Arena/01a0db23 metamanifold webui - #13
hyperpolymath wants to merge 265 commits into
Conversation
…nd working cutadapt -> vsearch-dada merge on default settings.
…for DADA2 and VSEARCH
… of previously run stages. Created a versatile project structure.
….it was getting messy and altogether not worth it for now.
…venance probe visibility) (#85) ## Why Every workflow run on this repository since **2026-09-25 22:19 UTC** has failed with `startup_failure` and **zero jobs** — CI has produced no verdict on anything since (the refreshed audit in `docs/audit/2026-09-26-memory-numerics-warning-audit.md` records the same observation). The run annotations name the cause; two rules, neither reportable by a job that never starts: > The actions `julia-actions/setup-julia@…`, `julia-actions/cache@…`, and `julia-actions/julia-processcoverage@…` are **not allowed** in hyperpolymath/MetaManifold-WebUI because all actions must be from a repository owned by hyperpolymath, created by GitHub, verified in the GitHub Marketplace, or match the pattern: `arena-ai-coding-agent[bot]`. **All actions must also be pinned to a full-length commit SHA.** - `ci.yml`, `ui.yml`, `doi.yml` used the three disallowed `julia-actions/*` actions; - `proofs.yml` used tag refs (`@v4`/`@v5`) instead of full SHAs (its annotation from run 36293672919). Dependabot PR #68 (merged 2026-09-25 22:26) was **not** the cause — it only changed which ref each disallowed action used; the enforcement itself turned on at 22:19 and broke the arena-branch run five minutes before #68 merged. ## What changed (behaviour preserved) | workflow | was | now | |---|---|---| | ci/ui/doi | `julia-actions/setup-julia` | inline install of official 1.12.5 binaries, **verified against the official checksum file** before use; `JULIA_VERSION` keeps the pin cross-checked by `test_install_pins` | | ci/ui/doi | `julia-actions/cache` | `actions/cache@55cc834` (v6.1.0) over the same depot dirs, keyed on each workflow's own Manifest/Project | | ci | `julia-actions/julia-processcoverage` | equivalent `CoverageTools` run step (same default dirs, same `lcov.info`) | | proofs | `checkout/setup-python/cache/upload-artifact@v4/@v5` | same tags' **commits** — no version change | Plus **two guards** so this cannot regress silently: - `test/unit/test_install_pins.jl` now locates the Julia pin by step name (`JULIA_VERSION=` in `Set up Julia`) and gains a new testset that walks **every workflow** and fails on any action that is not full-SHA-pinned or not allow-listed — a future dependabot bump to a tag reddens `Pkg.test` instead of silencing Actions; - the provenance probe fallbacks in `src/analysis/Execution.jl` (the second commit) now `@warn` before writing `version=unknown`/`hostname=unknown` placeholders — the manifest schema and all existing assertions over it are untouched. ## Validation done offline - YAML parse + duplicate-key scan of all four workflows; - policy self-check mirroring the new testset (every `uses:` full-SHA + allow-listed owner); - `bash -n` on **every** `run:` block; - `JULIA_VERSION` regex against `config/defaults/tool_versions.yml` (1.12.5 = 1.12.5); - `sha256sum -c` and `/usr/local/bin/<tool>` strings the pin tests assert on are still present. ## Known remaining (settings-side, not fixable from workflow files) A run on this branch also reported **`Actor is not allowed to trigger Actions workflows`** (run 36295388349) — the repository's actor allow-list appears to glob `arena-ai-coding-agent[bot]` (the `[bot]` read as a character class), so pushes made by the Arena bot may still be refused even with compliant workflow files. An admin needs to fix that pattern; runs triggered by `hyperpolymath` should proceed once this merges. --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
) Follow-up to #85, which restored workflow startup. With CI alive again, the **Source lint** step (`config/ci/lint_source.jl`) produced its first verdict in two days and failed on two files it had never been able to run against — neither of them touched by #85: 1. **`test/doi/fixtures.jl`** uses the suite aliases `B`/`P`, which are `const` bindings defined in `tests.jl` before `include("fixtures.jl")`. The lint check is deliberately textual and per-file, so an alias supplied by the includer is invisible to it. The three call sites (`B.write_checksums!`, `P.prepare!`, `P.publish!`) now go through `Target.DOIBundles` / `Target.DOIPublications` — the same bindings at runtime (tests.jl defines them from `Target`), legible in isolation. 2. **`test/unit/test_zero_replacement.jl:215`** broadcast `Float64.(parse.(Float64, ...))` — the outer map is an identity (`parse` with a `Float64` target already yields `Float64`), and the `Float64.(` spelling matches the lint's `Module.member` pattern over test files. Removing the outer conversion changes no value. **Validation:** replayed the lint's textual checks (escaped interpolation, adjacent docstrings, bare-alias member refs, the `Float64.( pattern`) over both files — all clean. Julia itself isn't available in this sandbox, so the definitive gate is the CI Source lint step on this PR. **Known-red checks NOT addressed here** (pre-existing, not introduced by this change): repo-hygiene `tsc --noEmit` (frontend, likely #83-era), the stale apt-Agda 2.6.4.3 `Proofs (Agda)` job inside ci.yml (proofs.yml — the real gate — is green), and the DOI contracts job. Co-authored-by: arena-agent <arena-agent@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Summary - Make the KYAML drift list exempt paths from `--check` only. `use-kyaml` and `use-yaml` now still convert and roll back bot-owned workflow files, matching the pilot's stated scope. - Qualify the CLI's `KYAML.Stats` type and add CLI-level coverage for conversion, check exemption, and rollback. - Exercise all 17 tracked YAML files in the parser corpus. Compare emitted YAML/KYAML values with the production `YAML.jl` reader for application-consumed files; leave GitHub workflow acceptance to real Actions runs. - Correct the corpus count and add an upstream architecture / migration-risk audit. No source YAML files are reformatted and no application serializers or runtime behavior are changed. ## Review focus Please review the distinction between migration scope and canonicality-gate exemptions, and whether the semantic comparison boundary for GitHub workflow YAML is appropriate. The new audit maps upstream's defaults, mutable user overlays, generated files, serializer paths, and a staged adoption plan. ## Validation - `bash scripts/check-spdx.sh` — passed. - `bash scripts/check-format.sh` — passed. - `git diff --check` — passed. - Julia tests were **not run**: Julia is unavailable in this sandbox. - The PR's `CI` and `Proofs` workflows both ended in `startup_failure` with zero jobs ([CI](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36308344216), [Proofs](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36308344682)). These runs provide no test verdict. Please diagnose the workflow-start failure and obtain an actual passing CI run before merging; this PR is not being represented as green. Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
|
Thanks for pushing again. Every item below is a requirement for merge. 1. Rebase rather than mergingThis branch shares only one commit with Concretely:
Self-check before you push: I need 2. Please include in your PR
Everything not on this list stays on your fork. If you think something else belongs here, please open an issue first and ask. 3. Delete
|
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
#93) …… (#92) …-slice kit (#82) ## Summary Establishes the strategic, technical, and operational roadmap for transitioning contributions from the `hyperpolymath/MetaManifold-WebUI` fork back to upstream maintainer **Joshua Jewell** (`JoshuaJewell/MetaManifold-WebUI`), directly addressing his feedback on upstream PR #13. ### What this PR adds 1. **Maintainer Handoff Ultraplan** (`docs/migration/ULTRAPLAN-MAINTAINER-HANDOFF.md`): - **Retraction of PR #13**: Diagnosis of the 159 merge conflicts (merge base reverted to January root commit `06d85ba` after git-filter-repo dead-asset cleanup) and exact closure command + drafted comment for Joshua. - **Maintainer Profile**: Ground rules respecting veterinary science workflows, microbiome amplicon analysis priorities, and team bandwidth. - **8-Track Taxonomy**: Clear classification across Pipeline Fixes, Biological QC, Benchmarks, Statistics Cluster, Test Organization, React UI, Architectural Hard Calls, and Formal Evidence. - **'Free' vs 'Hard Decision' Trade-Off Matrix**: High-clarity breakdown showing what is safe/additive vs what requires architectural choice (YAML vs KYAML, Estate CI vs simple CI, React vs Stipple, exact math vs canonical R pipeline). - **R-Pipeline Protection & Dual-Track CI/CD**: Guarantees that canonical biological tools (`dada2`, `vegan`, `MASS::glm.nb`) remain the primary blocking ground truth. - **Phased PR Sequencing**: Atomic clean-branch roadmap re-anchored on `ecefb1c` (upstream `main`) with zero conflicts and zero Stipple/Vue dependencies. 2. **Automated Upstream Slicing Kit** (`scripts/prepare-upstream-slices.sh`): - Fetches `upstream/main` (`ecefb1c`). - Generates four atomic, conflict-free branches directly from `ecefb1c` in temporary worktrees: - `upstream-slice/01-qc-and-fixes` (FastQC/MultiQC in CI + 1x1 matrix & zero-depth fixes, 6 files) - `upstream-slice/02-benchmarks` (`bench/` suites, 16 files) - `upstream-slice/03-statistics-cluster` (real models, exact offsets, test renames, 16 files) - `upstream-slice/04-frontend-polish` (accessible dialogs, TS types, 13 files) - Excludes `ui/` and all Genie/Stipple dependencies completely. - Verifies zero merge conflicts against upstream `main`. ### Hygiene & Conformance - `scripts/check-spdx.sh`: OK (361 files covered). - `scripts/check-format.sh`: OK (465 files checked). <!-- SPDX-License-Identifier: CC-BY-SA-4.0 --> ## Summary <!-- What this PR does and why. Link issues with "Closes #N". --> ## Base check - [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`) ## Changes <!-- List the key changes. --> - ## Engineering checklist ### Required - [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests, benchmarks) - [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass (advisory in CI — does not block merge) - [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in CI) - [ ] New source files carry the correct SPDX header (`NOTICE` explains the authorship rule) - [ ] No secrets, credentials, `.env`, or sequencing data included - [ ] No application-logic changes hidden inside alignment/tooling PRs ### As applicable - [ ] `CHANGELOG.md` updated for user/developer-visible changes - [ ] `docs/types/architecture.md` updated if type boundaries moved - [ ] `docs/testing/coverage.md` updated if test coverage moved - [ ] New dependencies reviewed for licence compatibility - [ ] `docs/reproducibility.md` updated if environment requirements changed ## Testing <!-- How you verified these changes. Include `bun run check` output tail for engineering PRs. --> <!-- SPDX-License-Identifier: CC-BY-SA-4.0 --> ## Summary <!-- What this PR does and why. Link issues with "Closes #N". --> ## Base check - [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`) ## Changes <!-- List the key changes. --> - ## Engineering checklist ### Required - [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests, benchmarks) - [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass (advisory in CI — does not block merge) - [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in CI) - [ ] New source files carry the correct SPDX header (`NOTICE` explains the authorship rule) - [ ] No secrets, credentials, `.env`, or sequencing data included - [ ] No application-logic changes hidden inside alignment/tooling PRs ### As applicable - [ ] `CHANGELOG.md` updated for user/developer-visible changes - [ ] `docs/types/architecture.md` updated if type boundaries moved - [ ] `docs/testing/coverage.md` updated if test coverage moved - [ ] New dependencies reviewed for licence compatibility - [ ] `docs/reproducibility.md` updated if environment requirements changed ## Testing <!-- How you verified these changes. Include `bun run check` output tail for engineering PRs. --> Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Security and quality patch Updates the isolated DOI-contract test toolchain to patched releases for both open Dependabot alerts: - **ajv** `8.17.1` → `8.18.0`, patched for [GHSA-2g4f-4pwh-qvx6](GHSA-2g4f-4pwh-qvx6) (ReDoS when `$data` is enabled). - **yaml** `2.8.2` → `2.8.3`, patched for [GHSA-48c2-rrv3-qjmp](GHSA-48c2-rrv3-qjmp) (stack overflow on deeply nested collections). - Adds a Bun/npm `overrides.ajv` pin. A refreshed Bun lock initially retained `ajv@8.17.1` nested under `ajv-formats`; the override removes that still-vulnerable copy too. - Regenerates `test/doi/bun.lock` with the repository-pinned Bun 1.3.10. These are development-only dependencies of `test/doi`; this patch does not change the shipped frontend or main application bundle. ## Validation - `bun install --frozen-lockfile` — pass. - `bun run test` — 15 pass, 0 fail (121 assertions). - `bun audit --json` — `{}`; no advisories in the installed DOI-test dependency tree. The planned KYAML corpus migration is intentionally separate. This patch is independently reviewable and cherry-pickable; the migration requires the repository's pinned Julia-based converter and its equivalence/gate checks. Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary
<!-- What this PR does and why. Link issues with "Closes #N". -->
## Base check
- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)
## Changes
<!-- List the key changes. -->
-
## Engineering checklist
### Required
- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs
### As applicable
- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed
## Testing
<!-- How you verified these changes. Include `bun run check` output tail
for
engineering PRs. -->
---------
Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
No description provided.