\`lh doctor\`'s context7 check is a required, env-only check by design
(ADR: never inferred, never persisted). Tests that shell out to \`lh\`
or \`scripts/onboard.mjs\` inherited whatever CONTEXT7_API_KEY the
developer's shell happened to export, so \`doctor passes once the repo
is initialised\` and the onboard-script e2e test only ever passed on
machines with a real key set — never verified in a clean environment
until this CI run (no secret configured, correctly).
Fixed by injecting an obviously-fake fixture key (TEST_ENV in
helpers.mjs, exported and reused by onboard.test.mjs) into every
subprocess these tests spawn, so behaviour no longer depends on the
ambient shell. Verified locally with \`env -u CONTEXT7_API_KEY\` to
reproduce the CI environment exactly: 58/58 pass either way now.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- scripts/onboard.mjs: bootstraps a target repo onto the harness — copies
the behaviour layer (.github/agents, skills, instructions, prompts,
mcp.json, copilot-instructions.md, AGENTS.md), npm links the `lh` CLI,
runs `lh init` + `lh doctor`, prints next steps. Idempotent: identical
files are skipped, differing files require --force, re-running `lh init`
on an initialized repo warns instead of failing. Supports --dry-run and
--no-npm-link for CI/sandboxed use.
- tests/onboard.test.mjs: 5 new e2e tests (dry-run, full run, idempotent
rerun, missing target dir, conflict + --force).
- README: new "Onboarding a new project" section, full lh flag reference
for every subcommand (previously only one-line summaries), Development
section mentions the onboarding script.
Live-tested against ~/Sources/ralph-runtime (a real, not-yet-git-tracked
project): git init, .github/ copied, `npm link` succeeded, `lh init`
ran, `lh doctor` correctly flagged its one real gap (no verify command
configured) rather than a false pass.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>