Merge pull request #66 from Curabis/setup/git-based-consumption

QualityHub: det nye private repo får sit eget navn
This commit is contained in:
Michael Dieringer 2026-07-03 18:04:35 +02:00 • committed by GitHub
commit 3a70d10afd
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
10 changed files with 52 additions and 35 deletions

View file

@ -5,7 +5,24 @@ Microsoft/BCQuality architecture: an orchestrator invokes `/skills/entry.md`,
Entry dispatches layer action skills, each skill runs Source → Relevance →
Worklist → Action and emits DO-shaped findings. That document is the
*architecture*. This document is the *actual state* — which consumption paths
are live in the CURABIS fork, and which are dormant upstream inheritance.
are live, and which are dormant upstream inheritance.
## The two-repo architecture
- **`Curabis/BCQuality`** (PUBLIC, fork of microsoft/BCQuality): the intake.
Carries only upstream content — `microsoft/`, `community/`, `skills/`,
`tools/`. Synced from Microsoft via GitHub's *Sync fork*. It is also the
contribution path: community-layer improvements go upstream through it.
It NEVER contains the custom layer.
- **`Curabis/QualityHub`** (PRIVATE, this repo): the product. Custom layer,
agents, setup machinery, release channel, governance — everything below.
Because QualityHub shares git ancestry with microsoft/BCQuality, upstream
updates arrive as a clean merge.
**"Opdater QualityHub fra BCQuality":** fetch the `bcquality` remote → merge
`bcquality/main` on a branch → PR (CI validates the merged corpus, catching
upstream schema drift at the gate) → Michael merges → promote. Never merge
upstream directly into `stable`.
## Active: the CURABIS Standard session model
@ -41,7 +58,7 @@ future CI/PR-review integration:
## Access model: PRIVATE repo, git-based consumption
BCQuality is a **private** repository. All consumption is git-based through
the **channel clone** at `%USERPROFILE%\.claude\BCQuality`, pinned to the
the **channel clone** at `%USERPROFILE%\.claude\QualityHub`, pinned to the
`stable` branch. Authentication is Git Credential Manager — the developer's
existing GitHub login; the first git contact opens a browser login, and that
is the entire token story. `raw.githubusercontent.com` and unauthenticated
@ -51,8 +68,8 @@ GitHub-API calls are dead and must not appear in any consumer.
Two lines (idempotent — safe to re-run; the clone prompts the GCM login):
git clone --branch stable --single-branch https://github.com/Curabis/BCQuality.git "$env:USERPROFILE\.claude\BCQuality"
powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\BCQuality\custom\setup\machine\Install-CurabisMachine.ps1"
git clone --branch stable --single-branch https://github.com/Curabis/QualityHub.git "$env:USERPROFILE\.claude\QualityHub"
powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\QualityHub\custom\setup\machine\Install-CurabisMachine.ps1"
It installs the global CLAUDE.md (identity substituted from git config),
bc-mcp-bridge.js, the bc-mcp config template (the developer inserts their

View file

@ -78,7 +78,7 @@ reviews what happened. He asks one question about every significant event:
He compares against the full BCQuality knowledge base — the machine-local
mirror at `%USERPROFILE%\.claude\bcquality-knowledge\custom\` (fallback: the
channel clone `%USERPROFILE%\.claude\BCQuality\custom\knowledge\`).
channel clone `%USERPROFILE%\.claude\QualityHub\custom\knowledge\`).
Domains: `architecture/`, `testing/`, `mcp/`
## The Two Proposal Types
@ -161,7 +161,7 @@ delivery channel depends on where Francis fires:
1. **Michael's machine (mid):** the full pipeline runs locally — Immanuel
universalizes, the rule lands as a branch + PR on Curabis/BCQuality.
2. **Any other machine (field):** file the proposal as a **GitHub Issue** on
`Curabis/BCQuality` with the complete Ferencz-format brief (Observation,
`Curabis/QualityHub` with the complete Ferencz-format brief (Observation,
Evidence with citations, Suggested rule/filename, Context). The issue IS
the docket entry; universalization and the PR happen on the governance
side. If `gh` is unavailable, hand the finished brief to the developer

