Update(governance): adopt SpecSync 5 and Trust 1 - #3
Conversation
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
There was a problem hiding this comment.
馃挕 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cceccce237
鈩癸笍 About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 馃憤.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -0,0 +1,16 @@ | |||
| { | |||
| "timestamp": 1783926616, | |||
| "commit": "b486aae95baa4fa7063ec6c0f35dc57f13a46291", | |||
There was a problem hiding this comment.
Re-run verification for the accepted change
The accepted SpecSync change is being committed as cf2fc0c, but this verification evidence is bound to b486aae, whose tree differs from the submitted commit because the accepted metadata and SDD config changed afterward. Since the lifecycle evidence is meant to bind to the exact commit/workspace that is accepted, audits of this commit are relying on stale results; re-run the verification after the final metadata changes so the recorded commit matches the submitted commit.
Useful? React with 馃憤聽/ 馃憥.
| "base_commit": "c460c7a07018000b4896f8ef923c93c59c27712b", | ||
| "created_at": 1783882385, | ||
| "updated_at": 1783926665, | ||
| "affected_specs": [], |
There was a problem hiding this comment.
Track the roast spec in this change
This migration adds specs/roast/roast.spec.md plus companion requirement/task/testing files, but the accepted change records no affected specs here. That breaks traceability for the newly introduced canonical contract: future reviewers or automation see this as a no-spec migration even though it created the roast spec; include roast in affected_specs and remove the no-spec classification before accepting.
Useful? React with 馃憤聽/ 馃憥.
| "meaningful_paths": [ | ||
| "src/", | ||
| "tests/", | ||
| "site/", |
There was a problem hiding this comment.
Include actual docs and policy files in SDD coverage
With require_change_for_meaningful_files enabled, this path list determines what requires an SDD change, but it includes a non-existent site/ directory while this repo's public docs live in README.md and docs/; it also omits the new policy/config files such as plugin.toml, fledge.toml, .trust.toml, .attest.json, and .augur.toml. Changes to those files can therefore bypass the lifecycle even though the added workflow says public documentation and configuration changes must be tracked; add the real docs and policy paths to meaningful_paths.
Useful? React with 馃憤聽/ 馃憥.
|
|
||
| Arguments: `$ARGUMENTS` | ||
|
|
||
| 1. Parse the arguments above: the first whitespace-separated token is the |
There was a problem hiding this comment.
Parse free-text spec descriptions before choosing a module
When a user invokes the advertised natural-language flow, e.g. /specsync:create-spec "I want a feature that exports CSV", this instruction first fixes the module name to the first whitespace-delimited token (I) before the later step can invent a kebab-case name from the description. The same template is copied to the other agent integrations, so free-text spec creation will scaffold badly named modules instead of the intended feature name; classify bare names versus descriptions before assigning module-name.
Useful? React with 馃憤聽/ 馃憥.
| threshold = "block" | ||
|
|
||
| [provenance] | ||
| mode = "soft" |
There was a problem hiding this comment.
Enforce provenance instead of allowing degraded checks
With provenance left in soft mode, the pinned Trust action treats a missing attestation ledger or an unsatisfied .attest.json policy as soft-failed/degraded and still exits successfully, so the new trust required check can pass even when no commit has the required attestation or testsPassed record. Since this adoption adds .attest.json with requireAttestation and requireTestsPassed, switch this to enforced mode once the ledger is expected so CI actually blocks unprovenanced changes.
Useful? React with 馃憤聽/ 馃憥.
Summary
Verification