Hardening: stable-branch som udrulningskanal - merge til main er ikke laengere deploy

Alle forbrugere laeser nu fra stable i stedet for main:
- curabis-standard.agent.md v10: BASE/AGENTS_BASE + self-heal-URL -> stable
- sync-bcquality-knowledge.ps1: $branch = stable
- machine/CLAUDE.md: auto-update gater paa stable-SHA og fetcher setup fra stable
- templates/bcquality.agent.md + al-triage.agent.md: knowledge-URLer -> stable
  (+ fix af doed reference: branch-merge-to-main-workflow.md var omdoebt til
  feature-branch-must-merge-to-track-branch.md - templaten shippede et 404)
- francis.agent.md + Invoke-CurabisEvidence.ps1: raw-base -> stable
- CONSUMPTION.md: Release channel-sektion med promote-procedure og rationale

Deploy sker herefter kun ved bevidst fast-forward af stable (kun Michael).
Kanal oprettet: stable @ 57b8292, tag v1.0.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Michael Dieringer 2026-07-02 00:02:44 +02:00
parent 57b8292848
commit 3ef2e95af6
8 changed files with 294 additions and 269 deletions

View file

@ -38,6 +38,31 @@ future CI/PR-review integration:
currently consumed by nothing. Keep it — but do not mistake it for active currently consumed by nothing. Keep it — but do not mistake it for active
configuration of the session model. configuration of the session model.
## Release channel: `stable`
Merging to `main` is **not** a deployment. All consumers — the machine
CLAUDE.md auto-update, `sync-bcquality-knowledge.ps1`, the setup agent's
fetch URLs, and the agent templates' knowledge references — read from the
**`stable`** branch, never from `main`. `main` is where PRs land and CI runs;
`stable` is what every developer machine actually executes.
Deploying is a deliberate act (Michael only):
git checkout stable
git merge --ff-only main
git push origin stable
git checkout main
Optionally cut a version tag at the same commit (`git tag vX.Y.Z && git push
origin vX.Y.Z`) for a historical record. If a bad change reaches `stable`,
roll back by force-moving `stable` to the previous good commit — consumers
follow the branch, so recovery is one push.
Rationale: `main` used to be the live deploy channel — any merge silently
overwrote `bc-mcp-bridge.js` (which handles S2S credentials) on every
developer machine at next session start. The `stable` gate separates "CI
accepted it" from "the organization runs it".
## Known deltas to close before activating the Entry flow ## Known deltas to close before activating the Entry flow
1. **`custom/skills/` is empty.** The CURABIS review pass lives in the 1. **`custom/skills/` is empty.** The CURABIS review pass lives in the

View file

@ -78,7 +78,7 @@ reviews what happened. He asks one question about every significant event:
He compares against the full BCQuality knowledge base: He compares against the full BCQuality knowledge base:
``` ```
BASE = https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge BASE = https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge
``` ```
Domains: `architecture/`, `testing/`, `mcp/` Domains: `architecture/`, `testing/`, `mcp/`

View file

@ -29,7 +29,7 @@ param(
[string]$BCQualityHome, [string]$BCQualityHome,
# Bruges naar der ikke er en lokal klon: knowledge-filer HTTP-tjekkes herfra. # Bruges naar der ikke er en lokal klon: knowledge-filer HTTP-tjekkes herfra.
[string]$RawBase = 'https://raw.githubusercontent.com/Curabis/BCQuality/main', [string]$RawBase = 'https://raw.githubusercontent.com/Curabis/BCQuality/stable',
[switch]$Quiet [switch]$Quiet
) )

View file

@ -1,7 +1,7 @@
--- ---
kind: action-skill kind: action-skill
id: curabis-standard-setup id: curabis-standard-setup
version: 9 version: 10
title: CURABIS Standard — Project Setup title: CURABIS Standard — Project Setup
description: > description: >
Configures a new or existing repository to the CURABIS Standard development Configures a new or existing repository to the CURABIS Standard development
@ -37,8 +37,8 @@ Detect which mode based on the trigger phrase and proceed accordingly.
## Source URLs (BCQuality — always fetch fresh) ## Source URLs (BCQuality — always fetch fresh)
``` ```
BASE = https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/setup BASE = https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/setup
AGENTS_BASE = https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/agents AGENTS_BASE = https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/agents
``` ```
| Artefakt | URL | | Artefakt | URL |
@ -168,7 +168,7 @@ If `~/.claude/bcquality-knowledge/` is missing or empty, self-heal before contin
If the sync script itself is missing, first download it AS RAW BYTES (do not If the sync script itself is missing, first download it AS RAW BYTES (do not
decode/re-encode — use `Invoke-WebRequest -OutFile`) from decode/re-encode — use `Invoke-WebRequest -OutFile`) from
`https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/setup/sync-bcquality-knowledge.ps1` `https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/setup/sync-bcquality-knowledge.ps1`
to `~/.claude/sync-bcquality-knowledge.ps1`, then run it. to `~/.claude/sync-bcquality-knowledge.ps1`, then run it.
These rules are always active. These rules are always active.

View file

@ -8,11 +8,11 @@ These instructions apply to every Claude Code session, regardless of project.
If the current project has `.github/.agents/bcquality.agent.md`: If the current project has `.github/.agents/bcquality.agent.md`:
1. Fetch the latest commit SHA for `custom/setup/` in BCQuality: 1. Fetch the latest commit SHA for `custom/setup/` in BCQuality:
`https://api.github.com/repos/Curabis/BCQuality/commits?path=custom/setup&per_page=1` `https://api.github.com/repos/Curabis/BCQuality/commits?path=custom/setup&sha=stable&per_page=1`
2. Read stored SHA from `~/.claude/.bcquality-version` (may not exist yet) 2. Read stored SHA from `~/.claude/.bcquality-version` (may not exist yet)
3. If SHA is different (or file missing): 3. If SHA is different (or file missing):
a. Fetch and execute Mode B from: a. Fetch and execute Mode B from:
`https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/setup/curabis-standard.agent.md` `https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/setup/curabis-standard.agent.md`
b. Write new SHA to `~/.claude/.bcquality-version` b. Write new SHA to `~/.claude/.bcquality-version`
c. Report: "BCQuality opdateret til [short-sha] — [antal] filer tjekket" c. Report: "BCQuality opdateret til [short-sha] — [antal] filer tjekket"
4. If SHA is unchanged: continue silently 4. If SHA is unchanged: continue silently
@ -25,7 +25,7 @@ unless something actually changed.
When the user says either of these commands, fetch and follow the setup agent: When the user says either of these commands, fetch and follow the setup agent:
``` ```
https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/setup/curabis-standard.agent.md https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/setup/curabis-standard.agent.md
``` ```
- **"Konfigurer dette projekt til CURABIS Standard"** → fuld setup af nyt repo - **"Konfigurer dette projekt til CURABIS Standard"** → fuld setup af nyt repo

View file

@ -20,7 +20,7 @@
$ErrorActionPreference = 'Stop' $ErrorActionPreference = 'Stop'
$repo = 'Curabis/BCQuality' $repo = 'Curabis/BCQuality'
$branch = 'main' $branch = 'stable'
$dest = Join-Path $env:USERPROFILE '.claude\bcquality-knowledge' $dest = Join-Path $env:USERPROFILE '.claude\bcquality-knowledge'
$staging = "$dest.tmp" $staging = "$dest.tmp"
$rawBase = "https://raw.githubusercontent.com/$repo/$branch" $rawBase = "https://raw.githubusercontent.com/$repo/$branch"

View file

@ -57,13 +57,13 @@ Loop: **reproduce -> root-cause -> minimal-fix recommendation.**
Layer 1 - Microsoft BCQuality: https://github.com/microsoft/BCQuality Layer 1 - Microsoft BCQuality: https://github.com/microsoft/BCQuality
Layer 2 - CURABIS custom knowledge (fetch before citing a finding): Layer 2 - CURABIS custom knowledge (fetch before citing a finding):
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/pages-must-not-contain-business-logic.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/pages-must-not-contain-business-logic.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/namespace-must-be-verified-from-source.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/namespace-must-be-verified-from-source.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/al-identifiers-must-be-english.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/al-identifiers-must-be-english.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/clarify-before-building.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/clarify-before-building.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-setup-must-use-library-codeunit.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-setup-must-use-library-codeunit.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-data-must-be-random-and-complete.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-data-must-be-random-and-complete.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/tests-must-adapt-to-existing-code.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/tests-must-adapt-to-existing-code.md
If a source is unreachable, **degrade gracefully**: fall back to the triage protocol If a source is unreachable, **degrade gracefully**: fall back to the triage protocol
below plus the CURABIS-ARCH rules in `bcquality.agent.md`, note that BCQuality was below plus the CURABIS-ARCH rules in `bcquality.agent.md`, note that BCQuality was

View file

@ -47,28 +47,28 @@ of the quality in the code they write.
Layer 1 - Microsoft BCQuality: https://github.com/microsoft/BCQuality Layer 1 - Microsoft BCQuality: https://github.com/microsoft/BCQuality
Layer 2 - CURABIS custom knowledge (fetch before applying rules): Layer 2 - CURABIS custom knowledge (fetch before applying rules):
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/pages-must-not-contain-business-logic.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/pages-must-not-contain-business-logic.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/namespace-must-be-verified-from-source.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/namespace-must-be-verified-from-source.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/al-identifiers-must-be-english.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/al-identifiers-must-be-english.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/clarify-before-building.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/clarify-before-building.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/xliff-translation-workflow.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/xliff-translation-workflow.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/new-file-requires-vscode-refresh.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/new-file-requires-vscode-refresh.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/exposed-objects-must-be-in-a-permission-set.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/exposed-objects-must-be-in-a-permission-set.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/shared-project-memory-must-be-in-repo.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/shared-project-memory-must-be-in-repo.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/commit-message-must-include-bc-task-id.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/commit-message-must-include-bc-task-id.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/architecture/branch-merge-to-main-workflow.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/architecture/feature-branch-must-merge-to-track-branch.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-setup-must-use-library-codeunit.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-setup-must-use-library-codeunit.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-data-must-be-random-and-complete.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-data-must-be-random-and-complete.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/tests-must-adapt-to-existing-code.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/tests-must-adapt-to-existing-code.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-one-when-per-test.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-one-when-per-test.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/ui-test-codeunit-naming.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/ui-test-codeunit-naming.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/testing/test-feature-scenario-tags.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/testing/test-feature-scenario-tags.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/api-page-flowfields-must-be-calcfields.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/api-page-flowfields-must-be-calcfields.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/stored-derived-fields-must-not-be-exposed-directly.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/stored-derived-fields-must-not-be-exposed-directly.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/api-page-key-fields-must-be-editable-on-insert.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/api-page-key-fields-must-be-editable-on-insert.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/api-page-least-privilege-write-access.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/api-page-least-privilege-write-access.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/agent-must-not-write-business-process-status.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/agent-must-not-write-business-process-status.md
- https://raw.githubusercontent.com/Curabis/BCQuality/main/custom/knowledge/mcp/bc-mcp-find-active-task-for-branch.md - https://raw.githubusercontent.com/Curabis/BCQuality/stable/custom/knowledge/mcp/bc-mcp-find-active-task-for-branch.md
## Action ## Action