Skip to content

feat(jev): advisory Jev layer v0.1 (shared client + routing core) - #39

Merged
CMaintz merged 2 commits into
mainfrom
feat/jev-integration
Sep 30, 2026
Merged

CMaintz merged 2 commits into
mainfrom
feat/jev-integration

Conversation

@CMaintz

@CMaintz CMaintz commented Sep 29, 2026

Copy link
Copy Markdown
Owner

First slice of SPECS/foundry-jev-integration.md - the reusable, deterministic core that later phases build on.

What lands

  • scripts/jev/client.mjs - the JevProvider port lifted from jev-triage (TypeSafe + Cloudflare adapters, postJson with 429/529 backoff) plus providerFromEnv, which returns null when no key is set so every caller fails open to current behavior. Honors TYPESAFE_AI_BASE_URL for self-host/proxy/mock.
  • scripts/jev/route.mjs - pure, no-network routing/triage core: routeReview, triageToolcall, and the batched question templates. Fail-open invariant: a missing or low-confidence answer always widens review, never narrows it.
  • scripts/jev/boundary.test.mjs - the mechanical guard for the spec's central invariant. Reds the build if any CI workflow or mise gate verb references scripts/jev, so a ~68%-accurate model can never reach the deterministic oracle.
  • 18 tests via node:test (zero deps): node --test scripts/jev/*.test.mjs.
  • docs/FEATURES.md entry + module README.md.

Boundary

Advisory only. Opt-in via JEV_API_KEY; absent key is a no-op. No change to any gate verb or workflow - Jev lives strictly on the proposer side.

Next phases (not in this PR)

  • v0.2 review depth/lens pre-filter in the review skill (cmaintz-skills), behind a flag, fail-open.
  • v0.3 per-turn tool-call risk triage Stop hook (warn-only).
  • v0.4 feature-loop pre-checks.

Refs SPECS/foundry-jev-integration.md.

First slice of the foundry-jev-integration spec: the reusable, deterministic
core that later phases (review pre-filter, tool-call triage) build on.

- scripts/jev/client.mjs: JevProvider port lifted from jev-triage (TypeSafe +
  Cloudflare adapters, postJson with 429/529 backoff) + providerFromEnv, which
  returns null with no key so every caller fails open. Honors TYPESAFE_AI_BASE_URL.
- scripts/jev/route.mjs: pure routing/triage core (routeReview, triageToolcall,
  question templates). Fail-open invariant: a missing or low-confidence answer
  always widens review, never narrows it.
- scripts/jev/boundary.test.mjs: mechanical guard for the spec's core invariant -
  reds the build if any CI workflow or mise gate verb references scripts/jev, so
  a ~68%-accurate model can never reach the deterministic oracle.
- 18 tests via node:test (zero deps). docs/FEATURES.md + module README.

Advisory only, opt-in via JEV_API_KEY, no change to any gate. Later: review
depth/lens pre-filter and per-turn tool-call triage in cmaintz-skills.
Completes the advisory Jev layer so v0.1 is actually usable, not just a library.

- scripts/jev/review.mjs: runnable review pre-filter. `node scripts/jev/review.mjs
  [baseRef]` parses the diff, asks Jev per changed file which warrant deep review and
  on which lens, and prints routing JSON. Fail-open: no key or a small diff reviews
  everything. Exported routeFiles/parseDiff are unit-tested with a fake provider.
- jev-scripts.yml: runs `node --test scripts/jev/*.test.mjs` on change, so the suite -
  including the boundary guard - actually executes in CI and has teeth.
- boundary.test.mjs now scans the gate-defining files explicitly (gate/security/_ts/
  _java/_dotnet/_php/_guards/_semgrep + mise verbs) rather than every workflow, so the
  test-runner workflow above is allowed while Jev-in-the-gate is still a red build.
- FEATURES + README updated. 22 node:test cases, all green.
@CMaintz
CMaintz merged commit b964d1a into main Sep 30, 2026
5 checks passed
@CMaintz
CMaintz deleted the feat/jev-integration branch September 30, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant