git-workflow-and-versioning-8afafe — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited git-workflow-and-versioning-8afafe (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Git is your safety net. Treat commits as save points, branches as sandboxes, and history as documentation. With AI agents generating code at high speed, disciplined version control is the mechanism that keeps changes manageable, reviewable, and reversible.
Always. Every code change flows through git.
Keep main always deployable. Work in short-lived feature branches that merge back within 1-3 days. Long-lived development branches are hidden costs — they diverge, create merge conflicts, and delay integration. DORA research consistently shows trunk-based development correlates with high-performing engineering teams.
main ──●──●──●──●──●──●──●──●──●── (always deployable)
╲ ╱ ╲ ╱
●──●─╱ ●──╱ ← short-lived feature branches (1-3 days)This is the recommended default. Teams using gitflow or long-lived branches can adapt the principles (atomic commits, small changes, descriptive messages) to their branching model — the commit discipline matters more than the specific branching strategy.
Each successful increment gets its own commit. Don't accumulate large uncommitted changes.
Work pattern:
Implement slice → Test → Verify → Commit → Next slice
Not this:
Implement everything → Hope it works → Giant commitCommits are save points. If the next change breaks something, you can revert to the last known-good state instantly.
Each commit does one logical thing:
# Good: Each commit is self-contained
git log --oneline
a1b2c3d Add task creation endpoint with validation
d4e5f6g Add task creation form component
h7i8j9k Connect form to API and add loading state
m1n2o3p Add task creation tests (unit + integration)
# Bad: Everything mixed together
git log --oneline
x1y2z3a Add task feature, fix sidebar, update deps, refactor utilsCommit messages explain the why, not just the what:
# Good: Explains intent
feat: add email validation to registration endpoint
Prevents invalid email formats from reaching the database.
Uses Zod schema validation at the route handler level,
consistent with existing validation patterns in auth.ts.
# Bad: Describes what's obvious from the diff
update auth.tsFormat:
<type>: <short description>
<optional body explaining why, not what>Types:
feat — New featurefix — Bug fixrefactor — Code change that neither fixes a bug nor adds a featuretest — Adding or updating testsdocs — Documentation onlychore — Tooling, dependencies, configDon't combine formatting changes with behavior changes. Don't combine refactors with features. Each type of change should be a separate commit — and ideally a separate PR:
# Good: Separate concerns
git commit -m "refactor: extract validation logic to shared utility"
git commit -m "feat: add phone number validation to registration"
# Bad: Mixed concerns
git commit -m "refactor validation and add phone number field"Separate refactoring from feature work. A refactoring change and a feature change are two different changes — submit them separately. This makes each change easier to review, revert, and understand in history. Small cleanups (renaming a variable) can be included in a feature commit at reviewer discretion.
Target ~100 lines per commit/PR. Changes over ~1000 lines should be split. See the splitting strategies in code-review-and-quality for how to break down large changes.
~100 lines → Easy to review, easy to revert
~300 lines → Acceptable for a single logical change
~1000 lines → Split into smaller changesmain (always deployable)
│
├── feature/task-creation ← One feature per branch
├── feature/user-settings ← Parallel work
└── fix/duplicate-tasks ← Bug fixesmain (or the team's default branch)feature/<short-description> → feature/task-creation
fix/<short-description> → fix/duplicate-tasks
chore/<short-description> → chore/update-deps
refactor/<short-description> → refactor/auth-moduleFor parallel AI agent work, use git worktrees to run multiple branches simultaneously:
# Create a worktree for a feature branch
git worktree add ../project-feature-a feature/task-creation
git worktree add ../project-feature-b feature/user-settings
# Each worktree is a separate directory with its own branch
# Agents can work in parallel without interfering
ls ../
project/ ← main branch
project-feature-a/ ← task-creation branch
project-feature-b/ ← user-settings branch
# When done, merge and clean up
git worktree remove ../project-feature-aBenefits:
For this repo, conform to GitHub's branch/PR model:
../wf-<slug>worktree, and one PR or draft PR when pushed.
STATUS.md is the claim and collision surface. GitHub is the durablebranch, commit, review, and merge surface.
exists, whether it is live-safe, what blocks it, what ideas are parked in it, who owns it, or whether it should merge, split, be abandoned, or become a PR. _PURPOSE.md, .agents/worktrees.md, STATUS.md, idea files, and draft PR bodies are the memory layer.
STATUS.md row with exact Files /Depends / Status, a branch, local worktree path, and _PURPOSE.md.
_PURPOSE.mdrecords ship/abandon condition, blockers, review gates, memory refs, related implications, and pickup hints.
ideas/INBOX.md, ideas/PIPELINE.md, orbottom "Idea feed refs"; not build authority until promoted into STATUS.md and checked against PLAN.md.
.agents/worktrees.md; useful ideas extracted first.
_PURPOSE.md at its root. See AGENTS.md§"GitHub-Aligned Worktree Discipline" for the canonical 12-field template.
.agents/worktrees.md.python scripts/worktree_status.py at session start to see active lanes,parked drafts, dirty current checkouts, missing/incomplete _PURPOSE.md, orphaned/missing paths, and PR/STATUS promotion gaps.
python scripts/provider_context_feed.py --provider <provider> --phase <claim|plan|build|review|foldback|memory-write>at every lifecycle checkpoint where work narrows or advances. This catches Claude/Codex/Cursor/shared memories, loose ideas, research artifacts, provider automation notes, and worktree handoffs that should feed the lane. Phase filters are coarse triage; use --limit 10 for compact hook-like output and a larger limit when auditing whether a category is absent.
_PURPOSE.md,.agents/worktrees.md, the STATUS row, and the PR body before coding. If none are listed, search .claude/agent-memory/, .agents/activity.log, recent audit artifacts, and branch/PR notes by task slug.
fold-back. Relevant PLAN.md modules are the project/module understanding and must be reviewed for the lane. Related STATUS.md lanes, ideas/PIPELINE.md rows, research artifacts, design notes, or memory refs stay live context until the PR folds back or the lane is explicitly rejected/deferred. ideas/INBOX.md captures are only idea-feed reminders; carry them at the bottom of the lane when useful, but do not treat them as design truth or build authorization.
pending with Depends naming the review artifact/verdict; do not advance runtime implementation, push, live rollout, or acceptance-test claims until review returns approve or adapt.
merged to main; merging to main affects the live MCP/backend deploy chain and requires the right gates. Do not switch a dirty checkout to main. Start a clean session/worktree from main for new live-ready work. Leaving a branch parked is safe only when it has durable lane metadata.
Legacy planning docs (ideas/PIPELINE.md, docs/vetted-specs.md, docs/exec-plans/active/*, old audits, and agent memories) are context, not build queues. Before building from them, refactor the item into current project state: re-check relevant PLAN.md modules, STATUS.md, ideas/PIPELINE.md, recent commits, active review gates, prior-provider memories, related implication lanes, and the provider-context feed for the current phase; then add/update a STATUS row with exact Files, Depends, branch, worktree, PR expectation, PLAN module refs, memory refs, and related implication refs. If there are relevant ideas/INBOX.md captures, park them at the bottom of the lane as Idea feed refs.
Agent starts work
│
├── Makes a change
│ ├── Test passes? → Commit → Continue
│ └── Test fails? → Revert to last commit → Investigate
│
├── Makes another change
│ ├── Test passes? → Commit → Continue
│ └── Test fails? → Revert to last commit → Investigate
│
└── Feature complete → All commits form a clean historyThis pattern means you never lose more than one increment of work. If an agent goes off the rails, git reset --hard HEAD takes you back to the last successful state.
After any modification, provide a structured summary. This makes review easier, documents scope discipline, and surfaces unintended changes:
CHANGES MADE:
- src/routes/tasks.ts: Added validation middleware to POST endpoint
- src/lib/validation.ts: Added TaskCreateSchema using Zod
THINGS I DIDN'T TOUCH (intentionally):
- src/routes/auth.ts: Has similar validation gap but out of scope
- src/middleware/error.ts: Error format could be improved (separate task)
POTENTIAL CONCERNS:
- The Zod schema is strict — rejects extra fields. Confirm this is desired.
- Added zod as a dependency (72KB gzipped) — already in package.jsonThis pattern catches wrong assumptions early and gives reviewers a clear map of the change. The "DIDN'T TOUCH" section is especially important — it shows you exercised scope discipline and didn't go on an unsolicited renovation.
Before every commit:
# 1. Check what you're about to commit
git diff --staged
# 2. Ensure no secrets
git diff --staged | grep -i "password\|secret\|api_key\|token"
# 3. Run tests
npm test
# 4. Run linting
npm run lint
# 5. Run type checking
npx tsc --noEmitAutomate this with git hooks:
// package.json (using lint-staged + husky)
{
"lint-staged": {
"*.{ts,tsx}": ["eslint --fix", "prettier --write"],
"*.{json,md}": ["prettier --write"]
}
}package-lock.json, Prisma migrations)dist/, .next/), environment files (.env), or IDE config (.vscode/settings.json unless shared)node_modules/, dist/, .env, .env.local, *.pem# Find which commit introduced a bug
git bisect start
git bisect bad HEAD
git bisect good <known-good-commit>
# Git checkouts midpoints; run your test at each to narrow down
# View what changed recently
git log --oneline -20
git diff HEAD~5..HEAD -- src/
# Find who last changed a specific line
git blame src/services/task.ts
# Search commit messages for a keyword
git log --grep="validation" --oneline| Rationalization | Reality |
|---|---|
| "I'll commit when the feature is done" | One giant commit is impossible to review, debug, or revert. Commit each slice. |
| "The message doesn't matter" | Messages are documentation. Future you (and future agents) will need to understand what changed and why. |
| "I'll squash it all later" | Squashing destroys the development narrative. Prefer clean incremental commits from the start. |
| "Branches add overhead" | Short-lived branches are free and prevent conflicting work from colliding. Long-lived branches are the problem — merge within 1-3 days. |
| "I'll split this change later" | Large changes are harder to review, riskier to deploy, and harder to revert. Split before submitting, not after. |
| "I don't need a .gitignore" | Until .env with production secrets gets committed. Set it up immediately. |
.gitignore in the projectnode_modules/, .env, or build artifactsFor every commit:
.gitignore covers standard exclusions~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.