View file

@ -179,7 +179,7 @@ POST https://api.github.com/repos/Curabis/BCQuality/pulls
### Step 5 — Report PR URL to user
```
PR åben: https://github.com/Curabis/BCQuality/pull/<number>
PR åben: https://github.com/Curabis/QualityHub/pull/<number>
Afventer Michaels godkendelse via GitHub-merge.
```

View file

@ -30,7 +30,7 @@ param(
# LEGACY: repoet er privat - raw-URLs virker ikke laengere. Brug altid en
# lokal klon; kanal-klonen findes paa alle onboardede maskiner:
# -BCQualityHome "$env:USERPROFILE\.claude\BCQuality"
# -BCQualityHome "$env:USERPROFILE\.claude\QualityHub"
[string]$RawBase = '',
[switch]$Quiet

View file

@ -37,24 +37,24 @@ Detect which mode based on the trigger phrase and proceed accordingly.
## Source: the channel clone (BCQuality is PRIVATE — no raw URLs)
All artifacts come from the machine's **channel clone** — a git clone of
`Curabis/BCQuality` pinned to the `stable` branch. Authentication is Git
`Curabis/QualityHub` pinned to the `stable` branch. Authentication is Git
Credential Manager (the developer's existing GitHub login); there are NO
tokenless raw.githubusercontent fetches anywhere — the repo is private.
```
SRC = %USERPROFILE%\.claude\BCQuality (kanal-klonen, stable)
SRC = %USERPROFILE%\.claude\QualityHub (kanal-klonen, stable)
BASE = {SRC}\custom\setup
AGENTS_BASE = {SRC}\custom\agents
```
**Before ANY Mode A/B work, ensure the channel clone is fresh:**
git -C "$env:USERPROFILE\.claude\BCQuality" fetch origin stable --quiet
git -C "$env:USERPROFILE\.claude\BCQuality" checkout -B stable origin/stable --quiet
git -C "$env:USERPROFILE\.claude\QualityHub" fetch origin stable --quiet
git -C "$env:USERPROFILE\.claude\QualityHub" checkout -B stable origin/stable --quiet
If the clone is missing entirely:
git clone --branch stable --single-branch https://github.com/Curabis/BCQuality.git "$env:USERPROFILE\.claude\BCQuality"
git clone --branch stable --single-branch https://github.com/Curabis/QualityHub.git "$env:USERPROFILE\.claude\QualityHub"
**Vocabulary:** wherever this document says "fetch", it means **copy the file
from SRC** — a filesystem copy, which preserves raw bytes by definition (the
@ -210,10 +210,10 @@ onboarded — `~/.claude/CLAUDE.md` or `~/.claude/bc-mcp-bridge.js` is missing
run the full onboarding NOW (idempotent; identity taken from git config; the
first git contact may open a browser login — that IS the authentication):
git clone --branch stable --single-branch https://github.com/Curabis/BCQuality.git "$env:USERPROFILE\.claude\BCQuality"
powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\BCQuality\custom\setup\machine\Install-CurabisMachine.ps1"
git clone --branch stable --single-branch https://github.com/Curabis/QualityHub.git "$env:USERPROFILE\.claude\QualityHub"
powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\QualityHub\custom\setup\machine\Install-CurabisMachine.ps1"
(Skip the clone line if `%USERPROFILE%\.claude\BCQuality` already exists.)
(Skip the clone line if `%USERPROFILE%\.claude\QualityHub` already exists.)
Then report the manual leftovers it lists (personal client secret; the AL
Language extension if VS Code lacks it) and ask the developer to restart
Claude Code.
@ -224,7 +224,7 @@ self-heal suffices:
powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\sync-bcquality-knowledge.ps1"
(If that sync script itself is missing, copy it from the channel clone:
`%USERPROFILE%\.claude\BCQuality\custom\setup\sync-bcquality-knowledge.ps1` —
`%USERPROFILE%\.claude\QualityHub\custom\setup\sync-bcquality-knowledge.ps1` —
or run the full onboarding above.)
These rules are always active.
@ -545,7 +545,7 @@ Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Triggered by: "Opdater CURABIS Standard fra BCQuality"
**Step 0 — freshen the channel clone** (see Source section): fetch + checkout
`origin/stable` in `%USERPROFILE%\.claude\BCQuality`; create the clone if
`origin/stable` in `%USERPROFILE%\.claude\QualityHub`; create the clone if
missing. Every copy below reads from that clone.
Updates only the files that come directly from BCQuality.
@ -778,7 +778,7 @@ Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
## Invocation note
This agent is read on demand from the machine's channel clone
(`%USERPROFILE%\.claude\BCQuality\custom\setup\curabis-standard.agent.md`,
(`%USERPROFILE%\.claude\QualityHub\custom\setup\curabis-standard.agent.md`,
after freshening — see Source section). Both commands work in any project —
including one not yet configured — because the machine's `~/.claude/CLAUDE.md`
(installed by onboarding) knows the clone location. On a machine without the

View file

@ -3,7 +3,7 @@
These instructions apply to every Claude Code session, regardless of project.
BCQuality is a PRIVATE repo: all access is git-based via the channel clone at
`%USERPROFILE%\.claude\BCQuality` (pinned to `stable`; auth = Git Credential
`%USERPROFILE%\.claude\QualityHub` (pinned to `stable`; auth = Git Credential
Manager). No raw.githubusercontent URLs — they do not work and must not be used.
## Auto-update BCQuality (runs at every session start)
@ -11,15 +11,15 @@ Manager). No raw.githubusercontent URLs — they do not work and must not be use
If the current project has `.github/.agents/bcquality.agent.md`:
1. Freshen the channel clone and read its SHA:
`git -C "$env:USERPROFILE\.claude\BCQuality" fetch origin stable --quiet`
`git -C "$env:USERPROFILE\.claude\BCQuality" rev-parse origin/stable`
`git -C "$env:USERPROFILE\.claude\QualityHub" fetch origin stable --quiet`
`git -C "$env:USERPROFILE\.claude\QualityHub" rev-parse origin/stable`
(If the clone is missing: run the machine self-heal from the project
CLAUDE.md — two lines: git clone + Install-CurabisMachine.ps1.)
2. Read stored SHA from `~/.claude/.bcquality-version` (may not exist yet)
3. If SHA is different (or file missing):
a. `git -C "$env:USERPROFILE\.claude\BCQuality" checkout -B stable origin/stable --quiet`
a. `git -C "$env:USERPROFILE\.claude\QualityHub" checkout -B stable origin/stable --quiet`
b. Execute Mode B from the clone:
`%USERPROFILE%\.claude\BCQuality\custom\setup\curabis-standard.agent.md`
`%USERPROFILE%\.claude\QualityHub\custom\setup\curabis-standard.agent.md`
c. Refresh the local knowledge mirror:
`powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\sync-bcquality-knowledge.ps1"`
(git-based; also writes the new SHA to the version marker)
@ -49,7 +49,7 @@ When the user says either of these commands, freshen the channel clone (see
Auto-update step 1) and follow the setup agent read from:
```
%USERPROFILE%\.claude\BCQuality\custom\setup\curabis-standard.agent.md
%USERPROFILE%\.claude\QualityHub\custom\setup\curabis-standard.agent.md
```
- **"Konfigurer dette projekt til CURABIS Standard"** → fuld setup af nyt repo

View file

@ -4,8 +4,8 @@
# Onboarding paa en ny maskine er TO linjer (GCM-login i browseren ved
# foerste git-kontakt ER autentificeringen):
#
# git clone --branch stable --single-branch https://github.com/Curabis/BCQuality.git "$env:USERPROFILE\.claude\BCQuality"
# powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\BCQuality\custom\setup\machine\Install-CurabisMachine.ps1"
# git clone --branch stable --single-branch https://github.com/Curabis/QualityHub.git "$env:USERPROFILE\.claude\QualityHub"
# powershell -ExecutionPolicy Bypass -File "$env:USERPROFILE\.claude\QualityHub\custom\setup\machine\Install-CurabisMachine.ps1"
#
# Alt kopieres fra kanal-klonen (filsystem-kopi = raa bytes; ingen raw-URLs).
#
@ -19,7 +19,7 @@ param(
$ErrorActionPreference = 'Stop'
$claude = Join-Path $env:USERPROFILE '.claude'
$clone = Join-Path $env:USERPROFILE '.claude\BCQuality'
$clone = Join-Path $env:USERPROFILE '.claude\QualityHub'
New-Item -ItemType Directory -Force $claude | Out-Null
# Kilde: scriptet ligger i <klon>\custom\setup\machine → klonrod tre niveauer op
@ -28,7 +28,7 @@ $src = (Resolve-Path (Join-Path $PSScriptRoot '..\..\..')).Path
# Sikr kanal-klonen paa den kanoniske placering (scriptet KAN vaere koert fra en anden klon)
if (-not (Test-Path (Join-Path $clone '.git'))) {
if ($src -ne $clone) {
git clone --branch stable --single-branch 'https://github.com/Curabis/BCQuality.git' $clone
git clone --branch stable --single-branch 'https://github.com/Curabis/QualityHub.git' $clone
if ($LASTEXITCODE -ne 0) { throw 'git clone af kanal-klonen fejlede - tjek adgang/GCM.' }
}
}

View file

@ -1,7 +1,7 @@
# Refresh the MACHINE-LOCAL mirror of the Curabis BCQuality knowledge base.
#
# v2 - GIT-BASED (privat repo): al konsumtion sker via en kanal-klon i
# %USERPROFILE%\.claude\BCQuality (pinned til stable-branchen)
# %USERPROFILE%\.claude\QualityHub (pinned til stable-branchen)
# Autentificering haandteres af Git Credential Manager - ingen raw-URLs,
# ingen GitHub API, ingen CDN-cache. Foerste koersel udloeser evt. et
# GCM-login i browseren; det ER onboarding-autentificeringen.
@ -18,8 +18,8 @@
$ErrorActionPreference = 'Stop'
$repoUrl = 'https://github.com/Curabis/BCQuality.git'
$clone = Join-Path $env:USERPROFILE '.claude\BCQuality'
$repoUrl = 'https://github.com/Curabis/QualityHub.git'
$clone = Join-Path $env:USERPROFILE '.claude\QualityHub'
$dest = Join-Path $env:USERPROFILE '.claude\bcquality-knowledge'
$marker = Join-Path $env:USERPROFILE '.claude\.bcquality-version'
$staging = "$dest.tmp"

View file

@ -59,7 +59,7 @@ Layer 1 - Microsoft BCQuality: https://github.com/microsoft/BCQuality
Layer 2 - CURABIS custom knowledge: read from the machine-local mirror —
`%USERPROFILE%\.claude\bcquality-knowledge\custom\` (always complete; never a
hardcoded file list — the rulebook grows). Fallback without a mirror: the
channel clone at `%USERPROFILE%\.claude\BCQuality\custom\knowledge\`. The
channel clone at `%USERPROFILE%\.claude\QualityHub\custom\knowledge\`. The
repo is PRIVATE — raw URLs do not exist.
If a source is unreachable, **degrade gracefully**: fall back to the triage protocol

View file

@ -55,8 +55,8 @@ Resolve the current rule set at review time, in this order:
`%USERPROFILE%\.claude\bcquality-knowledge\custom\`). The mirror is synced
from the `stable` release channel and is always the complete custom layer.
2. **Fallback (no mirror):** read directly from the machine's channel clone —
`%USERPROFILE%\.claude\BCQuality\custom\knowledge\**\*.md` (freshen with
`git -C "$env:USERPROFILE\.claude\BCQuality" pull` if stale). The repo is
`%USERPROFILE%\.claude\QualityHub\custom\knowledge\**\*.md` (freshen with
`git -C "$env:USERPROFILE\.claude\QualityHub" pull` if stale). The repo is
PRIVATE: tree-API/raw-URL fallbacks no longer exist. Consumers without
filesystem access outside the workspace (e.g. Copilot) rely on the
repo-committed agent files alone — deep custom-layer lookups happen in