Skip to content

Commit 73d16b9

Browse files
Merge branch 'main' into fix/ci-426-batch15
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
2 parents 2ba5c24 + 0441afc commit 73d16b9

10 files changed

Lines changed: 259 additions & 76 deletions

File tree

‎.github/workflows/codeql.yml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,10 @@ jobs:
3030
fail-fast: false
3131
matrix:
3232
include:
33-
- language: javascript-typescript
33+
- language: actions
34+
build-mode: none
35+
- language: rust
3436
build-mode: none
35-
3637
steps:
3738
- name: Checkout
3839
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -258,26 +258,26 @@ jobs:
258258
259259
# Validate TOML structure using Python 3.11+ tomllib
260260
python3 -c "
261-
import tomllib, sys
262-
with open('eclexiaiser.toml', 'rb') as f:
263-
data = tomllib.load(f)
264-
project = data.get('project', {})
265-
if not project.get('name', '').strip():
266-
print('ERROR: project.name is required', file=sys.stderr)
267-
sys.exit(1)
268-
functions = data.get('functions', [])
269-
if not functions:
270-
print('ERROR: at least one [[functions]] entry is required', file=sys.stderr)
271-
sys.exit(1)
272-
for fn in functions:
273-
if not fn.get('name', '').strip():
274-
print('ERROR: function name cannot be empty', file=sys.stderr)
275-
sys.exit(1)
276-
if not fn.get('source', '').strip():
277-
print(f'ERROR: function {fn[\"name\"]} has no source path', file=sys.stderr)
278-
sys.exit(1)
279-
print(f'Valid: {project[\"name\"]} ({len(functions)} function(s))')
280-
" || {
261+
import tomllib, sys
262+
with open('eclexiaiser.toml', 'rb') as f:
263+
data = tomllib.load(f)
264+
project = data.get('project', {})
265+
if not project.get('name', '').strip():
266+
print('ERROR: project.name is required', file=sys.stderr)
267+
sys.exit(1)
268+
functions = data.get('functions', [])
269+
if not functions:
270+
print('ERROR: at least one [[functions]] entry is required', file=sys.stderr)
271+
sys.exit(1)
272+
for fn in functions:
273+
if not fn.get('name', '').strip():
274+
print('ERROR: function name cannot be empty', file=sys.stderr)
275+
sys.exit(1)
276+
if not fn.get('source', '').strip():
277+
print(f'ERROR: function {fn[\"name\"]} has no source path', file=sys.stderr)
278+
sys.exit(1)
279+
print(f'Valid: {project[\"name\"]} ({len(functions)} function(s))')
280+
" || {
281281
echo "::error file=eclexiaiser.toml::Invalid eclexiaiser.toml — see step output for details"
282282
exit 1
283283
}

‎.github/workflows/scorecard.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ on:
55
branch_protection_rule:
66
schedule:
77
- cron: '23 4 * * 1'
8-
push:
9-
branches: [main]
108

119
permissions: read-all
1210

‎.github/workflows/secret-scanner.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,5 @@ jobs:
1717
scan:
1818
permissions:
1919
contents: read
20-
pull-requests: write
21-
actions: read
2220
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
2321
secrets: inherit

‎0-AI-MANIFEST.a2ml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,3 +47,20 @@ cloudguard dns list|add|delete|bulk-add
4747
cloudguard zones list|status
4848
cloudguard pages list
4949
```
50+
51+
<!-- BEGIN requires-initialisation -->
52+
53+
## PRIORITY ACTION — this repository is not fully initialised
54+
55+
22 substitution token(s) still have no value. **Read
56+
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
57+
else here** — it lists every outstanding token, what it means, and which
58+
files it belongs in.
59+
60+
Do not fabricate values for them, and do not delete the sections that
61+
contain them to quiet a gate. They are unfilled because they need a
62+
decision, not because they were overlooked. Resolve what you legitimately
63+
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when
64+
nothing outstanding remains.
65+
66+
<!-- END requires-initialisation -->

‎ARCHITECTURE.md‎

Lines changed: 0 additions & 47 deletions
This file was deleted.

‎PLACEHOLDERS.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@ sed -i "s/2026-03-02/$(date +%Y-%m-%d)/g" $(grep -rl '2026-03-02' .)
7171
| `[PGP fingerprint not set]` | 40-char PGP fingerprint | `ABCD 1234 ...` | SECURITY.md |
7272
| `{{PGP_KEY_URL}}` | URL to public PGP key | `https://keys.openpgp.org/...` | SECURITY.md |
7373
| `{{WEBSITE}}` | Project website | `https://example.org` | SECURITY.md |
74-
| `{{CONDUCT_EMAIL}}` | Conduct reports email | `conduct@example.org` | CODE_OF_CONDUCT.md |
74+
| `j.d.a.jewell@open.ac.uk` | Conduct reports email | `conduct@example.org` | CODE_OF_CONDUCT.md |
7575
| `{{CONDUCT_TEAM}}` | Conduct committee name | `Code of Conduct Committee` | CODE_OF_CONDUCT.md |
7676
| `{{RESPONSE_TIME}}` | SLA for initial response | `48 hours` | CODE_OF_CONDUCT.md |
7777

‎REQUIRES_INITIALISATION.md‎

Lines changed: 216 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,216 @@
1+
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
2+
3+
# REQUIRES INITIALISATION
4+
5+
**This repository is not finished being set up.** 22 substitution token(s) across 9 file(s) still have no value.
6+
7+
## Why this is not already done
8+
9+
This repo was created from `hyperpolymath/rsr-template-repo`. The mint
10+
(`just repo-init`) fills every token that has a single mechanical answer —
11+
owner, repo, author, dates, licence, branch — and it has done so here.
12+
13+
The tokens below are the ones it *deliberately cannot* answer. They need a
14+
decision or a fact that exists only in your head: what this project is for,
15+
what command builds it, which port the service listens on, whether a PGP key
16+
is held at all. The template's own token vocabulary says as much — you cannot
17+
sensibly answer "required invariants" in a thirty-second bootstrap.
18+
19+
They were left **visibly unfilled on purpose**. The alternatives were both
20+
worse: inventing plausible values would put confident falsehoods into a
21+
security policy and an architecture document, and silently deleting the
22+
sections would hide the fact that a decision is owed. A visible gap is
23+
honest; a fabricated answer is not.
24+
25+
## Do not delete this file until every item below is resolved
26+
27+
This file is the only marker that the work is outstanding. Deleting it early
28+
does not finish the setup, it just conceals it — and the next person or agent
29+
to arrive will reasonably assume the repo is complete.
30+
31+
- **If you are a person:** delete this file yourself once the last item is done.
32+
- **If you are an agent:** resolve what you legitimately can, leave the rest,
33+
and delete this file only when no token below remains anywhere in the tree.
34+
Do not delete it to make a gate go green.
35+
36+
Re-running the estate top-up tool will remove this file automatically once
37+
nothing is outstanding, so the safest way to finish is to fix the tokens and
38+
let the check confirm it.
39+
40+
## What is needed, and where it goes
41+
42+
### `{{AUTHOR_ORG}}`
43+
44+
Author's organisation. NOTE: no filled instance of this exists anywhere in the estate — consider deleting the field instead.
45+
46+
Appears in:
47+
48+
- `.machine_readable/svc/k9/examples/project-metadata.k9.ncl`
49+
- `PLACEHOLDERS.md`
50+
51+
### `{{CONDUCT_TEAM}}`
52+
53+
Name of the conduct body. If there is no committee, rewrite the sentence rather than substituting a plural noun into 'a {{CONDUCT_TEAM}} member'.
54+
55+
Appears in:
56+
57+
- `PLACEHOLDERS.md`
58+
59+
### `{{CONSUMER1}}`
60+
61+
A downstream repo that consumes this one.
62+
63+
Appears in:
64+
65+
- `.machine_readable/INTENT.contractile`
66+
67+
### `{{CONSUMER2}}`
68+
69+
A second downstream consumer.
70+
71+
Appears in:
72+
73+
- `.machine_readable/INTENT.contractile`
74+
75+
### `{{DEP1}}`
76+
77+
First named dependency, in .machine_readable/INTENT.contractile.
78+
79+
Appears in:
80+
81+
- `.machine_readable/INTENT.contractile`
82+
83+
### `{{DEP2}}`
84+
85+
Second named dependency, in .machine_readable/INTENT.contractile.
86+
87+
Appears in:
88+
89+
- `.machine_readable/INTENT.contractile`
90+
91+
### `{{DOMAIN}}`
92+
93+
Appears in:
94+
95+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
96+
97+
### `{{DS_RECORD}}`
98+
99+
Appears in:
100+
101+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
102+
103+
### `{{KEY_TAG}}`
104+
105+
Appears in:
106+
107+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
108+
109+
### `{{LICENSE}}`
110+
111+
SPDX identifier for this repo's licence.
112+
113+
Appears in:
114+
115+
- `container/Containerfile`
116+
- `container/manifest.toml`
117+
118+
### `{{MONOREPO_OR_STANDALONE}}`
119+
120+
Literally 'monorepo' or 'standalone'.
121+
122+
Appears in:
123+
124+
- `.machine_readable/INTENT.contractile`
125+
126+
### `{{MTA_STS_ID}}`
127+
128+
Appears in:
129+
130+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
131+
132+
### `{{ONE_PARAGRAPH_ANTI_PURPOSE}}`
133+
134+
A paragraph on what this deliberately is NOT for.
135+
136+
Appears in:
137+
138+
- `.machine_readable/INTENT.contractile`
139+
140+
### `{{ONE_PARAGRAPH_PURPOSE}}`
141+
142+
A paragraph on what this is for.
143+
144+
Appears in:
145+
146+
- `.machine_readable/INTENT.contractile`
147+
148+
### `{{PGP_KEY_URL}}`
149+
150+
Public URL the PGP key can be fetched from. Same caveat as PGP_FINGERPRINT.
151+
152+
Appears in:
153+
154+
- `PLACEHOLDERS.md`
155+
156+
### `{{PROJECT_DOMAIN}}`
157+
158+
Taxonomy value for the subject domain.
159+
160+
Appears in:
161+
162+
- `.machine_readable/anchors/ANCHOR.a2ml`
163+
164+
### `{{PROJECT_KIND}}`
165+
166+
Taxonomy value (library, service, tool, lab…).
167+
168+
Appears in:
169+
170+
- `.machine_readable/anchors/ANCHOR.a2ml`
171+
172+
### `{{PROJECT_PURPOSE}}`
173+
174+
One line: what this exists to do.
175+
176+
Appears in:
177+
178+
- `.machine_readable/anchors/ANCHOR.a2ml`
179+
- `PLACEHOLDERS.md`
180+
- `guix.scm`
181+
182+
### `{{PROJECT_UNIQUE_STRENGTH}}`
183+
184+
What this does that its alternatives do not.
185+
186+
Appears in:
187+
188+
- `.machine_readable/agent_instructions/methodology.a2ml`
189+
190+
### `{{RESPONSE_TIME}}`
191+
192+
Initial-response SLA for a security or conduct report. Promise only what a solo maintainer can actually meet.
193+
194+
Appears in:
195+
196+
- `PLACEHOLDERS.md`
197+
198+
### `{{SECURITY_TXT_EXPIRES}}`
199+
200+
Appears in:
201+
202+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
203+
204+
### `{{WEBSITE}}`
205+
206+
Project homepage URL, or delete the field if there is none.
207+
208+
Appears in:
209+
210+
- `PLACEHOLDERS.md`
211+
212+
---
213+
214+
Generated by the estate top-up pass. Rationale and the governing rulings are
215+
in `hyperpolymath/standards`; the token vocabulary is
216+
`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.

‎container/manifest.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ tracking.
1717
"""
1818
license = "{{LICENSE}}"
1919
homepage = "https://github.com/hyperpolymath/cloudguard-cli"
20-
maintainer = "Jonathan D.A. Jewell <{{EMAIL}}>"
20+
maintainer = "Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>"
2121

2222
[provenance]
2323
upstream = "https://github.com/hyperpolymath/cloudguard-cli"

‎container/vordr.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ output = "stdout"
9494
# on = ["failure", "recovery", "resource_critical"]
9595

9696
# [notifications.email]
97-
# to = "{{EMAIL}}"
97+
# to = "j.d.a.jewell@open.ac.uk"
9898
# from = "vordr@cloudguard-cli.local"
9999
# smtp = "smtp://localhost:25"
100100
# on = ["failure", "resource_critical"]

0 commit comments

Comments
 (0)