Skip to content

Add shared AI-policy compliance tooling (hooks, reusable workflow, AI-POLICY.md) - #36

Open
francisco-dlp wants to merge 14 commits into
hyperspy:mainfrom
francisco-dlp:ai-policy-compliance
Open

francisco-dlp wants to merge 14 commits into
hyperspy:mainfrom
francisco-dlp:ai-policy-compliance

Conversation

@francisco-dlp

Copy link
Copy Markdown
Member

Add shared AI-policy compliance tooling (hooks, reusable workflow, AI-POLICY.md)

What this adds

  • AI-POLICY.md — the normative HyperSpy AI policy (proposal gate, Assisted-by: <tool>:<model> attribution, Co-authored-by: prohibition for AI tools) with a sentinel-delimited pinned block that repositories embed in their root AGENTS.md.
  • scripts/ — stdlib-only, pytest-covered enforcement scripts: check-ai-co-author.py (commit-msg hook), ci-check-ai-trailers.py (PR-wide trailer scan), ci-check-changelog.py (towncrier-aware, parameterized source dirs), check-agents-policy.py (AGENTS.md pin checker with --fix). Shared patterns live in one module (hyperspy_ai_patterns.py) — no more "keep in sync" duplicates.
  • .pre-commit-hooks.yaml — publishes check-ai-co-author and check-agents-policy so any repository consumes them with one tag-pinned repo: block.
  • .github/workflows/compliance.yml — reusable workflow (workflow_call) with jobs ai-trailers, changelog, agents-policy; deterministic, offline, no secrets, stable job ids; second-checkout pattern (tooling_repo/tooling_ref inputs) so consumers can test against a fork before tagging.
  • .github/workflows/self-test.yml — pytest (Python 3.9 + 3.12 matrix), ruff, hook try-repo proofs, and a synthetic negative proof (no prohibited commit is ever published).
  • AGENTS.md — knowledge base with the pinned policy block (inserted by the tool, not typed).
  • PULL_REQUEST_TEMPLATE.md + CONTRIBUTING.md — org default community files carrying the AI-assistance disclosure fields to every repository in the organization lacking its own.
  • README.md — adoption guide: 4-step recipe (pre-commit block, workflow caller, pin insertion, required checks), inputs table, pre-tag testing, versioning.

Verification

  • pytest suites for every script (merge-base diff semantics, deleted-fragment predicate, CRLF/two-marker pin edge cases).
  • Fork-internal CI proved the self-test workflow green before this PR was opened, including the in-CI rejection of an AI Co-authored-by: trailer (synthetic fixture).

Versioning plan

After merge: tag v1.0.0 (annotated) on the merge commit plus a floating v1; consumers pin @v1 for workflows and v1.0.0 for pre-commit; pre-commit.ci autoupdate follows the tags.

Relates to the HyperSpy proposals repository policy (AI-assisted non-trivial changes require an accepted proposal) and to the coding_with_ai.rst developer guide, which will link this file once published.

Assisted-by: OmO:claude-fable-5.1

Add ruff, YAML and end-of-file checks for the shared tooling scripts and tests, plus an interim commit-msg guard that rejects AI Co-authored-by trailers.

Assisted-by: OmO:claude-fable-5.1
…ok with tests

Ports the HyperSpy AI co-author trailer check into the shared org tooling repository as a module plus hook, with pytest coverage.

Assisted-by: OmO:claude-fable-5.1
Ports HyperSpy's PR-commit trailer scan into the shared org tooling repository, parameterized like the hook, with pytest coverage.

Assisted-by: OmO:claude-fable-5.1
…AGENTS.md

Adds the AGENTS.md policy-pin checker with byte-preserving CRLF-aware fixups and 19 pytest cases covering two-marker layouts, stale-block replacement and malformed-sentinel handling.

Assisted-by: OmO:claude-fable-5.1
Parameterizes HyperSpy's changelog CI check for any org repository: towncrier config derivation (package/package_dir nesting without the equality shortcut), merge-base diffs, deletion-safe fragment predicates and 16 pytest cases.

Assisted-by: OmO:claude-fable-5.1
…-policy section

Adds the organisation-level default PR template with AI-assistance disclosure fields and a CONTRIBUTING guide carrying the HyperSpy AI policy, for every repository lacking its own.

Assisted-by: OmO:claude-fable-5.1
Adds the normative AI contribution rules, the shared enforcement tooling description and the sentinel-delimited block that check-agents-policy pins into AGENTS.md.

Assisted-by: OmO:claude-fable-5.1
…hooks

Publish the shared commit-msg hook and AGENTS.md pin tool as
.pre-commit-hooks.yaml so any organisation repository can adopt them with
a single repo: block pinned to a tag.

Dogfood by registering both hooks in the local .pre-commit-config.yaml
(repo: local) against scripts/... so this repository enforces the same
policy it ships. check-agents-policy runs with --fix and --policy
AI-POLICY.md.

Assisted-by: OmO:claude-fable-5.1
…elog, AGENTS.md policy pin)

Adds a reusable workflow_call workflow with jobs ai-trailers, changelog and agents-policy. Each job checks out the caller and the shared tooling repo at a pinned ref into .hyperspy-github; ai-trailers resolves the PR/push/skip commit range and scans for prohibited trailers (warning-only on push), changelog requires a fragment when the configured source dirs change on a PR, and agents-policy verifies the pinned AGENTS.md block. Eight inputs parameterize the tooling repo/ref, pyproject, source dirs, changelog dir, AGENTS.md path and the check toggles. Job display names equal job ids (no name keys), contents: read only, no secrets.

Assisted-by: OmO:claude-fable-5.1
Adds the hand-authored AGENTS.md for hyperspy/.github: purpose, key-files
table, working-in-this-repository notes and the MANUAL marker. The pinned
AI policy block is inserted by `python3 scripts/check-agents-policy.py
--policy AI-POLICY.md --fix AGENTS.md` so it stays in sync with the
canonical text in AI-POLICY.md.

Assisted-by: OmO:claude-fable-5.1
Rewrite the org repo README around the new compliance tooling:
reusable workflows, composite actions, and the AI-POLICY.md /
scripts / .pre-commit-hooks.yaml set. Adds the four-step adoption
recipe (pre-commit block pinned to v1.0.0, compliance.yml caller,
check-agents-policy to insert the pinned block, and the three
required status checks), a full inputs table, a fork-testing
section, the vX.Y.Z / v1 versioning contract, and a Developing
section covering pytest, pre-commit, and the self-test workflow.

Assisted-by: OmO:claude-fable-5.1
Add the org repo self-test workflow that proves the shared AI-policy
tooling before any consumer depends on it.

The pytest job runs the script test suite on Python 3.9 and 3.12 and
lints scripts/ + tests/ with ruff on 3.12. The changelog tests
importorskip tomllib and therefore skip on 3.9.

The smoke job runs the AI-policy tooling against itself: the
check-agents-policy pin against the canonical AI-POLICY.md block, a
synthetic negative proof that the ci-check-ai-trailers.py script
rejects a prohibited trailer (with the wrap-around 'if' that fails
the job if the scan ever silently passes), the PR-only trailer
scan, and two pre-commit try-repo proofs against a local hook repo
that exercise the bad case (rejection expected) and the ok case
(acceptance expected).

tests/requirements.txt is added as a documentation of the dev
dependency so consumers can see what the test suite needs without
reading the workflow.

Must NOT call the reusable workflow from the org repo itself
(GAP-4): the org repo has no pyproject; consumers prove it.

Assisted-by: OmO:claude-fable-5.1
…flags

The tomllib import guard aborted the check even when explicit flags made towncrier parsing unnecessary; derivation tests now skip on Python < 3.11.

Assisted-by: OmO:claude-fable-5.1
The inline AI_PATTERNS fallback was a temporary crutch for the parallel per-todo worktrees where the sibling module did not exist yet; every real deployment (CI second checkout, pre-commit hook clone, contributor checkout) has the module adjacent, so the fallback was unreachable dead code that re-created the exact keep-in-sync duplication the shared module exists to remove. Missing dependency is now a hard exit-2 configuration error naming the module and the remedy, pinned by a regression test that runs the script in isolation.

Assisted-by: OmO:claude-fable-5.1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant