From bbf4db1980934e1565c55b0602ce1e6572a76eff Mon Sep 17 00:00:00 2001 From: Sebastian Kern Date: Sat, 26 Sep 2026 11:15:11 +0200 Subject: [PATCH 1/2] =?UTF-8?q?Repo-Baseline:=20copilot-instructions.md=20?= =?UTF-8?q?AGENTS.md=20CLAUDE.md=20(+@AGENTS.md)=20ci.yml=20(ai/ENGINEERIN?= =?UTF-8?q?G=20=C2=A75,=20=C2=A77;=20github-org-setup)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/copilot-instructions.md | 1 + .github/workflows/ci.yml | 70 +++++++++++++++++++++++++++++++++ AGENTS.md | 38 ++++++++++++++++++ CLAUDE.md | 2 + 4 files changed, 111 insertions(+) create mode 100644 .github/copilot-instructions.md create mode 100644 .github/workflows/ci.yml create mode 100644 AGENTS.md diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md new file mode 100644 index 0000000..a81d392 --- /dev/null +++ b/.github/copilot-instructions.md @@ -0,0 +1 @@ +Read AGENTS.md first. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..4dc9fcb --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,70 @@ +# .github/workflows/ci.yml — Stoicera baseline (ai/ENGINEERING.md §7). +# Steps run for the stack that is present (package.json → pnpm, pyproject.toml → uv). +# The final job "ci" is the required status check of the organisation ruleset. +name: CI +on: + pull_request: + push: + branches: [main] + +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: true + +jobs: + test: + runs-on: ubuntu-latest + env: + CI: true + steps: + - uses: actions/checkout@v4 + - id: stack + run: | + [ -f package.json ] && echo node=true >> "$GITHUB_OUTPUT" || true + [ -f pyproject.toml ] && echo python=true >> "$GITHUB_OUTPUT" || true + [ -f Dockerfile ] && echo docker=true >> "$GITHUB_OUTPUT" || true + + # Node / TypeScript + - if: steps.stack.outputs.node == 'true' + uses: pnpm/action-setup@v4 + - if: steps.stack.outputs.node == 'true' + uses: actions/setup-node@v4 + with: { node-version: 22, cache: pnpm } + - if: steps.stack.outputs.node == 'true' + run: | + pnpm install --frozen-lockfile + pnpm lint + pnpm typecheck + pnpm test -- --coverage + pnpm build + pnpm audit --audit-level=high + + # Python + - if: steps.stack.outputs.python == 'true' + uses: astral-sh/setup-uv@v6 + - if: steps.stack.outputs.python == 'true' + run: | + uv sync --frozen + uv run ruff check . + uv run ruff format --check . + uv run pytest --cov + uv run pip-audit || uvx pip-audit + + # Container + - if: steps.stack.outputs.docker == 'true' + run: docker build -t app:${{ github.sha }} . + - if: steps.stack.outputs.docker == 'true' + uses: aquasecurity/trivy-action@0.28.0 + with: + image-ref: app:${{ github.sha }} + severity: HIGH,CRITICAL + exit-code: "1" + ignore-unfixed: true + + ci: + # Aggregate gate: the organisation ruleset requires this check by name. + runs-on: ubuntu-latest + needs: [test] + if: always() + steps: + - run: test "${{ needs.test.result }}" = "success" diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..6d45708 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,38 @@ +# migration-lab — Agent Context + + +## Company (Stoicera Software Group) + +Two founders (Sebastian Kern, Raphael Lugmayr), Upper Austria. Brands: Stoicera (B2B web/AI/EU cloud, modern stack) and Lugmayr-Kern (.NET/Java contract work, B2C). Goal until 7.7.2027: 10,000 € monthly result, half recurring — every task names the goal it serves; results first, ship the 80 % version, measure, iterate. Founders orchestrate; agents build, test, deploy, operate. Truth before effect: no invented facts, no superlatives, name assumptions. Simple over complete. Decide and report in three lines (done, open, blocked). Customer contact answered substantively within 4 hours. Never: customer data or secrets in repo/prompts; dark patterns; religious or warrior vocabulary in anything public; Hostinger/Vercel/Railway. German (AT) for customers, code in English, commits in