commit 203af9d952d4ce691245fd55c92ad351b9c659fc
parent 9074d93f3f17003c33ec1ba194d97a00643f963e
Author: triesap <tyson@radroots.org>
Date: Wed, 29 Jul 2026 23:28:57 +0000
repo: forbid hosted workflow automation
- declare the OSS capsule source-only for automation authority
- forbid GitHub workflows and capsule-local CI definitions
- retain validation through checked-in forge-agnostic commands
- delegate any local orchestration to the parent root act surface
Diffstat:
1 file changed, 1 insertion(+), 0 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -13,5 +13,6 @@
- avoid `unsafe` unless it is strictly necessary, locally justified, and documented with nearby invariants
- do not expose secrets, private keys, credentials, tokens, invite codes, private identifiers, sensitive user data, or sensitive event content in code, logs, tests, fixtures, docs, or examples
- use checked-in, repo-owned validation first; run the smallest documented validation that credibly covers the change, and use release acceptance validation for production candidates
+- `.github/**` and capsule-local CI workflows are forbidden; keep validation forge-agnostic, and place any required monorepo orchestration exclusively under the parent monorepo's root `.act/**` authority
- if validation cannot run, report exactly what was skipped and why; never claim validation passed unless it actually ran
- keep commits focused and reviewable, using `<scope>: <imperative summary>` unless a repo convention overrides it