refactor: delete dead prompt rename, config helpers, and CI scripts orphaned by #1131 - #1175
Merged
Merged
Conversation
…ate template resolver renamePromptId, renameConcreteNodeId and rewriteArtifactPathForPromptId (rename.ts), their render.ts helpers (renamePromptArtifactReferences and three private rewriters) and the frontmatter round-trip support they needed (serializePromptDocument, diffPromptIdentity, the allowUnknownFields option, unknownFrontmatter/rawFrontmatter and the invalid-rename error code) had no caller outside their own tests. getPrompt had no caller at all. TemplateOccurrence.rawName existed only so rename could preserve whitespace. Output-contract templates had their own three-candidate resolver whose middle candidate, dist/prompts, is the layout the build stopped producing in #796. They now resolve through builtInPromptRoot(), the packaged-first lookup the agent preamble templates already use, so both kinds of prompt asset follow one rule. The packaged-layout render test, which copies the real dist below a directory with no repository above it, still covers the sealed-snapshot case; the installed-layout test that rebuilt the old dist/prompts layout is removed and its content assertions are folded into the packaged-layout test. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…o production caller
- The prompt-metadata layer: resolveConfig applied
createDefaultPromptMetadataLayer(), which always returned {}, and an
input.promptMetadata that only one test supplied. PromptMetadataLayer,
ResolveConfigInput.promptMetadata and the "prompt-metadata" diagnostic
source go with it.
- restoreRedactedConfig and assertNoRedactionPlaceholders: nothing in
runtime, cli, modal or evals calls them. Runs launch from the unredacted
resolved config; the redacted copy and its manifest are written for
readers of the run directory, and no command restores values from them.
docs/config.md no longer describes a restore step or launch guard that
does not exist. The "redaction" diagnostic source goes with them.
- applyDefaultProfileOverrides: a one-line wrapper only tests called.
Its test now drives applyModelProfileOverrides, which validate.ts and
plan-run.ts use.
- assertResolvedConfigZod and resolvedConfigSchemaEntry: no callers.
- resolvedConfigValidatorsAgree: moved into the schema test, its only
user.
redactResolvedConfig and serializeRedactedResolvedConfigToml, which
plan-run.ts and init.ts use, are unchanged.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
#1131 deleted eval-benchmarks.yml, the only workflow that invoked scripts/ci/modal-benchmark-control-window.mjs (create/deadline) and scripts/ci/validate-threat-model-benchmark-gate.mjs. Since then the control-window script was kept alive only by a knip entry and a block of ci-config.test.ts that exercised it, and the threat-model gate only by its own test, which still ran in every PR's test:ci-scripts step. Delete both scripts, the gate's test, the knip entry, and the control-window block of the EVMBench full-mode manifest test; the manifest assertions around it stay. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…rs into tests Deleted, no reference anywhere: MAX_MODAL_DOCUMENT_BYTES, MODAL_SMOKE_STOP_PATH (smoke-worker.ts builds its own stop path) and DEFAULT_NODE_TIMEOUT_SECONDS. Deleted with the tests that only exercised them: - createTrackedSourceArchive; production archives the exact candidate with createExactCandidateSourceArchive. - persistentWorkspaceRoot. - locateModalResumeWorkspace, documented as "retained for tests"; worker.ts uses findModalResumeWorkspace, and the removed "locates one exact linked durable run" test duplicated the existing tolerant-lookup test. The two finalize tests unwrap findModalResumeWorkspace through a local helper. Moved into tests, their only users: - DEFAULT_BENCHMARK_MODELS, a stale model list no production code reads, is now test/model-spec-fixtures.ts, typed as a const tuple so indexed fixtures need no non-null assertion. - modalBenchmarkConfigValidatorsAgree, WORKER_RESULT_ALLOWED_KEYS (the test now states the expected persisted key set), and publicEvalFailureDiagnosticLogPayload, which composed the same two calls runCommand already makes inline. - PUBLIC_BENCHMARK_MAX_PARALLEL_EVAL_ROWS and its full-lane twin, aliases of the evals lane limits that only a test imported. Un-exported, used only inside their own module: five public-worker constants and WORKER_STDERR_TAIL_BYTES. The source-constant reader in prepare-eval-history-publication.mjs matches top-level const declarations with or without export, and its test against the real public-worker.ts still passes. Co-Authored-By: Claude Opus 5.5 <[email protected]>
commandCapabilities() returned restartWholeRun, doctor, triage, merge, restartFromNode, rerunSelectedNode and arbitraryShell as the constant false. The frontend only declared them in its CommandCapabilities type: capabilityForCommand never maps a command to any of them, so nothing read them. Remove them from the server, the dashboard HTTP schema's commandCapabilities definition, and the frontend type. The schema edit is required because that definition is closed (required plus additionalProperties: false). The dashboard schema feeds neither the validator build identity, which hashes only the artifacts validator modules and the ajv versions, nor the artifact schema bundle digest that planned outputs and the trusted CLI identity bind to. The flow test's two assertions that doctor and merge are false are removed. Every dashboard HTTP response in the tests is still validated against the schema, so a server that emitted one of these keys again would fail the flow test with "must NOT have additional properties" (checked by re-adding doctor: false to the compiled server). Co-Authored-By: Claude Opus 5.5 <[email protected]>
packages/runtime/package.json calls scripts/run-tests.mjs with no selector or with "supporting"; nothing passes "materialize", "clean" or "smithers". A single test file can still be selected by name through the existing fallback. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
getPrompt still has no caller, but #1164 adds projectPromptsDifferingFromBuiltIns directly above it in catalog.ts, so deleting it here made the two PRs conflict textually (git merge-tree reported CONFLICT (content) in catalog.ts). catalog.ts is outside this change's files, so restore it to origin/main and leave the deletion for a follow-up once #1164 lands. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…idence Drop getPrompt, which this change no longer deletes. Name the actual callers of the two CI scripts (eval-benchmarks.yml and the watch-modal-benchmark.sh it ran, both deleted in #1131) instead of "the workflows #1131 deleted": the other two workflows #1131 removed never invoked either script. Stop describing the config prompt-metadata layer as code no production path calls: resolveConfig ran it on every resolution, only ever with an empty layer. Mention the run-tests.mjs selectors and the docs/config.md change, and add the [runtime] and [docs] tags for them. Co-Authored-By: Claude Opus 5.5 <[email protected]>
aviggiano
added a commit
that referenced
this pull request
Sep 29, 2026
…vers Move projectPromptsDifferingFromBuiltIns below builtInPromptRelativePaths so it no longer sits in the hunk where #1175 deletes getPrompt; with that placement the two branches merge without a conflict in catalog.ts. No behaviour change. The anchor test comment claimed a prompt and its topology "cannot drift apart again". The test checks only nodes whose built-in prompt promises an extended timeout (triage and severity-classification) in the packaged topologies, so say that, and that dedupe-findings is not covered. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This was referenced Sep 29, 2026
Merged
Every pull request in this batch inserts its entry at the same place in CHANGELOG.md, so each merge would conflict with the next. The entries are collected into one changelog update instead. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This was referenced Sep 29, 2026
aviggiano
added a commit
that referenced
this pull request
Sep 29, 2026
…/gate contradictions (#1164) * fix(topology): restore the review group time budget The triage and severity-classification prompts tell the agent that "the topology gives this review node an extended timeout", but no shipped topology did. The review group lost its pin in v0.0.2, so dedupe, triage, severity classification, test aggregation and the final report ran on run.default_timeout_seconds (3600) while every goal, strategy and specialist lane had 7200. The review chain is the widest fan-in, so a review stage that needs more than the default window times out deterministically and is retried with the same window; the review group halts on failure, so every later review stage and the final-report node are then skipped (#1150). Pin the review group in the four non-smoke topologies to the same 7200 seconds as the goal, strategy and specialist groups. smoke.yml has no triage or severity node and is left alone. Like the existing group pins, this one takes precedence over run.default_timeout_seconds and model-profile timeouts (#675). The new packaged-topology test expands every shipped topology and holds each node whose prompt promises an extended timeout to a window above the largest shipped default. It fails on the previous topologies with "default.yml node `triage` promises an extended timeout but resolves to ultrafuzz.toml `run.default_timeout_seconds`=3600". Co-Authored-By: Claude Opus 5.5 <[email protected]> * chore(topology): drop the unused timeout on pinned reference nodes Every property reference node in the four non-smoke topologies set timeout_seconds: 300 (36 lines). Reference nodes are materialized by plan-run before launch and compileSmithersWorkflow only compiles agentic nodes into Smithers tasks, so the value never bounded anything. It was only copied into the expanded graph fingerprint and the planned graph, and displayed by the dashboard. The vulnerability-database reference node already had no timeout. Existing project topologies that still carry the lines keep validating; the reference docs now say the field has no effect on reference nodes. Co-Authored-By: Claude Opus 5.5 <[email protected]> * fix(prompts): stop inviting production interface edits the handoff rejects The stateful-invariant setup and implement-properties prompts told the agent not to edit production src/ or contracts/ "except for interfaces if they are genuinely required by the harness". Both nodes publish a workspace patch, and captureWorkspacePatch rejects every change under the configured production source roots (src and contracts by default), added files included: source-snapshot violation: workspace patch modifies protected production source: src/interfaces/IVault.sol So with the default roots, following the exception failed the handoff, and a retry starts a fresh session from the same prompt. Remove the exception and tell the agent to declare harness interfaces in the test tree, which the same capture accepts. Co-Authored-By: Claude Opus 5.5 <[email protected]> * fix(runtime): warn at validate time when a project prompt differs from its built-in Runs use the project copy of every prompt, and ultrafuzz init without --force keeps an existing copy. After an upgrade a scaffolded copy therefore keeps an older release's text while the artifact gates move on, and nothing said so until a node failed its gate at the end of an attempt. projectPromptsDifferingFromBuiltIns lists the project prompts whose bytes differ from the built-in prompt at the same path. validate reports each one as a PROMPT_DIFFERS_FROM_BUILT_IN warning, which sets the prompts posture to warn without failing validation, planning or the dashboard's prompt save. A freshly scaffolded project and prompts the project adds at new paths produce no warning. The new runtime test fails on the previous validate.ts (prompts posture 'pass' where 'warn' is expected) and also checks the remedy the warning names: deleting the copy and rerunning init restores a passing posture. Co-Authored-By: Claude Opus 5.5 <[email protected]> * docs: changelog for the review timeout and prompt/gate fixes Co-Authored-By: Claude Opus 5.5 <[email protected]> * fix(prompts): tell Vyper setup agents to declare interfaces in the test tree The setup-foundry and base-test-setup prompts ask for Solidity interfaces to the Vyper contracts' ABI but never say where to put them. Both nodes publish a workspace patch, and captureWorkspacePatch rejects any change under the production source roots (src and contracts by default), so an interface written under contracts/interfaces/ fails the setup handoff, and the setup group halts the run on failure. Say to declare new interfaces in the test tree, as the stateful-invariant prompts now do. Whether agents actually chose a production location here was not observed; this closes the same gap the invariant prompts had. Co-Authored-By: Claude Opus 5.5 <[email protected]> * fix(runtime): doctor no longer summarizes a validation with warnings as a pass doctor reported the validate check as `warning` but kept the summary "config, topology, prompts, paths, agents, and trust posture pass". Now that validate warns about project prompts that differ from their built-in, every upgraded project with such a copy would see that contradiction. The summary now says validation passed with warnings and points to `ultrafuzz validate --json`, since text-mode output does not print warnings. The new test fails on the previous doctor.ts with actual 'config, topology, prompts, paths, agents, and trust posture pass'. Co-Authored-By: Claude Opus 5.5 <[email protected]> * chore: move the prompt drift helper and state what the anchor test covers Move projectPromptsDifferingFromBuiltIns below builtInPromptRelativePaths so it no longer sits in the hunk where #1175 deletes getPrompt; with that placement the two branches merge without a conflict in catalog.ts. No behaviour change. The anchor test comment claimed a prompt and its topology "cannot drift apart again". The test checks only nodes whose built-in prompt promises an extended timeout (triage and severity-classification) in the packaged topologies, so say that, and that dedupe-findings is not covered. Co-Authored-By: Claude Opus 5.5 <[email protected]> * docs: record the review pin's precedence break and the topology refresh A group pin takes precedence over run.default_timeout_seconds and model-profile timeout_seconds (#675), so a project that raised either above 7200 now gets 7200 on review nodes of the packaged exhaustive and invariant-only topologies and of new scaffolds, and a cloud config whose explicit global resource timeout is below 7200 needs per-node overrides for the review nodes as well. Record that under Breaking changes with the escape hatch. Tighten the Other changes entry: name the three pinned topologies instead of "the shipped topologies" (smoke stays unpinned), and give the one-command refresh for an uncustomized project topology, which init keeps. The how-to now says the same about the topology as it already did about prompts. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Several features and helpers have no production caller but are still built, exported, documented and tested:
rename.ts,renamePromptArtifactReferences,diffPromptIdentity,serializePromptDocument). Output-contract templates also had a second asset resolver that still probeddist/prompts, a layout the build stopped producing in fix(prompts): build bundled assets into the directory the resolver reads #796.restoreRedactedConfig,assertNoRedactionPlaceholders,applyDefaultProfileOverrides,assertResolvedConfigZodandresolvedConfigSchemaEntry. The prompt-metadata layer did run:resolveConfigapplied it on every resolution. ButcreateDefaultPromptMetadataLayer()always returned{}, and only one test passedpromptMetadata, so in production it only ever applied an empty layer.docs/config.mddescribed a restore step and a placeholder launch guard, and no code runs either one.scripts/ci/validate-threat-model-benchmark-gate.mjsandscripts/ci/modal-benchmark-control-window.mjswereeval-benchmarks.ymland thewatch-modal-benchmark.shit ran. Remove paid benchmark CI and repair CI gates #1131 deleted both. The gate's 333-line test still ran in every PR'stest:ci-scriptsstep. The control-window script stayed alive only through a knip entry and aci-config.test.tsblock.commandCapabilities()returned seven flags as the constantfalse(restartWholeRun,doctor,triage,merge,restartFromNode,rerunSelectedNode,arbitraryShell). The frontend only declares them in a type, andcapabilityForCommandnever maps a command to any of them.scripts/run-tests.mjsdefines three selectors (materialize,clean,smithers) that nothing passes.Root cause
These features were removed, or never wired up, but their library code and tests were left behind. CI cannot see this:
pnpm -w knipruns with--include files,dependencies,unlisted,unresolved, so it does not report unused exports. And any file that a test imports still counts as used.Change
One commit per area. Only deletions, apart from the resolver change.
refactor(prompts):allowUnknownFieldsoption,unknownFrontmatter,rawFrontmatter, theinvalid-renamecode andTemplateOccurrence.rawName.builtInPromptRoot(), the packaged-first lookup the agent-preamble templates already use.dist/promptslayout. Its content assertions move into the packaged-layout test, which copies the realdistunder a directory with no repository above it (the sealed-snapshot case).refactor(config):PromptMetadataLayer,ResolveConfigInput.promptMetadataand theprompt-metadatadiagnostic source.restoreRedactedConfigandassertNoRedactionPlaceholders, plus their path helpers and theredactiondiagnostic source.applyDefaultProfileOverrides; its test now drivesapplyModelProfileOverrides, whichvalidate.tsandplan-run.tscall. Also deletesassertResolvedConfigZodandresolvedConfigSchemaEntry.resolvedConfigValidatorsAgreemoves into its only test.docs/config.mdnow states that no command restores values from the redaction manifest.ci: deletes both scripts, the gate's test, theknip.jsoncentry, and the control-window block (~lines 206-297) of the EVMBench full-mode test inpackages/modal/test/ci-config.test.ts. The manifest assertions around that block stay.refactor(modal):MAX_MODAL_DOCUMENT_BYTES,MODAL_SMOKE_STOP_PATH,DEFAULT_NODE_TIMEOUT_SECONDS.createTrackedSourceArchive,persistentWorkspaceRoot, andlocateModalResumeWorkspace. The last one's "locates one exact linked durable run" test duplicated the existing tolerant-lookup test.DEFAULT_BENCHMARK_MODELSbecomestest/model-spec-fixtures.ts, typed as a const tuple.modalBenchmarkConfigValidatorsAgreemoves into its test.WORKER_RESULT_ALLOWED_KEYS: the test now states the expected key set.publicEvalFailureDiagnosticLogPayload: the same two callsrunCommandalready makes inline.PUBLIC_*_MAX_PARALLEL_EVAL_ROWSaliases.public-worker.tsconstants andWORKER_STDERR_TAIL_BYTES; they are used only inside their own modules.refactor(dashboard): drops the seven flags from the server,dashboard-http.schema.jsonand the frontend type. The schema edit is required:commandCapabilitiesis closed (requiredplusadditionalProperties: false).chore(runtime): drops the unusedrun-tests.mjsselectors.CHANGELOG.mdentry.refactor(prompts): leave getPrompt to the catalog work itemrestorespackages/prompts/src/catalog.tstoorigin/main. The earlier revision deletedgetPromptfrom it.docs(changelog)tightens the entry's wording (see Verification).Net: 47 files, +170 / −2164.
Deliberately not built (and why)
getPrompt(packages/prompts/src/catalog.ts) has no caller either. But fix(topology): restore the review group time budget and remove prompt/gate contradictions #1164 addsprojectPromptsDifferingFromBuiltInsdirectly above it, andcatalog.tsis outside this item's files. Deleting it here madegit merge-treereportCONFLICT (content)incatalog.tsagainst fix(topology): restore the review group time budget and remove prompt/gate contradictions #1164, so it is left for a follow-up after fix(topology): restore the review group time budget and remove prompt/gate contradictions #1164 lands.smithers.ts(the__ULTRAFUZZ_RETRY_FAILURE_TEMPLATE__injection) and byworkflow.tsx:1666-1667, a few lines from therenderAgentPromptregion another work item is editing. Deleting only the prompts side would break workflow generation, so it stays.createPublicEvalDiagnosticsis test-only, but it is the pure seam that 23 calls inpublic-eval-diagnostics.test.tsuse to reach the privatecreatePublicEvalDiagnosticsFromRecords. Moving it into tests would mean either exporting the private function or rewriting those tests over file fixtures. Kept.assertCurrentPersistentWorkerLineagestays exported. Un-exporting it touches a line that the strict diff lint rejects for an unrelated reason: it is async with noawait.hasRedactionPlaceholder(security): its only callers were the config helpers deleted here, so it now has none.packages/securitybelongs to another work item, so it is left in place.exportsgate. CI gating belongs to another work item. For reference,pnpm dlx [email protected] --include exports,types,duplicatesreports 40 unused exports onorigin/mainand 33 on this branch, and nothing new. The seven that leave the report are all modal:public-worker.tsconstants andWORKER_STDERR_TAIL_BYTES;publicEvalFailureEnvelopeDiagnostics, is still exported. It leaves the report only because the rewrittenpublic-worker.test.tsnow imports it. Production uses it insidepublic-worker.ts.PromptConcreteNode/PromptGraphNodeRuntimeConfigOverrides.triageQuorum/triagePanelSizescripts/ci/prepare-eval-history-publication.mjs, also orphaned by Remove paid benchmark CI and repair CI gates #1131Verification
Deletions. For every deleted or un-exported symbol, a grep over
packages/,scripts/,docs/and the runtime templates (excludingdist,dist-testandnode_modules) finds no remaining reference, apart from the test-local helpers this PR adds.At
a49a626f^, the parent of #1131, the scripts' only invocations outside tests were:.github/workflows/eval-benchmarks.ymllines 335, 408, 518 and 600 (control-window) and 735 (gate);scripts/ci/watch-modal-benchmark.sh:24(control-window), whicheval-benchmarks.ymlran at lines 426 and 620.#1131 deleted both files. The other two workflows #1131 deleted never invoked either script.
Discriminating evidence. This PR deletes code, and only two behaviours change.
dist/assets/promptsand the source tree) resolve as before. The packaged-layout test covers the sealed-snapshot case and passes. The deleted installed-layout test was the only thing that builtdist/prompts.doctor: falsetocommandCapabilities()in the test build of the server,packages/dashboard/dist-test/src/index.js, which is the file the dashboard test imports.serves logical topology flow with expanded attempt detailsfails with/capabilities additionalProperties: must NOT have additional properties. It passes before the mutation and again after the file is restored. I re-ran this on this revision.dist/index.jsdoes not fail the test, because the test does not import that build.Tests run on
e6c395c1(targeted). The follow-up commits only restorecatalog.tstoorigin/mainand editCHANGELOG.md, so they cannot affect any suite except prompts, which is re-run below.config,layout,resume,runner,worker-result,worker-lineage,workspace-config,public-worker,ci-config,modal-documents,smokeandworker-diagnostics.public-workertests, which exceed their explicit 30 s budget:recognizes and cleans the legacy persistent public workspace…,rejects a present dangling public bundle…andaccepts the bounded full lane….origin/mainworktree on this machine (load average 30-39), so the timeouts are not caused by this PR.config,worker-lineage,workspace-config,worker-result,layoutandresume: 115/115.contracts4/4;frontend-wire-contracts+dashboard34/34.pnpm -w test:ci-scripts: 94 pass, 1 fail.safe-archive-bun.test.ts > repeatedly extracts a synthetic archive without stalling Bun callbacks, a 15 s timeout. It also times out onorigin/mainhere, and this PR does not touchsafe-archive.ts.prepare-eval-history-publication.test.tspasses 17/17. It includestrustedCandidateRuntimePolicyDimensions(process.cwd(), "smoke"), which parses the realpublic-worker.tsafter the un-exports.dynamic-expansion15/15. It materializes dynamic children, which callsrenderPromptand so loads the output-contract templates through the new lookup.prompt-artifact-authority+model-override-validation10/10.Re-run on this revision (
d7704ae7):tsc --noEmit.npx prettier --checkandnpx eslint --max-warnings 0over all 47 changed files.CI=1 ESLINT_PLUGIN_DIFF_COMMIT=origin/main pnpm -w lint:strict:ci,pnpm -w knip,node scripts/docs-check.mjsandnode scripts/prompt-catalog-docs.mjs --check.git merge-tree --write-treeagainst the 25 other open work-item branches. The only conflict isCHANGELOG.md, which every entry touches. Thecatalog.tsconflict with fix(topology): restore the review group time budget and remove prompt/gate contradictions #1164 is gone.Static checks on
e6c395c1:pnpm --filter @ultrafuzz/{prompts,config,dashboard,modal,runtime} typecheck.tsc --noEmitfor topology, references, runtime, evals, evmbench and cli.Not run: the full runtime and CLI suites, CI itself, and any real campaign.
Risk / compatibility
@ultrafuzz/prompts,@ultrafuzz/configand@ultrafuzz/modalare private workspace packages, and no in-repo caller of a removed export remains.parsePromptFrontmatterno longer takes an options argument; unknown frontmatter keys already failed by default, and no caller passedallowUnknownFields.builtInPromptRoot()rethrows non-ENOENTstaterrors, where the old output-contract resolver moved on to its next candidate. Rendering fails either way; only the error message differs.dist. Since fix(prompts): build bundled assets into the directory the resolver reads #796 that containsdist/assets/promptsand nodist/prompts, so dropping that probe matches every current build.packages/modal/test/ci-config.test.ts: this PR's hunk is ~206-297; the ci.yml string assertions (~625-808) are untouched.docs/config.md: only the three-line "Redaction" paragraph changes.CHANGELOG.md: one entry at the top of "Other changes".eslint-suppressions.json, and itspnpm -w lintfails when a suppression no longer matches a violation. Violations this PR deletes therefore make that file stale.eslint.config.js,eslint-suppressions.json,package.jsonand the mergedci-config.test.tson this branch. ESLint over this PR's 38 changed lint targets exited 2 withThere are suppressions left that do not occur anymore. Linting only the mergedci-config.test.tsalso exits 2, while ci: validate every package on PRs, stop cancelling main runs, and add a global complexity ceiling #1184's own copy of that file lints clean against its own baseline.--prune-suppressionsthen removes the threescripts/ci/validate-threat-model-benchmark-gate.mjsentries (complexity,max-lines-per-function,max-statements) and lowerspackages/modal/test/ci-config.test.tsmax-lines-per-functionfrom 2 to 1.pnpm -w lint:pruneand the smaller baseline committed.Refs #462
🤖 Generated with Claude Code
The PR appears safe to merge; no actionable new issue was established.
Summary
This PR removes unused prompt, configuration, Modal, CI, dashboard, and runtime code. Output-contract templates now use the shared packaged-first prompt resolver, and the dashboard contract drops seven always-false capability flags. A follow-up removes this PR’s changelog entry for consolidation elsewhere.
Reviews (3) · Last reviewed commit: "chore: move the changelog entry to the c..."