Repository navigation
feat(review): integrate OCR planning, CLI review gates and audit reports - #2
Merged
Merged
Conversation
vannt-dev
force-pushed
the
feat/ocr-governance-integration
branch
from
September 18, 2026 17:03
eedc5b2 to
44e2190
Compare
…rce rules at every checkpoint Replace the review provider with the real ocr CLI contract (no --files/ --context; --background-file, -f json, delegate preview) and adopt a shared 5-severity/7-category finding vocabulary; reviewer infrastructure failures surface as ReviewResult.error, never as findings. Resolve changed files with git ... -z so paths with spaces, renames, and untracked files are handled safely, and git failures raise instead of returning an empty list. Scope task reviews to committed changes and pending workspace edits as separate scopes so nothing merges silently and a skipped scope never counts as a completed review. Resolve rule-matched gates and human-approval checkpoints at verify, advance, and state, not only when junto__plan was called. Add junto__plan to build a deterministic plan from git, rules, and the skill registry. The skill resolver now reads appliesTo/tags from skill frontmatter and the skills root's skillset.json. Rebuild the committed plugin hooks and MCP server bundle to match source.
Cover the review gate config, the ocr provider contract, task-scoped review evidence, and rule-driven approval checkpoints in the README and changelog.
vannt-dev
force-pushed
the
feat/ocr-governance-integration
branch
from
September 20, 2026 03:00
44e2190 to
112c76e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OCR review gates now resolve changed files, matching rules and skills before review, pass requirement context to the real OCR CLI contract, and block on explicit severity policy or incomplete evidence. A trusted host CLI can perform semantic review using OCR delegation for file and rule selection.
.junto/.Validation:
corepack pnpm build,corepack pnpm typecheck, and full tests pass locally on Windows (354 passed, 3 skipped with real OCR 1.12.7 preview/rule smoke tests enabled). Both finding contract files match governed-agent-sdlc byte-for-byte. The previous session's bounded live host CLI evaluation detected the known bug and produced zero high/critical findings on the clean control.The independent model review's literal-pathspec finding was fixed with real Git/process regression tests for workspace, commit and range review. Final fixes received local regression verification; no new independent model verdict is claimed. Direct OCR LLM review remains unconfigured; delegation smoke tests do not establish semantic coverage. CI does not call a paid model. No merge or release is included.