Files
RepoFoundry/docs/sqa/reviews/rc-020-mil-005.md
2026-10-06 12:47:33 +08:00

5.1 KiB

SQA Review Record: MIL-005 and the planning change it causes

Metadata

Key Value
ID RC-020
CrossReference MIL-005, QC-MIL-001, US-001, UC-001

Version History

Date Status Author Reviewer Change Commit
2026-10-06 Proposed Jens Tirsvad Nielsen S02 Initial version ded26a6

Artifact Under Review

Checklist Results (MIL-005, QC-MIL-001)

# Criterion Status Evidence/Notes
1 A concrete deliverable is defined for every gate Pass A script that asks for a missing credential and creates the new project's .env, the documentation of the feature and its risk, and tests for every case.
2 Explicit Go/No-Go criteria are stated for each gate Pass Nine criteria, each with an objective Go and No-Go, including all acceptance criteria of US-001.05.
3 Dependencies on other milestones are explicitly mapped Pass Depends on [MIL-004], with the reason.
4 Each milestone is traceable to a Business Case objective or KPI Pass Maps to objective 9, the amended objective 6 and success criteria 1 and 9 of BC-001, and to US-001.05.
5 Milestone owner and approving reviewer are identified Pass Owner S01, approving reviewer S02.
6 Milestone has a defined target date consistent with project constraints Pass 2026-11-27 matches PP-001; the Business Case sets no duration, so nothing conflicts. The date is a proposal and is accepted here.

Change checks on the other artifacts

Artifact Change Status Evidence/Notes
BC-001 Objective 9, scope items, success criterion 9, a risk and a constraint; objective 6 and success criterion 1 amended Pass The security guarantee is weakened on purpose and said so in the same place: a token may be written only to the new project's .env, after a yes. The risk row lists the mitigations.
US-001 US-001.05 with five acceptance criteria Pass Given/when/then; traces to UC-001 and MIL-005; the last criterion keeps the "no credential in output" rule.
UC-001 Precondition, step 2 and 9 notes, extensions 2b, 9c, 9d, a postcondition and two business rules Pass Extension 2b ends before any change when input ends; 9c and 9d keep "never replaced without a yes".
SSD-001 writeEnvFile and the credentials not provided in .env become parameters; the lifecycle note names the one thing that persists Pass One new parameter and a note; the operations are unchanged.
OC-001 Postcondition P14, a precondition, two exceptions, and P2 reworded Pass P14 states the contents, the mode, the git exclusion and "no credential shown".
SD-001 CredentialCollector and EnvFileWriter and their messages Pass Every new postcondition has a message; the coverage table is updated. Three lines damaged by an earlier edit (actor Maintainer, the first provideProjectDetails message, the final summary return) are restored in this change.
DM-001, DM-002 Concept Credentials File and two associations Pass Both models changed in the same way.
DICT-001 Credentials File ↔ EnvFile Pass One PO term and one IT term, as the dictionary rules require.
PP-001 Phase MIL-005, dependency chain, timeline Pass Dates agree with MIL-005.

One point for the implementation: the Go/No-Go criterion 5 says the file has mode 600 "from the moment it is created". That means the script must create it under umask 077 (or with install -m 600) and not write it first and restrict it afterwards. Task 2 already says so.

Overall Verdict

Go — MIL-005 passes every mandatory criterion and the changes to the other artifacts are consistent with each other. The weakening of the credential guarantee is deliberate, bounded and recorded in the Business Case. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.

Action Items

Action Owner Due
None - -