docs: bot sign-off, local agent notes, public pages - #7
Merged
Merged
Conversation
A DCO sign-off is a personal certification the project bot cannot make, so commits authored as quality-runtime[bot] omit it; pull requests the bot opens are already exempt from the dco check.
CLAUDE.md imports CLAUDE.local.md for per-developer notes, and .gitignore keeps that file from being committed to this public repository.
Hostnames stay deployment configuration. Public pages, when they exist, are answered only on their own origin so nothing there can use a session, and render structured records rather than tenant-supplied markup; anything that needs a sign-in, an auditor's access included, stays on the application's origin.
koistya
added this pull request to stack #9
September 19, 2026 18:04
koistya
pushed a commit
that referenced
this pull request
Sep 19, 2026
Commits authored as quality-runtime[bot] carry no DCO sign-off, which a bot cannot give; pull requests it opens are exempt from the dco job. CLAUDE.md imports CLAUDE.local.md for per-developer notes, and .gitignore keeps that file out of the repository. ARCHITECTURE.md sets the boundary for public pages before any exists: hostnames are deployment configuration, public pages are answered only on their own origin so nothing there can use a session, and anything that needs a sign-in, an auditor's access included, stays on the application's origin.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three small guideline changes, split out so the evidence PR stacked on this one stays about evidence.
AGENTS.mdnow says commits authored asquality-runtime[bot]omit it. Pull requests the bot opens are already exempt from thedcojob (fix(ci): exempt the real bot login from the DCO check #6).CLAUDE.mdimportsCLAUDE.local.mdfor per-developer instructions, and.gitignorenow keeps that file out of this public repository — onmainit is not ignored today.ARCHITECTURE.mdrecords, ahead of any public page, that hostnames are deployment configuration, that public pages are answered only on a separate origin so nothing there can use a session, and that anything needing a sign-in — an auditor's access included — stays on the application's origin.Verified:
bun run checkandreuse lintpass; with the new.gitignore, a localCLAUDE.local.mdis reported ignored andgit add -Aleaves it out. No code changes.