One rule set, three placements
In-loop, pre-push and CI enforce the same rules. Different rules in different places is how you get "green locally, red in CI".
Seen in: Foundry →
~/what-i-do/devops
A pipeline is a promise about quality that runs on every change. I build ones that are deterministic, fast, cheap to run and hard to quietly weaken, including by AI agents.
In-loop, pre-push and CI enforce the same rules. Different rules in different places is how you get "green locally, red in CI".
Seen in: Foundry →
Existing issues become a baseline that may only shrink. Only new violations fail, so a legacy codebase can adopt strict rules on day one.
Linters, types, tests and scanners own pass/fail. AI may propose a fix, but it only lands when the deterministic gate passes.
Seen in: Foundry →
SHA-pinned actions, least-privilege tokens, secret and dependency scanning, and no long-lived keys in CI.
from 7,000 DKK fixed
One deterministic rule set - format, lint, types, tests, coverage, security - that runs identically in the editor, before push and in CI. Ratcheted so legacy code can adopt it on day one.
Why I stopped treating CI and "AI coding standards" as two separate things - and what Foundry does instead.