Skip to content

Require verified impact coverage for shared changes - #60

Merged
laimis91 merged 14 commits into
mainfrom
feature/shared-change-impact-protection
Sep 21, 2026
Merged

laimis91 merged 14 commits into
mainfrom
feature/shared-change-impact-protection

Conversation

@laimis91

@laimis91 laimis91 commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

A fix to shared behavior could satisfy the reported case while omitting other consumers or state transitions. This change records bounded impact across workflow, standalone debugging, and review, then validates the captured evidence before mutation and at completion.

  • Capture base/candidate consumers, distinct contract and state obligations, planned verification, current results, and original review bindings. Local and cosmetic changes retain compact applicability and proportionate verification.
  • Reject expanded behavior assessments with empty discovery/consumer evidence, including explicitly expanded local work; each consumer retains a required contract/state obligation. Compact local work and cosmetic controls remain proportionate.
  • Require one jointly justified equivalence group per verification plan; separately justified groups cannot share one execution record.
  • Selective installs include transitive bundled requires, so debugging and workflow receive the canonical review producer. Both installers deduplicate cycles, refresh bundled dependencies, preserve missing-external notes, and resolve selection before writes. Bash now preflights every resolved skill path before metadata reads or writes, rejecting traversal, links, and wrong-type nodes.
  • Bind each actual verification to the executed base/candidate/universe snapshot and the verification source identity. Refreshed headers cannot make an old run current; missing execution snapshots require verification to be rerun.
  • Allow blocked, invalid, or gap-reporting outputs to cite their blocker without a fabricated checker result; valid evidence and mutation handoffs stay strict.
  • Require current valid pre_build evidence and an assessment before source/test mutations and mutation dispatches, including entry-time Spec Review repairs. Read-only discovery remains available.
  • Add a Node 22+ standard-library checker for incomplete or stale evidence. Waivers separate their explanation from existing authority and cannot pass completion. Both installers deploy the common checker.
  • Route light expanded-impact completion through canonical assistant-review outputs without changing the light Build policy or automatically adding architecture/QA work. All completion tiers conditionally retain impact evidence; preparation-only work retains discovery evidence.
  • Align the four-value applicability domain across all three skills and the v7.2 migration notice with persisted 6.0/7.0/7.1 invalidation, preserving complete historical finding identities.
  • Reject behavior pre-build and completion when every obligation is unaffected and no verification is bound; retain discovery and cosmetic controls.
  • Bind successful checker results to versioned, phase-specific semantic JSON digests. Reusing evidence requires current validation plus an exact prior-result match through --receipt; legacy or stale evidence requires a fresh run. Workflow, debugging, and review retain their existing result-reference carriers.
  • Keep preparation-only discovery free of implementation completion/review requirements across the gate and generated phase guidance.
  • Return compact applicability from debugging, workflow, and review, including local causal evidence and cosmetic decisions. All workflow completion tiers and both progressive output routes retain it without requiring expansion. Keep both harness artifact ledgers aligned with the canonical enum.

Validation

  • CI-equivalent aggregate: 624 passed, 0 failed, repeated after the first review corrections. The original fixture-whitelist failure is covered.
  • Final descriptor-snapshot correction: Node API/CLI tests 31/0, impact contracts 16/0, context contracts 23/0, and Bash installer checks 24/0, including the installed checker for all three consumer skills. Unchanged aggregate checks are reused after a recorded three-file delta audit.
  • All 14 skills validate; existing instruction budgets are unchanged. Independent probes cover phase-specific digests, changed-input rejection, sparse arrays, and inert current/prior input snapshots.
  • Fresh canonical review, source hash audit, eight finding closures, and the framework's completion validator passed. Matching completion receipt reuse also passed.

Local validation runs on macOS with Node 25; the checker supports Node 22+. Fresh hosted Node 22/Linux and Windows checks are tracked on the published head.

Limits

The deterministic guarantee covers captured-evidence consistency and closure. It does not prove exhaustive dependency discovery, semantic truth, or unavoidable invocation by a model. Contract tests validate instruction routing and evidence shapes; checker tests execute the validator.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T09:46:59.117397Z f9a8ada New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1333d94885

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-review/contracts/handoffs.yaml Outdated
Comment thread tools/change-impact/validate-change-impact.cjs
Comment thread skills/assistant-workflow/contracts/output.yaml
@laimis91

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 467d1008ec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-workflow/contracts/handoffs.yaml Outdated
Comment thread tools/change-impact/README.md Outdated
@laimis91

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f3c4057990

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-review/SKILL.md Outdated
Comment thread skills/assistant-workflow/contracts/output.yaml
Comment thread skills/assistant-workflow/references/change-impact.md Outdated
Comment thread skills/assistant-workflow/contracts/input.yaml
@laimis91

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ef21f675d0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/change-impact/validate-change-impact.cjs Outdated
Comment thread skills/assistant-workflow/contracts/output.yaml Outdated
@laimis91

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b0b3f6de87

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-debugging/contracts/output.yaml
Comment thread tools/change-impact/validate-change-impact.cjs
Comment thread tools/change-impact/validate-change-impact.cjs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e4064391ee

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-workflow/contracts/phase-gates.yaml
Comment thread tools/change-impact/validate-change-impact.cjs
Comment thread skills/assistant-workflow/contracts/output.yaml
Comment thread skills/assistant-debugging/contracts/output.yaml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a9eb51d79e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-workflow/contracts/output.yaml
Comment thread skills/assistant-review/contracts/output.yaml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cc5bedcb64

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/change-impact/validate-change-impact.cjs
Comment thread tools/change-impact/validate-change-impact.cjs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 609be9027f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-review/contracts/output.yaml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ca90df6ed6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-workflow/contracts/phase-gates.yaml
Comment thread skills/assistant-review/SKILL.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1866d8ba1b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-review/contracts/phase-gates.yaml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fe1c79ee62

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/assistant-workflow/contracts/handoffs.yaml
Comment thread skills/assistant-workflow/contracts/input.yaml
Comment thread tools/change-impact/validate-change-impact.cjs
@laimis91
laimis91 merged commit b8f7519 into main Sep 21, 2026
7 checks passed
@laimis91
laimis91 deleted the feature/shared-change-impact-protection branch September 21, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant