Skip to content

docs: bot sign-off, local agent notes, public pages - #7

Merged
quality-runtime[bot] merged 3 commits into
mainfrom
docs/guidelines
Sep 19, 2026
Merged

quality-runtime[bot] merged 3 commits into
mainfrom
docs/guidelines

Conversation

@quality-runtime

Copy link
Copy Markdown
Contributor

Three small guideline changes, split out so the evidence PR stacked on this one stays about evidence.

  • Bot commits carry no sign-off. A DCO sign-off is a personal certification a bot cannot make, so AGENTS.md now says commits authored as quality-runtime[bot] omit it. Pull requests the bot opens are already exempt from the dco job (fix(ci): exempt the real bot login from the DCO check #6).
  • Local agent notes stay local. CLAUDE.md imports CLAUDE.local.md for per-developer instructions, and .gitignore now keeps that file out of this public repository — on main it is not ignored today.
  • Public pages get their own origin. ARCHITECTURE.md records, ahead of any public page, that hostnames are deployment configuration, that public pages are answered only on a separate origin so nothing there can use a session, and that anything needing a sign-in — an auditor's access included — stays on the application's origin.

Verified: bun run check and reuse lint pass; with the new .gitignore, a local CLAUDE.local.md is reported ignored and git add -A leaves it out. No code changes.

A DCO sign-off is a personal certification the project bot cannot make, so commits authored as quality-runtime[bot] omit it; pull requests the bot opens are already exempt from the dco check.
CLAUDE.md imports CLAUDE.local.md for per-developer notes, and .gitignore keeps that file from being committed to this public repository.
Hostnames stay deployment configuration. Public pages, when they exist, are answered only on their own origin so nothing there can use a session, and render structured records rather than tenant-supplied markup; anything that needs a sign-in, an auditor's access included, stays on the application's origin.
@koistya
koistya added this pull request to stack #9 September 19, 2026 18:04
@quality-runtime
quality-runtime Bot merged commit 91d511a into main Sep 19, 2026
6 checks passed
@quality-runtime
quality-runtime Bot deleted the docs/guidelines branch September 19, 2026 18:05
koistya pushed a commit that referenced this pull request Sep 19, 2026
Commits authored as quality-runtime[bot] carry no DCO sign-off, which a bot cannot give; pull requests it opens are exempt from the dco job. CLAUDE.md imports CLAUDE.local.md for per-developer notes, and .gitignore keeps that file out of the repository. ARCHITECTURE.md sets the boundary for public pages before any exists: hostnames are deployment configuration, public pages are answered only on their own origin so nothing there can use a session, and anything that needs a sign-in, an auditor's access included, stays on the application's origin.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants