You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adopt the hub's reusable workflow chain. This is the hub rollout item "ESPHome-NonRoot (docker-prepare hook for the upstream pin)" in the hub's docs/reusable-workflows.md "Stage 4", plus the Stage 2 gates.
Delete the six hub-hosted task files: build-docker-task.yml, build-release-task.yml, check-upstream-version-task.yml, get-version-task.yml, publish-plan-task.yml, and validate-task.yml.
Replace them with caller stubs pinned to a hub release SHA, plus hooks:
docker-prepare, which reads upstream-version.json for the :<esphome> tag and the ESPHOME_VERSION / DEVICE_BUILDER_VERSION build args.
A validate hook carrying the firmware compile-test job.
resolve-upstream for the tracker.
Fold check-upstream-dependency.yml into the hub's check-upstream-version-task.yml with auto-merge: false, per the hub's spec/divergences.json note on that file.
Delete repo-config/ (disposition retire) and sweep its inbound references in WORKFLOW.md.
Add the devcontainers Dependabot ecosystem for both branches.
Done when python3 spec/audit.py --branch <feature-branch> ESPHome-NonRoot shows no hub-only:, interface: or dependabot: finding, and a real publish succeeds after promotion. The publish is the true test, since secrets:, permissions: and hook resolution only resolve in a real run.
Fix Compile Error: "Opus: 'patch' command not found" #279, the image missing a patch utility. ESP-IDF's micro-opus managed component shells out to patch, so a build using it fails in the image. Add the Debian patch package to the Dockerfile's runtime stage, and consider a compile-test fixture that pulls a managed component. Done when the reporter's configuration class compiles in a locally built image.
README structure PR. Bring README.md in line with the hub's spec/readme-structure.md:
Make the tagline link-free.
Add the Table of Contents, Build and Distribution, Questions or Issues and 3rd Party Tools sections.
Delete the retired byob.yarr.is last-build shield.
Rename commit-link to commits-link and docker-link to docker-hub-link, strip the suffix from license-link, and group the reference definitions.
Then set the About panel and the Docker Hub short description from the tagline, which today differ from it by a trailing period.
Promote develop to main once the above land, using merge-and-release with an explicit go-ahead. The first promotion meets an EOL-only conflict on upstream-version.json, because main's tracker still writes CRLF until promotion. Resolve it by taking develop's side.
External Blockers
The stale DOCKER_HUB_PASSWORD secret in both the Actions and Dependabot stores is claimed by no mechanism, since the workflows read DOCKER_HUB_ACCESS_TOKEN. Deleting a secret is the maintainer's call. Ask, and meanwhile leave it alone.
Internal Dependencies
Step 1 before step 4: promoting before the workflow adoption would ship the carried task copies to main, only to delete them in the next promotion.
Worktrees from this round, to remove once their branches are gone: resync/eol-lf and resync/instruction-set in ESPHome-NonRoot, and one detached hub worktree at hub main. Re-derive them with git worktree list.
Repository configuration was applied with the hub's configure.sh apply. check reports Configuration matches.
Audit on develop: 2026-09-26T13:21:36Z | hub 45669468 | branch override develop reports 11 findings, all in the classes named in the next steps.
Do not trust the old AGENTS.md "Devcontainer" claim that the devcontainer's extensions mirror the workspace recommendations. The lists differ, so the claim was dropped rather than carried.
Next Steps, in Priority Order
docker-preparehook for the upstream pin)" in the hub'sdocs/reusable-workflows.md"Stage 4", plus the Stage 2 gates.build-docker-task.yml,build-release-task.yml,check-upstream-version-task.yml,get-version-task.yml,publish-plan-task.yml, andvalidate-task.yml.docker-prepare, which readsupstream-version.jsonfor the:<esphome>tag and theESPHOME_VERSION/DEVICE_BUILDER_VERSIONbuild args.validatehook carrying the firmwarecompile-testjob.resolve-upstreamfor the tracker.check-upstream-dependency.ymlinto the hub'scheck-upstream-version-task.ymlwithauto-merge: false, per the hub'sspec/divergences.jsonnote on that file.repo-config/(dispositionretire) and sweep its inbound references inWORKFLOW.md.devcontainersDependabot ecosystem for both branches.publish-plan-task.ymlconvergence the deletion supersedes.python3 spec/audit.py --branch <feature-branch> ESPHome-NonRootshows nohub-only:,interface:ordependabot:finding, and a real publish succeeds after promotion. The publish is the true test, sincesecrets:,permissions:and hook resolution only resolve in a real run.patchutility. ESP-IDF'smicro-opusmanaged component shells out topatch, so a build using it fails in the image. Add the Debianpatchpackage to the Dockerfile's runtime stage, and consider a compile-test fixture that pulls a managed component. Done when the reporter's configuration class compiles in a locally built image.README.mdin line with the hub'sspec/readme-structure.md:Table of Contents,Build and Distribution,Questions or Issuesand3rd Party Toolssections.last-buildshield.commit-linktocommits-linkanddocker-linktodocker-hub-link, strip the suffix fromlicense-link, and group the reference definitions.developtomainonce the above land, usingmerge-and-releasewith an explicit go-ahead. The first promotion meets an EOL-only conflict onupstream-version.json, becausemain's tracker still writes CRLF until promotion. Resolve it by takingdevelop's side.External Blockers
DOCKER_HUB_PASSWORDsecret in both the Actions and Dependabot stores is claimed by no mechanism, since the workflows readDOCKER_HUB_ACCESS_TOKEN. Deleting a secret is the maintainer's call. Ask, and meanwhile leave it alone.Internal Dependencies
main, only to delete them in the next promotion.developafter step 1 merges rather than stacking it. A stacked child loses its coverage statement and reopens its diff when the parent squash-merges, per A stacked pull request's diff reopens after the parent squash-merges, and nothing documents it ProjectTemplate#1742.State
developis atc383370, with Move the Repository to the Fleet LF Line-Ending Default #275 and Split AGENTS.md Onto the Fleet Router Model and Carry the Instruction Set #276 merged.mainhas neither, so no promotion or release has happened.resync/eol-lfandresync/instruction-setin ESPHome-NonRoot, and one detached hub worktree at hubmain. Re-derive them withgit worktree list.configure.sh apply.checkreportsConfiguration matches.develop:2026-09-26T13:21:36Z | hub 45669468 | branch override developreports 11 findings, all in the classes named in the next steps.Parked Decision Queue
0 issues carry
decisionin this repository.What the Last Round Did
AGENTS.mdonto the router model. It addedCLAUDE.md,GOVERNANCE.md,OPERATIONS.md,AUDIT.md,host-tools.jsonand the.github/skillstree, and re-vendoredCODESTYLE.mdand.github/copilot-instructions.md.developand human-authored comments, both local here) and on A stacked pull request's diff reopens after the parent squash-merges, and nothing documents it ProjectTemplate#1742 (stacked-PR reconcile conflicts and lost coverage).What Not to Repeat
develop. Taking the child's side was correct, but it took a merge commit, and the reconciled head then lost its Copilot coverage statement for two more rounds.AGENTS.md"Devcontainer" claim that the devcontainer's extensions mirror the workspace recommendations. The lists differ, so the claim was dropped rather than carried.New Learnings