From f4bbd9f414242a9ac2470edef9b6519b8070d859 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 22 Sep 2026 09:28:25 +0000 Subject: [PATCH] docs(audit): verify the project board now that the scope is available The Milestone 2 close-out recorded the project board as unverified: a user-level Projects v2 board needs the `project` scope, which the token in use at the time did not carry. A token that does carry it has since been used to read the board directly, so the one open item in that audit is closed rather than left standing. Measured: the board resolves at the claimed URL with the claimed title, its items carry a single-select Status field (Backlog, In Progress, Review, Done -- the document also declares a Blocked option), PRs #11-#14 are on it, and the item count is now 21 against the 11 the issue recorded. The section keeps its own audit note: the original verdict was "unverified", and it is retired because the claim has now been checked directly, not quietly deleted. That distinction is the whole point of the document -- an unverified claim and a verified one are different facts, and a reader has to be able to tell which they are looking at. Refs #15 --- docs/audit/milestone-2-close-out.md | 29 +++++++++++++++++++++-------- 1 file changed, 21 insertions(+), 8 deletions(-) diff --git a/docs/audit/milestone-2-close-out.md b/docs/audit/milestone-2-close-out.md index 6c045e9b..a2aa54b1 100644 --- a/docs/audit/milestone-2-close-out.md +++ b/docs/audit/milestone-2-close-out.md @@ -32,6 +32,7 @@ that has aged in the safe direction. | `ls bench/`, `ls frontend/bench/` | repository root | | `grep` over `ci.yml`, `README.md`, `bench/**`, `frontend/bench/baseline.json` | repository root | | `GET /actions/runs?branch=main&status=success` | GitHub API | +| `projectV2(number: 45)` over GraphQL, with the `project` scope | GitHub API | ## Claims, evidence, verdicts @@ -171,14 +172,26 @@ environment does. **Claimed:** https://github.com/users/hyperpolymath/projects/45 — "Analysis Layer & Cladistics Development", 11 items, PRs #11–#14 linked. -**Measured: not verifiable with the credentials available to this audit.** The board -is a user-level Projects v2 board; reading it needs the `read:project` scope, which is -granted per-token, and the token in use during this audit carries `repo` and -`workflow` only. - -**Verdict: unverified, and recorded as such rather than assumed.** Everything else on -this page was re-derived from the repository or the API. The link and the board's own -existence are the owner's to confirm; nothing in the codebase depends on it. +**Measured** (2026-09-22, once a token carrying the `project` scope was available): +the board resolves at that URL with the title "Analysis Layer & Cladistics +Development", and its items carry a single-select **Status** field whose values are +`Backlog`, `In Progress`, `Review` and `Done`. PRs #11, #12, #13 and #14 are present +on it. Items now total **21**, not 11. + +**Verdict: holds, with the item count grown.** Every part of the claim that was +checkable at the time of writing was accurate — the board, its title, the linked PRs, +and the Status field — and the item count has simply risen as work was added to the +board since the milestone document was written. The sections of the claim that could +not be checked then (the board's existence and link) are confirmed here rather than +assumed. + +> **Audit note.** The first version of this section recorded the board as +> *unverified*, because reading a user-level Projects v2 board requires the +> `read:project` scope and the credentials available to the audit did not carry it. +> It is recorded as verified above only because it has since been read directly and +> the raw output quoted. Where a claim cannot be checked, this document says so +> instead of inferring it; this is that note being retired rather than quietly +> dropped. ## Consequences