Repository navigation
Validate canonical facts and add scoped description automation - #38
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Facts updates currently require separate validation and manual repository-description refreshes. This adds pull-request validation of canonical facts and deterministic scoreboard outputs, plus a separately scoped description workflow with dry-run as its default. It manages engine, codegen, corpus and the released HPO license description; static descriptions stay read-only.
Release jobs now declare their protected environment and obtain consumer targets from environment secrets. The release replay harness checks the same target mapping, typed dispatch payloads and independent consumer failure behavior. The runbook describes the credential transition and requires a separately authorized live rollout before removing the temporary repository-secret fallback.
Validation on the executable candidate: 23 facts tests, 22 renderer/workflow tests, 67 release tests, 31 fingerprint checks, 15 harness tests and all 63 release-replay checks passed. Six card renders, YAML validation and actionlint also passed. External services are shimmed in replay; no production mint, description write or release dispatch is claimed by this proof. The final commit only corrects the runbook; an independent review verified every executable and test byte is unchanged from the tested candidate. Two independent reviews cleared the implementation, and the final documentation addendum is cleared.
Canonical facts and schema bytes are unchanged. Website dispatch, deployment and served-facts freshness are follow-up stages. Before landing, the operator must verify description apply is disabled at every variable scope; the live App/environment and release proof remain separate rollout gates.