Update the agents submodule to its master tip - #767
Merged
Merged
Conversation
The `agents` repository deleted `protect-version-file.sh` in `f41f49c` and asked consuming repositories to remove its entry from `.claude/settings.json`, which PR #700 did. The same script is also wired in `.codex/hooks.json`, where it ran before every `apply_patch`, `Edit`, and `Write`. Once `.agents/shared` moves past `f41f49c`, that entry would point at a missing file. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move the `.agents/shared` pin from `5698000` (2026-06-02) to `f3d8ac5` (2026-09-03), the tip of `agents/master`, 253 commits later. Fresh clones and worktrees get the pinned commit from `init-submodules`, not the branch tip, and the old pin left their hooks broken: - `.claude/settings.json` runs `secret-scan-gate.sh` before every Bash command, and `init-submodules` points `core.hooksPath` at `.agents/scripts/git-hooks/`. Neither existed at `5698000`, so no local secret scan ran there. - The pre-PR gate at `5698000` expects `pre-pr.ok` under `.git/`, which is a file in a worktree, so it blocked every `gh pr create` there. `fe86e5c` and `c4626e0` make it resolve the absolute git directory. The shared agent, command, guideline, script, and skill directories are linked as a whole, so the files this range deletes or renames (the `kotlin-review` skill and agent, `coding-guidelines.md`, and others) leave no dangling symlinks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
armiol
approved these changes
Sep 24, 2026
alexander-yevsyukov
added a commit
to SpineEventEngine/core-jvm-compiler
that referenced
this pull request
Sep 25, 2026
Brings in: - SpineEventEngine/config#767: update the `agents` submodule. - SpineEventEngine/config#769: let a publication describe what its SBOM lists, with `sbom { dependencies(...); bundled(...) }`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
.agents/sharedpin from5698000(2026-06-02) tof3d8ac5(2026-09-03), the current tip ofagents/master, 253 commits later.apply_patch|Edit|Write→protect-version-file.shPreToolUse entry from.codex/hooks.json. Upstream deleted the script inf41f49c, and Stop wiring theversion.gradle.ktsEdit-block hook #700 un-wired it for Claude Code, but the Codex copy was missed. After this bump, it would have pointed at a missing file.Why
Fresh clones and worktrees get the pinned commit from
init-submodules, not the branch tip, so they have been running hooks from anagentssnapshot that is almost four months old:secret-scan-gate.sh, wired in.claude/settings.json, and.agents/scripts/git-hooks/, thecore.hooksPaththatinit-submodulessets, did not exist at5698000. Neither local secret scan ran in those checkouts; only the gitleaks CI job did.5698000looks for$repo_root/.git/pre-pr.ok. In a worktree,.gitis a file, so a session started in a fresh worktree could never satisfy the gate.fe86e5candc4626e0resolve--absolute-git-dirinstead.Notes for reviewers
agents,commands,guidelines,scripts, andskillsdirectories as whole directories. The files this range deletes or renames therefore leave no dangling links: thekotlin-reviewskill and agent,coding-guidelines.md,documentation-guidelines.md,refactoring-guidelines.md→refactoring.md, andprotect-version-file.sh. Every.agents/,.claude/, or.junie/path named in config's tracked files resolves atf3d8ac5. The one exception is the gitignoredcheck-links/.cacheruntime directory, which only appears when the skill runs..claude/settings.jsonand.codex/hooks.jsonis present and executable (100755) atf3d8ac5. The three Bash gates allow a harmless command, and the pre-PR gate still blocksgh pr createwhen there is no sentinel.extra.set(...), and the secret-scan wiring with the gitleaks CI job from Prevent secret commits: authoritative.gitignore, non-destructive merge, hooks, CI #706.plansDirectoryis.claude/plans(a345512b), while theagentsrepo sends its own plans to.agents/tasks(575e85f). That setting belongs to theagentsrepo itself and doesn't reach config through the submodule..gitmodulessetsignore = allon the submodule, sogit show --stathides the pin change. To see it, rungit diff --ignore-submodules=none master.....agents/or.codex/, and the submodule has no Kotlin files for Detekt at either pin.🤖 Generated with Claude Code