Files
Danijel Martinek 90fc2853f2 feat(work): add ISO timestamps + auto-bump on staged work-doc changes
- New scripts/work/bump-updated-timestamps.mjs stamps the `updated:`
  frontmatter field to the current ISO 8601 UTC timestamp on every
  staged docs/work/**/*.md file. Idempotent; adds the field after
  `created:` if missing.
- .husky/pre-commit invokes the bump script as step 2 (before
  rebuild-state) so _state.json sees the fresh timestamp.
- Backfill all existing work docs (4 PRDs + 3 epics + 21 stories):
    * created: promoted from \`YYYY-MM-DD\` -> ISO timestamp using
      git log --diff-filter=A on each file (first-commit date for
      stories that had no \`created:\` line, midnight UTC for PRDs
      and epics that had date-only created).
    * updated: added from \`git log -1 --format=%aI\` on each file
      (last-commit timestamp); will be re-stamped to "now" by the
      pre-commit hook on this commit.

Stories that had no \`created:\` line now get one.
2026-05-14 21:10:34 +02:00

4.3 KiB

id, epic, title, type, status, feature, depends-on, blocks, created, updated
id epic title type status feature depends-on blocks created updated
05-trace-revalidation-workflow 2026-05-14-ci-security-and-supply-chain Trace revalidation workflow technical-story done scripts
01-trace-schema-extensions
04-major-bump-reevaluation
09-ci-security-guide-and-docs
2026-05-14T18:59:12+02:00 2026-05-14T19:10:35.370Z

Goal

Write scripts/library-decisions/revalidate.mjs — a script that walks every approved + pre-shipped trace, re-runs each trace's verification-commands, classifies divergence as soft or hard, and opens/updates/closes GitHub issues accordingly — then wire it into .github/workflows/trace-revalidation-weekly.yml (weekly cron + workflow_dispatch).

Why

ADR-022 traces go stale silently when new CVEs drop or Socket picks up behavioral changes in a package post-adoption. A weekly automated revalidation creates a feedback loop: soft divergence (minor drift) surfaces as a rolling dashboard issue; hard divergence (a re-evaluation is warranted) surfaces as a per-dep library-policy/re-evaluation issue with the trace path + finding + re-walk handoff. No auto-edit of traces and no CI gating on main — the workflow runs in parallel, not on the critical path.

External dependency: library-evaluation epic story 02 (pre-commit check script) must be complete — check.mjs and the docs/library-decisions/ fixture patterns are the prior art this script mirrors.

Done when

  • scripts/library-decisions/revalidate.mjs walks all traces in docs/library-decisions/ whose decision field is accepted or pre-shipped; for each trace, re-runs its verification-commands; classifies divergence (soft: minor discrepancy from expected output; hard: finding that would change the evaluation decision); opens a rolling library-policy/dashboard-labeled issue for soft divergence (creates or updates a single issue); opens a library-policy/re-evaluation-labeled per-dep issue for hard divergence with title re-evaluate: <package>@<version> — <finding>, trace path, and evaluate-library re-walk pointer; closes open library-policy/re-evaluation issues whose dep has since had lastRevalidated refreshed; skips rejected traces entirely.
  • Integration tests use a fixture trace directory (no real gh CLI / no network): no-drift trace → no issue; soft-drift trace → dashboard issue created; hard-drift trace → per-dep issue with correct labels + title format; open per-dep issue already exists → no duplicate opened; lastRevalidated refreshed → open issue closed with comment.
  • .github/workflows/trace-revalidation-weekly.yml triggers on schedule: - cron: "30 6 * * 1" and workflow_dispatch; job steps: checkout, pnpm install --frozen-lockfile, node scripts/library-decisions/revalidate.mjs; permissions: issues: write, contents: read (NO contents: write).
  • pnpm typecheck && pnpm lint && pnpm test && pnpm conformance && pnpm fallow:audit && pnpm coverage:diff all pass.

In scope

  • scripts/library-decisions/revalidate.mjs — the revalidation script.
  • scripts/library-decisions/revalidate.test.mjs — integration tests with fixture directory and mocked gh CLI surface.
  • .github/workflows/trace-revalidation-weekly.yml — the workflow file.

Out of scope

  • Auto-editing trace files — explicitly forbidden (no contents: write).
  • Auto-dispatching on library-policy/re-evaluation issues — human triage required (PRD out of scope).
  • CI gating on main from this workflow — main keeps deploying; revalidation runs in parallel.

Tasks

  • Write scripts/library-decisions/revalidate.mjs (walk approved+pre-shipped traces, re-run verification-commands, classify soft/hard divergence, open/update/close issues via gh CLI; mock-friendly gh surface for tests); write revalidate.test.mjs integration tests with fixture traces covering: no-drift, soft-drift (dashboard issue), hard-drift (per-dep issue with correct labels+title), duplicate-issue guard, stale-issue close on refreshed lastRevalidated, rejected-trace skip; one commit, all gates pass.
  • Create .github/workflows/trace-revalidation-weekly.yml (trigger: schedule: cron: "30 6 * * 1" + workflow_dispatch; steps: checkout, pnpm install --frozen-lockfile, node scripts/library-decisions/revalidate.mjs; permissions: issues: write, contents: read); one commit, all gates pass.