Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Update: adopt Trust v1.2.0-rc.4 - #14

Open
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout
Open

Update: adopt Trust v1.2.0-rc.4#14
0xLeif wants to merge 6 commits into
mainfrom
0xleif/trust-1-org-rollout

Conversation

@0xLeif

@0xLeif0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt Trust 1.0.0 and prepare the GitHub plugin for SpecSync extensionless-source coverage without changing product behavior.
  • Keep all six existing bin/fledge-github* executables in the active canonical GitHub spec with five stable requirements and no placeholder data.
  • Lint and syntax-check every executable and smoke-test every offline --help surface.
  • Install Claude, Cursor, Codex, and Gemini integrations and protect the repository's real runtime, spec, workflow, agent, and governance paths.
  • Record the rollout files omitted from the earlier lifecycle scope and refresh portable verification and closing approvals.

Local verification

  • released SpecSync 5.0.2 (a9422ae): 1/1 spec, 6/6 files, 1,411/1,411 LOC, 100%, zero warnings
  • fledge lanes run verify: ShellCheck, Bash syntax, and all-executable offline help
  • Claude, Cursor, Codex, and Gemini integrations installed
  • fledge trust doctor
  • local fledge trust verify: complete gate passed with expected progressive provenance because no remote ledger exists
  • all review threads resolved and no merge conflict
  • definition, native verification, and closing approvals recorded as user:0xLeif

Hosted verification

  • pinned SpecSync contract / Trust
  • CodeQL

Blocker

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence. Released SpecSync 5.0.2 validates this exact committed tree at truthful 100% file and LOC coverage, but Trust has no released patch that can consume it yet. This PR remains draft until a coordinated immutable Trust patch pin is available and exact-head hosted Trust passes.

Authenticated GitHub reads and mutations remain independently authorized and are intentionally excluded from the offline migration lane.

Exact head: 285789391a06a610e22a0cdc4e68da9c70d10004.

@gemini-code-assistgemini-code-assistBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adopts SpecSync 5.0.1 and Trust 1.0.0 governance for the GitHub Fledge plugin, introducing canonical specs, companion files, migration change records, task definitions, and IDE skill commands. The review feedback suggests removing redundant empty headings in the skill markdown files, correcting split acceptance criteria in the migration change files, and expanding the smoke test and verification commands to cover all fledge-github sub-executables instead of only the main dispatcher.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread.claude/skills/spec-sync/SKILL.md Outdated
Comment thread.codex/skills/spec-sync/SKILL.md Outdated
Comment thread.cursor/skills/spec-sync/SKILL.md Outdated
Comment threadfledge.toml Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as ready for review July 13, 2026 14:54
@0xLeif
0xLeif requested a review from 0xGasparJuly 13, 2026 14:54

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:f5ee59c46f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread.gemini/commands/specsync/create-change.toml Outdated
Comment thread.claude/commands/specsync/create-spec.md Outdated
Comment thread.specsync/sdd.json Outdated
@0xLeif
0xLeif marked this pull request as draft July 13, 2026 22:20
@0xLeifChatGPT Codex Connector

Copy link
Copy Markdown
ContributorAuthor

Rollout update:

  • This repository is public; its existing Ubuntu-hosted runner remains appropriate.
  • Local SpecSync 5.0.2 validation is complete, but the pinned Trust 1.0.0 action composes SpecSync 5.0.1 and cannot consume the refreshed extensionless-source evidence.
  • The PR remains blocked pending a compatible immutable Trust pin and exact-head hosted Trust success.

This PR remains draft until the release compatibility blocker is resolved.

@0xGaspar0xGaspar left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing as a comment rather than an approval, since this is a draft and self-blocked.

You've documented the blocker clearly:

Trust 1.0.0 intentionally bundles immutable SpecSync 5.0.1. That release does not recognize include_extensionless, cannot measure the six extensionless Bash executables, and rejects the refreshed accepted evidence.

That's a real coordination deadlock rather than anything wrong with this changeset, and I don't think there's a useful code review to give until the Trust patch pin exists. A few observations for when it does:

  1. The dependency is worth recording somewhere durable. "Trust needs a released patch that can consume SpecSync 5.0.2" is the actual blocking work, and it currently lives only in this PR description. If there isn't a tracking issue on the Trust side, it'd be worth opening one and linking it here — otherwise this PR is the only record of a cross-repo dependency.

  2. include_extensionless is the crux. Six extensionless Bash executables that the pinned SpecSync literally cannot measure means coverage is structurally unreportable, not merely low. Worth confirming that the eventual Trust patch fixes measurement rather than just relaxing the gate — the second would make the green check meaningless for this repo.

  3. The diff is +1582/−0 across 63 files and almost entirely governance scaffolding (.specsync/, .claude/, .cursor/, .codex/, .gemini/, .trust.toml, .augur.toml), with no change to the bin/fledge-github* executables. If that's accurate — no product behaviour change at all — saying so as a one-liner at the top would let a reviewer calibrate quickly. Your summary says it, but it's below the fold.

  4. trust is red in CI here, which is expected given the blocker. It's also red on all thirteen open PRs in CorvidLabs/spec-sync, including ones that merge and test clean. If those share a root cause it may be worth chasing centrally rather than per-repo.

No action needed from me until the Trust pin lands — ping me then and I'll do a proper pass.

@corvid-agentcorvid-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes.

This draft is honest about why it cannot land, and hosted Trust is still red on 2857893.

  1. .github/workflows/trust.yml pins CorvidLabs/trust@9d32b578 (v1.0.0) and never runs a SpecSync action. Trust 1.0.0 bundles SpecSync 5.0.1, which this PR's own body says cannot measure the six extensionless bin/fledge-github* binaries or accept the refreshed evidence. That blocker is still true on this head.

  2. SpecSync 6 / Trust 1.2.0-rc.2 is the current product cut (spec-sync #748, corvid-verify #46). Landing a SpecSync 5 / Trust 1.0 adoption now is the wrong target. Retarget to a Trust pin that can consume SpecSync 6 (and truthful extensionless coverage), then re-verify hosted Trust.

  3. The installed agent skills still teach the 5.0 SDD recipe and specsync check --strict as the PR gate. That is the same overtaken gate spec-sync #748 asked consumers to stop using.

Keep this draft until hosted Trust is green on a 6.x pin. This review does not merge.

Pin CorvidLabs/trust to e0272543ad5c (v1.2.0-rc.4). SpecSync 6.0.0-rc.12 is Trust rc.4's default; no separate spec-sync uses added.
@corvid-agentcorvid-agent changed the title Update: adopt SpecSync 5 and Trust 1Update: adopt Trust v1.2.0-rc.4Sep 2, 2026
@corvid-agent
corvid-agent marked this pull request as ready for review September 2, 2026 20:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@0xLeif@0xGaspar@corvid-agent