Skip to content

Arena/01a0db23 metamanifold webui - #13

Draft
hyperpolymath wants to merge 265 commits into
JoshuaJewell:mainfrom
hyperpolymath:arena/01a0db23-metamanifold-webui
Draft

hyperpolymath wants to merge 265 commits into
JoshuaJewell:mainfrom
hyperpolymath:arena/01a0db23-metamanifold-webui

Conversation

@hyperpolymath

Copy link
Copy Markdown

No description provided.

…nd working cutadapt -> vsearch-dada merge on default settings.
… of previously run stages. Created a versatile project structure.
….it was getting messy and altogether not worth it for now.
arena-ai-coding-agent Bot and others added 7 commits September 27, 2026 06:20
…venance probe visibility) (#85)

## Why

Every workflow run on this repository since **2026-09-25 22:19 UTC** has
failed with `startup_failure` and **zero jobs** — CI has produced no
verdict on anything since (the refreshed audit in
`docs/audit/2026-09-26-memory-numerics-warning-audit.md` records the
same observation). The run annotations name the cause; two rules,
neither reportable by a job that never starts:

> The actions `julia-actions/setup-julia@…`, `julia-actions/cache@…`,
and `julia-actions/julia-processcoverage@…` are **not allowed** in
hyperpolymath/MetaManifold-WebUI because all actions must be from a
repository owned by hyperpolymath, created by GitHub, verified in the
GitHub Marketplace, or match the pattern: `arena-ai-coding-agent[bot]`.
**All actions must also be pinned to a full-length commit SHA.**

- `ci.yml`, `ui.yml`, `doi.yml` used the three disallowed
`julia-actions/*` actions;
- `proofs.yml` used tag refs (`@v4`/`@v5`) instead of full SHAs (its
annotation from run 36293672919).

Dependabot PR #68 (merged 2026-09-25 22:26) was **not** the cause — it
only changed which ref each disallowed action used; the enforcement
itself turned on at 22:19 and broke the arena-branch run five minutes
before #68 merged.

## What changed (behaviour preserved)

| workflow | was | now |
|---|---|---|
| ci/ui/doi | `julia-actions/setup-julia` | inline install of official
1.12.5 binaries, **verified against the official checksum file** before
use; `JULIA_VERSION` keeps the pin cross-checked by `test_install_pins`
|
| ci/ui/doi | `julia-actions/cache` | `actions/cache@55cc834` (v6.1.0)
over the same depot dirs, keyed on each workflow's own Manifest/Project
|
| ci | `julia-actions/julia-processcoverage` | equivalent
`CoverageTools` run step (same default dirs, same `lcov.info`) |
| proofs | `checkout/setup-python/cache/upload-artifact@v4/@v5` | same
tags' **commits** — no version change |

Plus **two guards** so this cannot regress silently:

- `test/unit/test_install_pins.jl` now locates the Julia pin by step
name (`JULIA_VERSION=` in `Set up Julia`) and gains a new testset that
walks **every workflow** and fails on any action that is not
full-SHA-pinned or not allow-listed — a future dependabot bump to a tag
reddens `Pkg.test` instead of silencing Actions;
- the provenance probe fallbacks in `src/analysis/Execution.jl` (the
second commit) now `@warn` before writing
`version=unknown`/`hostname=unknown` placeholders — the manifest schema
and all existing assertions over it are untouched.

## Validation done offline

- YAML parse + duplicate-key scan of all four workflows;
- policy self-check mirroring the new testset (every `uses:` full-SHA +
allow-listed owner);
- `bash -n` on **every** `run:` block;
- `JULIA_VERSION` regex against `config/defaults/tool_versions.yml`
(1.12.5 = 1.12.5);
- `sha256sum -c` and `/usr/local/bin/<tool>` strings the pin tests
assert on are still present.

## Known remaining (settings-side, not fixable from workflow files)

A run on this branch also reported **`Actor is not allowed to trigger
Actions workflows`** (run 36295388349) — the repository's actor
allow-list appears to glob `arena-ai-coding-agent[bot]` (the `[bot]`
read as a character class), so pushes made by the Arena bot may still be
refused even with compliant workflow files. An admin needs to fix that
pattern; runs triggered by `hyperpolymath` should proceed once this
merges.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
)

Follow-up to #85, which restored workflow startup. With CI alive again,
the **Source lint** step (`config/ci/lint_source.jl`) produced its first
verdict in two days and failed on two files it had never been able to
run against — neither of them touched by #85:

1. **`test/doi/fixtures.jl`** uses the suite aliases `B`/`P`, which are
`const` bindings defined in `tests.jl` before `include("fixtures.jl")`.
The lint check is deliberately textual and per-file, so an alias
supplied by the includer is invisible to it. The three call sites
(`B.write_checksums!`, `P.prepare!`, `P.publish!`) now go through
`Target.DOIBundles` / `Target.DOIPublications` — the same bindings at
runtime (tests.jl defines them from `Target`), legible in isolation.

2. **`test/unit/test_zero_replacement.jl:215`** broadcast
`Float64.(parse.(Float64, ...))` — the outer map is an identity (`parse`
with a `Float64` target already yields `Float64`), and the `Float64.(`
spelling matches the lint's `Module.member` pattern over test files.
Removing the outer conversion changes no value.

**Validation:** replayed the lint's textual checks (escaped
interpolation, adjacent docstrings, bare-alias member refs, the
`Float64.( pattern`) over both files — all clean. Julia itself isn't
available in this sandbox, so the definitive gate is the CI Source lint
step on this PR.

**Known-red checks NOT addressed here** (pre-existing, not introduced by
this change): repo-hygiene `tsc --noEmit` (frontend, likely #83-era),
the stale apt-Agda 2.6.4.3 `Proofs (Agda)` job inside ci.yml (proofs.yml
— the real gate — is green), and the DOI contracts job.

Co-authored-by: arena-agent <arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Summary

- Make the KYAML drift list exempt paths from `--check` only.
`use-kyaml` and `use-yaml` now still convert and roll back bot-owned
workflow files, matching the pilot's stated scope.
- Qualify the CLI's `KYAML.Stats` type and add CLI-level coverage for
conversion, check exemption, and rollback.
- Exercise all 17 tracked YAML files in the parser corpus. Compare
emitted YAML/KYAML values with the production `YAML.jl` reader for
application-consumed files; leave GitHub workflow acceptance to real
Actions runs.
- Correct the corpus count and add an upstream architecture /
migration-risk audit. No source YAML files are reformatted and no
application serializers or runtime behavior are changed.

## Review focus

Please review the distinction between migration scope and
canonicality-gate exemptions, and whether the semantic comparison
boundary for GitHub workflow YAML is appropriate. The new audit maps
upstream's defaults, mutable user overlays, generated files, serializer
paths, and a staged adoption plan.

## Validation

- `bash scripts/check-spdx.sh` — passed.
- `bash scripts/check-format.sh` — passed.
- `git diff --check` — passed.
- Julia tests were **not run**: Julia is unavailable in this sandbox.
- The PR's `CI` and `Proofs` workflows both ended in `startup_failure`
with zero jobs
([CI](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36308344216),
[Proofs](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36308344682)).
These runs provide no test verdict. Please diagnose the workflow-start
failure and obtain an actual passing CI run before merging; this PR is
not being represented as green.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@JoshuaJewell

JoshuaJewell commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Thanks for pushing again. Every item below is a requirement for merge.

1. Rebase rather than merging

This branch shares only one commit with main; the initial commit. compare main...<head> currently reports behind_by: 89 with merge_base: 7884553. Because that merge base contains two files, roughly 159 paths are add/add conflicts. An automated "resolution" does not resolve anything: it folds my 89 commits into your 244 and produces a tree nobody has reviewed. That is what the last push looks like.

Concretely:

  • create the branch from ecefb1c72b3d2515e7086024b14227ef13329605 (current main);
  • re-apply your work on top of it as your own commits;
  • no merge commits from main into the branch.

Self-check before you push:

gh api repos/JoshuaJewell/MetaManifold-WebUI/compare/main...<head-sha> \
  --jq '{behind_by, merge_base: .merge_base_commit.sha}'

I need behind_by: 0 and merge_base equal to ecefb1c72b3d2515e7086024b14227ef13329605. The PR must also report mergeable: MERGEABLE. If your work cannot be re-applied on top of current main, it is not ready to send.

2. Please include in your PR

Everything not on this list stays on your fork. If you think something else belongs here, please open an issue first and ask.

3. Delete ui/ and all of Genie

ui/Project.toml still depends on Genie 6, Stipple 1 and StippleUI 1, and all eleven files under ui/ are still in the diff. The HTTP layer already here is Oxygen.jl in Project.toml:15 and src/server/server.jl:16. Remove the directory and every reference to it.

4. Leave the licence metadata alone

Do not touch LICENSE, CITATION.cff, the licence and acknowledgement sections of README.md, or the headers on files you did not write. Do not add a NOTICE, and do not add a LICENSES/ directory. A NOTICE that restates how this project classifies its files is writing policy for a repository that is not yours.

For your own new files: you may keep them MPL-2.0 if that is what you want. That is your call, and ensuring they are compatible with the AGPL-3.0 surrounding them is your responsibility. Mark them per file with an SPDX identifier. Prose you author is CC-BY-SA-4.0, which is what README.md already states for documentation.

If you want to be credited in CITATION.cff, ask for it explicitly in the PR description and we will discuss it. It is not something to resolve by editing the file inside a PR.

5. CI must run and pass on the PR

The branch hasn't got a single workflow run. A PR with no CI will not be reviewed.

6. The description must exist

What it does, which issues it closes, how to run the tests, and the Julia, R and bun versions you tested against. The PR body is currently empty.

What happens next

Meet all six and I will review it properly, including real feedback on the statistics work, which is the part we actually want.

hyperpolymath and others added 18 commits September 28, 2026 21:33
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
#93)

…… (#92)

…-slice kit (#82)

## Summary

Establishes the strategic, technical, and operational roadmap for
transitioning contributions from the `hyperpolymath/MetaManifold-WebUI`
fork back to upstream maintainer **Joshua Jewell**
(`JoshuaJewell/MetaManifold-WebUI`), directly addressing his feedback on
upstream PR #13.

### What this PR adds

1. **Maintainer Handoff Ultraplan**
(`docs/migration/ULTRAPLAN-MAINTAINER-HANDOFF.md`):
- **Retraction of PR #13**: Diagnosis of the 159 merge conflicts (merge
base reverted to January root commit `06d85ba` after git-filter-repo
dead-asset cleanup) and exact closure command + drafted comment for
Joshua.
- **Maintainer Profile**: Ground rules respecting veterinary science
workflows, microbiome amplicon analysis priorities, and team bandwidth.
- **8-Track Taxonomy**: Clear classification across Pipeline Fixes,
Biological QC, Benchmarks, Statistics Cluster, Test Organization, React
UI, Architectural Hard Calls, and Formal Evidence.
- **'Free' vs 'Hard Decision' Trade-Off Matrix**: High-clarity breakdown
showing what is safe/additive vs what requires architectural choice
(YAML vs KYAML, Estate CI vs simple CI, React vs Stipple, exact math vs
canonical R pipeline).
- **R-Pipeline Protection & Dual-Track CI/CD**: Guarantees that
canonical biological tools (`dada2`, `vegan`, `MASS::glm.nb`) remain the
primary blocking ground truth.
- **Phased PR Sequencing**: Atomic clean-branch roadmap re-anchored on
`ecefb1c` (upstream `main`) with zero conflicts and zero Stipple/Vue
dependencies.

2. **Automated Upstream Slicing Kit**
(`scripts/prepare-upstream-slices.sh`):
   - Fetches `upstream/main` (`ecefb1c`).
- Generates four atomic, conflict-free branches directly from `ecefb1c`
in temporary worktrees:
- `upstream-slice/01-qc-and-fixes` (FastQC/MultiQC in CI + 1x1 matrix &
zero-depth fixes, 6 files)
     - `upstream-slice/02-benchmarks` (`bench/` suites, 16 files)
- `upstream-slice/03-statistics-cluster` (real models, exact offsets,
test renames, 16 files)
- `upstream-slice/04-frontend-polish` (accessible dialogs, TS types, 13
files)
   - Excludes `ui/` and all Genie/Stipple dependencies completely.
   - Verifies zero merge conflicts against upstream `main`.

### Hygiene & Conformance

- `scripts/check-spdx.sh`: OK (361 files covered).
- `scripts/check-format.sh`: OK (465 files checked).

<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
(advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Security and quality patch

Updates the isolated DOI-contract test toolchain to patched releases for
both open Dependabot alerts:

- **ajv** `8.17.1` → `8.18.0`, patched for
[GHSA-2g4f-4pwh-qvx6](GHSA-2g4f-4pwh-qvx6)
(ReDoS when `$data` is enabled).
- **yaml** `2.8.2` → `2.8.3`, patched for
[GHSA-48c2-rrv3-qjmp](GHSA-48c2-rrv3-qjmp)
(stack overflow on deeply nested collections).
- Adds a Bun/npm `overrides.ajv` pin. A refreshed Bun lock initially
retained `ajv@8.17.1` nested under `ajv-formats`; the override removes
that still-vulnerable copy too.
- Regenerates `test/doi/bun.lock` with the repository-pinned Bun 1.3.10.

These are development-only dependencies of `test/doi`; this patch does
not change the shipped frontend or main application bundle.

## Validation

- `bun install --frozen-lockfile` — pass.
- `bun run test` — 15 pass, 0 fail (121 assertions).
- `bun audit --json` — `{}`; no advisories in the installed DOI-test
dependency tree.

The planned KYAML corpus migration is intentionally separate. This patch
is independently reviewable and cherry-pickable; the migration requires
the repository's pinned Julia-based converter and its equivalence/gate
checks.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

<!-- What this PR does and why. Link issues with "Closes #N". -->

## Base check

- [ ] Base is `hyperpolymath/MetaManifold-WebUI:main` (not the upstream
parent; application changes go to `JoshuaJewell/MetaManifold-WebUI`)

## Changes

<!-- List the key changes. -->

-

## Engineering checklist

### Required

- [ ] `bun run check` passes (`frontend/`: typecheck 0 errors, tests,
      benchmarks)
- [ ] `scripts/check-spdx.sh` / `check-format.sh` / `check-lint.sh` pass
      (advisory in CI — does not block merge)
- [ ] Conventional commit subjects (see `CONTRIBUTING.md`; advisory in
CI)
- [ ] New source files carry the correct SPDX header (`NOTICE` explains
      the authorship rule)
- [ ] No secrets, credentials, `.env`, or sequencing data included
- [ ] No application-logic changes hidden inside alignment/tooling PRs

### As applicable

- [ ] `CHANGELOG.md` updated for user/developer-visible changes
- [ ] `docs/types/architecture.md` updated if type boundaries moved
- [ ] `docs/testing/coverage.md` updated if test coverage moved
- [ ] New dependencies reviewed for licence compatibility
- [ ] `docs/reproducibility.md` updated if environment requirements
changed

## Testing

<!-- How you verified these changes. Include `bun run check` output tail
for
     engineering PRs. -->

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@hyperpolymath
hyperpolymath marked this pull request as draft September 29, 2026 00:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants