Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
540 commits
Select commit Hold shift + click to select a range
09688de
docs: remove generated project plan docs
djm81 Mar 20, 2026
f7cca1e
Merge branch 'main' into dev
djm81 Mar 20, 2026
f4e91be
Add code-review change
djm81 Mar 20, 2026
37dfecb
fix: preserve native backlog import payloads (#429)
djm81 Mar 20, 2026
b54aaa6
fix: add docs review workflow and repair docs links (#428)
djm81 Mar 20, 2026
ae7f05c
fix: keep imported change ids stable across title changes (#431)
djm81 Mar 20, 2026
7449714
Merge branch 'main' into dev
djm81 Mar 20, 2026
65726fb
fix: remove conflicting pages file copies
djm81 Mar 20, 2026
fbb3b83
Merge branch 'main' into dev
djm81 Mar 20, 2026
c6c47fc
Add docs sync changs
djm81 Mar 20, 2026
eaa87ac
docs: update openspec clean-code planning
djm81 Mar 22, 2026
f602dba
Update change status
djm81 Mar 22, 2026
58314e5
fix: code-review-zero-findings dogfood remediation (v0.42.3) (#435)
djm81 Mar 23, 2026
fb3c5fd
Merge branch 'main' into dev
djm81 Mar 23, 2026
2809390
Add docs refactoring changes
djm81 Mar 23, 2026
215df59
Add bug change tracking for encoding and resources
djm81 Mar 24, 2026
2a60f15
docs: restructure core site IA to 6-section progressive nav (#442)
djm81 Mar 24, 2026
81bca26
fix: harden cross-platform runtime and IDE resource discovery (#443)
djm81 Mar 24, 2026
852f446
fix: resolve review type-safety findings
djm81 Mar 24, 2026
2bbde33
Merge branch 'main' into dev
djm81 Mar 24, 2026
8272233
Improve clarity and scope of ide prompt change
djm81 Mar 25, 2026
2f0675c
feat(init): IDE prompt source catalog, --prompts, namespaced exports …
djm81 Mar 25, 2026
278142e
fix tests
djm81 Mar 25, 2026
38a9d21
release: bump version to 0.42.5 and update CHANGELOG
djm81 Mar 25, 2026
f552107
Fix review findings
djm81 Mar 25, 2026
dab2ffe
feat(init): selective IDE prompt export cleanup and VS Code recommend…
djm81 Mar 25, 2026
fbb2307
Fix review findings
djm81 Mar 25, 2026
71e760b
Merge branch 'main' into dev
djm81 Mar 25, 2026
41dc0db
Add missing import
djm81 Mar 25, 2026
2b26098
Bump patch version and changelog
djm81 Mar 25, 2026
90da7da
Fix failed tests
djm81 Mar 25, 2026
1eca7a9
Fix review findings
djm81 Mar 25, 2026
07c19b4
Merge branch 'main' into dev
djm81 Mar 26, 2026
db4ddc3
docs: core vs modules URL contract and OpenSpec alignment (#448)
djm81 Mar 26, 2026
96f35d7
feat(docs-12): docs command validation and cross-site link checks (#449)
djm81 Mar 26, 2026
f11cb9e
fix(scripts): CliRunner without mix_stderr for Click 8.3+ compatibili…
djm81 Mar 26, 2026
7ccb122
fix: review gates (semgrep print, radon CC, icontract, questionary ty…
djm81 Mar 26, 2026
d516657
Merge branch 'main' into dev
djm81 Mar 26, 2026
86bdc7c
Add speckit adapter alignment change and update affected change specs
djm81 Mar 27, 2026
f92c820
feat(adapters): spec-kit v0.4.x adapter alignment (#454)
djm81 Mar 27, 2026
dd1e359
chore: bump version to 0.43.0 for spec-kit v0.4.x alignment (#455)
djm81 Mar 27, 2026
eec640e
fix(packaging): remove workflow prompts from core wheel (packaging-02…
djm81 Mar 27, 2026
f7fefdd
Potential fix for pull request finding 'Empty except'
djm81 Mar 28, 2026
280d158
Merge branch 'main' into dev
djm81 Mar 28, 2026
0cc2c3c
Fix changelog version
djm81 Mar 28, 2026
c1c2e47
docs: unify core docs portal UX (#459)
djm81 Mar 28, 2026
ce49cd5
Harden docs home URL test assertion
djm81 Mar 28, 2026
cb08cbb
Merge branch 'main' into dev
djm81 Mar 29, 2026
715d472
feat: doc frontmatter validation, v0.43.2 review JSON gate, and pre-c…
djm81 Mar 29, 2026
edc89a7
docs: archive doc-frontmatter-schema openspec change
djm81 Mar 29, 2026
85572f2
Apply suggestions from code review
djm81 Mar 29, 2026
117d568
fix: restore protocol stubs for type checking
djm81 Mar 29, 2026
582a53c
Add frontamtter check
djm81 Mar 29, 2026
4c4ef24
fix: harden protocol stubs for code quality
djm81 Mar 29, 2026
52ee695
Add PR test hardening change
djm81 Mar 29, 2026
644474a
fix: remediate review findings and harden review gates
djm81 Mar 30, 2026
3eff782
fix: rebuild review report model for pydantic
djm81 Mar 30, 2026
e44f15a
Merge branch 'main' into dev
djm81 Mar 30, 2026
93ff11e
Add story and onboarding change
djm81 Mar 30, 2026
506679e
Update change tracking
djm81 Mar 30, 2026
f84aa39
Improve scope for ci/cd requirements
djm81 Mar 30, 2026
11391c9
docs: sharpen first-contact story and onboarding (#467)
djm81 Mar 30, 2026
0fc5f1f
fix: harden review blockers and bump patch version
djm81 Mar 30, 2026
ab42fd0
test: harden modules docs url assertions
djm81 Mar 30, 2026
93b6dee
Merge branch 'main' into dev
djm81 Mar 30, 2026
c5efee3
fix: harden trustworthy green checks (#469)
djm81 Mar 30, 2026
30c70f3
fix: address CodeRabbit review findings for ci-02 (#471)
djm81 Mar 30, 2026
7709718
fix: propagate docker actionlint exit code instead of masking failure…
djm81 Mar 30, 2026
1ffdace
fix: assert hook id stability and cd to repo root for local actionlin…
djm81 Mar 30, 2026
4dcf207
Merge branch 'main' into dev
djm81 Mar 30, 2026
9dbe9d4
feat: clean-code-01-principle-gates — 7-principle charter gates, v0.4…
djm81 Mar 31, 2026
9855d35
feat: archive completed openspec changes and update main specs
djm81 Mar 31, 2026
e9e75d4
Merge branch 'main' into dev
djm81 Mar 31, 2026
6663324
Add new user onboarding change
djm81 Apr 1, 2026
b4a7ecf
docs & tooling: new user onboarding + smart-test and pre-commit revie…
djm81 Apr 2, 2026
e87058b
fix: code-review gate (Typer params), typer<0.24 vs semgrep, module u…
djm81 Apr 3, 2026
9696489
docs: restructure README for star conversion (#480)
djm81 Apr 3, 2026
8fe4a26
Merge branch 'main' into dev
djm81 Apr 3, 2026
903b131
Merge branch 'main' into dev
djm81 Apr 5, 2026
f1f1919
archived implemented changes
djm81 Apr 5, 2026
17ac397
Archive and remove outdated changes
djm81 Apr 5, 2026
9900b72
Split and refactor change proposals between both repos
djm81 Apr 8, 2026
2a73434
Merge remote-tracking branch 'origin/main' into dev
djm81 Apr 8, 2026
e8c3848
Archive alignment change
djm81 Apr 8, 2026
98cf86e
Merge branch 'main' into dev
djm81 Apr 8, 2026
5b5bac7
Add changes and github hierarchy scripts
djm81 Apr 9, 2026
280ac57
feat: add GitHub hierarchy cache sync (#492)
djm81 Apr 9, 2026
1b314a1
[codex] Compact agent governance loading (#493)
djm81 Apr 10, 2026
647ce0c
Archived github hierarchy change
djm81 Apr 10, 2026
338aa92
Update from dev
djm81 Apr 10, 2026
c5083cf
Update rules for openspec archive
djm81 Apr 10, 2026
74c566b
Potential fix for pull request finding 'Unused local variable'
djm81 Apr 10, 2026
685bd4e
Add wiki update notes
djm81 Apr 10, 2026
fdcc51a
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 Apr 10, 2026
6c9f03b
Archive governance-03 change, format markdown, add wiki instructions …
djm81 Apr 10, 2026
de48d48
Fix review findings
djm81 Apr 10, 2026
186120e
Fix type errors
djm81 Apr 10, 2026
73b8f48
Merge branch 'main' into dev
djm81 Apr 10, 2026
951f3ae
fix: safe VS Code settings merge and project artifact writes (#490) (…
djm81 Apr 12, 2026
14f3b41
Fix review findings (#498)
djm81 Apr 12, 2026
6096c3c
feat(openspec): add marketplace-06-ci-module-signing change proposal
djm81 Apr 13, 2026
448328b
chore(pre-commit): modular hooks + branch-aware module verify (#501)
djm81 Apr 14, 2026
f7e3fd2
apply code review fixes
djm81 Apr 14, 2026
96879a9
apply code review fixes
djm81 Apr 14, 2026
cdf7e4d
merge: integrate origin/dev with local PyPI pre-commit and type-check…
djm81 Apr 14, 2026
29fdca8
merge: integrate origin/main into dev (conflicts resolved favoring dev)
djm81 Apr 14, 2026
3ffec56
fix(pre-commit): include staged deletions in staged_files() for Block 2
djm81 Apr 14, 2026
95ccde3
Fix review findings
djm81 Apr 14, 2026
c8a1116
Fix code review findings
djm81 Apr 14, 2026
b9b8691
feat(ci): module signing on PR approval and manual workflow_dispatch …
djm81 Apr 14, 2026
01e7351
Feature/ci module sign on approval (#504)
djm81 Apr 14, 2026
b2cc72f
feat(ci): workflow_dispatch for sign-modules-on-approval (#505)
djm81 Apr 14, 2026
a1dda6d
fix(ci): module signing workflows, PyPI version check, and review gate
djm81 Apr 14, 2026
85e7b5a
fix(modules): bump init to 0.1.28 for enforce-version-bump on dev
djm81 Apr 14, 2026
e7efd7d
Merge branch 'main' into dev
djm81 Apr 14, 2026
e61a8a2
chore(release): v0.46.2 — require signatures on all PRs to main
djm81 Apr 14, 2026
1ceddab
sign changed package
djm81 Apr 14, 2026
48ea131
fix(modules): bump init to 0.1.29 for dev→main PR version gate
djm81 Apr 14, 2026
7e9504e
Signed modules and bumped version
djm81 Apr 14, 2026
b34f9fb
Signed modules and bumped version
djm81 Apr 14, 2026
55c4c97
Fix sign flow
djm81 Apr 14, 2026
7091747
Merge branch 'main' into dev
djm81 Apr 15, 2026
5d0d82f
feat: dep-security-cleanup (license gate, pycg, commentjson, review e…
djm81 Apr 16, 2026
01d1bb1
apply review findings
djm81 Apr 16, 2026
5125725
Fix publish module and security gate findings
djm81 Apr 16, 2026
4df303c
Fix findings and publish bug
djm81 Apr 16, 2026
bbea309
Fix review findings and publish modules flow
djm81 Apr 16, 2026
1c1624d
Update publish and sign flows
djm81 Apr 16, 2026
e69ea29
Update publish and sign flows
djm81 Apr 16, 2026
ef07858
chore(modules): auto-sign bundled manifests [skip ci] (#510)
github-actions[bot] Apr 16, 2026
daa73c6
Apply code review findings
djm81 Apr 16, 2026
e62d223
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 Apr 16, 2026
1e255e5
Fix failed tests
djm81 Apr 16, 2026
ce3bbb4
[codex] Add five-pillar governance OpenSpec wave (#531)
djm81 Apr 19, 2026
f48b156
[codex] stabilize module install and init state (#535)
djm81 Apr 28, 2026
0200ba5
chore(modules): auto-sign bundled manifests [skip ci] (#536)
github-actions[bot] Apr 28, 2026
b6505f4
Merge branch 'main' into dev
djm81 Apr 28, 2026
d0eb4a4
fix: remove unused checksum tuple in verifier
djm81 Apr 28, 2026
be171d3
chore: reduce low-signal coderabbit review noise
djm81 Apr 28, 2026
73741e4
fix: address codex review findings
djm81 Apr 28, 2026
d209150
fix: tighten local gate scope and module verification
djm81 Apr 28, 2026
01702e6
Merge branch 'main' into dev
djm81 Apr 28, 2026
9b7d968
Make `specfact upgrade` install-method-aware (uv/uvx support, pipx/pi…
djm81 May 3, 2026
3f349fc
chore(modules): auto-sign bundled manifests [skip ci] (#540)
github-actions[bot] May 3, 2026
7179e77
fix(upgrade): prefer pipx before uv tool detection
djm81 May 3, 2026
6e65c7d
fix(upgrade): address PR 541 review findings
djm81 May 3, 2026
88f3d90
fix(cli,upgrade): address PR 541 critical findings
djm81 May 3, 2026
082dc06
Update module manifest from main
djm81 May 3, 2026
990d1e8
chore(modules): auto-sign bundled manifests [skip ci] (#546)
github-actions[bot] May 3, 2026
cb00a4b
Fix module upgrade signature and version bump
djm81 May 3, 2026
27afdb5
Fix signature
djm81 May 3, 2026
d470837
chore(modules): auto-sign bundled manifests [skip ci] (#548)
github-actions[bot] May 3, 2026
86e7e70
fix(ci): terminate module publish output list
djm81 May 3, 2026
8a0aa0d
Merge branch 'main' into dev
djm81 May 3, 2026
bed4721
fix(cli): forward bare lazy subcommands (#549)
djm81 May 3, 2026
11a5e1e
Merge branch 'main' into dev
djm81 May 3, 2026
7724ea6
chore(openspec): park 21 deferred proposals + simplify CHANGE_ORDER (…
djm81 May 6, 2026
197c0d1
Ignore claude settings.json
djm81 May 6, 2026
8000f06
docs: refine telemetry change to active opt-in (#555)
djm81 May 6, 2026
a7a5336
Merge branch 'main' into dev
djm81 May 6, 2026
469af46
fix runtime module discovery reliability (#558)
djm81 May 7, 2026
fab4fa6
chore(modules): auto-sign bundled manifests [skip ci] (#559)
github-actions[bot] May 7, 2026
694fdb2
Merge branch 'main' into dev
djm81 May 8, 2026
abc2db1
Merge branch 'dev' of https://github.com/nold-ai/specfact-cli into dev
djm81 May 8, 2026
a021c53
Merge branch 'main' into dev
djm81 May 8, 2026
4f38ece
[codex] Add module scope version diagnostics (#566)
djm81 May 14, 2026
0c25c8a
chore(modules): auto-sign bundled manifests [skip ci] (#567)
github-actions[bot] May 14, 2026
4322275
fix: address module dependency review findings
djm81 May 17, 2026
3b0f198
fix: address dependency review follow-ups
djm81 May 17, 2026
59be197
Fix dependency resolver bounds and bundle dependency validation
djm81 May 17, 2026
f32da81
Merge branch 'main' into dev
djm81 May 17, 2026
3b13b54
Fix bundled module publish summary quoting
djm81 May 17, 2026
09e3c25
Merge branch 'main' into dev
djm81 May 20, 2026
3f74602
fix(upgrade): suppress benign pipx spaced-home warning (#574)
djm81 May 20, 2026
4ccb2d0
chore(bundled-modules): snapshot from dev@3f74602 (#576)
github-actions[bot] May 20, 2026
5394186
chore(modules): auto-sign bundled manifests [skip ci] (#575)
github-actions[bot] May 20, 2026
717c74d
fix(upgrade): tolerate undecodable child output
djm81 May 20, 2026
15b507c
chore(modules): auto-sign bundled manifests [skip ci] (#578)
github-actions[bot] May 20, 2026
e7b13db
chore(bundled-modules): snapshot from dev@717c74d (#579)
github-actions[bot] May 20, 2026
7d88cb6
Fix registry
djm81 May 20, 2026
b58f924
fix: keep core bundled registry URLs scoped (#580)
djm81 May 20, 2026
edc9651
chore(release): prepare core cli 0.46.28 (#582)
djm81 May 21, 2026
5d5ce89
Merge branch 'main' into dev
djm81 May 21, 2026
03b742f
Merge branch 'main' into dev
djm81 May 21, 2026
47f8e19
Harden CLI command reliability gates (#595)
djm81 Jun 1, 2026
8118ff2
chore(modules): auto-sign bundled manifests [skip ci] (#596)
github-actions[bot] Jun 1, 2026
c6b57a8
chore(bundled-modules): snapshot from dev@47f8e19 (#597)
github-actions[bot] Jun 1, 2026
a711057
fix: align release command validation with modules dev
djm81 Jun 1, 2026
06afb70
fix: tolerate code import alias help ambiguity
djm81 Jun 1, 2026
7e5b1c2
chore(fix): Fix code review findings and PR failure
djm81 Jun 2, 2026
82ed1ba
chore: fix PR 598 validation failures
djm81 Jun 2, 2026
9837a13
chore(modules): auto-sign bundled manifests [skip ci] (#599)
github-actions[bot] Jun 2, 2026
ed37663
chore(bundled-modules): snapshot from dev@82ed1ba (#600)
github-actions[bot] Jun 2, 2026
c4fd804
Merge branch 'main' into dev
djm81 Jun 2, 2026
b298fc1
docs: position SpecFact as AI-bloat defense CLI (#601)
djm81 Jun 2, 2026
dcc5a03
chore: archive completed docs OpenSpec change (#603)
djm81 Jun 2, 2026
c3d6c68
Archive upgrade-01 change
djm81 Jun 2, 2026
c8faa8f
Merge branch 'main' into dev
djm81 Jun 2, 2026
89df5ec
Fix conflict
Jun 6, 2026
9266fa9
add cli fix change
Jun 9, 2026
913f089
Ignore agent skills meant for local only
Jun 12, 2026
65608b4
Fix merge conflict
Jun 12, 2026
0e3c4d3
fix: replace stale flat command references and guard llms.txt freshne…
djm81 Jun 12, 2026
5308d1e
Don't ignore openspec workflow rules
Jun 12, 2026
da416b9
Tighten CI gates and module verification (#609)
djm81 Jun 13, 2026
09e95cf
Merge branch 'main' into dev
djm81 Jun 13, 2026
0a5f8d9
: use checked-in semgrep sast config
djm81 Jun 13, 2026
65dfe70
fix: harden pr gate remediation
djm81 Jun 13, 2026
10dda75
chore(modules): auto-sign bundled manifests (#611)
github-actions[bot] Jun 13, 2026
8fa6886
chore(modules): auto-sign bundled manifests (#613)
github-actions[bot] Jun 13, 2026
8b5fd59
chore(bundled-modules): snapshot from dev@8fa6886 (#615)
github-actions[bot] Jun 13, 2026
3154509
fix: refresh module consoles before install tests
djm81 Jun 13, 2026
66bca99
chore(modules): auto-sign bundled manifests (#616)
github-actions[bot] Jun 13, 2026
d568987
chore(bundled-modules): snapshot from dev@3154509 (#617)
github-actions[bot] Jun 13, 2026
ed2e2b7
chore(modules): auto-sign bundled manifests (#618)
github-actions[bot] Jun 13, 2026
30971b6
chore(bundled-modules): snapshot from dev@ed2e2b7 (#619)
github-actions[bot] Jun 13, 2026
519a599
test: avoid brittle bundle install capture
djm81 Jun 14, 2026
0853fde
chore(modules): auto-sign bundled manifests (#620)
github-actions[bot] Jun 14, 2026
ee041a9
chore(bundled-modules): snapshot from dev@519a599 (#621)
github-actions[bot] Jun 14, 2026
7705853
chore(modules): auto-sign bundled manifests (#622)
github-actions[bot] Jun 14, 2026
ead57ea
chore(bundled-modules): snapshot from dev@7705853 (#623)
github-actions[bot] Jun 14, 2026
890a5c9
feat(init): add validation profile layering (#624)
djm81 Jul 6, 2026
1ba3499
docs: add agent behavioral defaults
djm81 Jul 6, 2026
624b4ca
chore(modules): auto-sign bundled manifests (#625)
github-actions[bot] Jul 6, 2026
0d3b889
chore(bundled-modules): snapshot from dev@890a5c9 (#626)
github-actions[bot] Jul 6, 2026
625917e
chore(modules): auto-sign bundled manifests (#627)
github-actions[bot] Jul 6, 2026
f3d3ea5
chore(bundled-modules): snapshot from dev@625917e (#628)
github-actions[bot] Jul 6, 2026
d3a55a3
Merge branch 'main' into dev
djm81 Jul 7, 2026
c7b6719
Add requirements evidence input model (#630)
djm81 Jul 7, 2026
3803860
fix: address promotion review feedback
djm81 Jul 7, 2026
b3db513
chore: bump version after promotion fix
djm81 Jul 7, 2026
e034d40
docs: address requirements spec review
djm81 Jul 7, 2026
c630133
feat: add requirements context adapter (#632)
djm81 Jul 8, 2026
f80a769
docs: align use-case claims with validation-evidence positioning (#633)
djm81 Jul 8, 2026
35592a1
fix: address release review feedback
djm81 Jul 8, 2026
a2723c4
Merge remote-tracking branch 'origin/main' into dev
djm81 Jul 8, 2026
17d8964
fix: finalize release review cleanup
djm81 Jul 8, 2026
95e327a
chore: bump release to 0.50.1
djm81 Jul 8, 2026
1647522
docs: address release review scope comments
djm81 Jul 8, 2026
d647b9a
Merge branch 'main' into dev
djm81 Jul 8, 2026
b75f524
fix: mount requirements module command
djm81 Jul 8, 2026
ae93405
fix: include requirements in init bundles
djm81 Jul 8, 2026
754eca5
docs: document requirements marketplace bundle
djm81 Jul 8, 2026
cd797a4
chore(modules): auto-sign bundled manifests (#636)
github-actions[bot] Jul 8, 2026
05467e5
chore(bundled-modules): snapshot from dev@ae93405 (#637)
github-actions[bot] Jul 8, 2026
1d0d15a
chore(modules): auto-sign bundled manifests (#638)
github-actions[bot] Jul 8, 2026
813c54b
chore(bundled-modules): snapshot from dev@1d0d15a (#640)
github-actions[bot] Jul 8, 2026
dc05112
Merge branch 'main' into dev
djm81 Jul 9, 2026
53f0c70
feat(validation): complete evidence trace core (#641)
djm81 Jul 9, 2026
a264d81
fix(validation): harden evidence contracts
djm81 Jul 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,28 @@ All notable changes to this project will be documented in this file.

---

## [0.51.1] - 2026-07-10

### Fixed

- **Requirements traceability drift**: do not classify linked requirements as
stale when callers have not supplied the target universe; stale-link drift
remains enabled when `known_targets` is provided.

---

## [0.51.0] - 2026-07-09

### Added

- **Core evidence and traceability contracts**: add a typed evidence envelope
with deterministic CI verdict derivation plus a generic artifact index,
stable links/fingerprints, incremental rebuild facts, and deterministic
orphan/drift/ambiguity/contradiction classification. Requirements is the
first integrated adapter; runtime persistence and commands remain deferred.

---

## [0.50.2] - 2026-07-08

### Fixed
Expand Down
1 change: 1 addition & 0 deletions docs/reference/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ For bundle-specific deep command guides and runbooks, use the canonical modules
- **[Bridge Registry](bridge-registry.md)** - Registry-facing bridge converter declarations
- **[Requirements Evidence Input Model](requirements-evidence-input-model.md)** - Requirement input records used by validation evidence
- **[Requirements Context Adapter](requirements-context-adapter.md)** - Import, validation, and coverage helpers for requirement context evidence
- **[Validation Evidence Contracts](validation-evidence-contracts.md)** - Core envelope and traceability result contracts
- **[Directory Structure](directory-structure.md)** - Project structure and organization
- **[Feature Keys](feature-keys.md)** - Key normalization and formats
- **[Dependency Resolution](dependency-resolution.md)** - Module/pip dependency resolution behavior
Expand Down
9 changes: 7 additions & 2 deletions docs/reference/requirements-context-adapter.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@ requirements authoring workflow.
usefulness by profile.
- `inspect_requirement_context_coverage(...)` returns machine-readable coverage
counts for downstream command handlers.
- `analyze_requirement_traceability(...)` reads `requirements.inputs`; when
callers supply `known_targets`, it also returns deterministic stale-link drift
findings for evidence consumers.

```python
from specfact_cli.models.requirements import RequirementInput, RequirementSourceReference
Expand Down Expand Up @@ -73,7 +76,9 @@ payloads directly inside root CLI code.
reference.
- Invalid imported records produce bounded diagnostics; valid records remain
usable.
- Enterprise or strict validation treats missing downstream evidence links as
errors. Less strict profiles receive warnings.
- Enterprise, strict, and enterprise_full_stack validation treat missing
downstream evidence links as errors. Less strict profiles receive warnings.
- Backlog write-back and interactive requirement authoring remain outside this
core surface.
- Evidence files, CI flags, terminal rendering, and query commands are owned by
paired module runtimes rather than core.
38 changes: 38 additions & 0 deletions docs/reference/validation-evidence-contracts.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
---
layout: default
title: Validation Evidence Contracts
permalink: /reference/validation-evidence-contracts/
description: Core contracts for deterministic validation evidence and requirements-first traceability.
keywords: [validation, evidence, traceability, requirements]
audience: [team, enterprise]
expertise_level: [advanced]
doc_owner: specfact-cli
tracks:
- src/specfact_cli/evidence.py
- src/specfact_cli/traceability.py
last_reviewed: 2026-07-09
exempt: false
exempt_reason: ""
---

# Validation Evidence Contracts

Core exposes typed contracts only. Module runtimes own command flags, evidence
file persistence, and rendering.

- `EvidenceEnvelope` derives `PASS`, `PASS_WITH_ADVISORY`, or `FAIL` and its CI
exit code from typed result summaries.
- `ArtifactRecord`, `ArtifactLink`, and `build_artifact_index(...)` provide a
generic, deterministic, JSON-serializable index for normalized inputs from
requirements, architecture, specifications, code, tests, contracts, and other
adapters.
- The index classifies unlinked artifacts, dangling links, duplicate identities,
and self-referential contradictions; rebuild results report changed and
removed identities.
- `requirements_to_artifact_records(...)` is the first integrated adapter.
Architecture and other inputs are optional; their absence does not create a
finding.

Use these contracts as inputs to validation and governance modules; they do not
introduce a `specfact trace` command, index-file persistence, or requirements
authoring workflow.
7 changes: 4 additions & 3 deletions openspec/CHANGE_ORDER.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,12 +51,13 @@ into auditable validation evidence and cleanup feedback.
| 1 | `profile-01-config-layering` | [#237](https://github.com/nold-ai/specfact-cli/issues/237) | Rollout modes for validation severity and evidence strictness | - |
| 2 | `governance-01-evidence-output` | [#247](https://github.com/nold-ai/specfact-cli/issues/247) | Evidence JSON, CI verdicts, remediation packet attachment points | modules `policy-02` |
| 3 | `governance-02-exception-management` | [#248](https://github.com/nold-ai/specfact-cli/issues/248) | Time-bound validation exceptions and waiver evidence | governance-01; modules `policy-02` |
| 4 | `traceability-01-index-and-orphans` | [#242](https://github.com/nold-ai/specfact-cli/issues/242) | Artifact drift and orphan detection across inputs | requirements/architecture adapter contracts where present |
| 4 | `traceability-01-index-and-orphans` | [#242](https://github.com/nold-ai/specfact-cli/issues/242) | Generic artifact index and orphan/drift classification across normalized inputs | requirements input contracts; other adapters optional when present |
Comment thread
coderabbitai[bot] marked this conversation as resolved.
| 5 | `validation-02-full-chain-engine` | [#241](https://github.com/nold-ai/specfact-cli/issues/241) | Validation evidence graph over existing inputs, not a product lifecycle engine | governance-01, traceability-01 |
| 6 | `dogfooding-01-full-chain-e2e-proof` | [#255](https://github.com/nold-ai/specfact-cli/issues/255) | AI-bloat defense and validation proof on real PRs | governance-01, validation-02, traceability-01 |

**Critical path**: profile-01 plus governance-01 -> traceability-01 ->
validation-02 -> dogfooding proof.
**Critical path**: profile-01, governance-01, and traceability-01 converge at
validation-02 -> dogfooding proof. Traceability requires requirements inputs;
governance and traceability do not block each other.

### Track B - AI IDE Validation Distribution

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
## MODIFIED Requirements
## ADDED Requirements

### Requirement: Backlog Adapter
### Requirement: Source-Attributed Backlog Requirement Snippets

The system SHALL define source-attributed backlog requirement snippets that
requirements runtime adapters can normalize without provider-specific parsing in
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
## MODIFIED Requirements
## ADDED Requirements

### Requirement: Module Io Contract
### Requirement: Requirements Module IO Contract

Requirements implementations SHALL consume core requirements context adapter
helpers through the existing `ModuleIOContract` boundary.
Expand Down
31 changes: 19 additions & 12 deletions openspec/changes/governance-01-evidence-output/proposal.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,9 +17,19 @@ validation results consumable by any deterministic gate or agent handoff.
- Target modules-repo follow-up issue: [#169](https://github.com/nold-ai/specfact-cli-modules/issues/169) in `nold-ai/specfact-cli-modules`
- Downstream changes may extend the envelope, but they MUST NOT redefine the schema or imply core ownership of bundle runtime behavior.

## Core Slice (2026-07-09)

- This change delivers the typed envelope, result semantics, and deterministic CI
verdict derivation only.
- Runtime flags, file persistence, terminal rendering, and emitters remain
deferred to modules issue #169.
- `validation-02` is a downstream producer of envelope sections, not a
prerequisite for this core contract.
Comment thread
coderabbitai[bot] marked this conversation as resolved.

## What Changes

- **NEW**: Evidence writer producing standardized JSON artifacts:
- **NEW**: Typed evidence-envelope schema and field semantics for the
standardized JSON shape consumed by runtime emitters:
Comment on lines +31 to +32

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Align the canonical envelope example with the implemented core contract.

The example still presents run_id, timestamp, policy_mode, coverage, exceptions, and ci_exit_code as part of this core schema, while src/specfact_cli/evidence.py:36-67 currently defines only the typed validation envelope and derived overall_verdict. Remove those fields from the core example or explicitly mark them as module-owned extensions with their serialization contract; otherwise consumers may depend on fields core never emits.

As per path instructions, OpenSpec artifacts are the specification source of truth and must match implementation behavior and contract boundaries.

Also applies to: 64-69

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@openspec/changes/governance-01-evidence-output/proposal.md` around lines 31 -
32, The canonical envelope example in the proposal must match the core contract
implemented by the evidence schema. Update the example and related
field-semantics sections to remove run_id, timestamp, policy_mode, coverage,
exceptions, and ci_exit_code, or explicitly label them as module-owned
extensions with defined serialization rules; retain only fields represented by
the typed validation envelope and derived overall_verdict in
src/specfact_cli/evidence.py.

Source: Path instructions


```json
{
Expand Down Expand Up @@ -51,26 +61,23 @@ validation results consumable by any deterministic gate or agent handoff.
}
```

- **NEW**: `--evidence-dir .specfact/evidence/` flag on validation and code-review runs to persist evidence artifacts per run
- **NEW**: `--ci-mode` flag that sets exit codes based on profile enforcement mode: advisory=always 0, mixed=1 for hard-fail rules only, hard=1 for any failure
- **NEW**: Evidence artifact naming: `{timestamp}_{run_id}_evidence.json` for audit trail
- **NEW**: Evidence summary on terminal: human-readable table alongside JSON output
- **EXTEND**: Validation evidence graph (validation-02) extended to produce evidence artifacts
- **EXTEND**: Validation evidence can append `code_quality` as a parallel section when the run includes review-based clean-code checks
- **EXTEND**: Policy engine results formatted as evidence-compatible structures
- **NEW**: Deterministic core CI verdict derivation from typed result summaries.
- **DEFERRED TO MODULES #169**: `--evidence-dir`, `--ci-mode`, file
persistence, artifact naming, terminal rendering, and command emitters.
- **DOWNSTREAM**: validation-02 and policy owners populate compatible envelope
sections; they do not change the core schema ownership.
- **NEW**: Ownership authority — this change is authoritative for evidence JSON envelope/schema; sibling governance changes may add fields only through this envelope contract.

## Capabilities

### New Capabilities

- `governance-evidence-output`: Machine-readable JSON evidence artifacts for CI/CD gates and audit systems, with per-run persistence, CI exit code modes, coverage percentages, exception status, and profile-aware verdicts.
- `governance-evidence-output`: Typed machine-readable evidence envelope and
deterministic CI verdict contract for CI/CD gates and audit consumers.

### Modified Capabilities

- `validation-evidence-graph`: Extended with evidence artifact generation via `--evidence-dir` and `--ci-mode` flags
- `policy-engine`: Results formatted as evidence-compatible structures with run_id and timestamps
- `governance-evidence-output`: Extended with a `code_quality` section that remains parallel to `validation_results` rather than introducing a new traceability layer
(none; runtime delivery and downstream producers remain separately owned)

---

Expand Down
2 changes: 1 addition & 1 deletion openspec/changes/governance-01-evidence-output/tasks.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@

- [ ] 3.1 Implement minimal production code required to satisfy the new scenarios.
- [ ] 3.2 Add/update contract decorators and type enforcement on public APIs.
- [ ] 3.3 Update command wiring, adapters, and models required by this change scope only.
- [ ] 3.3 Add the core envelope models and deterministic verdict derivation; do not add command wiring, emitters, or persistence.
- [ ] 3.4 Keep clean-code evidence as a sibling `code_quality` section in the envelope rather than adding a new validation layer.

## 4. Validation and documentation
Expand Down
2 changes: 1 addition & 1 deletion openspec/changes/profile-01-config-layering/proposal.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,6 @@ layering around validation.
<!-- source_repo: nold-ai/specfact-cli -->
- **GitHub Issue**: #237
- **Issue URL**: <https://github.com/nold-ai/specfact-cli/issues/237>
- **Last Synced Status**: implementation-ready / PR candidate on `feature/profile-01-config-layering-baseline`
- **Last Synced Status**: implemented in PR [#624](https://github.com/nold-ai/specfact-cli/pull/624); GitHub issue #237 closed on 2026-07-08.
- **Sanitized**: false
<!-- content_hash: d7dfe1519fa64668 -->
2 changes: 1 addition & 1 deletion openspec/changes/profile-01-config-layering/tasks.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,4 +29,4 @@
## 5. Delivery

- [x] 5.1 Confirm `openspec/CHANGE_ORDER.md` did not need status/dependency updates; implementation sequencing stayed unchanged.
- [ ] 5.2 Open a PR from `feature/profile-01-config-layering-baseline` to `dev` with spec/test/code/docs evidence.
- [x] 5.2 Merge PR [#624](https://github.com/nold-ai/specfact-cli/pull/624) to `dev` with spec/test/code/docs evidence; promotion to `main` remains pending release PR #642.
Original file line number Diff line number Diff line change
@@ -1,31 +1,78 @@
# Change Validation: traceability-01-index-and-orphans
# Change Validation Report: traceability-01-index-and-orphans

- **Validated on (UTC):** 2026-02-15T21:54:26Z
- **Workflow:** /wf-validate-change (proposal-stage dry-run validation)
- **Strict command:** `openspec validate traceability-01-index-and-orphans --strict`
- **Result:** PASS
**Validation Date**: 2026-07-09 (Europe/Berlin)
**Change Proposal**: [proposal.md](./proposal.md)
**Validation Method**: Dry-run interface and dependency analysis in
`/tmp/specfact-validation-traceability-01-index-and-orphans.R4HtLY`

## Scope Summary
## Executive Summary

- **New capabilities:** traceability-index
- **Modified capabilities:** (none)
- **Declared dependencies:** requirements-02 (requirements module), architecture-01 (architecture module)
- **Proposed affected code paths:** - `modules/trace/` (new module);- `.specfact/trace/index.json` (new generated artifact)
- Breaking changes: 0 detected / 0 unresolved
- Dependent files: 3 affected (`traceability.py` and its two unit-test modules)
- Impact level: Low
- Validation result: Pass
- User decision: Extend the change to complete generic core issue #242; keep
persistence and runtime UX in modules #170.

## Breaking-Change Analysis (Dry-Run)
## Interface and Dependency Analysis

- Interface changes are proposal-level only; no production code modifications were performed in this workflow stage.
- Proposed modified capabilities are additive/extension-oriented in the current spec deltas and do not require immediate breaking migrations at proposal time.
- Backward-compatibility risk is primarily sequencing-related (dependency ordering), not signature-level breakage at this stage.
The new public contract adds `ArtifactRecord`, `ArtifactLink`,
`ArtifactEvidenceIndex`, and `build_artifact_index(...)`. It does not change an
existing public function signature. The existing
`analyze_requirement_traceability(...)` helper remains available and delegates
to the generic index.

## Dependency and Integration Review
`TraceabilityResult` remains an alias for the returned model, and the legacy
`TraceabilityFinding.requirement_id` read surface remains available as a
compatibility property. Repository search found no production callers outside
`src/specfact_cli/traceability.py`; the two existing requirement-traceability
tests were updated for the generalized finding names.

- Dependency declarations align with the 2026-02-15 architecture layer integration plan sequencing.
- Cross-change integration points are explicitly represented in proposal/spec/task artifacts.
- No additional mandatory scope expansion was required to pass strict OpenSpec validation.
No downstream runtime command or persistence dependency is introduced. The
requirements adapter is the sole required integrated input. Missing
architecture records cannot produce a finding because classification considers
only supplied normalized records.

## Validation Outcome
## Required Updates

- Required artifacts are present: `proposal.md`, `design.md`, `specs/**/*.md`, `tasks.md`.
- Strict OpenSpec validation passed.
- Change is ready for implementation-phase intake once prerequisites are satisfied.
### Critical Updates

None.

### Completed Updates

- Added generic index tests for canonical ordering, all four classifications,
rebuild deltas, JSON serialization, and requirements mapping.
- Updated the traceability contract, proposal, design, task list, change order,
and validation-evidence reference documentation.
- Updated the internal wiki source and rebuilt its dependency graph.

## Impact Assessment

- **Code impact**: One core traceability module gains a generic, in-memory
index contract and compatibility adapter.
- **Test impact**: Existing requirements-only tests are retained; new unit
tests cover the generalized contract.
- **Documentation impact**: Public evidence-contract documentation now
distinguishes core index ownership from modules runtime delivery.
- **Release impact**: Minor (new public core contract; no removals).

## Format Validation

- **proposal.md format**: Pass
- **tasks.md format**: Pass; worktree, TDD, documentation, validation, and PR
tasks are explicit.
- **specs format**: Pass; each requirement uses Given/When/Then scenarios.
- **Config compliance**: Pass, subject to final repository quality gates.

## OpenSpec Validation

- **Status**: Pass
- **Command**: `openspec validate traceability-01-index-and-orphans --strict`
- **Issues found/fixed**: 0 / 0

## Scope Resolution

Core issue #242 is complete when this reusable artifact index is merged.
Modules issue #170 remains a separate delivery follow-up for persistence,
commands, flags, rendering, and query UX; it is not a core-issue blocker.
22 changes: 22 additions & 0 deletions openspec/changes/traceability-01-index-and-orphans/TDD_EVIDENCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# TDD Evidence: traceability-01-index-and-orphans

- Failing-before: `hatch run pytest tests/unit/traceability/test_evidence_traceability.py -q` — 2026-07-09 Europe/Berlin; failed during collection because `specfact_cli.traceability` did not exist.
- Passing-after: `hatch run pytest tests/unit/traceability/test_evidence_traceability.py -q` — 2026-07-09 Europe/Berlin; 3 passed.
- Failing-before generic-index expansion: `hatch run pytest tests/unit/traceability/test_artifact_index.py -q` — 2026-07-09 Europe/Berlin; failed during collection because the generic index contracts did not exist.
- Passing-after generic-index expansion: `hatch run pytest tests/unit/traceability -q` — 2026-07-09 Europe/Berlin; 7 passed after aligning the compatibility assertion to the generic finding taxonomy.

## Quality Gate Evidence

Verified 2026-07-10T00:41:51+0200 Europe/Berlin after Codex and CodeRabbit
remediation:

- `hatch run pytest tests/unit/traceability tests/unit/requirements/test_context_adapter.py -q` — PASS, 18 passed.
- `hatch run type-check` — PASS, 0 errors; 1,627 pre-existing baseline warnings.
- `hatch run docs-validate` and `hatch run yaml-lint` — PASS.
- `hatch run contract-test` — PASS.
- `hatch run bandit-scan`, `hatch run semgrep-sast --json`, and
`hatch run semgrep-sast-gate` — PASS, no blocking findings.
- `hatch run specfact code review run --json --out .specfact/code-review.json --scope changed` — PASS, no findings.
- `openspec validate traceability-01-index-and-orphans --strict`,
`openspec validate governance-01-evidence-output --strict`, and
`openspec validate profile-01-config-layering --strict` — PASS.
Loading
Loading