Dev - #1402
Merged
Merged
Dev#1402
Conversation
* chore(main): release 3.3.0 * chore(main): release 3.4.0 * chore(main): release 3.5.0 * chore(main): release 4.0.0 * chore(main): release 4.1.0 * chore(main): release 5.0.0 --------- Co-authored-by: Brad Edwards <j.bradley.edwards@gmail.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat(sdl): add post-materialization attestations * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings (cycle 2)
…1296) * fix(evidence): centralize capture admission and proof authority * refactor(evidence): simplify capture and governance validation
* build(release): generate output-bound SBOM and build provenance * fix(release): admit operator paths and tighten evidence admission * fix(release): remove credential-shaped fixtures and narrow evidence types
* docs(sdl): audit product-shaped runtime semantics * docs(sdl): cite the preflight authority without retired branding * test(sdl): isolate the audit coverage exception assertion
…#1301) * ci: shard verification graph and decouple SonarCloud quality gate (#935) * ci: run integration lane with generic tools and keep shard artifacts out of the checkout (#935) * ci: resolve SonarCloud findings on the shard tooling (#935) * ci: reduce ci_latency_report parse_run complexity (#935)
* feat(experiment): validate scoped evidence refinements * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings after dev sync * Fix SonarCloud export findings
* feat(sdl): enforce open-by-default scenario augmentation scope * refactor(sdl): simplify augmentation admission boundaries * refactor(sdl): tighten augmentation composition types
* feat(sdl): add explicit participant relationships * refactor(sdl): simplify participant relationship checks * fix(contracts): refresh merged schema publication hashes
* feat: add authoring adapter conformance vectors * refactor: simplify authoring conformance validation * style: format versioned evidence test * fix: retain unique coverage release revisions * fix: refresh merged source evidence
* fix(sdl): admit partial listener descriptions * refactor(sdl): reduce listener validation complexity * refactor(sdl): simplify listener shape predicates
) * wip: oci mirror and pre-seed (pre-merge checkpoint) * wip: script entry point fix and capture republication * wip: review fixes * build(oci): mirror and pre-seed digest-pinned release-test images * fix(proof): rebind the opacity proof manifest to the updated policy gate source * test(evidence): pin the formal current release to 27.0.0 * build(oci): re-cut evidence captures above dev release 26/27 * refactor(oci): clear the SonarCloud new-violation findings * refactor(oci): split the lock projection out of the client boundary * build(oci): re-cut evidence captures above dev release 27/28
* feat: define mixed participant composition semantics * fix: resolve test assertions and keep git hooks lightweight * fix: align container smoke checks with lightweight hooks
* Separate native service-manager contracts * Fix SonarCloud findings (cycle 1) * Refresh service contract evidence pins * Rebind specification coverage analysis
* Implement startup reconciliation and recovery resolution * fix(validation): expect current formal evidence release * Fix SonarCloud findings (cycle 1) * fix(evidence): refresh specification source state
* docs: reconcile implementation status prose * fix: update asyncssh security patch * fix: refresh evidence source state
…ions/python in the python-minor-patch group (#1256) * chore(deps-dev): bump hatchling Bumps the python-minor-patch group in /implementations/python with 1 update: [hatchling](https://github.com/pypa/hatch). Updates `hatchling` from 1.27.0 to 1.32.0 - [Release notes](https://github.com/pypa/hatch/releases) - [Commits](pypa/hatch@hatchling-v1.27.0...hatchling-v1.32.0) --- updated-dependencies: - dependency-name: hatchling dependency-version: 1.32.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com> * build(tooling): regenerate the reviewed build closure for hatchling 1.32.0 Dependabot moved the project's isolated-build backend to hatchling 1.32.0, but the pin in `implementations/python/pyproject.toml` is a consumer of the reviewed build group, not its authority. The tooling project still pinned 1.27.0 and the expected-pin table, tool lock, hash-complete build constraints, and per-target smoke projections all still described that closure, so the development artifact policy rejected the build-system requirement as not matching the reviewed build group. The build group, the expected-pin table, and the lock move to 1.32.0 and the generated projections are regenerated from it. hatchling 1.32.0 takes tomlkit as a new runtime dependency, so tomlkit 0.15.1 enters the hash-complete build constraints and each target's tool closure. hatchling 1.28.0 dropped Python 3.9, which the reviewed interpreter range (>=3.11,<3.15) already excludes. The pending qualification records are re-bound to the resulting tooling policy digest. * docs(research): refresh evidence source state for the new build closure The current specification-coverage and formal-semantic-validation captures bind the live reference implementation through an implementation digest over `implementations/python/packages`, `pyproject.toml`, and `uv.lock`. Moving the build-system pin to hatchling 1.32.0 changed that surface, so both captures described code that no longer exists and the current-replay checks rejected them. Both captures are re-cut against the new source identity and the dependent analysis and bundle digests are recomputed from them. No classification, concept result, or claim changes; this is a source-state refresh, not a new finding. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Brad Edwards <j.bradley.edwards@gmail.com>
…38.0 in the github-actions group (#1257) * chore(deps): bump github/codeql-action/upload-sarif Bumps the github-actions group with 1 update: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action). Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdf488f...b96794f) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> * build(tooling): re-pin the reviewed CodeQL upload-sarif closure Dependabot moved the Scorecard SARIF upload to github/codeql-action/upload-sarif 4.38.0, but the workflow pin is only one of five places the reviewed action closure is recorded. The action policy still named the 4.37.9 commit as the reviewed source, closure review reference, service-exception evidence reference, and use-site pin, so the development artifact policy rejected the workflow as unowned, off-profile, and stale. The action.yml published at the new commit is byte-identical to the reviewed one, so the declared runtime, inputs, transitive service input, and security effects still describe the action exactly; this is a pure re-pin of the same reviewed closure. The four policy references move to the new commit and the pending qualification records are re-bound to the resulting tooling policy digest. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Brad Edwards <j.bradley.edwards@gmail.com>
* Preserve extensible HTTP method identity * Update historical identity record digests * Format HTTP method regression tests * Preserve omitted route method compatibility * Clarify parser diagnostic regression test
* Enforce runtime store ownership leases * Refresh runtime evidence source pins * Fix SonarCloud findings (cycle 1)
…#1317) * refactor(tooling): simplify connected developer and release workflows * fix(ci): select current paths and the approved proof mirror * refactor(tooling): clarify policy and installation validation * refactor(release): separate workflow input collection * docs(research): refresh evidence bindings after integration
* Publish mixed composition contracts * Split mixed composition resolution module * Refresh research evidence source identity * Resolve Sonar quality findings * Refresh research evidence after quality fixes * Refresh current evidence after dev merge
* test(sdl): verify progressive conformance end to end * test(sdl): isolate negative mutation calls
Verify and document supported container entry points, and rebuild a relocated development environment during setup
…1319) * fix(release): publish only admitted bytes and reconcile destinations * fix(release): fail closed on an uncertain Release asset listing * style(release): apply ruff format to the changed release tests * style(release): apply ruff format to the changed tooling module * refactor(release): split the publisher handoff into its own module
* fix(runtime): make idempotency claims atomic and scoped * refactor(runtime): split local operation record store * chore(research): refresh source-bound evidence * test(runtime): align replay and operation access expectations * refactor(runtime): resolve atomic claim quality findings * chore(research): refresh atomic claim source evidence * fix(deps): update anyio for reviewed advisories * chore(deps): refresh anyio closure projections
* Admit mixed and staged trial realizations * Fix SonarCloud findings (cycle 1) * Fix CI dependency and policy findings * Regenerate Python closure projections
* fix(runtime): align the served control-plane profile * fix(runtime): reconcile served-profile evidence bundle digests * test(runtime): resolve sonar S5778 in multi-worker admission test
…ffects (#1346) * feat(runtime): orchestrate modular participant control and governed effects * docs(runtime): split an over-long sentence in the participant-control guide * fix(evidence): bind the formal capture analysis to its own snapshot and release pins * chore(governance): assign the formal validation tests to the issue 1069 scope * refactor(runtime): resolve SonarCloud maintainability findings in participant control * refactor(runtime): type the effect binding tables and the closed carrier record
* feat!: separate participant identity and objective assignment * docs: declare participant decision classification waivers * fix: refresh participant migration fixture provenance * refactor: simplify participant migration and semantic validation * test: align evidence assertions with synchronized releases * refactor: separate evidence release revision constants
* feat: support participant-local outcome categories and state * fix: align generator formatting and public outcome documentation link * fix: replay research captures against participant outcome implementation * refactor: simplify participant outcome validation and production
* docs(runtime): define operation supervision and recovery * chore(policy): refresh identity record digests * test(runtime): isolate supervision exception assertions
* feat: enforce bounded participant temporal guarantees * fix: align temporal conformance with runtime boundaries * fix: reconcile temporal validation evidence * refactor: resolve participant temporal quality findings * fix: preserve scheduler binding compatibility * refactor: complete temporal quality remediation * fix: preserve temporal schema contracts * fix: clear remaining temporal quality findings
* docs: define reusable mixed-control policies and occurrences * docs: refresh identity records for the mixed-control ADR
* docs: define control applicability and effect decisions * docs: synchronize historical ADR content records
…ion (#1379) * docs: define external inject triggering and execution * docs: reconcile inject decision governance records * test: separate inject authoring assertions * ci: install merged delivery finalization workflow * style: retain policy module formatting
* docs(runtime): select reusable execution architecture * docs(runtime): align execution decision policy records * test(runtime): isolate execution evidence scanner tooling
* docs: define IFC profile variability and publication rules * test: isolate IFC exception assertions
* docs: define participant access trust boundary * fix: update ADR index identity digest
* docs: define participant access trust boundary * fix: update ADR index identity digest * docs: clarify participant access across sdk and http
* Fix governed context forwarding in v2 admission * Refresh specification coverage evidence for current source * Format specification coverage release check * Refresh formal semantic evidence for current source * Align evidence release tests with current revisions * Clarify unauthorized admission exception test
* fix: Record denied egress as failed operation * fix: Refresh source-bound evidence for denied egress * test: update current coverage revision expectation * test: update current formal evidence revision expectation * refactor: centralize governed projection replay * docs: refresh source-bound evidence after replay refactor
* feat: publish backend operation and supervision contracts * fix: preserve backend opt-in and refresh execution evidence * fix: keep reference backend supervision opt-in * refactor: simplify backend operation contract validation * style: align operation test imports with project lint context * Format formal evidence release list * Split formal evidence corpus revision selection
Bumps the github-actions group with 4 updates: [actions/checkout](https://github.com/actions/checkout), [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv), [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action). Updates `actions/checkout` from 4.3.1 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4.3.1...3d3c42e) Updates `astral-sh/setup-uv` from 10.1.0 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@bec219d...c18668a) Updates `SonarSource/sonarqube-scan-action` from 8.2.1 to 8.2.2 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@2291811...ba9859e) Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Implement mixed backend mapping and time contracts * Refresh specification coverage evidence for mixed runtime * Refresh formal semantic evidence for mixed runtime * Format formal validation release policy * Update evidence release regression expectations * Refactor mixed runtime stages for Sonar gate * Bind mixed handoff scope and source evidence * Fix remaining SonarCloud findings
* fix: admit participant delivery temporal subjects * fix: keep time subject validation modular * fix: normalize participant delivery test imports * test: refresh source-bound participant evidence * style: apply repository tooling format * fix: use autarchy Sonar credential * fix: restore refreshed Sonar credential * refactor: centralize formal evidence revisions * refactor: separate current historical revision * Fix Python test import ordering
…ices (#1398) * feat: require backends to honour authored trial timeout and retry choices * refactor: split admission and manifest modules under the size cap * test: refresh libvirt conformance report for new manifest fixtures * refactor: import cleanup admission from its owning module * test: keep one raising call in the canonical-guarantees check
* feat: publish applicable participant-control contracts * fix: format schema generator * fix: resolve public migration guide link * fix: refresh source-bound evidence for API-424 * fix: align evidence tests with current captures * Update stub manifest fixture for v2 controls * Refactor v2 control validation for quality gate * Trace composition module to API-424 * Fix SonarCloud findings (cycle 2) * Fix SonarCloud findings (cycle 3)
* feat(formal): add independent participant crossing models * fix(formal): refresh crossing source inventory after synchronization * fix(docs): refresh historical ADR index digest * fix(evidence): replay retained research controls for crossing models * test(evidence): align current capture revision assertions * fix(formal): address profile typing and assertion clarity * fix(deps): update PyJWT and refresh source-bound evidence * fix(build): refresh dependency projections for PyJWT update
* feat: enforce the administrative-only runtime API trust boundary * fix: keep contract models unchanged and republish research evidence captures * ci: supply the SonarCloud token from AUTARCHY_SONAR_TOKEN * ci: keep supplying the SonarCloud token from SONAR_TOKEN * ci: supply the SonarCloud token from PERSONAL_SONAR_TOKEN * ci: supply the SonarCloud token from SONAR_TOKEN * fix: seal the control-plane app and harden transport admission refusals * docs: record the sealed composition and refusal guarantees in API-404 traceability * Fix SonarCloud findings (cycle 1) * test: republish research evidence captures above the #1399 releases * fix(deps): upgrade pyjwt to 2.15.1 for ten published advisories
…y source (#1404) * feat: enforce the administrative-only runtime API trust boundary * fix: keep contract models unchanged and republish research evidence captures * ci: supply the SonarCloud token from AUTARCHY_SONAR_TOKEN * ci: keep supplying the SonarCloud token from SONAR_TOKEN * ci: supply the SonarCloud token from PERSONAL_SONAR_TOKEN * ci: supply the SonarCloud token from SONAR_TOKEN * fix: seal the control-plane app and harden transport admission refusals * docs: record the sealed composition and refusal guarantees in API-404 traceability * Fix SonarCloud findings (cycle 1) * test: republish research evidence captures above the #1399 releases * fix(deps): upgrade pyjwt to 2.15.1 for ten published advisories * test: republish research evidence captures above the #1397 releases * Fix SonarCloud findings (cycle 1): cover explicit current formal release selection
8 tasks done
… advisories (#1405) * fix(deps): upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for published advisories The pyjwt 2.15.1 upgrade from #1404's branch was dropped by a later merge-conflict resolution that took dev's uv.lock, so dev shipped pyjwt 2.14.0 (GHSA-42vr-xj54-vc7v). urllib3 2.7.0 has three new advisories fixed in 2.8.0 (GHSA-8988-9cw3-xx77, GHSA-gh4c-6fx4-qh6g, GHSA-vxq7-64xx-v4gw). Both made the osv-scan supply-chain gate fail. Regenerate the hash-complete smoke closures and republish both research-evidence captures, which bind to the locked dependency set: specification coverage 65.0.0 and formal semantic validation 66.0.0. * style: format the specification-coverage release set * fix(formal): rebind the crossing model bundle to the upgraded lock
* fix: reject unprovable required evidence media types * test: republish research evidence captures above the #1405 releases * Fix SonarCloud findings: isolate the raising call in exception tests
7 tasks done
#1406) Fix SonarCloud finding: partition shard items with comprehensions
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Requirement UIDs
Related Issues
ADR Impact
Changes
Test Plan
Ground Control Checks
Traceability
Checklist
CHANGELOG.mdfrom it)Documentation