From 64dd9134f1964d93c267d17712030adf9cdb955d Mon Sep 17 00:00:00 2001 From: HLLMR Date: Mon, 31 Aug 2026 07:58:52 -0500 Subject: [PATCH] Refresh GitHub Actions for Node 24 --- .github/workflows/ci.yml | 4 ++-- PROJECTION-MANIFEST.sha256 | 14 +++++++------- PROJECTION-PROVENANCE.md | 10 ++++++---- governance/LOG.md | 23 +++++++++++++++++++++++ governance/PLAN.md | 11 +++++++++++ governance/STATE.md | 18 ++++++++++-------- identity/legacy-references.json | 10 +++++----- tests/test_distribution.py | 6 ++++-- 8 files changed, 68 insertions(+), 28 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5d45e0d..333dc5a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,10 +19,10 @@ jobs: os: [ubuntu-latest, windows-latest, macos-latest] python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"] steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} - name: Provision declared build backend diff --git a/PROJECTION-MANIFEST.sha256 b/PROJECTION-MANIFEST.sha256 index 1c48c0c..075bfda 100644 --- a/PROJECTION-MANIFEST.sha256 +++ b/PROJECTION-MANIFEST.sha256 @@ -3,7 +3,7 @@ ad5c9e60c3e8512adbbe005585ab801cb58b44cb277ad2136fc0c2c42c5ad480 .github/ISSUE_ 97dd39f9b48f5eba205125b007204e6241088ad7a4b4e606132107f4b327f41a .github/ISSUE_TEMPLATE/feature_request.yml b2e36dfcfc6eb31570c9340640bcd73abc62f57c80b4794abf36e3d3e89ab34f .github/dependabot.yml 9e90d43615b02a265b08692ef7a1c00a37477a5c6b1e8233a8fc7bedefaedea6 .github/pull_request_template.md -b045a6fd84dfcf7c82784fe946943cca6e64fed965e781ce876eda9062cbc8f3 .github/workflows/ci.yml +40e5cddf710e4e6fa4984ac864fdb30a7031005ef1a80082ce0cc6a4f9bc115e .github/workflows/ci.yml e544abe8ffd83c81c7b002cbd2e552f9d56f226ea20e1e0722c5d1bdec914fe0 .gitignore 4a65afea0e3c9d30e235947e15e0fdbabb33885055c053279b0bc659d4b90165 ADOPTING.md 1179c999034f4ec1c1d44c1946bd2955c4625905e80767abe760c8c3ab01c493 CLAUDE.md @@ -16,7 +16,7 @@ c274f80372d90c012937370f0e1f15087d22e308ef98b27cea5dc0d2d088366c LICENSES/Apach a2010f343487d3f7618affe54f789f5487602331c0a8d03f49e9a7c547cf0499 LICENSES/CC0-1.0.txt 59746d6285ffa44bfc7ecada352aa5d6a20dc8eab418a60ce091cc739012c135 LICENSES/MIT-0.txt 35e6d37b7c5fa0c1fc872315cbd362cd24bfa41e1b7dc3019fbcd31e99350f51 NAMING.md -c2bbc10ccbe843bc7a4680a0d56a2833d58569685f6133907c407a6f82a07544 PROJECTION-PROVENANCE.md +52fcf28323ee138b15eaef0c5cf8979eadcb5c7d76baea5792607bc7f4aeae80 PROJECTION-PROVENANCE.md 190008263d9f329d14cc8dd35541cb4910a06ffc42a0d21466a84c4e4f7d3b96 PUBLICATION.md 51a221bad955b1172104340edaa2579c72901df75ab4fd453ee997c9738d1aca README.md 6c4855e221ad30f7ca15baa03f3f8be3f38868210921f0c15b31a30775a940e2 REUSE.toml @@ -60,10 +60,10 @@ d2c5a8ca21edf842dfd17a83862024afa0a92349abf693a60e55ce454c8d78fa examples/name- 30cdb11fbeb2fd9bbf4048255331ccbbdd6e516fae5adfa5317af00ce53607c9 governance/ADOPTION-MAPPING.md 08b235351ab7799715b1e2df4fa3dd9fa88bb85084c8aade4d01039bf255b489 governance/LOG-denials-probes.md 50784b173c90c4fd22572306429187c8a7e22614f4b9ad649a3005647467c7fa governance/LOG-denials.jsonl -9b2fed56c129f9671530f4a206c8a1238bddac1d15b2fb2f836472d526443948 governance/LOG.md -080d05377489d7672f654ae0cd606d03a8cf6b9d59f64578a732ce1672883e2b governance/PLAN.md +963eed17b25be834f2a2258da6f4f4a47fa8d4d13be671636a0a4065224ad2cf governance/LOG.md +85d0b38aab88e5241ecb6af2962a3496cb71079d74e6c21be9590ab502f851ad governance/PLAN.md dd445eb2994e0d9615bc61fe2ae157a6b14ba7b190c65b705d380b31c49fdfe0 governance/ROUTING.md -876b2f4b7f2fa025e514d70514816e2017b92f36dc27f418c1241a38c5bd9d18 governance/STATE.md +6b4fce32eed7eacf82eb2b498e29e9b6ad6d895a138979ea8215520994deb497 governance/STATE.md e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/archive/.gitkeep e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/briefs/.gitkeep e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/decisions/.gitkeep @@ -80,7 +80,7 @@ b567ce0c0867464328e81774d888f6491fa66b68ac73be01f993e5c4c66d3ed8 governance/tem d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 governance/templates/D-adoption-record.md 2b586efadab716a59fcafb74312a45a05401a4787fee6ae18cb5c9dd14ef3a09 governance/templates/E-adoption-mapping.md e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/work-orders/.gitkeep -896e22cd5a26bbe2500eb3770a9b631cb78df4ddd9abb440e96545821fdeb9fb identity/legacy-references.json +14108ecc57f9ef1e5b6c2adf4dc467e947c595d1ced92c4d07ed6669794d79a2 identity/legacy-references.json 345b7e962731c085a95aea66a344eae000b27c9bde13b0d790c76b73273dbe7a init.sh 5c90584642f405534b2071f27396ff293ab01632e4dbb8ccb6b8ec043dca4cc9 migration-guides/0.1-to-0.6.md ba4eff258ca5b9a45f3f9f1cbf646ba5bc5521fae812adacac65cd2e78698c9d migration-guides/0.6-to-0.7.md @@ -117,7 +117,7 @@ d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 templates/D-ad 5a63aad5f8cc8a1e880bb2767d9f006dd3b595bd9dba993fc560e2d7d498c10c tests/test_check_distribution.py b046f2eea794070194294a33f2914e627eed384e63fccffc2ac46693db2a968c tests/test_check_licenses.py 9a106ff5182b4a15713575de42e90b0dc5cdeebcb17ba08d97522a4c9aa6b2fa tests/test_check_work_order_dispatch.py -dc267b7d9ea957a5a7ae7122c49455c173afdb942c44fc66381b99f26a09c2e7 tests/test_distribution.py +271a2e0e6e2ad79d48a0c6ae53d60648d51fe338d2d578e08b9e9416cd912dd2 tests/test_distribution.py e150a2f988a4b0beac5f70644f55f5e185a8aa575e988a19642bafabc0f07775 tests/test_identity_migration.py 011d79618848880de8600b11bcedbdd6ba8b68124ddc3ae3e522288639c2498c tests/test_init_sh.py 96c255d84e37b8884cde769897e763776b81027080c2308c33dc5e4b8df4a4bf tests/test_name_clearance.py diff --git a/PROJECTION-PROVENANCE.md b/PROJECTION-PROVENANCE.md index 64b0a01..b4f068f 100644 --- a/PROJECTION-PROVENANCE.md +++ b/PROJECTION-PROVENANCE.md @@ -5,16 +5,18 @@ Legacy commit identifiers in projected records refer to that private source and are intentionally not resolvable from fresh public history. No private remote URL is recorded here. -- Source commit: `1724e1851570a840fb44012ddf9ae0ffdda531d7` -- Source commit time: `2026-08-30T15:17:38-05:00` +- Source commit: `7efb698303fa93c65265d0423f542bd70badb826` +- Source commit time: `2026-08-31T07:54:31-05:00` - Projection allowlist SHA-256: `69b9e56d0d121ea9ae9a9100891a51a5a60c8990f87b4b869691b09184b854fa` ## Legacy identifier inventory -- `11d5960a326750d5838078e36cf38b85af677262` — `.github/workflows/ci.yml` +- `11d5960a326750d5838078e36cf38b85af677262` — `tests/test_distribution.py` +- `3d3c42e5aac5ba805825da76410c181273ba90b1` — `.github/workflows/ci.yml`, `tests/test_distribution.py` +- `5fda3b95a4ea91299a34e894583c3862153e4b97` — `.github/workflows/ci.yml`, `tests/test_distribution.py` - `6e165e585f907baf83a787ba5cc71270a5a4652e` — `checks/check_distribution.py`, `governance/decisions/DR-001.md`, `tests/test_distribution.py` - `8d5b2b3668ef626525e57028ac09661e17d44edc` — `governance/LOG.md`, `governance/PLAN.md`, `governance/STATE.md`, `governance/decisions/DR-001.md` -- `a26af69be951a213d495a4c3e4e4022e16d87065` — `.github/workflows/ci.yml` +- `a26af69be951a213d495a4c3e4e4022e16d87065` — `tests/test_distribution.py` - `a6a71fee0b567e8c70a7ea518398af48b4d0175d` — `governance/decisions/DR-001.md` - `a905c87987f31094121c11a3b8163f97ef1abcf4` — `SELF-HOSTING.md`, `governance/STATE.md`, `governance/decisions/DR-001.md` - `ba3c0754e5019f1fa93779d110843562cfa07307` — `governance/STATE.md` diff --git a/governance/LOG.md b/governance/LOG.md index fd0b1cc..a5e7636 100644 --- a/governance/LOG.md +++ b/governance/LOG.md @@ -627,6 +627,29 @@ Codex was outside the installed Claude Code hook, so the strict classification remained **8 / 0 / 8** and no denial was generated. Issue #10 proceeds through the separately authorized post-closeout public PR; issue #11 remains separate. +### Post-pilot WO-WW-005 completed record + +WO-WW-005 is post-pilot and does not add an eleventh metrics row or change the +accepted ten-order aggregate. The Owner accepted it on 2026-08-31 and reported +active minutes **NOT REPORTED**. + +The order replaced the exact-SHA checkout v4 and setup-python v5 pins with the +official Node-24-native checkout `v7.0.1` and setup-python `v7.0.0` revisions. +Official release metadata and action manifests established the release tags, +commit SHAs, and `node24` runtime before dispatch. The 3-OS by 5-Python matrix, +read-only permission, full-history checkout, declared build-backend +provisioning, focused/full test split, and stable `CI required` job are +unchanged. + +The exact-pin public-interface regression failed on the old checkout pin, then +passed after only the two workflow references changed. Three focused contract +tests and the complete 715-test Windows suite passed, with two skips. Fresh +review found no implementation defect and returned one report-only command- +evidence omission; corrected re-review returned **ACCEPT**. No denial, RFI, +same-work-order implementation drift, later-detected drift, dependency change, +or public mutation occurred before acceptance. The public issue #11 PR and its +live complete matrix remain the separately authorized closeout tail. + --- ## Column definitions diff --git a/governance/PLAN.md b/governance/PLAN.md index 4f62f29..4378575 100644 --- a/governance/PLAN.md +++ b/governance/PLAN.md @@ -451,6 +451,17 @@ increments within that series. No historical record is renamed or renumbered. the defect record and proceeds through a post-closeout projection PR. GitHub Actions runtime maintenance remains separately tracked by issue #11. +5. **WO-WW-005 — COMPLETE: GitHub Actions Node 24 refresh.** Replaced the exact + full-SHA checkout v4 and setup-python v5 pins with verified official + Node-24-native `v7.0.1` and `v7.0.0` releases. The 3-OS by 5-Python matrix, + full-history checkout, read-only permissions, declared build-backend + provisioning, focused/full test split, and stable `CI required` check remain + unchanged and executable-test protected. Windows passed 715 tests with two + skips; corrected fresh record review returned ACCEPT. Public issue #11 is + the defect record and proceeds through the authorized post-closeout + projection PR. Dependency maintenance entered through governed source, not + by directly merging Dependabot PRs into the public projection. + The minimum supported topology is one human Owner, one Owner-Agent, one or more bounded Operators, and a fresh Reviewer. On small projects one capable agent may perform coordinator, dispatcher, and recorder roles sequentially, but a diff --git a/governance/STATE.md b/governance/STATE.md index 60ff020..db57a2c 100644 --- a/governance/STATE.md +++ b/governance/STATE.md @@ -11,14 +11,15 @@ accepted WO-PL-038 wall-glyph identity correction, accepted WO-PL-039 cache-safe public-identity and repository hardening, accepted WO-PL-040 executable day-zero coordination, accepted WO-WW-001 architect-interview and inception evidence, accepted WO-WW-002 build-backend provisioning recovery, and -accepted WO-WW-003 retained-identity ledger refresh, and accepted WO-WW-004 -managed day-zero privacy screening. +accepted WO-WW-003 retained-identity ledger refresh, accepted WO-WW-004 +managed day-zero privacy screening, and accepted WO-WW-005 GitHub Actions Node +24 refresh. -**Derived:** 2026-08-30 from the ten accepted pilot records, the Doctrine 9.3.1 +**Derived:** 2026-08-31 from the ten accepted pilot records, the Doctrine 9.3.1 fresh-agent evaluation, ratified DR-002 and project-migration DR-003, and accepted WO-PL-017 through WO-PL-023 and WO-PL-025 through WO-PL-033 records, the WO-PL-024 sequencing recovery, the verified public-release event, and the -accepted WO-WW-001 through WO-WW-004 closeout records. +accepted WO-WW-001 through WO-WW-005 closeout records. **Boundary:** post-adoption, all 10 counted pilot work orders and their evaluation complete; WO-PL-017 remediation complete; DR-003 ratified; WO-PL-018 through WO-PL-023 complete; WO-PL-024 void before implementation; @@ -30,9 +31,9 @@ the current identity with the two-line wall glyph; WO-PL-039 complete and accepted, with public PR #5 merged after the required CI passed and issue #4 closed; WO-PL-040 complete and accepted; public PR #8 merged and issue #1 closed; the historical `WO-PL` series ends at 040; **WO-WW-001 through -WO-WW-004 are COMPLETE and accepted**; public PR #9 merged with protected CI -green; the authorized WO-WW-004 post-closeout projection PR remains external -closeout work. +WO-WW-005 are COMPLETE and accepted**; public PR #9 and #12 merged with +protected CI green; the authorized WO-WW-005 issue #11 projection PR remains +external closeout work. The hash of the commit containing this file is intentionally recorded only externally. @@ -91,7 +92,8 @@ externally. | WO-WW-003 | **COMPLETE**, accepted 2026-08-30 under the Owner-approved complete PR #9 correction lifecycle. Two first post-WO-WW-002 projections failed closed on stale retained digests; both candidates were deleted. Exactly four digest fields for `governance/PLAN.md`, `governance/STATE.md`, and `tests/test_distribution.py` were refreshed without changing classification, context, transform, or enforcement. Source identity and 17 focused tests passed; corrected fresh review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public PR #9 refresh and protected-CI verification remain an external closeout tail; merge, release, tag, deploy, and visibility change are excluded | | WO-WW-004 | **COMPLETE**, accepted 2026-08-30; managed day-zero privacy screening. `writwall start` initializes a durable project-specific OS-local profile; normal projection build/check commands resolve it without a human-supplied path; temporary cleanup preserves it. Windows passed 715 tests with two skips; native Ubuntu privacy tests and owner-only mode checks passed; two independent 131-file candidates were checker-clean and byte-identical; corrected fresh re-review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public issue #10 proceeds through the authorized post-closeout public PR; issue #11 remains separate | | Pilot progress | **10 of 10 counted work orders complete; fresh-agent evaluation accepted with calibrations and disposed by DR-002** | -| Post-pilot sequence | **WO-PL-017 through WO-PL-023 COMPLETE**; WO-PL-024 **VOID BEFORE IMPLEMENTATION**; WO-PL-025 through WO-PL-040 **COMPLETE**; public PR #8 merged and issue #1 closed; historical `WO-PL` identifiers end at 040; **WO-WW-001 through WO-WW-004 COMPLETE and accepted**; public PR #9 merged with protected CI green; WO-WW-004 public PR pending | +| WO-WW-005 | **COMPLETE**, accepted 2026-08-31; official Node-24-native checkout `v7.0.1` and setup-python `v7.0.0` revisions are full-SHA pinned. The 3-OS by 5-Python matrix, permissions, full-history checkout, build provisioning, test split, and stable required check are unchanged. Windows passed 715 tests with two skips; corrected fresh record re-review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public issue #11 proceeds through the authorized post-closeout public PR; merge awaits a completely green live matrix and further Owner disposition | +| Post-pilot sequence | **WO-PL-017 through WO-PL-023 COMPLETE**; WO-PL-024 **VOID BEFORE IMPLEMENTATION**; WO-PL-025 through WO-PL-040 **COMPLETE**; public PR #8 merged and issue #1 closed; historical `WO-PL` identifiers end at 040; **WO-WW-001 through WO-WW-005 COMPLETE and accepted**; public PR #9 and #12 merged with protected CI green; public issues #1, #4, and #10 closed; WO-WW-005 issue #11 public PR pending | | Bootstrap history | Eleven completed work orders retained as uncounted pre-adoption evidence under `archive/pre-adoption-bootstrap/` | ### Verification accepted at WO-PL-016 closeout diff --git a/identity/legacy-references.json b/identity/legacy-references.json index 70b88f9..343f46d 100644 --- a/identity/legacy-references.json +++ b/identity/legacy-references.json @@ -94,19 +94,19 @@ { "path": "governance/LOG.md", "context": "historical_pilot_summary", - "sha256": "9b2fed56c129f9671530f4a206c8a1238bddac1d15b2fb2f836472d526443948", + "sha256": "963eed17b25be834f2a2258da6f4f4a47fa8d4d13be671636a0a4065224ad2cf", "projection_transform": "private_evidence_redaction" }, { "path": "governance/PLAN.md", "context": "ratified_historical_intent", - "sha256": "080d05377489d7672f654ae0cd606d03a8cf6b9d59f64578a732ce1672883e2b" + "sha256": "85d0b38aab88e5241ecb6af2962a3496cb71079d74e6c21be9590ab502f851ad" }, { "path": "governance/STATE.md", "context": "mixed_current_state_and_history", - "sha256": "f722cc515f4e50023bb558e132212fdd71030ff65a2c7b79fe8047f62fc2f80a", - "projection_sha256": "876b2f4b7f2fa025e514d70514816e2017b92f36dc27f418c1241a38c5bd9d18" + "sha256": "16392d93a738a2a9959daec90e26e8c8035324eb316abbc6867e7251bdbbd370", + "projection_sha256": "6b4fce32eed7eacf82eb2b498e29e9b6ad6d895a138979ea8215520994deb497" }, { "path": "governance/decisions/DR-001.md", @@ -127,7 +127,7 @@ { "path": "tests/test_distribution.py", "context": "historical_evidence_fixture", - "sha256": "dc267b7d9ea957a5a7ae7122c49455c173afdb942c44fc66381b99f26a09c2e7" + "sha256": "271a2e0e6e2ad79d48a0c6ae53d60648d51fe338d2d578e08b9e9416cd912dd2" }, { "path": "tests/test_identity_migration.py", diff --git a/tests/test_distribution.py b/tests/test_distribution.py index 146ce2a..aab84d0 100644 --- a/tests/test_distribution.py +++ b/tests/test_distribution.py @@ -1160,12 +1160,14 @@ def test_repository_automation_is_pinned_and_maintainable(self): self.assertRegex( workflow, - r"(?m)uses: actions/checkout@[0-9a-f]{40} # v4$", + r"(?m)uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7\.0\.1$", ) self.assertRegex( workflow, - r"(?m)uses: actions/setup-python@[0-9a-f]{40} # v5$", + r"(?m)uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7\.0\.0$", ) + self.assertNotIn("11d5960a326750d5838078e36cf38b85af677262", workflow) + self.assertNotIn("a26af69be951a213d495a4c3e4e4022e16d87065", workflow) self.assertIn("required:", workflow) self.assertIn("name: CI required", workflow) self.assertIn("needs: test", workflow)