Skip to content

feat(review): integrate OCR planning, CLI review gates and audit reports - #2

Merged
vannt-dev merged 3 commits into
mainfrom
feat/ocr-governance-integration
Sep 21, 2026
Merged

vannt-dev merged 3 commits into
mainfrom
feat/ocr-governance-integration

Conversation

@vannt-dev

@vannt-dev vannt-dev commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

OCR review gates now resolve changed files, matching rules and skills before review, pass requirement context to the real OCR CLI contract, and block on explicit severity policy or incomplete evidence. A trusted host CLI can perform semantic review using OCR delegation for file and rule selection.

  • Adds shared version-1 finding schemas/fixtures, a read-only report tool, escaped HTML export and review event evidence under .junto/.
  • Preserves renamed source paths and committed-plus-pending scope; fixes skill-root metadata precedence, evidence redaction and stale raw output.
  • Keeps selected filenames literal in Git so bracketed paths cannot include excluded files. Updates the authoritative gate semantics and rebuilds committed plugin artifacts.

Validation: corepack pnpm build, corepack pnpm typecheck, and full tests pass locally on Windows (354 passed, 3 skipped with real OCR 1.12.7 preview/rule smoke tests enabled). Both finding contract files match governed-agent-sdlc byte-for-byte. The previous session's bounded live host CLI evaluation detected the known bug and produced zero high/critical findings on the clean control.

The independent model review's literal-pathspec finding was fixed with real Git/process regression tests for workspace, commit and range review. Final fixes received local regression verification; no new independent model verdict is claimed. Direct OCR LLM review remains unconfigured; delegation smoke tests do not establish semantic coverage. CI does not call a paid model. No merge or release is included.

@vannt-dev
vannt-dev force-pushed the feat/ocr-governance-integration branch from eedc5b2 to 44e2190 Compare September 18, 2026 17:03
…rce rules at every checkpoint

Replace the review provider with the real ocr CLI contract (no --files/
--context; --background-file, -f json, delegate preview) and adopt a shared
5-severity/7-category finding vocabulary; reviewer infrastructure failures
surface as ReviewResult.error, never as findings. Resolve changed files with
git ... -z so paths with spaces, renames, and untracked files are handled
safely, and git failures raise instead of returning an empty list.

Scope task reviews to committed changes and pending workspace edits as
separate scopes so nothing merges silently and a skipped scope never counts
as a completed review. Resolve rule-matched gates and human-approval
checkpoints at verify, advance, and state, not only when junto__plan was
called. Add junto__plan to build a deterministic plan from git, rules, and
the skill registry. The skill resolver now reads appliesTo/tags from skill
frontmatter and the skills root's skillset.json.

Rebuild the committed plugin hooks and MCP server bundle to match source.
Cover the review gate config, the ocr provider contract, task-scoped
review evidence, and rule-driven approval checkpoints in the README and
changelog.
@vannt-dev
vannt-dev force-pushed the feat/ocr-governance-integration branch from 44e2190 to 112c76e Compare September 20, 2026 03:00
@vannt-dev vannt-dev changed the title feat(core): add deterministic changes resolver, rule matcher, skill resolver, plan generator and review provider feat(review): integrate OCR planning, CLI review gates and audit reports Sep 21, 2026
@vannt-dev
vannt-dev merged commit 8ea4c86 into main Sep 21, 2026
5 checks passed
@vannt-dev
vannt-dev deleted the feat/ocr-governance-integration branch September 21, 2026 00:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant