Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
509 commits
Select commit Hold shift + click to select a range
0448022
docs: archive backlog-02-migrate-core-commands change
djm81 Mar 11, 2026
e91e672
feat: document code-review module scaffold (#410)
djm81 Mar 11, 2026
aa494ff
Add change for project codebase ownership
djm81 Mar 11, 2026
b62292c
Merge branch 'main' into dev
djm81 Mar 11, 2026
67aaf31
Realign code import ownership surface (#412)
djm81 Mar 12, 2026
1f4d236
Update code review changes
djm81 Mar 16, 2026
516b4c7
docs: update reward ledger OpenSpec tracking (#413)
djm81 Mar 16, 2026
8579fe5
Track house-rules skill OpenSpec changes (#414)
djm81 Mar 16, 2026
ff8d041
docs: Update change-proposal for code-review-07 (#415)
djm81 Mar 16, 2026
b524f3a
Finalize code-review-07 status
djm81 Mar 16, 2026
097d8ef
Finalize code-review-08 status
djm81 Mar 16, 2026
37efea0
feat: apply code-review-09 pre-commit integration
djm81 Mar 17, 2026
fa503da
fix: fall back when cached hatch test env is broken
djm81 Mar 17, 2026
6e828e7
fix: avoid hatch env for coverage xml export
djm81 Mar 17, 2026
0aa178f
fix: install type-check and lint tools directly in CI
djm81 Mar 17, 2026
9f6a749
fix: install pytest fallback deps in test job
djm81 Mar 17, 2026
c451134
fix: install pytest-cov for test fallback path
djm81 Mar 17, 2026
f328223
Merge branch 'main' into dev
djm81 Mar 17, 2026
9146118
Merge branch 'main' into dev
djm81 Mar 17, 2026
0aa017d
Finalize code-review-09 status
djm81 Mar 17, 2026
f067288
[Change] Align core docs with modules site ownership (#419)
djm81 Mar 17, 2026
e456d46
fix: harden docs parity URL assertions
djm81 Mar 17, 2026
41052e6
Archive finished changes and update specs
djm81 Mar 17, 2026
05e81bb
Merge branch 'main' into dev
djm81 Mar 17, 2026
0648162
docs: fix command syntax parity after lean-core/modules split (v0.42.…
djm81 Mar 17, 2026
a6978a2
Archive finished changes and update specs
djm81 Mar 17, 2026
0273f1a
Update evidence
djm81 Mar 17, 2026
8ec2c11
Potential fix for pull request finding 'Unused global variable'
djm81 Mar 17, 2026
7d63dd8
Merge branch 'main' into dev
djm81 Mar 18, 2026
a77e5fd
docs: align core docs ownership and parity (#424)
djm81 Mar 20, 2026
664d4e4
docs: fix quickstart install guidance
djm81 Mar 20, 2026
09688de
docs: remove generated project plan docs
djm81 Mar 20, 2026
f7cca1e
Merge branch 'main' into dev
djm81 Mar 20, 2026
f4e91be
Add code-review change
djm81 Mar 20, 2026
37dfecb
fix: preserve native backlog import payloads (#429)
djm81 Mar 20, 2026
b54aaa6
fix: add docs review workflow and repair docs links (#428)
djm81 Mar 20, 2026
ae7f05c
fix: keep imported change ids stable across title changes (#431)
djm81 Mar 20, 2026
7449714
Merge branch 'main' into dev
djm81 Mar 20, 2026
65726fb
fix: remove conflicting pages file copies
djm81 Mar 20, 2026
fbb3b83
Merge branch 'main' into dev
djm81 Mar 20, 2026
c6c47fc
Add docs sync changs
djm81 Mar 20, 2026
eaa87ac
docs: update openspec clean-code planning
djm81 Mar 22, 2026
f602dba
Update change status
djm81 Mar 22, 2026
58314e5
fix: code-review-zero-findings dogfood remediation (v0.42.3) (#435)
djm81 Mar 23, 2026
fb3c5fd
Merge branch 'main' into dev
djm81 Mar 23, 2026
2809390
Add docs refactoring changes
djm81 Mar 23, 2026
215df59
Add bug change tracking for encoding and resources
djm81 Mar 24, 2026
2a60f15
docs: restructure core site IA to 6-section progressive nav (#442)
djm81 Mar 24, 2026
81bca26
fix: harden cross-platform runtime and IDE resource discovery (#443)
djm81 Mar 24, 2026
852f446
fix: resolve review type-safety findings
djm81 Mar 24, 2026
2bbde33
Merge branch 'main' into dev
djm81 Mar 24, 2026
8272233
Improve clarity and scope of ide prompt change
djm81 Mar 25, 2026
2f0675c
feat(init): IDE prompt source catalog, --prompts, namespaced exports …
djm81 Mar 25, 2026
278142e
fix tests
djm81 Mar 25, 2026
38a9d21
release: bump version to 0.42.5 and update CHANGELOG
djm81 Mar 25, 2026
f552107
Fix review findings
djm81 Mar 25, 2026
dab2ffe
feat(init): selective IDE prompt export cleanup and VS Code recommend…
djm81 Mar 25, 2026
fbb2307
Fix review findings
djm81 Mar 25, 2026
71e760b
Merge branch 'main' into dev
djm81 Mar 25, 2026
41dc0db
Add missing import
djm81 Mar 25, 2026
2b26098
Bump patch version and changelog
djm81 Mar 25, 2026
90da7da
Fix failed tests
djm81 Mar 25, 2026
1eca7a9
Fix review findings
djm81 Mar 25, 2026
07c19b4
Merge branch 'main' into dev
djm81 Mar 26, 2026
db4ddc3
docs: core vs modules URL contract and OpenSpec alignment (#448)
djm81 Mar 26, 2026
96f35d7
feat(docs-12): docs command validation and cross-site link checks (#449)
djm81 Mar 26, 2026
f11cb9e
fix(scripts): CliRunner without mix_stderr for Click 8.3+ compatibili…
djm81 Mar 26, 2026
7ccb122
fix: review gates (semgrep print, radon CC, icontract, questionary ty…
djm81 Mar 26, 2026
d516657
Merge branch 'main' into dev
djm81 Mar 26, 2026
86bdc7c
Add speckit adapter alignment change and update affected change specs
djm81 Mar 27, 2026
f92c820
feat(adapters): spec-kit v0.4.x adapter alignment (#454)
djm81 Mar 27, 2026
dd1e359
chore: bump version to 0.43.0 for spec-kit v0.4.x alignment (#455)
djm81 Mar 27, 2026
eec640e
fix(packaging): remove workflow prompts from core wheel (packaging-02…
djm81 Mar 27, 2026
f7fefdd
Potential fix for pull request finding 'Empty except'
djm81 Mar 28, 2026
280d158
Merge branch 'main' into dev
djm81 Mar 28, 2026
0cc2c3c
Fix changelog version
djm81 Mar 28, 2026
c1c2e47
docs: unify core docs portal UX (#459)
djm81 Mar 28, 2026
ce49cd5
Harden docs home URL test assertion
djm81 Mar 28, 2026
cb08cbb
Merge branch 'main' into dev
djm81 Mar 29, 2026
715d472
feat: doc frontmatter validation, v0.43.2 review JSON gate, and pre-c…
djm81 Mar 29, 2026
edc89a7
docs: archive doc-frontmatter-schema openspec change
djm81 Mar 29, 2026
85572f2
Apply suggestions from code review
djm81 Mar 29, 2026
117d568
fix: restore protocol stubs for type checking
djm81 Mar 29, 2026
582a53c
Add frontamtter check
djm81 Mar 29, 2026
4c4ef24
fix: harden protocol stubs for code quality
djm81 Mar 29, 2026
52ee695
Add PR test hardening change
djm81 Mar 29, 2026
644474a
fix: remediate review findings and harden review gates
djm81 Mar 30, 2026
3eff782
fix: rebuild review report model for pydantic
djm81 Mar 30, 2026
e44f15a
Merge branch 'main' into dev
djm81 Mar 30, 2026
93ff11e
Add story and onboarding change
djm81 Mar 30, 2026
506679e
Update change tracking
djm81 Mar 30, 2026
f84aa39
Improve scope for ci/cd requirements
djm81 Mar 30, 2026
11391c9
docs: sharpen first-contact story and onboarding (#467)
djm81 Mar 30, 2026
0fc5f1f
fix: harden review blockers and bump patch version
djm81 Mar 30, 2026
ab42fd0
test: harden modules docs url assertions
djm81 Mar 30, 2026
93b6dee
Merge branch 'main' into dev
djm81 Mar 30, 2026
c5efee3
fix: harden trustworthy green checks (#469)
djm81 Mar 30, 2026
30c70f3
fix: address CodeRabbit review findings for ci-02 (#471)
djm81 Mar 30, 2026
7709718
fix: propagate docker actionlint exit code instead of masking failure…
djm81 Mar 30, 2026
1ffdace
fix: assert hook id stability and cd to repo root for local actionlin…
djm81 Mar 30, 2026
4dcf207
Merge branch 'main' into dev
djm81 Mar 30, 2026
9dbe9d4
feat: clean-code-01-principle-gates — 7-principle charter gates, v0.4…
djm81 Mar 31, 2026
9855d35
feat: archive completed openspec changes and update main specs
djm81 Mar 31, 2026
e9e75d4
Merge branch 'main' into dev
djm81 Mar 31, 2026
6663324
Add new user onboarding change
djm81 Apr 1, 2026
b4a7ecf
docs & tooling: new user onboarding + smart-test and pre-commit revie…
djm81 Apr 2, 2026
e87058b
fix: code-review gate (Typer params), typer<0.24 vs semgrep, module u…
djm81 Apr 3, 2026
9696489
docs: restructure README for star conversion (#480)
djm81 Apr 3, 2026
8fe4a26
Merge branch 'main' into dev
djm81 Apr 3, 2026
903b131
Merge branch 'main' into dev
djm81 Apr 5, 2026
f1f1919
archived implemented changes
djm81 Apr 5, 2026
17ac397
Archive and remove outdated changes
djm81 Apr 5, 2026
9900b72
Split and refactor change proposals between both repos
djm81 Apr 8, 2026
2a73434
Merge remote-tracking branch 'origin/main' into dev
djm81 Apr 8, 2026
e8c3848
Archive alignment change
djm81 Apr 8, 2026
98cf86e
Merge branch 'main' into dev
djm81 Apr 8, 2026
5b5bac7
Add changes and github hierarchy scripts
djm81 Apr 9, 2026
280ac57
feat: add GitHub hierarchy cache sync (#492)
djm81 Apr 9, 2026
1b314a1
[codex] Compact agent governance loading (#493)
djm81 Apr 10, 2026
647ce0c
Archived github hierarchy change
djm81 Apr 10, 2026
338aa92
Update from dev
djm81 Apr 10, 2026
c5083cf
Update rules for openspec archive
djm81 Apr 10, 2026
74c566b
Potential fix for pull request finding 'Unused local variable'
djm81 Apr 10, 2026
685bd4e
Add wiki update notes
djm81 Apr 10, 2026
fdcc51a
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 Apr 10, 2026
6c9f03b
Archive governance-03 change, format markdown, add wiki instructions …
djm81 Apr 10, 2026
de48d48
Fix review findings
djm81 Apr 10, 2026
186120e
Fix type errors
djm81 Apr 10, 2026
73b8f48
Merge branch 'main' into dev
djm81 Apr 10, 2026
951f3ae
