diff --git a/.github/workflows/b10x-docs-bundle.yml b/.github/workflows/b10x-docs-bundle.yml index dde7d05..e767fec 100644 --- a/.github/workflows/b10x-docs-bundle.yml +++ b/.github/workflows/b10x-docs-bundle.yml @@ -39,7 +39,7 @@ jobs: uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c - name: Build normalized documentation bundle - uses: beyond10x/docs-system/.github/actions/bundle@1d4c0262911761118ffdd7037890f541a0688714 + uses: beyond10x/docs-system/.github/actions/bundle@339b4b8462f19b4c9d3716e6a44ed2a3691eb9d8 with: repository-root: . output: ${{ runner.temp }}/b10x-docs-bundle diff --git a/.github/workflows/b10x-docs-check.yml b/.github/workflows/b10x-docs-check.yml new file mode 100644 index 0000000..e07d604 --- /dev/null +++ b/.github/workflows/b10x-docs-check.yml @@ -0,0 +1,34 @@ +# Generated by `atlas docs reconcile`; edit Atlas documentation intent, not this file. +name: Documentation source check + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +concurrency: + group: b10x-docs-check-${{ github.ref }} + cancel-in-progress: true + +jobs: + b10x-docs-check: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Check out exact source + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + persist-credentials: false + + - name: Set up Node.js + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 + with: + node-version: 24 + + - name: Check declared documentation sources + uses: beyond10x/docs-system/.github/actions/check@339b4b8462f19b4c9d3716e6a44ed2a3691eb9d8 + with: + repository-root: . diff --git a/AGENTS.md b/AGENTS.md index e24b623..5b026b3 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -75,7 +75,7 @@ rules still apply; historical brand exemptions do not authorize new public assoc ## Public documentation operations -This repository owns the public source and presentation allowlist in `b10x.docs.yaml`. The generated credential-free `.github/workflows/b10x-docs-bundle.yml` passively packages only those declared files for the exact successful `main` commit; it must never run repository code. Atlas selects the latest successful bundle with every other catalog source, and Website plus Docs System own rendering, shared components, search, and feeds. Do not add a standalone docs deployer or put App credentials in this public repository. If Atlas catalogs a former Pages workflow, that file remains repository-owned validation: preserve its bespoke checks while keeping exact read-only permissions, an unconditional pull-request trigger, and no deployment primitives. Project Pages at `/agentplugins/` is only the generated stable redirect façade in `.github/workflows/b10x-docs-pages.yml`; content-only publication never rebuilds it. +This repository owns the public source and presentation allowlist in `b10x.docs.yaml`. The generated credential-free `.github/workflows/b10x-docs-bundle.yml` passively packages only those declared files for the exact successful `main` commit; it must never run repository code. The generated `.github/workflows/b10x-docs-check.yml` runs the publisher's per-source checks on every pull request and main push, with read-only contents and no credentials; it is deliberately separate from the shared gate, which runs on `pull_request_target` with a secret and never reads candidate source. Atlas selects the latest successful bundle with every other catalog source, and Website plus Docs System own rendering, shared components, search, and feeds. Do not add a standalone docs deployer or put App credentials in this public repository. If Atlas catalogs a former Pages workflow, that file remains repository-owned validation: preserve its bespoke checks while keeping exact read-only permissions, an unconditional pull-request trigger, and no deployment primitives. Project Pages at `/agentplugins/` is only the generated stable redirect façade in `.github/workflows/b10x-docs-pages.yml`; content-only publication never rebuilds it. From the complete organization workspace, verify the contract with a clean Atlas checkout at the current remote `main`. Set `B10X_ATLAS_CHECKOUT` to a managed Atlas worktree when the primary checkout is dirty or stale; never infer command availability from the primary alone.