diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index caebdda67..bc65a5e05 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -18,7 +18,7 @@ | **2. The 007 repo** | All Rights Reserved (ARR) | `hyperpolymath/007` specifically. Out-of-scope for any normalisation, scanning, or labelling. Surface to owner only. | | **3. Shared with son (Joshua)** | `AGPL-3.0-or-later` | Repos with son as co-author/maintainer. Examples: `idaptik`, `paint-type`. Permanent. | | **4. Third-party / forks** | DO NOT TOUCH | Whatever upstream chose. Never sweep, never normalise. Flag as out-of-scope if it surfaces in an audit. | -| **5. Palimpsest register** | `PMPL-1.0-or-later` | **Only repos named in the register** in `LICENCE-POLICY.adoc` Rule 2 — currently five: `palimpsest-license`, `palimpsest-plasma`, `metadatastician/consent-aware-web` (prospectively only — don't flip existing content), `insolvency-tycoon`, `sim-public-relations`. The cap of three was lifted 2026-08-26 as the Palimpsest family develops; the register is a growing **allowlist**, so PMPL in an unlisted repo is still drift. `LICENCE-POLICY.adoc` is authoritative — do not duplicate the list's contents here. | +| **5. Palimpsest register** | `PMPL-1.0-or-later` | **Only repos named in the register** in `3-practice/LICENCE-POLICY.adoc` Rule 2 — currently five: `palimpsest-license`, `palimpsest-plasma`, `metadatastician/consent-aware-web` (prospectively only — don't flip existing content), `insolvency-tycoon`, `sim-public-relations`. The cap of three was lifted 2026-08-26 as the Palimpsest family develops; the register is a growing **allowlist**, so PMPL in an unlisted repo is still drift. `3-practice/LICENCE-POLICY.adoc` is authoritative — do not duplicate the list's contents here. | ### Hard rules for agents @@ -106,15 +106,15 @@ for the canonical statement. > **Corrected 2026-08-07.** This section previously listed **Bun** as banned > with **Deno** as its replacement, and described Deno as "replaces Node/npm/bun". -> That inverted `LANGUAGE-POLICY.adoc` §1, which has ruled Bun > Deno > pnpm > npm +> That inverted `3-practice/LANGUAGE-POLICY.adoc` §1, which has ruled Bun > Deno > pnpm > npm > since 2026-07-29. Because this file is what agents read first, the recorded > ruling and agent behaviour had diverged: agents were being instructed to migrate > *away* from the estate's first-choice runtime. > > **RESOLVED 2026-08-25 — this file governs.** The contradiction previously > flagged here (this table bans TypeScript in favour of AffineScript, while -> `LANGUAGE-POLICY.adoc` §1.2 stated "TypeScript is *permitted under Bun*") has -> been ruled by the owner: **AffineScript governs.** `LANGUAGE-POLICY.adoc` §1.2 +> `3-practice/LANGUAGE-POLICY.adoc` §1.2 stated "TypeScript is *permitted under Bun*") has +> been ruled by the owner: **AffineScript governs.** `3-practice/LANGUAGE-POLICY.adoc` §1.2 > was the error and has been rewritten to match. > > The distinction that keeps both documents coherent: **Bun is the runtime, tier 1 @@ -225,7 +225,7 @@ Both are FOSS with independent governance (no Big Tech). ### Documentation Format - All docs must be `.adoc` (AsciiDoc), **including `README.adoc`** — this is the estate default. GitHub renders AsciiDoc natively on the repo page, so the README, its community-health view, and the file-list tab bar all display correctly. -- GitHub-required `.md` (must be Markdown): SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, CHANGELOG.md. (README is **not** in this list — see the README rule below.) +- GitHub-required `.md` (must be Markdown): 3-practice/SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, CHANGELOG.md. (README is **not** in this list — see the README rule below.) - **README is `.adoc` by default, with exactly two `.md` exceptions:** * `hyperpolymath/hyperpolymath` — the GitHub **profile** repo; profile READMEs render *only* `README.md`, never `.adoc`. * `hyperpolymath/boj-server` — surfaced in external MCP directories (Glama), which show AsciiDoc as raw markup. diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 23d2fee5e..c4559201a 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -21,14 +21,14 @@ # ⚠ ON EVERY LINE, not just the `*` default: in CODEOWNERS the LAST matching # rule wins, and a specific path line REPLACES the default rather than adding to # it. Naming a co-owner only on `*` would leave every explicitly-listed path -# below (SECURITY.md, .github/workflows/, *.sh …) single-owned and therefore +# below (3-practice/SECURITY.md, .github/workflows/, *.sh …) single-owned and therefore # still deadlocked for any PR touching them. # Default: both maintainers * @hyperpolymath @JoshuaJewell # Security-sensitive files require explicit ownership -SECURITY.md @hyperpolymath @JoshuaJewell +3-practice/SECURITY.md @hyperpolymath @JoshuaJewell .github/workflows/ @hyperpolymath @JoshuaJewell .machine_readable/ @hyperpolymath @JoshuaJewell 1-formats/contractiles/ @hyperpolymath @JoshuaJewell diff --git a/.github/workflows/doc-format.yml b/.github/workflows/doc-format.yml index 986a373e5..ed5947014 100644 --- a/.github/workflows/doc-format.yml +++ b/.github/workflows/doc-format.yml @@ -58,9 +58,9 @@ jobs: fi # CONTRIBUTING can have both but .md should just be a redirect - if [ -f "CONTRIBUTING.md" ] && [ -f "CONTRIBUTING.adoc" ]; then - if ! grep -q "See.*CONTRIBUTING.adoc" CONTRIBUTING.md 2>/dev/null; then - echo "::warning::CONTRIBUTING.md exists alongside CONTRIBUTING.adoc but is not a redirect" + if [ -f "CONTRIBUTING.md" ] && [ -f "3-practice/CONTRIBUTING.adoc" ]; then + if ! grep -q "See.*3-practice/CONTRIBUTING.adoc" CONTRIBUTING.md 2>/dev/null; then + echo "::warning::CONTRIBUTING.md exists alongside 3-practice/CONTRIBUTING.adoc but is not a redirect" fi fi @@ -81,7 +81,7 @@ jobs: # profile repo) need the derived .md. # Community-health files that GitHub special-cases by exact .md name: - # SECURITY.md, CONTRIBUTING.md (can redirect), CODE_OF_CONDUCT.md, CHANGELOG.md + # 3-practice/SECURITY.md, CONTRIBUTING.md (can redirect), CODE_OF_CONDUCT.md, CHANGELOG.md # Check other docs are .adoc for doc in ARCHITECTURE ROADMAP PHILOSOPHY INSTALL; do @@ -97,8 +97,8 @@ jobs: # These files are required/preferred by GitHub in .md format MISSING=0 - if [ ! -f "SECURITY.md" ]; then - echo "::warning::SECURITY.md not found (required for GitHub security tab)" + if [ ! -f "3-practice/SECURITY.md" ]; then + echo "::warning::3-practice/SECURITY.md not found (required for GitHub security tab)" fi if [ ! -f "LICENSE.txt" ] && [ ! -f "LICENSE" ]; then diff --git a/.github/workflows/governance-reusable.yml b/.github/workflows/governance-reusable.yml index fba87818d..fd811e79e 100644 --- a/.github/workflows/governance-reusable.yml +++ b/.github/workflows/governance-reusable.yml @@ -563,11 +563,11 @@ jobs: - name: Check for npm/yarn artifacts # standards#67 — npm-avoidant: package-lock.json must never be tracked # estate-wide. Check recursively (not just root) to catch monorepo - # sub-packages. See LANGUAGE-POLICY.adoc §1 and docs/JS-RUNTIME-POLICY.adoc. + # sub-packages. See 3-practice/LANGUAGE-POLICY.adoc §1 and docs/JS-RUNTIME-POLICY.adoc. # # 2026-08-07: this step previously failed any repository carrying # bun.lockb ("Use Deno instead") and any package.json declaring runtime - # dependencies. LANGUAGE-POLICY.adoc §1 has made Bun the tier-1 runtime + # dependencies. 3-practice/LANGUAGE-POLICY.adoc §1 has made Bun the tier-1 runtime # since 2026-07-29, and Bun's model IS an npm-compatible package.json # plus bun.lock — so this gate made adopting the estate's first-choice # runtime impossible, not merely awkward. It blocked what the policy @@ -597,7 +597,7 @@ jobs: FAILED=1 fi if [ -n "$BUN_LOCK" ]; then - echo "✅ Bun lockfile present — tier 1 (LANGUAGE-POLICY.adoc §1)." + echo "✅ Bun lockfile present — tier 1 (3-practice/LANGUAGE-POLICY.adoc §1)." fi # Root package.json with runtime "dependencies". Bun consumes # package.json by design, so this is only an anti-pattern when the @@ -754,7 +754,7 @@ jobs: fi echo "✅ Security policy check passed" - name: SSH-remote policy (token-in-URL detection) - # Estate Remote-URL policy (standards#69 / REMOTE-URL-POLICY.adoc). + # Estate Remote-URL policy (standards#69 / 3-practice/REMOTE-URL-POLICY.adoc). # Scans every .git/config present in the checkout tree for token-in-URL # remotes. Fails hard so a compromised credential cannot silently reach # a PR or main-branch push. @@ -771,7 +771,7 @@ jobs: if [ "$found" -gt 0 ]; then echo "" echo "Remediation: git remote set-url git@github.com:/.git" - echo "Policy: REMOTE-URL-POLICY.adoc — SSH-only remotes; no PAT/token in URL ever." + echo "Policy: 3-practice/REMOTE-URL-POLICY.adoc — SSH-only remotes; no PAT/token in URL ever." exit 1 fi echo "✅ SSH-remote policy: no token-in-URL remotes detected" diff --git a/.github/workflows/registry-verify.yml b/.github/workflows/registry-verify.yml index 99ca79e6f..8d112cb21 100644 --- a/.github/workflows/registry-verify.yml +++ b/.github/workflows/registry-verify.yml @@ -33,7 +33,7 @@ jobs: # The scorecard `--verify` step below EXECUTES every pass-row's check. # Those checks shell out to real tools; ubuntu-latest ships neither - # ripgrep nor xmllint. Without them `release-pre-flight/v1-audit.sh` + # ripgrep nor xmllint. Without them `3-practice/release-pre-flight/v1-audit.sh` # exits 2 ("v1-audit requires ripgrep") and the k9-svc MIME check exits # 127 — which the verifier then reported as "claimed PASS but the pass # is not real". That was a FALSE ACCUSATION: the passes were real, the diff --git a/.github/workflows/scorecard-enforcer.yml b/.github/workflows/scorecard-enforcer.yml index 08899943f..be6e8af65 100644 --- a/.github/workflows/scorecard-enforcer.yml +++ b/.github/workflows/scorecard-enforcer.yml @@ -69,10 +69,10 @@ jobs: steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Check SECURITY.md exists + - name: Check 3-practice/SECURITY.md exists run: | - if [ ! -f "SECURITY.md" ]; then - echo "::error::SECURITY.md is required" + if [ ! -f "3-practice/SECURITY.md" ]; then + echo "::error::3-practice/SECURITY.md is required" exit 1 fi diff --git a/.hypatia-baseline.json b/.hypatia-baseline.json index 64e773f04..83a5cc959 100644 --- a/.hypatia-baseline.json +++ b/.hypatia-baseline.json @@ -701,7 +701,7 @@ "severity": "medium", "rule_module": "structural_drift", "type": "SD022", - "file": "testing-and-benchmarking/TESTING-TAXONOMY.adoc", + "file": "3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc", "note": "FALSE POSITIVE (hypatia triage 2026-07-21): All src/rust/ mentions are explicitly paths inside the external echidna repo (named on each line). Cross-repo reference, not local drift." }, { diff --git a/.machine_readable/MUST.contractile b/.machine_readable/MUST.contractile index 95647e530..d50d6ab0e 100644 --- a/.machine_readable/MUST.contractile +++ b/.machine_readable/MUST.contractile @@ -91,7 +91,7 @@ (must "code, configuration and scripts carry SPDX-License-Identifier: MPL-2.0") (must "prose documentation (*.adoc, *.md) carries SPDX-License-Identifier: CC-BY-SA-4.0") (must "PMPL-1.0-or-later appears in NO standards file — it is reserved for palimpsest-license, palimpsest-plasma and consent-aware-http only") - (must "LICENCE-POLICY.adoc and .machine_readable/licensing-policy.toml state the same licence model — no contradiction") + (must "3-practice/LICENCE-POLICY.adoc and .machine_readable/licensing-policy.toml state the same licence model — no contradiction") (must "LICENSES/ contains the canonical text for every SPDX id in use (MPL-2.0, CC-BY-SA-4.0)") (must "no automated or bulk SPDX/licence edit — owner-only, manual, per-file (policy A2)") (must "consent-aware-http/ and any palimpsest* path is never relicensed by a sweep (protected)") diff --git a/.machine_readable/REGISTRY.a2ml b/.machine_readable/REGISTRY.a2ml index 7222a7ede..fe7c8bb5c 100644 --- a/.machine_readable/REGISTRY.a2ml +++ b/.machine_readable/REGISTRY.a2ml @@ -214,8 +214,8 @@ route = "the repository-compliance standard every repo is graded against" id = "session-management-standards" name = "Session Management Standards" stream = "governance" -home = "session-management-standards/" -canonical_doc = "session-management-standards/README.adoc" +home = "3-practice/session-management-standards/" +canonical_doc = "3-practice/session-management-standards/README.adoc" source_hash = "sha256:f97ff391eea3fc80a4ab0b94031cf4ad9a373f8699ca99f0f0daecfb968ac148" route = "continuity / verify / handover protocols" @@ -241,8 +241,8 @@ route = "the ensaid configuration standard" id = "accessibility" name = "Accessibility Standard" stream = "governance" -home = "accessibility/" -canonical_doc = "accessibility/STANDARD.a2ml" +home = "3-practice/accessibility/" +canonical_doc = "3-practice/accessibility/STANDARD.a2ml" source_hash = "sha256:73898902f539078297c9c1d952e403dc62ddcb39c1d0282442fdf4c22bea330b" route = "estate accessibility requirements" @@ -250,8 +250,8 @@ route = "estate accessibility requirements" id = "publication-pre-flight" name = "Publication Pre-Flight" stream = "governance" -home = "publication-pre-flight/" -canonical_doc = "publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc" +home = "3-practice/publication-pre-flight/" +canonical_doc = "3-practice/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc" source_hash = "sha256:86e93a00784d646d99dcaf412efc3d647a02ff7ac2e38cc1f94c1d6bc775c188" route = "submission gate (HOL + Zenodo checklists)" @@ -259,8 +259,8 @@ route = "submission gate (HOL + Zenodo checklists)" id = "release-pre-flight" name = "Release Pre-Flight (V1 Gate)" stream = "governance" -home = "release-pre-flight/" -canonical_doc = "release-pre-flight/V1-GATE.adoc" +home = "3-practice/release-pre-flight/" +canonical_doc = "3-practice/release-pre-flight/V1-GATE.adoc" source_hash = "sha256:f9dc04e36e6638518ccc9d72518ef5ed9f1187da1fe1044e6d1394bfecf86000" route = "hard v1.0.0 audit requirements" diff --git a/.machine_readable/contractiles/dust/Dustfile.a2ml b/.machine_readable/contractiles/dust/Dustfile.a2ml index f1563c310..786d9159e 100644 --- a/.machine_readable/contractiles/dust/Dustfile.a2ml +++ b/.machine_readable/contractiles/dust/Dustfile.a2ml @@ -37,10 +37,10 @@ dry-run by default and gated behind --apply. - severity: warning ### no-duplicate-licence-policy -- description: only one licence-policy doc (LICENCE-POLICY.adoc canonical) -- run: test ! -f docs/LICENSE-POLICY.md || test ! -f LICENCE-POLICY.adoc +- description: only one licence-policy doc (3-practice/LICENCE-POLICY.adoc canonical) +- run: test ! -f docs/LICENSE-POLICY.md || test ! -f 3-practice/LICENCE-POLICY.adoc - severity: warning -- notes: resolved 2026-06-04 — deleted the stale docs/LICENSE-POLICY.md (it wrongly asserted standards=AGPL); LICENCE-POLICY.adoc is the sole source of truth. Probe stands guard against reintroduction. +- notes: resolved 2026-06-04 — deleted the stale docs/LICENSE-POLICY.md (it wrongly asserted standards=AGPL); 3-practice/LICENCE-POLICY.adoc is the sole source of truth. Probe stands guard against reintroduction. ## Licence Hygiene diff --git a/.machine_readable/contractiles/must/Mustfile.a2ml b/.machine_readable/contractiles/must/Mustfile.a2ml index 9b605ac1e..f3a923d7d 100644 --- a/.machine_readable/contractiles/must/Mustfile.a2ml +++ b/.machine_readable/contractiles/must/Mustfile.a2ml @@ -20,8 +20,8 @@ requirements — CI and pre-commit hooks fail if any check fails. - severity: critical ### licence-policy-present -- description: LICENCE-POLICY.adoc (canonical licence policy) must exist -- run: test -f LICENCE-POLICY.adoc +- description: 3-practice/LICENCE-POLICY.adoc (canonical licence policy) must exist +- run: test -f 3-practice/LICENCE-POLICY.adoc - severity: critical ### readme-present @@ -30,8 +30,8 @@ requirements — CI and pre-commit hooks fail if any check fails. - severity: critical ### security-policy -- description: SECURITY.adoc must exist -- run: test -f SECURITY.adoc +- description: 3-practice/SECURITY.adoc must exist +- run: test -f 3-practice/SECURITY.adoc - severity: critical ### ai-manifest @@ -75,8 +75,8 @@ requirements — CI and pre-commit hooks fail if any check fails. - notes: Header-form only (head -8); LICENSES/ text and deep example mentions are not headers. ### policy-no-contradiction -- description: LICENCE-POLICY.adoc and licensing-policy.toml agree (both name CC-BY-SA-4.0) -- run: grep -q 'CC-BY-SA-4.0' LICENCE-POLICY.adoc && grep -q 'CC-BY-SA-4.0' .machine_readable/licensing-policy.toml +- description: 3-practice/LICENCE-POLICY.adoc and licensing-policy.toml agree (both name CC-BY-SA-4.0) +- run: grep -q 'CC-BY-SA-4.0' 3-practice/LICENCE-POLICY.adoc && grep -q 'CC-BY-SA-4.0' .machine_readable/licensing-policy.toml - severity: critical ## Structure diff --git a/.machine_readable/contractiles/trust/Trustfile.a2ml b/.machine_readable/contractiles/trust/Trustfile.a2ml index ef19b6867..f6a86b005 100644 --- a/.machine_readable/contractiles/trust/Trustfile.a2ml +++ b/.machine_readable/contractiles/trust/Trustfile.a2ml @@ -564,7 +564,7 @@ security: ### [VULNERABILITY_DISCLOSURE] policy: | Responsible disclosure welcomed. Researchers reporting real vulnerabilities - in good faith receive acknowledgement in SECURITY.adoc and in + in good faith receive acknowledgement in 3-practice/SECURITY.adoc and in /.well-known/security-acknowledgments. See security.txt for contact path. # TEMPLATE NOTE: replace {{SECURITY_CONTACT}} with a mailto: URI for this repo's # security contact, e.g. "mailto:j.d.a.jewell@open.ac.uk". diff --git a/.machine_readable/descriptiles/META.a2ml b/.machine_readable/descriptiles/META.a2ml index 6fc78bbc5..a8e2d856c 100644 --- a/.machine_readable/descriptiles/META.a2ml +++ b/.machine_readable/descriptiles/META.a2ml @@ -17,7 +17,7 @@ author = "Jonathan D.A. Jewell (hyperpolymath)" [architecture-decisions] decisions = [ - { id = "ADR-001", date = "2026-05-15", title = "CODEOWNERS policy for hyperpolymath repos", status = "accepted", ref = "CODEOWNERS-POLICY.adoc", issue = "standards#55", summary = "Solo-owned repos carry no catch-all `*` or `/.github/workflows/` CODEOWNERS lines (silences Dependabot review_requested flood); path lines kept only for genuine co-owners; co-owner removal needs explicit confirmation." } + { id = "ADR-001", date = "2026-05-15", title = "CODEOWNERS policy for hyperpolymath repos", status = "accepted", ref = "3-practice/CODEOWNERS-POLICY.adoc", issue = "standards#55", summary = "Solo-owned repos carry no catch-all `*` or `/.github/workflows/` CODEOWNERS lines (silences Dependabot review_requested flood); path lines kept only for genuine co-owners; co-owner removal needs explicit confirmation." } ] [development-practices] diff --git a/.machine_readable/licensing-policy.toml b/.machine_readable/licensing-policy.toml index d56f44008..7e82ba5d5 100644 --- a/.machine_readable/licensing-policy.toml +++ b/.machine_readable/licensing-policy.toml @@ -1,7 +1,7 @@ # SPDX-License-Identifier: MPL-2.0 # SPDX-FileCopyrightText: 2026 Jonathan Jewell (hyperpolymath) # -# Machine-readable form of LICENCE-POLICY.adoc. Tools enforce from this; +# Machine-readable form of 3-practice/LICENCE-POLICY.adoc. Tools enforce from this; # humans read the .adoc (the .adoc is the source of truth — keep in # sync, do not diverge). NOT a REUSE per-file dep5 map: this encodes # the RULES, not per-file claims. diff --git a/.machine_readable/scorecards/accessibility.scorecard.a2ml b/.machine_readable/scorecards/accessibility.scorecard.a2ml index 13b5e9dc7..7202474f4 100644 --- a/.machine_readable/scorecards/accessibility.scorecard.a2ml +++ b/.machine_readable/scorecards/accessibility.scorecard.a2ml @@ -21,7 +21,7 @@ effects = "Downstream projects copying this standard rely on this file as the ca [[must]] id = "M2" text = "Projects MUST implement keyboard navigation for all functionality (Level A)." -system = "probe in STANDARD.a2ml: test -f accessibility/keyboard.ex || find . -name \"*keyboard*\" -type f — but this is a per-consumer-project probe, not something the standards repo itself implements" +system = "probe in STANDARD.a2ml: test -f 3-practice/accessibility/keyboard.ex || find . -name \"*keyboard*\" -type f — but this is a per-consumer-project probe, not something the standards repo itself implements" status = "fail" effects = "Consuming projects (e.g. the example 'Burble' project referenced in docs/accessibility/README.adoc) cannot claim Level A compliance without their own implementation; the standards repo itself ships no reference implementation or fixture proving the probe works." diff --git a/.machine_readable/scorecards/axel-protocol.scorecard.a2ml b/.machine_readable/scorecards/axel-protocol.scorecard.a2ml index 43e479172..38a053c73 100644 --- a/.machine_readable/scorecards/axel-protocol.scorecard.a2ml +++ b/.machine_readable/scorecards/axel-protocol.scorecard.a2ml @@ -32,10 +32,10 @@ effects = "Downstream systems-integration consumers relying on the advertised 'Z [[must]] id = "M4" -text = "The repository MUST have a filled-in, non-boilerplate vulnerability-disclosure policy (SECURITY.md)." +text = "The repository MUST have a filled-in, non-boilerplate vulnerability-disclosure policy (3-practice/SECURITY.md)." system = "manual-only" status = "fail" -effects = "Security researchers and downstream adopters have no real contact path or supported-version table; SECURITY.md still contains the generic GitHub template text ('Use this section to tell people...') rather than project-specific content." +effects = "Security researchers and downstream adopters have no real contact path or supported-version table; 3-practice/SECURITY.md still contains the generic GitHub template text ('Use this section to tell people...') rather than project-specific content." [[must]] id = "M5" diff --git a/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml b/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml index 80c74c73b..1d0e1352d 100644 --- a/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml +++ b/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml @@ -71,7 +71,7 @@ effects = "1-formats/contractiles/must/Mustfile still contains the literal templ [[should]] id = "S4" -text = "Repository-level governance files that the README's 'Project Structure' section lists as present in 1-formats/a2ml/ecosystem/ (CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md, LICENSE) SHOULD actually exist at that stated path." +text = "Repository-level governance files that the README's 'Project Structure' section lists as present in 1-formats/a2ml/ecosystem/ (CONTRIBUTING.md, CODE_OF_CONDUCT.md, 3-practice/SECURITY.md, LICENSE) SHOULD actually exist at that stated path." system = "none" status = "fail" effects = "A contributor following the README's tree diagram (which places CONTRIBUTING.md/CODE_OF_CONDUCT.md/SECURITY.md/LICENSE directly under 1-formats/a2ml/ecosystem/) will find none of those files there; only monorepo-root equivalents exist (/home/user/standards/CONTRIBUTING.md etc.), which may or may not apply identically to this subproject's PMPL-1.0 licence claim." diff --git a/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml b/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml index edba94096..e33279416 100644 --- a/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml +++ b/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml @@ -32,7 +32,7 @@ id = "M3" text = "HYP-S004 (rsr-self-compliance) MUST accurately enumerate RSR-mandated files/workflows that the standards repo itself actually possesses, since it exists specifically to dogfood the repo against its own constitution." system = "none — no script in this repo executes rsr-self-compliance.a2ml's @required_files / @required_workflows / @forbidden_files lists against the tree; it is only ever run by an external Hypatia instance against VeriSimDB, which is outside this repo" status = "fail" -effects = "A stale or incorrect required-file/workflow list means RSR-self-compliance findings from Hypatia could be wrong (false pass or false fail) with no local safety net; downstream repos citing 'standards passes its own RSR self-compliance check' would be relying on an unverified claim. Concretely, README.adoc/Justfile show real files for README.adoc, SECURITY.md, CONTRIBUTING.md, LICENSE, CODE_OF_CONDUCT.md, .editorconfig, Justfile, guix.scm, flake.nix, and .machine_readable/ all exist, and hypatia-scan.yml/mirror.yml/scorecard-enforcer.yml/rsr-antipattern equivalents exist under different exact names (e.g. no literal 'rsr-antipattern.yml' file was found in .github/workflows/), so the rule's required_workflows list is not fully reconciled with the actual workflow filenames on disk." +effects = "A stale or incorrect required-file/workflow list means RSR-self-compliance findings from Hypatia could be wrong (false pass or false fail) with no local safety net; downstream repos citing 'standards passes its own RSR self-compliance check' would be relying on an unverified claim. Concretely, README.adoc/Justfile show real files for README.adoc, 3-practice/SECURITY.md, CONTRIBUTING.md, LICENSE, CODE_OF_CONDUCT.md, .editorconfig, Justfile, guix.scm, flake.nix, and .machine_readable/ all exist, and hypatia-scan.yml/mirror.yml/scorecard-enforcer.yml/rsr-antipattern equivalents exist under different exact names (e.g. no literal 'rsr-antipattern.yml' file was found in .github/workflows/), so the rule's required_workflows list is not fully reconciled with the actual workflow filenames on disk." [[must]] id = "M4" diff --git a/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml b/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml index 190e71788..732e8389e 100644 --- a/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml +++ b/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml @@ -69,8 +69,8 @@ effects = "The Contributing guideline in README.adoc (\"Examples validate agains [[should]] id = "S4" -text = "The repository SHOULD carry a SECURITY.md, per estate governance convention (checked elsewhere in the estate by scorecard-enforcer.yml's check-critical job)." -system = "none wired here — .github/workflows/scorecard-enforcer.yml's check-critical job asserts SECURITY.md exists, but that workflow lives at the monorepo root / is intended for satellite repos with their own workflow call-in; 1-formats/a2ml/neurosym/ has no .github/workflows and no SECURITY.md" +text = "The repository SHOULD carry a 3-practice/SECURITY.md, per estate governance convention (checked elsewhere in the estate by scorecard-enforcer.yml's check-critical job)." +system = "none wired here — .github/workflows/scorecard-enforcer.yml's check-critical job asserts 3-practice/SECURITY.md exists, but that workflow lives at the monorepo root / is intended for satellite repos with their own workflow call-in; 1-formats/a2ml/neurosym/ has no .github/workflows and no 3-practice/SECURITY.md" status = "fail" effects = "GitHub security-tab guidance and the estate scorecard consider this spec incomplete on baseline governance hygiene; COMPLIANCE-DASHBOARD.md already flags neurosym-a2ml as \"no scorecard\"." diff --git a/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml b/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml index 5d888e527..21218f62e 100644 --- a/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml +++ b/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml @@ -47,7 +47,7 @@ effects = "Consuming proof-heavy repos (Idris2/Lean4/Agda projects referenced in [[should]] id = "S1" text = "The repo SHOULD contain a Hypatia scan cache (.hypatia/ directory) reflecting a recent static-analysis pass (PREFLIGHT.adoc section 2)." -system = "none for this spec directory itself; a top-level .hypatia directory exists in the monorepo root, but publication-pre-flight/ has no self-scan and no script tying candidate papers to a fresh Hypatia run" +system = "none for this spec directory itself; a top-level .hypatia directory exists in the monorepo root, but 3-practice/publication-pre-flight/ has no self-scan and no script tying candidate papers to a fresh Hypatia run" status = "fail" effects = "Candidate paper repos lacking their own .hypatia/ cache would fail this SHOULD, weakening confidence in the 'Probed' P for any paper relying on this checklist." diff --git a/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml b/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml index 3744a4a35..536336548 100644 --- a/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml +++ b/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml @@ -15,7 +15,7 @@ text = "The gate document MUST enumerate hard gates (proof completeness, test co system = "/home/user/standards/release-pre-flight/V1-GATE.adoc sections 3.1-3.7" status = "pass" evidence = "V1-GATE.adoc lines 47-130 define sections 3.1 through 3.7 with concrete, checkable criteria for each hard gate." -check = "for s in \"3.1 Proof Completeness\" \"3.2 Test Completeness\" \"3.3 Benchmark Completeness\" \"3.4 Build and Execution Integrity\" \"3.5 Aspect Integrity\" \"3.6 Static and Security Audit\" \"3.7 Claim and Artifact Parity\"; do grep -q \"=== $s\" release-pre-flight/V1-GATE.adoc || exit 1; done" +check = "for s in \"3.1 Proof Completeness\" \"3.2 Test Completeness\" \"3.3 Benchmark Completeness\" \"3.4 Build and Execution Integrity\" \"3.5 Aspect Integrity\" \"3.6 Static and Security Audit\" \"3.7 Claim and Artifact Parity\"; do grep -q \"=== $s\" 3-practice/release-pre-flight/V1-GATE.adoc || exit 1; done" effects = "Any repo/spec claiming v1.0.0 without meeting these criteria has no documented basis for the claim; consumers relying on the label lose the guarantee it is meant to encode." [[must]] @@ -23,8 +23,8 @@ id = "M2" text = "There MUST be an automated audit script that mechanically scans a target repo for unfinished-marker residue (TODO/FIXME/XXX/HACK/STUB/PARTIAL, template placeholders) in claimed release paths." system = "/home/user/standards/release-pre-flight/v1-audit.sh check_marker_scan() (MARKER_PATTERN regex via ripgrep)" status = "pass" -evidence = "Running `bash release-pre-flight/v1-audit.sh .` against the monorepo root exercises check_marker_scan and correctly flags real STUB/TODO occurrences (e.g. session-management-standards/continuity/*/CHECKLIST.adoc:7 'Status: STUB', 2-protocols/axel/config/ci.k9.ncl:38 'TODO: Add coverage')." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: unfinished markers or placeholders present'" +evidence = "Running `bash 3-practice/release-pre-flight/v1-audit.sh .` against the monorepo root exercises check_marker_scan and correctly flags real STUB/TODO occurrences (e.g. 3-practice/session-management-standards/continuity/*/CHECKLIST.adoc:7 'Status: STUB', 2-protocols/axel/config/ci.k9.ncl:38 'TODO: Add coverage')." +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: unfinished markers or placeholders present'" effects = "Without this, downstream repos could tag v1.0.0 while shipping scaffold residue; consumers of the standards repo could not trust the marker-scan portion of any v1.0.0 claim." [[must]] @@ -33,7 +33,7 @@ text = "The audit script MUST detect proof-debt escape hatches (believe_me, sorr system = "/home/user/standards/release-pre-flight/v1-audit.sh check_proof_debt() (PROOF_DEBT_PATTERN via ripgrep)" status = "pass" evidence = "Executing the script against the repo root correctly surfaced 4 real `postulate` occurrences in lol/proofs/theories/information_theory.agda:115,121,127,132, recorded as a BLOCKER." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: proof escape hatches found'" +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: proof escape hatches found'" effects = "Repos with unresolved proof holes (e.g. lol's Agda postulates) would otherwise be able to claim a machine-checked/provable v1.0.0 status that the proof artifacts do not support." [[must]] @@ -41,7 +41,7 @@ id = "M4" text = "The audit script MUST verify that the target repo has real build, point-to-point/unit test, end-to-end test, aspect test, benchmark, and execution/smoke recipes (via Justfile or equivalent test paths), not placeholder recipes." system = "/home/user/standards/release-pre-flight/v1-audit.sh check_audit_surfaces()" status = "fail" -effects = "check_audit_surfaces() calls `Justfile_path` (capital J) at line 271, but the function is defined as `justfile_path` (lowercase) at line 198. This is a real bash case-sensitivity bug: the call always fails with 'command not found', is swallowed by `if !`, and the script unconditionally records a false 'missing Justfile/Justfile' blocker and returns early -- even though a top-level Justfile exists in the repo root (confirmed: /home/user/standards/Justfile is present, 10380 bytes). Verified by running `bash release-pre-flight/v1-audit.sh .`, which printed 'Justfile_path: command not found' followed by 'BLOCKER: missing Justfile/Justfile'. This means the entire build/test/benchmark/aspect/execution-surface portion of the gate is non-functional for every invocation, silently short-circuiting the most substantive part of the audit." +effects = "check_audit_surfaces() calls `Justfile_path` (capital J) at line 271, but the function is defined as `justfile_path` (lowercase) at line 198. This is a real bash case-sensitivity bug: the call always fails with 'command not found', is swallowed by `if !`, and the script unconditionally records a false 'missing Justfile/Justfile' blocker and returns early -- even though a top-level Justfile exists in the repo root (confirmed: /home/user/standards/Justfile is present, 10380 bytes). Verified by running `bash 3-practice/release-pre-flight/v1-audit.sh .`, which printed 'Justfile_path: command not found' followed by 'BLOCKER: missing Justfile/Justfile'. This means the entire build/test/benchmark/aspect/execution-surface portion of the gate is non-functional for every invocation, silently short-circuiting the most substantive part of the audit." [[must]] id = "M5" @@ -49,7 +49,7 @@ text = "The audit script MUST verify the target repo has a CI workflow surface ( system = "/home/user/standards/release-pre-flight/v1-audit.sh check_ci_surface()" status = "pass" evidence = "Running the script against the monorepo root printed 'PASS: CI workflow surface present', correctly detecting /home/user/standards/.github/workflows (30+ workflow files present, e.g. codeql.yml, secret-scanner.yml)." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: CI workflow surface present'" +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: CI workflow surface present'" effects = "Without this check, a repo could claim v1.0.0 with no CI wired at all, and no automated signal would catch it." [[should]] @@ -65,7 +65,7 @@ text = "The audit script SHOULD attempt to detect fake or placeholder test/bench system = "/home/user/standards/release-pre-flight/v1-audit.sh check_fake_evidence() (PLACEHOLDER_EVIDENCE_PATTERN)" status = "pass" evidence = "Running the script printed 'PASS: no obvious fake test or benchmark evidence found' and 'PASS: no placeholder fuzz/bench artifact files found' for the monorepo root, exercising the check_fake_evidence() function successfully (it ran without error and returned a clean result)." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: no obvious fake test or benchmark evidence found'" +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: no obvious fake test or benchmark evidence found'" effects = "Without this, a repo could pad coverage numbers with trivial/copied scaffold tests and still pass claim review." [[should]] @@ -74,7 +74,7 @@ text = "The audit script SHOULD surface (not gate) explicit stable/high-assuranc system = "/home/user/standards/release-pre-flight/v1-audit.sh check_stable_claims()" status = "pass" evidence = "Running the script surfaced real matches such as 2-protocols/axel/ROADMAP.adoc:15 'v1.0.0 - Stable Release', .machine_readable/contractiles/trust/Trustfile.a2ml:395 'ALPHA -- NOT production-ready', confirming the informational scan works end-to-end." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: stable or high-assurance claims detected'" +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: stable or high-assurance claims detected'" effects = "Reviewers doing the manual claim-parity judgement (gate 3.7) lose their starting point for finding overclaiming text if this check silently broke." [[should]] @@ -83,7 +83,7 @@ text = "The audit script SHOULD cross-check any STATE.a2ml release-stage metadat system = "/home/user/standards/release-pre-flight/v1-audit.sh check_state_release_stage()" status = "pass" evidence = "Running the script found /home/user/standards/.machine_readable/6a2/STATE.a2ml and printed 'maturity = \"experimental\"', confirming the discovery/print logic executes correctly (though it is informational only, not a correlation/gate)." -check = "bash release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: STATE metadata found'" +check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: STATE metadata found'" effects = "Without even this informational cross-reference, a repo's maturity metadata could drift from what the audit actually found with no automated flag." [[could]] diff --git a/.machine_readable/scorecards/session-management-standards.scorecard.a2ml b/.machine_readable/scorecards/session-management-standards.scorecard.a2ml index 8bfacea72..4eb136f8e 100644 --- a/.machine_readable/scorecards/session-management-standards.scorecard.a2ml +++ b/.machine_readable/scorecards/session-management-standards.scorecard.a2ml @@ -43,13 +43,13 @@ text = "The 'Directory Map' and 'Canonical Protocol Families' enumerated in READ system = "none (no automated drift check), but verified pass by direct filesystem inspection." status = "pass" evidence = "All 12 protocol directories (verify/{maintenance-sweep,substantial-completion,release-audit}, continuity/{repo-intake,checkpoint-before-major-change,planned-session-close,emergency-termination,recovery-operation}, handover/{full-transfer,collaborative-transfer,model-transfer,human-transfer}) and all 9 templates/ files listed in the README Directory Map exist exactly as named on disk." -check = "for d in verify/maintenance-sweep verify/substantial-completion verify/release-audit continuity/repo-intake continuity/checkpoint-before-major-change continuity/planned-session-close continuity/emergency-termination continuity/recovery-operation handover/collaborative-transfer handover/full-transfer handover/human-transfer handover/model-transfer; do test -d \"session-management-standards/$d\" || exit 1; done && for f in SESSION_STATE.adoc NEXT_STEPS.adoc SESSION_SUMMARY.adoc EMERGENCY-CHECKPOINT.adoc SUBSTANTIAL_COMPLETION_REPORT.adoc HANDOVER-REPORT.adoc RECOVERY-PLAN.adoc RELEASE_AUDIT.adoc MAINTENANCE_REPORT.adoc; do test -f \"session-management-standards/templates/$f\" || exit 1; done" +check = "for d in verify/maintenance-sweep verify/substantial-completion verify/release-audit continuity/repo-intake continuity/checkpoint-before-major-change continuity/planned-session-close continuity/emergency-termination continuity/recovery-operation handover/collaborative-transfer handover/full-transfer handover/human-transfer handover/model-transfer; do test -d \"3-practice/session-management-standards/$d\" || exit 1; done && for f in SESSION_STATE.adoc NEXT_STEPS.adoc SESSION_SUMMARY.adoc EMERGENCY-CHECKPOINT.adoc SUBSTANTIAL_COMPLETION_REPORT.adoc HANDOVER-REPORT.adoc RECOVERY-PLAN.adoc RELEASE_AUDIT.adoc MAINTENANCE_REPORT.adoc; do test -f \"3-practice/session-management-standards/templates/$f\" || exit 1; done" effects = "n/a — this is currently sound, so no downstream impact." [[should]] id = "S1" text = "PROTOCOL.k9 files SHOULD conform to the repository's existing K9 configuration grammar (K9! magic number, pedigree block with name/version, security-level field) since a generic validator for that grammar exists in this monorepo." -system = "1-formats/k9/actions/validate/validate-k9.sh — checks .k9 files for 'K9!' magic-number line 1, pedigree block, valid security level (kennel/yard/hunt), and SPDX header. Exists but is not wired to session-management-standards/." +system = "1-formats/k9/actions/validate/validate-k9.sh — checks .k9 files for 'K9!' magic-number line 1, pedigree block, valid security level (kennel/yard/hunt), and SPDX header. Exists but is not wired to 3-practice/session-management-standards/." status = "fail" effects = "All 12 PROTOCOL.k9 files here begin with a plain '# ...' comment, not the 'K9!' magic number, and have no pedigree/security-level fields, so they would fail validate-k9.sh if it were ever run repo-wide. This is a naming collision risk: '.k9' files that don't follow the actual K9 grammar could confuse tooling or reviewers who expect the k9-svc schema." diff --git a/.machine_readable/template-capability-gates.toml b/.machine_readable/template-capability-gates.toml index addeae8f8..de111b2f1 100644 --- a/.machine_readable/template-capability-gates.toml +++ b/.machine_readable/template-capability-gates.toml @@ -56,7 +56,7 @@ paths = ["README.adoc", "EXPLAINME.adoc|docs/EXPLAINME.adoc", "LICENSE", "SECURI "docs/AUDIT.adoc|AUDIT.adoc" = "governance-tier" "docs/AFFIRMATION.adoc|AFFIRMATION.adoc" = "governance-tier" "docs/GOVERNANCE.adoc|0-canon/GOVERNANCE.adoc|.github/GOVERNANCE.md" = "governance-tier" -"docs/MAINTAINERS.adoc|MAINTAINERS.adoc" = "governance-tier" +"docs/MAINTAINERS.adoc|MAINTAINERS.adoc|3-practice/MAINTAINERS.adoc" = "governance-tier" [carrier] # Paths a SPINE (template) repo may carry WITHOUT declaring the gating diff --git a/0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc b/0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc index 128e8ba5d..4a46e1455 100644 --- a/0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc +++ b/0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc @@ -110,7 +110,7 @@ and the SPDX licence invariant (`LICENCE-POLICY.adoc`). | mobile shell (Tauri/Dioxus) | `mobile` | `affinescript/` subtree | `affinescript` | `benches/` | `benchmarks` -| `AUDIT.adoc`, `AFFIRMATION.adoc`, `0-canon/GOVERNANCE.adoc`, `MAINTAINERS.adoc` | `governance-tier` +| `AUDIT.adoc`, `AFFIRMATION.adoc`, `0-canon/GOVERNANCE.adoc`, `MAINTAINERS.adoc`, `3-practice/MAINTAINERS.adoc` | `governance-tier` | `.github/workflows/release.yml`, registry metadata | `published-package` |=== diff --git a/0-canon/rsr/CHANGELOG.adoc b/0-canon/rsr/CHANGELOG.adoc index 863bd07bb..725c8f4e6 100644 --- a/0-canon/rsr/CHANGELOG.adoc +++ b/0-canon/rsr/CHANGELOG.adoc @@ -30,7 +30,7 @@ The format is based on https://keepachangelog.com/[Keep a Changelog], and this s ** Gold: 100% compliance ** Rhodium: 100% + exemplary practices -* *Language Policy* (link:LANGUAGE-POLICY.adoc[LANGUAGE-POLICY.adoc]) +* *Language Policy* (link:3-practice/LANGUAGE-POLICY.adoc[3-practice/LANGUAGE-POLICY.adoc]) ** 10 allowed languages defined ** 9 banned languages with replacements ** SaltStack Python exception documented diff --git a/0-canon/rsr/REPO-STANDARD-MUST-INTEND-LIKE.adoc b/0-canon/rsr/REPO-STANDARD-MUST-INTEND-LIKE.adoc index 1499b7f27..dc7c7ea74 100644 --- a/0-canon/rsr/REPO-STANDARD-MUST-INTEND-LIKE.adoc +++ b/0-canon/rsr/REPO-STANDARD-MUST-INTEND-LIKE.adoc @@ -31,7 +31,7 @@ Must include: * `README` (what it does, supported scope, quickstart, known limits) * `ROADMAP` (Must/Intend/Like or equivalent staged plan) * `CHANGELOG` (user-visible changes and migration impact) -* `SECURITY.md` (reporting + hardening posture) +* `3-practice/SECURITY.md` (reporting + hardening posture) * `LICENSE` * `CONTRIBUTING` (workflow and quality gates) * `CODEOWNERS` or `MAINTAINERS` diff --git a/0-canon/rsr/RSR-SPEC.adoc b/0-canon/rsr/RSR-SPEC.adoc index 0fff067d9..4df95bde6 100644 --- a/0-canon/rsr/RSR-SPEC.adoc +++ b/0-canon/rsr/RSR-SPEC.adoc @@ -111,7 +111,7 @@ RSR integrates with related specifications: == Language Policy -RSR enforces strict language requirements. See link:LANGUAGE-POLICY.adoc[LANGUAGE-POLICY.adoc] for details. +RSR enforces strict language requirements. See link:3-practice/LANGUAGE-POLICY.adoc[3-practice/LANGUAGE-POLICY.adoc] for details. *Allowed*: ReScript, Rust, Deno, Gleam, OCaml, Ada, Julia, Guile Scheme, Nickel @@ -121,7 +121,7 @@ RSR enforces strict language requirements. See link:LANGUAGE-POLICY.adoc[LANGUAG * link:COMPLIANCE-CHECKLIST.adoc[Full Compliance Checklist] (150+ criteria) * link:TIERS.adoc[Tier Definitions] -* link:LANGUAGE-POLICY.adoc[Language Policy] +* link:3-practice/LANGUAGE-POLICY.adoc[Language Policy] * link:../GOVERNANCE.adoc[Governance Model] * link:../SECURITY.md[Security Policy] diff --git a/0-canon/rsr/TIERS.adoc b/0-canon/rsr/TIERS.adoc index 71966874b..74459b18b 100644 --- a/0-canon/rsr/TIERS.adoc +++ b/0-canon/rsr/TIERS.adoc @@ -28,7 +28,7 @@ image:../badges/rsr-bronze.svg[RSR Bronze,64] .Required * [ ] README.md or README.adoc * [ ] LICENSE.txt (SPDX-identified) -* [ ] SECURITY.md with vulnerability policy +* [ ] 3-practice/SECURITY.md with vulnerability policy * [ ] CI/CD pipeline (GitLab or GitHub Actions) * [ ] SPDX headers on all source files * [ ] .gitignore and .gitattributes @@ -44,8 +44,8 @@ image:../badges/rsr-silver.svg[RSR Silver,64] *Professional-grade compliance.* .Includes all Bronze requirements, plus: -* [ ] CODE_OF_CONDUCT.adoc -* [ ] CONTRIBUTING.adoc +* [ ] 3-practice/CODE_OF_CONDUCT.adoc +* [ ] 3-practice/CONTRIBUTING.adoc * [ ] 0-canon/GOVERNANCE.adoc * [ ] MAINTAINERS.md * [ ] FUNDING.yml diff --git a/0-canon/rsr/VERSION.adoc b/0-canon/rsr/VERSION.adoc index 85eb822ab..0e24ed5b2 100644 --- a/0-canon/rsr/VERSION.adoc +++ b/0-canon/rsr/VERSION.adoc @@ -51,7 +51,7 @@ The following components are locked in v1.0. Any changes require a new specifica | image:../badges/rsr-bronze.svg[Bronze,24] Bronze | 75-89% -| README, LICENSE.txt, SECURITY.md, CI/CD, SPDX headers +| README, LICENSE.txt, 3-practice/SECURITY.md, CI/CD, SPDX headers | *LOCKED* | image:../badges/rsr-silver.svg[Silver,24] Silver @@ -139,7 +139,7 @@ The following components are locked in v1.0. Any changes require a new specifica | `README.md` or `README.adoc` | Bronze | Project overview | `LICENSE.txt` | Bronze | SPDX-identified, plain text -| `SECURITY.md` | Bronze | Vulnerability policy +| `3-practice/SECURITY.md` | Bronze | Vulnerability policy | `CODE_OF_CONDUCT.md` or `.adoc` | Bronze (rec.) | Community standards | `CONTRIBUTING.md` or `.adoc` | Bronze (rec.) | Contribution guide | `0-canon/GOVERNANCE.adoc` | Silver | Decision-making process diff --git a/1-formats/A2ML-REPO-TEMPLATE.adoc b/1-formats/A2ML-REPO-TEMPLATE.adoc index d9cf517ab..eeb55d2dd 100644 --- a/1-formats/A2ML-REPO-TEMPLATE.adoc +++ b/1-formats/A2ML-REPO-TEMPLATE.adoc @@ -91,8 +91,8 @@ Every A2ML specification repository MUST have: │ └── FAQ.adoc # Common questions ├── README.adoc # Overview and quick start ├── CONTRIBUTING.md # Contribution guidelines -├── CONTRIBUTING.adoc # Detailed contribution guide -├── SECURITY.md # Security policy +├── 3-practice/CONTRIBUTING.adoc # Detailed contribution guide +├── 3-practice/SECURITY.md # Security policy ├── CODE_OF_CONDUCT.md # Community standards ├── LICENSE.txt # PMPL-1.0-or-later ├── 1-formats/SATELLITES.a2ml # List of satellite projects (if hub) diff --git a/1-formats/a2ml/ecosystem/README.adoc b/1-formats/a2ml/ecosystem/README.adoc index 62cfa93a4..1a916474e 100644 --- a/1-formats/a2ml/ecosystem/README.adoc +++ b/1-formats/a2ml/ecosystem/README.adoc @@ -373,7 +373,7 @@ See link:STANDARDS-ROADMAP.adoc[STANDARDS-ROADMAP.adoc] for the complete standar | +-- scm-family.schema.json # Unified validation schema +-- CONTRIBUTING.md +-- CODE_OF_CONDUCT.md -+-- SECURITY.md ++-- 3-practice/SECURITY.md +-- LICENSE # PMPL-1.0 ---- diff --git a/1-formats/a2ml/meta/.claude/CLAUDE.md b/1-formats/a2ml/meta/.claude/CLAUDE.md index bec918947..b45054f01 100644 --- a/1-formats/a2ml/meta/.claude/CLAUDE.md +++ b/1-formats/a2ml/meta/.claude/CLAUDE.md @@ -42,7 +42,7 @@ in A2ML format (migrated from Guile Scheme on 2026-04-12): | Deno | Bun | | Node.js | Bun | | npm | Bun | -| ~~Bun~~ | — | Bun is TIER 1 as of LANGUAGE-POLICY.adoc §1 (2026-07-29). This row is retired. | +| ~~Bun~~ | — | Bun is TIER 1 as of 3-practice/LANGUAGE-POLICY.adoc §1 (2026-07-29). This row is retired. | | pnpm/yarn | Bun | | Go | Rust | | Python | Julia/Rust/AffineScript | diff --git a/1-formats/a2ml/meta/examples/comprehensive.a2ml b/1-formats/a2ml/meta/examples/comprehensive.a2ml index 924156197..934ef1562 100644 --- a/1-formats/a2ml/meta/examples/comprehensive.a2ml +++ b/1-formats/a2ml/meta/examples/comprehensive.a2ml @@ -132,7 +132,7 @@ dependencies = "SHA-pinned in CI; SPDX headers on all files" authentication = "OAuth 2.0 + OIDC" [development-practices.documentation] -format = "AsciiDoc for long-form; Markdown for GitHub-required files (SECURITY.md, CONTRIBUTING.md)" +format = "AsciiDoc for long-form; Markdown for GitHub-required files (3-practice/SECURITY.md, CONTRIBUTING.md)" adr-location = "META.a2ml in each service repository" runbooks = "Required for all production services" diagrams = "Mermaid, version controlled" diff --git a/1-formats/a2ml/state/.gitlab-ci.yml b/1-formats/a2ml/state/.gitlab-ci.yml index 2c5efdf20..22d8b1d21 100644 --- a/1-formats/a2ml/state/.gitlab-ci.yml +++ b/1-formats/a2ml/state/.gitlab-ci.yml @@ -68,9 +68,9 @@ pages: - mkdir -p public - asciidoctor README.adoc -o public/index.html - asciidoctor USAGE.adoc -o public/usage.html - - asciidoctor CONTRIBUTING.adoc -o public/contributing.html + - asciidoctor 3-practice/CONTRIBUTING.adoc -o public/contributing.html - asciidoctor 0-canon/GOVERNANCE.adoc -o public/governance.html - - asciidoctor CODE_OF_CONDUCT.adoc -o public/code-of-conduct.html + - asciidoctor 3-practice/CODE_OF_CONDUCT.adoc -o public/code-of-conduct.html artifacts: paths: - public diff --git a/1-formats/a2ml/state/README.adoc b/1-formats/a2ml/state/README.adoc index a2febaab0..b1bc2d3b8 100644 --- a/1-formats/a2ml/state/README.adoc +++ b/1-formats/a2ml/state/README.adoc @@ -187,9 +187,9 @@ updated = "2025-12-08" * `README.adoc` - This documentation * `USAGE.adoc` - Comprehensive usage guide * `CHANGELOG.adoc` - Version history -* `CONTRIBUTING.adoc` - Contribution guidelines +* `3-practice/CONTRIBUTING.adoc` - Contribution guidelines * `0-canon/GOVERNANCE.adoc` - Project governance -* `CODE_OF_CONDUCT.adoc` - Community standards +* `3-practice/CODE_OF_CONDUCT.adoc` - Community standards === Infrastructure diff --git a/1-formats/a2ml/state/spec/README.adoc b/1-formats/a2ml/state/spec/README.adoc index d29b73959..a459e70ac 100644 --- a/1-formats/a2ml/state/spec/README.adoc +++ b/1-formats/a2ml/state/spec/README.adoc @@ -98,7 +98,7 @@ The ABNF grammar can be used with ABNF parser generators: === Contributing -See link:../CONTRIBUTING.adoc[CONTRIBUTING.adoc] for contribution guidelines. +See link:../CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for contribution guidelines. Specification changes require: diff --git a/1-formats/contractiles/must/Mustfile b/1-formats/contractiles/must/Mustfile index 85ea046f8..c5742bc77 100644 --- a/1-formats/contractiles/must/Mustfile +++ b/1-formats/contractiles/must/Mustfile @@ -41,5 +41,5 @@ checks: run: "bash -uc '! rg -rn \"REPLACE-WITH|PLMP-1.0-or-later\" --type-not binary . | rg .'" - name: tooling-version-integrity - description: "Installed just must satisfy the import? floor (>= 1.19.0). Dependency-free; proves the running just is new enough — the burble#39 invariant an in-file guard cannot enforce. See standards TOOLING-VERSION-INTEGRITY-POLICY.adoc." + description: "Installed just must satisfy the import? floor (>= 1.19.0). Dependency-free; proves the running just is new enough — the burble#39 invariant an in-file guard cannot enforce. See standards 3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc." run: "bash -uc 'command -v just >/dev/null 2>&1 || exit 0; jv=$(just --version 2>/dev/null | cut -d\" \" -f2); test -n \"$jv\" || { echo \"just present, version unreadable\"; exit 1; }; maj=${jv%%.*}; rest=${jv#*.}; min=${rest%%.*}; { [ \"$maj\" -gt 1 ] || { [ \"$maj\" -eq 1 ] && [ \"$min\" -ge 19 ]; }; } || { echo \"just $jv < 1.19.0 import? unsupported\"; exit 1; }'" diff --git a/1-formats/k9/CONTRIBUTING.adoc b/1-formats/k9/CONTRIBUTING.adoc index 60f195625..ee610a557 100644 --- a/1-formats/k9/CONTRIBUTING.adoc +++ b/1-formats/k9/CONTRIBUTING.adoc @@ -32,7 +32,7 @@ suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── MAINTAINERS.md ├── -README.adoc ├── SECURITY.md ├── guix.scm # Guix manifest (Perimeter 1) └── +README.adoc ├── 3-practice/SECURITY.md ├── guix.scm # Guix manifest (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/1-formats/k9/DOGFOODING-OPPORTUNITIES.adoc b/1-formats/k9/DOGFOODING-OPPORTUNITIES.adoc index 40a65eb53..14c3658f3 100644 --- a/1-formats/k9/DOGFOODING-OPPORTUNITIES.adoc +++ b/1-formats/k9/DOGFOODING-OPPORTUNITIES.adoc @@ -193,7 +193,7 @@ trust_requirements = { ], required_files = [ - "SECURITY.md", + "3-practice/SECURITY.md", "LICENSE", ".machine_readable/STATE.scm" ], @@ -543,7 +543,7 @@ repo_health = { files = [ "LICENSE", - "SECURITY.md", + "3-practice/SECURITY.md", "README.adoc", ".machine_readable/STATE.scm" ] diff --git a/1-formats/k9/README.adoc b/1-formats/k9/README.adoc index 599388754..435bcba84 100644 --- a/1-formats/k9/README.adoc +++ b/1-formats/k9/README.adoc @@ -145,7 +145,7 @@ K9 takes security seriously. Self-executing components require careful design an * **Before using K9:** Read link:docs/SECURITY-BEST-PRACTICES.adoc[Security Best Practices] * **Common questions:** See link:docs/SECURITY-FAQ.adoc[Security FAQ] -* **Report vulnerabilities:** See link:SECURITY.md[Security Policy] +* **Report vulnerabilities:** See link:3-practice/SECURITY.md[Security Policy] **For Decision Makers:** diff --git a/1-formats/k9/docs/SECURITY-BEST-PRACTICES.adoc b/1-formats/k9/docs/SECURITY-BEST-PRACTICES.adoc index 4c6b33502..96994531e 100644 --- a/1-formats/k9/docs/SECURITY-BEST-PRACTICES.adoc +++ b/1-formats/k9/docs/SECURITY-BEST-PRACTICES.adoc @@ -12,7 +12,7 @@ **Related Documentation:** -- link:../SECURITY.md[SECURITY.md] - Vulnerability reporting policy +- link:../SECURITY.md[3-practice/SECURITY.md] - Vulnerability reporting policy - link:SECURITY-FAQ.adoc[SECURITY-FAQ.adoc] - Common security questions - link:SECURITY-ROADMAP.adoc[SECURITY-ROADMAP.adoc] - Security implementation timeline - link:SECURITY-FOR-DECISION-MAKERS.adoc[SECURITY-FOR-DECISION-MAKERS.adoc] - Executive summary @@ -257,7 +257,7 @@ just --list --justfile component.k9.ncl 1. **STOP immediately** 2. Do not proceed with execution 3. Report to component author -4. If potentially malicious, report to SECURITY.md contacts +4. If potentially malicious, report to 3-practice/SECURITY.md contacts === Red Flags to Watch For @@ -1093,7 +1093,7 @@ k9-trust author.pub == Additional Resources -- **SECURITY.md** - Vulnerability reporting policy +- **3-practice/SECURITY.md** - Vulnerability reporting policy - **SECURITY-FAQ.adoc** - Common security questions answered - **SECURITY-ROADMAP.adoc** - Planned security improvements - **SECURITY-FOR-DECISION-MAKERS.adoc** - Executive summary for managers diff --git a/1-formats/k9/docs/SECURITY-FAQ.adoc b/1-formats/k9/docs/SECURITY-FAQ.adoc index cd07557bb..983b185e6 100644 --- a/1-formats/k9/docs/SECURITY-FAQ.adoc +++ b/1-formats/k9/docs/SECURITY-FAQ.adoc @@ -849,7 +849,7 @@ strace -f ./must deploy 2>&1 | tee execution.log → "Open source, developed by hyperpolymath. Available for security review on GitHub." **"What's the incident response plan?"** -→ "Documented in SECURITY.md. Includes CVE disclosure, key revocation, user notification." +→ "Documented in 3-practice/SECURITY.md. Includes CVE disclosure, key revocation, user notification." --- diff --git a/2-protocols/0-ai-gatekeeper/.machine_readable/descriptiles/AGENTIC.a2ml b/2-protocols/0-ai-gatekeeper/.machine_readable/descriptiles/AGENTIC.a2ml index 28bf1d9cd..2822cbaf1 100644 --- a/2-protocols/0-ai-gatekeeper/.machine_readable/descriptiles/AGENTIC.a2ml +++ b/2-protocols/0-ai-gatekeeper/.machine_readable/descriptiles/AGENTIC.a2ml @@ -20,7 +20,7 @@ can-create-files = true # - Never use banned languages (TypeScript, Python, Go, etc.) # - Never place state files in repository root (must be in .machine_readable/) # - Never relicense an existing file, and never run an automated licence -# sweep (LICENCE-POLICY.adoc A2). New files get correct SPDX from birth. +# sweep (3-practice/LICENCE-POLICY.adoc A2). New files get correct SPDX from birth. # - Never assume a licence. Read standards/LICENCE-POLICY.adoc: Rule 1 # defaults to MPL-2.0 (code) / CC-BY-SA-4.0 (prose), but Rule 3 # (co-developed), Rule 4 (network-deployed services) and Rule 5 diff --git a/2-protocols/0-ai-gatekeeper/CONTRIBUTING.adoc b/2-protocols/0-ai-gatekeeper/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/2-protocols/0-ai-gatekeeper/CONTRIBUTING.adoc +++ b/2-protocols/0-ai-gatekeeper/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/2-protocols/avow/BINDING.adoc b/2-protocols/avow/BINDING.adoc index eb2aad6dc..be9348b94 100644 --- a/2-protocols/avow/BINDING.adoc +++ b/2-protocols/avow/BINDING.adoc @@ -15,7 +15,7 @@ spec, source, docs, tests, and governance. == Standards this component opts into -* `LICENCE-POLICY.adoc` — canonical MPL-2.0 (code) / CC-BY-SA-4.0 (docs) pair +* `3-practice/LICENCE-POLICY.adoc` — canonical MPL-2.0 (code) / CC-BY-SA-4.0 (docs) pair * Reusable CI workflows: Scorecard, Hypatia scan, Governance bundle * `.machine_readable/contractiles/` obligation-typing convention diff --git a/2-protocols/axel/CONTRIBUTING.adoc b/2-protocols/axel/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/2-protocols/axel/CONTRIBUTING.adoc +++ b/2-protocols/axel/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/CODEOWNERS-POLICY.adoc b/3-practice/CODEOWNERS-POLICY.adoc similarity index 95% rename from CODEOWNERS-POLICY.adoc rename to 3-practice/CODEOWNERS-POLICY.adoc index 835cd5b45..48ff7c0af 100644 --- a/CODEOWNERS-POLICY.adoc +++ b/3-practice/CODEOWNERS-POLICY.adoc @@ -65,7 +65,7 @@ done without the co-owner's (or repo lead's) explicit confirmation. ---- # SPDX-License-Identifier: MPL-2.0 # Solo-maintained hyperpolymath repo: no owner lines by policy. -# See hyperpolymath/standards CODEOWNERS-POLICY.adoc (Rule 1). +# See hyperpolymath/standards 3-practice/CODEOWNERS-POLICY.adoc (Rule 1). # Sole-maintainer review is moot; SPDX headers carry attribution. ---- @@ -147,6 +147,6 @@ unless every listed owner is a genuine co-owner (Rule 2). == See Also * link:https://github.com/hyperpolymath/standards/issues/55[standards#55] — originating decision -* `LICENCE-POLICY.adoc` (this directory) — companion canonical policy; SPDX headers cover attribution -* `MAINTAINERS.adoc` (this directory) — maintainer-of-record (separate from CODEOWNERS auto-ping) +* `3-practice/LICENCE-POLICY.adoc` (this directory) — companion canonical policy; SPDX headers cover attribution +* `3-practice/MAINTAINERS.adoc` (this directory) — maintainer-of-record (separate from CODEOWNERS auto-ping) * link:https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners[GitHub: About code owners] diff --git a/CODE_OF_CONDUCT.adoc b/3-practice/CODE_OF_CONDUCT.adoc similarity index 100% rename from CODE_OF_CONDUCT.adoc rename to 3-practice/CODE_OF_CONDUCT.adoc diff --git a/CONTRIBUTING.adoc b/3-practice/CONTRIBUTING.adoc similarity index 97% rename from CONTRIBUTING.adoc rename to 3-practice/CONTRIBUTING.adoc index 58d24f7b2..a60ff4b3c 100644 --- a/CONTRIBUTING.adoc +++ b/3-practice/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── guix.scm # Guix manifest +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── guix.scm # Guix manifest (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/LANGUAGE-POLICY.adoc b/3-practice/LANGUAGE-POLICY.adoc similarity index 98% rename from LANGUAGE-POLICY.adoc rename to 3-practice/LANGUAGE-POLICY.adoc index 19524f3f9..80c25f84c 100644 --- a/LANGUAGE-POLICY.adoc +++ b/3-practice/LANGUAGE-POLICY.adoc @@ -150,7 +150,7 @@ own SPDX header said `MPL-2.0` — one package definition copied estate-wide, carrying another project's identity and licence. Both are now corrected. Use Guix's built-in licence bindings (`mpl2.0`) rather than hand-rolled licence -records. See link:LICENCE-POLICY.adoc[LICENCE-POLICY.adoc] for which licence +records. See link:3-practice/LICENCE-POLICY.adoc[3-practice/LICENCE-POLICY.adoc] for which licence applies to which repository. == 3. Banned languages diff --git a/LICENCE-POLICY.adoc b/3-practice/LICENCE-POLICY.adoc similarity index 100% rename from LICENCE-POLICY.adoc rename to 3-practice/LICENCE-POLICY.adoc diff --git a/MAINTAINERS.adoc b/3-practice/MAINTAINERS.adoc similarity index 100% rename from MAINTAINERS.adoc rename to 3-practice/MAINTAINERS.adoc diff --git a/PROOF-NEEDS.adoc b/3-practice/PROOF-NEEDS.adoc similarity index 100% rename from PROOF-NEEDS.adoc rename to 3-practice/PROOF-NEEDS.adoc diff --git a/REMOTE-URL-POLICY.adoc b/3-practice/REMOTE-URL-POLICY.adoc similarity index 98% rename from REMOTE-URL-POLICY.adoc rename to 3-practice/REMOTE-URL-POLICY.adoc index c67d18931..2abdf72bc 100644 --- a/REMOTE-URL-POLICY.adoc +++ b/3-practice/REMOTE-URL-POLICY.adoc @@ -125,7 +125,7 @@ installer) to catch tokens before they reach CI: # pre-push hook: reject token-in-URL remotes if git -C . config --get-all remote.origin.url \ | grep -qE "x-access-token:|:gho_|:ghp_|:ghs_|:github_pat_|://[^@]+:[^@]+@"; then - echo "ERROR: token-in-URL remote detected — see REMOTE-URL-POLICY.adoc" + echo "ERROR: token-in-URL remote detected — see 3-practice/REMOTE-URL-POLICY.adoc" exit 1 fi ---- diff --git a/SECURITY-ADVISORIES.adoc b/3-practice/SECURITY-ADVISORIES.adoc similarity index 100% rename from SECURITY-ADVISORIES.adoc rename to 3-practice/SECURITY-ADVISORIES.adoc diff --git a/SECURITY.adoc b/3-practice/SECURITY.adoc similarity index 100% rename from SECURITY.adoc rename to 3-practice/SECURITY.adoc diff --git a/SECURITY.md b/3-practice/SECURITY.md similarity index 71% rename from SECURITY.md rename to 3-practice/SECURITY.md index 4f3b055fd..ec79767a7 100644 --- a/SECURITY.md +++ b/3-practice/SECURITY.md @@ -5,11 +5,11 @@ SPDX-FileCopyrightText: 2025-2026 Jonathan D.A. Jewell # Security Policy -**The security policy for this repository lives in [`SECURITY.adoc`](SECURITY.adoc).** +**The security policy for this repository lives in [`3-practice/SECURITY.adoc`](3-practice/SECURITY.adoc).** Please read that file. It is the authoritative document and covers the GitHub Security Advisories workflow, the response timeline, and the coordinated -disclosure policy. See also [`SECURITY-ADVISORIES.adoc`](SECURITY-ADVISORIES.adoc). +disclosure policy. See also [`3-practice/SECURITY-ADVISORIES.adoc`](3-practice/SECURITY-ADVISORIES.adoc). ## Why this file exists @@ -17,19 +17,19 @@ This estate writes prose in AsciiDoc, so every community-health document here is `.adoc` — `README`, `CONTRIBUTING`, `CODE_OF_CONDUCT`, `GOVERNANCE` and `SECURITY` alike. That is a deliberate convention, not an omission. -Several tools nonetheless look for the literal filename `SECURITY.md` and +Several tools nonetheless look for the literal filename `3-practice/SECURITY.md` and report the policy as missing when they do not find it: - `hypatia/scorecard/SecurityPolicy` and `hypatia/cicd_rules/missing_requirement` raise code-scanning alerts against this repository - `.github/workflows/scorecard-enforcer.yml`'s `check-critical` job runs - `if [ ! -f "SECURITY.md" ]` and **fails on every push** without it + `if [ ! -f "3-practice/SECURITY.md" ]` and **fails on every push** without it This pointer satisfies those literal filename checks without duplicating the policy text, so there is exactly one source of truth. Do not copy the policy into this file — it will drift. The alternative fix would be to teach the Hypatia rule and the enforcer script -to accept `SECURITY.adoc`. That is the more consistent long-term answer and is +to accept `3-practice/SECURITY.adoc`. That is the more consistent long-term answer and is worth doing, but it changes two pieces of shared infrastructure rather than adding one pointer file. diff --git a/TEST-NEEDS.adoc b/3-practice/TEST-NEEDS.adoc similarity index 99% rename from TEST-NEEDS.adoc rename to 3-practice/TEST-NEEDS.adoc index 9a6283f65..bf47c7014 100644 --- a/TEST-NEEDS.adoc +++ b/3-practice/TEST-NEEDS.adoc @@ -4,7 +4,7 @@ To achieve CRG Grades B and above, projects MUST implement *Zigzag Testing* for their critical paths, following the -link:ZIGZAG-TESTING.adoc[ZIGZAG-TESTING.adoc] methodology. +link:3-practice/ZIGZAG-TESTING.adoc[3-practice/ZIGZAG-TESTING.adoc] methodology. === CRG Grade: C — ACHIEVED 2026-04-04 diff --git a/TOOLING-VERSION-INTEGRITY-POLICY.adoc b/3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc similarity index 100% rename from TOOLING-VERSION-INTEGRITY-POLICY.adoc rename to 3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc diff --git a/TRUST-DEFAULTS-POLICY.adoc b/3-practice/TRUST-DEFAULTS-POLICY.adoc similarity index 99% rename from TRUST-DEFAULTS-POLICY.adoc rename to 3-practice/TRUST-DEFAULTS-POLICY.adoc index 599c8abeb..f0ef6d4cb 100644 --- a/TRUST-DEFAULTS-POLICY.adoc +++ b/3-practice/TRUST-DEFAULTS-POLICY.adoc @@ -375,7 +375,7 @@ Names are the FIPS ones (ML-KEM, ML-DSA) in every new document; "Kyber" and implicitly; a repo that needs one records it in <> with the reason and the exit condition. * This complements - link:TOOLING-VERSION-INTEGRITY-POLICY.adoc[TOOLING-VERSION-INTEGRITY-POLICY.adoc]: + link:3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc[3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc]: Rule 1 (never install unversioned) is satisfied because mise resolves `latest` to a concrete version in `mise.lock`; Rule 2 (declare the minimum) is the `[tools]` table; Rule 5 (resolve at source) is why the refresh @@ -870,8 +870,8 @@ now dated and proposing the switch? Ruling recorded here: == Related * link:ACCESSIBILITY-DEFAULTS-POLICY.adoc[Accessibility Defaults Policy] -* link:LANGUAGE-POLICY.adoc[Language Policy] (Python ban; permitted languages) -* link:TOOLING-VERSION-INTEGRITY-POLICY.adoc[Tooling Version Integrity Policy] +* link:3-practice/LANGUAGE-POLICY.adoc[Language Policy] (Python ban; permitted languages) +* link:3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc[Tooling Version Integrity Policy] * link:0-canon/PORT-REGISTRY.adoc[Port Registry] * `.machine_readable/contractiles/trust/Trustfile.a2ml` (exemplar) * `metadatastician/authority-watch`, `metadatastician/consent-aware-web`, diff --git a/ZIGZAG-TESTING.adoc b/3-practice/ZIGZAG-TESTING.adoc similarity index 100% rename from ZIGZAG-TESTING.adoc rename to 3-practice/ZIGZAG-TESTING.adoc diff --git a/accessibility/STANDARD.a2ml b/3-practice/accessibility/STANDARD.a2ml similarity index 98% rename from accessibility/STANDARD.a2ml rename to 3-practice/accessibility/STANDARD.a2ml index 4034b031e..b91be4acc 100644 --- a/accessibility/STANDARD.a2ml +++ b/3-practice/accessibility/STANDARD.a2ml @@ -38,7 +38,7 @@ HAS is structured as a contractile system with three compliance levels: ### keyboard-navigation - description: All functionality available via keyboard - compliance: A -- probe: test -f accessibility/keyboard.ex || find . -name "*keyboard*" -type f +- probe: test -f 3-practice/accessibility/keyboard.ex || find . -name "*keyboard*" -type f - notes: Tab, arrow keys, space/enter for activation ### keyboard-shortcuts diff --git a/ai-instruction/README.adoc b/3-practice/ai-instruction/README.adoc similarity index 94% rename from ai-instruction/README.adoc rename to 3-practice/ai-instruction/README.adoc index 6c7e4cc03..25be46e9b 100644 --- a/ai-instruction/README.adoc +++ b/3-practice/ai-instruction/README.adoc @@ -1,4 +1,4 @@ -== `+ai-instruction/+` — briefing templates for large language models +== `+3-practice/ai-instruction/+` — briefing templates for large language models === Scope @@ -38,7 +38,7 @@ particular repo behaves_ — its invariants, contractiles, neurosymbolic rules, canonical file locations. It is consumed mechanically by bots at CI time and by the MCP guardian at agent session start. -This directory (`+ai-instruction/+`) is a different channel entirely: it +This directory (`+3-practice/ai-instruction/+`) is a different channel entirely: it tells _a prompter_ how to choose and structure a request to a given model tier so the output is useful. The bot fleet never reads these files; they are editorial guidance that lives alongside the other diff --git a/ai-instruction/haiku.adoc b/3-practice/ai-instruction/haiku.adoc similarity index 100% rename from ai-instruction/haiku.adoc rename to 3-practice/ai-instruction/haiku.adoc diff --git a/ai-instruction/opus.adoc b/3-practice/ai-instruction/opus.adoc similarity index 100% rename from ai-instruction/opus.adoc rename to 3-practice/ai-instruction/opus.adoc diff --git a/ai-instruction/sonnet.adoc b/3-practice/ai-instruction/sonnet.adoc similarity index 100% rename from ai-instruction/sonnet.adoc rename to 3-practice/ai-instruction/sonnet.adoc diff --git a/immaculate-guide/IMMACULATE-GUIDE.adoc b/3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc similarity index 100% rename from immaculate-guide/IMMACULATE-GUIDE.adoc rename to 3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc diff --git a/outreach/.editorconfig b/3-practice/outreach/.editorconfig similarity index 100% rename from outreach/.editorconfig rename to 3-practice/outreach/.editorconfig diff --git a/outreach/.gitattributes b/3-practice/outreach/.gitattributes similarity index 100% rename from outreach/.gitattributes rename to 3-practice/outreach/.gitattributes diff --git a/outreach/.gitignore b/3-practice/outreach/.gitignore similarity index 100% rename from outreach/.gitignore rename to 3-practice/outreach/.gitignore diff --git a/outreach/.machine_readable/descriptiles/AGENTIC.a2ml b/3-practice/outreach/.machine_readable/descriptiles/AGENTIC.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/AGENTIC.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/AGENTIC.a2ml diff --git a/outreach/.machine_readable/descriptiles/ECOSYSTEM.a2ml b/3-practice/outreach/.machine_readable/descriptiles/ECOSYSTEM.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/ECOSYSTEM.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/ECOSYSTEM.a2ml diff --git a/outreach/.machine_readable/descriptiles/META.a2ml b/3-practice/outreach/.machine_readable/descriptiles/META.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/META.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/META.a2ml diff --git a/outreach/.machine_readable/descriptiles/NEUROSYM.a2ml b/3-practice/outreach/.machine_readable/descriptiles/NEUROSYM.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/NEUROSYM.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/NEUROSYM.a2ml diff --git a/outreach/.machine_readable/descriptiles/PLAYBOOK.a2ml b/3-practice/outreach/.machine_readable/descriptiles/PLAYBOOK.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/PLAYBOOK.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/PLAYBOOK.a2ml diff --git a/outreach/.machine_readable/descriptiles/STATE.a2ml b/3-practice/outreach/.machine_readable/descriptiles/STATE.a2ml similarity index 100% rename from outreach/.machine_readable/descriptiles/STATE.a2ml rename to 3-practice/outreach/.machine_readable/descriptiles/STATE.a2ml diff --git a/outreach/CODE_OF_CONDUCT.adoc b/3-practice/outreach/CODE_OF_CONDUCT.adoc similarity index 100% rename from outreach/CODE_OF_CONDUCT.adoc rename to 3-practice/outreach/CODE_OF_CONDUCT.adoc diff --git a/outreach/CONTRIBUTING.adoc b/3-practice/outreach/CONTRIBUTING.adoc similarity index 96% rename from outreach/CONTRIBUTING.adoc rename to 3-practice/outreach/CONTRIBUTING.adoc index e301a8fad..e87a283a5 100644 --- a/outreach/CONTRIBUTING.adoc +++ b/3-practice/outreach/CONTRIBUTING.adoc @@ -32,7 +32,7 @@ specs (Perimeter 2) │ └── proposals/ # RFCs (Perimeter 3) ├── exam (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/outreach/LICENSE b/3-practice/outreach/LICENSE similarity index 100% rename from outreach/LICENSE rename to 3-practice/outreach/LICENSE diff --git a/outreach/SECURITY.adoc b/3-practice/outreach/SECURITY.adoc similarity index 100% rename from outreach/SECURITY.adoc rename to 3-practice/outreach/SECURITY.adoc diff --git a/outreach/blog-post-a2ml-attested-markup.adoc b/3-practice/outreach/blog-post-a2ml-attested-markup.adoc similarity index 100% rename from outreach/blog-post-a2ml-attested-markup.adoc rename to 3-practice/outreach/blog-post-a2ml-attested-markup.adoc diff --git a/outreach/blog-post-meta-dogfooding-k9.adoc b/3-practice/outreach/blog-post-meta-dogfooding-k9.adoc similarity index 100% rename from outreach/blog-post-meta-dogfooding-k9.adoc rename to 3-practice/outreach/blog-post-meta-dogfooding-k9.adoc diff --git a/outreach/demo-script-k9-meta-dogfooding.adoc b/3-practice/outreach/demo-script-k9-meta-dogfooding.adoc similarity index 100% rename from outreach/demo-script-k9-meta-dogfooding.adoc rename to 3-practice/outreach/demo-script-k9-meta-dogfooding.adoc diff --git a/outreach/hn-post-a2ml.adoc b/3-practice/outreach/hn-post-a2ml.adoc similarity index 100% rename from outreach/hn-post-a2ml.adoc rename to 3-practice/outreach/hn-post-a2ml.adoc diff --git a/outreach/hn-post-k9.adoc b/3-practice/outreach/hn-post-k9.adoc similarity index 100% rename from outreach/hn-post-k9.adoc rename to 3-practice/outreach/hn-post-k9.adoc diff --git a/outreach/nickel-community-k9-announcement.adoc b/3-practice/outreach/nickel-community-k9-announcement.adoc similarity index 100% rename from outreach/nickel-community-k9-announcement.adoc rename to 3-practice/outreach/nickel-community-k9-announcement.adoc diff --git a/outreach/reddit-post-a2ml.adoc b/3-practice/outreach/reddit-post-a2ml.adoc similarity index 100% rename from outreach/reddit-post-a2ml.adoc rename to 3-practice/outreach/reddit-post-a2ml.adoc diff --git a/outreach/reddit-post-k9.adoc b/3-practice/outreach/reddit-post-k9.adoc similarity index 100% rename from outreach/reddit-post-k9.adoc rename to 3-practice/outreach/reddit-post-k9.adoc diff --git a/outreach/talk-proposal-icfp-ml-workshop-a2ml.adoc b/3-practice/outreach/talk-proposal-icfp-ml-workshop-a2ml.adoc similarity index 100% rename from outreach/talk-proposal-icfp-ml-workshop-a2ml.adoc rename to 3-practice/outreach/talk-proposal-icfp-ml-workshop-a2ml.adoc diff --git a/outreach/talk-proposal-strange-loop-k9.adoc b/3-practice/outreach/talk-proposal-strange-loop-k9.adoc similarity index 100% rename from outreach/talk-proposal-strange-loop-k9.adoc rename to 3-practice/outreach/talk-proposal-strange-loop-k9.adoc diff --git a/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc b/3-practice/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc similarity index 100% rename from publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc rename to 3-practice/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc diff --git a/publication-pre-flight/PREFLIGHT.adoc b/3-practice/publication-pre-flight/PREFLIGHT.adoc similarity index 100% rename from publication-pre-flight/PREFLIGHT.adoc rename to 3-practice/publication-pre-flight/PREFLIGHT.adoc diff --git a/publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc b/3-practice/publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc similarity index 100% rename from publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc rename to 3-practice/publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc diff --git a/release-pre-flight/V1-GATE.adoc b/3-practice/release-pre-flight/V1-GATE.adoc similarity index 100% rename from release-pre-flight/V1-GATE.adoc rename to 3-practice/release-pre-flight/V1-GATE.adoc diff --git a/release-pre-flight/v1-audit.sh b/3-practice/release-pre-flight/v1-audit.sh similarity index 99% rename from release-pre-flight/v1-audit.sh rename to 3-practice/release-pre-flight/v1-audit.sh index 44817edfb..1af4b1aa3 100755 --- a/release-pre-flight/v1-audit.sh +++ b/3-practice/release-pre-flight/v1-audit.sh @@ -42,9 +42,9 @@ EXCLUDES=( --glob '!**/.cache/**' --glob '!**/.jj/**' --glob '!**/release-pre-flight/**' - --glob '!release-pre-flight/**' + --glob '!3-practice/release-pre-flight/**' --glob '!**/publication-pre-flight/**' - --glob '!publication-pre-flight/**' + --glob '!3-practice/publication-pre-flight/**' --glob '!**/docs/reports/audit/**' --glob '!docs/reports/audit/**' --glob '!**/PROOF-NEEDS.md' diff --git a/session-management-standards/CONCURRENT-WRITE-COLLISION-PROTOCOL.adoc b/3-practice/session-management-standards/CONCURRENT-WRITE-COLLISION-PROTOCOL.adoc similarity index 100% rename from session-management-standards/CONCURRENT-WRITE-COLLISION-PROTOCOL.adoc rename to 3-practice/session-management-standards/CONCURRENT-WRITE-COLLISION-PROTOCOL.adoc diff --git a/session-management-standards/README.adoc b/3-practice/session-management-standards/README.adoc similarity index 98% rename from session-management-standards/README.adoc rename to 3-practice/session-management-standards/README.adoc index 7b1eb80d1..56cab7fdf 100644 --- a/session-management-standards/README.adoc +++ b/3-practice/session-management-standards/README.adoc @@ -58,7 +58,7 @@ tables, and lists, ensuring full context transfer between sessions. [source,text] ---- -session-management-standards/ +3-practice/session-management-standards/ README.adoc SHARED-CONTINUITY-CORE.adoc # cross-cutting CONCURRENT-WRITE-COLLISION-PROTOCOL.adoc # cross-cutting diff --git a/session-management-standards/SHARED-CONTINUITY-CORE.adoc b/3-practice/session-management-standards/SHARED-CONTINUITY-CORE.adoc similarity index 100% rename from session-management-standards/SHARED-CONTINUITY-CORE.adoc rename to 3-practice/session-management-standards/SHARED-CONTINUITY-CORE.adoc diff --git a/session-management-standards/adoption-and-integration-guide/GUIDE.adoc b/3-practice/session-management-standards/adoption-and-integration-guide/GUIDE.adoc similarity index 100% rename from session-management-standards/adoption-and-integration-guide/GUIDE.adoc rename to 3-practice/session-management-standards/adoption-and-integration-guide/GUIDE.adoc diff --git a/session-management-standards/continuity/checkpoint-before-major-change/CHECKLIST.adoc b/3-practice/session-management-standards/continuity/checkpoint-before-major-change/CHECKLIST.adoc similarity index 100% rename from session-management-standards/continuity/checkpoint-before-major-change/CHECKLIST.adoc rename to 3-practice/session-management-standards/continuity/checkpoint-before-major-change/CHECKLIST.adoc diff --git a/session-management-standards/continuity/checkpoint-before-major-change/PROTOCOL.k9 b/3-practice/session-management-standards/continuity/checkpoint-before-major-change/PROTOCOL.k9 similarity index 100% rename from session-management-standards/continuity/checkpoint-before-major-change/PROTOCOL.k9 rename to 3-practice/session-management-standards/continuity/checkpoint-before-major-change/PROTOCOL.k9 diff --git a/session-management-standards/continuity/checkpoint-before-major-change/STATE-template.a2ml b/3-practice/session-management-standards/continuity/checkpoint-before-major-change/STATE-template.a2ml similarity index 100% rename from session-management-standards/continuity/checkpoint-before-major-change/STATE-template.a2ml rename to 3-practice/session-management-standards/continuity/checkpoint-before-major-change/STATE-template.a2ml diff --git a/session-management-standards/continuity/emergency-termination/CHECKLIST.adoc b/3-practice/session-management-standards/continuity/emergency-termination/CHECKLIST.adoc similarity index 100% rename from session-management-standards/continuity/emergency-termination/CHECKLIST.adoc rename to 3-practice/session-management-standards/continuity/emergency-termination/CHECKLIST.adoc diff --git a/session-management-standards/continuity/emergency-termination/PROTOCOL.k9 b/3-practice/session-management-standards/continuity/emergency-termination/PROTOCOL.k9 similarity index 100% rename from session-management-standards/continuity/emergency-termination/PROTOCOL.k9 rename to 3-practice/session-management-standards/continuity/emergency-termination/PROTOCOL.k9 diff --git a/session-management-standards/continuity/emergency-termination/STATE-template.a2ml b/3-practice/session-management-standards/continuity/emergency-termination/STATE-template.a2ml similarity index 100% rename from session-management-standards/continuity/emergency-termination/STATE-template.a2ml rename to 3-practice/session-management-standards/continuity/emergency-termination/STATE-template.a2ml diff --git a/session-management-standards/continuity/planned-session-close/CHECKLIST.adoc b/3-practice/session-management-standards/continuity/planned-session-close/CHECKLIST.adoc similarity index 100% rename from session-management-standards/continuity/planned-session-close/CHECKLIST.adoc rename to 3-practice/session-management-standards/continuity/planned-session-close/CHECKLIST.adoc diff --git a/session-management-standards/continuity/planned-session-close/EXAMPLE-FILLED-IN.adoc b/3-practice/session-management-standards/continuity/planned-session-close/EXAMPLE-FILLED-IN.adoc similarity index 100% rename from session-management-standards/continuity/planned-session-close/EXAMPLE-FILLED-IN.adoc rename to 3-practice/session-management-standards/continuity/planned-session-close/EXAMPLE-FILLED-IN.adoc diff --git a/session-management-standards/continuity/planned-session-close/PROTOCOL.k9 b/3-practice/session-management-standards/continuity/planned-session-close/PROTOCOL.k9 similarity index 100% rename from session-management-standards/continuity/planned-session-close/PROTOCOL.k9 rename to 3-practice/session-management-standards/continuity/planned-session-close/PROTOCOL.k9 diff --git a/session-management-standards/continuity/planned-session-close/STATE-template.a2ml b/3-practice/session-management-standards/continuity/planned-session-close/STATE-template.a2ml similarity index 100% rename from session-management-standards/continuity/planned-session-close/STATE-template.a2ml rename to 3-practice/session-management-standards/continuity/planned-session-close/STATE-template.a2ml diff --git a/session-management-standards/continuity/recovery-operation/CHECKLIST.adoc b/3-practice/session-management-standards/continuity/recovery-operation/CHECKLIST.adoc similarity index 100% rename from session-management-standards/continuity/recovery-operation/CHECKLIST.adoc rename to 3-practice/session-management-standards/continuity/recovery-operation/CHECKLIST.adoc diff --git a/session-management-standards/continuity/recovery-operation/PROTOCOL.k9 b/3-practice/session-management-standards/continuity/recovery-operation/PROTOCOL.k9 similarity index 100% rename from session-management-standards/continuity/recovery-operation/PROTOCOL.k9 rename to 3-practice/session-management-standards/continuity/recovery-operation/PROTOCOL.k9 diff --git a/session-management-standards/continuity/recovery-operation/STATE-template.a2ml b/3-practice/session-management-standards/continuity/recovery-operation/STATE-template.a2ml similarity index 100% rename from session-management-standards/continuity/recovery-operation/STATE-template.a2ml rename to 3-practice/session-management-standards/continuity/recovery-operation/STATE-template.a2ml diff --git a/session-management-standards/continuity/repo-intake/CHECKLIST.adoc b/3-practice/session-management-standards/continuity/repo-intake/CHECKLIST.adoc similarity index 100% rename from session-management-standards/continuity/repo-intake/CHECKLIST.adoc rename to 3-practice/session-management-standards/continuity/repo-intake/CHECKLIST.adoc diff --git a/session-management-standards/continuity/repo-intake/PROTOCOL.k9 b/3-practice/session-management-standards/continuity/repo-intake/PROTOCOL.k9 similarity index 100% rename from session-management-standards/continuity/repo-intake/PROTOCOL.k9 rename to 3-practice/session-management-standards/continuity/repo-intake/PROTOCOL.k9 diff --git a/session-management-standards/continuity/repo-intake/STATE-template.a2ml b/3-practice/session-management-standards/continuity/repo-intake/STATE-template.a2ml similarity index 100% rename from session-management-standards/continuity/repo-intake/STATE-template.a2ml rename to 3-practice/session-management-standards/continuity/repo-intake/STATE-template.a2ml diff --git a/session-management-standards/handover/collaborative-transfer/CHECKLIST.adoc b/3-practice/session-management-standards/handover/collaborative-transfer/CHECKLIST.adoc similarity index 100% rename from session-management-standards/handover/collaborative-transfer/CHECKLIST.adoc rename to 3-practice/session-management-standards/handover/collaborative-transfer/CHECKLIST.adoc diff --git a/session-management-standards/handover/collaborative-transfer/PROTOCOL.k9 b/3-practice/session-management-standards/handover/collaborative-transfer/PROTOCOL.k9 similarity index 100% rename from session-management-standards/handover/collaborative-transfer/PROTOCOL.k9 rename to 3-practice/session-management-standards/handover/collaborative-transfer/PROTOCOL.k9 diff --git a/session-management-standards/handover/collaborative-transfer/STATE-template.a2ml b/3-practice/session-management-standards/handover/collaborative-transfer/STATE-template.a2ml similarity index 100% rename from session-management-standards/handover/collaborative-transfer/STATE-template.a2ml rename to 3-practice/session-management-standards/handover/collaborative-transfer/STATE-template.a2ml diff --git a/session-management-standards/handover/full-transfer/CHECKLIST.adoc b/3-practice/session-management-standards/handover/full-transfer/CHECKLIST.adoc similarity index 100% rename from session-management-standards/handover/full-transfer/CHECKLIST.adoc rename to 3-practice/session-management-standards/handover/full-transfer/CHECKLIST.adoc diff --git a/session-management-standards/handover/full-transfer/PROTOCOL.k9 b/3-practice/session-management-standards/handover/full-transfer/PROTOCOL.k9 similarity index 100% rename from session-management-standards/handover/full-transfer/PROTOCOL.k9 rename to 3-practice/session-management-standards/handover/full-transfer/PROTOCOL.k9 diff --git a/session-management-standards/handover/full-transfer/STATE-template.a2ml b/3-practice/session-management-standards/handover/full-transfer/STATE-template.a2ml similarity index 100% rename from session-management-standards/handover/full-transfer/STATE-template.a2ml rename to 3-practice/session-management-standards/handover/full-transfer/STATE-template.a2ml diff --git a/session-management-standards/handover/human-transfer/CHECKLIST.adoc b/3-practice/session-management-standards/handover/human-transfer/CHECKLIST.adoc similarity index 100% rename from session-management-standards/handover/human-transfer/CHECKLIST.adoc rename to 3-practice/session-management-standards/handover/human-transfer/CHECKLIST.adoc diff --git a/session-management-standards/handover/human-transfer/PROTOCOL.k9 b/3-practice/session-management-standards/handover/human-transfer/PROTOCOL.k9 similarity index 100% rename from session-management-standards/handover/human-transfer/PROTOCOL.k9 rename to 3-practice/session-management-standards/handover/human-transfer/PROTOCOL.k9 diff --git a/session-management-standards/handover/human-transfer/STATE-template.a2ml b/3-practice/session-management-standards/handover/human-transfer/STATE-template.a2ml similarity index 100% rename from session-management-standards/handover/human-transfer/STATE-template.a2ml rename to 3-practice/session-management-standards/handover/human-transfer/STATE-template.a2ml diff --git a/session-management-standards/handover/model-transfer/CHECKLIST.adoc b/3-practice/session-management-standards/handover/model-transfer/CHECKLIST.adoc similarity index 100% rename from session-management-standards/handover/model-transfer/CHECKLIST.adoc rename to 3-practice/session-management-standards/handover/model-transfer/CHECKLIST.adoc diff --git a/session-management-standards/handover/model-transfer/PROTOCOL.k9 b/3-practice/session-management-standards/handover/model-transfer/PROTOCOL.k9 similarity index 100% rename from session-management-standards/handover/model-transfer/PROTOCOL.k9 rename to 3-practice/session-management-standards/handover/model-transfer/PROTOCOL.k9 diff --git a/session-management-standards/handover/model-transfer/STATE-template.a2ml b/3-practice/session-management-standards/handover/model-transfer/STATE-template.a2ml similarity index 100% rename from session-management-standards/handover/model-transfer/STATE-template.a2ml rename to 3-practice/session-management-standards/handover/model-transfer/STATE-template.a2ml diff --git a/session-management-standards/src/ui/tea/system_update_gui.affine b/3-practice/session-management-standards/src/ui/tea/system_update_gui.affine similarity index 100% rename from session-management-standards/src/ui/tea/system_update_gui.affine rename to 3-practice/session-management-standards/src/ui/tea/system_update_gui.affine diff --git a/session-management-standards/templates/EMERGENCY-CHECKPOINT.adoc b/3-practice/session-management-standards/templates/EMERGENCY-CHECKPOINT.adoc similarity index 100% rename from session-management-standards/templates/EMERGENCY-CHECKPOINT.adoc rename to 3-practice/session-management-standards/templates/EMERGENCY-CHECKPOINT.adoc diff --git a/session-management-standards/templates/HANDOVER-REPORT.adoc b/3-practice/session-management-standards/templates/HANDOVER-REPORT.adoc similarity index 100% rename from session-management-standards/templates/HANDOVER-REPORT.adoc rename to 3-practice/session-management-standards/templates/HANDOVER-REPORT.adoc diff --git a/session-management-standards/templates/MAINTENANCE_REPORT.adoc b/3-practice/session-management-standards/templates/MAINTENANCE_REPORT.adoc similarity index 100% rename from session-management-standards/templates/MAINTENANCE_REPORT.adoc rename to 3-practice/session-management-standards/templates/MAINTENANCE_REPORT.adoc diff --git a/session-management-standards/templates/NEXT_STEPS.adoc b/3-practice/session-management-standards/templates/NEXT_STEPS.adoc similarity index 100% rename from session-management-standards/templates/NEXT_STEPS.adoc rename to 3-practice/session-management-standards/templates/NEXT_STEPS.adoc diff --git a/session-management-standards/templates/RECOVERY-PLAN.adoc b/3-practice/session-management-standards/templates/RECOVERY-PLAN.adoc similarity index 100% rename from session-management-standards/templates/RECOVERY-PLAN.adoc rename to 3-practice/session-management-standards/templates/RECOVERY-PLAN.adoc diff --git a/session-management-standards/templates/RELEASE_AUDIT.adoc b/3-practice/session-management-standards/templates/RELEASE_AUDIT.adoc similarity index 100% rename from session-management-standards/templates/RELEASE_AUDIT.adoc rename to 3-practice/session-management-standards/templates/RELEASE_AUDIT.adoc diff --git a/session-management-standards/templates/SESSION_STATE.adoc b/3-practice/session-management-standards/templates/SESSION_STATE.adoc similarity index 100% rename from session-management-standards/templates/SESSION_STATE.adoc rename to 3-practice/session-management-standards/templates/SESSION_STATE.adoc diff --git a/session-management-standards/templates/SESSION_SUMMARY.adoc b/3-practice/session-management-standards/templates/SESSION_SUMMARY.adoc similarity index 100% rename from session-management-standards/templates/SESSION_SUMMARY.adoc rename to 3-practice/session-management-standards/templates/SESSION_SUMMARY.adoc diff --git a/session-management-standards/templates/SUBSTANTIAL_COMPLETION_REPORT.adoc b/3-practice/session-management-standards/templates/SUBSTANTIAL_COMPLETION_REPORT.adoc similarity index 100% rename from session-management-standards/templates/SUBSTANTIAL_COMPLETION_REPORT.adoc rename to 3-practice/session-management-standards/templates/SUBSTANTIAL_COMPLETION_REPORT.adoc diff --git a/session-management-standards/verify/maintenance-sweep/CHECKLIST.adoc b/3-practice/session-management-standards/verify/maintenance-sweep/CHECKLIST.adoc similarity index 100% rename from session-management-standards/verify/maintenance-sweep/CHECKLIST.adoc rename to 3-practice/session-management-standards/verify/maintenance-sweep/CHECKLIST.adoc diff --git a/session-management-standards/verify/maintenance-sweep/PROTOCOL.k9 b/3-practice/session-management-standards/verify/maintenance-sweep/PROTOCOL.k9 similarity index 100% rename from session-management-standards/verify/maintenance-sweep/PROTOCOL.k9 rename to 3-practice/session-management-standards/verify/maintenance-sweep/PROTOCOL.k9 diff --git a/session-management-standards/verify/maintenance-sweep/STATE-template.a2ml b/3-practice/session-management-standards/verify/maintenance-sweep/STATE-template.a2ml similarity index 100% rename from session-management-standards/verify/maintenance-sweep/STATE-template.a2ml rename to 3-practice/session-management-standards/verify/maintenance-sweep/STATE-template.a2ml diff --git a/session-management-standards/verify/release-audit/CHECKLIST.adoc b/3-practice/session-management-standards/verify/release-audit/CHECKLIST.adoc similarity index 100% rename from session-management-standards/verify/release-audit/CHECKLIST.adoc rename to 3-practice/session-management-standards/verify/release-audit/CHECKLIST.adoc diff --git a/session-management-standards/verify/release-audit/PROTOCOL.k9 b/3-practice/session-management-standards/verify/release-audit/PROTOCOL.k9 similarity index 100% rename from session-management-standards/verify/release-audit/PROTOCOL.k9 rename to 3-practice/session-management-standards/verify/release-audit/PROTOCOL.k9 diff --git a/session-management-standards/verify/release-audit/STATE-template.a2ml b/3-practice/session-management-standards/verify/release-audit/STATE-template.a2ml similarity index 100% rename from session-management-standards/verify/release-audit/STATE-template.a2ml rename to 3-practice/session-management-standards/verify/release-audit/STATE-template.a2ml diff --git a/session-management-standards/verify/substantial-completion/CHECKLIST.adoc b/3-practice/session-management-standards/verify/substantial-completion/CHECKLIST.adoc similarity index 100% rename from session-management-standards/verify/substantial-completion/CHECKLIST.adoc rename to 3-practice/session-management-standards/verify/substantial-completion/CHECKLIST.adoc diff --git a/session-management-standards/verify/substantial-completion/PROTOCOL.k9 b/3-practice/session-management-standards/verify/substantial-completion/PROTOCOL.k9 similarity index 100% rename from session-management-standards/verify/substantial-completion/PROTOCOL.k9 rename to 3-practice/session-management-standards/verify/substantial-completion/PROTOCOL.k9 diff --git a/session-management-standards/verify/substantial-completion/STATE-template.a2ml b/3-practice/session-management-standards/verify/substantial-completion/STATE-template.a2ml similarity index 100% rename from session-management-standards/verify/substantial-completion/STATE-template.a2ml rename to 3-practice/session-management-standards/verify/substantial-completion/STATE-template.a2ml diff --git a/testing-and-benchmarking/TESTING-TAXONOMY.adoc b/3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc similarity index 100% rename from testing-and-benchmarking/TESTING-TAXONOMY.adoc rename to 3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc diff --git a/Justfile b/Justfile index 86797dcdd..3cc9aa386 100644 --- a/Justfile +++ b/Justfile @@ -5,7 +5,7 @@ # requires: just >= 1.19.0 (import? optional-import support) # Enforced by the `tooling-version-integrity` must-check, not self- # enforcing: import? fails at parse time before any recipe can guard it. -# See TOOLING-VERSION-INTEGRITY-POLICY.adoc (root cause: burble#39). +# See 3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc (root cause: burble#39). default: @just --list diff --git a/PALIMPSEST.adoc b/PALIMPSEST.adoc index e5c79eab0..fcd41a581 100644 --- a/PALIMPSEST.adoc +++ b/PALIMPSEST.adoc @@ -97,6 +97,6 @@ original code uses PMPL-1.0-or-later (falling back to MPL-2.0). == Further Reading -* `LICENCE-POLICY.adoc` — canonical policy statement (this directory) +* `3-practice/LICENCE-POLICY.adoc` — canonical policy statement (this directory) * `rhodium-standard-repositories/PALIMPSEST.adoc` — RSR integration * link:https://github.com/hyperpolymath/palimpsest-license[palimpsest-license repo] — PMPL licence text diff --git a/README.adoc b/README.adoc index baed67d8e..7c302f84d 100644 --- a/README.adoc +++ b/README.adoc @@ -82,12 +82,12 @@ This repository serves as the canonical source for policies, templates, and spec * **Language-Maturation Grades** -- link:adoption-readiness-grades/[ARG (Adoption Readiness)] + link:foundations-readiness-grades/[FRG (Foundations Readiness)] per-language profile templates; aggregated into the link:https://github.com/hyperpolymath/nextgen-languages[nextgen-languages] dashboard. TRG (Trust) + CRG (Compliance) profile templates live under each framework's `templates/` directory. * **Decriptiles Family** -- 7 machine-readable project metadata formats in A2ML (see link:1-formats/SATELLITES.a2ml[1-formats/SATELLITES.a2ml]) * **Build System** -- Mustfile/justfile (no Makefiles) -* **Stable Release Gate** -- link:release-pre-flight/V1-GATE.adoc[hard `v1.0.0` audit requirements] for all repos and multi-repo systems -* **Publication Pre-Flight** -- link:publication-pre-flight/PREFLIGHT.adoc[submission gate] plus link:publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc[HOL] and link:publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc[Zenodo] checklists -* **Session Management Standards** -- link:session-management-standards/README.adoc[canonical continuity, verify, and handover protocols] +* **Stable Release Gate** -- link:3-practice/release-pre-flight/V1-GATE.adoc[hard `v1.0.0` audit requirements] for all repos and multi-repo systems +* **Publication Pre-Flight** -- link:3-practice/publication-pre-flight/PREFLIGHT.adoc[submission gate] plus link:3-practice/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc[HOL] and link:3-practice/publication-pre-flight/ZENODO-DEPOSIT-CHECKLIST.adoc[Zenodo] checklists +* **Session Management Standards** -- link:3-practice/session-management-standards/README.adoc[canonical continuity, verify, and handover protocols] * **Contractiles / K9** -- link:1-formats/contractiles/CANONICAL-TEMPLATES.adoc[canonical Must/Trust/Dust/Intent semantics] and Kennel/Yard/Hunt guidance * **Governance Templates** -- Reusable CODE_OF_CONDUCT, CONTRIBUTING, and SECURITY documents -* **CODEOWNERS Policy** -- link:CODEOWNERS-POLICY.adoc[canonical `CODEOWNERS` rules] (no catch-all/workflow lines on solo-owned repos) +* **CODEOWNERS Policy** -- link:3-practice/CODEOWNERS-POLICY.adoc[canonical `CODEOWNERS` rules] (no catch-all/workflow lines on solo-owned repos) * **Licensing** -- MPL-2.0 (see link:LICENSE[LICENSE]); licence/SPDX changes are owner-only (see link:.claude/CLAUDE.md[.claude/CLAUDE.md]) * **Enforcement** -- CI/CD workflows and pre-commit hooks @@ -326,7 +326,7 @@ All documentation must be AsciiDoc (`.adoc`) except for GitHub-required files: **Must be .md (GitHub community health):** -* `SECURITY.md` +* `3-practice/SECURITY.md` * `CONTRIBUTING.md` (can redirect to `.adoc`) * `CODE_OF_CONDUCT.md` * `CHANGELOG.md` @@ -422,7 +422,7 @@ standards/ +-- 1-formats/A2ML-REPO-TEMPLATE.adoc # Canonical structure for -a2ml repos +-- CODE_OF_CONDUCT.md # Template +-- CONTRIBUTING.md # Template -+-- SECURITY.md # Template ++-- 3-practice/SECURITY.md # Template +-- LICENSE # MPL-2.0 +-- ROADMAP.adoc +-- README.adoc # This file diff --git a/ROADMAP.adoc b/ROADMAP.adoc index 0160c9c6f..c1f4352fc 100644 --- a/ROADMAP.adoc +++ b/ROADMAP.adoc @@ -183,7 +183,7 @@ Multi-session estate-wide migration of TypeScript to AffineScript, parallel to t |Layer |Description |Status |**Layer 1 — Policy & enforcement** -|hypatia `:typescript_detected` rule + `path_allow_prefixes` (9 carve-out classes); standards `.claude/CLAUDE.md` exemption table; `LANGUAGE-POLICY.adoc` Banned TS row; `language-policy.yml` CI gate. Layer-1 PRs: hypatia#375, hypatia#378, standards#235, standards#238, reposystem#82. +|hypatia `:typescript_detected` rule + `path_allow_prefixes` (9 carve-out classes); standards `.claude/CLAUDE.md` exemption table; `3-practice/LANGUAGE-POLICY.adoc` Banned TS row; `language-policy.yml` CI gate. Layer-1 PRs: hypatia#375, hypatia#378, standards#235, standards#238, reposystem#82. |Complete |**Layer 2 — Stdlib binding capacity** diff --git a/TOPOLOGY.adoc b/TOPOLOGY.adoc index 2bb14768e..28583408c 100644 --- a/TOPOLOGY.adoc +++ b/TOPOLOGY.adoc @@ -64,12 +64,12 @@ ____ | Spec | Home | If you want… | Hyperpolymath Estate Constitution | link:0-canon/constitution/[`+0-canon/constitution/+`] | the highest estate-level rules, authority precedence, assurance, contribution, exceptions, and known tensions | RSR — Rhodium Standard Repositories | link:rhodium-standard-repositories/[`+rhodium-standard-repositories/+`] | the repository-compliance standard every repo is graded against -| Session Management Standards | link:session-management-standards/[`+session-management-standards/+`] | continuity / verify / handover protocols +| Session Management Standards | link:3-practice/session-management-standards/[`+3-practice/session-management-standards/+`] | continuity / verify / handover protocols | DYADT — Did-You-Actually-Do-That | link:1-formats/sub-specs/did-you-actually-do-that/[`+1-formats/sub-specs/did-you-actually-do-that/+`] | post-action agent-claim verification (Tier 4 accountability) | ENSAID Config | link:1-formats/sub-specs/ensaid-config/[`+1-formats/sub-specs/ensaid-config/+`] | the ensaid configuration standard -| Accessibility Standard | link:accessibility/[`+accessibility/+`] | estate accessibility requirements -| Publication Pre-Flight | link:publication-pre-flight/[`+publication-pre-flight/+`] | submission gate (HOL + Zenodo checklists) -| Release Pre-Flight (V1 Gate) | link:release-pre-flight/[`+release-pre-flight/+`] | hard v1.0.0 audit requirements +| Accessibility Standard | link:3-practice/accessibility/[`+3-practice/accessibility/+`] | estate accessibility requirements +| Publication Pre-Flight | link:3-practice/publication-pre-flight/[`+3-practice/publication-pre-flight/+`] | submission gate (HOL + Zenodo checklists) +| Release Pre-Flight (V1 Gate) | link:3-practice/release-pre-flight/[`+3-practice/release-pre-flight/+`] | hard v1.0.0 audit requirements |=== === Readiness grading — ARG / FRG / CRG / TRG diff --git a/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml b/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml index 8d7c2025a..78a282127 100644 --- a/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml +++ b/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml @@ -77,7 +77,7 @@ (stability-posture "broadly-trial-stable") (ordinal 5) (description "Broadly adopted beta. Language has escaped its home repo. External people in unrelated organisations and contexts write real programs in it.") - (evidence-required "all C + TRG >= B estate-wide + CRG >= B per §3 component + >=100 distinct external users meeting diversity-metrics + >=6 diverse external projects use the language (TRG diversity-metrics verified) + X1 >=12 third-party libraries + X2 >=3 third-party tools (not founder-written) + X3 ecosystem-plugged (language-specific per profile) + X4 >=2 maintainers beyond founder with >=6 months sustained contribution + Δ4 deprecation policy active + >=1 deprecation cycle completed + Δ5 SECURITY.md with response demonstrated + E2 training materials used externally + continuous fuzzing >=30 days incl structure-aware + external single-party audit + SBOM + Hypatia zero Critical/High + branch protection") + (evidence-required "all C + TRG >= B estate-wide + CRG >= B per §3 component + >=100 distinct external users meeting diversity-metrics + >=6 diverse external projects use the language (TRG diversity-metrics verified) + X1 >=12 third-party libraries + X2 >=3 third-party tools (not founder-written) + X3 ecosystem-plugged (language-specific per profile) + X4 >=2 maintainers beyond founder with >=6 months sustained contribution + Δ4 deprecation policy active + >=1 deprecation cycle completed + Δ5 3-practice/SECURITY.md with response demonstrated + E2 training materials used externally + continuous fuzzing >=30 days incl structure-aware + external single-party audit + SBOM + Hypatia zero Critical/High + branch protection") (minimum-for "beta")) (grade (code A) diff --git a/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc b/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc index 5a414ae2f..7c0098599 100644 --- a/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc +++ b/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc @@ -133,7 +133,7 @@ the public artefacts an adopter encounters. The required surfaces are: * *Δ2* Package registry presence (or canonical install path) * *Δ3* Versioning policy (Semver or estate Edition system) * *Δ4* Deprecation policy and visible deprecation log -* *Δ5* Security disclosure policy (SECURITY.md, contact, response time) +* *Δ5* Security disclosure policy (3-practice/SECURITY.md, contact, response time) === 3.6 Education surface * *E1* Slide deck or talk-script suitable for a 1-hour external presentation @@ -286,7 +286,7 @@ home-context assumptions without making progress impossible. * X4 (≥ 2 maintainers beyond the founder with sustained contribution over ≥ 6 months) * Δ4 (deprecation policy active; ≥ 1 deprecation cycle completed) -* Δ5 (SECURITY.md with disclosure policy and demonstrated response) +* Δ5 (3-practice/SECURITY.md with disclosure policy and demonstrated response) * E2 (training materials for 1-day workshop) exists and has been used externally * Continuous fuzzing per TRG, 30 days minimum, including structure-aware diff --git a/adoption-readiness-grades/templates/ARG-PROFILE-TEMPLATE.adoc b/adoption-readiness-grades/templates/ARG-PROFILE-TEMPLATE.adoc index aa2a70b1c..12da2026b 100644 --- a/adoption-readiness-grades/templates/ARG-PROFILE-TEMPLATE.adoc +++ b/adoption-readiness-grades/templates/ARG-PROFILE-TEMPLATE.adoc @@ -101,7 +101,7 @@ Cross-axis rule: ARG ≤ TRG holds (currently TRG = {TRG_GRADE}, ARG = {GRADE}). | *Distribution Δ1-Δ5* | {YES/NO partial per item} -| {Release artefact URL; registry/install URL; versioning policy path; deprecation log; SECURITY.md path} +| {Release artefact URL; registry/install URL; versioning policy path; deprecation log; 3-practice/SECURITY.md path} | *Education E1-E4 (grade-dependent)* | {YES/NO partial per item} diff --git a/audits/licence-flags-2026-07.adoc b/audits/licence-flags-2026-07.adoc index bbe1c8be5..60e02efd9 100644 --- a/audits/licence-flags-2026-07.adoc +++ b/audits/licence-flags-2026-07.adoc @@ -36,7 +36,7 @@ None of the following were edited; they are surfaced for the owner to rule on. Palimpsest is a carve-out family; whether this file should carry a Palimpsest component is an owner ruling, not an audit action. Left untouched. -| `SECURITY-ADVISORIES.adoc` +| `3-practice/SECURITY-ADVISORIES.adoc` | A standing deferred `rand < 0.9.3` advisory is recorded. Not a licence matter, but flagged alongside release hygiene: renew with an expiry date or bump. (Tracked under the umbrella's release-hygiene item.) diff --git a/canon.lock b/canon.lock index 6c7a4b32a..a61a7d81f 100644 --- a/canon.lock +++ b/canon.lock @@ -115,6 +115,26 @@ # --------------------------------------------------------------------------- # +# 2026-09-17 - PATCH 2.0.3 -> 2.0.4. THE 3-PRACTICE DISTRICT. +# +# Twenty-three paths move under 3-practice/. Twenty-two of them need no law +# change: the baseline `paths` list is not capability-gated, so a community-health +# file may move without the table caring. MAINTAINERS.adoc is the exception - it +# is one of the four governance-tier rows, and the move took it out of the only +# location that row named, so the canon stopped satisfying a capability it +# declares. Exactly the drift the self-conformance job exists to catch. +# +# The ROW GAINS THE NEW LOCATION; it does not trade one for the other. Dropping +# `MAINTAINERS.adoc` would have broken every estate repo that carries it at the +# root - cadastra does - by silently reducing a documented alternative to a +# single canon-internal path. The precedent is the row above it: GOVERNANCE.adoc +# moved into 0-canon/ in the 0-canon release and `0-canon/GOVERNANCE.adoc` was +# appended the same way, for the same reason. +# +# PATCH, not MINOR: no criterion changes meaning, nothing new becomes required, +# and every previously-conforming repo still conforms. The estate gains a +# location, and loses nothing. + # 2026-09-17 - PATCH 2.0.2 -> 2.0.3. THE 0-CANON RELOCATION. # # The 0-canon district exists. The law moves into it: constitution/ becomes @@ -160,7 +180,7 @@ # A released major is immutable. Bumping `version` to a new MAJOR means the # prior major's criteria file is copied to 0-canon/rsr/archive/ and pinned # there; a freeze guard fails any PR that mutates a frozen major. -version = "2.0.3" +version = "2.0.4" spec_family = "rhodium-standard-repositories" status = "draft" # draft | stable released = "2026-09-17" @@ -169,7 +189,7 @@ authority = "0-canon/constitution/ESTATE-CONSTITUTION.adoc" # The full git ref that realises this canon. A tag alone is not sufficient # (tags move); a commit alone is not sufficient (it has no version). Both. commit = "0000000000000000000000000000000000000000" # ← fill at release -tag = "canon-v2.0.3" +tag = "canon-v2.0.4" # --------------------------------------------------------------------------- # THE ARTEFACT SET — the files that ARE the canon. @@ -186,11 +206,11 @@ criteria = { path = "0-canon/rsr/rsr-criteria-v2.a2ml", # relocated fr slot = "criteria", normative = true } gates = { path = ".machine_readable/template-capability-gates.toml", # from .machine_readable/ - sha256 = "b927ab0e54a0f75b20ca182afe4e48d26765ac486eef603bfc4a5e3d00281220", + sha256 = "b65ce75438c42d01bedf0325b9a97f1a575064866158b4340d7427fca911dd1b", slot = "gates", normative = true } applicability = { path = "0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc", - sha256 = "ecf6d7be771379a03b50bbe0d9fa98d082be0dad44738cad2eadd15514539181", + sha256 = "f99543732675f53e25b40d042a1dd1ec4c9cfe7c31d71def18a202b419c26414", slot = "applicability", normative = true } lifecycle = { path = "0-canon/rsr/SCAFFOLD-LIFECYCLE.adoc", diff --git a/component-readiness-grades/COMPONENT-READINESS-GRADES.adoc b/component-readiness-grades/COMPONENT-READINESS-GRADES.adoc index 8ed984181..fdc5269ae 100644 --- a/component-readiness-grades/COMPONENT-READINESS-GRADES.adoc +++ b/component-readiness-grades/COMPONENT-READINESS-GRADES.adoc @@ -204,7 +204,7 @@ that the component is at least inspectable and auditable while still unstable. * *Immaculate Guide compliance* (hyperpolymath projects): The repository MUST satisfy the nine principles of the Hyperpolymath Immaculate Guide -(`+immaculate-guide/IMMACULATE-GUIDE.adoc+`). Evidence recorded in +(`+3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc+`). Evidence recorded in `+.machine_readable/STATE.a2ml+` under `+(immaculate-guide-compliance ...)+`. Specifically at minimum: `+0-AI-MANIFEST.a2ml+` present, `+.tool-versions+` pins all tools, @@ -651,7 +651,7 @@ E, D, C, B, A}. . Components graded D or above satisfy RSR compliance or a documented equivalent repository discipline. 6a. Components graded D or above in hyperpolymath projects satisfy the Immaculate Guide -(`+immaculate-guide/IMMACULATE-GUIDE.adoc+`) with compliance evidence in +(`+3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc+`) with compliance evidence in `+.machine_readable/STATE.a2ml+`. . Components graded C or above have deep code and folder annotation. . Non-abstract publication claims about implementation-facing work are diff --git a/component-readiness-grades/SELF-ASSESSMENT.adoc b/component-readiness-grades/SELF-ASSESSMENT.adoc index e4afc6634..2463cfbd4 100644 --- a/component-readiness-grades/SELF-ASSESSMENT.adoc +++ b/component-readiness-grades/SELF-ASSESSMENT.adoc @@ -29,7 +29,7 @@ Assessed: 2026-04-04 |**D (RSR-Compliant)** |PASSED -|RSR scaffolding complete: LICENSE, SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, MAINTAINERS.adoc, RSR-required CI workflows (per `hypatia-rules/rsr-self-compliance.a2ml @required_workflows`) + adopted optional set, .machine_readable/, 0-AI-MANIFEST.a2ml, Justfile/Mustfile +|RSR scaffolding complete: LICENSE, 3-practice/SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, 3-practice/MAINTAINERS.adoc, RSR-required CI workflows (per `hypatia-rules/rsr-self-compliance.a2ml @required_workflows`) + adopted optional set, .machine_readable/, 0-AI-MANIFEST.a2ml, Justfile/Mustfile |**C (Self-Validated)** |PASSED diff --git a/config/gitleaks/estate-baseline.toml b/config/gitleaks/estate-baseline.toml index d1f67c003..f6d872a49 100644 --- a/config/gitleaks/estate-baseline.toml +++ b/config/gitleaks/estate-baseline.toml @@ -202,7 +202,7 @@ regexes = [ # --- public-by-definition / non-secret identifiers ------------------------ # OpenPGP 40-hex fingerprints. A fingerprint *identifies* a key; it is - # published deliberately (SECURITY.md, audit records, keyservers) and + # published deliberately (3-practice/SECURITY.md, audit records, keyservers) and # discloses nothing. Secret key *material* is PEM-armoured and is caught by # the dedicated private-key rules, which are NOT allowlisted here. '''^[A-F0-9]{40}$''', diff --git a/docs/AFFIRMATION.adoc b/docs/AFFIRMATION.adoc index 0eac8bf1d..504e3808e 100644 --- a/docs/AFFIRMATION.adoc +++ b/docs/AFFIRMATION.adoc @@ -17,7 +17,7 @@ applies; profile A (evidential) is for implementation repos. **Status: DRAFT — UNSIGNED.** This file was added to give the canon the `governance-tier` artefact trio it declared a capability for but did not carry (`docs/AUDIT.adoc` and `docs/AFFIRMATION.adoc` were both absent, while -`0-canon/GOVERNANCE.adoc` and `MAINTAINERS.adoc` were present at root). +`0-canon/GOVERNANCE.adoc` and `3-practice/MAINTAINERS.adoc` were present at root). An affirmation is *signed* by the owner. That signature is not an agent's to give. Every claim below is measured and reproducible; the attestation block at diff --git a/docs/DEBTFILE-SPEC.adoc b/docs/DEBTFILE-SPEC.adoc index 9b2661157..56b12fb3d 100644 --- a/docs/DEBTFILE-SPEC.adoc +++ b/docs/DEBTFILE-SPEC.adoc @@ -115,7 +115,7 @@ Location: `.machine_readable/Debtfile.a2ml`, one per repository. `##
