Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 2 additions & 13 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,11 +68,7 @@
echo "Expected one of: mix.exs, Cargo.toml, build.zig, deno.json, gossamer.conf.json, gleam.toml, rebar.config, Justfile"
exit 1
fi
# TODO: Upload build artifacts if needed
# - uses: actions/upload-artifact@v4
# with:
# name: release-artifacts
# path: target/release/
# Library: no release binary to upload (Zig FFI is not a tagged product).
changelog:
name: Generate Changelog
runs-on: ubuntu-latest
Expand Down Expand Up @@ -122,23 +118,16 @@
contents: write
steps:
- uses: actions/checkout@v7.0.1
# TODO: Download build artifacts if uploading to the release
# - uses: actions/download-artifact@v4
# with:
# name: release-artifacts
# path: artifacts/
# No binary artifacts — notes-only GitHub Release.
- name: Create GitHub Release
uses: softprops/action-gh-release@v3.0.3
with:
body: ${{ needs.changelog.outputs.changelog }}
draft: false
prerelease: ${{ contains(github.ref_name, '-rc') || contains(github.ref_name, '-beta') || contains(github.ref_name, '-alpha') }}
generate_release_notes: false
# TODO: Add artifact files to the release
# files: |
# artifacts/*
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Check warning on line 130 in .github/workflows/release.yml

View workflow job for this annotation

GitHub Actions / Hypatia neurosymbolic scan

[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
provenance:
name: SLSA Provenance
needs: [build]
Expand Down
10 changes: 5 additions & 5 deletions .machine_readable/contractiles/Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ info:
@echo "Version: {{version}}"
@echo "RSR Tier: {{tier}}"
@echo "Recipes: $(just --summary | wc -w)"
@[ -f ".machine_readable/descriptiles/STATE.deed" ] && grep -oP 'phase\s*=\s*"\K[^"]+' .machine_readable/descriptiles/STATE.deed | head -1 | xargs -I{} echo "Phase: {}" || true
@[ -f ".machine_readable/descriptiles/STATE.deed" ] && grep -oP ':phase\s+\K[A-Za-z]+' .machine_readable/descriptiles/STATE.deed | head -1 | xargs -I{} echo "Phase: {}" || true

# Run Invariant Path overlay tools for this repository
invariant-path *ARGS:
Expand Down Expand Up @@ -547,16 +547,16 @@ import? "build/just/validate.just"
# STATE MANAGEMENT
# ═══════════════════════════════════════════════════════════════════════════════

# Update STATE.deed timestamp
# Attempt to update the timestamp in a key-value-formatted STATE.deed
state-touch:
@if [ -f ".machine_readable/descriptiles/STATE.deed" ]; then \
sed -i 's/last-updated = "[^"]*"/last-updated = "'"$(date +%Y-%m-%d)"'"/' .machine_readable/descriptiles/STATE.deed && \
sed -i 's/:last-updated "[^"]*"/:last-updated "'"$(date +%Y-%m-%d)"'"/' .machine_readable/descriptiles/STATE.deed && \
echo "STATE.deed timestamp updated"; \
fi

# Show current phase from STATE.deed
# Show the phase from a key-value-formatted STATE.deed
state-phase:
@grep -oP 'phase\s*=\s*"\K[^"]+' .machine_readable/descriptiles/STATE.deed 2>/dev/null | head -1 || echo "unknown"
@grep -oP ':phase\s+\K[A-Za-z]+' .machine_readable/descriptiles/STATE.deed 2>/dev/null | head -1 || echo "unknown"

# ═══════════════════════════════════════════════════════════════════════════════
# GUIX (channels — Nix is deprecated)
Expand Down
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/adjust/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/intend/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/must/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/trust/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
2 changes: 1 addition & 1 deletion .machine_readable/descriptiles/LANGUAGES.deed
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,4 @@
:config ("nickel" "deed")
:build ("just" "bash"))
(planned
:core "TBD"))
:core "not-implemented"))
14 changes: 5 additions & 9 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ info:
@echo "Version: {{version}}"
@echo "RSR Tier: {{tier}}"
@echo "Recipes: $(just --summary | wc -w)"
@[ -f ".machine_readable/descriptiles/STATE.deed" ] && grep -oP 'phase\s*=\s*"\K[^"]+' .machine_readable/descriptiles/STATE.deed | head -1 | xargs -I{} echo "Phase: {}" || true
@[ -f ".machine_readable/descriptiles/STATE.deed" ] && grep -oP ':phase\s+\K[A-Za-z]+' .machine_readable/descriptiles/STATE.deed | head -1 | xargs -I{} echo "Phase: {}" || true

# Run Invariant Path overlay tools for this repository
invariant-path *ARGS:
Expand Down Expand Up @@ -265,14 +265,10 @@ deps:
@command -v zig >/dev/null 2>&1 && echo " [OK] zig" || echo " [FAIL] zig not found"
@command -v just >/dev/null 2>&1 && echo " [OK] just" || echo " [FAIL] just not found"

# Audit dependencies for vulnerabilities
# Audit dependencies for vulnerabilities (no cargo/mix; trivy if present)
deps-audit:
@echo "Auditing for vulnerabilities..."
# TODO: Replace with your audit command
# Examples:
# cargo audit
# mix audit
@command -v trivy >/dev/null && trivy fs --severity HIGH,CRITICAL --quiet . || true
@command -v trivy >/dev/null && trivy fs --severity HIGH,CRITICAL --quiet . || echo "trivy not installed — skip"
@echo "Audit complete"

# ═══════════════════════════════════════════════════════════════════════════════
Expand Down Expand Up @@ -527,10 +523,10 @@ import? "build/just/validate.just"
# STATE MANAGEMENT
# ═══════════════════════════════════════════════════════════════════════════════

# Update STATE.deed timestamp
# Attempt to update the timestamp in a key-value-formatted STATE.deed
state-touch:
@if [ -f ".machine_readable/descriptiles/STATE.deed" ]; then \
sed -i 's/last-updated = "[^"]*"/last-updated = "'"$(date +%Y-%m-%d)"'"/' .machine_readable/descriptiles/STATE.deed && \
sed -i 's/:last-updated "[^"]*"/:last-updated "'"$(date +%Y-%m-%d)"'"/' .machine_readable/descriptiles/STATE.deed && \
echo "STATE.deed timestamp updated"; \
fi

Expand Down
24 changes: 17 additions & 7 deletions build/just/validate.just
Original file line number Diff line number Diff line change
Expand Up @@ -51,15 +51,25 @@ validate-rsr:
fi
echo "RSR compliance: PASS"

# Validate STATE.deed syntax
# Report whether STATE.deed contains key-value metadata and project markers
validate-state:
@if [ -f ".machine_readable/descriptiles/STATE.deed" ]; then \
grep -q '^\[metadata\]' .machine_readable/descriptiles/STATE.deed && \
grep -q 'project\s*=' .machine_readable/descriptiles/STATE.deed && \
echo "STATE.deed: valid" || echo "STATE.deed: INVALID (missing required sections)"; \
else \
echo "No .machine_readable/descriptiles/STATE.deed found"; \
#!/usr/bin/env bash
STATE_FILE=".machine_readable/descriptiles/STATE.deed"
if [ ! -f "$STATE_FILE" ]; then
echo "No $STATE_FILE found"
exit 1
fi
for field in schema-version canonical-name repo-uuid beholding-chora last-updated status phase; do
if ! grep -Eq "^[[:space:]]*:${field}[[:space:]]" "$STATE_FILE"; then
echo "STATE.deed: INVALID (missing :${field})"
exit 1
fi
done
if ! grep -q '^(repo-deed' "$STATE_FILE"; then
echo "STATE.deed: INVALID (missing repo-deed form)"
exit 1
fi
echo "STATE.deed: valid"

# Validate AI installation guide completeness (finishbot pre-release check)
validate-ai-install:
Expand Down
2 changes: 1 addition & 1 deletion ci/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
6 changes: 4 additions & 2 deletions docs/governance/CRG-AUDIT-2026-09-20.adoc
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
// SPDX-License-Identifier: MPL-2.0
// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
= Panoply — CRG Audit (2026-09-20)
:toc:
Expand Down Expand Up @@ -46,7 +46,9 @@ Zig FFI unit+integration; `tests/aspect_tests.sh`, `p2p.sh`, `core_spec.sh`,

=== External validation

Zero diverse external targets. Cap **C** is unreachable; **B/A** out of scope.
Zero diverse external targets. This blocks **B/A** while **C** remains the
maximum possible grade. C still depends on home-context dogfooding and
annotation requirements and is separately unmet here for lack of evidence.

== Grade matrix

Expand Down
2 changes: 1 addition & 1 deletion docs/reports/PHASE-11-FINAL.adoc
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
// SPDX-License-Identifier: MPL-2.0
// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
= Phase 11 — completeness, CRG/TRG, close-out
:revdate: 2026-09-20
Expand Down
5 changes: 3 additions & 2 deletions docs/status/READINESS.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -170,9 +170,10 @@ Real-world external feedback confirming value. Populate

== 7. Summary (2026-09-20)

* Project grade: **E**. Tests exist; Core does not; RSR D-floor unmet.
* Project grade: **X**. Tests exist; Core does not; RSR D-floor unmet.
FFI / spec surfaces are **E**; they do not lift the project grade.
* TRG overall: **X** (worst required toolchain component).
* Delta: X → E after protocol 0–10 (honest promotion, not a product claim).
* Delta: X → X after protocol 0–10 (FFI / spec surfaces reached E, not the project).
* Next: D requires C5 + Idris2 CI + STATE test matrix. No product tag.

'''
Expand Down
6 changes: 2 additions & 4 deletions src/api/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,5 @@
// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
= api

Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Zig fail-closed adapter: `src/api/zig/adapter.zig` (`NotImplemented` until a
gateway exists — ROADMAP H8). Not an HTTP product.
2 changes: 1 addition & 1 deletion tests/e2e/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
2 changes: 1 addition & 1 deletion tests/shape/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@
Holding directory required by `rsr-template-repo`.
Not yet populated with panoply-specific content.

TODO: see `docs/status/ROADMAP.adoc` (Phase 1 structural placeholders).
Holding — see `docs/status/ROADMAP.adoc` (H1). Not a product surface.
Loading