Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,10 @@ jobs:
os: [ubuntu-latest, windows-latest, macos-latest]
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Provision declared build backend
Expand Down
14 changes: 7 additions & 7 deletions PROJECTION-MANIFEST.sha256
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ ad5c9e60c3e8512adbbe005585ab801cb58b44cb277ad2136fc0c2c42c5ad480 .github/ISSUE_
97dd39f9b48f5eba205125b007204e6241088ad7a4b4e606132107f4b327f41a .github/ISSUE_TEMPLATE/feature_request.yml
b2e36dfcfc6eb31570c9340640bcd73abc62f57c80b4794abf36e3d3e89ab34f .github/dependabot.yml
9e90d43615b02a265b08692ef7a1c00a37477a5c6b1e8233a8fc7bedefaedea6 .github/pull_request_template.md
b045a6fd84dfcf7c82784fe946943cca6e64fed965e781ce876eda9062cbc8f3 .github/workflows/ci.yml
40e5cddf710e4e6fa4984ac864fdb30a7031005ef1a80082ce0cc6a4f9bc115e .github/workflows/ci.yml
e544abe8ffd83c81c7b002cbd2e552f9d56f226ea20e1e0722c5d1bdec914fe0 .gitignore
4a65afea0e3c9d30e235947e15e0fdbabb33885055c053279b0bc659d4b90165 ADOPTING.md
1179c999034f4ec1c1d44c1946bd2955c4625905e80767abe760c8c3ab01c493 CLAUDE.md
Expand All @@ -16,7 +16,7 @@ c274f80372d90c012937370f0e1f15087d22e308ef98b27cea5dc0d2d088366c LICENSES/Apach
a2010f343487d3f7618affe54f789f5487602331c0a8d03f49e9a7c547cf0499 LICENSES/CC0-1.0.txt
59746d6285ffa44bfc7ecada352aa5d6a20dc8eab418a60ce091cc739012c135 LICENSES/MIT-0.txt
35e6d37b7c5fa0c1fc872315cbd362cd24bfa41e1b7dc3019fbcd31e99350f51 NAMING.md
c2bbc10ccbe843bc7a4680a0d56a2833d58569685f6133907c407a6f82a07544 PROJECTION-PROVENANCE.md
52fcf28323ee138b15eaef0c5cf8979eadcb5c7d76baea5792607bc7f4aeae80 PROJECTION-PROVENANCE.md
190008263d9f329d14cc8dd35541cb4910a06ffc42a0d21466a84c4e4f7d3b96 PUBLICATION.md
51a221bad955b1172104340edaa2579c72901df75ab4fd453ee997c9738d1aca README.md
6c4855e221ad30f7ca15baa03f3f8be3f38868210921f0c15b31a30775a940e2 REUSE.toml
Expand Down Expand Up @@ -60,10 +60,10 @@ d2c5a8ca21edf842dfd17a83862024afa0a92349abf693a60e55ce454c8d78fa examples/name-
30cdb11fbeb2fd9bbf4048255331ccbbdd6e516fae5adfa5317af00ce53607c9 governance/ADOPTION-MAPPING.md
08b235351ab7799715b1e2df4fa3dd9fa88bb85084c8aade4d01039bf255b489 governance/LOG-denials-probes.md
50784b173c90c4fd22572306429187c8a7e22614f4b9ad649a3005647467c7fa governance/LOG-denials.jsonl
9b2fed56c129f9671530f4a206c8a1238bddac1d15b2fb2f836472d526443948 governance/LOG.md
080d05377489d7672f654ae0cd606d03a8cf6b9d59f64578a732ce1672883e2b governance/PLAN.md
963eed17b25be834f2a2258da6f4f4a47fa8d4d13be671636a0a4065224ad2cf governance/LOG.md
85d0b38aab88e5241ecb6af2962a3496cb71079d74e6c21be9590ab502f851ad governance/PLAN.md
dd445eb2994e0d9615bc61fe2ae157a6b14ba7b190c65b705d380b31c49fdfe0 governance/ROUTING.md
876b2f4b7f2fa025e514d70514816e2017b92f36dc27f418c1241a38c5bd9d18 governance/STATE.md
6b4fce32eed7eacf82eb2b498e29e9b6ad6d895a138979ea8215520994deb497 governance/STATE.md
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/archive/.gitkeep
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/briefs/.gitkeep
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/decisions/.gitkeep
Expand All @@ -80,7 +80,7 @@ b567ce0c0867464328e81774d888f6491fa66b68ac73be01f993e5c4c66d3ed8 governance/tem
d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 governance/templates/D-adoption-record.md
2b586efadab716a59fcafb74312a45a05401a4787fee6ae18cb5c9dd14ef3a09 governance/templates/E-adoption-mapping.md
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/work-orders/.gitkeep
896e22cd5a26bbe2500eb3770a9b631cb78df4ddd9abb440e96545821fdeb9fb identity/legacy-references.json
14108ecc57f9ef1e5b6c2adf4dc467e947c595d1ced92c4d07ed6669794d79a2 identity/legacy-references.json
345b7e962731c085a95aea66a344eae000b27c9bde13b0d790c76b73273dbe7a init.sh
5c90584642f405534b2071f27396ff293ab01632e4dbb8ccb6b8ec043dca4cc9 migration-guides/0.1-to-0.6.md
ba4eff258ca5b9a45f3f9f1cbf646ba5bc5521fae812adacac65cd2e78698c9d migration-guides/0.6-to-0.7.md
Expand Down Expand Up @@ -117,7 +117,7 @@ d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 templates/D-ad
5a63aad5f8cc8a1e880bb2767d9f006dd3b595bd9dba993fc560e2d7d498c10c tests/test_check_distribution.py
b046f2eea794070194294a33f2914e627eed384e63fccffc2ac46693db2a968c tests/test_check_licenses.py
9a106ff5182b4a15713575de42e90b0dc5cdeebcb17ba08d97522a4c9aa6b2fa tests/test_check_work_order_dispatch.py
dc267b7d9ea957a5a7ae7122c49455c173afdb942c44fc66381b99f26a09c2e7 tests/test_distribution.py
271a2e0e6e2ad79d48a0c6ae53d60648d51fe338d2d578e08b9e9416cd912dd2 tests/test_distribution.py
e150a2f988a4b0beac5f70644f55f5e185a8aa575e988a19642bafabc0f07775 tests/test_identity_migration.py
011d79618848880de8600b11bcedbdd6ba8b68124ddc3ae3e522288639c2498c tests/test_init_sh.py
96c255d84e37b8884cde769897e763776b81027080c2308c33dc5e4b8df4a4bf tests/test_name_clearance.py
Expand Down
10 changes: 6 additions & 4 deletions PROJECTION-PROVENANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,16 +5,18 @@ Legacy commit identifiers in projected records refer to that private
source and are intentionally not resolvable from fresh public history.
No private remote URL is recorded here.

- Source commit: `1724e1851570a840fb44012ddf9ae0ffdda531d7`
- Source commit time: `2026-08-30T15:17:38-05:00`
- Source commit: `7efb698303fa93c65265d0423f542bd70badb826`
- Source commit time: `2026-08-31T07:54:31-05:00`
- Projection allowlist SHA-256: `69b9e56d0d121ea9ae9a9100891a51a5a60c8990f87b4b869691b09184b854fa`

## Legacy identifier inventory

- `11d5960a326750d5838078e36cf38b85af677262` — `.github/workflows/ci.yml`
- `11d5960a326750d5838078e36cf38b85af677262` — `tests/test_distribution.py`
- `3d3c42e5aac5ba805825da76410c181273ba90b1` — `.github/workflows/ci.yml`, `tests/test_distribution.py`
- `5fda3b95a4ea91299a34e894583c3862153e4b97` — `.github/workflows/ci.yml`, `tests/test_distribution.py`
- `6e165e585f907baf83a787ba5cc71270a5a4652e` — `checks/check_distribution.py`, `governance/decisions/DR-001.md`, `tests/test_distribution.py`
- `8d5b2b3668ef626525e57028ac09661e17d44edc` — `governance/LOG.md`, `governance/PLAN.md`, `governance/STATE.md`, `governance/decisions/DR-001.md`
- `a26af69be951a213d495a4c3e4e4022e16d87065` — `.github/workflows/ci.yml`
- `a26af69be951a213d495a4c3e4e4022e16d87065` — `tests/test_distribution.py`
- `a6a71fee0b567e8c70a7ea518398af48b4d0175d` — `governance/decisions/DR-001.md`
- `a905c87987f31094121c11a3b8163f97ef1abcf4` — `SELF-HOSTING.md`, `governance/STATE.md`, `governance/decisions/DR-001.md`
- `ba3c0754e5019f1fa93779d110843562cfa07307` — `governance/STATE.md`
Expand Down
23 changes: 23 additions & 0 deletions governance/LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -627,6 +627,29 @@ Codex was outside the installed Claude Code hook, so the strict classification
remained **8 / 0 / 8** and no denial was generated. Issue #10 proceeds through
the separately authorized post-closeout public PR; issue #11 remains separate.

### Post-pilot WO-WW-005 completed record

WO-WW-005 is post-pilot and does not add an eleventh metrics row or change the
accepted ten-order aggregate. The Owner accepted it on 2026-08-31 and reported
active minutes **NOT REPORTED**.

The order replaced the exact-SHA checkout v4 and setup-python v5 pins with the
official Node-24-native checkout `v7.0.1` and setup-python `v7.0.0` revisions.
Official release metadata and action manifests established the release tags,
commit SHAs, and `node24` runtime before dispatch. The 3-OS by 5-Python matrix,
read-only permission, full-history checkout, declared build-backend
provisioning, focused/full test split, and stable `CI required` job are
unchanged.

The exact-pin public-interface regression failed on the old checkout pin, then
passed after only the two workflow references changed. Three focused contract
tests and the complete 715-test Windows suite passed, with two skips. Fresh
review found no implementation defect and returned one report-only command-
evidence omission; corrected re-review returned **ACCEPT**. No denial, RFI,
same-work-order implementation drift, later-detected drift, dependency change,
or public mutation occurred before acceptance. The public issue #11 PR and its
live complete matrix remain the separately authorized closeout tail.

---

## Column definitions
Expand Down
11 changes: 11 additions & 0 deletions governance/PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -451,6 +451,17 @@ increments within that series. No historical record is renamed or renumbered.
the defect record and proceeds through a post-closeout projection PR. GitHub
Actions runtime maintenance remains separately tracked by issue #11.

5. **WO-WW-005 — COMPLETE: GitHub Actions Node 24 refresh.** Replaced the exact
full-SHA checkout v4 and setup-python v5 pins with verified official
Node-24-native `v7.0.1` and `v7.0.0` releases. The 3-OS by 5-Python matrix,
full-history checkout, read-only permissions, declared build-backend
provisioning, focused/full test split, and stable `CI required` check remain
unchanged and executable-test protected. Windows passed 715 tests with two
skips; corrected fresh record review returned ACCEPT. Public issue #11 is
the defect record and proceeds through the authorized post-closeout
projection PR. Dependency maintenance entered through governed source, not
by directly merging Dependabot PRs into the public projection.

The minimum supported topology is one human Owner, one Owner-Agent, one or more
bounded Operators, and a fresh Reviewer. On small projects one capable agent
may perform coordinator, dispatcher, and recorder roles sequentially, but a
Expand Down
18 changes: 10 additions & 8 deletions governance/STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,14 +11,15 @@ accepted WO-PL-038 wall-glyph identity correction, accepted WO-PL-039
cache-safe public-identity and repository hardening, accepted WO-PL-040
executable day-zero coordination, accepted WO-WW-001 architect-interview and
inception evidence, accepted WO-WW-002 build-backend provisioning recovery, and
accepted WO-WW-003 retained-identity ledger refresh, and accepted WO-WW-004
managed day-zero privacy screening.
accepted WO-WW-003 retained-identity ledger refresh, accepted WO-WW-004
managed day-zero privacy screening, and accepted WO-WW-005 GitHub Actions Node
24 refresh.

**Derived:** 2026-08-30 from the ten accepted pilot records, the Doctrine 9.3.1
**Derived:** 2026-08-31 from the ten accepted pilot records, the Doctrine 9.3.1
fresh-agent evaluation, ratified DR-002 and project-migration DR-003, and
accepted WO-PL-017 through WO-PL-023 and WO-PL-025 through WO-PL-033 records,
the WO-PL-024 sequencing recovery, the verified public-release event, and the
accepted WO-WW-001 through WO-WW-004 closeout records.
accepted WO-WW-001 through WO-WW-005 closeout records.
**Boundary:** post-adoption, all 10 counted pilot work orders and their
evaluation complete; WO-PL-017 remediation complete; DR-003 ratified;
WO-PL-018 through WO-PL-023 complete; WO-PL-024 void before implementation;
Expand All @@ -30,9 +31,9 @@ the current identity with the two-line wall glyph; WO-PL-039 complete and
accepted, with public PR #5 merged after the required CI passed and issue #4
closed; WO-PL-040 complete and accepted; public PR #8 merged and issue #1
closed; the historical `WO-PL` series ends at 040; **WO-WW-001 through
WO-WW-004 are COMPLETE and accepted**; public PR #9 merged with protected CI
green; the authorized WO-WW-004 post-closeout projection PR remains external
closeout work.
WO-WW-005 are COMPLETE and accepted**; public PR #9 and #12 merged with
protected CI green; the authorized WO-WW-005 issue #11 projection PR remains
external closeout work.
The hash of the commit containing this file is intentionally recorded only
externally.

Expand Down Expand Up @@ -91,7 +92,8 @@ externally.
| WO-WW-003 | **COMPLETE**, accepted 2026-08-30 under the Owner-approved complete PR #9 correction lifecycle. Two first post-WO-WW-002 projections failed closed on stale retained digests; both candidates were deleted. Exactly four digest fields for `governance/PLAN.md`, `governance/STATE.md`, and `tests/test_distribution.py` were refreshed without changing classification, context, transform, or enforcement. Source identity and 17 focused tests passed; corrected fresh review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public PR #9 refresh and protected-CI verification remain an external closeout tail; merge, release, tag, deploy, and visibility change are excluded |
| WO-WW-004 | **COMPLETE**, accepted 2026-08-30; managed day-zero privacy screening. `writwall start` initializes a durable project-specific OS-local profile; normal projection build/check commands resolve it without a human-supplied path; temporary cleanup preserves it. Windows passed 715 tests with two skips; native Ubuntu privacy tests and owner-only mode checks passed; two independent 131-file candidates were checker-clean and byte-identical; corrected fresh re-review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public issue #10 proceeds through the authorized post-closeout public PR; issue #11 remains separate |
| Pilot progress | **10 of 10 counted work orders complete; fresh-agent evaluation accepted with calibrations and disposed by DR-002** |
| Post-pilot sequence | **WO-PL-017 through WO-PL-023 COMPLETE**; WO-PL-024 **VOID BEFORE IMPLEMENTATION**; WO-PL-025 through WO-PL-040 **COMPLETE**; public PR #8 merged and issue #1 closed; historical `WO-PL` identifiers end at 040; **WO-WW-001 through WO-WW-004 COMPLETE and accepted**; public PR #9 merged with protected CI green; WO-WW-004 public PR pending |
| WO-WW-005 | **COMPLETE**, accepted 2026-08-31; official Node-24-native checkout `v7.0.1` and setup-python `v7.0.0` revisions are full-SHA pinned. The 3-OS by 5-Python matrix, permissions, full-history checkout, build provisioning, test split, and stable required check are unchanged. Windows passed 715 tests with two skips; corrected fresh record re-review returned ACCEPT. Owner active minutes **NOT REPORTED**. Public issue #11 proceeds through the authorized post-closeout public PR; merge awaits a completely green live matrix and further Owner disposition |
| Post-pilot sequence | **WO-PL-017 through WO-PL-023 COMPLETE**; WO-PL-024 **VOID BEFORE IMPLEMENTATION**; WO-PL-025 through WO-PL-040 **COMPLETE**; public PR #8 merged and issue #1 closed; historical `WO-PL` identifiers end at 040; **WO-WW-001 through WO-WW-005 COMPLETE and accepted**; public PR #9 and #12 merged with protected CI green; public issues #1, #4, and #10 closed; WO-WW-005 issue #11 public PR pending |
| Bootstrap history | Eleven completed work orders retained as uncounted pre-adoption evidence under `archive/pre-adoption-bootstrap/` |

### Verification accepted at WO-PL-016 closeout
Expand Down
10 changes: 5 additions & 5 deletions identity/legacy-references.json
Original file line number Diff line number Diff line change
Expand Up @@ -94,19 +94,19 @@
{
"path": "governance/LOG.md",
"context": "historical_pilot_summary",
"sha256": "9b2fed56c129f9671530f4a206c8a1238bddac1d15b2fb2f836472d526443948",
"sha256": "963eed17b25be834f2a2258da6f4f4a47fa8d4d13be671636a0a4065224ad2cf",
"projection_transform": "private_evidence_redaction"
},
{
"path": "governance/PLAN.md",
"context": "ratified_historical_intent",
"sha256": "080d05377489d7672f654ae0cd606d03a8cf6b9d59f64578a732ce1672883e2b"
"sha256": "85d0b38aab88e5241ecb6af2962a3496cb71079d74e6c21be9590ab502f851ad"
},
{
"path": "governance/STATE.md",
"context": "mixed_current_state_and_history",
"sha256": "f722cc515f4e50023bb558e132212fdd71030ff65a2c7b79fe8047f62fc2f80a",
"projection_sha256": "876b2f4b7f2fa025e514d70514816e2017b92f36dc27f418c1241a38c5bd9d18"
"sha256": "16392d93a738a2a9959daec90e26e8c8035324eb316abbc6867e7251bdbbd370",
"projection_sha256": "6b4fce32eed7eacf82eb2b498e29e9b6ad6d895a138979ea8215520994deb497"
},
{
"path": "governance/decisions/DR-001.md",
Expand All @@ -127,7 +127,7 @@
{
"path": "tests/test_distribution.py",
"context": "historical_evidence_fixture",
"sha256": "dc267b7d9ea957a5a7ae7122c49455c173afdb942c44fc66381b99f26a09c2e7"
"sha256": "271a2e0e6e2ad79d48a0c6ae53d60648d51fe338d2d578e08b9e9416cd912dd2"
},
{
"path": "tests/test_identity_migration.py",
Expand Down
6 changes: 4 additions & 2 deletions tests/test_distribution.py
Original file line number Diff line number Diff line change
Expand Up @@ -1160,12 +1160,14 @@ def test_repository_automation_is_pinned_and_maintainable(self):

self.assertRegex(
workflow,
r"(?m)uses: actions/checkout@[0-9a-f]{40} # v4$",
r"(?m)uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7\.0\.1$",
)
self.assertRegex(
workflow,
r"(?m)uses: actions/setup-python@[0-9a-f]{40} # v5$",
r"(?m)uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7\.0\.0$",
)
self.assertNotIn("11d5960a326750d5838078e36cf38b85af677262", workflow)
self.assertNotIn("a26af69be951a213d495a4c3e4e4022e16d87065", workflow)
self.assertIn("required:", workflow)
self.assertIn("name: CI required", workflow)
self.assertIn("needs: test", workflow)
Expand Down