文件历史

提交图

327 次代码提交

作者 SHA1 备注 提交日期
Asim Aslam c9e61c0f7b Classify provider failures in agent inspection (#4782)
Co-authored-by: Codex <codex@openai.com>
2026-07-12 06:49:13 +01:00
Asim Aslam 5aa6e50ae5 Stream remote agent chat replies (#4763)
Co-authored-by: Codex <codex@openai.com>
2026-07-12 02:15:11 +01:00
Asim Aslam 741f308546 Add CLI input resume for agent runs (#4758)
Co-authored-by: Codex <codex@openai.com>
2026-07-12 00:59:29 +01:00
Asim Aslam 85e2091ec9 docs: gate first-agent quickcheck wayfinding (#4725)
Co-authored-by: Codex <codex@openai.com>
2026-07-11 18:58:20 +01:00
Asim Aslam 2452647d7b Add first-agent debug smoke breadcrumbs (#4720)
Co-authored-by: Codex <codex@openai.com>
2026-07-11 17:59:01 +01:00
Asim Aslam 7d00219b5d docs: verify first-agent wayfinding contract (#4707)
Co-authored-by: Codex <codex@openai.com>
2026-07-11 15:38:42 +01:00
Asim Aslam 7b782589d3 docs: surface first-agent quickcheck (#4608)
Co-authored-by: Codex <codex@openai.com>
2026-07-10 20:15:55 +01:00
Asim Aslam 10a5a5b235 Add first-agent quickcheck breadcrumbs (#4597)
Co-authored-by: Codex <codex@openai.com>
2026-07-10 18:19:38 +01:00
Asim Aslam 99a956dec3 Add agent resume breadcrumbs (#4589)
Co-authored-by: Codex <codex@openai.com>
2026-07-10 17:34:29 +01:00
Asim Aslam 98cbafd11a docs(loop): formalize the agent-agnostic mention model (#4559)
The loop's dispatch is agent-agnostic already — `--agent` just sets the
@mention it posts, so any coding agent that responds to an issue @mention and
opens a PR works. Make that explicit instead of implying Codex-only:

- micro-loop guide: add a "Choosing an agent" section — Codex (default), Claude
  Code (via anthropics/claude-code-action responding to @claude), any other
  mention-driven agent, and an honest note that assignment-triggered agents
  (e.g. Copilot's coding agent) aren't supported by the mention dispatch yet.
- Clarify the `--agent` help text and the CLI README bullet.

No behavior change — the mention model already covers Codex and Claude; this
documents it and scopes the one real gap (an "assign" adapter) honestly.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-10 11:12:28 +01:00
Asim Aslam a565dce4a0 Add first-agent docs CLI parity check (#4506)
Co-authored-by: Codex <codex@openai.com>
2026-07-09 23:15:14 +01:00
Asim Aslam 7d2586a2f9 Make micro new contract use local module (#4472)
Co-authored-by: Codex <codex@openai.com>
2026-07-09 16:49:31 +01:00
Asim Aslam 5274f7c44f docs: tighten first-agent wayfinding guard (#4457)
Co-authored-by: Codex <codex@openai.com>
2026-07-09 12:45:25 +01:00
Asim Aslam da5b1a2599 loop-release: bump minor for features, patch for fixes (semver-honest) (#4377)
The release action always bumped the PATCH, so genuine features (new providers,
`micro loop`, the security role, agent memory, …) all shipped as patches while
the minor stayed frozen at .3 (now on v6.3.18). By semver, backward-compatible
features are MINOR bumps.

Now the bump reflects what shipped, read from the CHANGELOG [Unreleased] section
(kept current by the coherence role):
- `### Added` / `### Changed`  -> MINOR (vX.(M+1).0)
- fixes/docs only             -> PATCH (vX.M.(P+1))
- breaking (`### Removed` / a "(breaking)" heading / BREAKING) -> skip the
  automated release; a MAJOR stays a human decision.

Applied to both go-micro's loop-release.yml and the generic `micro loop`
template (guards a missing CHANGELOG.md -> patch). Verified against the current
CHANGELOG: next release resolves to v6.4.0 (features present), not v6.3.19.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-08 19:36:32 +01:00
Asim Aslam e70111426b Allow direct first-agent chat prompts (#4373)
Co-authored-by: Codex <codex@openai.com>
2026-07-08 17:22:23 +01:00
Asim Aslam 5a85cba982 docs: add examples wayfinding index (#4239)
Co-authored-by: Codex <codex@openai.com>
2026-07-07 13:34:38 +01:00
Asim Aslam 45cf24162b Add first-agent examples CLI wayfinding (#4124)
Co-authored-by: Codex <codex@openai.com>
2026-07-06 07:17:16 +01:00
Asim Aslam 96eea598fc docs: align first-agent inspect command (#4113)
Co-authored-by: Codex <codex@openai.com>
2026-07-06 03:30:28 +01:00
Asim Aslam eb16370f03 Add zero-to-hero CLI entrypoint (#4102)
Co-authored-by: Codex <codex@openai.com>
2026-07-06 01:02:09 +01:00
Asim Aslam 36fd5b7bcd Promote first-agent doctor recovery (#4090)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 22:59:00 +01:00
Asim Aslam 304d14331c docs: lead getting started with no-secret path (#4057)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 17:09:01 +01:00
Asim Aslam 8c9521cc63 docs: surface agent demo after scaffolding (#4052)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 16:11:07 +01:00
Asim Aslam 621aa68f13 Lead CLI docs with agent demo (#4049)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 15:17:24 +01:00
Asim Aslam 84e37e413e feat(cli): surface no-secret agent demo (#4039)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 13:08:42 +01:00
Asim Aslam 9cc49f7718 Add first-agent recovery doctor (#4034)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 12:23:30 +01:00
Asim Aslam 6ecfcd5cdf cli: surface first-agent next steps (#3993)
Co-authored-by: Codex <codex@openai.com>
2026-07-05 00:59:18 +01:00
Asim Aslam 96ecf67573 agent: surface checkpoint resume hints in inspect (#3912)
Co-authored-by: Codex <codex@openai.com>
2026-07-04 11:26:58 +01:00
Asim Aslam ab0bf29c79 feat(loop): add a security role that vets for vulnerabilities (#3818)
Adds an opt-in `security` role to `micro loop` and wires it into go-micro's own
loop. On a schedule it dispatches the agent to audit the codebase for real,
exploitable vulnerabilities and file them.

Security gets a deliberately more conservative policy than the other roles,
encoded in .github/loop/prompts/security.md:
- NEVER auto-merges a security change (fixes stay human-reviewed).
- NEVER publishes exploit detail / PoC in a public issue — novel exploitable
  findings get a concise `security` + `needs-human` issue (class, location,
  impact) routed to private disclosure; only known/public dep CVEs get a
  bump PR (no auto-merge).
- Weekly by default (`--security-cron`, 0 6 * * 1); tunable.

The go-micro prompt targets its real attack surface: MCP/A2A gateways, x402
payments, JWT/wrapper auth, provider BaseURL SSRF + key leakage, the agent
tool loop (prompt injection / guardrail bypass), TLS defaults, the loop's own
PAT, and dependency CVEs via govulncheck.

Note: an agent review is not a gate. The deterministic companion — govulncheck
as a required CI check — is a recommended follow-up so known-vulnerable deps
can't merge at all.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-04 07:03:08 +01:00
Asim Aslam 3cafff8789 Make agent preflight failures actionable (#3851)
Co-authored-by: Codex <codex@openai.com>
2026-07-03 22:00:02 +01:00
Asim Aslam 6042a6c5f5 Add CLI docs wayfinding (#3807)
Co-authored-by: Codex <codex@openai.com>
2026-07-03 14:21:34 +01:00
Asim Aslam cf790048ad loop: triage watches Lint + Run Tests too, not just the harness (#3714)
Backstop for the gate: previously loop-triage only fired on Harness (E2E)
failures, so a red lint or test on master (e.g. the misspell that slipped past
because golangci-lint isn't a required check) produced no fix issue. Now triage
watches all the gate workflows.

- micro loop: `--ci-workflow` accepts a comma-separated list of workflow names,
  rendered into the triage workflow_run trigger as a YAML array; the issue names
  the actual failed workflow via github.event.workflow_run.name. (generic CLI)
- go-micro: regenerate loop-triage.yml to watch "Harness (E2E)", "Lint",
  "Run Tests"; generalize the triage prompt beyond the harness (a lint/test
  failure on master is a real regression to fix, not a flake to ignore).
- Docs: update CONTINUOUS_IMPROVEMENT.md triage description.

Note: this is defense-in-depth. The primary fix is making golangci-lint a
required status check so red lint can't merge in the first place — that stays
with the human (branch protection).


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 20:21:07 +01:00
Asim Aslam 76961d503a feat(loop): go-micro runs on micro loop (dogfood its own tool) (#3657)
* feat(loop): go-micro now runs on `micro loop` (dogfood its own tool)

Replace go-micro's five hand-written loop workflows with ones generated by
`micro loop init --roles all`, making "go-micro builds itself with micro loop"
literally true rather than aspirational.

- Generate loop-planner/builder/triage/coherence/release.yml via the CLI with
  go-micro's cadence and wiring (planner :59, builder :29, coherence 07:00,
  release 23:00; CI gate "Harness (E2E)"; token CODEX_TRIGGER_TOKEN; base master;
  tag prefix v). The old loop-architect.yml and loop-devrel.yml become
  loop-planner.yml and loop-coherence.yml.
- Move the queue to .github/loop/PRIORITIES.md and add .github/loop/NORTH_STAR.md
  (a concise steer pointing to internal/docs/THESIS.md), adopting the loop's
  convention.
- Preserve go-micro's rich instructions as editable policy in
  .github/loop/prompts/{planner,builder,triage,coherence}.md — the architect
  founder-lens + adoption steer, the increment builder, harness-failure triage,
  and the DevRel changelog/blog pass — faithfully ported from the old inline
  prompts. Behavior is preserved; only the mechanism is now generated.
- CLI refinement the migration surfaced: prompts (and NORTH_STAR/PRIORITIES) are
  now write-once — `micro loop init --force` refreshes workflow MECHANICS but
  never clobbers customized POLICY. Added renderKeep + a test.
- Update internal/docs/CONTINUOUS_IMPROVEMENT.md (renamed workflows, moved queue,
  the prompt-file model, and a note that these files are generated by micro loop).

Verified: build, go test ./cmd/micro/loop/..., golangci-lint (0 issues), gofmt;
`micro loop verify` passes; all generated workflows are valid YAML; re-running
init --force is idempotent and preserves policy.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

* loop: strip prompt editorial comments before posting to the agent

Verification of the migration surfaced that a dispatch workflow posted the
prompt file's leading <!-- editorial --> header to the agent, and __ISSUE__
inside it got substituted too (e.g. "Keep 4242 literal"). Harmless (invisible
in rendered markdown) but unclean and mildly confusing. The dispatch and triage
body construction now strips <!-- --> blocks with `sed '/<!--/,/-->/d'` before
substituting runtime tokens. Regenerated go-micro's workflows; added a test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 11:14:21 +01:00
Asim Aslam f839ca7427 feat(cli): prompt-file-driven micro loop + coherence & release roles (#3655)
Rework `micro loop` so the workflows are the mechanism and each dispatch role's
instruction is an editable .github/loop/prompts/<role>.md file (the policy).
That split lets any repo — including go-micro itself — customize behavior by
editing prompt files instead of forking the CLI, which is the prerequisite for
go-micro consuming its own tool without losing its richer prompts.

- Add two opt-in roles: `coherence` (README/docs/CHANGELOG alignment) and
  `release` (cut the next patch tag on new commits; bakes in the
  persist-credentials:false fix so the PAT push isn't clobbered by the
  checkout token — the 403 we hit on the live release action).
- `--roles` selects which roles to scaffold (default planner,builder,triage;
  `all` for everything); `--tag-prefix`, `--release-cron`, `--coherence-cron`
  added. Templates keep the << >> delimiters so GHA ${{ }} passes through;
  prompts leave __ISSUE__/__RUNURL__ as runtime tokens the workflow substitutes.
- `micro loop verify` now checks each present role workflow has its prompt.
- README updated with the five roles and a copy-pasteable flag example
  (folds in the readability fix from the now-closed #3651).

Verified: build, `go test ./cmd/micro/loop/...`, vet, golangci-lint (0 issues),
gofmt; and an end-to-end `micro loop init --roles all` whose generated
workflows all parse as valid YAML and pass `micro loop verify`.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 10:47:49 +01:00
Asim Aslam 5f3244d09e feat(cli): add micro loop to scaffold a self-improving repo loop (#3649)
`micro loop init` writes an autonomous improvement loop into any repository —
the same planner/builder/triage loop that maintains go-micro, generalized:

- planner (loop-planner.yml): keeps a ranked queue in .github/loop/PRIORITIES.md
- builder (loop-builder.yml): builds the top open item as a single-concern PR,
  auto-merged on green CI
- triage (loop-triage.yml): turns CI failures into scoped fix issues

plus .github/loop/NORTH_STAR.md (direction) and PRIORITIES.md (queue).

The agent adapter is mention-based, not hardcoded to Codex: `--agent @codex`
(or any @mention agent that responds on an issue and can run gh), `--token-secret`,
`--branch`, `--ci-workflow`, and cron flags are the whole config-vs-core boundary.
Templates use << >> delimiters so GitHub Actions' own ${{ }} expressions pass
through untouched. `micro loop verify` checks the wiring and flags the two things
the CLI can't: the token secret and branch protection (the green-CI gate).

Built inside go-micro with the config/core split already drawn, so the workflows
can later be extracted to a standalone reusable-workflows repo without a rewrite.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 10:12:12 +01:00
Asim Aslam 45a23a3417 test first-agent walkthrough boundaries (#3621)
Co-authored-by: Codex <codex@openai.com>
2026-07-02 03:31:30 +01:00
Asim Aslam 28320fc1d4 cli: add first-agent preflight diagnostics (#3608)
Co-authored-by: Codex <codex@openai.com>
2026-07-02 00:02:53 +01:00
Asim Aslam 0595130f16 run: surface MCP tools in the micro run banner by default (#3434)
The gateway already serves /mcp/tools on :8080 unconditionally (every
endpoint is an AI-callable tool), but the startup banner only printed an MCP
line when --mcp-address was set — so the live `micro run` experience hid the
harness's signature feature even though it was running, and didn't match the
README. Always advertise MCP Tools on the gateway address; keep the optional
standalone MCP-protocol server (--mcp-address) as a clearly separate line.
No behavior change — banner output only.

Co-authored-by: Claude <noreply@anthropic.com>
2026-06-30 11:21:26 +01:00
Asim Aslam c4e110c77f Add deploy dry-run harness checkpoint (#3384)
Co-authored-by: Codex <codex@openai.com>
2026-06-29 22:14:28 +01:00
Asim Aslam 3540bf5a50 Add CLI inspect command for run history (#3313)
Co-authored-by: Codex <codex@openai.com>
2026-06-29 00:57:40 +01:00
Asim Aslam f7a3e8461e test deploy inner-loop contract (#3287)
Co-authored-by: Codex <codex@openai.com>
2026-06-28 21:07:20 +01:00
Asim Aslam 22b3b9ca22 Add zero-to-hero CI reference scenario (#3252)
Co-authored-by: Codex <codex@openai.com>
2026-06-28 14:09:17 +01:00
Asim Aslam 28cbf0be7e test: verify scaffolded service run and call contract (#3248)
Co-authored-by: Codex <codex@openai.com>
2026-06-28 13:14:22 +01:00
Asim Aslam 27f5e2be52 Add OpenAI streaming path (#3185)
Co-authored-by: Codex <codex@openai.com>
2026-06-27 20:01:45 +01:00
Asim Aslam c5c08e24d8 test: cover micro new no-mcp contract (#3160)
Co-authored-by: Codex <codex@openai.com>
2026-06-27 12:17:19 +01:00
Asim Aslam 467c937873 Improve flow run history validation (#3148)
Co-authored-by: Codex <codex@openai.com>
2026-06-27 04:55:49 +01:00
Asim Aslam c9e045961d Add flow run stage filtering (#3144)
Co-authored-by: Codex <codex@openai.com>
2026-06-27 02:28:39 +01:00
Asim Aslam 87eb5ce665 Add filters for flow run history (#3140)
Co-authored-by: Codex <codex@openai.com>
2026-06-27 00:00:58 +01:00
Asim Aslam cefc9438c4 Add JSON output for AI provider capabilities (#3126)
Co-authored-by: Codex <codex@openai.com>
2026-06-26 17:31:18 +01:00
Asim Aslam ae91863343 Add trace filter for agent runs (#3114)
Co-authored-by: Codex <codex@openai.com>
2026-06-26 10:50:49 +01:00
Asim Aslam d7a74735c8 Add AI provider capability command (#3104)
Co-authored-by: Codex <codex@openai.com>
2026-06-26 04:55:16 +01:00