How to check that this project actually follows the fairyfox standards it has
adopted — the enforcement layer. Each adopted standard says (in its own ## Verify
section) how to tell whether the repo follows it; this audit is the single
on-request pass that runs every one of those checks at once and reports the result.
Canonical, project-agnostic source: assets/references/fairyfox.io/hub/standards/compliance.md.
See also cross-project-sync.md (the read-only, on-request
reads this reuses) and process-reports.md (a run can end in a
report).
Establishment vs. enforcement
- Established — the rule is written canonically in
hub/standards/and reflected wherever it's used here (this project'sCLAUDE.md, notes, templates). A standard that contradicts the artifacts that operationalize it is drift, not establishment. - Enforced — there's a concrete check that catches a violation, run deliberately and reported honestly. A rule with no check is a suggestion.
Relationship to the other checks
- The onboarding completeness audit (in the hub's
onboarding-existing-project.md) is the join-time gate: is this repo in the mesh yet? This project passed it. - This audit is the recurring, whole-set check: re-runnable anytime, covering
every adopted standard via its
## Verifysection. "Is it still following everything?"
The audit matrix (this project)
This matrix aims to list every standard this project has adopted. Run every row; report each
done / partial / missing with the specific gap named. The detailed pass/fail lives in each
standard's ## Verify section where it has one; a few standards are enforced by CI config or a
CLAUDE.md standing instruction rather than a note (their row says where).
| Standard | Enforced by (the check) |
|---|---|
| git-workflow | git-workflow.md → Verify — main is --no-ff tagged releases only; no master; history intact |
| versioning | versioning.md → Verify — VERSION is one SemVer line = newest main tag; nothing hardcoded |
| notes-system | ../README.md — core notes/ tree present; status.md current; inline changelog in version/ |
| ai-context | ../../CLAUDE.md — has identity · start-here→status.md · landmines · build/run · default workflow · notes-maintenance table; workflow matches git-flow |
| cross-project-sync | cross-project-sync.md → anti-recursion checklist — pulls on-request, read-only, git-ignored, copy-not-link; the authorizations.yml ledger is read-only and only skips a redundant prompt (never lets the hub act on this node) |
| process-reports | process-reports.md → Verify — a real report per fairyfox run in notes/fairyfox-reports/ |
| docs-site | the hub's docs-site compliance checklist — themed site at fairyfox.io/<key>/ + "← Back to Fairy Fox" way-home link |
| agent-tooling | agent-tooling.md → Verify — CLAUDE.md names PowerShell + file tools & forbids the bash sandbox; root .gitattributes * text=auto eol=lf; no CRLF phantom-diff noise |
| engineering-quality | engineering-quality.md → Verify — no hacks/temp-fixes shipped; features land finished; doc-comments + current docs; refactors carry test updates; user-data fidelity |
| planning | planning.md → Verify — substantive work has a written plan (task list / notes/plans/) that predates execution; CLAUDE.md Default Workflow states plan-first |
| research-capture | research-capture.md → Verify — non-trivial findings get a plain-English reference/ note; load-bearing conclusions verified with the probe committed; wired into map/status/session/plan |
| working-rhythm | working-rhythm.md → Verify — multi-step work task-tracked live; runs stay background then surfaced; features briefed before built; ambiguity surfaced up front |
| self-hosted-assets | self-hosted-assets.md → Verify — fonts self-hosted (no googleapis/gstatic/CDN hot-links in built output); off-origin presentation requests absent; exceptions disclosed in the legal pages |
| coins | coins.md → Verify — docs-site coins.js vendored verbatim from master (byte-identical), loaded after reader.js; gates nothing; store read-merged not reset; fairyfox:coins:a disclosed via the same-origin hub /legal/coins/ |
| dependencies | dependencies.md — every runtime/dev dep justified, current majors tracked with breaking-change notes; Dependabot bumps triaged |
| deployment | deployment.md — CI/Pages/release pipelines match reality (ci.yml · pages.yml · release.yml); tag is CI-derived, not hand-pushed |
| repo-hygiene | repo-hygiene.md — check:docs (no broken links) · check:tidy (nothing untracked) · check:committed (tree == HEAD); no branch/PR litter |
| maintenance-sweep | maintenance-sweep.md — the periodic whole-repo cleanup composes git-workflow + repo-hygiene + versioning; run on "full maintenance" |
| testing | ../plans/testing.md — Vitest (Node + jsdom) + Playwright suites green; every fix ships a regression test (working-agreements.md §B1) |
| supply-chain-hardening | CI config, not a note — Scorecard/CodeQL/SonarCloud/Dependabot workflows + main branch protection; quality metrics hold or rise (working-agreements.md §B5/§F) |
| legal-docs | CLAUDE.md "Keep the Legal Docs Accurate" + working-agreements.md §F — the three self-hosted pages under targets/web/public/legal/ stay code-accurate; "Last updated" bumped on data-practice changes |
| badges | the README badge block (shields.io + Codecov) reflects the live CI/coverage/security state — all 20 canonical badges present in order (§badges) |
| checklists-are-contracts | checklists-are-contracts.md → Verify — no unbacked ✅/"adopted" over a list; per-item outcomes recorded; deferrals carry attempt + retest; every pass ends with a disclosed not-done list; the adoption manifest is the backing record |
| mandate-ledger | mandate-ledger.md → Verify — a multi-part owner directive gets a verbatim one-row-per-clause notes/plans/<date>-mandate.md; completion claims cite rows; no milestone-anchoring under an open mandate |
| readme | readme.md → Verify — worded docs link near top, organized "Get it" section, mesh footer at bottom; missing links for existing destinations carry a recorded exception |
| docker | docker.md → Verify — Linux-only build/test runs locally in a committed Docker path first, CI as backstop (tracked gap until the Dockerfile ships — see adoption-manifest) |
| adoption-manifest | adoption-manifest.md → Verify — one row per standard; copied-only ≠ adopted; no implemented without a recorded per-row pass; no summary claim without a backing row |
The adoption manifest is the record this audit reconciles against. A row here flips to
implementedin the manifest only on a recorded per-row## Verifypass; this audit is the pass that does it.
How to run it (on request only)
Gated like every cross-repo read here: an explicit request paired with the intent — "audit the fairyfox standards", "are the standards being followed", "run a compliance pass". A bare "check things" doesn't qualify.
- Run each matrix row against this repo, using that standard's
## Verifycheck. - Report
done/partial/missingper row, naming the exact gap for anything notdone. Onemissingrow means the repo is not fully compliant — say which. - Report findings, then stop. An audit changes nothing on disk.
- Fix only on go-ahead. A node gap is closed here through ordinary work; hub drift is reported to the owner to fix in the hub repo — this repo never edits the hub. A run can end in a process report.