feat(ai-systems): register the AI systems you use and see the high-risk ones without a FRIA - #1191
Merged
Merged
Conversation
…d before the change
…sk ones without a FRIA
…ree demo systems, formatters in their own module
Contributor
Quality Report — ConductionNL/stackiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| check-vue-demi | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| check-schema-l10n | ✅ | ||||
| check-l10n-js | ✅ | ||||
| composer | ✅ | ✅ 130/130 | |||
| npm | ✅ | ✅ 807/807 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ✅ | ||||
| Newman | ⏭️ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ✅ |
Quality workflow — 2026-09-29 19:42 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change:
landscape-ai-system-inventory(archived here as2026-09-29-landscape-ai-system-inventory; its spec is nowopenspec/specs/ai-system-inventory/spec.md).Rows moved to built:
stackiq:comp-ai-act-classification(rated yes now) andstackiq:land-ai-agent-inventory(rated partial: AI systems link to applications; the link to processes waits forarchitecture-process-mapping, as the proposal says).What a user can now do: open Applications, then AI systems, and register the AI agents, AI models and AI features the organisation uses, each linked to the application it runs in, with its supplier and purpose. Each AI system records its EU AI Act risk category, the organisation's role, the date of the last assessment, its algorithm register entry and a reference to its fundamental rights impact assessment (FRIA). Evidence files carry the tags FRIA, Technical documentation, Human oversight and Logging, and the AI Act evidence panel on the page shows which are there. The list filters on each risk category and on High risk without FRIA; such a system reads FRIA missing in the list and shows a warning on its page. The application page lists its AI systems.
How: the
aiSystemschema joins the stackiq register inlib/Settings/softwarecatalogus_register.json(register 2.5.3). The design put it in aregister.dfragment, but this repo's own tests allow a fragment only to overlay a schema the monolith declares, so the design now says so. The schema has a lifecycle (release, withdraw) on exactly its status values, and reads scoped to the organisation that registered it and to the supplier; a manifest fragmentsrc/manifest.d/ai-systems.jsonwith the list and detail pages under Applications (ADR-097); anmd-ai-systemslist on ModuleDetail;AiActChecklistas a body widget (it reads the object's files and their tags, which no built-in widget lists per tag); the app cell formatterfriaStatusinsrc/formatters.js, passed to CnAppRoot (the connection-registry spec asserted App.vue passes no formatters; it now asserts that none of the app's formatters shadows a library built-in, which was the reason for it); three demo AI systems, one of them high risk without a FRIA. The quick filter sendsfriaDocumentRef=IS NULL, which OpenRegister's property filter reads as a null check.Scenarios and the tests that prove them:
tests/Unit/Settings/AiSystemFragmentTest.php(5 tests, all red on development: no aiSystem schema there).tests/vitest/aiSystems.spec.js(15 tests, red on development: the file failed to load).tests/e2e/workflows/ai-systems.spec.ts(Playwright, seeds and removes its own rows through the objects API). It lists (3 tests); it was not run here, because no local instance has a seeded stackiq register.New text is in English and Dutch. Docs:
docs/features/ai-systems.md; its screenshot waits for a seeded instance.Checks (one run on the branch head, which contains development at ba60bb1): composer check:strict exit 0; PHPUnit 927 tests, 20 errors, all 20 inherited (MigrateRegisterSlugTest x12, MigrateSchemaApplicationIdTest x7, PortfolioReportControllerTest::testCsvFormatReturnsDownloadResponse, the same names as on development); npm lint, stylelint, format, test:l10n, check:schema-l10n, check:l10n-js, check:manifest, check:vue-demi exit 0; jest 100 passed; vitest 329 passed; Hydra gates (ConductionNL/.github main, full scope, --require-full-coverage) exit 0, 85 of 85 applicable gates pass. The seed commit (97500a2) was re-run for PHPUnit, check:schema-l10n, check:manifest and the gates.
Live check: after the register re-imports, open Applications, AI systems; the three demo systems show and the scoring model reads FRIA missing; the High risk without FRIA filter lists only it; its page shows the warning and FRIA as missing in AI Act evidence. Link an AI system to an application and open that application: its AI systems section lists it.