Skip to content

docs(cyborg): complete CAGE-2 source ledger - #57

Merged
Brad-Edwards merged 3 commits into
devfrom
13-complete-source-ledger
Jul 30, 2026
Merged

Brad-Edwards merged 3 commits into
devfrom
13-complete-source-ledger

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Collaborator

Summary

Completes the pinned CAGE-2 evidence bridge for issue #13 so every consumed backend fact is tied to immutable upstream bytes, a verifiable selector, a published RAES contract target or explicit scope boundary, and claim-limiting loss disclosure.

Requirement UIDs

  • (none — bug/refactor/maintenance run; see Traceability section below)

Related Issues

Closes #13

ADR Impact

  • ADR-021
  • ADR-069
  • ADR-003

Changes

  • replace placeholder CAGE-2 mapping artifacts with an atomic pinned source ledger and tiered loss disclosures
  • add module-local fail-closed validation for ledger shape, coverage, source qualification, selectors, RAES contract targets, and loss bindings
  • extend the pinned source qualification and verification driver so detached upstream bytes and selectors are checked without executing simulator code
  • document the evidence-boundary guardrails and expose the design note in the documentation index
  • ignore the local .codex workspace directory without modifying its contents

Test Plan

  • Unit tests pass
  • Integration tests pass if applicable
  • Configured completion command passes
  • No coverage regression

Canonical make verify and make policy pass after focused source-ledger, qualification, detached-selector, Ruff, mypy, and strict MkDocs checks. Pre-push production and test-quality findings were fixed; no over-cap review cycle was run per user direction.

Ground Control Checks

  • Configured repository policy command passes
  • gc_evaluate_quality_gates passes or is unchanged by this repo-only change
  • gc_run_sweep reviewed; findings fixed or recorded with rationale

Traceability

Checklist

  • Code follows project coding standards (docs/CODING_STANDARDS.md)
  • No business logic in API layer
  • Domain layer has no framework imports
  • Envers @Audited on new entities if applicable
  • Changelog: owned by Release Please (generated from the Conventional Commit PR title; no per-PR fragment)
  • Architectural docs updated if stack, package structure, or key behaviors changed

Documentation

Updated: see diff.

@Brad-Edwards
Brad-Edwards merged commit b3a9a5a into dev Jul 30, 2026
13 checks passed
@Brad-Edwards
Brad-Edwards deleted the 13-complete-source-ledger branch July 30, 2026 03:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant