Files
accounted/.github/workflows/swedish-compliance-diff.yml
T
Jakob Wennberg ec27228a8e style: remove em/en dashes repo-wide, add CLAUDE.md rule against them (#890)
Em dashes (—) and en dashes (–) had spread across comments, docs, tests,
and a few UI strings, reading as AI-generated boilerplate rather than
house style. Replaced each with punctuation matching its context: colon
for explanatory clauses, comma for asides, plain hyphen for numeric/legal
ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for
paired-dash asides. messages/en.json and messages/sv.json were fixed by
hand together to keep sv/en in sync.

Left untouched where the dash is the functional subject rather than
decorative punctuation: date-range-parser.ts's separator regex,
charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE
encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the
agent system-prompt files that already instruct against em dashes, and
a golden iXBRL test fixture compared byte-for-byte.

Also fixes two bugs surfaced along the way: an off-by-one in
ApiKeysPanel's scope-label split (a leftover from an earlier partial
pass), and a charset-repair test that had lost the literal en-dash it
exists to verify.

Regenerated the agent atom seed migration (skills:generate) since 27
SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes,
with an explicit carve-out for the functional-dash cases above.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 15:58:06 +02:00

52 lines
2.0 KiB
YAML

name: Compliance diff
# Stage 1 of the fork-safe compliance review (see swedish-compliance-review.yml).
#
# This runs on the untrusted PR head, but is SAFE because it has NO secrets and
# only a read-only token: it computes the diff and uploads it as an artifact.
# It never runs project code (no `npm install`, no `node`): only git plumbing,
# which does not execute repository hooks. The privileged half (model call +
# comment) lives in stage 2, which never checks out fork code.
on:
pull_request:
types: [opened, synchronize, reopened]
permissions:
contents: read
jobs:
prepare:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
ref: ${{ github.event.pull_request.head.sha }}
fetch-depth: 0
- name: Compute diff vs base
# Pass GitHub context via env, never interpolate ${{ }} into the shell
# body: expression substitution happens before bash parses the script,
# so a value with shell metacharacters would be a code-execution sink.
env:
BASE_REF: ${{ github.base_ref }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
# Full fetch (not --depth=1): the PR branch may be behind base, and a
# shallow base can leave merge-base with no reachable common ancestor.
# checkout above uses fetch-depth: 0, so HEAD already has full history.
git fetch origin "$BASE_REF"
MERGE_BASE=$(git merge-base "origin/$BASE_REF" HEAD)
git diff "$MERGE_BASE" HEAD > diff.patch
git diff --name-only "$MERGE_BASE" HEAD > files.txt
printf '%s\n' "$PR_NUMBER" > pr-number.txt
- name: Upload diff artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: compliance-input
path: |
diff.patch
files.txt
pr-number.txt
retention-days: 1