Skip to content

spec: 004 Role, title, and description of each spec source - #3532

Merged
jiparis merged 5 commits into
chainloop-dev:mainfrom
jiparis:issue-3531-spec-role
Oct 6, 2026
Merged

jiparis merged 5 commits into
chainloop-dev:mainfrom
jiparis:issue-3531-spec-role

Conversation

@jiparis

@jiparis jiparis commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Design spec for review. This PR adds only the spec. It adds no code.

Summary

This spec changes the spec capture of Spec 002 and Spec 003. It does not replace them. Today each spec source has a kind: ticket, document, image, or text. The kind tells the format of a source, but not its purpose. With this change, the agent can also record a role for each source: task, spec, plan, or reference. The CLI stores the role in the session material and in the annotations of the spec material. A tool that shows the sources can then group them by purpose.

For reviewers

The spec has no open questions. These decisions are the most likely to get challenges:

  • D-003: a binary file gets its role from a companion file that the agent writes, named <file>.meta.yaml. The CLI does not guess a role for an image.
  • D-004: a missing or unknown role gives no role in the evidence. The CLI does not derive a role from the kind.

Refs #3531

Review in cubic

Refs chainloop-dev#3531

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>
@jiparis jiparis added the spec Design spec label Oct 6, 2026
@jiparis
jiparis requested a review from migmartri October 6, 2026 11:19
@chainloop-platform

chainloop-platform Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — 🟢 84% · ✅ 0 failing

Avg score Sessions Failing policies Attribution Files Lines Total Duration
🟢 84% 1 ✅ 0 100% AI / 0% Human 1 +222 / -59 21h21m33s

🟢 84% — 100% AI — ✅ All policies passing

Oct 5, 2026 15:05 UTC · 21h21m33s · $56.42 · 1.3k in / 598.4k out · claude-code 2.1.289 (claude-opus-5-5)

View session details ↗

Change Summary

  • Updates platform spec 003 for the AI session Context tab: source grouping, title-based labels, transcript placement, and a Skills group.
  • Updates OSS spec 004 to add optional role, title, and description metadata plus redaction rules for spec sources.
  • Refreshes related review-thread decisions and design artifacts so both specs stay aligned.

AI Session Overall Score

🟢 84% — Well-planned spec work; only the early OSS workaround merits reviewer attention.

AI Session Analysis Breakdown

🟢 94% · context-and-planning

🟢 The eng-spec prompt and research gave the work clear upfront structure. · High Impact

🟢 93% · scope-discipline

No notes.

🟢 91% · user-trust-signal

🟢 The user kept delegating follow-up work, showing steady confidence overall. · High Impact

🟢 90% · alignment

No notes.

🟡 68% · solution-quality

🟢 AI corrected the trace gap with Edit-based, signed, attested commits. · High Impact

🟠 AI first opened the OSS PR from a scratch clone/API path, so the initial PR missed trace attribution. · Medium Severity

💡 When a workflow constraint blocks normal commits, ask before using an untracked workaround.

abstained · verification

🟡 Verification abstained: reviewed commits are spec/design changes, so no runtime behavior was validated. · Low Severity

Missing criteria: verification


File Attribution

████████████████████ 100% AI / 0% Human

Status Attribution File Lines
modified ai docs/specs/003-ai-session-spec-viewer.md +222 / -59

Policies (4)

Status Policy Material Messages
✅ Passed ai-config-ai-agents-allowed ai-coding-session-d4043d -
✅ Passed ai-config-no-dangerous-commands ai-coding-session-d4043d -
✅ Passed ai-config-no-secrets ai-coding-session-d4043d -
✅ Passed ai-config-mcp-servers-allowed ai-coding-session-d4043d -

Security Checks — ✅ 5 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed cwe-top25 -
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top26-40-cusp -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 3 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed
iac-scan no IaC files changed

View attestation ↗


PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -
✅ Passed pr-min-approvals pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@jiparis
jiparis marked this pull request as ready for review October 6, 2026 11:37

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

Refs chainloop-dev#3531

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>

Chainloop-Trace-Sessions: d4043d7b-f121-41dd-a642-42aff4c66211
@jiparis jiparis changed the title spec: 004 Role of each spec source spec: 004 Role and title of each spec source Oct 6, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread docs/specs/004-spec-source-role.md Outdated
Refs chainloop-dev#3531

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>

Chainloop-Trace-Sessions: d4043d7b-f121-41dd-a642-42aff4c66211
migmartri
migmartri previously approved these changes Oct 6, 2026
Comment thread docs/specs/004-spec-source-role.md Outdated
Refs chainloop-dev#3531

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>

Chainloop-Trace-Sessions: d4043d7b-f121-41dd-a642-42aff4c66211
@jiparis jiparis changed the title spec: 004 Role and title of each spec source spec: 004 Role, title, and description of each spec source Oct 6, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread docs/specs/004-spec-source-role.md
Refs chainloop-dev#3531

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>

Chainloop-Trace-Sessions: d4043d7b-f121-41dd-a642-42aff4c66211
@jiparis
jiparis requested a review from migmartri October 6, 2026 12:25
@jiparis
jiparis merged commit a2dc7a4 into chainloop-dev:main Oct 6, 2026
17 checks passed
@jiparis
jiparis deleted the issue-3531-spec-role branch October 6, 2026 13:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

spec Design spec

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants