From 47ee9d37fc103dd4e09fa27648ce517dabe5ebdb Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 14 Sep 2026 18:13:40 +0100 Subject: [PATCH 1/3] chore(ci): move the CodeQL scheduled scan to monthly Aligns this repo with the estate convention already landed on 10 of the 21 repos in this family: the scheduled CodeQL backstop runs monthly on the 1st at 06:00 UTC rather than every Monday, to reduce standing pressure on the shared account-wide Actions quota. PR-triggered analysis is unchanged and still runs on every pull request against main/master, so changed code is scanned exactly as before; only the backstop cadence for unchanged code moves. This is the one benign change carried by the fix/token-permissions-id-20260911 branch in this repo. It is landed here on a clean branch off main because that branch ALSO deletes guix.scm (71 lines, still live on main and last maintained on 2026-08-23 by "chore(guix): quality pass" #139). The deletion is unrelated to token permissions and is the sole cause of that PR's merge conflict, so the branch cannot be landed as-is. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_014QN8x5x4kNKY8EYCFsCmWB --- .github/workflows/codeql.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ff3d8a1..ef5a6ab 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -7,7 +7,7 @@ on: pull_request: branches: [main, master] schedule: - - cron: '0 6 * * 1' + - cron: '0 6 1 * *' # monthly 1st 06:00 UTC # Estate guardrail: cancel superseded runs so re-pushes / rebased PR # updates do not pile up queued runs against the shared account-wide From 7713271517c8e961c442f86c0cc83ea977fd9491 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Tue, 15 Sep 2026 00:03:51 +0100 Subject: [PATCH 2/3] Relocate descriptiles and complete the K9 deploy pedigree (#73) Moves A2ML descriptiles from `.machine_readable/6a2` to `.machine_readable/descriptiles` and updates topology references. Adds the K9 marker and required Hunt-level pedigree fields to the deployment component to address CI gate failures. Validation was not run. [View coding task](https://app.coderabbit.ai/code/tasks/5ad5d090-5353-42d6-9a26-650af678ebec?source=coding_agent_github_pr_description) Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --- .machine_readable/{6a2 => descriptiles}/AGENTIC.a2ml | 0 .machine_readable/{6a2 => descriptiles}/ECOSYSTEM.a2ml | 0 .machine_readable/{6a2 => descriptiles}/META.a2ml | 0 .machine_readable/{6a2 => descriptiles}/NEUROSYM.a2ml | 0 .machine_readable/{6a2 => descriptiles}/PLAYBOOK.a2ml | 0 .machine_readable/{6a2 => descriptiles}/STATE.a2ml | 0 TOPOLOGY.adoc | 6 +++--- container/deploy.k9.ncl | 8 +++++++- 8 files changed, 10 insertions(+), 4 deletions(-) rename .machine_readable/{6a2 => descriptiles}/AGENTIC.a2ml (100%) rename .machine_readable/{6a2 => descriptiles}/ECOSYSTEM.a2ml (100%) rename .machine_readable/{6a2 => descriptiles}/META.a2ml (100%) rename .machine_readable/{6a2 => descriptiles}/NEUROSYM.a2ml (100%) rename .machine_readable/{6a2 => descriptiles}/PLAYBOOK.a2ml (100%) rename .machine_readable/{6a2 => descriptiles}/STATE.a2ml (100%) diff --git a/.machine_readable/6a2/AGENTIC.a2ml b/.machine_readable/descriptiles/AGENTIC.a2ml similarity index 100% rename from .machine_readable/6a2/AGENTIC.a2ml rename to .machine_readable/descriptiles/AGENTIC.a2ml diff --git a/.machine_readable/6a2/ECOSYSTEM.a2ml b/.machine_readable/descriptiles/ECOSYSTEM.a2ml similarity index 100% rename from .machine_readable/6a2/ECOSYSTEM.a2ml rename to .machine_readable/descriptiles/ECOSYSTEM.a2ml diff --git a/.machine_readable/6a2/META.a2ml b/.machine_readable/descriptiles/META.a2ml similarity index 100% rename from .machine_readable/6a2/META.a2ml rename to .machine_readable/descriptiles/META.a2ml diff --git a/.machine_readable/6a2/NEUROSYM.a2ml b/.machine_readable/descriptiles/NEUROSYM.a2ml similarity index 100% rename from .machine_readable/6a2/NEUROSYM.a2ml rename to .machine_readable/descriptiles/NEUROSYM.a2ml diff --git a/.machine_readable/6a2/PLAYBOOK.a2ml b/.machine_readable/descriptiles/PLAYBOOK.a2ml similarity index 100% rename from .machine_readable/6a2/PLAYBOOK.a2ml rename to .machine_readable/descriptiles/PLAYBOOK.a2ml diff --git a/.machine_readable/6a2/STATE.a2ml b/.machine_readable/descriptiles/STATE.a2ml similarity index 100% rename from .machine_readable/6a2/STATE.a2ml rename to .machine_readable/descriptiles/STATE.a2ml diff --git a/TOPOLOGY.adoc b/TOPOLOGY.adoc index d9cbfd0..7c80145 100644 --- a/TOPOLOGY.adoc +++ b/TOPOLOGY.adoc @@ -156,13 +156,13 @@ All machine-readable metadata lives here (never in root). [width="100%",cols="40%,60%",options="header",] |=== |Path |Purpose -|`+.machine_readable/6a2/STATE.a2ml+` |Project state: scaffold phase, 5% +|`+.machine_readable/descriptiles/STATE.a2ml+` |Project state: scaffold phase, 5% complete -|`+.machine_readable/6a2/META.a2ml+` |Architecture decisions: +|`+.machine_readable/descriptiles/META.a2ml+` |Architecture decisions: iser-pattern, ABI-FFI standard, RSR template -|`+.machine_readable/6a2/ECOSYSTEM.a2ml+` |Ecosystem position: -iser +|`+.machine_readable/descriptiles/ECOSYSTEM.a2ml+` |Ecosystem position: -iser family, siblings (typedqliser, chapeliser, verisimiser) |`+.machine_readable/CLADE.a2ml+` |Clade taxonomy classification diff --git a/container/deploy.k9.ncl b/container/deploy.k9.ncl index 0ad0d04..ce61fc6 100644 --- a/container/deploy.k9.ncl +++ b/container/deploy.k9.ncl @@ -1,3 +1,4 @@ +K9! # SPDX-License-Identifier: MPL-2.0 # deploy.k9.ncl — {{PROJECT_NAME}} deployment component (Hunt level) # @@ -143,7 +144,12 @@ echo "K9: Rollback complete." # Export the component { - pedigree = component_pedigree, + pedigree = component_pedigree & { + name = "{{SERVICE_NAME}}-deploy", + version = "{{VERSION}}", + leash = 'Hunt, + signature = "PLACEHOLDER-SIGNATURE-REQUIRED-FOR-HUNT", + }, deployment = deployment, scripts = scripts, From 160688ef71b974d07665a05855b492c7d5eef1b1 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Mon, 14 Sep 2026 23:13:41 +0000 Subject: [PATCH 3/3] docs(container): strip K9 marker before Nickel typecheck --- container/README.adoc | 4 ++-- container/deploy.k9.ncl | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/container/README.adoc b/container/README.adoc index 7a2ef6c..546e6b5 100644 --- a/container/README.adoc +++ b/container/README.adoc @@ -154,8 +154,8 @@ For k9-svc managed deployments: [source,bash] ---- -# Validate the deployment component -nickel typecheck container/deploy.k9.ncl +# Validate the deployment component (strip its required K9! marker first) +nickel typecheck <(tail -n +2 container/deploy.k9.ncl) # Deploy (requires Hunt-level authorisation) k9-svc deploy container/deploy.k9.ncl --env production diff --git a/container/deploy.k9.ncl b/container/deploy.k9.ncl index ce61fc6..5f950c8 100644 --- a/container/deploy.k9.ncl +++ b/container/deploy.k9.ncl @@ -9,7 +9,7 @@ K9! # It requires explicit authorisation via the Leash system. # # Usage: -# nickel typecheck container/deploy.k9.ncl +# nickel typecheck <(tail -n +2 container/deploy.k9.ncl) # k9-svc validate container/deploy.k9.ncl # k9-svc deploy container/deploy.k9.ncl --env production