Skip to content

docs: preflight readiness record, SPEC-018 stays blocked - #186

Merged
scrimshawlife-ctrl merged 3 commits into
mainfrom
hardening/preflight-record
Sep 30, 2026
Merged

scrimshawlife-ctrl merged 3 commits into
mainfrom
hardening/preflight-record

Conversation

@scrimshawlife-ctrl

Copy link
Copy Markdown
Owner

Problem

main had no branch protection, and the remaining production-readiness gaps were not written down as observed facts. That made it easy to treat a green check as launch authority.

Released authority

  • Stack 0.6.0, RELEASE_MANIFEST-0.6.0.md
  • SPEC018_OWNER_LAUNCH_PACKET.md settlement KEEP_BLOCKED (2026-09-26)
  • OPERATOR_CALLS_2026-09-25.md for D-001, D-002, D-006, D-008, D-010, D-013, D-021/D-023/D-024, D-022, D-034, D-036

Files changed

  • docs/hardening/BRANCH_PROTECTION.md
  • docs/hardening/READINESS_MATRIX.md

Tests

No product code changed. No test run.

Security / privacy effect

None in the application. The matrix restates that native session storage stays memory-only and that HIPAA classification is counsel-owned.

Migration effect

None.

Rollback / forward-fix

Revert the documentation commit. The GitHub branch-protection change is separate and is recorded in BRANCH_PROTECTION.md. Reverting the commit does not remove that GitHub setting.

Remaining unavailable surfaces

SPEC-018 stays KEEP_BLOCKED. No readiness gate moves to READY. D-001, D-002, D-006, D-008, D-010, and D-013 stay pending. SLO, RTO, and RPO stay NOT_COMPUTABLE.

Evidence

On 2026-09-30 the branch-protection API applied, for suas main: pull request required, required check verify (strict), conversation resolution required, force-push blocked, deletion blocked. enforce_admins is false. required_approving_review_count is 0.

suas-specs and suas-android received pull-request protection without a required status check. suas-ios returned HTTP 403 (private repository, GitHub Pro or public required). That protection was not applied.

The matrix states observed controls. It does not flip a readiness gate,
choose a queue vendor, or claim production authority.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af1382a9a0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/hardening/READINESS_MATRIX.md Outdated
Comment thread docs/hardening/BRANCH_PROTECTION.md Outdated
The suas-specs protection row was one column short. The missing blocker cell is restored, and Prettier can check the file.
The D-022 packet and factory already select the Postgres outbox. The readiness row records that choice as partial. The 2026-09-25 operator call still forbids a PRODUCTION_DURABLE_QUEUE READY claim. worker-deploy.yml is labeled a synthetic-staging deployment, and production deployment stays prohibited.
@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit e3a9a16 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant