- New scripts/work/bump-updated-timestamps.mjs stamps the `updated:`
frontmatter field to the current ISO 8601 UTC timestamp on every
staged docs/work/**/*.md file. Idempotent; adds the field after
`created:` if missing.
- .husky/pre-commit invokes the bump script as step 2 (before
rebuild-state) so _state.json sees the fresh timestamp.
- Backfill all existing work docs (4 PRDs + 3 epics + 21 stories):
* created: promoted from \`YYYY-MM-DD\` -> ISO timestamp using
git log --diff-filter=A on each file (first-commit date for
stories that had no \`created:\` line, midnight UTC for PRDs
and epics that had date-only created).
* updated: added from \`git log -1 --format=%aI\` on each file
(last-commit timestamp); will be re-stamped to "now" by the
pre-commit hook on this commit.
Stories that had no \`created:\` line now get one.
3.1 KiB
id, epic, title, type, status, feature, depends-on, blocks, created, updated
| id | epic | title | type | status | feature | depends-on | blocks | created | updated | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 01-trace-schema-extensions | 2026-05-14-ci-security-and-supply-chain | Trace schema extensions (socketRisk + lastRevalidated) | technical-story | done | scripts |
|
2026-05-14T18:59:12+02:00 | 2026-05-14T19:10:35.370Z |
Goal
Extend scripts/library-decisions/schema.mjs with two new fields — socketRisk (the 9th filter result) and lastRevalidated (ISO-date or null) — and update docs/library-decisions/_template.md to reflect the expanded schema.
Why
Every downstream enforcement layer (the evaluate-library skill's 9th filter, the check.mjs major-bump mode, the revalidate.mjs weekly cron) depends on these two fields being present and validated at the schema layer first. Landing them here in one green commit before any consumer touches them prevents schema-drift between layers.
External dependency: library-evaluation epic story 01 (trace schema foundation) must be complete before this story — scripts/library-decisions/schema.mjs and docs/library-decisions/_template.md must exist. That epic is marked done.
Done when
scripts/library-decisions/schema.mjsexports an updated Zod schema wherefilter-resultsincludessocketRisk: z.union([z.literal("clean"), z.literal("flagged"), z.string()])and the trace frontmatter includeslastRevalidated: z.string().nullable()(ISO date or null).docs/library-decisions/_template.mdmirrors both new fields with inline documentation of their allowed values.schema.test.mjscovers:socketRiskround-trips for all three variants (clean,flagged, arbitrary string);lastRevalidatedaccepts ISO date strings andnull; a trace missingsocketRiskinfilter-resultsfails validation;lastRevalidated: nullis valid (default for fresh adoptions).pnpm typecheck && pnpm lint && pnpm test && pnpm conformance && pnpm fallow:audit && pnpm coverage:diffall pass.
In scope
scripts/library-decisions/schema.mjs— schema additions only (no new exports, no breaking changes to existing field shapes).scripts/library-decisions/schema.test.mjs— new test cases for the two new fields.docs/library-decisions/_template.md— field documentation additions.
Out of scope
socket-cliinvocation or Socket CI step — Story 02.check.mjsmajor-bump mode — Story 04.revalidate.mjsscript — Story 05.- Backfilling existing traces with the new fields — Story 05 (the revalidation cron handles this on its first run).
Tasks
- Extend
scripts/library-decisions/schema.mjsaddingsocketRisk(union:"clean" | "flagged" | string) to thefilter-resultsZod object andlastRevalidated(nullable ISO-date string) to the trace frontmatter schema; updatedocs/library-decisions/_template.mdto document both fields with their enum values; add test cases toschema.test.mjscoveringsocketRiskround-trips (all three variants),lastRevalidatedISO + null acceptance, and missing-socketRiskrejection; all gates pass on this single commit.