Repository navigation
Conversation
Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
The stale good-first-issue and monthly recap watchers (spec 097) ran inside every user's daemon. They are Shep-maintainer automation, so they now run from .github/workflows/contributor-maintenance.yml through two new subcommands, `shep contributors stale-issues` and `shep contributors recap`, which reuse the existing use cases. The watcher services are deleted. The contributor view (leaderboard, contributor doctor) moves from /onboarding to /contributors, linked from CONTRIBUTING.md and not from the sidebar. /onboarding keeps only the collaboration tutorial that the supervisor and agents pages link to, and leaves the sidebar. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
ROADMAP said ASPM ships behind a flag, but the flag defaulted to on. ASPM is a separate product category, so new installs now start with featureFlags.aspm = false (TypeSpec default, defaults factory and the web env fallback). Values users already persisted are left as they are: no migration touches feature_flag_aspm. The e2e suites that visit /aspm turn the flag on from Settings for the test and restore it afterwards. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Supply-chain security had its own `supplyChainSecurity` flag and overlapped ASPM. It now has no flag of its own: isSupplyChainSecurityEnabled() derives it from featureFlags.aspm, and the feature-agent pre-check, the canvas security badge, the Settings section and `shep security enforce` all use it. SHEP_SUPPLY_CHAIN_SECURITY still overrides it for CI: "false" turns it off and "true" turns it on, which Shep's own security-enforce job already sets, so the release gate keeps running on a fresh install. The field leaves TypeSpec, the defaults, the mapper and the repository SQL. The feature_flag_supply_chain_security column stays (NOT NULL DEFAULT 1) so older builds keep reading it; no data is dropped. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Nothing read `system.autoUpdate`, so it leaves TypeSpec, the defaults and the mapper. Its sys_auto_update column is NOT NULL with no default, so the mapper keeps writing 1 (the old default) and never reads it; older builds still see their usual value. The Aider and Continue agent types were "coming soon" placeholders with no executor. They leave the AgentType enum, the agent catalog, the canvas icons, the TUI picker translations and the stories. A settings row that still holds either value reads back as the default agent, so no data is rewritten. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Specs 120–132 shipped with no flag. Each software-factory area now has one, default on so nothing changes for users: spaces, trackers, knowledge, signals, opportunities, feedback, discovery, incidents, outcomes, docsFirst, autopilot and factory (TypeSpec, migration 166 with DEFAULT 1, mapper, repository SQL, defaults, web flag state). Each flag gates its area: sidebar entries, pages (requireFeaturePage), POST /api/feedback and /api/alerts (404 while off), CLI groups (gateByFeatureFlag hides the group and says how to turn it on; shep aspm now uses it too), the daemon's sync, discovery, outcome and autopilot passes (checked on every pass), and the docs-first planning instructions and merge gate. A domain catalog gives every flag a group and a one-line description. ListFeatureFlagsUseCase and SetFeatureFlagUseCase serve both /settings/feature-flags (every flag, its default and a switch; linked from Settings) and `shep settings flags [enable|disable <flag>]`. The Settings page's Feature Flags section renders the same catalog-driven list instead of hand-written rows, which also adds the missing githubImport switch. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Cloudflare Pages was the only cloud deploy provider that worked. Vercel, Netlify, AWS Amplify and GCP Cloud Run were stubs listed as "Coming soon" that threw on connect and deploy. This removes them. Cloudflare Pages works as before. - TypeSpec: CloudDeploymentProvider keeps only CloudflarePages (output.ts and apis/json-schema regenerated) - core: delete the four *.provider.stub.ts files, base-provider-stub.ts, their DI registrations and ProviderNotImplementedError; drop `enabled` from ICloudDeploymentProvider, the registry descriptor and ListCloudProvidersUseCase - the registry now lists only ids that have an adapter, and resolves them from the container it was registered in rather than the global root - add domain parseCloudDeploymentProvider, replacing four copies of parseProvider in the CLI commands and web routes - CLI: `shep app cloud-providers ls/connect` lose the coming-soon output - web: drop the "Coming soon" rows, disabled states and removed brand icons from ProviderList, ProviderDropdown, DeployPanel, DeployButton, SmartDeployCluster and ConnectProviderModal; share labels and the list entry type in cloud-providers.ts; update stories, add ProviderList and CloudProviderIcons stories Persisted values: connect rejected the stubs, so no cloud_provider_tokens row can hold one, but `select-provider` and `shep app deploy start --provider` could store a stub id in applications.cloud_deployment_provider. No migration rewrites data. The application mapper reads an unknown provider id as no selection, so deploy falls back to the first connected provider. Token listing skips unknown ids too. Claude-Session: https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
Specs 133 and 134 are taken by the telemetry and unified-decisions workstreams. Comments and test names that cite the spec follow the new number. Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
The view's group headings jumped from h1 to h3; they are h2 on the page and stay h3 inside the Settings section. The phone navigation test opens the ASPM Security group, so it turns the aspm flag on first now that it defaults to off. Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
git 2.56 on the Windows runner rejects GIT_CONFIG_GLOBAL=NUL, so every harness real-git test failed in git init. Git for Windows maps /dev/null to its null device, as the merge-step real-git tests already rely on. Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
|
Unit Tests (windows-latest) failed on The cause is not this PR's code. The Windows runner now has git 2.56.0, which rejects
Generated by Claude Code |
|
Unit Tests (windows-latest) failed on I don't think this PR causes it. The PR does not touch the terminal service or that test, and the same unit step passed on Windows on the previous commit ( I tried to re-run the failed job and got a 403, because this integration cannot re-run workflows. Could someone with access re-run "Unit Tests (windows-latest)"? If it keeps happening, my proposed fix (not applied here, to keep this PR's scope) is to make that test's teardown tolerate a lingering ConPTY handle on Windows. The temp directory lives under the OS temp folder and does not affect any assertion: } finally {
try {
removeDirWithRetry(tempDir);
} catch (error) {
// Windows: conhost can outlive the shell and keep tempDir open.
if (process.platform !== 'win32' || (error as NodeJS.ErrnoException).code !== 'EBUSY') throw error;
}
}Generated by Claude Code |
On Windows the conhost.exe that node-pty starts with the shell inherits its cwd and can outlive the shell's exit event, so the pty test's teardown failed with EBUSY even after waiting for exit and retrying. The test now leaves that temp dir to the OS on that one Windows error; any other error still fails it. Co-Authored-By: Shep Bot <shep-agent@users.noreply.github.com>
|
Unit Tests (windows-latest) failed again on No test in this PR's diff ran before the service died, and the terminal test fixed in This needs a re-run of Unit Tests (windows-latest). This integration gets a 403 when it tries to re-run workflows, so could someone with access re-run it? If esbuild dies again, it is reproducible and I will dig into what is taking the transform service down. Generated by Claude Code |
|
I looked into whether this PR causes the esbuild crash in Unit Tests (windows-latest) on
I conclude that the esbuild service on the runner died in the middle of the run, and that nothing in this PR caused it. A re-run of Unit Tests (windows-latest) should confirm it: https://github.com/shep-ai/shep/actions/runs/37937489099. This integration cannot re-run it (403). If it fails the same way again, it is reproducible and I will chase it. Generated by Claude Code |
What
This is the cleanup PR from the T3 Code product review. It covers the items the owner agreed to, with one commit per item:
bb81a67_serve,shep ui,dev:web). They now run from the new scheduled workflow.github/workflows/contributor-maintenance.yml, through two new commands,shep contributors stale-issuesandshep contributors recap. Both reuse the existing use cases. The watcher services are deleted. The contributor view (leaderboard, contributor doctor) moves to/contributors, which is linked from CONTRIBUTING.md and not from the sidebar./onboardingkeeps only the collaboration tutorial and leaves the sidebar.2810b71featureFlags.aspmnow defaults tofalsein TypeSpec, the defaults factory and the web env fallback. Values users already saved are kept; no migration touches them. ROADMAP.md is updated to match. The e2e tests that visit/aspmturn the flag on for the test and back off afterwards.0b9221fsupplyChainSecurityflag is gone, and every surface followsaspmthroughisSupplyChainSecurityEnabled(): the feature-agent pre-check, the canvas badge, the Settings section andshep security enforce.SHEP_SUPPLY_CHAIN_SECURITYstill overrides the flag in either direction. Shep's ownsecurity-enforceCI job already sets it totrue, so the release gate keeps running. Thefeature_flag_supply_chain_securitycolumn stays and is no longer read.d3a2157system.autoUpdateand the placeholder agent typesaiderandcontinue. Thesys_auto_updatecolumn is NOT NULL with no default, so it is still written as1but never read. A settings row that still holdsaiderorcontinuereads back as the default agent.agentQuestionBridge,AgentQuestionExecutorBridgeandInteractionBubbleare untouched.ef9c9aespaces,trackers,knowledge,signals,opportunities,feedback,discovery,incidents,outcomes,docsFirst,autopilot,factory. They are stored in migration 166 (DEFAULT 1). Each flag gates its area's nav entry, pages, intake API, CLI group, daemon loop and, fordocsFirst, the docs gate. A new view at/settings/feature-flagslists every flag with a one-line description, its default and an on/off switch; Settings links to it.shep settings flags [enable|disable <flag>]does the same from the CLI.1b681a2b4e7420renumbers the spec to 135: the telemetry and unified-decisions workstreams took 133 and 134.Why
Implements
specs/135-review-cleanup-cuts/, from the "Where Shep Is Today and What to Cut" section ofdocs/competitors/t3code.md.Screenshots / Recording
I checked the feature-flags view at desktop and phone width in the running app with
pnpm dev:weband Playwright. Turningspacesoff removed the Spaces link from the sidebar and made/spacesreturn 404; turning it back on restored both. (The screenshots are local to the session; I can attach them if needed.)Testing
Local runs:
pnpm generatepnpm tsp:compilepnpm lint,pnpm format:checkpnpm typecheck,pnpm typecheck:webpnpm test:unitpnpm test:intpnpm check:storiespnpm buildpnpm build:storybookThe e2e specs I edited (aspm, ui-experience, ui-populated, cloud-deploy, contributor-onboarding) have not been run locally; CI runs them.
New tests:
shep settings flagsrequireFeaturePageStories added: FeatureFlagsList, FeatureFlagsPageClient, SettingsRows, ProviderList, CloudProviderIcons.
Notes for the reviewer
recaps/files already show (zero events), since recognition is still recorded by hand (see CONTRIBUTING). The stale-issues job reads GitHub and works as is.maintoday. If the telemetry or unified-decisions PRs merge first, I'll mergemainand renumber.shep security enforcekeeps its name. Moving it undershep aspmwould have broken existing CI scripts.Checklist
pnpm lintpassespnpm format:checkpassespnpm typecheckpassespnpm test:unitandpnpm test:intpasspnpm buildsucceedspnpm build:storybooksucceeds and every new component has a colocated.stories.tsxpnpm tsp:compileran andoutput.tsis committeddomain/orapplication/file imports frominfrastructure/feat/fixfor user-visible changes🤖 Generated with Claude Code
https://claude.ai/code/session_01TxtN2VcWzg6NTCLj4DbmfL