From b6ba86af3b6f5e2f1a86bf187b863a99ddc5201e Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Sun, 6 Sep 2026 20:06:31 +0200 Subject: [PATCH 1/5] chore(deps): bump kirchDev/workflows from v0.8.0 to v0.8.2 --- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/fast-forward-queue.yml | 2 +- .github/workflows/promotion-pr.yml | 2 +- .github/workflows/queue-branch.yml | 2 +- .github/workflows/release-please.yml | 6 +++--- 6 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3c9148c..9146f68 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -22,4 +22,4 @@ permissions: jobs: check: name: CI - uses: kirchDev/workflows/.github/workflows/_ci-check.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_ci-check.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 9b0190c..be3566a 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,4 +24,4 @@ jobs: packages: read actions: read contents: read - uses: kirchDev/workflows/.github/workflows/_codeql.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_codeql.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 diff --git a/.github/workflows/fast-forward-queue.yml b/.github/workflows/fast-forward-queue.yml index 942c8e1..6a80dbc 100644 --- a/.github/workflows/fast-forward-queue.yml +++ b/.github/workflows/fast-forward-queue.yml @@ -26,7 +26,7 @@ jobs: pull-requests: read checks: read statuses: read - uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_fast-forward-queue.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 with: pr: ${{ inputs.pr }} secrets: diff --git a/.github/workflows/promotion-pr.yml b/.github/workflows/promotion-pr.yml index d8c467d..10a32bf 100644 --- a/.github/workflows/promotion-pr.yml +++ b/.github/workflows/promotion-pr.yml @@ -15,4 +15,4 @@ permissions: jobs: promotion-pr: name: Promotion PR - uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_promotion-pr.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 diff --git a/.github/workflows/queue-branch.yml b/.github/workflows/queue-branch.yml index 28af885..40a8135 100644 --- a/.github/workflows/queue-branch.yml +++ b/.github/workflows/queue-branch.yml @@ -16,6 +16,6 @@ jobs: permissions: contents: read pull-requests: write - uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_queue-branch.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 secrets: BWS_ACCESS_TOKEN: ${{ secrets.BWS_ACCESS_TOKEN }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 7a2a0b7..a5ab735 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -23,7 +23,7 @@ jobs: permissions: contents: write pull-requests: write - uses: kirchDev/workflows/.github/workflows/_release-please.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_release-please.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 with: # This repo is consumed as `kirchDev/coverage-report@`, so `@v0` has # to keep meaning "the newest v0.x.y". @@ -41,7 +41,7 @@ jobs: # NPM_TOKEN exists in this repo; npm verifies this workflow against the # trusted publisher configured on the package. id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 with: tag-name: ${{ needs.release-please.outputs.tag-name }} # The npm artifact is lib/, built by build:npm — not the action bundle in @@ -63,7 +63,7 @@ jobs: permissions: contents: read id-token: write - uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@94cbcbd676b989ac6c6327055a240132f5cd76a5 # v0.8.0 + uses: kirchDev/workflows/.github/workflows/_publish-npm.yml@1e57db95ff601f03ae87b78e329ef238f9d0cbf6 # v0.8.2 with: prerelease: true build-script: build:npm From a08e7097e4b3879c957432cb55435fdbd3807491 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Tue, 8 Sep 2026 14:02:36 +0200 Subject: [PATCH 2/5] chore: declare the docs tree as duxt-rendered --- .tituskirch-skills.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.tituskirch-skills.json b/.tituskirch-skills.json index 6b855e1..dc61e32 100644 --- a/.tituskirch-skills.json +++ b/.tituskirch-skills.json @@ -48,7 +48,8 @@ } }, "docs": { - "preset": "package" + "preset": "package", + "render": "duxt" }, "work": { "tracker": "github", From 624c69ab4193cde7b481516e5d328a026d35e519 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Wed, 9 Sep 2026 15:57:52 +0200 Subject: [PATCH 3/5] chore: name work profiles after their branch strategy Rename fleet to parallel-worktree and fleet-with-queue to parallel-worktree-queue, so the name states the isolation the profile buys, and add a parallel profile for parallel work on the shared branch. --- .tituskirch-skills.json | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/.tituskirch-skills.json b/.tituskirch-skills.json index dc61e32..abdc1f0 100644 --- a/.tituskirch-skills.json +++ b/.tituskirch-skills.json @@ -79,7 +79,20 @@ ] }, "profiles": { - "fleet": { + "parallel": { + "work": { + "parallel": true, + "concurrency": 4 + } + }, + "parallel-worktree": { + "work": { + "concurrency": 8, + "branch": "worktree", + "parallel": true + } + }, + "parallel-worktree-queue": { "work": { "concurrency": 8, "branch": "worktree", From dec02b4f1ca9135793b9aa8b19e3fc4f60da96c0 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Thu, 10 Sep 2026 13:30:37 +0200 Subject: [PATCH 4/5] fix(config): correct the codex policy match examples --- .codex/rules/default.rules | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.codex/rules/default.rules b/.codex/rules/default.rules index cd54e1d..d3467e0 100644 --- a/.codex/rules/default.rules +++ b/.codex/rules/default.rules @@ -130,7 +130,7 @@ prefix_rule( pattern = ["rm", ["-rf", "-fr", "-Rf", "-fR"], "/"], decision = "forbidden", justification = "Recursive delete from the filesystem root", - match = ["rm -rf /", "rm -rf /etc"], + match = ["rm -rf /", "rm -fr /"], not_match = ["rm -rf node_modules", "rm -rf dist"], ) @@ -153,7 +153,7 @@ prefix_rule( pattern = [["dd", "mkfs", "shred", "fdisk", "parted"]], decision = "forbidden", justification = "Writes to block devices; never needed from a repo", - match = ["dd if=/dev/zero of=/dev/sda", "mkfs.ext4 /dev/sdb1"], + match = ["dd if=/dev/zero of=/dev/sda", "mkfs -t ext4 /dev/sdb1"], ) # ──────────────────────────── databases ────────────────────────────────────── From 089096416401b309a264889a0e4a68f62028d296 Mon Sep 17 00:00:00 2001 From: Titus Kirch Date: Thu, 10 Sep 2026 14:58:08 +0200 Subject: [PATCH 5/5] fix(ci): publish prereleases only from main --- .github/workflows/release-please.yml | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index a5ab735..62680cc 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -8,7 +8,6 @@ on: push: branches: - main - - dev concurrency: group: ${{ github.workflow }}-${{ github.ref }} @@ -17,8 +16,7 @@ concurrency: jobs: release-please: name: Release Please - # `dev` reaches this workflow for the prerelease job below; release-please - # itself only ever runs on the release branch. + # Release-please only ever runs on the release branch. if: github.ref_name == 'main' permissions: contents: write @@ -53,12 +51,9 @@ jobs: # Skip the version-bump merges release-please pushes onto main. if: >- ${{ - github.ref_name == 'dev' - || ( - github.ref_name == 'main' - && !startsWith(github.event.head_commit.message, 'chore(main): release') - && !startsWith(github.event.head_commit.message, 'chore: release') - ) + github.ref_name == 'main' + && !startsWith(github.event.head_commit.message, 'chore(main): release') + && !startsWith(github.event.head_commit.message, 'chore: release') }} permissions: contents: read