Skip to content

docs(specs): correct feature 009 docs that still call #263 open - #289

Merged
ValgulNecron merged 1 commit into
masterfrom
013-converge-009-doc-updates
Aug 30, 2026
Merged

docs(specs): correct feature 009 docs that still call #263 open#289
ValgulNecron merged 1 commit into
masterfrom
013-converge-009-doc-updates

Conversation

@ValgulNecron

Copy link
Copy Markdown
Owner

Implements Phase 13 (T075, T076) of feature 009, appended by the third /speckit-converge run.

Why

PR #263 (sigstore/sigstore 1.10.8 → 1.10.9) merged as 5291807 once T071 / PR #287 migrated operator/internal/verify/verify.go off the deprecated fulcioroots API and cleared the staticcheck SA1019 finding that had been failing lint (operator). Two feature-009 documents still described the pre-merge world.

Worse, quickstart.md had begun to contradict itself: the summary near the top said 18 merged, while the SC-002 acceptance ledger further down — the section a reader actually uses to verify SC-002 — still said 18 merged / 2 deferred. Anyone checking SC-002 today would have gotten the wrong answer.

What changed

quickstart.md — every current-state claim about #263 corrected. All count claims now agree:

merged 19 (#263 added, sorted between #264 and #262)
closed without merging 1 (#269)
deferred 1 (#272)
total 21

Both enumerated merged lists contain exactly 19 PR numbers, matching their stated counts; the Go/npm split is 9 + 10. The "#263 has 1 failing check, cause not yet diagnosed" special case is rewritten as the resolved outcome it now is.

contracts/dependency-upgrade.md — this is an append-only research record, so the superseded T035 disposition ("#263 stays open and unmerged") is left intact and a dated update note added beneath it.

Deliberately untouched: the "Historical baseline (2026-08-28)" list and the per-PR module inventory table, where #263 correctly appears as it was at the time. #272’s descriptions are unchanged — it is still genuinely blocked upstream.

Notes

  • Documentation only, entirely inside specs/009-remediate-security-dependabot/. No code, no go.mod, no package.json — so this PR is expected to show no CI checks.
  • Feature 009’s only remaining open tasks are T055/T056, blocked upstream: no published @typescript-eslint (including canary) accepts TypeScript 7, so npm ci fails at ERESOLVE before tsc runs.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SgeYHZV5dBRpRB1BTM5Pd1

The third /speckit-converge run on feature 009 found two documents
asserting a state the recent merges had falsified. PR #263
(sigstore/sigstore 1.10.8 -> 1.10.9) merged as 5291807 once T071/PR #287
migrated operator/internal/verify/verify.go off the deprecated
fulcioroots API and cleared the staticcheck SA1019 finding that had been
failing lint (operator).

quickstart.md still listed #263 among the open PRs and, further down, in
the SC-002 acceptance ledger — so the document contradicted itself: the
summary said 18 merged while the section a reader uses to verify SC-002
said 19. Every count claim now agrees: 19 merged, 1 closed without
merging (#269), 1 deferred (#272), 21 total. The Historical baseline
(2026-08-28) section and the per-PR module inventory table are left
untouched; #263 correctly appears there as it was.

contracts/dependency-upgrade.md is an append-only research record, so
the superseded T035 disposition ("#263 stays open and unmerged") is left
intact and a dated update note added beneath it.

Appends Phase 13 (T075, T076) to tasks.md and marks both complete. The
only tasks still open are T055/T056, blocked upstream on no published
@typescript-eslint accepting TypeScript 7.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SgeYHZV5dBRpRB1BTM5Pd1
Signed-off-by: valgulnecron <39313199+ValgulNecron@users.noreply.github.com>
@ValgulNecron
ValgulNecron merged commit 7fccf00 into master Aug 30, 2026
5 of 6 checks passed
@ValgulNecron
ValgulNecron deleted the 013-converge-009-doc-updates branch August 30, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant