Skip to content

Adopt Trust 1 and SpecSync 5 - #52

Merged
0xLeif merged 16 commits into
mainfrom
0xleif/trust-1-rollout
Jul 14, 2026
Merged

Adopt Trust 1 and SpecSync 5#52
0xLeif merged 16 commits into
mainfrom
0xleif/trust-1-rollout

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt SpecSync 5.0.1 and its verified SDD lifecycle without changing product behavior.
  • Preserve the existing draft/review status and semantics of the ThreeMD, ThreeMDCLI, and ThreeMDElement contracts while assigning stable requirement IDs.
  • Install Claude, Cursor, Codex, and Gemini integrations and replace separate governance actions with the immutable Trust 1.0.0 gate.
  • Apply the final governance review corrections so public documentation is governed, policy/spec files cannot be broadly ignored, and multi-word interview answers are quoted in every generated agent skill.

Validation

  • All 51 requirement statements are concrete; no tautological or placeholder contract text remains.
  • Released SpecSync 5.0.1 passes normal and forced strict checks at 14/14 files and 2002/2002 LOC (100%).
  • All four agent integrations report installed.
  • Local Trust passes with progressive provenance.
  • Native Swift (129 tests), JavaScript (79 tests), Rust (1 integration and 3 documentation tests), generated-bundle, lint, build, and editor-grammar verification passes.
  • Trust runs for every governed public-documentation path.
  • SDD policy and canonical spec files cannot be exempted by broad ignore rules.
  • Every installed skill quotes multi-word interview answers.
  • Exact-head hosted Trust, Chromium/WebKit UI, and CodeQL checks pass.
  • All addressed review threads are resolved.

Scope

This is a governance migration only. It does not change product code, tests, packages, or dependencies. Existing unchecked spec tasks are concrete future product roadmap items, not migration placeholders.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request transitions the repository to SpecSync v5 and Trust 1.0.0, introducing verified SDD change lifecycles, native coding-agent integrations, and stable requirement identifiers (REQ-*) across ThreeMD modules. The review feedback highlights a few minor issues: the test directory path in .specsync/sdd.json should be capitalized as Tests/ to match Swift conventions and prevent CI case-sensitivity issues; several requirement files have the ### Non-Functional Requirements header incorrectly appended to the end of a paragraph; and the SKILL.md files contain an empty ## Companion files header that should be cleaned up.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread .specsync/sdd.json
Comment thread specs/ThreeMD/requirements.md Outdated
Comment thread specs/ThreeMDCLI/requirements.md Outdated
Comment thread specs/ThreeMDElement/requirements.md Outdated
Comment thread .codex/skills/spec-sync/SKILL.md
Comment thread .cursor/skills/spec-sync/SKILL.md

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d5e65b654f

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 65ccd666e9

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .gemini/commands/specsync/create-change.toml Outdated
Comment thread .cursor/commands/specsync-create-spec.md Outdated
Comment thread AGENTS.md
Comment thread .specsync/sdd.json Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ac7142a319

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread specs/ThreeMD/requirements.md Outdated
Comment thread .specsync/changes/CHG-0001-adopt-trust-1-and-specsync-5/state.json Outdated
Comment thread .specsync/sdd.json Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6249695b7

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .claude/commands/specsync/create-spec.md Outdated
Comment thread AGENTS.md
Comment thread .claude/commands/specsync/create-change.md Outdated
Comment thread .trust.toml
@0xLeif
0xLeif requested review from a team, 0xGaspar, Kyntrin and tofu-ux July 13, 2026 19:47

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8bb1f76a1e

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread fledge.toml
Comment thread .specsync/sdd.json

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2458e7d2e6

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment thread .codex/skills/spec-sync/SKILL.md Outdated
Comment thread .specsync/sdd.json Outdated
Comment thread .specsync/sdd.json
Comment thread .specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 20:54
@0xLeif
0xLeif marked this pull request as ready for review July 14, 2026 07:30
@0xLeif
0xLeif merged commit 7232b86 into main Jul 14, 2026
7 checks passed
@0xLeif
0xLeif deleted the 0xleif/trust-1-rollout branch July 14, 2026 07:31

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1916c06727

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment on lines +25 to +28
".specsync/sdd.json",
".specsync/config.toml",
".specsync/config.json",
".specsync/version",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Govern the SpecSync registry file

This policy now requires SDD coverage for only the listed .specsync files, but the repo also has .specsync/registry.toml mapping module names to their canonical specs. A future PR can change or delete registry entries without matching any meaningful_paths entry, so the required change workflow can be bypassed for the file that controls which specs are registered; include the registry file or an appropriate .specsync/ policy subset here.

Useful? React with 馃憤聽/ 馃憥.

Comment thread .specsync/sdd.json
"src/",
"tests/",
"site/",
".github/",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run Trust for meaningful issue-template edits

With the whole .github/ tree declared meaningful, updates to the existing .github/ISSUE_TEMPLATE/bug_report.md or spec_question.md files should require the same SDD/Trust coverage as other GitHub configuration. The Trust workflow still ignores .github/ISSUE_TEMPLATE/**; GitHub skips a workflow when every changed path matches paths-ignore, so an issue-template-only PR bypasses the required change coverage unless this ignore is removed or the SDD policy is narrowed.

Useful? React with 馃憤聽/ 馃憥.

Comment thread .specsync/sdd.json
Comment on lines +49 to +52
"fledge.toml",
".trust.toml",
".augur.toml",
".attest.json",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Cover the Swift formatter policy

The new SDD allowlist covers the Fledge and Trust configs, but it omits the root .swift-format file even though fledge.toml's lint task reads that formatter configuration on every verify run. A future PR can relax or break formatting rules without matching any meaningful path, bypassing the change lifecycle for CI-enforced project configuration; add .swift-format to the governed paths.

Useful? React with 馃憤聽/ 馃憥.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant