Skip to content

Update(governance): adopt SpecSync 5 and Trust 1 - #3

Merged
0xLeif merged 3 commits into
mainfrom
0xleif/trust-1-org-rollout
Jul 13, 2026
Merged

0xLeif merged 3 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • adopt SpecSync 5.0.1 and its verified SDD lifecycle without changing plugin behavior
  • document the existing bounded-prompt and Fledge Ask delegation contract under stable governance metadata
  • install Claude, Cursor, Codex, and Gemini integrations
  • add the immutable Trust 1.0.0 gate while preserving ShellCheck, smoke-test, and Pages workflows
  • keep coverage advisory for the extensionless Bash executable while native verification remains blocking

Verification

  • strict SpecSync validation and lifecycle enforcement
  • accepted SDD change with recorded definition approval and verification evidence
  • all four agent integrations installed
  • Trust doctor
  • ShellCheck, syntax, help, invalid-input, and manifest checks
  • workflow lint
  • hosted pull-request checks

@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 07:14
@0xLeif
0xLeif merged commit 51e8dc2 into main Jul 13, 2026
3 checks passed
@0xLeif
0xLeif deleted the 0xleif/trust-1-org-rollout branch July 13, 2026 07:14

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cceccce237

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -0,0 +1,16 @@
{
"timestamp": 1783926616,
"commit": "b486aae95baa4fa7063ec6c0f35dc57f13a46291",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Re-run verification for the accepted change

The accepted SpecSync change is being committed as cf2fc0c, but this verification evidence is bound to b486aae, whose tree differs from the submitted commit because the accepted metadata and SDD config changed afterward. Since the lifecycle evidence is meant to bind to the exact commit/workspace that is accepted, audits of this commit are relying on stale results; re-run the verification after the final metadata changes so the recorded commit matches the submitted commit.

Useful? React with 馃憤聽/ 馃憥.

"base_commit": "c460c7a07018000b4896f8ef923c93c59c27712b",
"created_at": 1783882385,
"updated_at": 1783926665,
"affected_specs": [],

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Track the roast spec in this change

This migration adds specs/roast/roast.spec.md plus companion requirement/task/testing files, but the accepted change records no affected specs here. That breaks traceability for the newly introduced canonical contract: future reviewers or automation see this as a no-spec migration even though it created the roast spec; include roast in affected_specs and remove the no-spec classification before accepting.

Useful? React with 馃憤聽/ 馃憥.

Comment thread .specsync/sdd.json
"meaningful_paths": [
"src/",
"tests/",
"site/",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include actual docs and policy files in SDD coverage

With require_change_for_meaningful_files enabled, this path list determines what requires an SDD change, but it includes a non-existent site/ directory while this repo's public docs live in README.md and docs/; it also omits the new policy/config files such as plugin.toml, fledge.toml, .trust.toml, .attest.json, and .augur.toml. Changes to those files can therefore bypass the lifecycle even though the added workflow says public documentation and configuration changes must be tracked; add the real docs and policy paths to meaningful_paths.

Useful? React with 馃憤聽/ 馃憥.


Arguments: `$ARGUMENTS`

1. Parse the arguments above: the first whitespace-separated token is the

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Parse free-text spec descriptions before choosing a module

When a user invokes the advertised natural-language flow, e.g. /specsync:create-spec "I want a feature that exports CSV", this instruction first fixes the module name to the first whitespace-delimited token (I) before the later step can invent a kebab-case name from the description. The same template is copied to the other agent integrations, so free-text spec creation will scaffold badly named modules instead of the intended feature name; classify bare names versus descriptions before assigning module-name.

Useful? React with 馃憤聽/ 馃憥.

Comment thread .trust.toml
threshold = "block"

[provenance]
mode = "soft"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enforce provenance instead of allowing degraded checks

With provenance left in soft mode, the pinned Trust action treats a missing attestation ledger or an unsatisfied .attest.json policy as soft-failed/degraded and still exits successfully, so the new trust required check can pass even when no commit has the required attestation or testsPassed record. Since this adoption adds .attest.json with requireAttestation and requireTestsPassed, switch this to enforced mode once the ledger is expected so CI actually blocks unprovenanced changes.

Useful? React with 馃憤聽/ 馃憥.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant