docs: ADR 由来のドキュメント drift を修正(SEC_review 観点5・deployment の secret 一覧)#462
Conversation
- SEC_review スキルの観点5「LLM プロンプトのサニタイズ」を更新。 ADR-0008(LLM 廃止)当時の記述のままだったが、ADR-0010 で DevForge Agent として LLM を再導入済みのため、現行アーキテクチャ(context_builder / 静的プロンプト / 構造化出力)に即した確認項目に置き換え - docs/deployment.md の常時注入 secret 一覧から anthropic-api-key を削除。 ADR-0015 で Anthropic / Gemini は Vertex AI(ADC)経由へ移行済みで、 infra 実装(cloud_run/main.tf)では注入・コンテナとも削除済みだった Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
ADR が個別の技術判断として独立しており、プロダクト全体の意思決定として
横断参照できない課題への対応(設計リファレンス化の基盤)。
- docs/adr/README.md を新設し、一覧・関係(テーマ・置き換え・関連)の正本とする
- 現在有効な決定(Accepted)の早見表
- 全 ADR 一覧(ステータス・テーマ・置き換え/関連)
- テーマ別の決定系統図(Mermaid)+ 系統の物語(LLM 系の導入→撤去→再導入の
往復、0005 の根拠入れ替わり等)
- CONTRIBUTING.md の ADR 一覧表を削除し索引へ一本化(0012〜0015・0017 未掲載、
0006 ステータス古い等の陳腐化が実際に起きていたため、複製を消す)
- 0000-template.md に「関連 ADR」欄(Supersedes / Superseded by / 関連)を追加
- scripts/lint-adr-index.sh を新設(lint-env-keys.sh と同型・bash のみ):
索引↔ファイルの存在(双方向)・ステータス・見出し番号を突合。
make lint / test.yml に組込み、PR テンプレートにチェック項目を追加
- 0011 の見出し誤記(# ADR-0009:)を修正
- CLAUDE.md の ADR 節を索引起点の参照フローに更新
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
ADR 17 本から帰納抽出した 7 つの設計原則を docs/design-principles.md に言語化: - P1 コスト最適化を第一制約にする - P2 PII を信頼境界の外に出さない - P3 正本を定め、規律は機械検証で守る - P4 責務を層で分離する - P5 デフォルトは決定論、LLM は対話型に限定する - P6 可逆性を設計する - P7 依存は固定し、追従は自動化する 各原則に「内容 / 根拠となった判断(ADR 引用) / 例外・緊張関係」を記述し、 原則 × ADR 対応マトリクス(● 主 / ○ 従)を付与。原則の改訂は ADR 経由という メタルールを明記した。 - ADR 索引の全 ADR 一覧に「原則」列(中心的な判断軸の ID)を追加 - ADR テンプレートに「設計原則との関係」欄を追加 - README のドキュメント表・CLAUDE.md・CONTRIBUTING.md から参照を追加 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
|
Warning Review limit reached
Next review available in: 18 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis PR establishes ChangesADR Index Governance and Validation
Estimated code review effort: 2 (Simple) | ~15 minutes Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
scripts/lint-adr-index.sh (1)
94-126: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winConsider also validating title consistency between the two tables.
Status/Accepted-set drift is checked between "全 ADR 一覧" and "現在有効な決定", but title text isn't cross-checked between the two tables. If a title is updated in one table but not the other, the lint won't catch it.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/lint-adr-index.sh` around lines 94 - 126, The current lint in lint-adr-index.sh only compares ADR status and the Accepted set, so title text can drift between the “全 ADR 一覧” and “現在有効な決定” tables without detection. Extend the existing table cross-check logic near the accepted_file_nums/index_accepted_nums handling to also extract each ADR title from both tables and compare them for matching ADR numbers, emitting an error when the same ADR has different titles. Keep the check aligned with the existing parsing style and use the same ADR identifiers (for example ADR-$num) so mismatches are reported consistently.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@scripts/lint-adr-index.sh`:
- Around line 94-126: The current lint in lint-adr-index.sh only compares ADR
status and the Accepted set, so title text can drift between the “全 ADR 一覧” and
“現在有効な決定” tables without detection. Extend the existing table cross-check logic
near the accepted_file_nums/index_accepted_nums handling to also extract each
ADR title from both tables and compare them for matching ADR numbers, emitting
an error when the same ADR has different titles. Keep the check aligned with the
existing parsing style and use the same ADR identifiers (for example ADR-$num)
so mismatches are reported consistently.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: aff473d3-dcc4-4495-bf17-3e2eade34d9a
📒 Files selected for processing (13)
.claude/CLAUDE.md.claude/skills/SEC_review/SKILL.md.github/PULL_REQUEST_TEMPLATE.md.github/workflows/test.ymlCONTRIBUTING.mdMakefileREADME.mddocs/adr/0000-template.mddocs/adr/0011-frontend-textlint-proofread.mddocs/adr/README.mddocs/deployment.mddocs/design-principles.mdscripts/lint-adr-index.sh
scripts/lint-adr-index.sh はステータス突合はしていたが、「全 ADR 一覧」と 「現在有効な決定」のタイトル列は未検証だった。片方だけリネームして更新し忘れる drift を検知できるよう、両表に存在する ADR のタイトルが一致するかを追加検証する。 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
ADR-0008(LLM 廃止)当時の記述のままだったが、ADR-0010 で DevForge Agent
として LLM を再導入済みのため、現行アーキテクチャ(context_builder /
静的プロンプト / 構造化出力)に即した確認項目に置き換え
ADR-0015 で Anthropic / Gemini は Vertex AI(ADC)経由へ移行済みで、
infra 実装(cloud_run/main.tf)では注入・コンテナとも削除済みだった
Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_015qpm5pb2utquc7NsTtru5J
Summary by CodeRabbit
New Features
Documentation
Bug Fixes