docs: gate consolidation audit — evidence-based proposal for the 78-gate maze - #2525
Conversation
Eight-family investigation of the repo's 78 check:* gates, 284 npm scripts, and 23 workflows, synthesized into a ranked consolidation proposal. Stage 4 adversarial review (red team, blue team, verification-router) still running; their findings will be appended in a follow-up commit before this is pushed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
Appends the red team, blue team, and verification-router responses verbatim, with inline correction notes where they overturned or qualified a Tier 2/3 finding (notably: C3 is withdrawn and reclassified load-bearing, and G2's "orphaned" claim was wrong — check:client-bundle-secrets already runs via the build:internal chain). Regenerates data/repo-awareness-snapshot.json to reflect the new doc, per check:repo-awareness-snapshot's own fix instruction. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Team Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_9d815e50-37d8-4340-b82a-edb1033d182d) |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Resolves the generated-file conflict in data/repo-awareness-snapshot.json by regenerating it with npm run snapshot:repo-awareness against the merged tree, rather than hand-resolving. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_95eba532-f76b-41bf-926d-ac8226a543b5) |
Second sync: main advanced again (PR #2539) touching the same generated data/repo-awareness-snapshot.json. Regenerated with npm run snapshot:repo-awareness against the merged tree rather than hand-resolving the conflict. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
Resolves the generated-file conflict in data/repo-awareness-snapshot.json by regenerating it with npm run snapshot:repo-awareness against the merged tree, rather than hand-resolving. Also brings in PR #2530, which fixes the root cause of this repeated conflict (the two generated snapshots colliding on every concurrent PR). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_bd016fc1-f1be-48a8-a5f2-7290d3a19b89) |
|
CI:
This PR's diff is Generated by Claude Code |
# Conflicts: # data/repo-awareness-snapshot.json
# Conflicts: # data/repo-awareness-snapshot.json
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_240ec3f0-a58f-44fd-a0e5-02b81c5739ed) |
|
"Production UI (1)" failed on Failing test:
No existing record of this failure in Generated by Claude Code |
# Conflicts: # data/repo-awareness-snapshot.json
Summary
docs/audit/gate-consolidation-audit-2026-09-02.md— a proposal-only audit of thisrepo's 78
check:*npm scripts, 284 npm scripts total, and 23 GitHub Actions workflows,investigating gate-by-gate whether each is load-bearing or routine, and where consolidation
is plausible.
explicitly as a limitation), a full CI routing map, eight parallel family investigations
(static/consistency, lint/type, unit/coverage, browser/Playwright, database/migration,
RAG/clinical, docs/workflow, security/secrets), a synthesis ranking findings by confidence,
and a Stage 4 adversarial pass (red team, blue team, and
verification-router, each seeingonly the synthesis, not the underlying reasoning) whose full verbatim responses are appended —
including two real corrections to the synthesis's own claims (one Tier 2 proposal was
factually wrong and is withdrawn/reclassified load-bearing; one "gap" finding turned out to
already be covered via an indirect script chain).
data/repo-awareness-snapshot.jsonto reflect the new document, percheck:repo-awareness-snapshot's own fix instruction.origin/mainin to pick up PR Correct the Ward Flow pinned-clock record and defend the fix at screen level #2522, which touched the same generated snapshot file;resolved by regenerating with
npm run snapshot:repo-awarenessagainst the merged treerather than hand-resolving the conflict.
package.jsonscript, no GitHub Actions workflow, and no checkscript is touched — every recommendation in the document is for a human to read and decide on.
Verification
npm run verify:pr-local— full green before the merge (19/19 gates completed, 0 failed);re-run after merging
origin/mainto confirm the merged tree is still clean.npm run verify:ui— not applicable, no UI/routing/styling changed.npm run verify:release— not applicable, no release/handoff claim.eval:retrieval:quality/eval:rag/eval:quality— not applicable, no retrieval,ranking, or answer-generation code changed (this PR is a Markdown document only).
check:production-readiness/check:deployment-readiness— not applicable, no clinicalworkflow, privacy, environment, Supabase, source-governance, or deployment behavior changed.
Risk and rollout
bot classifies this as clinical-risk purely because it touches a path under
data/(theregenerated
data/repo-awareness-snapshot.json, a route/doc-count inventory with no clinicalcontent) — the classifier is deliberately broad on that path since PR perf: reduce Therapy startup and sidebar layout work #1489 once shipped a
mislabeled therapy record without tripping it; this PR carries no clinical dataset content.
changes none of them).
Clinical Governance Preflight
Triggered only by the
data/path match on the regenerated snapshot file described above(a route/doc-count inventory, not clinical content). None of these items are substantively
affected — checked as true for this PR:
Clinical KB Database(sjrfecxgysukkwxsowpy)Notes
"never touch" list, and the Stage 4 adversarial responses are meant to be read together —
several findings were contested or corrected between stages, and that disagreement is
preserved rather than resolved in the document's favor.
document's recommendations (script merges, CI routing changes, doc updates) would be separate,
reviewed work.
🤖 Generated with Claude Code
https://claude.ai/code/session_01FDiC2BK8XcPbstaJf7So2x
Note
Low Risk
Documentation and generated snapshot only; no runtime, CI, or gate behavior changes. Snapshot under
data/may trigger policy checks but carries no clinical data.Overview
Adds
docs/audit/gate-consolidation-audit-2026-09-02.md, a proposal-only audit of the repo’s ~78check:*scripts, npm/CI routing, and where consolidation might be safe. It ranks gaps and overlaps (e.g.verify:pr-localvsverify:cheap), names a never-touch set (RAG, drift, tenancy), and appends Stage 4 red/blue/verification-router reviews with inline corrections (e.g. client-bundle-secrets already runs viabuild:internal; C3 withdrawn).No gates, workflows, or
package.jsonscripts change — recommendations are for humans only.Regenerates
data/repo-awareness-snapshot.jsonso it lists the new audit doc, updates doc counts, refreshescaptured_revision, and picks up merged ledger entries (including caring-contacts review rows). That path can trip broad clinical-risk PR policy despite non-clinical inventory content.Reviewed by Cursor Bugbot for commit cdfb3fd. Configure here.