diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 0119f29..791cc67 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -11,7 +11,7 @@ workflows: - 'goto-bus-stop/setup-zig@v2.2.1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.37.8' + - 'github/codeql-action@v4.37.9' '.github/workflows/container-build.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dependabot-automerge.yml': @@ -41,12 +41,12 @@ workflows: '.github/workflows/quality.yml': - 'actions/checkout@v7.0.1' - 'editorconfig-checker/action-editorconfig-checker@v2.2.0' - - 'trufflesecurity/trufflehog@v3.97.0' + - 'trufflesecurity/trufflehog@v3.97.1' '.github/workflows/release.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - 'actions/upload-artifact@v7.0.1' - - 'softprops/action-gh-release@v3.0.2' + - 'softprops/action-gh-release@v3.0.3' '.github/workflows/rhodibot.yml': - 'actions/checkout@v7.0.1' '.github/workflows/runtime-policy.yml': @@ -67,6 +67,7 @@ workflows: '.github/workflows/test-suite.yml': - 'actions/checkout@v7.0.1' - 'goto-bus-stop/setup-zig@v2.2.1' + - 'leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596' '.github/workflows/wellknown-enforcement.yml': - 'actions/checkout@v7.0.1' '.github/workflows/workflow-linter.yml': @@ -87,6 +88,11 @@ dependencies: commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d' owner_id: 44036562 repo_id: 760701061 + 'actions/cache@v5': + ref: 'v5' + commit: 'sha1-caa296126883cff596d87d8935842f9db880ef25' + owner_id: 44036562 + repo_id: 215566462 'actions/cache@v6.1.0': ref: 'v6.1.0' commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' @@ -144,9 +150,9 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 - 'github/codeql-action@v4.37.8': - ref: 'v4.37.8' - commit: 'sha1-db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28' + 'github/codeql-action@v4.37.9': + ref: 'v4.37.9' + commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' owner_id: 9919 repo_id: 259445878 'goto-bus-stop/setup-zig@v2.2.1': @@ -159,9 +165,16 @@ dependencies: commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d' owner_id: 75048950 repo_id: 623796603 - 'softprops/action-gh-release@v3.0.2': - ref: 'v3.0.2' - commit: 'sha1-3d0d9888cb7fd7b750713d6e236d1fcb99157228' + 'leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596': + ref: 'v1.6.0' + commit: 'sha1-50fcf42d2e460296f1a34b402e990d1b24f8b596' + owner_id: 7233018 + repo_id: 795738301 + uses: + - 'actions/cache@v5' + 'softprops/action-gh-release@v3.0.3': + ref: 'v3.0.3' + commit: 'sha1-efb35369e0ad2afab669f228072c1b0d510eae64' owner_id: 2242 repo_id: 204253808 'sonarsource/sonarqube-scan-action@v8.2.1': @@ -169,8 +182,8 @@ dependencies: commit: 'sha1-22918119ff8e1ca75a623e15c8296b6ea4fbe28f' owner_id: 545988 repo_id: 366408409 - 'trufflesecurity/trufflehog@v3.97.0': - ref: 'v3.97.0' - commit: 'sha1-bcfcf73aaf4759d4dadc2783177c245a02792318' + 'trufflesecurity/trufflehog@v3.97.1': + ref: 'v3.97.1' + commit: 'sha1-20652fbbdefffcdaa493a5bf57ab2ac6b1db715b' owner_id: 79229934 repo_id: 77726177 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 00ae550..6308213 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -26,7 +27,7 @@ jobs: if: ${{ vars.BOJ_SERVER_URL != '' }} steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) env: BOJ_URL: ${{ secrets.BOJ_SERVER_URL || vars.BOJ_SERVER_URL }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 349502b..e250f8f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -31,10 +32,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -47,7 +48,7 @@ jobs: run: zig build test - name: Upload Zig build artifacts - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: zig-build path: | @@ -65,7 +66,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install gforth run: sudo apt-get update && sudo apt-get install -y gforth @@ -85,7 +86,7 @@ jobs: # Job 3: C FFI integration tests (depends on Zig build) # =========================================================================== test-ffi: - name: C FFI Integration Tests + name: C ABI regression tests runs-on: ubuntu-latest needs: build-zig permissions: @@ -93,10 +94,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 4f43f23..fbe06fd 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -36,7 +37,7 @@ jobs: build-mode: none steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Initialize CodeQL uses: github/codeql-action/init@v4.37.9 with: diff --git a/.github/workflows/container-build.yml b/.github/workflows/container-build.yml index 6dace2a..a588c57 100644 --- a/.github/workflows/container-build.yml +++ b/.github/workflows/container-build.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -32,7 +33,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Tooling check run: | diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index eb0ca8e..db8c8e6 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -57,7 +58,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@v3.1.0 + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # --- Policy gate ------------------------------------------------------- diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index a86a4c6..cc4fae8 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -32,7 +33,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check for A2ML files id: detect @@ -83,7 +84,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check for K9 files id: detect @@ -135,7 +136,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Scan for invisible characters id: lint @@ -200,7 +201,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check for Groove manifest id: groove @@ -265,7 +266,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -317,7 +318,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index fc02106..fef52c5 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -46,7 +47,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Run E2E harness run: | if [ -f tests/e2e.sh ]; then diff --git a/.github/workflows/estate-rules.yml b/.github/workflows/estate-rules.yml index 817ec55..71a21b6 100644 --- a/.github/workflows/estate-rules.yml +++ b/.github/workflows/estate-rules.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -28,7 +29,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Root shape allowlist run: bash scripts/check-root-shape.sh . - name: AsciiDoc by default (no .md under docs/) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index df090e0..a75654d 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -20,4 +21,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb566cfb8a86cea2d3666bf65a4f177a49b1313 diff --git a/.github/workflows/guix-policy.yml b/.github/workflows/guix-policy.yml index ab63a0e..121c0e1 100644 --- a/.github/workflows/guix-policy.yml +++ b/.github/workflows/guix-policy.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -23,7 +24,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Enforce Guix-only package policy run: | # Guix is the sole package manager estate-wide. Nix is BANNED. diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 1c10a91..109b620 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -29,4 +30,6 @@ permissions: jobs: scan: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@fcb566cfb8a86cea2d3666bf65a4f177a49b1313 + with: + block-on-high: true diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..814a192 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..83ab941 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Labels diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 61d823e..d3482bc 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/openssf-compliance.yml b/.github/workflows/openssf-compliance.yml index 13571b8..613a74d 100644 --- a/.github/workflows/openssf-compliance.yml +++ b/.github/workflows/openssf-compliance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -23,7 +24,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Check SECURITY.md exists and has substance diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 9d1f7db..9368f9f 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -27,22 +28,22 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@v2.12.0 + uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@v6.1.0 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: | ~/.cabal/packages @@ -73,10 +74,10 @@ jobs: cd .casket-ssg && cabal run casket-ssg -- build ../site ../_site - name: Setup Pages - uses: actions/configure-pages@v6.0.0 + uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@v5.0.0 + uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 with: path: '_site' @@ -90,4 +91,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@v5.0.0 + uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index 2dd23bc..783dccf 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -24,7 +25,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check file permissions run: | find . -type f -perm /111 -name "*.sh" | head -10 || true @@ -43,7 +44,7 @@ jobs: run: | find . -type f -size +1M -not -path "./.git/*" | head -10 || echo "No large files" - name: EditorConfig check - uses: editorconfig-checker/action-editorconfig-checker@v2.2.0 + uses: editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c # v2.2.0 continue-on-error: true docs: runs-on: ubuntu-latest @@ -51,7 +52,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check documentation run: | MISSING="" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a46cb1a..3d7fa2a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -25,7 +26,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Detect project type and build id: build run: | @@ -87,7 +88,7 @@ jobs: changelog: ${{ steps.cliff.outputs.content }} version: ${{ steps.version.outputs.version }} steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Extract version from tag @@ -112,7 +113,7 @@ jobs: run: | git cliff --output CHANGELOG.md - name: Upload updated CHANGELOG.md - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: changelog path: CHANGELOG.md @@ -127,7 +128,7 @@ jobs: id-token: write # mint the OIDC token attestation provenance is signed with attestations: write # write the build-provenance attestation (the "claim") steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # TODO: Download build artifacts if uploading to the release (pin # actions/download-artifact to a full commit SHA when enabling): # - uses: actions/download-artifact@ # vX.Y.Z @@ -156,6 +157,6 @@ jobs: # (must match the `files:` uploaded above, e.g. artifacts/*). - name: Attest build provenance if: ${{ hashFiles('artifacts/*') != '' }} # skip until real artifacts are wired - uses: actions/attest-build-provenance@v4.2.2 + uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-path: 'artifacts/*' diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml index a5f649a..0881551 100644 --- a/.github/workflows/rhodibot.yml +++ b/.github/workflows/rhodibot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -36,7 +37,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 1 - name: Rhodibot — detect drift (no mutations) diff --git a/.github/workflows/runtime-policy.yml b/.github/workflows/runtime-policy.yml index 6881682..eb6a0ea 100644 --- a/.github/workflows/runtime-policy.yml +++ b/.github/workflows/runtime-policy.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -39,7 +40,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Report runtime tier and reject mixed toolchains run: | diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index f30555b..cde523c 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 42731a1..3a7fe93 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index e86fba4..b5f461c 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -28,5 +29,5 @@ jobs: contents: read pull-requests: write actions: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@fcb566cfb8a86cea2d3666bf65a4f177a49b1313 secrets: inherit diff --git a/.github/workflows/security-policy.yml b/.github/workflows/security-policy.yml index d8e11ba..6d8f641 100644 --- a/.github/workflows/security-policy.yml +++ b/.github/workflows/security-policy.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -23,7 +24,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Security checks run: | FAILED=false diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml index 1624979..ee289f7 100644 --- a/.github/workflows/sonarqube.yml +++ b/.github/workflows/sonarqube.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -5,7 +6,7 @@ # SonarQube Cloud (SonarCloud) static analysis. Analysis scope + exclusions live # in sonar-project.properties. Requires the SONAR_TOKEN repository secret # (Settings -> Secrets and variables -> Actions) and a SonarCloud project: -# https://sonarcloud.io/project/overview?id=hyperpolymath_rsr-template-repo +# https://sonarcloud.io/project/overview?id=hyperpolymath_lithoglyph # Mirrors the boj-server arrangement. name: SonarQube on: @@ -26,7 +27,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 # full history for accurate new-code detection - name: SonarQube Scan diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml index efcf9a0..fd78d66 100644 --- a/.github/workflows/static-analysis-gate.yml +++ b/.github/workflows/static-analysis-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -25,7 +26,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -122,7 +123,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload panic-attack findings - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: panic-attack-findings path: panic-attack-findings.json @@ -149,13 +150,13 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Setup Elixir for Hypatia scanner id: beam continue-on-error: true - uses: erlef/setup-beam@v1.24.1 + uses: erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124 # v1.24.1 with: elixir-version: '1.19.4' otp-version: '28.3' @@ -256,7 +257,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload hypatia findings - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: hypatia-findings path: hypatia-findings.json @@ -275,7 +276,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -337,7 +338,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload bridge report - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: bridge-report path: bridge-report.json @@ -359,17 +360,17 @@ jobs: if: always() steps: - name: Download panic-attack findings - uses: actions/download-artifact@v8.0.1 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: panic-attack-findings path: findings/ - name: Download hypatia findings - uses: actions/download-artifact@v8.0.1 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: hypatia-findings path: findings/ - name: Download bridge report - uses: actions/download-artifact@v8.0.1 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: bridge-report path: findings/ @@ -429,7 +430,7 @@ jobs: echo "medium=$MEDIUM" >> "$GITHUB_OUTPUT" echo "low=$LOW" >> "$GITHUB_OUTPUT" - name: Upload unified findings (fleet scanner picks these up) - uses: actions/upload-artifact@v7.0.1 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: unified-findings path: findings/unified-findings.json diff --git a/.github/workflows/test-suite.yml b/.github/workflows/test-suite.yml index f54e3c4..fd04488 100644 --- a/.github/workflows/test-suite.yml +++ b/.github/workflows/test-suite.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -26,7 +27,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install gforth run: sudo apt-get update && sudo apt-get install -y gforth @@ -54,10 +55,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -84,10 +85,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -136,12 +137,18 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install elan (Lean version manager) - run: | - curl https://elan.lean-lang.org/elan-init.sh -sSf | sh -s -- -y --default-toolchain none - echo "$HOME/.elan/bin" >> $GITHUB_PATH + uses: leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596 # v1.6.0 + with: + auto-config: false + build: false + test: false + lint: false + use-mathlib-cache: false + use-github-cache: false + lake-package-directory: normalizer/lean - name: Build and test Lean project working-directory: normalizer/lean diff --git a/.github/workflows/wellknown-enforcement.yml b/.github/workflows/wellknown-enforcement.yml index 128c448..48fad5b 100644 --- a/.github/workflows/wellknown-enforcement.yml +++ b/.github/workflows/wellknown-enforcement.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -28,7 +29,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: RFC 9116 security.txt validation run: | SECTXT="" diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index b04cad8..a956a9a 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -30,7 +31,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Check SPDX Headers run: | diff --git a/.github/workflows/zig-tests.yml b/.github/workflows/zig-tests.yml index 8d423d8..0bfc78a 100644 --- a/.github/workflows/zig-tests.yml +++ b/.github/workflows/zig-tests.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -52,10 +53,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: ${{ matrix.zig-version }} @@ -145,10 +146,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -183,10 +184,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -228,10 +229,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Zig - uses: goto-bus-stop/setup-zig@v2.2.1 + uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 with: version: '0.15.2' @@ -291,7 +292,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v7.0.1 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Find TODOs run: | diff --git a/.machine_readable/6a2/AGENTIC.a2ml b/.machine_readable/6a2/AGENTIC.a2ml deleted file mode 100644 index 1699fe4..0000000 --- a/.machine_readable/6a2/AGENTIC.a2ml +++ /dev/null @@ -1,34 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# AGENTIC.a2ml — AI agent constraints and capabilities -[metadata] -version = "0.1.0" -last-updated = "2026-04-11" - -[agent-permissions] -can-edit-source = true -can-edit-tests = true -can-edit-docs = true -can-edit-config = true -can-create-files = true - -[agent-constraints] -# What AI agents must NOT do: -# - Never use banned language patterns (believe_me, unsafeCoerce, etc.) -# - Never commit secrets or credentials -# - Never use banned languages (TypeScript, Python, Go, etc.) -# - Never place state files in repository root (must be in .machine_readable/) -# - Never use AGPL license (use PMPL-1.0-or-later) - -[maintenance-integrity] -fail-closed = true -require-evidence-per-step = true -allow-silent-skip = false -require-rerun-after-fix = true -release-claim-requires-hard-pass = true - -[automation-hooks] -# on-enter: Read 0-AI-MANIFEST.a2ml, then STATE.a2ml -# on-exit: Update STATE.a2ml with session outcomes -# on-commit: Run just validate-rsr diff --git a/.machine_readable/6a2/ECOSYSTEM.a2ml b/.machine_readable/6a2/ECOSYSTEM.a2ml deleted file mode 100644 index d8035f5..0000000 --- a/.machine_readable/6a2/ECOSYSTEM.a2ml +++ /dev/null @@ -1,22 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# ECOSYSTEM.a2ml — Lithoglyph ecosystem position -[metadata] -version = "1.0" -last-updated = "2026-04-11" - -[project] -name = "Lithoglyph" -purpose = "Narrative-first, reversible, audit-grade database for domains - where provenance, auditability, and human understanding matter - more than raw performance." -role = "database-engine" - -[position-in-ecosystem] -category = "Databases" - -[related-projects] -projects = [ - # No related projects recorded -] diff --git a/.machine_readable/6a2/META.a2ml b/.machine_readable/6a2/META.a2ml deleted file mode 100644 index b175db4..0000000 --- a/.machine_readable/6a2/META.a2ml +++ /dev/null @@ -1,27 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# META.a2ml — Lithoglyph meta-level information -[metadata] -version = "0.1.0" -last-updated = "2026-04-11" - -[project-info] -license = "PMPL-1.0-or-later" -author = "Jonathan D.A. Jewell (hyperpolymath)" - -[architecture-decisions] -decisions = [ - # No ADRs recorded -] - -[development-practices] -versioning = "SemVer" -documentation = "AsciiDoc" -build-tool = "just" - -[maintenance-axes] -scoping-first = true -axis-1 = "must > intend > like" -axis-2 = "corrective > adaptive > perfective" -axis-3 = "systems > compliance > effects" diff --git a/.machine_readable/6a2/NEUROSYM.a2ml b/.machine_readable/6a2/NEUROSYM.a2ml deleted file mode 100644 index e1d34c0..0000000 --- a/.machine_readable/6a2/NEUROSYM.a2ml +++ /dev/null @@ -1,21 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# NEUROSYM.a2ml — Neurosymbolic integration metadata -[metadata] -version = "0.1.0" -last-updated = "2026-04-11" - -[hypatia-config] -scan-enabled = true -scan-depth = "standard" # quick | standard | deep -report-format = "logtalk" - -[symbolic-rules] -# Custom symbolic rules for this project -# - { name = "no-unsafe-ffi", pattern = "believe_me|unsafeCoerce", severity = "critical" } - -[neural-config] -# Neural pattern detection settings -# confidence-threshold = 0.85 -# model = "hypatia-v2" diff --git a/.machine_readable/6a2/PLAYBOOK.a2ml b/.machine_readable/6a2/PLAYBOOK.a2ml deleted file mode 100644 index 5003fd0..0000000 --- a/.machine_readable/6a2/PLAYBOOK.a2ml +++ /dev/null @@ -1,26 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# PLAYBOOK.a2ml — Operational playbook -[metadata] -version = "0.1.0" -last-updated = "2026-04-11" - -[deployment] -# method = "gitops" # gitops | manual | ci-triggered -# target = "container" # container | binary | library | wasm - -[incident-response] -# 1. Check .machine_readable/STATE.a2ml for current status -# 2. Review recent commits and CI results -# 3. Run `just validate` to check compliance -# 4. Run `just security` to audit for vulnerabilities - -[release-process] -# 1. Update version in STATE.a2ml, META.a2ml -# 2. Run `just release-preflight` (validate + quality + security + maint-hard-pass) -# 3. Tag and push - -[maintenance-operations] -# Baseline audit: just maint-audit -# Hard release gate: just maint-hard-pass diff --git a/.machine_readable/6a2/STATE.a2ml b/.machine_readable/6a2/STATE.a2ml deleted file mode 100644 index b36ea25..0000000 --- a/.machine_readable/6a2/STATE.a2ml +++ /dev/null @@ -1,38 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) -# -# STATE.a2ml — Lithoglyph project state -[metadata] -project = "Lithoglyph" -version = "0.0.7" -last-updated = "2026-03-13" -status = "active" -session = "converted from scheme — 2026-04-11" - -[project-context] -name = "Lithoglyph" -purpose = """C ABI bridge with persistent BlockStorage, WAL commit, 6-phase sync. IP rename complete: fdb_*→lith_*, FQL→GQL, FormBD→Lith.""" -completion-percentage = 65 - -[position] -phase = "ip-rename-complete" # design | implementation | testing | maintenance | archived -maturity = "experimental" # experimental | alpha | beta | production | lts - -[route-to-mvp] -milestones = [ - # No milestones recorded -] - -[blockers-and-issues] -issues = [ - "NAMING-001", -] - -[critical-next-actions] -actions = [ - # No actions recorded -] - -[maintenance-status] -last-run-utc = "2026-03-13T00:00:00Z" -last-result = "unknown" # unknown | pass | warn | fail diff --git a/.machine_readable/descriptiles/CLADE.a2ml b/.machine_readable/descriptiles/CLADE.a2ml index 2c1cc67..29627fd 100644 --- a/.machine_readable/descriptiles/CLADE.a2ml +++ b/.machine_readable/descriptiles/CLADE.a2ml @@ -18,7 +18,7 @@ # uuidgen --sha1 --namespace @url --name "github.com/hyperpolymath/lithoglyph" # # Verify the method first by reproducing a known worked example: -# januskey -> e216170e-ff47-5a5c-bbdd-15e61c8190c8 +# januskey -> e216170e-ff47-5a5c-bbdd-15e61c8190c8 # gitleaks:allow (public UUIDv5 example) # # The owner segment is part of the derived name, so it is part of the IDENTITY: # the same repo hosted under a different owner has a different uuid. Record the diff --git a/.machine_readable/descriptiles/ECOSYSTEM.a2ml b/.machine_readable/descriptiles/ECOSYSTEM.a2ml index 0757418..d8035f5 100644 --- a/.machine_readable/descriptiles/ECOSYSTEM.a2ml +++ b/.machine_readable/descriptiles/ECOSYSTEM.a2ml @@ -1,45 +1,22 @@ # SPDX-License-Identifier: MPL-2.0 -# ECOSYSTEM.a2ml — Ecosystem position (META-TEMPLATE) +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # -# This is the ECOSYSTEM file for rsr-template-repo itself. It records the -# TEMPLATE's own position in the estate. When consumed by a new project, -# replace these fields with the target project's ecosystem position and -# related projects (see the NOTE FOR CONSUMERS at the bottom). - +# ECOSYSTEM.a2ml — Lithoglyph ecosystem position [metadata] -project = "rsr-template-repo" -ecosystem = "hyperpolymath" +version = "1.0" +last-updated = "2026-04-11" -[position] -type = "repository-template" -purpose = "Canonical RSR-compliant repository template: scaffolding (CI/CD, AI manifests, ABI/FFI standards, container ecosystem, governance) that new hyperpolymath projects are instantiated from." -# IS-NOT — anti-identity (the boundary-erosion guard; each line is a real past confusion) -what-this-is-not = [ - "a project in its own right", - "Scaffoldia (the full-featured repo designer)", - "standards (the canon source this template operationalises)", -] +[project] +name = "Lithoglyph" +purpose = "Narrative-first, reversible, audit-grade database for domains + where provenance, auditability, and human understanding matter + more than raw performance." +role = "database-engine" -[pipeline] -position = "foundation" -chain = "standards → rsr-template-repo → (every estate repo)" -notes = "rsr-template-repo turns the RSR standard into runnable scaffolding. New repos are created from it via `just init`, which substitutes the {{PLACEHOLDER}} tokens." -coordination = "standards" +[position-in-ecosystem] +category = "Databases" [related-projects] projects = [ - { name = "standards", relationship = "standard-source", notes = "Defines the RSR standard, contractile canon, and policies that this template operationalises." }, - { name = "stapeln", relationship = "build-tooling", notes = "Layer-based container build system; the template ships stapeln.toml scaffolding." }, - { name = "selur-compose", relationship = "build-tooling", notes = "Service composition; the template ships selur-compose.toml scaffolding." }, - { name = "k9-svc", relationship = "validation-tooling", notes = "Runs the self-validating k9.ncl checks (.machine_readable/self-validating/)." }, - { name = "cerro-torre", relationship = "signing-tooling", notes = "Container/image signing provider referenced by the container scaffolding." }, - { name = "svalinn", relationship = "verification-tooling", notes = "Supply-chain verification referenced by the container scaffolding." }, - { name = "vordr", relationship = "verification-tooling", notes = "Build/artifact verification referenced by the container scaffolding." }, + # No related projects recorded ] - -# --------------------------------------------------------------------------- -# NOTE FOR CONSUMERS: When using this template to create a new repo, replace -# the project/purpose above and rewrite [related-projects] to describe YOUR -# project's actual ecosystem. The entries above describe the TEMPLATE's own -# position, not yours. -# --------------------------------------------------------------------------- diff --git a/.machine_readable/descriptiles/STATE.a2ml b/.machine_readable/descriptiles/STATE.a2ml index 3d2d647..bd51ee6 100644 --- a/.machine_readable/descriptiles/STATE.a2ml +++ b/.machine_readable/descriptiles/STATE.a2ml @@ -1,64 +1,42 @@ # SPDX-License-Identifier: MPL-2.0 # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # -# STATE.a2ml — Project state checkpoint (META-TEMPLATE) -# -# This is the STATE file for rsr-template-repo itself. -# When consumed by a new project, replace {{PLACEHOLDER}} tokens -# and customize sections below for the target project. - +# STATE.a2ml — Lithoglyph project state [metadata] -project = "rsr-template-repo" -version = "0.2.0" -last-updated = "2026-02-28" -status = "active" # active | paused | archived +project = "Lithoglyph" +version = "0.0.7" +last-updated = "2026-09-07" +status = "active" +session = "2026-09-07 proof verification boundary and CI repair" [project-context] -name = "rsr-template-repo" -purpose = "Canonical RSR-compliant repository template providing scaffolding for all hyperpolymath projects — including CI/CD, AI manifests, ABI/FFI standards, container ecosystem, and governance infrastructure." -completion-percentage = 95 +name = "Lithoglyph" +purpose = "Narrative-first database with provenance and reversible operations; GNPL is the associated database language." +# The previous March checkpoint recorded 65%; no current portfolio-wide percentage is asserted. [position] -phase = "maintenance" # design | implementation | testing | maintenance | archived -maturity = "production" # experimental | alpha | beta | production | lts +phase = "ip-rename-complete" # design | implementation | testing | maintenance | archived +maturity = "experimental" # experimental | alpha | beta | production | lts [route-to-mvp] milestones = [ - { name = "Phase 0: Core scaffolding (justfile, CI/CD, .machine_readable)", completion = 100 }, - { name = "Phase 1: ABI/FFI standard (Idris2/Zig templates)", completion = 100 }, - { name = "Phase 1b: AI Gatekeeper Protocol (0-AI-MANIFEST.a2ml)", completion = 100 }, - { name = "Phase 1c: TOPOLOGY.md standard and guide", completion = 100 }, - { name = "Phase 1d: Maintenance gate (axes, checklist, approach)", completion = 100 }, - { name = "Phase 1e: Trustfile / contractiles", completion = 100 }, - { name = "Phase 2: Container ecosystem templates (stapeln)", completion = 100 }, - { name = "Phase 3: Multi-forge sync hardening", completion = 0 }, - { name = "Phase 4: Guix reproducible shells", completion = 50 }, + # No milestones recorded ] [blockers-and-issues] -# No active blockers +issues = [ + "NAMING-001", +] [critical-next-actions] actions = [ - "Container templates complete — test with `just container-init`", - "Validate container templates across wolfi-base and static Chainguard images", - "Harden multi-forge sync for GitLab/Bitbucket mirroring edge cases", - "Expand Guix development shell templates", + # No actions recorded ] [maintenance-status] -last-run-utc = "never" -last-report = "docs/reports/maintenance/latest.json" +last-run-utc = "2026-03-13T00:00:00Z" last-result = "unknown" # unknown | pass | warn | fail -open-warnings = 0 -open-failures = 0 - -[ecosystem] -part-of = ["RSR Framework", "stapeln ecosystem"] -depends-on = ["stapeln", "selur-compose", "cerro-torre", "svalinn", "vordr", "k9-svc"] -# --------------------------------------------------------------------------- -# NOTE FOR CONSUMERS: When using this template to create a new repo, reset -# the fields above to your project's values and replace all {{PLACEHOLDER}} -# tokens. The milestones above describe the TEMPLATE's evolution, not yours. -# --------------------------------------------------------------------------- +[verification-2026-09-07] +local = ["27 Zig core tests passed", "18 C FFI integration tests passed, including verifier acceptance and refusal controls"] +limits = ["Builtin certificate verification is unimplemented and refuses", "Remote CI and high-severity native-boundary findings still require resolution before merge"] diff --git a/.machine_readable/root-allow.txt b/.machine_readable/root-allow.txt index e9d76c0..5935380 100644 --- a/.machine_readable/root-allow.txt +++ b/.machine_readable/root-allow.txt @@ -24,6 +24,9 @@ SECURITY.md # Accepted at root OR .github/ — see CONTRIBUTING.m LICENSE LICENSES/ # REUSE licence texts (MPL-2.0.txt + CC-BY-SA-4.0.txt) for the dual-licence model (code MPL-2.0 / docs CC-BY-SA-4.0) CHANGELOG.md +CHANGELOG.adoc # Current changelog after the AsciiDoc migration. +CONTRIBUTING.adoc # Current contributor guide after the AsciiDoc migration. +SECURITY.adoc # Current security policy after the AsciiDoc migration. CITATION.cff # citation metadata (surfaced at root by #96) RSR-PHILOSOPHY.adoc # RSR philosophy statement (root authority file; was drift until 2026-07-07) diff --git a/api/src/integration_tests.zig b/api/src/integration_tests.zig index 6321cb5..bb95ab6 100644 --- a/api/src/integration_tests.zig +++ b/api/src/integration_tests.zig @@ -182,7 +182,7 @@ test "WebSocket accept key computation follows RFC 6455" { const allocator = createTestAllocator(); // Example from RFC 6455 Section 1.3 - const key = "dGhlIHNhbXBsZSBub25jZQ=="; + const key = "dGhlIHNhbXBsZSBub25jZQ=="; // gitleaks:allow -- public RFC 6455 Section 1.3 nonce const expected = "s3pPLMBiTxaQ9kYGzzhZRbK+xOo="; const accept = try websocket.computeAcceptKey(allocator, key); diff --git a/api/src/websocket.zig b/api/src/websocket.zig index 93a428f..545be15 100644 --- a/api/src/websocket.zig +++ b/api/src/websocket.zig @@ -303,7 +303,7 @@ test "websocket accept key computation" { const allocator = std.testing.allocator; // Example from RFC 6455 - const key = "dGhlIHNhbXBsZSBub25jZQ=="; + const key = "dGhlIHNhbXBsZSBub25jZQ=="; // gitleaks:allow -- public RFC 6455 Section 1.3 nonce const accept = try computeAcceptKey(allocator, key); defer allocator.free(accept); diff --git a/clients/README.adoc b/clients/README.adoc index 90d0fdd..c119757 100644 --- a/clients/README.adoc +++ b/clients/README.adoc @@ -75,6 +75,7 @@ All clients support: [source,rescript] ---- // ReScript - API Key +// hypatia: allow security_errors/secret_detected -- illustrative placeholder, not a credential let client = make(~baseUrl="http://localhost:8080", ~apiKey="your-api-key") // ReScript - Bearer Token diff --git a/core-zig/src/bridge.zig b/core-zig/src/bridge.zig index 8f8b9f6..88c269d 100644 --- a/core-zig/src/bridge.zig +++ b/core-zig/src/bridge.zig @@ -971,7 +971,7 @@ pub export fn lith_proof_unregister_verifier( /// Verify a proof using registered verifiers /// -/// @param proof_ptr CBOR-encoded proof blob +/// @param proof_ptr JSON envelope {"type": string, "data": string} /// @param proof_len Length of proof /// @param out_valid Output: true if proof is valid /// @param out_err Output parameter for error blob @@ -982,6 +982,9 @@ pub export fn lith_proof_verify( out_valid: *bool, out_err: *LgBlob, ) LgStatus { + // A reused output must never retain a successful verdict on an error path. + out_valid.* = false; + out_err.* = LgBlob.empty(); const proof_data = proof_ptr[0..proof_len]; // Parse JSON proof to extract type and data @@ -1034,50 +1037,19 @@ pub export fn lith_proof_verify( const verify_data = data_value.string; const status = entry.callback(verify_data.ptr, verify_data.len, entry.context); - out_valid.* = (status == .ok); - out_err.* = LgBlob.empty(); - return .ok; -} - -/// Built-in verifier for FD-holds proofs (always accepts for PoC) -fn builtin_fd_verifier( - _: [*]const u8, - _: usize, - _: ?*anyopaque, -) callconv(.c) LgStatus { - // In production, this would actually verify the proof - // For PoC, we accept all well-formed proofs - return .ok; -} - -/// Built-in verifier for normalization proofs -fn builtin_normalization_verifier( - _: [*]const u8, - _: usize, - _: ?*anyopaque, -) callconv(.c) LgStatus { - // In production, this would verify losslessness and dependency preservation - // For PoC, we accept all well-formed proofs + if (status != .ok) { + out_err.* = createErrorBlob(status, "Registered proof verifier rejected the proof or could not verify it"); + return status; + } + out_valid.* = true; return .ok; } -/// Initialize built-in proof verifiers +/// Built-in mathematical verifiers are not implemented. Keep the ABI symbol, +/// report that fact, and leave registered verifiers untouched. Consumers must +/// explicitly install a real verifier with lith_proof_register_verifier. pub export fn lith_proof_init_builtins() LgStatus { - // Register FD-holds verifier - const fd_type = "fd-holds"; - var status = lith_proof_register_verifier(fd_type.ptr, fd_type.len, builtin_fd_verifier, null); - if (status != .ok) return status; - - // Register normalization verifier - const norm_type = "normalization"; - status = lith_proof_register_verifier(norm_type.ptr, norm_type.len, builtin_normalization_verifier, null); - if (status != .ok) return status; - - // Register denormalization verifier (same logic) - const denorm_type = "denormalization"; - status = lith_proof_register_verifier(denorm_type.ptr, denorm_type.len, builtin_normalization_verifier, null); - - return status; + return .err_not_implemented; } // ============================================================ @@ -1148,3 +1120,52 @@ test "version" { const version = lith_version(); try std.testing.expectEqual(@as(u32, 100), version); // 0.1.0 } + +test "unimplemented builtins cannot certify a proof" { + try std.testing.expectEqual(LgStatus.err_not_implemented, lith_proof_init_builtins()); + const proofs = [_][]const u8{ + "{\"type\":\"fd-holds\",\"data\":\"not a proof\"}", + "{\"type\":\"normalization\",\"data\":\"not a proof\"}", + "{\"type\":\"denormalization\",\"data\":\"not a proof\"}", + }; + for (proofs) |proof| { + var valid = true; + var err = LgBlob.empty(); + const status = lith_proof_verify(proof.ptr, proof.len, &valid, &err); + defer lith_blob_free(&err); + try std.testing.expectEqual(LgStatus.err_not_found, status); + try std.testing.expect(!valid); + } +} + +test "malformed proof clears a previous successful verdict" { + const proof = "not JSON"; + var valid = true; + var err = LgBlob.empty(); + defer lith_blob_free(&err); + try std.testing.expectEqual(LgStatus.err_invalid_argument, lith_proof_verify(proof.ptr, proof.len, &valid, &err)); + try std.testing.expect(!valid); +} + +test "registered verifier controls the verdict and failures propagate" { + // A test protocol, not a mathematical proof verifier. This positive control + // shows that denying unavailable builtins does not disable registration. + const TestVerifier = struct { + fn check(ptr: [*]const u8, len: usize, _: ?*anyopaque) callconv(.c) LgStatus { + return if (std.mem.eql(u8, ptr[0..len], "accepted-witness")) .ok else .err_invalid_argument; + } + }; + const kind = "test-protocol"; + try std.testing.expectEqual(LgStatus.ok, lith_proof_register_verifier(kind.ptr, kind.len, TestVerifier.check, null)); + defer _ = lith_proof_unregister_verifier(kind.ptr, kind.len); + const good = "{\"type\":\"test-protocol\",\"data\":\"accepted-witness\"}"; + const bad = "{\"type\":\"test-protocol\",\"data\":\"forged-witness\"}"; + var valid = false; + var err = LgBlob.empty(); + defer lith_blob_free(&err); + try std.testing.expectEqual(LgStatus.ok, lith_proof_verify(good.ptr, good.len, &valid, &err)); + try std.testing.expect(valid); + try std.testing.expectEqual(LgStatus.err_invalid_argument, lith_proof_verify(bad.ptr, bad.len, &valid, &err)); + try std.testing.expect(!valid); + try std.testing.expect(err.len > 0); +} diff --git a/core-zig/test-ffi-integration.c b/core-zig/test-ffi-integration.c index 073eb40..bf90f2f 100644 --- a/core-zig/test-ffi-integration.c +++ b/core-zig/test-ffi-integration.c @@ -444,7 +444,7 @@ static int test_introspection(void) { static int test_proof_init_builtins(void) { LithStatus s = lith_proof_init_builtins(); printf(" init_builtins status: %d\n", s); - return (s == LITH_OK) ? 0 : 1; + return (s == LITH_ERR_NOT_IMPLEMENTED) ? 0 : 1; } /* ============================================================ @@ -482,11 +482,11 @@ static int test_proof_register_unregister(void) { * Test 15: Proof verify * ============================================================ */ static int test_proof_verify(void) { - /* Ensure builtins are registered */ - lith_proof_init_builtins(); + /* Unimplemented builtins must never certify a placeholder payload. */ + if (lith_proof_init_builtins() != LITH_ERR_NOT_IMPLEMENTED) return 1; const char* proof_json = "{\"type\":\"fd-holds\",\"data\":\"dGVzdA==\"}"; - bool valid = false; + bool valid = true; /* Refusal must clear a previous verdict. */ LgBlob err = {0}; LithStatus s = lith_proof_verify( @@ -496,7 +496,40 @@ static int test_proof_verify(void) { printf(" verify status: %d, valid: %s\n", s, valid ? "true" : "false"); free_blob(&err); - return (s == LITH_OK && valid) ? 0 : 1; + return (s == LITH_ERR_NOT_FOUND && !valid) ? 0 : 1; +} + +/* Test-only witness protocol: exercises the C callback ABI, not a proof checker. */ +static LithStatus witness_verifier(const uint8_t* proof, size_t len, void* ctx) { + (void)ctx; + const char* accepted = "accepted-witness"; + return len == strlen(accepted) && memcmp(proof, accepted, len) == 0 + ? LITH_OK : LITH_ERR_INVALID_ARGUMENT; +} + +static int test_proof_registered_verdict(void) { + const char* kind = "test-protocol"; + if (lith_proof_register_verifier((const uint8_t*)kind, strlen(kind), + witness_verifier, NULL) != LITH_OK) return 1; + const char* inputs[] = { + "{\"type\":\"test-protocol\",\"data\":\"accepted-witness\"}", + "{\"type\":\"test-protocol\",\"data\":\"forged-witness\"}", + "not JSON" + }; + const LithStatus expected[] = {LITH_OK, LITH_ERR_INVALID_ARGUMENT, + LITH_ERR_INVALID_ARGUMENT}; + bool valid = false; + int ok = 1; + for (size_t i = 0; i < 3; ++i) { + LgBlob err = {0}; + if (i == 2) valid = true; + LithStatus s = lith_proof_verify((const uint8_t*)inputs[i], strlen(inputs[i]), + &valid, &err); + ok = ok && s == expected[i] && valid == (i == 0); + free_blob(&err); + } + ok = lith_proof_unregister_verifier((const uint8_t*)kind, strlen(kind)) == LITH_OK && ok; + return ok ? 0 : 1; } /* ============================================================ @@ -561,6 +594,7 @@ int main(void) { RUN_TEST(test_proof_init_builtins); RUN_TEST(test_proof_register_unregister); RUN_TEST(test_proof_verify); + RUN_TEST(test_proof_registered_verdict); RUN_TEST(test_blob_free_null); RUN_TEST(test_apply_readonly_rejected); diff --git a/docs/SECURITY-AUTH.adoc b/docs/SECURITY-AUTH.adoc index 80d5b38..8ad3e3a 100644 --- a/docs/SECURITY-AUTH.adoc +++ b/docs/SECURITY-AUTH.adoc @@ -1216,9 +1216,10 @@ rotation_period = "1h" [source,bash] ---- # Secrets should be injected via environment -export LITH_AUTH_JWT_SECRET="..." -export LITH_ENCRYPTION_MASTER_KEY="..." -export LITH_OIDC_CLIENT_SECRET="..." +: "${LITH_AUTH_JWT_SECRET:?inject the JWT signing secret}" +: "${LITH_ENCRYPTION_MASTER_KEY:?inject the encryption master key}" +: "${LITH_OIDC_CLIENT_SECRET:?inject the OIDC client secret}" +export LITH_AUTH_JWT_SECRET LITH_ENCRYPTION_MASTER_KEY LITH_OIDC_CLIENT_SECRET ---- === HashiCorp Vault Integration 🚧 @@ -1239,8 +1240,8 @@ kubernetes_mount = "kubernetes" # Secret paths [secrets.vault.paths] master_key = "secret/data/lith/master-key" -jwt_secret = "secret/data/lith/jwt-secret" -oidc_secret = "secret/data/lith/oidc-client" +jwt_secret = "secret/data/lith/jwt-secret" # hypatia: allow security_errors/secret_detected -- Vault lookup path, not the secret value +oidc_secret = "secret/data/lith/oidc-client" # hypatia: allow security_errors/secret_detected -- Vault lookup path, not the secret value # Dynamic secrets for database connections # postgres_creds = "database/creds/lith-role" @@ -1258,8 +1259,8 @@ region = "us-east-1" [secrets.aws.paths] master_key = "lith/master-key" -jwt_secret = "lith/jwt-secret" -oidc_secret = "lith/oidc-client" +jwt_secret = "lith/jwt-secret" # hypatia: allow security_errors/secret_detected -- AWS lookup path, not the secret value +oidc_secret = "lith/oidc-client" # hypatia: allow security_errors/secret_detected -- AWS lookup path, not the secret value ---- == Security Hardening diff --git a/docs/proof-verification-boundary.adoc b/docs/proof-verification-boundary.adoc new file mode 100644 index 0000000..53a29a8 --- /dev/null +++ b/docs/proof-verification-boundary.adoc @@ -0,0 +1,45 @@ +// SPDX-License-Identifier: CC-BY-SA-4.0 += Lithoglyph proof verification boundary + +The bridge can dispatch a proof envelope to an explicitly registered verifier. +It does not currently implement mathematical verifiers for functional +dependencies, lossless normalisation, or dependency preservation. + +`lith_proof_init_builtins()` returns `err_not_implemented` and leaves the +registry unchanged. Applications must check that status. Registering a callback +with `lith_proof_register_verifier` is an explicit trust decision: the callback +must actually validate the claimed proposition against its evidence and context. + +`lith_proof_verify` accepts a JSON envelope with string fields `type` and `data`. +The callback defines the payload protocol. The bridge clears `out_valid` before +parsing, returns an error for an unknown verifier, and propagates a callback's +failure status. Only a callback returning `ok` sets `out_valid` to true. +Envelope parsing, provenance recording, and a successful storage operation do +not establish the proposition in a proof payload. + +== Executable checks + +With the repository's pinned Zig 0.15.2: + +[source,shell] +---- +cd core-zig +zig build test +---- + +The bridge suite checks that all three unavailable built-in proof types refuse +arbitrary payloads, that malformed input cannot retain an earlier successful +verdict, and that an explicitly registered test verifier controls acceptance and +rejection. The test verifier is a positive control for dispatch, not a +mathematical proof checker. + +Before this change, each of those three regression tests failed against the +accepting callbacks and stale-output behaviour. After the change, all 27 test +executions in the bridge, block, and crypto build passed locally on 2026-09-07. + +== Remaining obligation + +A deployed proof-bearing operation needs a verifier for its concrete proposition, +a binding to the exact data and transition being authorised, and rejection tests +for forged, stale, or mismatched evidence. The registration ABI alone supplies +none of those guarantees. diff --git a/lith-http/docs/sessions/M12-AUTH-RATE-LIMIT-COMPLETE.adoc b/lith-http/docs/sessions/M12-AUTH-RATE-LIMIT-COMPLETE.adoc index d79261c..44f1e39 100644 --- a/lith-http/docs/sessions/M12-AUTH-RATE-LIMIT-COMPLETE.adoc +++ b/lith-http/docs/sessions/M12-AUTH-RATE-LIMIT-COMPLETE.adoc @@ -37,7 +37,7 @@ Claims validation (exp, iat, nbf, iss, aud) - Configurable expiration [source,elixir] ---- config :lith_http, - jwt_secret: "your-secret-key-here", + jwt_secret: System.fetch_env!("LITH_AUTH_JWT_SECRET"), jwt_algorithm: "HS256", jwt_issuer: "lith-http", jwt_expiration: 3600 # seconds diff --git a/lith-http/k8s/base/secret.yaml.template b/lith-http/k8s/base/secret.yaml.template index 9ca803d..753f5d4 100644 --- a/lith-http/k8s/base/secret.yaml.template +++ b/lith-http/k8s/base/secret.yaml.template @@ -26,7 +26,7 @@ stringData: secret-key-base: "REPLACE_WITH_REAL_SECRET" # JWT signing secret (generate with: openssl rand -base64 64) - jwt-secret: "REPLACE_WITH_REAL_JWT_SECRET" + jwt-secret: "REPLACE_WITH_REAL_JWT_SECRET" # hypatia: allow security_errors/secret_detected -- explicit unfilled template value, never a deployment credential # Erlang distribution cookie (generate with: openssl rand -base64 32) erlang-cookie: "REPLACE_WITH_REAL_ERLANG_COOKIE" diff --git a/sonar-project.properties b/sonar-project.properties index 9a2b945..d70585d 100644 --- a/sonar-project.properties +++ b/sonar-project.properties @@ -1,9 +1,9 @@ # SPDX-License-Identifier: MPL-2.0 # SonarQube Cloud (SonarCloud) configuration. -# Project: https://sonarcloud.io/project/overview?id=hyperpolymath_rsr-template-repo +# Project: https://sonarcloud.io/project/overview?id=hyperpolymath_lithoglyph # Requires the SONAR_TOKEN repository secret + a SonarCloud project (owner setup). sonar.organization=hyperpolymath -sonar.projectKey=hyperpolymath_rsr-template-repo +sonar.projectKey=hyperpolymath_lithoglyph # Analysable surface = shell scripts + any JS/TS the template carries. Idris2, # Zig, Elixir and AffineScript have no SonarCloud analyser; vendored, generated,