Skip to content

Update project templates for Trust 1 and SpecSync 5#497

Merged
0xLeif merged 25 commits into
mainfrom
0xleif/trust-1-support
Jul 13, 2026
Merged

Update project templates for Trust 1 and SpecSync 5#497
0xLeif merged 25 commits into
mainfrom
0xleif/trust-1-support

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adopt SpecSync 5.0.1 and Trust 1.0.0 with all four agent integrations.
  • Update the Corvid stack template to immutable Trust 1 governance.
  • Replace starter TODO commands with deterministic format, configuration, governance, and workflow checks.
  • Preserve all native OS, integration, lint, audit, template, corvid-pet, CodeQL, and attestation workflows.
  • Complete and accept both SDD changes and require trust on main.

Test Plan

  • 33/33 specs with 100% file and LOC coverage
  • All 10 templates validate with zero errors
  • Generated Corvid stack four-step governance lane
  • Ubuntu, macOS, and Windows native and integration matrices
  • Lint, audit, spec-check, corvid-pet, and CodeQL
  • Hosted trust
  • Independent code-owner approval

Accepted changes remain active until this delivery diff merges, then they can be archived.

@0xLeif
0xLeif requested a review from a team as a code owner July 12, 2026 03:15
@0xLeif
0xLeif requested review from 0xGaspar, Kyntrin and tofu-ux July 12, 2026 03:15

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the SpecSync validation to version 5.0.1, removes obsolete embedded-AI configurations, and simplifies the GitHub Actions Trust workflow by adopting the unified CorvidLabs Trust gate. It also introduces standard SDD and Trust configurations to the corvid-stack template. Feedback on these changes includes correcting a mismatched version comment for the checkout action in the workflow file, and removing the ".specsync/" directory from "ignored_paths" in the SDD configuration to prevent it from overriding the tracking of meaningful configuration files.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread templates/corvid-stack/.github/workflows/trust.yml Outdated
Comment thread templates/corvid-stack/.specsync/sdd.json Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c2548ae6ca

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread templates/corvid-stack/.github/workflows/trust.yml
Comment thread templates/corvid-stack/.trust.toml Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"I'm pecking through the errors..."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ failure
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions
github-actions Bot dismissed their stale review July 12, 2026 04:34

Superseded by updated review.

github-actions[bot]
github-actions Bot previously approved these changes Jul 12, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Looking sharp! Like a beak should be."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Even the dumpster of code seems empty today."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ❌ cancelled
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ failure
Tests (3 OS) ❌ cancelled

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 442c531ec9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment thread templates/corvid-stack/.specsync/sdd.json
Comment thread .gemini/commands/specsync/create-change.toml Outdated
Comment thread .cursor/commands/specsync-create-spec.md Outdated
@github-actions
github-actions Bot dismissed their stale review July 12, 2026 05:12

Superseded by updated review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Even the dumpster of code seems empty today."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ❌ cancelled
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ❌ cancelled

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 63db32ca6b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment thread .gemini/commands/specsync/create-spec.toml Outdated
Comment thread AGENTS.md Outdated
Comment thread .attest.json
@github-actions
github-actions Bot dismissed their stale review July 12, 2026 05:41

Superseded by updated review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"I'm pecking through the errors..."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions
github-actions Bot dismissed their stale review July 12, 2026 15:57

Superseded by updated review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"I'm pecking through the errors..."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ failure
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cf0c37ea4a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .trust.toml
Comment thread .specsync/changes/CHG-0001-adopt-trust-1-and-specsync-5/state.json
Comment thread .github/workflows/trust.yml
Comment thread templates/corvid-stack/.specsync/sdd.json
Comment thread .specsync/sdd.json
@github-actions
github-actions Bot dismissed their stale review July 12, 2026 22:44

Superseded by updated review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Caw... validation failed..."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ❌ cancelled
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ failure
Tests (3 OS) ❌ cancelled

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 57fb57aa7d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .trust.toml Outdated
Comment thread templates/corvid-stack/fledge.toml Outdated
Comment thread .github/workflows/trust.yml Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Even the dumpster of code seems empty today."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 37ab5e8b7d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/changes/CHG-0001-adopt-trust-1-and-specsync-5/verification.json Outdated
Comment thread .specsync/sdd.json
Comment thread templates/corvid-stack/.github/workflows/trust.yml Outdated
Comment thread templates/corvid-stack/README.md.tera Outdated
Comment thread specs/ai/requirements.md Outdated
Comment thread .specsync/sdd.json

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Caw... your imports are all over the place."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Caw... your imports are all over the place."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Even the dumpster of code seems empty today."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ cancelled
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Caw... your imports are all over the place."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ❌ cancelled
Lint (fmt + clippy) ✅ Passed
Spec Validation ❌ failure
Tests (3 OS) ✅ Passed

Powered by corvid-pet

github-actions[bot]
github-actions Bot previously approved these changes Jul 13, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Caw! Your code sparkles like a dropped french fry."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ea62bf537d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread templates/corvid-stack/fledge.toml Outdated
Comment thread templates/corvid-stack/.specsync/sdd.json
Comment thread templates/corvid-stack/fledge.toml Outdated
Comment thread .trust.toml
github-actions[bot]
github-actions Bot previously approved these changes Jul 13, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Caw! Found a shiny new spec!"

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d98db8524b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .specsync/sdd.json
Comment thread templates/corvid-stack/.github/workflows/trust.yml
Comment thread .github/workflows/ci.yml

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Corvin says...

      _
    <(;\  .oO(oh no...)
     |/(\
      \(\\
      " "\\

"Even the dumpster of code seems empty today."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ❌ cancelled
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

github-actions[bot]
github-actions Bot previously approved these changes Jul 13, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Caw! Found a shiny new spec!"

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Looking sharp! Like a beak should be."

CI Summary

Check Status
Dependency Audit ✅ Passed
Integration (3 OS) ✅ Passed
Lint (fmt + clippy) ✅ Passed
Spec Validation ✅ Passed
Tests (3 OS) ✅ Passed

Powered by corvid-pet

@0xLeif
0xLeif merged commit fb6260e into main Jul 13, 2026
15 checks passed
@0xLeif
0xLeif deleted the 0xleif/trust-1-support branch July 13, 2026 07:03

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9e8bcec77e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +22 to +24
- name: CorvidLabs Trust gate
id: trust
uses: CorvidLabs/trust@9d32b5786d2e9e4d39fc581c0091c721ee3d4226 # v1.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run SDD change checks in the Trust job

This new trust workflow relies on the pinned Trust action, but I checked that action and it only runs the lifecycle command, specsync check, risk, and provenance; it does not invoke specsync lifecycle enforce --all or specsync change check. Since this commit also enables .specsync/sdd.json for meaningful paths, a PR can edit src/, .github/, etc. without accepted CHG-* evidence and still pass the trust job if branch protection keys on this gate, so mirror the explicit SDD lifecycle/change checks here as well.

Useful? React with 👍 / 👎.

Comment thread .specsync/sdd.json
Comment on lines +41 to +44
".trust.toml",
".augur.toml",
".attest.json",
"AGENTS.md"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Protect the root Claude rules file

This new SDD allowlist protects AGENTS.md and the agent integration directories, but the repository also has a root CLAUDE.md rule entry point. With require_change_for_meaningful_files enabled, a future PR can change or remove Claude-specific instructions without any SpecSync change evidence; add CLAUDE.md here, as the generated template policy already does.

Useful? React with 👍 / 👎.

Comment on lines +34 to +35
5. Open the newly created `specs/<module-name>/<module-name>.spec.md` and fill
in the `Purpose`, `Requirements`, and `Public API` sections. If a free-text

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Target the real spec sections in create-spec

When an agent follows this create-spec workflow, these lines tell it to fill a Requirements section in the new .spec.md, but the configured required sections are Purpose, Public API, Invariants, Behavioral Examples, Error Cases, Dependencies, and Change Log, with acceptance criteria living in requirements.md. That misdirects free-text scaffolding toward a non-canonical section and can leave the actual contract sections as placeholders; update the agent command copies to name the real sections and companion file.

Useful? React with 👍 / 👎.

Comment thread .specsync/sdd.json
Comment on lines +8 to +10
"specs/",
"site/",
".github/",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Cover root public docs in SDD policy

This allowlist protects site/, but not the public root docs that users and release automation rely on (README.md, CHANGELOG.md, SECURITY.md, CONTRIBUTING.md, and MIGRATION.md). With require_change_for_meaningful_files enabled, a future PR can change those public contracts or release notes without any accepted SpecSync change evidence, so include the root documentation files alongside the site docs.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant