Skip to content

[Bug]: synchronize superseded release status documentation #114

Description

@pillowtalk-Qy

Observed behavior

Current main@4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d contains mutually contradictory release statements:

  • README.md says implementation stops at M5-06 although Gate C, visual QA, deployment, and the merged frontend are complete.
  • SECURITY.md calls the application a non-integrated Web/API baseline.
  • docs/real-vs-mock.md says there is no integrated runnable demo and lists already implemented Moss, orchestration, report, and UI behavior as absent.
  • docs/judge-map.md lists completed workbench and visual acceptance as remaining proof.
  • docs/known-issues.md reports production advisories as currently open although P0: remediate production dependency advisories blocking Gate C #102/PR P0: remediate production dependency advisories #104 remediated them and Gate C's production audit passed.
  • docs/security-audit-report.md retains its exact-subject historical NO-GO without an upfront resolution/supersession notice, so readers can mistake it for current release status.

Expected behavior

Current-status documentation must match merged main and distinguish historical exact-SHA audit results from the later remediation and Gate C PASS. It must preserve all Live/Fixture, MANUAL_REVIEW, STOP, Moss integration-fork, Clear402, wallet/signing, and no-hosted-Live limitations.

Reproduction

  1. Check out 4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d.
  2. Compare the six files above with docs/gate-c-report.md, docs/visual-qa-report.md, closed P0: remediate production dependency advisories blocking Gate C #102, and main quality-gate run 31300536251.
  3. Observe that old statements describe completed or remediated work as current gaps.

Evidence

Scope

Writable only:

  • README.md
  • SECURITY.md
  • docs/real-vs-mock.md
  • docs/judge-map.md
  • docs/known-issues.md
  • docs/security-audit-report.md

Non-goals

  • No product, test, schema, dependency, lockfile, Gate verdict, STOP policy, trust-boundary, deployment, tag, media, or submission change.
  • Do not erase exact-subject historical audit evidence; add explicit resolution context.
  • Do not claim hosted Live, official Moss support, signing, authentication, safety, or RC tag completion.

Acceptance

  • Current-status statements match merged main and current public health.
  • Historical audit subject/verdict remain attributable and the resolved blocker links P0: remediate production dependency advisories blocking Gate C #102 and Gate C.
  • No active Known Issue claims remediated advisories remain open.
  • Integrated Fixture workflow and bounded standalone Live observation are described without conflation.
  • All local Markdown links resolve.
  • Claim-risk scan is manually classified.
  • pnpm check, production audit, public smoke, and git diff --check pass.
  • Exact-head CI passes before merge.

Security impact

Documentation-only correction. It reduces misleading release and evidence claims without changing runtime behavior or assurance.

Activity

  1. pillowtalk-Qy commented on Aug 9, 2026

    @pillowtalk-Qy
    ContributorAuthor

    SINGLE_OPERATOR_SCOPE_REVIEW / IMPLEMENTATION AUTHORIZED

    Baseline: main@4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d.

    Writable scope is exactly the six documentation files listed in the Issue. The correction will reconcile current status with Gate C, #102, visual QA, current main CI, and public health while preserving all accepted evidence and trust boundaries.

    No runtime, test, dependency, lockfile, Gate verdict, tag, media, or submission change is authorized. Historical audit results remain intact with an explicit later-resolution notice.

    Verification: six-file path audit, local-link audit, claim-risk classification, Node 22 pnpm check, production audit, public 9-test smoke, exact-head CI, and detached clean SINGLE_OPERATOR_QA.

  2. added a commit that references this issue on Aug 9, 2026
    34f64df
  3. pillowtalk-Qy commented on Aug 9, 2026

    @pillowtalk-Qy
    ContributorAuthor

    POST_MERGE_AUDIT: squash merge 34f64df is on protected main; Issue is Closed; Project status is Done; merged-main quality-gate run 31304149377 succeeded; remote feature branch was deleted; no trust-boundary or runtime behavior changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:docsDocumentation and evidence-boundary workarea:securitySecurity controls and boundariespriority:P1High prioritystatus:readyReady to starttype:bugDefect or regression

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions