Skip to content

Fleet rollout: standardized deps.yml across all 81 remaining bounded-systems repos #2

Description

@bdelanghe

Execution tracker for the org-wide fan-out (infra#104). Decision: maximum coverage, predictable and standardized — the byte-identical templates/deps.yml goes to every non-archived, attachable repo, landed as PRs auto-merged when green.

Why no lockfile survey first: the lane passes cleanly on repos with nothing scannable (--allow-no-lockfiles), so eligibility is universal — the org-wide code search that blocked this earlier became prioritization, not a gate. Wave order favors npm/deno-heavy repos so findings arrive early and in triageable volume.

Red PRs do not auto-merge. Under the hard-fail posture, a red osv check on an adoption PR is a real pre-existing finding (front-desk#70's maiden scan caught GHSA-frvp-7c67-39w9 exactly this way). Those get triaged individually: relock if an upstream fix exists, osv-scanner.toml with a written reason if not.

Inventory (90 org repos): 3 covered (front-desk-scheduler, infra, ci-workflows self-test) · 4 archived (dev-contracts-{validate,spec,transform,extract}) · 2 dotfile repos no agent session can attach (.github, .github-private — human-only) · 81 to adopt.

Standing recommendation once coverage lands: delete (or mark inert) bounded-systems/.github/required-baseline.yml — it claims to be an org-wide injected floor, has never run (no workflows ruleset rule exists on Free), and its report-only posture contradicts the fleet's hard-fail. Human-only, since .github is unattachable.

Waves

  • 1 (npm/deno-heavy): guest-room, gh-project-room, prx, site-mcp, static-mcp, verbspec, verbspec-mcp, claude-token-tools
  • 2: door-kit, door-keeper, agent-memory, scout-wire, door-scout, site, repo-health, await-approval
  • 3: conformance, ocap-provenance, facilities, door-peercred, door-net, door-concierge, claude-box, brand, synoptic
  • 4: trellis, trellis-kit, drift-gate, trellis-private, fleet, descriptor-kit, conformance-kit, keeper-wire, trust
  • 5: concierge-wire, deploy, dev-contracts, mint, baobab, string-audit, gh-action-brand-checks, gh-action-node-uniqueness, gh-action-contracts
  • 6: cas, lone, hooksmith, git-ast, installer, cf-oidc-token-broker, env, anchored-chain-sqlite, anchored-chain
  • 7: audit-context, fs, gh, auth, git, github-budget, bd, machine-schema, policy
  • 8: proc, repo-root, disposition, host, schema-gen, scout, slack, surface-sync, seam-check
  • 9: fold-engine, bounded-tools-mcp, bounded.tools, verify, content-catalog, schema-bridge, lobby, lima-devshell, frond, dev-registry

Per repo: attach → branch claude/deps-osv-scan → push template → PR → checks → merge green / triage red. Findings and exceptions get logged here as they happen.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions