jamesfredley commented on PR #16025:
URL: https://github.com/apache/grails-core/pull/16025#issuecomment-5123237616

   Thanks for the detailed review. Addressed on 
chore/automate-project-conventions:
   
   **7a0aceb5ff - main review feedback**
   - First-party actions/* and apache/grails-github-actions/* back on 
version/branch refs; third-party stay SHA-pinned
   - PMD opt-in via per-project grailsCodeAnalysis extension (no central 
project-name list)
   - Lazy aggregation (configureEach), aggregate-only cleanup/Markdown, no 
direct-task report clobbering
   - Validator UTF-8, i18n grails-app/i18n/**/*.properties, worktree hygiene, 
skill-discovery compatibility with #15977
   - Release packaging: symlink-safe timestamps, agent guidance kept in source 
zip, SnakeYAML managed at 2.6
   - Expanded TestKit coverage and CI wiring for conventions + advisory SpotBugs
   
   **9a8fbeed87 - source-root marker**
   - Keep .asf.yaml in the signed source ZIP (it is the findRootGrailsCoreDir 
marker); RAT-only exclude
   - Terminate root search at the filesystem root; GradleUtilsSpec covers both 
paths
   
   Open inline threads have been resolved against the current head. Happy to 
follow up on anything still unclear.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to