[codex] docs: add OpenCoven IP protection records#3
Merged
Conversation
BunsDev
force-pushed
the
codex/ip-protection-record-20260704
branch
from
July 4, 2026 14:21
51230f9 to
583cca3
Compare
BunsDev
marked this pull request as ready for review
July 4, 2026 14:52
There was a problem hiding this comment.
Pull request overview
Adds repository-root governance/IP documents intended to define OpenCoven’s security reporting, contribution terms (DCO + patent non-assertion), and provenance/patent prior-art record for the project.
Changes:
- Add a SECURITY.md policy describing reporting channels, scope, and architectural security properties.
- Add IP/provenance documentation via PATENTS and PROVENANCE.md.
- Add CONTRIBUTING.md outlining DCO sign-off and patent non-assertion terms for contributors.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 7 comments.
| File | Description |
|---|---|
| SECURITY.md | Introduces a security policy and reporting guidance. |
| PROVENANCE.md | Adds an origin/provenance record for OpenCoven concepts and publication timeline. |
| PATENTS | Adds a patent non-assertion pledge plus prior-art/publication timeline. |
| CONTRIBUTING.md | Documents contribution process, DCO sign-off, and patent non-assertion terms. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+11
to
+13
| Contact the maintainers directly: | ||
| - Discord: https://discord.gg/OpenCoven (DM @BunsDev) | ||
| - Or open a GitHub Security Advisory on the repository |
Comment on lines
+19
to
+24
| Security reports are welcome for: | ||
| - OpenCoven core harness and routing logic | ||
| - OpenTrust memory and session substrate | ||
| - Authentication and identity handling | ||
| - Agent sandbox and execution boundaries | ||
| - Any mechanism that could allow one agent or user to access another's context |
Comment on lines
+16
to
+18
| - Repository creation date: **2026-04-27** (verifiable via GitHub API: `https://api.github.com/repos/OpenCoven/coven`) | ||
|
|
||
| This repository has no fork parent. It is an original work with no upstream source repository. |
| ## Architectural Concepts and Their Origins | ||
|
|
||
| ### 1. The Familiar Identity Model | ||
| **First appeared:** `coven-cli/src/familiar_identity.rs`, commit history from 2026-04-27 |
| This concept was original to this repository. It has been independently acknowledged as prior art by third parties in their own published documentation. | ||
|
|
||
| ### 2. The Agent Spawn Harness | ||
| **First appeared:** `pty_runner.rs:307` (`spawn_piped_with_observer`), commit history from 2026-04-27 |
|
|
||
| OpenCoven is MIT licensed. The maintainers of this project have not filed and do not intend to file patents on the architectural patterns, protocols, or mechanisms described in this repository. | ||
|
|
||
| **Architectural concepts originating in this repository include, but are not limited to:** |
| - The agent spawn harness: a structured dispatch pattern that validates and routes process execution through a defined set of primitives | ||
| - The multi-agent orchestration substrate: composable, purpose-scoped agents ("familiars") coordinating through structured routing with shared session context | ||
| - The session memory and continuity substrate (OpenTrust): durable, portable agent memory and session state with provenance tracking | ||
| - The graded approval tier model: auto → familiar-review → human-review → human-required escalation for agent actions affecting protected resources |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the OpenCoven root IP protection and disclosure documents:
PATENTS: patent non-assertion pledge and prior-art noticePROVENANCE.md: origin and publication recordCONTRIBUTING.md: DCO and patent contribution terms, merged with any existing repo guidanceSECURITY.md: responsible disclosure policy, merged with any existing repo guidanceValidation
PATENTS,PROVENANCE.md,CONTRIBUTING.md,SECURITY.mdgit diff --checkpassed locally