Skip to content

chore(ci): 3/3 stack — attest-build-provenance v4.2.2 - #219

Closed
cryptoxdog wants to merge 1 commit into
chore/stack-observability-depsfrom
chore/stack-attest-v4
Closed

chore(ci): 3/3 stack — attest-build-provenance v4.2.2#219
cryptoxdog wants to merge 1 commit into
chore/stack-observability-depsfrom
chore/stack-attest-v4

Conversation

@cryptoxdog

Copy link
Copy Markdown
Collaborator

Summary

Top of the stack. actions/attest-build-provenance v2.0.0 → v4.2.2 from #214 (docker-build.yml only).

Merge last. Leaf — squash is safe after 1/3 and 2/3 are on main.

Stack

  1. chore(ci): 1/3 stack — pin refresh + license allow-list #217 pin refresh + license allow-list
  2. Observability deps
  3. This PR

Test plan

  • Workflow lint / docker-build job still configures
  • Attest step is if: github.event_name != 'pull_request' — verify on the first post-merge image build

Made with Cursor

Independent docker-build.yml change from #214, stacked on the
observability layer so the three PRs merge oldest-first without
file fights.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

Copy link
Copy Markdown

PR reviewable size is within recommended limits

@github-actions

Copy link
Copy Markdown

L9 Audit Harness Report

  • Generated: 2026-08-21T13:27:28.695636+00:00
  • Repo root: /home/runner/work/Cognitive.Engine.Graphs/Cognitive.Engine.Graphs
  • Overall result: ✅ PASSED
  • Exit code: 0

Step Results

Step Status Exit Code Notes
Architecture Audit ✅ Passed 0
Spec Coverage ✅ Passed 0
Contract Wiring ✅ Passed 0

Architecture Audit Findings

Severity Count
🔴 CRITICAL 0
🟠 HIGH 0
🟡 MEDIUM 25
🔵 LOW 0

See artifacts/audit_report.md for full details.

Spec Coverage

  • ✅ Implemented: 37
  • ⚠️ Partial: 9
  • ❌ Missing: 0
  • Total features: 46
Category Implemented Partial Missing Total
gates 10 0 0 10
scoring 7 0 0 7
v1.1_node 2 0 0 2
v1.1_edge 2 0 0 2
v1.1_action 0 2 0 2
v1.1_scoring 1 1 0 2
action_handler 0 6 0 6
gds_algorithm 5 0 0 5
research_pattern 10 0 0 10

See artifacts/coverage_report.md for full details.

Next Steps

All checks passed. Safe to merge.

@sonarqubecloud

Copy link
Copy Markdown

@cryptoxdog

Copy link
Copy Markdown
Collaborator Author

Superseded by #220 — compatible sdk-revision (b1a49141), SPDX AND licenses appended despite repo ALLOWED_LICENSES, Poetry+requirements.txt observability, attest v4.2.2. Closing this stack PR.

@cryptoxdog

Copy link
Copy Markdown
Collaborator Author

Closed in favor of #220.

@cryptoxdog cryptoxdog closed this Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant