Repository navigation
Update(governance): adopt SpecSync 5 and Trust 1 - #4
Conversation
There was a problem hiding this comment.
Code Review
This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the Gitleaks Fledge plugin, introducing configuration files, agent integrations, a migration change record, and the canonical gitleaks module specification with its companion files. Feedback on these changes includes fixing an empty and misplaced ## Companion files header across the agent skill files, consolidating fragmented acceptance criteria bullet points in the change documentation and state JSON, and invoking the configured fledge lanes run verify command in .specsync/sdd.json to avoid duplicating hardcoded verification steps.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7128abdcc3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e2ad4825f3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ".claude/", | ||
| ".cursor/", | ||
| ".gemini/", |
There was a problem hiding this comment.
Include Codex integration in lifecycle paths
This commit adds .codex/skills/spec-sync/SKILL.md, but the SDD meaningful_paths list only covers the Claude, Cursor, and Gemini agent surfaces here. A future change to the Codex skill can therefore bypass the required SpecSync change lifecycle even though the equivalent generated instructions for the other agents are governed, leaving one of the advertised integrations outside the Trust/SpecSync coverage.
Useful? React with 👍 / 👎.
| ".trust.toml", | ||
| ".augur.toml", | ||
| ".attest.json", | ||
| ".claude/", |
There was a problem hiding this comment.
Govern the managed AGENTS instructions
This rollout adds a root AGENTS.md that tells every agent session to run the Trust gate and keep specs synchronized, but that managed instruction file is not included in the SDD meaningful_paths list alongside the other Trust and agent-governance files. A later change can therefore weaken or remove the AGENTS trust block without requiring a SpecSync change workspace, leaving one of the generated governance surfaces outside the lifecycle it is meant to enforce.
Useful? React with 👍 / 👎.
Summary
Test Plan
fledge lanes run verifycargo run --release -- --helpspecsync check --strict --force --require-coverage 100— 1/1 file, 326/326 LOCuser:0xLeife2ad482Review Notes
The migration does not modify product code. The canonical hook contract now states the current behavior precisely: installation refuses an unmanaged existing hook, repeated installation recognizes the managed marker, removal deletes the complete marker-bearing hook, and removal refuses a hook without that marker.