From d0faf61147b676a10967c2a3cf2deaf586b00e49 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sat, 4 Jul 2026 19:12:38 +0200 Subject: [PATCH] =?UTF-8?q?chore(memory):=20TODO=20=E2=80=94=20chantier=20?= =?UTF-8?q?/tour=20(RED/GREEN/REFACTOR=20trac=C3=A9s,=20re-test=20diff?= =?UTF-8?q?=C3=A9r=C3=A9=20au=201er=20usage=20r=C3=A9el)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/tasks/TODO.md | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/.claude/tasks/TODO.md b/.claude/tasks/TODO.md index 562cc68..62d1a55 100644 --- a/.claude/tasks/TODO.md +++ b/.claude/tasks/TODO.md @@ -1,5 +1,38 @@ # TODO +## 2026-07-04 — skill /tour (tir groupé multi-projets, feature/tour-skill) +Goal: 1 orchestrateur = clean-code + sécurité (security-auditor/semgrep [+cso si +gstack ON]) + reconcile + doc, mode auto, sur 1..N projets. Boucle de convergence +(fixes peuvent invalider l'audit précédent) BORNÉE 3× (LRN-083). Build via +superpowers:writing-skills (TDD, pattern audit-delta/reconcile) + guidance +skill-creator (structure, description trigger-pushy). +Design verrouillé : +- auto = fixes committés sur `chore/tour-` par repo (gitflow lib), JAMAIS + finish/merge (signal humain only). Tree sale ou pas de develop → report-only. +- ordre par repo : sécurité → clean → re-verify (checks projet, fail=revert + fail-closed) → reconcile (REPORT-ONLY, jamais d'auto-coche TODO) → doc + (mode silencieux doc-syncer) → re-audit convergence. +- convergence = 1 passe complète à zéro finding nouveau + checks verts ; + sinon re-boucle, max 3 itérations, résidus rapportés honnêtement. +- rapport `.claude/audits/TOUR.md` par repo + synthèse inline multi-repos. +- registres : offre capitalize gatée en fin, jamais silencieux. +- [x] RED : fixture repo → baseline SANS skill. 6 gaps : TODO cible ré-écrit + silencieusement ; registres écrits de façon autonome ; sécu = grep ad-hoc + sans semgrep ; zéro rapport persistant ; scope creep (.gitignore + + registres bootstrap) ; boucle sans borne déclarée. (Bien fait : branche + gitflow via lib, pas de merge, commits atomiques, convergence passe 2.) +- [x] GREEN : skills/tour/SKILL.md — run avec skill sur fixture-green, + 6/6 gaps fermés VÉRIFIÉS sur disque (TODO zero-diff, 0 registre, + semgrep chaque itération, TOUR.md committé 18 findings, 0 scope + creep, 3 it. bornées convergées, chore branch non mergée) +- [x] REFACTOR : 2 trous du GREEN patchés (scratch semgrep non trackés → + auto-blocage du prochain run, STEP 3.2 cleanup ; fix sécu cassant + non signalé → tag BREAKING structurel dans template). Additions + template-structurelles NON re-testées par un 3e run complet (coût) — + re-test au premier usage réel. +- [x] Routage CLAUDE.md (ligne « Grouped all-axes sweep → tour ») +- [ ] Commit branche (pas de finish sans GO) + ## 2026-07-03 — verify loops + semgrep gate + contract (chantier orchestrateurs) Archi validée au gate (session 2026-07-03). Cible : contract sur DISQUE dès création (fichier de run, pattern DIAGNOSIS) + verifier frais (verdict structuré