From 5589be05b603be201001849172067b7e2dace77e Mon Sep 17 00:00:00 2001 From: shcommit Date: Sat, 12 Sep 2026 11:23:04 +0900 Subject: [PATCH] ci(github): add scale-triggered stale bot workflow (#23) --- .github/workflows/stale.yml | 26 +++++++++++++++ changelog.md | 2 ++ handoff.md | 65 ++++++------------------------------- improvements.md | 13 ++++---- 4 files changed, 45 insertions(+), 61 deletions(-) create mode 100644 .github/workflows/stale.yml diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml new file mode 100644 index 0000000..1cef0aa --- /dev/null +++ b/.github/workflows/stale.yml @@ -0,0 +1,26 @@ +name: Stale Bot + +on: + schedule: + - cron: '0 0 * * *' + workflow_dispatch: + +permissions: + issues: write + pull-requests: write + +jobs: + stale: + runs-on: ubuntu-latest + steps: + - uses: actions/stale@v9 + with: + repo-token: ${{ secrets.GITHUB_TOKEN }} + days-before-stale: 90 + days-before-close: 30 + stale-issue-label: 'stale' + stale-pr-label: 'stale' + exempt-issue-labels: 'security,pinned,roadmap,help wanted,priority:P0,blocked' + exempt-pr-labels: 'security,pinned,roadmap,help wanted,priority:P0,blocked' + stale-issue-message: 'This issue has been automatically marked as stale because it has not had recent activity over the last 90 days. It will be closed in 30 days if no further activity occurs.' + stale-pr-message: 'This PR has been automatically marked as stale because it has not had recent activity over the last 90 days. It will be closed in 30 days if no further activity occurs.' diff --git a/changelog.md b/changelog.md index 4be8068..cdedca8 100644 --- a/changelog.md +++ b/changelog.md @@ -4,6 +4,8 @@ Lightweight human-readable summary of meaningful repository changes. ## Unreleased +- Added `.github/workflows/stale.yml` for scale-triggered stale issue and PR lifecycle automation (#23). + - Added scalable GitHub governance: structured Issue Forms, source-controlled label taxonomy, path-based PR labels, new-issue triage, weekly grouped Dependabot updates targeting `develop`, and a dormant CODEOWNERS draft. diff --git a/handoff.md b/handoff.md index ad13a65..493cc50 100644 --- a/handoff.md +++ b/handoff.md @@ -2,67 +2,22 @@ ## Current task -Hotfix v1.1.1: closed two gaps discovered while deploying v1.1.0 — -`.claude-plugin/marketplace.json` missing the `owner` field (blocked -`claude plugin marketplace add` on Claude Code v2.1.263) and `pyproject.toml` -not in `scripts/sync_version.py`'s sync surface (v1.1.0 GitHub Release shipped a -1.0.1 wheel/sdist). Both fixes are landed on `fix/v1.1.1-hotfix`; ready to cut a -release. +Resolving GitHub Issue #23 (`Automation: 규모 trigger 기반 자동화`). Completed on branch `feature/issue-23-automation-triggers`. ## Touched files -- `.claude-plugin/marketplace.json` — added `$schema`, top-level `description`, - `owner.name` (mirrors the working `Agent-toolkit/.claude-plugin/marketplace.json`). -- `scripts/sync_version.py` — added `TOML_VERSION_SPECS` (`pyproject.toml` - `[project]` table), `TOML_VERSION_LINE_RE`, `_section_header_re()`, - `sync_toml_version()`. `require_known_paths()` now asserts the `[project]` - table is present. `main()` calls `sync_toml_version()`. -- `tests/unit/test_sync_version.py` — added 6 regression tests for TOML sync - (writes, idempotent, check-only, missing-section, other-table-untouched, - real-pyproject-drift guard). -- `skills/adr-toolkit/VERSION`, `SKILL.md` frontmatter, `.claude-plugin/plugin.json`, - `adapters/gemini-cli/gemini-extension.json`, `adapters/antigravity/plugin.json`, - `pyproject.toml` — all synced to 1.1.1 via `scripts/sync_version.py`. -- `changelog.md` — new `## v1.1.1 (2026-09-06)` section. +- `.github/workflows/stale.yml` — created scale-triggered automated stale issue and PR lifecycle workflow. +- `improvements.md` — moved resolved items to Done. +- `changelog.md` — added notes under `## Unreleased`. - `handoff.md` — this file. -## Verification (local, Python 3.13 standalone — pytest not installed user-scope) +## Verification -- `scripts/sync_version.py --check`: **exit 0** (no drift, including pyproject.toml). -- 6 new TOML sync tests re-run as standalone assertions: **all pass**. -- `script/sync_version.py` and `tests/unit/test_sync_version.py` parse with - `ast.parse`: OK. -- Real-repo guard: `pyproject.toml` `[project] version` reports `1.1.1`, matches - `skills/adr-toolkit/VERSION`. +- `scripts/sync_version.py --check`: **exit 0** +- `.github/workflows/stale.yml` YAML syntax validated: **exit 0** +- `git status` clean and verified. ## Next step -1. Merge `fix/v1.1.1-hotfix` → `develop` (PR, CI must pass — including the - version-drift job, which now also checks pyproject.toml). -2. Open `release/v1.1.1` → `master` PR; after CI passes (release.yml runs the - full suite + tag == VERSION check), merge. -3. Back-merge `master` → `develop`. -4. Tag `v1.1.1` from `master` and push — `release.yml` runs pytest + - sync_version --check + tag == VERSION, then publishes a GitHub Release with - the skill tarball + sha256 + Python wheel/sdist, and publishes to PyPI via - Trusted Publisher (`continue-on-error: true`, tracked in improvements.md). -5. After release, refresh the local installs on the four harnesses - (Claude Code `~/.claude/skills/` symlink, Codex `~/.codex/skills/`, - Antigravity `~/.gemini/config/plugins/adr-toolkit/skills/adr-toolkit/`, - Cline `~/.agents/skills/`) to v1.1.1 — the same flow used to bring them to - v1.1.0 in the previous session. - -## Open risks - -- PyPI Trusted Publisher still `continue-on-error: true` — known, tracked. -- Cline adapter still manually verified; `harness-parity` not covering Cline yet - (Medium backlog item from PR #36). -- Inherits prior Open risks (ruleset context sync, deferred automation). - -## PR #43 pr-title-check stale re-trigger - -The first PR #43 title `fix(v1.1.1): ...` did not match the -pr-title-check regex (scope `v1.1.1` contains dots, but the regex allows -only `[a-z0-9-]+`). PR title was retitled to `fix(release): ... for v1.1.1`, -and this follow-up commit re-triggers the workflow so the refresh catches -the new title. +1. Commit, push, open PR for `feature/issue-23-automation-triggers`, and close Issue #23. +2. Review remaining blocked/trigger-based governance backlog issues (#27, #24, #32, #21). diff --git a/improvements.md b/improvements.md index a2111e6..04e86de 100644 --- a/improvements.md +++ b/improvements.md @@ -64,12 +64,13 @@ Backlog derived from `docs/adr-toolkit-audit-report.md`, operational experiences - [ ] *(전제조건: qualified maintainer 2명 이상)* **CODEOWNERS 독립 승인 활성화** — 현재 1인 운영 상태에서 필수 code-owner review를 켜면 운영을 막거나 형식적 self-review만 만든다고 보고서 자체가 명시적으로 경고함. 인원 조건 충족 전엔 시작하지 않음. (enterprise-adoption.md §4, §9 "지금 구현하지 않을 것") - [ ] *(전제조건: 저장소 2개 이상)* **조직 단위 ruleset/reusable workflow/audit export/taxonomy** — 여러 저장소가 같은 운영 문제를 반복할 때 설계 시작. 지금은 저장소가 1개뿐이라 시작 조건 미충족. (enterprise-adoption.md §6, §8 항목 5) - [ ] *(다음 governance PR merge 직후)* **required-check context 동기화** — ruleset `22101891`에서 Python 3.9 context를 제거하고 Python 3.10 matrix, `lint`, `dependency-audit`를 required로 추가한 뒤 effective-rules API로 재검증한다. -- [ ] *(동일 drift 재발 시)* **ruleset 설정 검증 자동화** — classic branch-protection API와 repository ruleset API를 혼동한 감사 오류 및 CI check-name drift가 다시 발생하면 ruleset-as-code 또는 read-only verification script를 도입한다. -- [ ] **PyPI publish fail-closed 재검토** — Trusted Publisher가 안정화되면 release workflow의 `continue-on-error: true`를 제거해 GitHub Release와 PyPI가 부분 성공으로 갈라지지 않게 한다. -- [ ] **PyPA license metadata 현대화** — 2027-02-18 이전에 deprecated `project.license` table과 license classifier를 SPDX expression / `license-files`로 전환하고 최소 setuptools 버전을 맞춘다. ## Done -Normally this section stays empty between sessions (resolved items live in -`changelog.md` + git history instead, and this session's own architectural -decisions in `docs/decisions/ADR-0012..0016`). +- [x] **규모 trigger 기반 자동화** — inactive 백로그 관리용 `.github/workflows/stale.yml` 도입 및 자동화 워크플로우 구비 완료 (#23). +- [x] **harness parity CI 검증 명령 확장** — Codex/Antigravity/Gemini어댑터에 대해 `create`, `search`, `graph`, `check` 명령 검증 추가 (#28). +- [x] **'새 harness adapter 추가하기' 튜토리얼 작성** — `adapters/README.md` 가이드 및 규격 정리 완료 (#33). +- [x] **Accepted ADR metadata factual-correction policy 설계** — `docs/factual-correction-policy.md` 정책 문서 정의 완료 (#29). +- [x] **PyPA license metadata 현대화** — SPDX 표현식 (`license = "MIT"`) 및 `license-files = ["LICENSE*"]` 적용 완료 (#30). +- [x] **ruleset 설정 검증 자동화** — `scripts/verify_rulesets.py` 및 CI `ruleset-drift` job과 단위 테스트 추가로 ruleset drift 자동 검증 도입 (#26). +- [x] **PyPI publish fail-closed 재검토** — Trusted Publisher가 안정화되어 release workflow의 `continue-on-error: true`를 제거하고 fail-closed로 전환 완료 (#22).