Skip to content

Merge call-use-web + call-use-brand into monorepo - #71

Merged
robotlearning123 merged 2 commits into
mainfrom
merge/satellites
Sep 23, 2026
Merged

robotlearning123 merged 2 commits into
mainfrom
merge/satellites

Conversation

@robotlearning123

Copy link
Copy Markdown
Member

Summary

Squash-imports the two private satellite repos into call-use as a monorepo:

  • agent-next/call-use-web → web/ — Astro v6 + Tailwind v4 marketing site (call-use.com), deploys to Cloudflare Workers
  • agent-next/call-use-brand → brand/ — brand assets, guidelines, legal/strategy docs, IP checklist

File trees were copied as-is (squash import — no git history carried over), one commit per source repo. Source repos are untouched.

Provenance

Source repo HEAD SHA imported Branch
agent-next/call-use-web e24a949e54a906a4a4ae47729f4ccebc1d3d63b2 main
agent-next/call-use-brand 3a4782d030aa0a8196d120e57569f26952ec190a master

Secret scan (private → public)

All imported files were scanned for BEGIN .* PRIVATE KEY, api[_-]?key, secret, token, password, AKIA, sk-, ghp_, glpat-, xox*, JWT (eyJ), AIza, Bearer, .env/*.pem/*.key files, and high-entropy strings ≥45 chars.

Result: zero real credentials found. Hits were all placeholders (sk-xxxx…, your_api_key, your-api-secret), env-var names in code samples, GitHub Actions ${{ secrets.* }} references, and lockfile/URL noise. The brand repo's own security-pre-public-audit.md reaches the same conclusion.

Flagged (not secrets, FYI): brand/strategy/pine-ai-comparison.md contains two local absolute paths (/Users/robert/workspace/...) inside a quoted snippet; brand/security-audit.md documents historical vuln findings against call-use. Left in place per "import the tree" scope — easy to scrub in a follow-up if unwanted.

Notes on imported CI/config

  • web/.github/workflows/deploy.yml was kept but is inert: GitHub only runs workflows from the repo-root .github/workflows/, so it cannot affect call-use CI. It is workflow_dispatch-only and references ${{ secrets.* }} placeholders. Re-activating deploys from the monorepo (path filters, root-level workflow) is intentionally out of scope.
  • web/ keeps its own README.md, .gitignore, .vscode/, package.json, package-lock.json, wrangler.jsonc; brand/ keeps its README.md. No changes to any existing call-use file.
  • call-use's CI scopes lint/typecheck/test/security to call_use/ and tests/ — the new dirs don't intersect it.

Test plan

  • Reviewers confirm web/ and brand/ contents match the source repos' current trees
  • CI passes on this PR (lint/typecheck/test/security/build are unaffected; commit-lint expects conventional commits — import commits use chore(repo):)
  • After merge: archive agent-next/call-use-web and agent-next/call-use-brand (separate step, not part of this PR)

@robotlearning123

Copy link
Copy Markdown
Member Author

CI note: the test (3.11/3.12/3.13) and typecheck jobs fail on this PR, but both failures are pre-existing upstream dependency drift unrelated to this diff (which only adds web/ and brand/ — no Python touched):

  • test: ImportError: cannot import name 'FastMCP' from 'mcp.server' — a newer mcp package release moved FastMCP; call_use/mcp_server.py:23 needs an import fix or a version pin.
  • typecheck: mypy fails parsing numpy/__init__.pyi:737 (Type statement is only supported in Python 3.12 and greater) — numpy stubs vs. the CI's mypy version.

Last green CI on main was 2026-03-16; these deps drifted since. lint, security, commit-lint, pr-size all pass here. Fixing the drift is out of scope for this import PR.

@robotlearning123
robotlearning123 merged commit 1f07f38 into main Sep 23, 2026
5 of 9 checks passed
@robotlearning123
robotlearning123 deleted the merge/satellites branch September 23, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants