers CI job runs every helper's --self-test. - main merges through the merge queue: CI reruns on label changes, and the docs, memory and settings arm pull requests with gh pr merge <n> --auto and deny --admin. - Changelog fragments under changelog.d/, checked by scripts/release/changelog.sh --check and changelog-guard, and assembled into CHANGELOG.md at the release cut. - project.sh gains transfer/transferred and points at the organisation board; rel.sh gains a --self-test. - The block_dangerous and versions_guard hooks, the SessionStart dump and /phase-status print <Type/Priority>, /next-task orders by priority, and every reader of an issue uses gh issue view --json.
rubentalstra
enabled auto-merge (squash)
October 5, 2026 17:11
…hook (#704) The hook ported from FerroFED let a /tmp delete clear every other delete on the same line, missed --recursive and --force, and allowed deleting main on a remote. It now tokenizes each command of a compound line, refuses a recursive forced delete unless every path sits under /tmp with no '..', and refuses a push that deletes main or master, or mirrors. The merge deny rule also catches -R glued to its value.
…it as a code-scanning tool (#704) The project is FerroHEALTH_FerroTERM in the ferrohealth organization, as FerroFED and FerroEHR. sonar-project.properties, the README badges, .mcp.json, the review rule, docs/ci-cd.md and the org-move memory name it. After each analysis of main, scripts/sonar/sarif.sh converts the open issues to SARIF and the workflow uploads them to code scanning under the category sonarqube-cloud, as FerroFED does (FerroHEALTH/FerroFED#387).
#704) The per-command rewrite judged rm only as the command word, so xargs rm, then rm, bash -c "rm ..." and \\rm passed where the original pattern refused them. Each command is now scanned for an rm word with quotes and backslashes stripped.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
… are (#704) Owner decision 2026-10-05: migrate-fields.sh skips a closed issue, which keeps no type or priority once labels.sh deletes the old labels. The self-test pins that a closed issue gets no write.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What changed and why
FerroTERM moves onto the FerroHEALTH organisation model that FerroFED already runs (FerroHEALTH/FerroFED#154, FerroHEALTH/FerroFED#598, FerroHEALTH/FerroFED#605).
scripts/gh/fields.shsets and reads the type (Bug,Feature,Task), thePriorityand theEffortof an issue and files new issues with all three.scripts/gh/migrate-fields.shmoves the open issues off thebug,enhancementandP0toP3labels and gives each a judged effort. Closed issues stay as they are (owner decision), so they lose their type and priority labels whenlabels.shdeletes them.scripts/gh/labels.shretires those six labels plusblocked(the native blocked-by edge carries it) and addsno-changelog. A newtracker-helpersCI job runs the--self-testoffields.sh,labels.sh,migrate-fields.shandrel.sh.ci.ymlalready runs onmerge_group; it now also reruns onlabeled/unlabeled. The docs, memory and.claude/settings.jsonarm pull requests withgh pr merge <n> --autoand deny--adminand-R.changelog.d/,scripts/release/changelog.sh(--check,--assemble),scripts/checks/changelog-guard.sh, and thechangelogandchangelog-guardjobs. The release checklist assembles the fragments, so pull requests stop conflicting on[Unreleased]. I trial-ran--assembleagainst this repository'sCHANGELOG.mdin a scratch clone and it produced a clean section and link references.project.shpoints at the organisation board, addstransfer/transferred, and reads status updates throughorganization(...).FerroHEALTH_FerroTERMin theferrohealthorganization, as FerroFED and FerroEHR (ci(sonar): point SonarQube Cloud at the FerroHEALTH project and list it as a code-scanning tool FerroFED#387). That project existed but had never been analyzed.sonar-project.properties, the README badges,.mcp.json, the review rule anddocs/ci-cd.mdname it. After each analysis ofmain,scripts/sonar/sarif.shconverts the open issues to SARIF andsonar.ymluploads them to code scanning undersonarqube-cloud.block_dangerousandversions_guardhooks. The port is hardened: each command of a compound line is judged on its own,--recursive/--forcecount, and a push that deletesmainis refused. The SessionStart dump and/phase-statusprint<Type/Priority>, and/next-taskorders by priority. Every reader of an issue usesgh issue view --json, because on gh 2.101.0--commentsprints nothing for an issue without comments. The rules, agents, issue forms, PR template and release-note categories follow the new model.No specification governs any of this; it is our own design.
Part of #704. Its remaining criteria are tracker-side steps (the migration apply, the label retirement, the ruleset's merge queue and the board), and the issue closes once they are done.
Licensing of contributions
Checklist
shellcheck --severity=style,actionlintandzizmor --min-severity=low .github/are clean apart from the dependabot cooldown finding already onmain.comment-style.sh,versions.shandrepo-map.shpass.--self-testof everyscripts/gh/helper andscripts/guard the change touched passes.changelog.d/704-changelog-fragments.changed.md, records the change.