German. + +## What migration-lab is + +See `docs/00_ssot.md`. One sentence here: public, reproducible Java legacy modernisation with measured results, for Austrian SMEs and universities. +Non-goals: . +Active PRD: `docs/prd/NN_*.md` — read before building. + +## How we work here + +- Work = GitHub issue. Questions as issue comments, not chat. +- Fresh git worktree per task from `origin/main` (never build on main), PR against `main` with `Closes #NN` and the template Intent · Gherkin · Evidence · Debt taken · Open. Small PRs. CI green before PR. Full loop: `ai/prompts/factory-feature.md`. +- Build: `` · Test: `` · Lint/Typecheck: `` · Migrate: `` +- Deploy: push to `main` → GitHub Actions → Coolify (``) → smoke test → Sentry check. PostHog receives events from `main` (big products). Rollback: ``. +- Preview per PR at ``. +- Before you request review: check the result against the intent, fix deviations yourself. Copilot review runs automatically on every PR; a second model reviews security. +- Decisions with reach → `docs/decisions/` (ADR, one page). Cycle memo → `docs/cycles/`. +- After any production change: append one line to `ops/runlog.md` (date · agent · what · rollback). + +## Conventions + +- Stack: . +- Money in cents (integer), time zone Europe/Vienna, tenant id on every table. +- No new dependency without one sentence of justification in the PR. No speculative abstractions. +- Tests: unit for logic, integration for API, one E2E per critical path. Synthetic data only. +- Accessibility and Lighthouse ≥ 90 on public pages are merge gates. + +## Never + +- Personal or customer data in repo, fixtures, logs or prompts. +- Secrets in files; use 1Password (`op run`) or Coolify secrets. +- Destructive operations (drop, force-push, rm -rf on servers) without a fresh backup and a run-log line. +- Silent scope changes: if the PRD is wrong, say so in the issue, then build. diff --git a/CLAUDE.md b/CLAUDE.md index 9cdeadd..27637bb 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -1,3 +1,5 @@ +@AGENTS.md + # CLAUDE.md — migration-lab You are working on **migration-lab**: a public, reproducible legacy modernization (Java 8 / Spring Boot 1.5 / AngularJS → Java 25 / Spring Boot 4 / Angular 22) with a Selenium safety net, measured AI-assisted test generation, and a German migration playbook. This is a portfolio piece of the Stoicera Software Group aimed at Austrian SMEs and universities (JKU) — it must demonstrate how a senior team de-risks migrations. Honesty and reproducibility are the product. From 5d854676576a8d2330cfaa8468f25330d9788902 Mon Sep 17 00:00:00 2001 From: Sebastian Kern Date: Wed, 30 Sep 2026 13:11:57 +0200 Subject: [PATCH 2/2] CI: Action-Versionen aktualisiert (trivy-action 0.28.0 fehlt) --- .github/workflows/ci.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4dc9fcb..2bf3b17 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,7 +17,7 @@ jobs: env: CI: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v5 - id: stack run: | [ -f package.json ] && echo node=true >> "$GITHUB_OUTPUT" || true @@ -26,9 +26,9 @@ jobs: # Node / TypeScript - if: steps.stack.outputs.node == 'true' - uses: pnpm/action-setup@v4 + uses: pnpm/action-setup@v6 - if: steps.stack.outputs.node == 'true' - uses: actions/setup-node@v4 + uses: actions/setup-node@v6 with: { node-version: 22, cache: pnpm } - if: steps.stack.outputs.node == 'true' run: | @@ -41,7 +41,7 @@ jobs: # Python - if: steps.stack.outputs.python == 'true' - uses: astral-sh/setup-uv@v6 + uses: astral-sh/setup-uv@v7 - if: steps.stack.outputs.python == 'true' run: | uv sync --frozen @@ -54,7 +54,7 @@ jobs: - if: steps.stack.outputs.docker == 'true' run: docker build -t app:${{ github.sha }} . - if: steps.stack.outputs.docker == 'true' - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.35.0 with: image-ref: app:${{ github.sha }} severity: HIGH,CRITICAL