You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(ship): run security checks for all workspaces regardless of affected paths
- Add cross-cutting security audit step (Step 4) that always runs for all
workspaces (codingbuddy, codingbuddy-claude-plugin, landing-page) when
any workspace has changes, matching CI behavior
- Add --full flag to run ALL workspace checks locally (matches CI exactly)
- Update docs-only fast path to respect --full flag override
- Renumber steps to accommodate new security check step
Closes#979
Copy file name to clipboardExpand all lines: .claude/skills/ship/SKILL.md
+36-14Lines changed: 36 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
---
2
2
name: ship
3
-
description: Run local CI checks and ship changes — create branch, commit, push, and PR. Optionally link to a GitHub issue. Use when changes are ready to ship.
4
-
argument-hint: [issue-url-or-number]
3
+
description: Run local CI checks and ship changes — create branch, commit, push, and PR. Optionally link to a GitHub issue. Use `--full` to run all workspace checks. Use when changes are ready to ship.
Follow every step in order. Stop and report if any step fails.
13
13
14
-
## Step 1: Determine Issue Context
14
+
## Step 1: Parse Arguments and Determine Issue Context
15
15
16
-
Check if `$ARGUMENTS` is provided:
16
+
Parse `$ARGUMENTS` for:
17
+
-**`--full` flag**: If present, run ALL workspace checks (matches CI exactly). Remove `--full` from arguments before processing issue context.
18
+
-**Issue context**: Remaining argument is an issue number or URL.
17
19
18
-
-**With issue** (`/ship 613` or `/ship https://github.com/.../issues/613`):
20
+
Check if issue context is provided:
21
+
22
+
-**With issue** (`/ship 613` or `/ship --full 613`):
19
23
```bash
20
24
gh issue view <number> --json title,body,labels
21
25
```
22
26
Use the issue title and labels to inform branch name, commit message, and PR description.
23
27
24
-
-**Without issue** (`/ship`):
28
+
-**Without issue** (`/ship` or `/ship --full`):
25
29
Skip issue fetch. Derive context entirely from the changed files and `git diff`. The user will be asked to confirm the commit message and PR title before proceeding.
26
30
27
31
## Step 2: Check Working Tree
@@ -45,7 +49,9 @@ Run `git diff --name-only` (include both staged and unstaged changes) and classi
If changed files don't match any pattern (e.g., docs-only, root config), skip CI checks entirely and proceed to Step 5.
52
+
**Docs-only changes**: If changed files don't match any pattern above (e.g., docs-only, root config) AND `--full` is NOT set, skip all CI checks (including security) and proceed to Step 7.
53
+
54
+
**`--full` mode**: If `--full` flag is set, mark ALL workspaces as affected regardless of changed files.
49
55
50
56
## Step 3.5: Verify Dependencies
51
57
@@ -68,9 +74,23 @@ npx --version
68
74
69
75
**Iron Law:** Never skip CI checks due to missing dependencies.
70
76
71
-
## Step 4: Run Local CI Checks
77
+
## Step 4: Run Cross-cutting Security Checks
78
+
79
+
**Security is cross-cutting** — always run security audit for ALL workspaces when any workspace has changes, even if only one workspace is affected. This matches CI behavior where all security jobs run on every triggered push.
80
+
81
+
```bash
82
+
yarn workspace codingbuddy npm audit --severity high
83
+
yarn workspace codingbuddy-claude-plugin npm audit --severity high
84
+
yarn workspace landing-page npm audit --severity high
85
+
```
86
+
87
+
If ANY security check fails, stop and report the failure. Do NOT proceed to shipping.
88
+
89
+
## Step 5: Run Local CI Checks
90
+
91
+
Run checks for **affected workspaces only** (or ALL workspaces if `--full` is set). Execute checks sequentially within each workspace. Stop at first failure.
72
92
73
-
Run checks **only for affected workspaces**. Execute checks sequentially within each workspace. Stop at first failure.
93
+
**Note:** Security audits were already run in Step 4 for all workspaces — do not repeat them here.
0 commit comments