Update AGENTS.md files across multiple modules to standardize task status update instructions and introduce a new document for Secret Leak Detection operations.
- Modified task status update instructions in AGENTS.md files to refer to corresponding sprint files as `/docs/implplan/SPRINT_*.md` instead of `docs/implplan/SPRINTS.md`. - Added a comprehensive document for Secret Leak Detection operations detailing scope, prerequisites, rule bundle lifecycle, enabling the analyzer, policy patterns, observability, troubleshooting, and references.
This commit is contained in:
@@ -19,7 +19,7 @@ Implement deterministic Java analyzers that normalise JVM/Build ecosystem inputs
|
||||
- Build system references linked from sprint tasks (Maven, Gradle, shading).
|
||||
|
||||
## Working Agreement
|
||||
1. **Status synchronisation**: set tasks to `DOING`/`DONE` in `docs/implplan/SPRINTS.md` and local `TASKS.md` as work progresses.
|
||||
1. **Status synchronisation**: set tasks to `DOING`/`DONE` in corresponding sprint file `docs/implplan/SPRINT_*.md` and local `TASKS.md` as work progresses.
|
||||
2. **Surface usage**: rely on shared Surface libraries for env detection, cached artifacts, secret access, and validation.
|
||||
3. **Deterministic outputs**: stabilise classpath ordering, canonicalise PURLs, and avoid network fetches; rely on local caches.
|
||||
4. **SBOM accuracy**: produce consistent component/relationship data; no policy/severity decisions.
|
||||
|
||||
Reference in New Issue
Block a user