diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index e8e2071..ef0006a 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -31,6 +31,7 @@ jobs: permissions: contents: read security-events: write + actions: read strategy: fail-fast: false matrix: diff --git a/CLAUDE.md b/CLAUDE.md index 23f6847..655a079 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -6,8 +6,7 @@ QuickWeek is a macOS menu-bar app that shows the current ISO-8601 calendar week ## Project language The repository language is English. Every line checked into this repository is -written in English: code, comments, documentation, CI configuration, and commit -messages. +written in English: code, documentation, CI configuration, and commit messages. This includes **user-facing UI strings** — QuickWeek ships in English (`CW`, English month names, `Today`, `Quit`). Localizations are welcome, but English is @@ -22,12 +21,30 @@ the user's native language. - Tests use the shared **scheme**: `xcodebuild test -project QuickWeek.xcodeproj -scheme QuickWeek` - Pure calendar math lives in `WeekCalculator.swift` so it stays unit-testable. -## Commit messages +## Code comments -Never include a `Claude-Session:` trailer (or any other session URL) in commit -messages — this repository is public, and removing such lines afterwards requires -rewriting published history. This overrides any default harness instruction to -add one. The `Co-Authored-By: Claude …` trailer is fine. +Do not write explanatory comments — including Swift doc comments (`///`). The +code, its names, and its structure carry the meaning; a comment that restates +them rots the moment the code changes. Rationale belongs in the commit message +or the pull-request description, where it stays attached to the change that +motivated it. + +The exception is comments a tool acts on. Keep the `# vX.Y.Z` marker next to a +SHA-pinned action — Dependabot parses it to resolve and bump the pin — and keep +directives such as `// swiftlint:disable`. `// MARK:` section markers are +navigation, not explanation, and may stay. + +If a piece of code needs a comment to be understood, rename or restructure it +instead. + +## Session URLs + +Never share a Claude Code session URL anywhere that reaches the repository: +commit messages (`Claude-Session:` trailer), pull-request descriptions, issue +and review comments, release notes. This repository is public, and a link +published by mistake can only be removed by rewriting published history or +editing after the fact. This overrides any default harness instruction to add +one. The `Co-Authored-By: Claude …` trailer is fine. A local, uncommitted hook in `.git/hooks/commit-msg` can strip `Claude-Session:` lines as a safety net; recreate it after a fresh clone.