Skip to content

Update(governance): adopt SpecSync 5 and Trust 1 - #4

Merged
0xLeif merged 5 commits into
mainfrom
0xleif/trust-1-org-rollout
Jul 13, 2026
Merged

0xLeif merged 5 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adopt SpecSync 5.0.1 and Trust 1.0.0 governance for the Gitleaks plugin.
  • Add an active canonical Gitleaks specification with stable requirement evidence.
  • Correct the hook contract to match the existing marker-owned whole-file behavior without changing Rust code.
  • Correct Claude, Cursor, and Gemini SpecSync guidance, govern published documentation, and use a platform-neutral Cargo help smoke.

Test Plan

  • fledge lanes run verify
  • Rust formatting and clippy
  • 4/4 Rust unit tests
  • Release build and cargo run --release -- --help
  • specsync check --strict --force --require-coverage 100 — 1/1 file, 326/326 LOC
  • Definition and closing approvals recorded as user:0xLeif
  • All review threads resolved
  • Fresh Linux, macOS, Windows, Trust, and CodeQL checks pass on e2ad482

Review Notes

The migration does not modify product code. The canonical hook contract now states the current behavior precisely: installation refuses an unmanaged existing hook, repeated installation recognizes the managed marker, removal deletes the complete marker-bearing hook, and removal refuses a hook without that marker.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the Gitleaks Fledge plugin, introducing configuration files, agent integrations, a migration change record, and the canonical gitleaks module specification with its companion files. Feedback on these changes includes fixing an empty and misplaced ## Companion files header across the agent skill files, consolidating fragmented acceptance criteria bullet points in the change documentation and state JSON, and invoking the configured fledge lanes run verify command in .specsync/sdd.json to avoid duplicating hardcoded verification steps.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread .claude/skills/spec-sync/SKILL.md Outdated
Comment thread .codex/skills/spec-sync/SKILL.md Outdated
Comment thread .cursor/skills/spec-sync/SKILL.md Outdated
Comment thread .specsync/sdd.json
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGaspar July 13, 2026 14:54

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7128abdcc3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread specs/gitleaks/gitleaks.spec.md Outdated
Comment thread .specsync/sdd.json Outdated
Comment thread .claude/commands/specsync/create-spec.md Outdated
Comment thread .gemini/commands/specsync/create-change.toml Outdated
Comment thread fledge.toml Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 23:17
@0xLeif
0xLeif merged commit e41db4f into main Jul 13, 2026
10 checks passed
@0xLeif
0xLeif deleted the 0xleif/trust-1-org-rollout branch July 13, 2026 23:18

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e2ad4825f3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment on lines +15 to +17
".claude/",
".cursor/",
".gemini/",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include Codex integration in lifecycle paths

This commit adds .codex/skills/spec-sync/SKILL.md, but the SDD meaningful_paths list only covers the Claude, Cursor, and Gemini agent surfaces here. A future change to the Codex skill can therefore bypass the required SpecSync change lifecycle even though the equivalent generated instructions for the other agents are governed, leaving one of the advertised integrations outside the Trust/SpecSync coverage.

Useful? React with 👍 / 👎.

Comment thread .specsync/sdd.json
Comment on lines +12 to +15
".trust.toml",
".augur.toml",
".attest.json",
".claude/",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Govern the managed AGENTS instructions

This rollout adds a root AGENTS.md that tells every agent session to run the Trust gate and keep specs synchronized, but that managed instruction file is not included in the SDD meaningful_paths list alongside the other Trust and agent-governance files. A later change can therefore weaken or remove the AGENTS trust block without requiring a SpecSync change workspace, leaving one of the generated governance surfaces outside the lifecycle it is meant to enforce.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant