docs(agents): Anthropic API labels and the workflow-secrets lint plan text - #2178
Merged
Merged
Conversation
…finish the R01 plan text Deferred review follow-ups (external review R13, R01). - agent-factory.drawio: no node presents Bedrock or Vertex as the internal provider (ADR-0054). The internal default is the Anthropic API, direct, with a gateway-held key; Bedrock and Vertex AI are optional per cloud. The Bedrock mark becomes the Claude mark from icons/, and the optional box goes plain — one mark cannot label two products. - ai-platform.drawio (gateways page): the Claude box names the Anthropic API (direct) instead of Bedrock · Vertex AI. - agents/_index.md: the agent-factory diagram alt text follows the labels. - SP3 plan Task 6.3: the test-workflow-secrets block gains the R01 fixtures the Interfaces bullet already specifies — a workflow-level write and an unlisted job holding write both fail, naming file and permission/job. - SP1 spec T13: the R01 residual is stale — security-events: write has lived only on sarif-upload since 04d7f00 (#2171). - SP3 spec phase table: phase 6 waits on the Anthropic API backend (agentgateway migration phase I, ADR-0054), not SP4's Bedrock backend. SVGs regenerated (export-diagrams.sh, pinned drawio 30.3.6); ci-pipeline.svg churned unrelatedly and was restored.
…llowlist Review fix (round 1, Important): the Step 1 R01 fixtures demand write-permission parsing the Step 3 implementation block never had, so an executor copying it verbatim could not make Step 4 pass. check-workflow-secrets.sh now implements what the task's Interfaces bullet specifies, on top of the unchanged T8 secrets check: - workflow-level write in a pull_request/pull_request_target workflow fails, naming file and permission; - a job-level write outside the script's own allowlist fails, naming file and job (sarif-upload: security-events, render-diff-comment: pull-requests, build-and-push: packages, security-events); - an allowlisted job with a actions/checkout of the PR head or any run: step fails. pull_request's default checkout ref is the PR merge commit; pull_request_target's is the base, so only an explicit pull_request ref counts there. The allowlist lives in the script (a gate path, R17). build-and-push's split out of the PR path is its own fix(ci) PR; until it lands the lint flags the job, and the entry stays so the split cannot quietly widen it again.
Contributor
🔍 Rendered manifest diff — this PR vs
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Two follow-ups from the 2026-10-02 external review (#2173) — R13 (the diagrams still present Bedrock/Vertex as the internal provider) and R01 (the SP3 plan's workflow-secrets lint text does not implement its own contract) — plus the two spec sentences the same review flagged as stale.
R13 — the internal provider is the Anthropic API (direct)
Per ADR-0054, the internal model provider relabels from the per-cloud Bedrock/Vertex story to the Anthropic API (direct):
docs/architecture/agent-factory.drawio— the internal-data node now readsAnthropic API (direct) · internal data · gateway-held key; Bedrock and Vertex collapse into one optional node (optional, per cloud), so no node presents either as the internal provider. The Bedrock mark is replaced by the established Claude mark; the collapsed node drops its single-product icon rather than assert the wrong thing.docs/architecture/ai-platform.drawio(page 2) — the Claude gateway box's sub-line becomesAnthropic API (direct)(bold "Claude" and its mark stay; the model is still Claude).agent-factory.svgalt text follows;gateways.mdandstatus.mdalready carry the ADR-0054 wording (verified, unchanged).R01 — the SP3 plan's workflow-secrets lint text
docs/superpowers/plans/2026-09-27-agent-dark-factory-plan.md, Task 6.3:sarif-upload(security-events),render-diff-comment(pull-requests),build-and-push(packages,security-events), andnotify-main-broken: issuesrecorded as a push-gated exception (itsif:pinsgithub.event_name == 'push', so the write never coincides with PR code). Allowlisted jobs that run PR code — arun:step or a checkout of the PR head — fail the lint.exit 0) andshellcheckis clean, where the pre-fix extraction failed 4 assertions.Stale spec sentences
ci.yamlfix lands" clause; the fix landed in fix(ci): scope write permissions to jobs that run no PR code #2171 (security-events: writeis job-level onsarif-uploadonly, confirmed against the tree).Verification
Run in the worktree after the commits:
Detail and review evidence:
.superpowers/sdd/2026-09-27-agent-dark-factory-plan/f24-docs-report.mdin theo1-agent-observabilityworktree (branchfix/ci-image-build-splitin the same SDD stream carries the build-and-push split this plan's lint anticipates — see its own PR).