PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission
scope (verified list: actions, contents, issues, pull-requests, etc. - no
'workflows'). Merging it broke workflow_dispatch outright:
Invalid Argument - failed to parse workflow: (Line: 21, Col: 3):
Unexpected value 'workflows'
GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard
GitHub restriction, not something the permissions: block controls. The
correct fix is to never let the sync branch carry workflow-file changes in
the first place: after a clean merge, restore .github/workflows from
origin/main and amend. This also closes a latent risk - a clean upstream
merge could otherwise silently overwrite QualityHub's own CI files
(including this one) with whatever microsoft/BCQuality ships under the same
paths.
Confirmed via both REST API and gh CLI: promote-stable.yml has been on main
since 2026-07-03 but GitHub Actions never listed it as a dispatchable
workflow (404 on both). File content is valid, no encoding issues - a known
GitHub indexing gap. A no-op touch to the file forces re-discovery.
The last two scheduled runs (2026-07-13, 2026-07-20) failed silently: merge
was clean and validators green, but the push of the sync branch was rejected
by GitHub because upstream commits touch .github/workflows/*.yml and the
default token lacked the workflows scope. No issue was opened for this
failure mode, so the drift (now 3+ weeks / 31 commits) went unnoticed.
Michaels instinkt (Florence som upstream-vagt) realiseret efter ugens
staffing-lektion: opdagelse er mekanik, doemmekraft er menneske. En
cron ER et heartbeat - Florence gaar runden hver mandag 05:00 (eller
paa workflow_dispatch: Florence, gaa din runde) og taender lampen:
- Nye upstream-commits + rent merge + begge validatorer groenne over
det mergede korpus -> faerdigvalideret sync-PR (validatorer koerer
I workflowet, da GITHUB_TOKEN-PRs ikke trigger CI)
- Konflikt eller validator-fejl -> Issue med commit-liste og manuel
procedure
- Intet nyt -> een linje i summary, lampen forbliver slukket
(CURABIS-ROEMER-004-stil: orden faar tavshed)
Review, merge og promote forbliver Michaels. Florence lyser kun.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Merge til main er kvalitetsgaten; promote er udrulningsgaten - og
udrulningsgaten skal ikke kraeve en git-klon og fire kommandoer, isaer
ikke fra en strandkant. Actions -> Promote to stable -> Run workflow:
- Naegter at koere hvis stable er divergeret fra main (aldrig force;
divergens er en finding)
- Idempotent: intet at promovere = pæn besked, ingen fejl
- Skriver job-summary med de udrullede commits
- Kun write-adgang kan dispatche; ved kommende stable-ruleset skal
GitHub Actions paa bypass-listen
CONSUMPTION.md: de tre ligevaerdige promote-former dokumenteret
(knappen, een-linjeren, den eksplicitte form).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The /custom/ layer is a template: in upstream microsoft/BCQuality it stays
empty by default and is meant to be populated only inside a fork or consumer
clone. PR #55 both targeted /custom/ and leaked a new top-level folder.
- skills/write.md: add a fork-precondition guard so authors (human or agent)
confirm they are not in microsoft/BCQuality before scaffolding /custom/ content.
- Guard custom layer workflow: auto-closes upstream PRs that add/modify /custom/
content beyond the template files, with a friendly redirect-to-fork comment.
- Flag new top-level entries workflow: posts an advisory (non-blocking) comment
when a PR introduces an unexpected top-level folder or file for maintainer review.
Both workflows run only on microsoft/BCQuality (never on forks) and read the PR
file list via the API without checking out or executing PR code.
Co-authored-by: Jeremy Vyska <jeremy@sparebrained.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Make domain-skill knowledge discovery index-aware
The 6 AL domain review skills and read.md now enumerate candidate articles
from the BCQuality knowledge index (knowledge-index.json) instead of opening
every file under the domain folder to read its frontmatter. The worklist
selection predicate is unchanged (keywords intersect diff tokens, or topic
matches a changed object type) - only the discovery source changes, so the
same articles are selected. Full article bodies are read only for worklisted
entries.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Reconcile §Source wording with the lean knowledge index
The BCQuality filter now emits a lean index whose per-article description is a
one-line hint rather than the full verbatim Description. Update the six domain
skills' §Source to say the index carries a one-line description hint (keywords,
title, and a one-line description) instead of the full description. The
worklist selection predicate is unchanged: keywords drive selection and the
agent opens worklisted articles in full for their rule bodies.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Own the knowledge-index generator in BCQuality
The knowledge index is an acceleration of the skills' Source step, and its
schema is part of that contract — so BCQuality should own the generator rather
than each consumer re-implementing it. Add tools/Build-KnowledgeIndex.ps1 (the
parser + lean-description shaping + emit, lifted verbatim from the
BCAppsBCQuality filter prototype) and document the index in agent-consumption.md.
Consumers prune their clone to policy, then call this script; the index stays
in lockstep with the Source contract and every orchestrator gets the same
faithful index for free. The worklist selection predicate is unchanged.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Own knowledge-index generation in BCQuality (runtime + CI), not the consumer
The index is now produced by BCQuality itself: Entry's preparation step
rebuilds knowledge-index.json over the live, already-pruned clone at the start
of every run, and a new CI workflow validates the generator's health
(determinism, full coverage, selection-input integrity). Consumers no longer
invoke or know about the index.
Rebuilding over the pruned clone (vs shipping a committed full-corpus index)
keeps the index exact for any consumer policy: it can never list a denied
article, so policy-excluded rules cannot leak into discovery. READ now states
the index is discovery-only -- a finding must cite an article opened in full,
and rows whose file is absent are discarded before ranking.
- skills/entry.md: new 'Preparation -- knowledge index' precondition
- skills/read.md: index ownership + discovery-only invariant
- microsoft/skills/review/*.md (6): 'BCQuality builds' (not 'the filter emits')
- agent-consumption.md 5a: runtime+CI ownership rationale
- .github/workflows/knowledge-index.yml + scripts/Test-KnowledgeIndex.ps1: generator guard
- .gitignore: never commit the runtime index
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Make runtime index build non-interactive and self-contained
entry.md now gives the exact build command (pwsh ./tools/Build-KnowledgeIndex.ps1)
so the agent's preparation step is unambiguous, and the generator's -BCQualityRoot
parameter is optional (defaults to the clone root) so it runs in non-interactive
-p mode without prompting.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Resolve knowledge-index root to absolute path (cross-platform fix)
Get-ChildItem.FullName is always absolute, so deriving the relative article
path via Substring(\.Length) requires an absolute root. A relative root
such as '.' (used by the CI guard's 'Test-KnowledgeIndex.ps1 -Root .') left the
full path almost intact on Linux, producing bogus 'home/runner/.../knowledge'
paths and failing the coverage check. Normalise both the generator's
-BCQualityRoot and the test's -Root with Resolve-Path before use.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Jesper Schulz-Wedde <jesper.schulzwedde@microsoft.com>
Python validator derived from READ, WRITE, DO, and Entry. Enforces
frontmatter shape, required sections, knowledge-file length and
no-code-blocks rule, sample-sibling naming (<slug>.good.al /
<slug>.bad.al), action-skill section ordering, and unique skill ids
per kind. Runs in GitHub Actions on PRs and pushes to main; emits
GitHub annotations when GITHUB_ACTIONS is set, plain text otherwise.
Warnings do not fail the build.
Passes cleanly against the existing microsoft-layer corpus.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>