Skip to content

feat(governance): 'contextos gate' CLI command and PR Quality Gate Action #27

Description

@kok-o

Problem Statement

As outlined in \ENTERPRISE_ROADMAP.md\ (Phase 1), teams adopting AI coding assistants need automated guardrails in CI/CD to prevent 'toxic AI code' from entering main branches (e.g. unverified placeholders // TODO: implement later, undeclared architectural drift, and missing test proofs).

While .github/actions/contextos-gate/action.yml\ exists, it is an internal composite action and lacks a standalone CLI command or diff-level AST / placeholder inspections.

Objective

Create a first-class \contextos gate\ command and modernize the GitHub Action to evaluate Pull Requests and enforce engineering policies before merging.

Scope of Work

  1. **CLI Command \contextos gate**:
    • Scan git diff for prohibited lazy patterns (// TODO: implement, // ... rest of code ...).
    • Verify adapter drift (
      ode .agents/ctx.js export all --check).
    • Run skill integrity and schema validation (
      ode .agents/ctx.js validate).
    • Scan for leaked credentials or secrets (\scripts/check-secrets.js).
    • Run project test suites.
  2. GitHub Action Integration:
    • Provide a GitHub Action step summary and PR annotation with pass/fail breakdown for each governance check.
    • Support configuration flags (--strict, --allow-todos, --skip-tests).

Acceptance Criteria


  • px contextos gate\ runs locally and returns non-zero exit code if prohibited patterns or drift are detected.
  • GitHub Action produces a formatted PR Quality Summary in Actions step summary.
  • Comprehensive unit tests for \gate\ command under \ ests/gate.test.js.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions