Skip to content

research: finalize Zenodo DOI metadata for pilot v1 - #160

Merged
ErenAri merged 7 commits into
mainfrom
research/finalize-zenodo-doi-v1
Sep 19, 2026
Merged

ErenAri merged 7 commits into
mainfrom
research/finalize-zenodo-doi-v1

Conversation

@ErenAri

@ErenAri ErenAri commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Finalize repository-side DOI metadata for the published BPFCompat Research
Dataset v1 without modifying the frozen research-v1 payload.

Zenodo identifiers

  • record: https://zenodo.org/records/22848155
  • exact Version DOI: 10.5281/zenodo.22848155
  • Concept DOI: 10.5281/zenodo.22848154
  • version: research-v1
  • resource type: Dataset
  • publication date: 2026-09-19

Changes

  • README.md
    • publishes the exact Version DOI and Concept DOI;
    • explicitly tells readers to use the Version DOI for exact
      research-v1 reproducibility;
    • distinguishes software citation metadata from dataset citation metadata.
  • docs/research-v1/CITATION.cff
    • adds a standalone CFF 1.2 dataset citation file outside the frozen archive
      payload;
    • binds the exact Version DOI, Concept DOI, GitHub research release URL,
      version, date, licenses, and Zenodo record URL.
  • docs/research-v1-zenodo.md
    • converts the pre-publication checklist into the published archival record;
    • records Zenodo metadata, DOI roles, canonical release hashes, and integrity
      evidence;
    • records the no-mutation policy and the fact that research/** remains
      frozen.

The root CITATION.cff is deliberately unchanged because it is part of the
frozen v1 archive selection and remains the BPFCompat software citation
metadata.

Integrity evidence

Before upload, all four GitHub release assets were re-hashed locally with
SHA-256 and matched the frozen values.

After publication, the Zenodo record displayed the expected exact sizes and MD5
values for all four files; those MD5 values were independently reproduced from
the canonical GitHub archival artifact.

A strict post-publication Zenodo re-download followed by SHA-256 recomputation
was not completed in the assistant environment because direct Zenodo file
downloads were unavailable there. This limitation is recorded explicitly in
the documentation rather than being hidden.

Frozen-v1 boundary

This PR does not modify:

  • CITATION.cff at repository root
  • research/**
  • the research-v1 tag
  • the GitHub research release
  • any published release asset
  • the archive lock

Corrections to frozen evidence require a new research version instead of
rewriting v1.

Summary by CodeRabbit

  • Documentation
    • Expanded research and citation guidance, including links to citation metadata, protocols, and dataset DOI references.
    • Updated the research archive documentation to reflect its published Zenodo record, licensing, integrity evidence, and citation practices.
    • Added citation metadata for the Research Dataset v1, including authorship, version, release date, licensing, and DOI information.

Copilot AI lite review requested due to automatic review settings September 19, 2026 18:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a2655851-7979-4393-88e9-46d83e371420

📥 Commits

Reviewing files that changed from the base of the PR and between 51bc697 and 44e66e8.

📒 Files selected for processing (3)
  • README.md
  • docs/research-v1-zenodo.md
  • docs/research-v1/CITATION.cff

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The PR records the published research-v1 Zenodo archive, documents its integrity evidence and citation rules, updates README citation guidance, and adds dataset-specific CITATION.cff metadata.

Changes

Research citation and archival records

Layer / File(s) Summary
Finalize research-v1 archival record
docs/research-v1-zenodo.md
The document now records the published Zenodo identifiers, frozen asset checks, archival metadata, dataset citation, and no-mutation policy.
Add software and dataset citation metadata
README.md, docs/research-v1/CITATION.cff
README citation guidance now distinguishes version and concept DOIs. The new CFF file defines metadata for the archived research-v1 dataset.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

🚥 Pre-merge checks | ✅ 7 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Security Regression ⚠️ Warning The PR weakens the frozen dataset integrity gate. The base document required a Zenodo re-download, SHA-256 recomputation, and a blocked archival gate on any mismatch. The changed document removes that… Restore the post-publication integrity gate. In a trusted environment, download every Zenodo asset, recompute SHA-256, and compare each digest and size with the canonical release values and archive lock. Do not mark the DOI record as an exa…
✅ Passed checks (7 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Code Quality Regression ✅ Passed PASS. The pull request changes only README.md and research citation documentation. It does not change source code, frozen research data, or archive handling. The new CFF passes the official CFF 1.2.0 …
Missing Regression Tests ✅ Passed PASS: The review-scoped diff changes only README.md, docs/research-v1-zenodo.md, and adds docs/research-v1/CITATION.cff. These are documentation and citation metadata changes. The diff does not …
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: finalizing Zenodo DOI metadata for the research pilot v1 dataset.
Full details: Security Regression

Explanation

The PR weakens the frozen dataset integrity gate. The base document required a Zenodo re-download, SHA-256 recomputation, and a blocked archival gate on any mismatch. The changed document removes that requirement and accepts DOI finalization from pre-upload SHA-256 plus exact sizes and MD5 values. The repository's archive workflow and release evidence use SHA-256 and an archive lock, so the post-publication check is the remaining control that verifies the bytes served by Zenodo. If a Zenodo asset is altered, same-size and MD5 evidence does not provide the same integrity protection because MD5 collision resistance is broken. The changed documentation then directs users to treat the DOI as the exact frozen evidence.

Resolution

Restore the post-publication integrity gate. In a trusted environment, download every Zenodo asset, recompute SHA-256, and compare each digest and size with the canonical release values and archive lock. Do not mark the DOI record as an exact archival copy, or instruct users to rely on it for exact reproducibility, until all comparisons pass. Keep MD5 values only as supplementary evidence, not as a substitute for SHA-256. If Zenodo downloads are unavailable, leave the gate pending and record the DOI as unverified rather than finalizing it.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ErenAri
ErenAri merged commit 0120123 into main Sep 19, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants