Skip to content

docs: stop presenting .machine_readable/6a2 as current state - #357

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/retire-6a2-refs
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/retire-6a2-refs

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

A2ML is retired estate-wide (D308). Five live pointers in this repo still describe .machine_readable/6a2/ as the canonical, current machine-readable state, and one of them is in the agent instructions (.claude/CLAUDE.md). This PR rewords them so that no live doc presents 6a2 as current. The success criterion: no live doc and no executed assertion presents 6a2 as current.

Changes

  • .claude/CLAUDE.md: the "canonical 6-file layout … in A2ML format" sentence is replaced. It now tells agents that A2ML is retired, that they must not create or edit .a2ml, and that descriptive metadata moves to the chora deed via kcX.
  • docs/README.adoc, docs/READINESS.adoc, docs/practice/TESTS-AND-BENCHES.adoc, docs/wikis/CI-and-Required-Checks.adoc: each 6a2 pointer now says "retired A2ML (D308), pending kcX → chora deed".

Left unchanged on purpose:

  • The 11 files under .machine_readable/6a2/ stay. Hand-converting them is out of scope: conversion is kcX's first front end (D313).
  • Dated history and planning docs (docs/governance/CRG-AUDIT-2026-04-18, docs/handover/*, docs/planning/*) are records of their date.
  • docs/AFFIRMATION.adoc already describes 6a2 as retired.
  • The site/catalog.json 007-mcp text describes another repo's paths.
  • Lockfile matches are binary false positives.
  • src/abi/Boj/CartridgeData.idr:234 is a doc comment in Idris source. Changing it needs the owner's OK for .idr edits, so it gets its own change.

Type of change

Documentation only.

📌 New pins

Head SHA: a386013. No action, lockfile or container pins are added or changed.

RSR Quality Checklist

Required

  • Tests pass: no code touched. CI runs the usual gates.
  • Code is formatted. Not applicable: AsciiDoc and Markdown prose only.
  • Linter is clean: no new warnings.
  • No banned language patterns.
  • No unsafe blocks. Not applicable.
  • No banned functions. Not applicable.
  • SPDX headers: unchanged on all five files.
  • No secrets.

As Applicable

  • .machine_readable/*. Not touched: A2ML is retired, and conversion is kcX's job (D313).
  • Documentation updated: that is the whole change.
  • New dependencies. Not applicable.
  • ABI/FFI. Not applicable.

Testing

git grep -n 6a2 -- docs/README.adoc docs/READINESS.adoc docs/practice/TESTS-AND-BENCHES.adoc docs/wikis/CI-and-Required-Checks.adoc .claude/CLAUDE.md: every remaining hit is now inside a "retired" statement. Each was read by eye after the edit.

Pre-existing red checks (deferred, not introduced here)

🤖 Generated with Claude Code

https://claude.ai/code/session_019j8She9eTFx54r6aL6sCHP

A2ML is retired (D308). Five live pointers still described the 6a2
files as the canonical, current machine-readable state. Reword them to say
the files are retired and read-only, pending kcX conversion into the chora
deed. The 6a2 files themselves and dated history docs are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019j8She9eTFx54r6aL6sCHP
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 7, 2026 11:36
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 33 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 01288a41-383e-4294-a60c-078b8d8e2a87
📥 Commits

Reviewing files that changed from the base of the PR and between e574569 and a386013.

📒 Files selected for processing (5)
  • .claude/CLAUDE.md
  • docs/READINESS.adoc
  • docs/README.adoc
  • docs/practice/TESTS-AND-BENCHES.adoc
  • docs/wikis/CI-and-Required-Checks.adoc
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 4d77913 into main Oct 7, 2026
56 of 58 checks passed
@hyperpolymath
hyperpolymath deleted the docs/retire-6a2-refs branch October 7, 2026 11:36
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 114 issues detected

Severity Count
🔴 Critical 10
🟠 High 20
🟡 Medium 84

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `sonarqube` in build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sonarqube"
  },
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "Job `deploy` in pages-deploy.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/pages-deploy.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.",
    "type": "secret_action_without_presence_gate",
    "file": ".github/workflows/instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_secret_presence_gate"
  },
  {
    "reason": "codeql.yml does not list `language: actions` in its matrix, but the repo has workflow files. CodeQL's `actions` language scans workflow YAML for injection and other CI/CD-specific weaknesses — every repo with workflows benefits. Add an entry to `matrix.include` with `language: actions` + `build-mode: none`.",
    "type": "codeql_missing_actions_language",
    "file": ".github/workflows/codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "fix_recipe": "add_codeql_actions_language"
  },
  {
    "line": 39,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 46,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 32,
    "reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/container-publish.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/container-publish.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant