|
27 | 27 | - The `squash-history` opt-in tracks the release boundary: the first release FREEZES history through that commit, and only the unreleased tail squashes. [`squash-until-release`](docs/fleet/agents.md/squash-until-release.md) |
28 | 28 | - `fleet-main-protection` blocks force-push, `fleet-tag-protection` blocks `v*` tag deletes. [`history-rewrites`](docs/fleet/agents.md/history-rewrites.md) |
29 | 29 | - npm stages burn versions: minor default, odai patch/minor, major needs `X.Y.Z-prerelease`. [`version-bumps`](docs/fleet/agents.md/version-bumps.md) |
30 | | -- NEVER open a pull request to land a version bump: the bump commit goes DIRECTLY on the default branch via the release App. (`.claude/hooks/fleet/no-version-bump-pr-guard/`) [`version-bumps`](docs/fleet/agents.md/version-bumps.md) |
| 30 | +- Never hand-create a version-bump PR. The npm publish workflow uses the PR App to sign the bump, open its reviewed PR, and resume staging after merge; the Release App handles Actions and release operations. (`.claude/hooks/fleet/no-version-bump-pr-guard/`) [`version-bumps`](docs/fleet/agents.md/version-bumps.md) |
31 | 31 | - Dot-naming `@owner/<name>[.<lang>].<target>[-<platform>]`: the `.target` token carries the domain. [`binary-vs-napi-naming`](docs/fleet/agents.md/binary-vs-napi-naming.md) |
32 | 32 | - A private package is unscoped `local-<directory>` at version `0.0.0`. [`private-package-identity`](docs/fleet/agents.md/private-package-identity.md) |
33 | 33 | - Every `release.publishedPackages` entry is non-private and the set carries ONE version. (`scripts/fleet/check/published-packages-are-release-ready.mts`) [`private-package-identity`](docs/fleet/agents.md/private-package-identity.md) |
|
158 | 158 | - Validate what SHIPS, not the source tree: the packed tarball's bytes, plus a leak scan of both. [`artifact-hygiene`](docs/fleet/agents.md/artifact-hygiene.md) |
159 | 159 | - A `github-action` member ships committed `dist/` at a tag. (`scripts/fleet/check/github-action-aliases-are-not-frozen.mts`) [`github-action-release-contract`](docs/fleet/agents.md/github-action-release-contract.md) |
160 | 160 | - GitHub CLI tokens: keychain only; `workflow` scope off by default; 8-hour age cap. [`gh-token-hygiene`](docs/fleet/agents.md/gh-token-hygiene.md) |
161 | | -- Release App writes default-branch and release content. PR App writes repair branches, issues, and PRs. Both are organization-wide. [`token-hygiene`](docs/fleet/agents.md/token-hygiene.md) |
| 161 | +- Release App manages Actions runs and release content. PR App writes signed branches, issues, and PRs. Both are organization-wide. [`token-hygiene`](docs/fleet/agents.md/token-hygiene.md) |
162 | 162 | - Commits on `main`/`master` must be signed. [`commit-signing`](docs/fleet/agents.md/commit-signing.md) [`git-config-write-guard`](docs/fleet/agents.md/git-config-write-guard.md) |
163 | 163 | - Keep AI logic canonical; generate client aliases during setup, never commit them. [`release-vs-cascade`](docs/fleet/agents.md/release-vs-cascade.md) |
164 | 164 | - Skills, commands, and agent instructions are thin wrappers. [`agents-and-skills`](docs/fleet/agents.md/agents-and-skills.md) |
|
0 commit comments