fix: safe VS Code settings merge and project artifact writes (#490) (…
djm81 Apr 12, 2026
14f3b41
Fix review findings (#498)
djm81 Apr 12, 2026
6096c3c
feat(openspec): add marketplace-06-ci-module-signing change proposal
djm81 Apr 13, 2026
448328b
chore(pre-commit): modular hooks + branch-aware module verify (#501)
djm81 Apr 14, 2026
f7e3fd2
apply code review fixes
djm81 Apr 14, 2026
96879a9
apply code review fixes
djm81 Apr 14, 2026
cdf7e4d
merge: integrate origin/dev with local PyPI pre-commit and type-check…
djm81 Apr 14, 2026
29fdca8
merge: integrate origin/main into dev (conflicts resolved favoring dev)
djm81 Apr 14, 2026
3ffec56
fix(pre-commit): include staged deletions in staged_files() for Block 2
djm81 Apr 14, 2026
95ccde3
Fix review findings
djm81 Apr 14, 2026
c8a1116
Fix code review findings
djm81 Apr 14, 2026
b9b8691
feat(ci): module signing on PR approval and manual workflow_dispatch …
djm81 Apr 14, 2026
01e7351
Feature/ci module sign on approval (#504)
djm81 Apr 14, 2026
b2cc72f
feat(ci): workflow_dispatch for sign-modules-on-approval (#505)
djm81 Apr 14, 2026
a1dda6d
fix(ci): module signing workflows, PyPI version check, and review gate
djm81 Apr 14, 2026
85e7b5a
fix(modules): bump init to 0.1.28 for enforce-version-bump on dev
djm81 Apr 14, 2026
e7efd7d
Merge branch 'main' into dev
djm81 Apr 14, 2026
e61a8a2
chore(release): v0.46.2 — require signatures on all PRs to main
djm81 Apr 14, 2026
1ceddab
sign changed package
djm81 Apr 14, 2026
48ea131
fix(modules): bump init to 0.1.29 for dev→main PR version gate
djm81 Apr 14, 2026
7e9504e
Signed modules and bumped version
djm81 Apr 14, 2026
b34f9fb
Signed modules and bumped version
djm81 Apr 14, 2026
55c4c97
Fix sign flow
djm81 Apr 14, 2026
7091747
Merge branch 'main' into dev
djm81 Apr 15, 2026
5d0d82f
feat: dep-security-cleanup (license gate, pycg, commentjson, review e…
djm81 Apr 16, 2026
01d1bb1
apply review findings
djm81 Apr 16, 2026
5125725
Fix publish module and security gate findings
djm81 Apr 16, 2026
4df303c
Fix findings and publish bug
djm81 Apr 16, 2026
bbea309
Fix review findings and publish modules flow
djm81 Apr 16, 2026
1c1624d
Update publish and sign flows
djm81 Apr 16, 2026
e69ea29
Update publish and sign flows
djm81 Apr 16, 2026
ef07858
chore(modules): auto-sign bundled manifests [skip ci] (#510)
github-actions[bot] Apr 16, 2026
daa73c6
Apply code review findings
djm81 Apr 16, 2026
e62d223
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 Apr 16, 2026
1e255e5
Fix failed tests
djm81 Apr 16, 2026
ce3bbb4
[codex] Add five-pillar governance OpenSpec wave (#531)
djm81 Apr 19, 2026
f48b156
[codex] stabilize module install and init state (#535)
djm81 Apr 28, 2026
0200ba5
chore(modules): auto-sign bundled manifests [skip ci] (#536)
github-actions[bot] Apr 28, 2026
b6505f4
Merge branch 'main' into dev
djm81 Apr 28, 2026
d0eb4a4
fix: remove unused checksum tuple in verifier
djm81 Apr 28, 2026
be171d3
chore: reduce low-signal coderabbit review noise
djm81 Apr 28, 2026
73741e4
fix: address codex review findings
djm81 Apr 28, 2026
d209150
fix: tighten local gate scope and module verification
djm81 Apr 28, 2026
01702e6
Merge branch 'main' into dev
djm81 Apr 28, 2026
9b7d968
Make `specfact upgrade` install-method-aware (uv/uvx support, pipx/pi…
djm81 May 3, 2026
3f349fc
chore(modules): auto-sign bundled manifests [skip ci] (#540)
github-actions[bot] May 3, 2026
7179e77
fix(upgrade): prefer pipx before uv tool detection
djm81 May 3, 2026
6e65c7d
fix(upgrade): address PR 541 review findings
djm81 May 3, 2026
88f3d90
fix(cli,upgrade): address PR 541 critical findings
djm81 May 3, 2026
082dc06
Update module manifest from main
djm81 May 3, 2026
990d1e8
chore(modules): auto-sign bundled manifests [skip ci] (#546)
github-actions[bot] May 3, 2026
cb00a4b
Fix module upgrade signature and version bump
djm81 May 3, 2026
27afdb5
Fix signature
djm81 May 3, 2026
d470837
chore(modules): auto-sign bundled manifests [skip ci] (#548)
github-actions[bot] May 3, 2026
86e7e70
fix(ci): terminate module publish output list
djm81 May 3, 2026
8a0aa0d
Merge branch 'main' into dev
djm81 May 3, 2026
bed4721
fix(cli): forward bare lazy subcommands (#549)
djm81 May 3, 2026
11a5e1e
Merge branch 'main' into dev
djm81 May 3, 2026
7724ea6
chore(openspec): park 21 deferred proposals + simplify CHANGE_ORDER (…
djm81 May 6, 2026
197c0d1
Ignore claude settings.json
djm81 May 6, 2026
8000f06
docs: refine telemetry change to active opt-in (#555)
djm81 May 6, 2026
a7a5336
Merge branch 'main' into dev
djm81 May 6, 2026
469af46
fix runtime module discovery reliability (#558)
djm81 May 7, 2026
fab4fa6
chore(modules): auto-sign bundled manifests [skip ci] (#559)
github-actions[bot] May 7, 2026
694fdb2
Merge branch 'main' into dev
djm81 May 8, 2026
abc2db1
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 May 8, 2026
a021c53
Merge branch 'main' into dev
djm81 May 8, 2026
4f38ece
[codex] Add module scope version diagnostics (#566)
djm81 May 14, 2026
0c25c8a
chore(modules): auto-sign bundled manifests [skip ci] (#567)
github-actions[bot] May 14, 2026
4322275
fix: address module dependency review findings
djm81 May 17, 2026
3b0f198
fix: address dependency review follow-ups
djm81 May 17, 2026
59be197
Fix dependency resolver bounds and bundle dependency validation
djm81 May 17, 2026
f32da81
Merge branch 'main' into dev
djm81 May 17, 2026
3b13b54
Fix bundled module publish summary quoting
djm81 May 17, 2026
09e3c25
Merge branch 'main' into dev
djm81 May 20, 2026
3f74602
fix(upgrade): suppress benign pipx spaced-home warning (#574)
djm81 May 20, 2026
4ccb2d0
chore(bundled-modules): snapshot from dev@3f74602 (#576)
github-actions[bot] May 20, 2026
5394186
chore(modules): auto-sign bundled manifests [skip ci] (#575)
github-actions[bot] May 20, 2026
717c74d
fix(upgrade): tolerate undecodable child output
djm81 May 20, 2026
15b507c
chore(modules): auto-sign bundled manifests [skip ci] (#578)
github-actions[bot] May 20, 2026
e7b13db
chore(bundled-modules): snapshot from dev@717c74d (#579)
github-actions[bot] May 20, 2026
7d88cb6
Fix registry
djm81 May 20, 2026
b58f924
fix: keep core bundled registry URLs scoped (#580)
djm81 May 20, 2026
edc9651
chore(release): prepare core cli 0.46.28 (#582)
djm81 May 21, 2026
5d5ce89
Merge branch 'main' into dev
djm81 May 21, 2026
03b742f
Merge branch 'main' into dev
djm81 May 21, 2026
47f8e19
Harden CLI command reliability gates (#595)
djm81 Jun 1, 2026
8118ff2
chore(modules): auto-sign bundled manifests [skip ci] (#596)
github-actions[bot] Jun 1, 2026
c6b57a8
chore(bundled-modules): snapshot from dev@47f8e19 (#597)
github-actions[bot] Jun 1, 2026
a711057
fix: align release command validation with modules dev
djm81 Jun 1, 2026
06afb70
fix: tolerate code import alias help ambiguity
djm81 Jun 1, 2026
7e5b1c2
chore(fix): Fix code review findings and PR failure
djm81 Jun 2, 2026
82ed1ba
chore: fix PR 598 validation failures
djm81 Jun 2, 2026
9837a13
chore(modules): auto-sign bundled manifests [skip ci] (#599)
github-actions[bot] Jun 2, 2026
ed37663
chore(bundled-modules): snapshot from dev@82ed1ba (#600)
github-actions[bot] Jun 2, 2026
c4fd804
Merge branch 'main' into dev
djm81 Jun 2, 2026
b298fc1
docs: position SpecFact as AI-bloat defense CLI (#601)
djm81 Jun 2, 2026
dcc5a03
chore: archive completed docs OpenSpec change (#603)
djm81 Jun 2, 2026
c3d6c68
Archive upgrade-01 change
djm81 Jun 2, 2026
c8faa8f
Merge branch 'main' into dev
djm81 Jun 2, 2026
89df5ec
Fix conflict
Jun 6, 2026
9266fa9
add cli fix change
Jun 9, 2026
913f089
Ignore agent skills meant for local only
Jun 12, 2026
65608b4
Fix merge conflict
Jun 12, 2026
0e3c4d3
fix: replace stale flat command references and guard llms.txt freshne…
djm81 Jun 12, 2026
5308d1e
Don't ignore openspec workflow rules
Jun 12, 2026
da416b9
Tighten CI gates and module verification (#609)
djm81 Jun 13, 2026
09e95cf
Merge branch 'main' into dev
djm81 Jun 13, 2026
0a5f8d9
: use checked-in semgrep sast config
djm81 Jun 13, 2026
65dfe70
fix: harden pr gate remediation
djm81 Jun 13, 2026
10dda75
chore(modules): auto-sign bundled manifests (#611)
github-actions[bot] Jun 13, 2026
8fa6886
chore(modules): auto-sign bundled manifests (#613)
github-actions[bot] Jun 13, 2026
8b5fd59
chore(bundled-modules): snapshot from dev@8fa6886 (#615)
github-actions[bot] Jun 13, 2026
3154509
fix: refresh module consoles before install tests
djm81 Jun 13, 2026
66bca99
chore(modules): auto-sign bundled manifests (#616)
github-actions[bot] Jun 13, 2026
d568987
chore(bundled-modules): snapshot from dev@3154509 (#617)
github-actions[bot] Jun 13, 2026
ed2e2b7
chore(modules): auto-sign bundled manifests (#618)
github-actions[bot] Jun 13, 2026
30971b6
chore(bundled-modules): snapshot from dev@ed2e2b7 (#619)
github-actions[bot] Jun 13, 2026
519a599
test: avoid brittle bundle install capture
djm81 Jun 14, 2026
0853fde
chore(modules): auto-sign bundled manifests (#620)
github-actions[bot] Jun 14, 2026
ee041a9
chore(bundled-modules): snapshot from dev@519a599 (#621)
github-actions[bot] Jun 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
625 changes: 518 additions & 107 deletions .github/workflows/pr-orchestrator.yml

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions .github/workflows/publish-modules.yml
Original file line number Diff line number Diff line change
Expand Up @@ -189,8 +189,8 @@ jobs:
auto-publish:
name: Package bundled modules and PR bundled-registry snapshot (after sign-modules)
# Trigger only when sign-modules.yml completed successfully on dev/main.
# Uses workflow_run so it is NOT suppressed by the `[skip ci]` marker on
# the bot's auto-sign commit (push events would be).
# Uses workflow_run so publishing follows the completed signing workflow,
# independent of which push event originally changed bundled manifests.
if: >-
github.event_name == 'workflow_run' &&
github.event.workflow_run.event == 'push' &&
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/sign-modules-on-approval.yml
Original file line number Diff line number Diff line change
Expand Up @@ -110,7 +110,7 @@ jobs:
echo "No staged module manifest updates."
exit 0
fi
git commit -m "chore(modules): ci sign changed modules [skip ci]"
git commit -m "chore(modules): ci sign changed modules"
git push origin "HEAD:${HEAD_REF}"
echo "## Signed manifests pushed" >> "${GITHUB_STEP_SUMMARY}"
echo "Updated \`module-package.yaml\` files were committed to \`${HEAD_REF}\`." >> "${GITHUB_STEP_SUMMARY}"
Expand Down Expand Up @@ -190,7 +190,7 @@ jobs:
echo "No staged module manifest updates."
exit 0
fi
git commit -m "chore(modules): manual approval-workflow sign changed modules [skip ci]"
git commit -m "chore(modules): manual approval-workflow sign changed modules"
git push origin "HEAD:${GITHUB_REF_NAME}"
echo "## Signed manifests pushed" >> "${GITHUB_STEP_SUMMARY}"
echo "Branch: \`${GITHUB_REF_NAME}\` (merge-base vs \`origin/${{ github.event.inputs.base_branch }}\`, bump: \`${{ github.event.inputs.version_bump }}\`)." >> "${GITHUB_STEP_SUMMARY}"
4 changes: 2 additions & 2 deletions .github/workflows/sign-modules.yml
Original file line number Diff line number Diff line change
Expand Up @@ -222,7 +222,7 @@ jobs:
fi
BRANCH="auto/sign-${GITHUB_REF_NAME}-${{ github.run_id }}"
git checkout -b "${BRANCH}"
git commit -m "chore(modules): auto-sign bundled manifests [skip ci]"
git commit -m "chore(modules): auto-sign bundled manifests"
git push -u origin "${BRANCH}"
gh pr create \
--repo "${{ github.repository }}" \
Expand Down Expand Up @@ -363,7 +363,7 @@ jobs:
echo "No staged module manifest updates."
exit 0
fi
git commit -m "chore(modules): manual workflow_dispatch sign changed modules [skip ci]"
git commit -m "chore(modules): manual workflow_dispatch sign changed modules"
git push origin "HEAD:${GITHUB_REF_NAME}"
echo "## Signed manifests pushed" >> "${GITHUB_STEP_SUMMARY}"
echo "Branch: \`${GITHUB_REF_NAME}\` (base: \`origin/${{ github.event.inputs.base_branch }}\`, bump: \`${{ github.event.inputs.version_bump }}\`, resign_all: \`${{ github.event.inputs.resign_all_manifests }}\`)." >> "${GITHUB_STEP_SUMMARY}"
42 changes: 42 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,48 @@ All notable changes to this project will be documented in this file.

---

## [0.47.11] - 2026-06-14

### Fixed

- **Bundle install CI stability**: avoid brittle Click stdout capture in the
already-present bundle dependency regression and apply module-registry review
annotations for callback type enforcement and isolated test state.

---

## [0.47.10] - 2026-06-13

### Fixed

- **Module install CI stability**: refresh loaded SpecFact module consoles before
direct module-registry invocations so stale Rich streams from earlier tests do
not close Click's captured stdout in Python 3.11 full-suite runs.

---

## [0.47.9] - 2026-06-13

### Fixed

- **PR gate remediation**: split Independent Static Analysis onto a dedicated
checked-in SAST profile, keep clean-code review separate from security SAST,
fix marketplace install output capture across Python CI jobs, and make the
module pre-commit verifier compatible with macOS's default Bash.

---

## [0.47.8] - 2026-06-13

### Fixed

- **PR hardening follow-up**: address PR review annotations and failing CI by
pinning orchestrator actions to immutable SHAs, preserving precise coverage
threshold comparisons, making Semgrep SAST result parsing fail closed, and
normalizing versioned dependency constraints before dedupe.

---

## [0.47.7] - 2026-06-12

### Fixed
Expand Down
17 changes: 16 additions & 1 deletion docs/agent-rules/50-quality-gates-and-review.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ tracks:
- scripts/verify-modules-signature.py
- scripts/module-verify-policy.sh
- docs/agent-rules/**
last_reviewed: 2026-04-16
last_reviewed: 2026-06-13
exempt: false
exempt_reason: ""
id: agent-rules-quality-gates-and-review
Expand Down Expand Up @@ -52,6 +52,17 @@ depends_on:
- Resolve every finding at any severity unless a rare, explicit exception is documented.
- Record the review command and timestamps in `TDD_EVIDENCE.md` or the PR description when quality gates are part of the change.

## Independent static analysis

Do not treat `specfact code review run` as sufficient security evidence for this repository. The review gate is intentionally self-referential: it is valuable for SpecFact-specific conventions, command-surface expectations, OpenSpec alignment, and local clean-code policy, but it can inherit blind spots from SpecFact itself.

PR validation therefore requires an independent static-analysis check alongside the self-review gate:

- `Independent Static Analysis` runs Semgrep OSS SAST through `hatch run semgrep-sast` and validates results with `hatch run semgrep-sast-gate`.
- Existing Semgrep findings are tracked in `tools/semgrep/sast-baseline.json`; new findings outside that baseline fail CI.
- Bandit runs through `hatch run bandit-scan` and is expected to remain clean for blocking medium/high findings.
- The Semgrep and Bandit artifacts are external evidence and must not be replaced by `.specfact/code-review.json`.

## Clean-code review gate

The repository enforces the clean-code charter through `specfact code review run`. Zero regressions in `naming`, `kiss`, `yagni`, `dry`, and `solid` are required before merge.
Expand All @@ -71,6 +82,10 @@ the change reaches `main`**.
hatch run verify-modules-signature
```

CI mirrors this boundary: `pr-orchestrator.yml` uses **`VERIFY_MODULES_STRICT`** for pull requests
targeting `main` and for pushes to `main`; relaxed PR verification is only for development PRs that do
not cross the release boundary.

If verification fails because module contents changed, re-sign the affected manifests and bump the
module version before re-running verification. Note: `verify-modules-signature.py` has **no**
`--allow-unsigned` flag. The `--allow-unsigned` option on **`sign-modules.py`** is only for local test signing.
15 changes: 9 additions & 6 deletions docs/guides/module-signing-and-key-rotation.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,8 @@ PR / feature-branch parity with pre-commit omit (version bump vs base; defer che
hatch run verify-modules-signature-pr --version-check-base origin/dev
```

Post-merge / push-style checksum + version (no `--require-signature`; matches `VERIFY_MODULES_PUSH_ORCHESTRATOR`):
Development push-style checksum + version for the `dev` path (no `--require-signature`; matches
`VERIFY_MODULES_PUSH_ORCHESTRATOR`):

```bash
hatch run python scripts/verify-modules-signature.py --enforce-version-bump --payload-from-filesystem
Expand All @@ -146,14 +147,16 @@ If you use `pre-commit` or `scripts/setup-git-hooks.sh`, commits that stage chan

Canonical flag bundles live in **`scripts/module-verify-policy.sh`** and are sourced by:

- **`pr-orchestrator.yml`** job `verify-module-signatures`: **pull requests** use **`VERIFY_MODULES_PR`**
(same as pre-commit omit). **Pushes** to `dev` / `main` use **`VERIFY_MODULES_PUSH_ORCHESTRATOR`**
(payload checksum + version bump; no `--require-signature` in this job).
- **`pr-orchestrator.yml`** job `verify-module-signatures`: pull requests targeting **`dev`** use
**`VERIFY_MODULES_PR`** (same as pre-commit omit). Pull requests targeting **`main`** and pushes to
**`main`** use **`VERIFY_MODULES_STRICT`** so unsigned or stale bundled manifests block before the
release trust boundary. Pushes to **`dev`** use **`VERIFY_MODULES_PUSH_ORCHESTRATOR`** (payload
checksum + version bump; no `--require-signature` in the `dev` push path).
- **`sign-modules.yml`** job `verify`: **push** to `dev` or `main` runs **`VERIFY_MODULES_STRICT`**
after the auto-sign step. **Pull requests** and **`workflow_dispatch`** use **`VERIFY_MODULES_PR`**.

Strict signatures on protected branches are enforced by **`sign-modules.yml`** (and local **`main`**
pre-commit), not by adding `--require-signature` to the PR orchestrator verify step.
Strict signatures at the release boundary are enforced by **`pr-orchestrator.yml`**, **`sign-modules.yml`**,
and local **`main`** pre-commit.

## Rotation Procedure

Expand Down
12 changes: 12 additions & 0 deletions docs/modules/code-review.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,18 @@ The scaffolded `ReviewReport` envelope carries these fields:
- Review-specific fields (`score`, `reward_delta`, `findings`, `summary`, `house_rules_updates`) extend the standard evidence shape without replacing it.
- CI can treat `ci_exit_code` as the contract-bound gate result from the start.

## Self-Review Limits

`specfact code review run` is deliberately optimized for SpecFact conventions: command surfaces, OpenSpec contract alignment, local clean-code rules, and repository-specific policy. That makes it useful, but it also means it can inherit blind spots from SpecFact itself. If SpecFact does not model a risk pattern, the self-review gate cannot reliably discover that pattern in this repository.

For SpecFact CLI itself, CI pairs the self-review evidence with an independent static-analysis gate:

- Semgrep OSS SAST runs through `hatch run semgrep-sast`.
- `hatch run semgrep-sast-gate` compares Semgrep JSON against `tools/semgrep/sast-baseline.json` and fails on new findings.
- Bandit runs through `hatch run bandit-scan`.

Use the self-review report for SpecFact-specific quality signals, and use Semgrep/Bandit as orthogonal evidence from external rulesets.

## Pre-Commit Review Gate

This repository wires `specfact code review run` into **Block 2** of the modular pre-commit pipeline
Expand Down
13 changes: 8 additions & 5 deletions docs/reference/module-security.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,13 +48,16 @@ Module packages carry **publisher** and **integrity** metadata so installation,
**`scripts/module-verify-policy.sh`** (`VERIFY_MODULES_STRICT`, `VERIFY_MODULES_PR`,
`VERIFY_MODULES_PUSH_ORCHESTRATOR`).
- **Strict** (`VERIFY_MODULES_STRICT`): `--require-signature --enforce-version-bump --payload-from-filesystem`
— local **`main`** pre-commit, **`sign-modules.yml`** verify on **push** to `dev`/`main` (after auto-sign).
— local **`main`** pre-commit, **`pr-orchestrator.yml`** verify on pull requests targeting
**`main`** and pushes to **`main`**, and **`sign-modules.yml`** verify on **push** to `dev`/`main`
(after auto-sign).
- **PR / feature relaxed** (`VERIFY_MODULES_PR`): `--enforce-version-bump --skip-checksum-verification`
— pre-commit on non-`main`, **`pr-orchestrator.yml`** verify job on **pull_request**, **`sign-modules.yml`**
verify on **pull_request** / **workflow_dispatch** (version discipline vs base; checksum refresh in CI).
— pre-commit on non-`main`, **`pr-orchestrator.yml`** verify job on pull requests targeting
**`dev`**, and **`sign-modules.yml`** verify on **pull_request** / **workflow_dispatch**
(version discipline vs base; checksum refresh in CI).
- **Orchestrator push** (`VERIFY_MODULES_PUSH_ORCHESTRATOR`): `--enforce-version-bump --payload-from-filesystem`
— **`pr-orchestrator.yml`** verify job on **push** to `dev`/`main` (payload checksum + version; no
`--require-signature` in that job).
— **`pr-orchestrator.yml`** verify job on **push** to **`dev`** (payload checksum + version; no
`--require-signature` in that `dev` push path).
- **Approval-time signing** (`sign-modules-on-approval.yml`): on **approved** reviews for same-repo PRs
targeting **`dev` or `main`**, CI runs `pull_request.base.sha`’s **`scripts/sign-modules.py`**
(trusted revision) against the **PR head** working tree, then pushes updated `module-package.yaml`
Expand Down
4 changes: 2 additions & 2 deletions openspec/changes/cli-val-04-acceptance-test-runner/design.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ This change implements the runner that compiles CLI behavior scenarios (from cli

## Risks / Trade-offs

- [subprocess tests depend on installed binary] -> Mitigation: CI installs via `pip install -e .` before running black-box tests
- [subprocess tests depend on installed binary] -> Mitigation: CI builds a wheel and installs that wheel into an isolated environment before running black-box tests; editable installs are allowed only for local fast feedback
- [Subprocess tests are slower] -> Mitigation: mark as `blackbox` for selective execution; fast path covers most validation
- [Context setup complexity] -> Mitigation: start with 3 simple context types; extend as needed

Expand All @@ -44,4 +44,4 @@ This change implements the runner that compiles CLI behavior scenarios (from cli
## Open Questions

- Whether to adopt Cram/Prysk/Scrut for the flagship tests in a future iteration
- Whether the black-box path should test the `specfact` or `specfact-cli` entry point (or both)
- Whether later release validation should add a published-package `uvx specfact-cli@<version>` leg after PR-time wheel validation is stable
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ The 73+ existing CliRunner tests prove commands work in-process. But SpecFact is

- **NEW**: Dual-path scenario runner in `tools/cli_acceptance_runner.py` that reads YAML scenarios from cli-val-01 and executes them via:
- Fast path: `typer.testing.CliRunner` (for development speed)
- Black-box path: `subprocess.run()` against the installed `specfact` binary (for CI/release validation)
- Black-box path: `subprocess.run()` against a built-wheel installation of the `specfact` and `specfact-cli` binaries (for CI/release validation)
- **NEW**: Acceptance test file `tests/e2e/test_cli_acceptance.py` wiring the runner into pytest collection
- **NEW**: Small set of Cram-style `.t` or Markdown acceptance tests for 3-5 flagship command chains (living documentation + executable tests)
- **EXTEND**: `pyproject.toml` with hatch scripts for fast-path and black-box acceptance runs
Expand All @@ -17,13 +17,13 @@ The 73+ existing CliRunner tests prove commands work in-process. But SpecFact is

### New Capabilities

- `acceptance-test-runner`: A dual-path test runner that executes CLI behavior scenarios from YAML files via CliRunner (fast, in-process) or subprocess (black-box, against installed binary). Supports workspace setup, exit code assertions, output pattern matching, and filesystem diff verification.
- `acceptance-test-runner`: A dual-path test runner that executes CLI behavior scenarios from YAML files via CliRunner (fast, in-process) or subprocess (black-box, against a built-wheel installed binary). Supports workspace setup, exit code assertions, output pattern matching, and filesystem diff verification.

## Impact

- **Affected specs**: No existing specs modified; new spec delta defines runner behavior
- **Affected code**: New tools/ and tests/ files only; no production CLI code changes
- **Integration points**: Consumes cli-val-01 YAML scenarios and cli-val-03 anti-patterns; consumed by cli-val-05 (CI gate runs black-box path)
- **Integration points**: Consumes cli-val-01 YAML scenarios and cli-val-03 anti-patterns; consumed by cli-val-05 (CI gate builds a wheel and runs the black-box path)
- **Documentation impact**: Developer guide update describing acceptance test workflow and how to add new scenarios

## Dependencies
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

### Requirement: Dual-Path Scenario Execution

The system SHALL execute CLI behavior scenarios via both in-process (CliRunner) and subprocess (installed binary) paths.
The system SHALL execute CLI behavior scenarios via both in-process (CliRunner) and subprocess (built-wheel installed binary) paths.

#### Scenario: Fast path executes scenario via CliRunner

Expand All @@ -14,11 +14,12 @@ The system SHALL execute CLI behavior scenarios via both in-process (CliRunner)

#### Scenario: Black-box path executes scenario via subprocess

- **GIVEN** a YAML scenario file and the `specfact` binary is installed on PATH
- **GIVEN** a YAML scenario file and the built wheel has been installed into an isolated environment
- **WHEN** the runner executes the scenario in black-box mode
- **THEN** the scenario is invoked via `subprocess.run()`
- **AND** real exit code, stdout, and stderr are captured and asserted
- **AND** the test validates the installed binary, not the source tree.
- **AND** both `specfact` and `specfact-cli` entry points can be validated
- **AND** the test validates the built artifact, not an editable source install.

#### Scenario: Filesystem diff verification in sandboxed workspace

Expand Down
Loading
Loading