Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Normalize text files to LF in the repository.
* text=auto eol=lf

# Keep the repository's source and data formats explicitly textual.
*.md text
*.py text
*.json text
*.jsonl text
*.yml text
*.yaml text
*.sh text
*.txt text

# These files are intended for direct viewing, not diffing as source.
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.pdf binary
78 changes: 78 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
name: Repository
on:
pull_request:
push:
branches: [main, 'dev*', 'dev**/**', 'release*', 'release**/**', 'codex/**']
workflow_dispatch:
permissions:
contents: read
concurrency:
group: repository-${{ github.ref }}
cancel-in-progress: true
jobs:
verify:
name: Repository / verify
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
path: product
persist-credentials: false
submodules: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Read fixed shared-tool source
id: tooling
working-directory: product
run: |
node --input-type=module -e 'import fs from "node:fs"; const t=JSON.parse(fs.readFileSync("release/tooling.json")); for(const k of ["workspace","core"]) if(t[k]) {if(!/^[a-f0-9]{40}$/.test(t[k].commit)) throw Error("Unpinned tools"); fs.appendFileSync(process.env.GITHUB_OUTPUT, k+"="+t[k].commit+"\n");}'
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: shendeguize/AgentOrganon
ref: ${{ steps.tooling.outputs.workspace }}
path: tools
persist-credentials: false
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: shendeguize/OrganonCore
ref: ${{ steps.tooling.outputs.core }}
path: core
persist-credentials: false
- name: Install pinned Lean toolchain in temporary runner storage
env:
ELAN_HOME: ${{ runner.temp }}/organon-elan
run: |
mkdir -p "$RUNNER_TEMP/organon-elan-bootstrap"
curl --proto '=https' --tlsv1.2 --fail --location https://github.com/leanprover/elan/releases/download/v4.2.4/elan-x86_64-unknown-linux-gnu.tar.gz --output "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz"
echo "42b94d4244e8353142c456ec0e4ca6528fd898a6c604d4059f494e706e431f63 $RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" | sha256sum --check --strict
tar -xzf "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" -C "$RUNNER_TEMP/organon-elan-bootstrap"
"$RUNNER_TEMP/organon-elan-bootstrap/elan-init" -y --no-modify-path --default-toolchain leanprover/lean4:v4.33.1
"$ELAN_HOME/bin/elan" toolchain install leanprover/lean4:v4.33.1
echo "ELAN_HOME=$ELAN_HOME" >> "$GITHUB_ENV"
echo "$ELAN_HOME/bin" >> "$GITHUB_PATH"
- name: Source tests and human-document links
working-directory: product
env:
ORGANON_WORKSPACE_ROOT: ${{ github.workspace }}/tools
ORGANON_CORE_ROOT: ${{ github.workspace }}/core
run: |
npm test
npm run check:content
- name: Install locked site build dependencies
working-directory: core/tools/site
run: npm ci --ignore-scripts
- name: Build and validate released-site paths
working-directory: product
env:
ORGANON_CORE_ROOT: ${{ github.workspace }}/core
run: npm run check:site
- name: Check current Lean evidence and four reader editions
run: node core/skills/organon-core-leanify-prove/scripts/check.js product/SoftwareEngineering/lean/philosophy --manuscript manuscript.json
- name: Keep development site preview
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: development-site-AdvisedOrganons-${{ github.run_attempt }}
path: product/dist/site/
if-no-files-found: error
77 changes: 77 additions & 0 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
name: Verified release Pages
on:
workflow_dispatch:
inputs:
version:
description: Published product version
required: true
type: string
manifest_sha256:
description: Canonical digest of the fully published release manifest
required: true
type: string
permissions: {}
concurrency:
group: site-data-${{ github.repository }}
cancel-in-progress: false
jobs:
prepare:
if: github.repository == 'shendeguize/AdvisedOrganons' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0')
runs-on: ubuntu-24.04
timeout-minutes: 45
permissions:
contents: write
outputs:
deploy: ${{ steps.state.outputs.deploy }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Read fixed workspace tooling
id: tooling
run: |
node --input-type=module - <<'NODE'
import fs from 'node:fs';
const tooling = JSON.parse(fs.readFileSync('release/tooling.json', 'utf8'));
if (tooling.schema_version !== 1 || tooling.workspace?.repository !== 'shendeguize/AgentOrganon' || !/^[a-f0-9]{40}$/.test(tooling.workspace.commit)) throw new Error('Invalid fixed workspace tooling');
fs.appendFileSync(process.env.GITHUB_OUTPUT, `commit=${tooling.workspace.commit}\n`);
NODE
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: shendeguize/AgentOrganon
ref: ${{ steps.tooling.outputs.commit }}
path: .tooling/workspace
persist-credentials: false
- name: Verify all channels and build fixed released sources
id: state
env:
GITHUB_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ github.token }}
GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }}
RELEASE_VERSION: ${{ inputs.version }}
MANIFEST_SHA256: ${{ inputs.manifest_sha256 }}
run: node .tooling/workspace/scripts/release/site-data.mjs pages --version "$RELEASE_VERSION" --manifest-sha256 "$MANIFEST_SHA256"
- uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa
if: steps.state.outputs.deploy == 'true'
with:
name: github-pages-${{ github.run_attempt }}
path: ${{ steps.state.outputs.public_dir }}
deploy:
needs: prepare
if: needs.prepare.outputs.deploy == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e
id: deployment
with:
artifact_name: github-pages-${{ github.run_attempt }}
90 changes: 90 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
name: Publish verified product
on:
workflow_dispatch:
inputs:
version:
description: Exact validated product version
required: true
manifest_sha256:
description: Canonical sealed manifest digest
required: true
operation:
description: Controlled publication step
required: true
type: choice
options: [publish, promote]
bootstrap_npm:
description: Use the short-lived first-publication credential
type: boolean
default: false
permissions:
contents: read
concurrency:
group: publish-${{ inputs.version }}
cancel-in-progress: false
jobs:
publish:
if: github.ref == 'refs/heads/release/1.0.0'
environment: ${{ startsWith(inputs.version, '1.0.0-rc.') && 'npm-rc' || 'npm-stable' }}
runs-on: ubuntu-24.04
permissions:
contents: write
actions: read
id-token: write
env:
RELEASE_VERSION: ${{ inputs.version }}
RELEASE_MANIFEST_SHA256: ${{ inputs.manifest_sha256 }}
APPROVED_RC_MANIFEST_SHA256: ${{ vars.APPROVED_RC_MANIFEST_SHA256 }}
NPM_CHANNEL_STRATEGY: ${{ vars.NPM_CHANNEL_STRATEGY }}
RELEASE_OPERATION: ${{ inputs.operation }}
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.sha }}
path: product
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
registry-url: https://registry.npmjs.org
- name: Read fixed release tooling
id: tooling
working-directory: product
run: |
node --input-type=module -e 'import fs from "node:fs"; const t=JSON.parse(fs.readFileSync("release/tooling.json")); if(t.workspace.repository!=="shendeguize/AgentOrganon" || !/^[a-f0-9]{40}$/.test(t.workspace.commit)) throw Error("Unpinned tools"); fs.appendFileSync(process.env.GITHUB_OUTPUT,"workspace="+t.workspace.commit+"\n")'
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: shendeguize/AgentOrganon
ref: ${{ steps.tooling.outputs.workspace }}
path: tools
persist-credentials: false
- name: Install exact npm with OIDC support in the temporary runner
run: npm install --global npm@12.0.2 --ignore-scripts
- name: Fetch exact public validated bundle

run: node tools/scripts/release/publish.mjs fetch --version "$RELEASE_VERSION" --manifest-sha256 "$RELEASE_MANIFEST_SHA256" --out candidate
- name: Verify identity and every gate before credentials are exposed
run: |
node tools/scripts/release/manifest.mjs check --manifest candidate/release-manifest.json
node --input-type=module -e 'import {readJSON} from "./tools/scripts/release/lib.mjs"; import {assertDispatch} from "./tools/scripts/release/manifest.mjs"; assertDispatch(readJSON("candidate/release-manifest.json"),process.env,"advised")'
- name: Verify approved RC to stable source transition
if: inputs.version == '1.0.0'
run: node tools/scripts/release/stable.mjs --manifest candidate/release-manifest.json
- name: First npm publication with short-lived bootstrap credential
if: inputs.operation == 'publish' && inputs.bootstrap_npm
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_BOOTSTRAP_TOKEN }}
GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }}
run: node tools/scripts/release/publish.mjs publish --manifest candidate/release-manifest.json --product advised
- name: OIDC publication or verified bundle operation
if: inputs.operation != 'promote' && !(inputs.operation == 'publish' && inputs.bootstrap_npm)
env:
GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }}
run: node tools/scripts/release/publish.mjs "$RELEASE_OPERATION" --manifest candidate/release-manifest.json --product advised
- name: Complete channel recommendation only after all three products match
if: inputs.operation == 'promote'
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TAG_TOKEN }}
GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }}
run: node tools/scripts/release/publish.mjs promote --manifest candidate/release-manifest.json --product advised
67 changes: 67 additions & 0 deletions .github/workflows/stars.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
name: Observed stars
on:
workflow_dispatch:
schedule:
- cron: '17 2 * * *'
permissions: {}
concurrency:
group: site-data-${{ github.repository }}
cancel-in-progress: false
jobs:
prepare:
if: github.repository == 'shendeguize/AdvisedOrganons' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0')
runs-on: ubuntu-24.04
timeout-minutes: 45
permissions:
contents: write
outputs:
deploy: ${{ steps.state.outputs.deploy }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Read fixed workspace tooling
id: tooling
run: |
node --input-type=module - <<'NODE'
import fs from 'node:fs';
const tooling = JSON.parse(fs.readFileSync('release/tooling.json', 'utf8'));
if (tooling.schema_version !== 1 || tooling.workspace?.repository !== 'shendeguize/AgentOrganon' || !/^[a-f0-9]{40}$/.test(tooling.workspace.commit)) throw new Error('Invalid fixed workspace tooling');
fs.appendFileSync(process.env.GITHUB_OUTPUT, `commit=${tooling.workspace.commit}\n`);
NODE
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: shendeguize/AgentOrganon
ref: ${{ steps.tooling.outputs.commit }}
path: .tooling/workspace
persist-credentials: false
- name: Sample actual total and retain released HTML
id: state
env:
GITHUB_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ github.token }}
run: node .tooling/workspace/scripts/release/site-data.mjs stars
- uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa
if: steps.state.outputs.deploy == 'true'
with:
name: github-pages-${{ github.run_attempt }}
path: ${{ steps.state.outputs.public_dir }}
deploy:
needs: prepare
if: needs.prepare.outputs.deploy == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e
id: deployment
with:
artifact_name: github-pages-${{ github.run_attempt }}
51 changes: 51 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Local project state
/.local/

# Python
__pycache__/
*.py[cod]
*$py.class
.Python
*.so
.venv/
venv/
env/
ENV/
pip-wheel-metadata/
*.egg-info/
build/
dist/

# Python tooling
.pytest_cache/
.mypy_cache/
.ruff_cache/
.tox/
.nox/
.coverage
.coverage.*
htmlcov/

# Operating system
.DS_Store
.AppleDouble
.LSOverride

# Editor and IDE
.idea/
.vscode/

node_modules/

*.log

# Lean compiler outputs
*.olean

# Public immutable review evidence required by the manuscript closure
!/SoftwareEngineering/lean/philosophy/reviews/r3-actual-audit.log
!/SoftwareEngineering/lean/philosophy/reviews/r3-build.log
!/SoftwareEngineering/lean/philosophy/reviews/r3-probes.log
!/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe.log
!/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.log
!/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.log
Loading
Loading