From eb3c87191103357f244c9ca71b515636ced063ab Mon Sep 17 00:00:00 2001 From: Davide Mirtillo Date: Sat, 28 Feb 2026 00:59:07 +0100 Subject: [PATCH 01/12] Add Dependabot configuration and fortify Docker CI pipeline This commit introduces automated dependency updates via Dependabot and adds validation steps to the Docker build workflow to prevent broken or vulnerable images from being pushed. Changes include: - Add Dependabot configuration for Go modules, GitHub Actions, and Docker. - Update Docker base image to Go 1.21 to align with go.mod. - Add Dockerfile linting (hadolint) to CI. - Add a runtime smoke test (`docker run --help`) to CI. - Add vulnerability scanning (Trivy) to CI. - Add OpenSpec specifications and configurations. --- .gemini/commands/opsx/apply.toml | 149 +++++++++ .gemini/commands/opsx/archive.toml | 154 ++++++++++ .gemini/commands/opsx/explore.toml | 170 +++++++++++ .gemini/commands/opsx/propose.toml | 103 +++++++ .gemini/skills/openspec-apply-change/SKILL.md | 156 ++++++++++ .../skills/openspec-archive-change/SKILL.md | 114 +++++++ .gemini/skills/openspec-explore/SKILL.md | 288 ++++++++++++++++++ .gemini/skills/openspec-propose/SKILL.md | 110 +++++++ .github/dependabot.yml | 34 +++ .github/workflows/build.yml | 33 +- .roo/commands/opsx-apply.md | 149 +++++++++ .roo/commands/opsx-archive.md | 154 ++++++++++ .roo/commands/opsx-explore.md | 170 +++++++++++ .roo/commands/opsx-propose.md | 103 +++++++ .roo/skills/openspec-apply-change/SKILL.md | 156 ++++++++++ .roo/skills/openspec-archive-change/SKILL.md | 114 +++++++ .roo/skills/openspec-explore/SKILL.md | 288 ++++++++++++++++++ .roo/skills/openspec-propose/SKILL.md | 110 +++++++ build/docker/Dockerfile | 2 +- .../.openspec.yaml | 2 + .../2026-02-28-fortify-docker-ci/design.md | 33 ++ .../2026-02-28-fortify-docker-ci/proposal.md | 26 ++ .../specs/docker-ci-validation/spec.md | 29 ++ .../2026-02-28-fortify-docker-ci/tasks.md | 20 ++ .../.openspec.yaml | 2 + .../2026-02-28-setup-dependabot/design.md | 31 ++ .../2026-02-28-setup-dependabot/proposal.md | 26 ++ .../specs/dependabot/spec.md | 15 + .../2026-02-28-setup-dependabot/tasks.md | 10 + openspec/config.yaml | 31 ++ openspec/specs/dependabot/spec.md | 15 + openspec/specs/docker-ci-validation/spec.md | 29 ++ 32 files changed, 2824 insertions(+), 2 deletions(-) create mode 100644 .gemini/commands/opsx/apply.toml create mode 100644 .gemini/commands/opsx/archive.toml create mode 100644 .gemini/commands/opsx/explore.toml create mode 100644 .gemini/commands/opsx/propose.toml create mode 100644 .gemini/skills/openspec-apply-change/SKILL.md create mode 100644 .gemini/skills/openspec-archive-change/SKILL.md create mode 100644 .gemini/skills/openspec-explore/SKILL.md create mode 100644 .gemini/skills/openspec-propose/SKILL.md create mode 100644 .github/dependabot.yml create mode 100644 .roo/commands/opsx-apply.md create mode 100644 .roo/commands/opsx-archive.md create mode 100644 .roo/commands/opsx-explore.md create mode 100644 .roo/commands/opsx-propose.md create mode 100644 .roo/skills/openspec-apply-change/SKILL.md create mode 100644 .roo/skills/openspec-archive-change/SKILL.md create mode 100644 .roo/skills/openspec-explore/SKILL.md create mode 100644 .roo/skills/openspec-propose/SKILL.md create mode 100644 openspec/changes/archive/2026-02-28-fortify-docker-ci/.openspec.yaml create mode 100644 openspec/changes/archive/2026-02-28-fortify-docker-ci/design.md create mode 100644 openspec/changes/archive/2026-02-28-fortify-docker-ci/proposal.md create mode 100644 openspec/changes/archive/2026-02-28-fortify-docker-ci/specs/docker-ci-validation/spec.md create mode 100644 openspec/changes/archive/2026-02-28-fortify-docker-ci/tasks.md create mode 100644 openspec/changes/archive/2026-02-28-setup-dependabot/.openspec.yaml create mode 100644 openspec/changes/archive/2026-02-28-setup-dependabot/design.md create mode 100644 openspec/changes/archive/2026-02-28-setup-dependabot/proposal.md create mode 100644 openspec/changes/archive/2026-02-28-setup-dependabot/specs/dependabot/spec.md create mode 100644 openspec/changes/archive/2026-02-28-setup-dependabot/tasks.md create mode 100644 openspec/config.yaml create mode 100644 openspec/specs/dependabot/spec.md create mode 100644 openspec/specs/docker-ci-validation/spec.md diff --git a/.gemini/commands/opsx/apply.toml b/.gemini/commands/opsx/apply.toml new file mode 100644 index 0000000..88a0dfe --- /dev/null +++ b/.gemini/commands/opsx/apply.toml @@ -0,0 +1,149 @@ +description = "Implement tasks from an OpenSpec change (Experimental)" + +prompt = """ +Implement tasks from an OpenSpec change. + +**Input**: Optionally specify a change name (e.g., `/opsx:apply add-auth`). If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes. + +**Steps** + +1. **Select the change** + + If a name is provided, use it. Otherwise: + - Infer from conversation context if the user mentioned a change + - Auto-select if only one active change exists + - If ambiguous, run `openspec list --json` to get available changes and use the **AskUserQuestion tool** to let the user select + + Always announce: "Using change: " and how to override (e.g., `/opsx:apply `). + +2. **Check status to understand the schema** + ```bash + openspec status --change "" --json + ``` + Parse the JSON to understand: + - `schemaName`: The workflow being used (e.g., "spec-driven") + - Which artifact contains the tasks (typically "tasks" for spec-driven, check status for others) + +3. **Get apply instructions** + + ```bash + openspec instructions apply --change "" --json + ``` + + This returns: + - Context file paths (varies by schema) + - Progress (total, complete, remaining) + - Task list with status + - Dynamic instruction based on current state + + **Handle states:** + - If `state: "blocked"` (missing artifacts): show message, suggest using `/opsx:continue` + - If `state: "all_done"`: congratulate, suggest archive + - Otherwise: proceed to implementation + +4. **Read context files** + + Read the files listed in `contextFiles` from the apply instructions output. + The files depend on the schema being used: + - **spec-driven**: proposal, specs, design, tasks + - Other schemas: follow the contextFiles from CLI output + +5. **Show current progress** + + Display: + - Schema being used + - Progress: "N/M tasks complete" + - Remaining tasks overview + - Dynamic instruction from CLI + +6. **Implement tasks (loop until done or blocked)** + + For each pending task: + - Show which task is being worked on + - Make the code changes required + - Keep changes minimal and focused + - Mark task complete in the tasks file: `- [ ]` → `- [x]` + - Continue to next task + + **Pause if:** + - Task is unclear → ask for clarification + - Implementation reveals a design issue → suggest updating artifacts + - Error or blocker encountered → report and wait for guidance + - User interrupts + +7. **On completion or pause, show status** + + Display: + - Tasks completed this session + - Overall progress: "N/M tasks complete" + - If all done: suggest archive + - If paused: explain why and wait for guidance + +**Output During Implementation** + +``` +## Implementing: (schema: ) + +Working on task 3/7: +[...implementation happening...] +✓ Task complete + +Working on task 4/7: +[...implementation happening...] +✓ Task complete +``` + +**Output On Completion** + +``` +## Implementation Complete + +**Change:** +**Schema:** +**Progress:** 7/7 tasks complete ✓ + +### Completed This Session +- [x] Task 1 +- [x] Task 2 +... + +All tasks complete! You can archive this change with `/opsx:archive`. +``` + +**Output On Pause (Issue Encountered)** + +``` +## Implementation Paused + +**Change:** +**Schema:** +**Progress:** 4/7 tasks complete + +### Issue Encountered + + +**Options:** +1.