diff --git a/.claude/README-gitnexus-reviewer-swarm.md b/.claude/README-gitnexus-reviewer-swarm.md index 4706a2cb1..07cb5228f 100644 --- a/.claude/README-gitnexus-reviewer-swarm.md +++ b/.claude/README-gitnexus-reviewer-swarm.md @@ -29,6 +29,8 @@ lanes on Sonnet. - **Read-only.** Tools limited to Read/Grep/Glob/Bash, and every persona enforces an explicit permitted/prohibited Bash list. No agent edits files, commits, or posts. + This is the interactive swarm; the CI review agent's `ci-personas/` lanes are + narrower still — file reads plus the safe graph tools, no Grep/Glob/Bash. - **Evidence-grounded**; **missing visibility becomes verification work**; **manually invoked.** ## Editing diff --git a/.claude/skills/gitnexus-guide/SKILL.md b/.claude/skills/gitnexus-guide/SKILL.md index c96616130..e52560422 100644 --- a/.claude/skills/gitnexus-guide/SKILL.md +++ b/.claude/skills/gitnexus-guide/SKILL.md @@ -81,6 +81,18 @@ list_repos { offset: 400 } → repos 401–437, hasMore false Notes: `offset` ≥ `total` returns an empty page (with `total` still reported). Out-of-range or malformed `limit`/`offset` (non-integer, `limit` outside `[1, 200]`, `offset < 0`) are rejected with a clear error — `limit` above the max is rejected, not silently capped. The order is deterministic (lower-cased name, then path), so paging never skips or duplicates an entry while the registry is unchanged. +### Inline staleness signal (`query` / `context` / `impact` / `cypher`) + +These four hot read tools attach a non-blocking `staleness` field to their response when the index is behind the checkout's current HEAD — the same `{ commitsBehind, hint }` shape `list_repos` already reports — so a direct tool call surfaces a behind-HEAD index without a separate `list_repos` call: + +```jsonc +{ /* …the tool's normal result… */ + "staleness": { "commitsBehind": 3, "hint": "⚠️ Index is 3 commits behind HEAD. Run analyze tool to update." } +} +``` + +The field is **absent when the index is current** (or when the freshness check can't run), so its presence is the signal. It is only ever added to object results — raw-array `cypher` output and error envelopes are returned unchanged. `@group`-targeted calls do not carry it (multi-repo staleness is ill-defined). When you see it, the graph may be behind the working tree — re-run `analyze` before trusting blast-radius or dependence answers. + ### Taint findings (`explain`) `explain` returns taint findings recorded by `gitnexus analyze --pdg` — intra-procedural `TAINTED` edges plus cross-function `TAINT_PATH` hops where the interprocedural taint phase found a function-level source→sink chain. Each finding includes a sink category (command-injection, code-injection, path-traversal, sql-injection, xss), source/sink lines, and the ordered hop path with the variable carried on each hop. diff --git a/.claude/skills/gitnexus-impact-analysis/SKILL.md b/.claude/skills/gitnexus-impact-analysis/SKILL.md index 45eb7ce87..0b81795de 100644 --- a/.claude/skills/gitnexus-impact-analysis/SKILL.md +++ b/.claude/skills/gitnexus-impact-analysis/SKILL.md @@ -17,22 +17,23 @@ description: "Use when the user wants to know what will break if they change som ## Workflow ``` -1. impact({target: "X", direction: "upstream"}) → What depends on this +1. impact({target: "X", direction: "upstream"}) or `node .gitnexus/run.cjs impact "X" --direction upstream --repo .` 2. READ gitnexus://repo/{name}/processes → Check affected execution flows -3. detect_changes() → Map current git changes to affected flows +3. detect_changes({scope: "all"}) or `node .gitnexus/run.cjs detect-changes --scope all --repo .` 4. Assess risk and report to user ``` > If "Index is stale" → run `node .gitnexus/run.cjs analyze` in terminal. +> If `.gitnexus/run.cjs` is missing, replace `node .gitnexus/run.cjs` with `npx gitnexus` in the fallback commands. ## Checklist ``` -- [ ] impact({target, direction: "upstream"}) to find dependents +- [ ] impact({target, direction: "upstream"}) or CLI fallback to find dependents - [ ] Review d=1 items first (these WILL BREAK) - [ ] Check high-confidence (>0.8) dependencies - [ ] READ processes to check affected execution flows -- [ ] detect_changes() for pre-commit check +- [ ] detect_changes({scope: "all"}) or CLI fallback for pre-commit check - [ ] Assess risk level and report to user ``` @@ -55,7 +56,7 @@ description: "Use when the user wants to know what will break if they change som ## Tools -**impact** — the primary tool for symbol blast radius: +**impact** — the primary tool for symbol blast radius. If MCP is unavailable, use `node .gitnexus/run.cjs impact --direction upstream --repo .` instead: ``` impact({ @@ -73,10 +74,10 @@ impact({ - authRouter (src/routes/auth.ts:22) [CALLS, 95%] ``` -**detect_changes** — git-diff based impact analysis: +**detect_changes** — git-diff based impact analysis. If MCP is unavailable, use `node .gitnexus/run.cjs detect-changes --scope all --repo .` instead: ``` -detect_changes({scope: "staged"}) +detect_changes({scope: "all"}) → Changed: 5 symbols in 3 files → Affected: LoginFlow, TokenRefresh, APIMiddlewarePipeline @@ -86,7 +87,7 @@ detect_changes({scope: "staged"}) ## Example: "What breaks if I change validateUser?" ``` -1. impact({target: "validateUser", direction: "upstream"}) +1. impact({target: "validateUser", direction: "upstream"}) or `node .gitnexus/run.cjs impact "validateUser" --direction upstream --repo .` → d=1: loginHandler, apiMiddleware (WILL BREAK) → d=2: authRouter, sessionManager (LIKELY AFFECTED) diff --git a/.claude/skills/gitnexus-review/SKILL.md b/.claude/skills/gitnexus-review/SKILL.md index 90fe12396..9eabc426c 100644 --- a/.claude/skills/gitnexus-review/SKILL.md +++ b/.claude/skills/gitnexus-review/SKILL.md @@ -181,8 +181,7 @@ dropping anything without a concrete failing scenario. ### Swarm lanes Six dispatchable lane definitions ship with this skill in `ci-personas/` — -read-only reviewers restricted to Read/Glob/Grep plus the safe graph -tools. Five are finder lanes: `ci-correctness-lens`, `ci-security-lens`, +read-only reviewers restricted to file reads plus the safe graph tools. Five are finder lanes: `ci-correctness-lens`, `ci-security-lens`, `ci-blast-radius-lens`, `ci-coverage-lens`, and `ci-adversarial-lens` (which assumes the change is broken and constructs reachable failure scenarios the pattern checks miss). They carry the verification diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-adversarial-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-adversarial-lens.md index c7d620afc..84d526cd2 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-adversarial-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-adversarial-lens.md @@ -1,7 +1,7 @@ --- name: ci-adversarial-lens description: CI review swarm lane. Assumes the change is broken and constructs concrete failure scenarios — races, hostile inputs, state corruption, abuse of new surfaces — verified against source and the GitNexus graph. Read-only; reports findings only. -tools: Read, Glob, Grep, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__explain, mcp__gitnexus__pdg_query, mcp__gitnexus__trace, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__explain, mcp__gitnexus__pdg_query, mcp__gitnexus__trace, mcp__gitnexus__list_repos maxTurns: 12 --- diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-blast-radius-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-blast-radius-lens.md index 65cf04771..e014d39dc 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-blast-radius-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-blast-radius-lens.md @@ -1,7 +1,7 @@ --- name: ci-blast-radius-lens description: CI review swarm lane. Maps a PR's blast radius — dependents outside the diff, API/route surface, schema and version constants, compatibility breaks — from the GitNexus graph. Read-only; reports findings only. -tools: Read, Glob, Grep, mcp__gitnexus__impact, mcp__gitnexus__api_impact, mcp__gitnexus__route_map, mcp__gitnexus__context, mcp__gitnexus__query, mcp__gitnexus__shape_check, mcp__gitnexus__tool_map, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__impact, mcp__gitnexus__api_impact, mcp__gitnexus__route_map, mcp__gitnexus__context, mcp__gitnexus__query, mcp__gitnexus__shape_check, mcp__gitnexus__tool_map, mcp__gitnexus__list_repos maxTurns: 12 --- diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-correctness-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-correctness-lens.md index 8de542079..1c2ef5ed9 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-correctness-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-correctness-lens.md @@ -1,7 +1,7 @@ --- name: ci-correctness-lens description: CI review swarm lane. Hunts logic errors, edge cases, contract breaks, and state bugs in the changed symbols of a PR, grounded in the GitNexus graph. Read-only; reports findings only. -tools: Read, Glob, Grep, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__pdg_query, mcp__gitnexus__trace, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__pdg_query, mcp__gitnexus__trace, mcp__gitnexus__list_repos maxTurns: 12 --- diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-coverage-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-coverage-lens.md index 55667ae91..faf2192f6 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-coverage-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-coverage-lens.md @@ -1,7 +1,7 @@ --- name: ci-coverage-lens description: CI review swarm lane. Judges whether a PR's changed behavior is actually tested — missing cases, weak assertions, stale baselines, drift guards — using the GitNexus graph's test linkage. Read-only; reports findings only. -tools: Read, Glob, Grep, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__check, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__impact, mcp__gitnexus__check, mcp__gitnexus__list_repos maxTurns: 12 --- diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-critic-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-critic-lens.md index 4bd5017b0..d610f8f94 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-critic-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-critic-lens.md @@ -1,7 +1,7 @@ --- name: ci-critic-lens description: CI review swarm gate. Audits the orchestrator's draft review before publication — every finding anchored and concrete, severities calibrated, sections and verdict wording conformant, no generic filler. Returns PASS or a defect list; never rewrites the review. -tools: Read, Glob, Grep, mcp__gitnexus__context, mcp__gitnexus__query, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__context, mcp__gitnexus__query, mcp__gitnexus__list_repos maxTurns: 6 --- diff --git a/.claude/skills/gitnexus-review/ci-personas/ci-security-lens.md b/.claude/skills/gitnexus-review/ci-personas/ci-security-lens.md index 5e643a6f9..e98180464 100644 --- a/.claude/skills/gitnexus-review/ci-personas/ci-security-lens.md +++ b/.claude/skills/gitnexus-review/ci-personas/ci-security-lens.md @@ -1,7 +1,7 @@ --- name: ci-security-lens description: CI review swarm lane. Audits a PR's changed trust boundaries — input handling, injection, unsafe parsing, secrets, workflow/config risk — with GitNexus taint and dependence evidence. Read-only; reports findings only. -tools: Read, Glob, Grep, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__explain, mcp__gitnexus__pdg_query, mcp__gitnexus__impact, mcp__gitnexus__list_repos +tools: Read, mcp__gitnexus__query, mcp__gitnexus__context, mcp__gitnexus__explain, mcp__gitnexus__pdg_query, mcp__gitnexus__impact, mcp__gitnexus__list_repos maxTurns: 12 --- diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile index c57c0d6aa..96003dcef 100644 --- a/.devcontainer/Dockerfile +++ b/.devcontainer/Dockerfile @@ -39,6 +39,7 @@ ENV BUN_VERSION=${BUN_VERSION} \ TZ=${TZ} \ DEVCONTAINER=true \ NODE_OPTIONS=--max-old-space-size=4096 \ + GITNEXUS_AUTO_HEAP=0 \ POWERLEVEL9K_DISABLE_GITSTATUS=true # Native build toolchain that gitnexus/postinstall needs. It compiles diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 000000000..17f2eebe7 --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,5 @@ +# Custom self-hosted runner labels actionlint can't discover on its own. +# gitnexus-evolution: the skill-evolution EC2 runner (infra/gitnexus-evolution/). +self-hosted-runner: + labels: + - gitnexus-evolution diff --git a/.github/claude-canary-runtime/package-lock.json b/.github/claude-canary-runtime/package-lock.json index e78392daa..7716ef93f 100644 --- a/.github/claude-canary-runtime/package-lock.json +++ b/.github/claude-canary-runtime/package-lock.json @@ -11,7 +11,7 @@ "@anthropic-ai/claude-code": "2.1.214" }, "engines": { - "node": "22.16.0" + "node": "22.18.0" } }, "node_modules/@anthropic-ai/claude-code": { diff --git a/.github/claude-canary-runtime/package.json b/.github/claude-canary-runtime/package.json index 57076d892..50820742b 100644 --- a/.github/claude-canary-runtime/package.json +++ b/.github/claude-canary-runtime/package.json @@ -3,7 +3,7 @@ "version": "0.0.0", "private": true, "engines": { - "node": "22.16.0" + "node": "22.18.0" }, "dependencies": { "@anthropic-ai/claude-code": "2.1.214" diff --git a/.github/gitnexus-review-runtime/package-lock.json b/.github/gitnexus-review-runtime/package-lock.json index e805e759b..0677011c0 100644 --- a/.github/gitnexus-review-runtime/package-lock.json +++ b/.github/gitnexus-review-runtime/package-lock.json @@ -11,7 +11,7 @@ "gitnexus": "1.6.9" }, "engines": { - "node": "22.16.0" + "node": "22.18.0" } }, "node_modules/@emnapi/runtime": { diff --git a/.github/gitnexus-review-runtime/package.json b/.github/gitnexus-review-runtime/package.json index 237310bad..de0a1dd12 100644 --- a/.github/gitnexus-review-runtime/package.json +++ b/.github/gitnexus-review-runtime/package.json @@ -3,7 +3,7 @@ "private": true, "version": "1.0.0", "engines": { - "node": "22.16.0" + "node": "22.18.0" }, "dependencies": { "gitnexus": "1.6.9" diff --git a/.github/scripts/npm-ci-retry.sh b/.github/scripts/npm-ci-retry.sh new file mode 100755 index 000000000..58a3ae462 --- /dev/null +++ b/.github/scripts/npm-ci-retry.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash +# Install a lock-pinned runtime, retrying only what a transient registry fault +# can change. `npm ci` re-creates node_modules from the committed lockfile and +# re-verifies every SHA-512 integrity on each attempt, so a retry can only +# reproduce the identical tree — never a different one. Each attempt is bounded +# so a hung registry cannot eat the job budget the model review needs. +# +# Usage: npm-ci-retry.sh