Skip to content

Update the agents submodule to its master tip - #767

Merged
alexander-yevsyukov merged 2 commits into
masterfrom
update-agents-submodule
Sep 24, 2026
Merged

alexander-yevsyukov merged 2 commits into
masterfrom
update-agents-submodule

Conversation

@alexander-yevsyukov

Copy link
Copy Markdown
Contributor

What

  • Moves the .agents/shared pin from 5698000 (2026-06-02) to f3d8ac5 (2026-09-03), the current tip of agents/master, 253 commits later.
  • Removes the apply_patch|Edit|Write → protect-version-file.sh PreToolUse entry from .codex/hooks.json. Upstream deleted the script in f41f49c, and Stop wiring the version.gradle.kts Edit-block hook #700 un-wired it for Claude Code, but the Codex copy was missed. After this bump, it would have pointed at a missing file.

Why

Fresh clones and worktrees get the pinned commit from init-submodules, not the branch tip, so they have been running hooks from an agents snapshot that is almost four months old:

  • secret-scan-gate.sh, wired in .claude/settings.json, and .agents/scripts/git-hooks/, the core.hooksPath that init-submodules sets, did not exist at 5698000. Neither local secret scan ran in those checkouts; only the gitleaks CI job did.
  • The pre-PR gate at 5698000 looks for $repo_root/.git/pre-pr.ok. In a worktree, .git is a file, so a session started in a fresh worktree could never satisfy the gate. fe86e5c and c4626e0 resolve --absolute-git-dir instead.

Notes for reviewers

  • config links the shared agents, commands, guidelines, scripts, and skills directories as whole directories. The files this range deletes or renames therefore leave no dangling links: the kotlin-review skill and agent, coding-guidelines.md, documentation-guidelines.md, refactoring-guidelines.md → refactoring.md, and protect-version-file.sh. Every .agents/, .claude/, or .junie/ path named in config's tracked files resolves at f3d8ac5. The one exception is the gitignored check-links/.cache runtime directory, which only appears when the skill runs.
  • Every script wired in .claude/settings.json and .codex/hooks.json is present and executable (100755) at f3d8ac5. The three Bash gates allow a harmless command, and the pre-PR gate still blocks gh pr create when there is no sentinel.
  • The other follow-ups upstream asked consumers to make in this range are already in config: the Version Guard parser for extra.set(...), and the secret-scan wiring with the gitleaks CI job from Prevent secret commits: authoritative .gitignore, non-destructive merge, hooks, CI #706.
  • One difference is left alone on purpose. config's plansDirectory is .claude/plans (a345512b), while the agents repo sends its own plans to .agents/tasks (575e85f). That setting belongs to the agents repo itself and doesn't reach config through the submodule.
  • .gitmodules sets ignore = all on the submodule, so git show --stat hides the pin change. To see it, run git diff --ignore-submodules=none master....
  • No Gradle build was run. Gradle doesn't read .agents/ or .codex/, and the submodule has no Kotlin files for Detekt at either pin.

🤖 Generated with Claude Code

alexander-yevsyukov and others added 2 commits September 24, 2026 19:40
The `agents` repository deleted `protect-version-file.sh` in
`f41f49c` and asked consuming repositories to remove its entry from
`.claude/settings.json`, which PR #700 did. The same script is also
wired in `.codex/hooks.json`, where it ran before every `apply_patch`,
`Edit`, and `Write`. Once `.agents/shared` moves past `f41f49c`, that
entry would point at a missing file.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move the `.agents/shared` pin from `5698000` (2026-06-02) to `f3d8ac5`
(2026-09-03), the tip of `agents/master`, 253 commits later.

Fresh clones and worktrees get the pinned commit from `init-submodules`,
not the branch tip, and the old pin left their hooks broken:

- `.claude/settings.json` runs `secret-scan-gate.sh` before every Bash
  command, and `init-submodules` points `core.hooksPath` at
  `.agents/scripts/git-hooks/`. Neither existed at `5698000`, so no
  local secret scan ran there.
- The pre-PR gate at `5698000` expects `pre-pr.ok` under `.git/`, which
  is a file in a worktree, so it blocked every `gh pr create` there.
  `fe86e5c` and `c4626e0` make it resolve the absolute git directory.

The shared agent, command, guideline, script, and skill directories are
linked as a whole, so the files this range deletes or renames (the
`kotlin-review` skill and agent, `coding-guidelines.md`, and others)
leave no dangling symlinks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T18:49:20.277026Z ddb49b2 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@alexander-yevsyukov
alexander-yevsyukov merged commit a494e7c into master Sep 24, 2026
2 checks passed
@alexander-yevsyukov
alexander-yevsyukov deleted the update-agents-submodule branch September 24, 2026 19:50
alexander-yevsyukov added a commit to SpineEventEngine/core-jvm-compiler that referenced this pull request Sep 25, 2026
Brings in:
- SpineEventEngine/config#767: update the `agents` submodule.
- SpineEventEngine/config#769: let a publication describe what its SBOM
  lists, with `sbom { dependencies(...); bundled(...) }`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants