Skip to content

Commit 140caee

Browse files
committed
fix(ship): run security checks for all workspaces regardless of affected paths
- Add cross-cutting security audit step (Step 4) that always runs for all workspaces (codingbuddy, codingbuddy-claude-plugin, landing-page) when any workspace has changes, matching CI behavior - Add --full flag to run ALL workspace checks locally (matches CI exactly) - Update docs-only fast path to respect --full flag override - Renumber steps to accommodate new security check step Closes #979
1 parent e4747e8 commit 140caee

1 file changed

Lines changed: 36 additions & 14 deletions

File tree

‎.claude/skills/ship/SKILL.md‎

Lines changed: 36 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
name: ship
3-
description: Run local CI checks and ship changes — create branch, commit, push, and PR. Optionally link to a GitHub issue. Use when changes are ready to ship.
4-
argument-hint: [issue-url-or-number]
3+
description: Run local CI checks and ship changes — create branch, commit, push, and PR. Optionally link to a GitHub issue. Use `--full` to run all workspace checks. Use when changes are ready to ship.
4+
argument-hint: "[--full] [issue-url-or-number]"
55
allowed-tools: Bash, Read, Grep, Glob
66
user-invocable: true
77
disable-model-invocation: true
@@ -11,17 +11,21 @@ disable-model-invocation: true
1111

1212
Follow every step in order. Stop and report if any step fails.
1313

14-
## Step 1: Determine Issue Context
14+
## Step 1: Parse Arguments and Determine Issue Context
1515

16-
Check if `$ARGUMENTS` is provided:
16+
Parse `$ARGUMENTS` for:
17+
- **`--full` flag**: If present, run ALL workspace checks (matches CI exactly). Remove `--full` from arguments before processing issue context.
18+
- **Issue context**: Remaining argument is an issue number or URL.
1719

18-
- **With issue** (`/ship 613` or `/ship https://github.com/.../issues/613`):
20+
Check if issue context is provided:
21+
22+
- **With issue** (`/ship 613` or `/ship --full 613`):
1923
```bash
2024
gh issue view <number> --json title,body,labels
2125
```
2226
Use the issue title and labels to inform branch name, commit message, and PR description.
2327

24-
- **Without issue** (`/ship`):
28+
- **Without issue** (`/ship` or `/ship --full`):
2529
Skip issue fetch. Derive context entirely from the changed files and `git diff`. The user will be asked to confirm the commit message and PR title before proceeding.
2630

2731
## Step 2: Check Working Tree
@@ -45,7 +49,9 @@ Run `git diff --name-only` (include both staged and unstaged changes) and classi
4549
| `apps/landing-page/**` | `landing-page` | lint, format:check, typecheck, test:coverage, check:circular, build |
4650
| `.claude/**`, `.cursor/**`, `.antigravity/**`, `.codex/**`, `.github/**`, `scripts/**` | rules-validation only | `ajv-cli validate` + `markdownlint-cli2` |
4751

48-
If changed files don't match any pattern (e.g., docs-only, root config), skip CI checks entirely and proceed to Step 5.
52+
**Docs-only changes**: If changed files don't match any pattern above (e.g., docs-only, root config) AND `--full` is NOT set, skip all CI checks (including security) and proceed to Step 7.
53+
54+
**`--full` mode**: If `--full` flag is set, mark ALL workspaces as affected regardless of changed files.
4955

5056
## Step 3.5: Verify Dependencies
5157

@@ -68,9 +74,23 @@ npx --version
6874

6975
**Iron Law:** Never skip CI checks due to missing dependencies.
7076

71-
## Step 4: Run Local CI Checks
77+
## Step 4: Run Cross-cutting Security Checks
78+
79+
**Security is cross-cutting** — always run security audit for ALL workspaces when any workspace has changes, even if only one workspace is affected. This matches CI behavior where all security jobs run on every triggered push.
80+
81+
```bash
82+
yarn workspace codingbuddy npm audit --severity high
83+
yarn workspace codingbuddy-claude-plugin npm audit --severity high
84+
yarn workspace landing-page npm audit --severity high
85+
```
86+
87+
If ANY security check fails, stop and report the failure. Do NOT proceed to shipping.
88+
89+
## Step 5: Run Local CI Checks
90+
91+
Run checks for **affected workspaces only** (or ALL workspaces if `--full` is set). Execute checks sequentially within each workspace. Stop at first failure.
7292

73-
Run checks **only for affected workspaces**. Execute checks sequentially within each workspace. Stop at first failure.
93+
**Note:** Security audits were already run in Step 4 for all workspaces — do not repeat them here.
7494

7595
### codingbuddy workspace
7696

@@ -114,7 +134,7 @@ yarn dlx markdownlint-cli2@0.20.0 "packages/rules/.ai-rules/**/*.md"
114134

115135
If ANY check fails, stop and report the failure. Do NOT proceed to shipping.
116136

117-
## Step 5: Check Commit Convention
137+
## Step 6: Check Commit Convention
118138

119139
```bash
120140
git log --oneline -10
@@ -124,7 +144,7 @@ Identify the commit message convention. This project uses: `type(scope): descrip
124144

125145
Common types: `feat`, `fix`, `docs`, `refactor`, `test`, `chore`, `perf`, `ci`
126146

127-
## Step 6: Create Branch and Commit
147+
## Step 7: Create Branch and Commit
128148

129149
### Branch naming
130150

@@ -154,12 +174,12 @@ EOF
154174
**Rules:**
155175
- Write commit message in **English**
156176
- Do NOT include author information
157-
- Follow the detected convention from Step 5
177+
- Follow the detected convention from Step 6
158178
- Use specific file paths in `git add` (never `git add -A` or `git add .`)
159179
- **Never stage `RESULT.json` or `TASK.md`** — these are ephemeral per-worktree artifacts and must not be committed
160180
- Only include `Closes #<number>` if an issue was provided
161181

162-
## Step 7: Push and Create PR
182+
## Step 8: Push and Create PR
163183

164184
```bash
165185
git push -u origin <branch-name>
@@ -204,10 +224,12 @@ EOF
204224
- Body: English, include Summary + Test plan sections
205225
- Do NOT include author information
206226

207-
## Step 8: Report Result
227+
## Step 9: Report Result
208228

209229
Print the PR URL and a summary of:
210230
- Which CI checks were run and passed (or "skipped — no matching workspace")
231+
- Security checks: always-run status for all workspaces
232+
- Whether `--full` mode was used
211233
- Branch name
212234
- Commit hash
213235
- PR URL

0 commit comments

Comments
 (0)