` headings group entries and are otherwise ignored. The four `taxonomy-*` fields are required together only when an entry records a -departure under `testing-and-benchmarking/TESTING-TAXONOMY.adoc`; otherwise omit +departure under `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc`; otherwise omit all four. === Fields diff --git a/docs/JS-RUNTIME-POLICY.adoc b/docs/JS-RUNTIME-POLICY.adoc index 84ae4b2b1..b64cc4bf3 100644 --- a/docs/JS-RUNTIME-POLICY.adoc +++ b/docs/JS-RUNTIME-POLICY.adoc @@ -60,8 +60,8 @@ deliberate, noted decision — not a default. [IMPORTANT] ==== *Corrected 2026-08-07.* This table previously ran `Deno > Bun > pnpm > npm`, -the exact inverse of `LANGUAGE-POLICY.adoc` §1, which has been the ruling since -2026-07-29. The ordering above now matches it. `LANGUAGE-POLICY.adoc` is +the exact inverse of `3-practice/LANGUAGE-POLICY.adoc` §1, which has been the ruling since +2026-07-29. The ordering above now matches it. `3-practice/LANGUAGE-POLICY.adoc` is authoritative; if the two ever disagree again, that one wins. ==== diff --git a/docs/README-EXPLAINME-STANDARD.adoc b/docs/README-EXPLAINME-STANDARD.adoc index d4ecf629e..4ccde7257 100644 --- a/docs/README-EXPLAINME-STANDARD.adoc +++ b/docs/README-EXPLAINME-STANDARD.adoc @@ -37,7 +37,7 @@ An EXPLAINME that only repeats README prose fails its purpose. === Required format -* AsciiDoc (`.adoc`) — **not** Markdown. GitHub-required files (`SECURITY.md`, +* AsciiDoc (`.adoc`) — **not** Markdown. GitHub-required files (`3-practice/SECURITY.md`, `CONTRIBUTING.md`, `CODE_OF_CONDUCT.md`) remain `.md` as a platform exception. * Header: `// SPDX-License-Identifier: MPL-2.0` (or applicable licence). * Document title (`= Title`) in sentence case, not ALL CAPS. @@ -76,7 +76,7 @@ An EXPLAINME that only repeats README prose fails its purpose. | Yes for repos with non-obvious structure | Documentation -| Bulleted list of named links to EXPLAINME.adoc, CONTRIBUTING.md, SECURITY.md, +| Bulleted list of named links to EXPLAINME.adoc, CONTRIBUTING.md, 3-practice/SECURITY.md, and any project-specific docs. | Yes @@ -240,7 +240,7 @@ An EXPLAINME is considered **complete** when: [NOTE] ==== -GitHub-required files (`SECURITY.md`, `CONTRIBUTING.md`, `CODE_OF_CONDUCT.md`, +GitHub-required files (`3-practice/SECURITY.md`, `CONTRIBUTING.md`, `CODE_OF_CONDUCT.md`, `CHANGELOG.md`) remain `.md` as a platform exception — GitHub Actions and the security advisory system expect `.md` for these. ==== diff --git a/docs/SEAMS-SPEC.adoc b/docs/SEAMS-SPEC.adoc index 2e0e4f0fa..5c1ddfd2e 100644 --- a/docs/SEAMS-SPEC.adoc +++ b/docs/SEAMS-SPEC.adoc @@ -74,7 +74,7 @@ P2P test:: boundary, IPC channel, or HTTP API surface. P2P tests are distinct from unit tests (which test one component in isolation) and integration tests (which test multiple seams at once). See - `testing-and-benchmarking/TESTING-TAXONOMY.adoc §2` for the full + `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc §2` for the full taxonomy definition. seam-register entry:: diff --git a/docs/audits/2026-05-26-estate-documentation-debt.adoc b/docs/audits/2026-05-26-estate-documentation-debt.adoc index 08d783ef7..eb7558378 100644 --- a/docs/audits/2026-05-26-estate-documentation-debt.adoc +++ b/docs/audits/2026-05-26-estate-documentation-debt.adoc @@ -8,7 +8,7 @@ - `+docs/+` directory present? How many `+.md+`/`+.adoc+`/`+.rst+` files? Total LoC? - Wiki indicator: `+wiki/+` dir, `+.wiki+` submodule, or in-repo reference? - Project hygiene: CHANGELOG.md, CONTRIBUTING.md, -CODE_OF_CONDUCT.md, SECURITY.md? +CODE_OF_CONDUCT.md, 3-practice/SECURITY.md? A repo has a *heavily-developed and well-organised wiki* for the purposes of this audit when it satisfies: `+docs/+` directory has ≥10 @@ -209,7 +209,7 @@ quickstart only) + `+docs/architecture.md+`, `+docs/usage.md+`, etc. |CHANGELOG.md |99 |180 |35% |CONTRIBUTING.md |252 |27 |90% |CODE_OF_CONDUCT.md |234 |45 |84% -|SECURITY.md |243 |36 |87% +|3-practice/SECURITY.md |243 |36 |87% |=== CONTRIBUTING/CODE_OF_CONDUCT/SECURITY are well covered (likely shipped diff --git a/docs/decisions/ADR-005-extract-consent-aware-web.adoc b/docs/decisions/ADR-005-extract-consent-aware-web.adoc index b19bf9427..49a3657aa 100644 --- a/docs/decisions/ADR-005-extract-consent-aware-web.adoc +++ b/docs/decisions/ADR-005-extract-consent-aware-web.adoc @@ -69,7 +69,7 @@ its own protocol, and is validated in CI. closeable in the new repository and were not closeable here. * `COMPLIANCE-DASHBOARD.md` regenerates without the row. Both it and the registry are derived; `build-registry.sh --check` confirms no drift. -* Licence references in `LICENCE-POLICY.adoc`, `PALIMPSEST.adoc`, `README.adoc`, +* Licence references in `3-practice/LICENCE-POLICY.adoc`, `PALIMPSEST.adoc`, `README.adoc`, `.claude/CLAUDE.md` and `.machine_readable/licensing-policy.toml` are statements about a *repository*, not a directory. They remain correct and now name the new location. The PMPL carve-out and the IETF-mandated MIT carve-out diff --git a/docs/reorg/STREAM-PROMPTS.adoc b/docs/reorg/STREAM-PROMPTS.adoc index 9f4a1fa39..8d3d62289 100644 --- a/docs/reorg/STREAM-PROMPTS.adoc +++ b/docs/reorg/STREAM-PROMPTS.adoc @@ -186,7 +186,7 @@ CONTEXT — confirmed drift to fix (file:line evidence exists): - QUICKSTART-*.adoc still contain unfilled {{PLACEHOLDER}} markers. - REORGANIZATION-PLAN.md describes redundancies that no longer match reality. - Competing entry docs: README.adoc, EXPLAINME.adoc, TOPOLOGY.adoc, 0-AI-MANIFEST.a2ml, - QUICKSTART-{DEV,USER,MAINTAINER}.adoc, llm-warmup-*.md, ai-instruction/. + QUICKSTART-{DEV,USER,MAINTAINER}.adoc, llm-warmup-*.md, 3-practice/ai-instruction/. CRITICAL GUARDRAIL: per .claude/CLAUDE.md, licence changes are MANUAL, OWNER-ONLY, FLAG-ONLY for agents. Do NOT touch any LICENSE file or SPDX header. Correcting a diff --git a/docs/tech-debt-2026-05-26.adoc b/docs/tech-debt-2026-05-26.adoc index 5cb20183f..3d48cfa7e 100644 --- a/docs/tech-debt-2026-05-26.adoc +++ b/docs/tech-debt-2026-05-26.adoc @@ -64,7 +64,7 @@ commentary). |CHANGELOG.md |N |CONTRIBUTING.md |Y |CODE_OF_CONDUCT.md |Y -|SECURITY.md |Y +|3-practice/SECURITY.md |Y |Severity |`+OK+` |=== diff --git a/docs/wikis/maintainers/index.adoc b/docs/wikis/maintainers/index.adoc index dc31274df..d49d10f11 100644 --- a/docs/wikis/maintainers/index.adoc +++ b/docs/wikis/maintainers/index.adoc @@ -15,7 +15,7 @@ NOTE: Scaffold. The link spine is complete; the connective prose is `TODO`. === Licence is Manual-Only for agents -* `.claude/CLAUDE.md` (§License Policy) + `LICENCE-POLICY.adoc`. +* `.claude/CLAUDE.md` (§License Policy) + `3-practice/LICENCE-POLICY.adoc`. * Never sweep SPDX/licence headers; licence-drift findings are *flag-only*. New files may carry correct SPDX from birth, matching the repo's classification. (Root cause: neurophone#99.) @@ -62,5 +62,5 @@ NOTE: Scaffold. The link spine is complete; the connective prose is `TODO`. === 6. Release & ownership -* `release-pre-flight/`, `publication-pre-flight/`, `just v1-audit`, - `MAINTAINERS.adoc`, `CODEOWNERS-POLICY.adoc`, `SECURITY.md`. +* `3-practice/release-pre-flight/`, `3-practice/publication-pre-flight/`, `just v1-audit`, + `3-practice/MAINTAINERS.adoc`, `3-practice/CODEOWNERS-POLICY.adoc`, `3-practice/SECURITY.md`. diff --git a/hypatia-rules/rsr-self-compliance.a2ml b/hypatia-rules/rsr-self-compliance.a2ml index 261eb56f8..dca7542cb 100644 --- a/hypatia-rules/rsr-self-compliance.a2ml +++ b/hypatia-rules/rsr-self-compliance.a2ml @@ -22,7 +22,7 @@ reference: "rhodium-standard-repositories/RSR.adoc" # RSR-mandated files that standards itself must have - path: "README.adoc" reason: "RSR R-001" -- path: "SECURITY.md" +- path: "3-practice/SECURITY.md" reason: "RSR R-002" - path: "CONTRIBUTING.md" reason: "RSR R-003" diff --git a/rhodium-standard-repositories/.github/workflows/language-policy.yml b/rhodium-standard-repositories/.github/workflows/language-policy.yml index b8bdb0ccb..42cf1c0a2 100644 --- a/rhodium-standard-repositories/.github/workflows/language-policy.yml +++ b/rhodium-standard-repositories/.github/workflows/language-policy.yml @@ -141,7 +141,7 @@ jobs: | grep -vE '/(example|examples|test-fixtures|fixtures)/' \ || true) if [ -n "$NEW_NPM_LOCK" ]; then - echo "❌ New package-lock.json files detected (standards#67 — npm-avoidant). npm is tier 4: permitted, never preferred. Use Bun (tier 1); see LANGUAGE-POLICY.adoc §1." + echo "❌ New package-lock.json files detected (standards#67 — npm-avoidant). npm is tier 4: permitted, never preferred. Use Bun (tier 1); see 3-practice/LANGUAGE-POLICY.adoc §1." echo "$NEW_NPM_LOCK" echo "" echo "In-flight migration tracked under hyperpolymath/standards#253." diff --git a/rhodium-standard-repositories/.gitlab-ci.yml b/rhodium-standard-repositories/.gitlab-ci.yml index d3c469b1a..0303ad6ba 100644 --- a/rhodium-standard-repositories/.gitlab-ci.yml +++ b/rhodium-standard-repositories/.gitlab-ci.yml @@ -186,7 +186,7 @@ secrets-scan: - echo "🔍 Scanning for secrets..." - | # Simple pattern matching for common secrets - ! git grep -E "(password|secret|api_key|private_key|token)\\s*=\\s*['\"][^'\"]+['\"]" -- ':!*.md' ':!SECURITY.md' || \ + ! git grep -E "(password|secret|api_key|private_key|token)\\s*=\\s*['\"][^'\"]+['\"]" -- ':!*.md' ':!3-practice/SECURITY.md' || \ (echo "⚠️ Possible secrets found!" && exit 1) rules: - if: '$CI_PIPELINE_SOURCE == "merge_request_event"' @@ -204,9 +204,9 @@ create-release: rsr-audit.sh \ README.adoc \ LICENSE.txt \ - SECURITY.md \ - CODE_OF_CONDUCT.adoc \ - CONTRIBUTING.adoc \ + 3-practice/SECURITY.md \ + 3-practice/CODE_OF_CONDUCT.adoc \ + 3-practice/CONTRIBUTING.adoc \ 0-canon/GOVERNANCE.adoc \ MAINTAINERS.md \ CHANGELOG.md \ diff --git a/rhodium-standard-repositories/.machine_readable/descriptiles/AGENTIC.a2ml b/rhodium-standard-repositories/.machine_readable/descriptiles/AGENTIC.a2ml index 28bf1d9cd..2822cbaf1 100644 --- a/rhodium-standard-repositories/.machine_readable/descriptiles/AGENTIC.a2ml +++ b/rhodium-standard-repositories/.machine_readable/descriptiles/AGENTIC.a2ml @@ -20,7 +20,7 @@ can-create-files = true # - Never use banned languages (TypeScript, Python, Go, etc.) # - Never place state files in repository root (must be in .machine_readable/) # - Never relicense an existing file, and never run an automated licence -# sweep (LICENCE-POLICY.adoc A2). New files get correct SPDX from birth. +# sweep (3-practice/LICENCE-POLICY.adoc A2). New files get correct SPDX from birth. # - Never assume a licence. Read standards/LICENCE-POLICY.adoc: Rule 1 # defaults to MPL-2.0 (code) / CC-BY-SA-4.0 (prose), but Rule 3 # (co-developed), Rule 4 (network-deployed services) and Rule 5 diff --git a/rhodium-standard-repositories/.well-known/consent-required.txt b/rhodium-standard-repositories/.well-known/consent-required.txt index 8ced3dc93..fb64de392 100644 --- a/rhodium-standard-repositories/.well-known/consent-required.txt +++ b/rhodium-standard-repositories/.well-known/consent-required.txt @@ -70,7 +70,7 @@ Status: NOT APPLICABLE Scope: This repository contains no personal data Note: If you contribute, your name/email from git commits are public. -See CONTRIBUTING.adoc for contributor privacy options. +See 3-practice/CONTRIBUTING.adoc for contributor privacy options. ## Surveillance / Monitoring @@ -118,6 +118,6 @@ Review Cycle: Quarterly - Full license: LICENSE.txt - AI policy: .well-known/ai.txt -- Security policy: SECURITY.md +- Security policy: 3-practice/SECURITY.md - Privacy policy: PRIVACY.md (if applicable) - Terms of service: TOS.md (if applicable) diff --git a/rhodium-standard-repositories/.well-known/provenance.json b/rhodium-standard-repositories/.well-known/provenance.json index 199f73a6b..fcaaa50ce 100644 --- a/rhodium-standard-repositories/.well-known/provenance.json +++ b/rhodium-standard-repositories/.well-known/provenance.json @@ -131,7 +131,7 @@ "contributionLevels": ["Community", "Regular", "Trusted", "Maintainer"] }, "security": { - "policy": "SECURITY.md", + "policy": "3-practice/SECURITY.md", "contact": "security@rhodium-standard.org", "disclosure": "coordinated-90-day-embargo", "sla": "4-hour-acknowledgement-critical" diff --git a/rhodium-standard-repositories/CHANGELOG.adoc b/rhodium-standard-repositories/CHANGELOG.adoc index c6bae3857..74ccb6327 100644 --- a/rhodium-standard-repositories/CHANGELOG.adoc +++ b/rhodium-standard-repositories/CHANGELOG.adoc @@ -34,11 +34,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 === Added - Documentation - **README.adoc**: Comprehensive project documentation in AsciiDoc format - **LICENSE.txt**: Dual MIT + Palimpsest-0.8 license -- **SECURITY.md**: Security policy with 10+ dimension security architecture +- **3-practice/SECURITY.md**: Security policy with 10+ dimension security architecture - **MAINTAINERS.md**: Maintainer attribution and TPCF progression path - **0-canon/GOVERNANCE.adoc**: Complete governance structure with TPCF framework -- **CODE_OF_CONDUCT.adoc**: Community standards and enforcement procedures -- **CONTRIBUTING.adoc**: Contribution guidelines with tri-perimeter model +- **3-practice/CODE_OF_CONDUCT.adoc**: Community standards and enforcement procedures +- **3-practice/CONTRIBUTING.adoc**: Contribution guidelines with tri-perimeter model - **FUNDING.yml**: Funding transparency configuration - **CHANGELOG.md**: This file - semantic versioning changelog @@ -168,7 +168,7 @@ Security vulnerabilities will be disclosed in this CHANGELOG with: - Fixed version - Credit to reporter (if consented) -See SECURITY.md for our coordinated disclosure policy. +See 3-practice/SECURITY.md for our coordinated disclosure policy. --- diff --git a/rhodium-standard-repositories/CLAUDE.md b/rhodium-standard-repositories/CLAUDE.md index 142676b3d..ac276ffcb 100644 --- a/rhodium-standard-repositories/CLAUDE.md +++ b/rhodium-standard-repositories/CLAUDE.md @@ -190,7 +190,7 @@ A repository is Rhodium Standard compliant when it meets the following comprehen repository-root/ ├── README.md # or .adoc ├── LICENSE.txt # MUST be .txt (plain text) -├── SECURITY.md # MUST be .md +├── 3-practice/SECURITY.md # MUST be .md ├── CODE_OF_CONDUCT.md # or .adoc ├── CONTRIBUTING.md # or .adoc ├── FUNDING.yml # MUST be .yml @@ -583,7 +583,7 @@ This is **graduated trust without gatekeeping**—everyone can contribute, but s - Security boundaries (Deno permissions) 5. **Document the fix** - - Update SECURITY.md if vulnerability + - Update 3-practice/SECURITY.md if vulnerability - Add regression test - Update CHANGELOG (SemVer) diff --git a/rhodium-standard-repositories/COMPLIANCE_CHECKLIST.md b/rhodium-standard-repositories/COMPLIANCE_CHECKLIST.md index df49e1813..fa08f94ac 100644 --- a/rhodium-standard-repositories/COMPLIANCE_CHECKLIST.md +++ b/rhodium-standard-repositories/COMPLIANCE_CHECKLIST.md @@ -57,9 +57,9 @@ Core documentation must exist with exact filenames: - [ ] `README.md` or `README.adoc` - [ ] `LICENSE.txt` (plain text, not `.md`) -- [ ] `SECURITY.md` (not `.txt` or `.adoc`) -- [ ] `CODE_OF_CONDUCT.md` or `CODE_OF_CONDUCT.adoc` -- [ ] `CONTRIBUTING.md` or `CONTRIBUTING.adoc` +- [ ] `3-practice/SECURITY.md` (not `.txt` or `.adoc`) +- [ ] `CODE_OF_CONDUCT.md` or `3-practice/CODE_OF_CONDUCT.adoc` +- [ ] `CONTRIBUTING.md` or `3-practice/CONTRIBUTING.adoc` - [ ] `FUNDING.yml` (not `.yaml`) - [ ] `0-canon/GOVERNANCE.adoc` - [ ] `MAINTAINERS.md` @@ -513,9 +513,9 @@ Must include: - [ ] Perimeter 1 (Core): Maintainers-only access defined - [ ] Perimeter 2 (Expert): Trusted contributor pathway defined - [ ] Perimeter 3 (Community): Open contribution sandbox defined -- [ ] `CONTRIBUTING.adoc` documents TPCF +- [ ] `3-practice/CONTRIBUTING.adoc` documents TPCF -**Automation**: `test -f CONTRIBUTING.adoc && rg "Perimeter" CONTRIBUTING.adoc` +**Automation**: `test -f 3-practice/CONTRIBUTING.adoc && rg "Perimeter" 3-practice/CONTRIBUTING.adoc` --- @@ -526,7 +526,7 @@ Must include: - [ ] Reporting mechanisms clear - [ ] Conflict resolution process -**Automation**: `test -f CODE_OF_CONDUCT.md || test -f CODE_OF_CONDUCT.adoc` +**Automation**: `test -f CODE_OF_CONDUCT.md || test -f 3-practice/CODE_OF_CONDUCT.adoc` --- diff --git a/rhodium-standard-repositories/CONTRIBUTING.adoc b/rhodium-standard-repositories/CONTRIBUTING.adoc index ac02e1c66..59cf5b25b 100644 --- a/rhodium-standard-repositories/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/CONTRIBUTING.adoc @@ -43,9 +43,9 @@ git push origin feature/your-feature-name Please read: * link:README.adoc[README.adoc] - Project overview -* link:CODE_OF_CONDUCT.adoc[CODE_OF_CONDUCT.adoc] - Community standards +* link:3-practice/CODE_OF_CONDUCT.adoc[3-practice/CODE_OF_CONDUCT.adoc] - Community standards * link:0-canon/GOVERNANCE.adoc[0-canon/GOVERNANCE.adoc] - Decision-making process -* link:SECURITY.md[SECURITY.md] - Security policies +* link:3-practice/SECURITY.md[3-practice/SECURITY.md] - Security policies == Tri-Perimeter Contribution Framework (TPCF) @@ -87,7 +87,7 @@ The Rhodium Standard uses a graduated trust model. Your contribution scope depen * Contribute to DocGementer tooling *How to Become a Trusted Contributor*: -See link:MAINTAINERS.adoc[MAINTAINERS.md] for the progression path. Typically: +See link:3-practice/MAINTAINERS.adoc[MAINTAINERS.md] for the progression path. Typically: * 20+ merged contributions OR deep expertise in specific area * 3+ months of consistent activity * Positive community interactions @@ -507,7 +507,7 @@ Help grow the community! 1. Create directory: `examples/your-example/` 2. Build RSR-compliant repo structure -3. Add `README.adoc`, `LICENSE.txt`, `SECURITY.md`, etc. +3. Add `README.adoc`, `LICENSE.txt`, `3-practice/SECURITY.md`, etc. 4. Achieve at least Bronze compliance (75%) 5. Document in root `README.adoc` 6. Create MR @@ -613,7 +613,7 @@ Or focus on areas you're comfortable with - all contributions are valuable! * **Trusted contributor** (20+ MRs, 3+ months): Listed in MAINTAINERS.md, can approve MRs in your domain * **Core maintainer** (6+ months trusted): Listed as maintainer, voting rights -See link:MAINTAINERS.adoc[MAINTAINERS.md] for details. +See link:3-practice/MAINTAINERS.adoc[MAINTAINERS.md] for details. == Legal @@ -646,7 +646,7 @@ We follow the https://developercertificate.org/[Developer Certificate of Origin] == Code of Conduct -All contributors must follow our link:CODE_OF_CONDUCT.adoc[Code of Conduct]. +All contributors must follow our link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct]. Key points: @@ -662,8 +662,8 @@ Violations can be reported to code-of-conduct@rhodium-standard.org * link:README.adoc[README] - Project overview * link:0-canon/GOVERNANCE.adoc[GOVERNANCE] - How decisions are made -* link:SECURITY.md[SECURITY] - Security policies -* link:MAINTAINERS.adoc[MAINTAINERS] - Team structure +* link:3-practice/SECURITY.md[SECURITY] - Security policies +* link:3-practice/MAINTAINERS.adoc[MAINTAINERS] - Team structure * link:CLAUDE.md[CLAUDE.md] - AI assistant guidance * link:COMPLIANCE_CHECKLIST.md[Compliance Checklist] - RSR standards diff --git a/rhodium-standard-repositories/PROJECT-STATUS.adoc b/rhodium-standard-repositories/PROJECT-STATUS.adoc index f66d25576..2c4aca7ac 100644 --- a/rhodium-standard-repositories/PROJECT-STATUS.adoc +++ b/rhodium-standard-repositories/PROJECT-STATUS.adoc @@ -49,9 +49,9 @@ Ideological/philosophical foundation * GitLab + SaltRover + Podman + Nix architecture * CADRE router, Elixir GenServers, Rust FFI, Ada SPARK flow . *Complete Documentation Suite* -* SECURITY.md with 10+ dimension security policy -* CODE_OF_CONDUCT.adoc -* CONTRIBUTING.adoc +* 3-practice/SECURITY.md with 10+ dimension security policy +* 3-practice/CODE_OF_CONDUCT.adoc +* 3-practice/CONTRIBUTING.adoc * 0-canon/GOVERNANCE.adoc * MAINTAINERS.md * CHANGELOG.md @@ -147,10 +147,10 @@ All templates now exist in `+templates/+`: * [x] *ETHICS.md.template* – Ethical guidelines * [x] *LEARNING.md.template* – Educational resources * [x] *FEEDBACK.md.template* – Community input mechanism -* [x] *SECURITY.md.template* – Vulnerability reporting, SLA -* [x] *CODE_OF_CONDUCT.adoc.template* – Community standards +* [x] *3-practice/SECURITY.md.template* – Vulnerability reporting, SLA +* [x] *3-practice/CODE_OF_CONDUCT.adoc.template* – Community standards * [x] *0-canon/GOVERNANCE.adoc.template* – Decision-making, roles, TPCF -* [x] *CONTRIBUTING.adoc.template* – Workflow, commit standards +* [x] *3-practice/CONTRIBUTING.adoc.template* – Workflow, commit standards ===== 1.2 Directory Structure Standards (✓ All Created) @@ -203,7 +203,7 @@ configuration Build a command-line validator that checks RSR compliance: *Features*: - [ ] Scans repository structure - [ ] Validates required -files exist (README, LICENSE.txt, SECURITY.md, etc.) - [ ] Checks SPDX +files exist (README, LICENSE.txt, 3-practice/SECURITY.md, etc.) - [ ] Checks SPDX headers on all source files - [ ] Validates link integrity (Lychee integration) - [ ] Checks accessibility (alt text, semantic HTML) - [ ] Verifies security headers configuration - [ ] Tests offline-first @@ -275,7 +275,7 @@ configuration - [x] Cargo.toml with proper metadata *`+examples/enterprise-service+`* - [x] Full Rust web service with Axum - [x] GitHub Actions CI/CD workflows - [x] Architecture Decision Records -(ADR) - [x] SECURITY.md, CONTRIBUTING.md - [x] Comprehensive +(ADR) - [x] 3-practice/SECURITY.md, CONTRIBUTING.md - [x] Comprehensive documentation *`+examples/ai-ml-project+`* - [x] Hybrid Rust/Python project - [x] diff --git a/rhodium-standard-repositories/README.adoc b/rhodium-standard-repositories/README.adoc index d052b2452..89ba6f005 100644 --- a/rhodium-standard-repositories/README.adoc +++ b/rhodium-standard-repositories/README.adoc @@ -294,7 +294,7 @@ cd my-new-project just init # Customize -$EDITOR README.adoc LICENSE.txt SECURITY.md +$EDITOR README.adoc LICENSE.txt 3-practice/SECURITY.md # Validate just validate @@ -347,10 +347,10 @@ Features: We welcome contributions! Please read our contribution guidelines: -* link:CONTRIBUTING.adoc[Contributing Guide] - How to contribute -* link:CODE_OF_CONDUCT.adoc[Code of Conduct] - Community standards +* link:3-practice/CONTRIBUTING.adoc[Contributing Guide] - How to contribute +* link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct] - Community standards * link:0-canon/GOVERNANCE.adoc[Governance] - Decision-making process -* link:SECURITY.md[Security Policy] - Reporting vulnerabilities +* link:3-practice/SECURITY.md[Security Policy] - Reporting vulnerabilities === Tri-Perimeter Contribution Framework (TPCF) @@ -360,7 +360,7 @@ RSR uses a graduated trust model: * 🧠 *Perimeter 2 (Expert)*: Trusted contributors - protocol extensions, validators * 🌱 *Perimeter 3 (Community)*: Open to all - docs, tests, proposals -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc] for details. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for details. == Documentation @@ -376,7 +376,7 @@ See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc] for details. * link:docs/haskell-registry-design.md[Haskell Registry Design] - Validation service architecture * link:PROJECT-STATUS.md[Project Status] - Current development status -* link:MAINTAINERS.adoc[Maintainers] - Project maintainers and contributors +* link:3-practice/MAINTAINERS.adoc[Maintainers] - Project maintainers and contributors == License @@ -442,7 +442,7 @@ The Rhodium Standard builds on decades of best practices from: * Erlang/OTP fault tolerance patterns * CRDTs and distributed systems research -See link:MAINTAINERS.adoc[MAINTAINERS.md] and link:.well-known/humans.txt[humans.txt] for contributor attribution. +See link:3-practice/MAINTAINERS.adoc[MAINTAINERS.md] and link:.well-known/humans.txt[humans.txt] for contributor attribution. == Citation diff --git a/rhodium-standard-repositories/RSR-AUDIT-GUIDE.adoc b/rhodium-standard-repositories/RSR-AUDIT-GUIDE.adoc index e7f907ad3..4de3e997d 100644 --- a/rhodium-standard-repositories/RSR-AUDIT-GUIDE.adoc +++ b/rhodium-standard-repositories/RSR-AUDIT-GUIDE.adoc @@ -52,7 +52,7 @@ pass - *Silver* (90-99%): Strong compliance - production-ready - * ✅ README.md (or .adoc) * ✅ LICENSE.txt (dual: MIT + Palimpsest v0.8) -* ✅ SECURITY.md (vulnerability reporting) +* ✅ 3-practice/SECURITY.md (vulnerability reporting) * ✅ CODE_OF_CONDUCT.md * ✅ CONTRIBUTING.md (TPCF framework) * ✅ MAINTAINERS.md diff --git a/rhodium-standard-repositories/RSR-AUDIT-SHOWCASE.adoc b/rhodium-standard-repositories/RSR-AUDIT-SHOWCASE.adoc index 1bbd7179f..ef33d2307 100644 --- a/rhodium-standard-repositories/RSR-AUDIT-SHOWCASE.adoc +++ b/rhodium-standard-repositories/RSR-AUDIT-SHOWCASE.adoc @@ -23,7 +23,7 @@ Just Bash + common Unix tools (grep, find, bc) *What It Checks*: 1. *Infrastructure*: Nix flakes, Justfile, GitLab CI, Podman, Git config 2. *Documentation*: README, LICENSE.txt (dual -MIT+Palimpsest), SECURITY.md, .well-known/, TPCF 3. *Security*: SPDX +MIT+Palimpsest), 3-practice/SECURITY.md, .well-known/, TPCF 3. *Security*: SPDX headers, type safety (Rust/Elixir/Ada/Haskell/ReScript), no unsafe code, no JavaScript 4. *Architecture*: Offline-first, CRDTs, reversibility, reproducibility 5. *Licensing*: Dual licensing, FUNDING.yml, attribution @@ -145,7 +145,7 @@ RSR Audit Results *Full RSR Compliance* - All checks pass Requirements: - ✅ Complete documentation (README, LICENSE.txt, -SECURITY.md, .well-known/, etc.) - ✅ Nix flakes for reproducible builds +3-practice/SECURITY.md, .well-known/, etc.) - ✅ Nix flakes for reproducible builds - ✅ Justfile with all essential recipes - ✅ GitLab CI/CD with comprehensive pipeline - ✅ SPDX headers on every source file - ✅ Type-safe language (Rust/Elixir/Ada/Haskell/ReScript) - ✅ Memory-safe diff --git a/rhodium-standard-repositories/SECURITY.adoc b/rhodium-standard-repositories/SECURITY.adoc index 096a16f57..52ee99b9c 100644 --- a/rhodium-standard-repositories/SECURITY.adoc +++ b/rhodium-standard-repositories/SECURITY.adoc @@ -1,4 +1,4 @@ -== SECURITY.md +== 3-practice/SECURITY.md == Security Policy diff --git a/rhodium-standard-repositories/TESTING-REPORT.adoc b/rhodium-standard-repositories/TESTING-REPORT.adoc index f84c14c06..2ec7c66ee 100644 --- a/rhodium-standard-repositories/TESTING-REPORT.adoc +++ b/rhodium-standard-repositories/TESTING-REPORT.adoc @@ -212,7 +212,7 @@ test result: ok. 0 passed; 0 failed; 0 ignored | Uses README.adoc (AsciiDoc variant is acceptable, but audit checks for .md first) | CONTRIBUTING.md present -| Uses CONTRIBUTING.adoc (similar situation) +| Uses 3-practice/CONTRIBUTING.adoc (similar situation) | Correct SPDX identifier in LICENSE.txt | License header shows "MIT OR PMPL-1.0-or-later" but audit expects "MIT AND Palimpsest" pattern diff --git a/rhodium-standard-repositories/TESTING-REPORT.scm b/rhodium-standard-repositories/TESTING-REPORT.scm index fe8e4fdb0..c86cef1df 100644 --- a/rhodium-standard-repositories/TESTING-REPORT.scm +++ b/rhodium-standard-repositories/TESTING-REPORT.scm @@ -190,7 +190,7 @@ (total 17) (failures ("README.md present" "Uses README.adoc instead") - ("CONTRIBUTING.md present" "Uses CONTRIBUTING.adoc instead"))) + ("CONTRIBUTING.md present" "Uses 3-practice/CONTRIBUTING.adoc instead"))) (security-architecture (passed 6) (total 6)) @@ -218,7 +218,7 @@ (passed 5) (total 6) (failures - ("CONTRIBUTING.md present" "Uses CONTRIBUTING.adoc instead"))) + ("CONTRIBUTING.md present" "Uses 3-practice/CONTRIBUTING.adoc instead"))) (maa (passed 3) (total 4)) diff --git a/rhodium-standard-repositories/docs/haskell-registry-design.adoc b/rhodium-standard-repositories/docs/haskell-registry-design.adoc index 90f8635d5..9e4a43a2b 100644 --- a/rhodium-standard-repositories/docs/haskell-registry-design.adoc +++ b/rhodium-standard-repositories/docs/haskell-registry-design.adoc @@ -320,7 +320,7 @@ validateDocumentation :: FilePath -> IO [CheckResult] validateDocumentation repoPath = sequence [ checkFileExists repoPath "README.md" 2 "README.md present" , checkFileExists repoPath "LICENSE.txt" 2 "LICENSE.txt present (must be .txt)" - , checkFileExists repoPath "SECURITY.md" 2 "SECURITY.md present" + , checkFileExists repoPath "3-practice/SECURITY.md" 2 "3-practice/SECURITY.md present" , checkFileExists repoPath "CODE_OF_CONDUCT.md" 2 "CODE_OF_CONDUCT.md present" , checkFileExists repoPath "CONTRIBUTING.md" 2 "CONTRIBUTING.md present" , checkFileExists repoPath "MAINTAINERS.md" 2 "MAINTAINERS.md present" diff --git a/rhodium-standard-repositories/docs/rhodium-init-design.adoc b/rhodium-standard-repositories/docs/rhodium-init-design.adoc index 6fb279cd3..470080ee1 100644 --- a/rhodium-standard-repositories/docs/rhodium-init-design.adoc +++ b/rhodium-standard-repositories/docs/rhodium-init-design.adoc @@ -369,9 +369,9 @@ end Rhodium.Init.Types; │ Generate these required files: │ │ [X] README.adoc │ │ [X] LICENSE.txt (MIT + Palimpsest) │ -│ [X] SECURITY.md │ -│ [X] CODE_OF_CONDUCT.adoc │ -│ [X] CONTRIBUTING.adoc │ +│ [X] 3-practice/SECURITY.md │ +│ [X] 3-practice/CODE_OF_CONDUCT.adoc │ +│ [X] 3-practice/CONTRIBUTING.adoc │ │ [X] FUNDING.yml │ │ [X] 0-canon/GOVERNANCE.adoc │ │ [X] REVERSIBILITY.md │ @@ -408,9 +408,9 @@ end Rhodium.Init.Types; │ my-ada-project/ │ │ ├── README.adoc │ │ ├── LICENSE.txt │ -│ ├── SECURITY.md │ -│ ├── CODE_OF_CONDUCT.adoc │ -│ ├── CONTRIBUTING.adoc │ +│ ├── 3-practice/SECURITY.md │ +│ ├── 3-practice/CODE_OF_CONDUCT.adoc │ +│ ├── 3-practice/CONTRIBUTING.adoc │ │ ├── FUNDING.yml │ │ ├── 0-canon/GOVERNANCE.adoc │ │ ├── REVERSIBILITY.md │ @@ -475,7 +475,7 @@ end Rhodium.Init.Types; │ 1. cd my-ada-project │ │ 2. Review generated files, especially: │ │ - README.adoc (customize project description) │ -│ - SECURITY.md (add security contact) │ +│ - 3-practice/SECURITY.md (add security contact) │ │ - FUNDING.yml (add funding links) │ │ 3. Customize placeholders marked with *REMINDER* │ │ 4. Run `just validate` to verify compliance │ diff --git a/rhodium-standard-repositories/examples/README.adoc b/rhodium-standard-repositories/examples/README.adoc index 4e7b2fd8b..7e83ff7d9 100644 --- a/rhodium-standard-repositories/examples/README.adoc +++ b/rhodium-standard-repositories/examples/README.adoc @@ -169,7 +169,7 @@ All examples demonstrate: * README.md (project overview) * LICENSE.txt (dual: MIT + Palimpsest v0.8) -* SECURITY.md (vulnerability reporting) +* 3-practice/SECURITY.md (vulnerability reporting) * CONTRIBUTING.md (TPCF framework) * CODE_OF_CONDUCT.md * MAINTAINERS.md diff --git a/rhodium-standard-repositories/examples/TUTORIAL.adoc b/rhodium-standard-repositories/examples/TUTORIAL.adoc index 1d5c9ed80..c5bc9e8c7 100644 --- a/rhodium-standard-repositories/examples/TUTORIAL.adoc +++ b/rhodium-standard-repositories/examples/TUTORIAL.adoc @@ -372,7 +372,7 @@ Accepted ==== Step 3: Add Security Policy -Create `+SECURITY.md+`: +Create `+3-practice/SECURITY.md+`: [source,markdown] ---- diff --git a/rhodium-standard-repositories/examples/ai-ml-project/ARCHITECTURE.adoc b/rhodium-standard-repositories/examples/ai-ml-project/ARCHITECTURE.adoc index b70c463f1..955aa0824 100644 --- a/rhodium-standard-repositories/examples/ai-ml-project/ARCHITECTURE.adoc +++ b/rhodium-standard-repositories/examples/ai-ml-project/ARCHITECTURE.adoc @@ -163,7 +163,7 @@ pooling === Security Considerations -See SECURITY.md for detailed security documentation. +See 3-practice/SECURITY.md for detailed security documentation. ==== Key Security Features diff --git a/rhodium-standard-repositories/examples/ai-ml-project/CHANGELOG.adoc b/rhodium-standard-repositories/examples/ai-ml-project/CHANGELOG.adoc index 0c302adf3..a5e0fc10f 100644 --- a/rhodium-standard-repositories/examples/ai-ml-project/CHANGELOG.adoc +++ b/rhodium-standard-repositories/examples/ai-ml-project/CHANGELOG.adoc @@ -27,7 +27,7 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. * Comprehensive test suite (>80% coverage) * Performance benchmarks with Criterion * Architecture documentation (ARCHITECTURE.md) -* Security policy (SECURITY.md) +* Security policy (3-practice/SECURITY.md) * Architecture Decision Records (ADRs) * SBOM generation support * Build provenance tracking diff --git a/rhodium-standard-repositories/examples/ai-ml-project/README.adoc b/rhodium-standard-repositories/examples/ai-ml-project/README.adoc index 8020e2ae0..26cd72de0 100644 --- a/rhodium-standard-repositories/examples/ai-ml-project/README.adoc +++ b/rhodium-standard-repositories/examples/ai-ml-project/README.adoc @@ -114,7 +114,7 @@ ____ ===== Gold Level ✓ -* ARCHITECTURE.md, SECURITY.md +* ARCHITECTURE.md, 3-practice/SECURITY.md * ADRs * SBOM, provenance tracking * Performance benchmarks @@ -194,7 +194,7 @@ pytest python/tests/ === Security -See SECURITY.md for: - Model security - Data privacy - Adversarial +See 3-practice/SECURITY.md for: - Model security - Data privacy - Adversarial robustness - Supply chain security === Compliance Automation diff --git a/rhodium-standard-repositories/examples/enterprise-service/.rhodium/config.toml b/rhodium-standard-repositories/examples/enterprise-service/.rhodium/config.toml index 5297b2525..6a1b881fa 100644 --- a/rhodium-standard-repositories/examples/enterprise-service/.rhodium/config.toml +++ b/rhodium-standard-repositories/examples/enterprise-service/.rhodium/config.toml @@ -36,7 +36,7 @@ versioning = true # Gold Level Requirements (All Met) [compliance.gold] architecture_documentation = true # ARCHITECTURE.md exists -security_policy = true # SECURITY.md exists +security_policy = true # 3-practice/SECURITY.md exists adr_records = true # Architecture Decision Records in docs/adr/ sbom_generation = true # Software Bill of Materials generated provenance_tracking = true # Build provenance tracked @@ -54,7 +54,7 @@ changelog_path = "CHANGELOG.md" contributing_path = "CONTRIBUTING.md" citation_path = "CITATION.cff" architecture_path = "ARCHITECTURE.md" -security_path = "SECURITY.md" +security_path = "3-practice/SECURITY.md" adr_directory = "docs/adr" generate_docs = true docs_command = "cargo doc --no-deps" @@ -75,7 +75,7 @@ sbom_command = "cargo sbom > sbom.json" verify_command = "cargo verify-project" [security] -security_policy = "SECURITY.md" +security_policy = "3-practice/SECURITY.md" vulnerability_scan = true scan_command = "cargo audit" dependency_review = true diff --git a/rhodium-standard-repositories/examples/enterprise-service/ARCHITECTURE.adoc b/rhodium-standard-repositories/examples/enterprise-service/ARCHITECTURE.adoc index b70c463f1..955aa0824 100644 --- a/rhodium-standard-repositories/examples/enterprise-service/ARCHITECTURE.adoc +++ b/rhodium-standard-repositories/examples/enterprise-service/ARCHITECTURE.adoc @@ -163,7 +163,7 @@ pooling === Security Considerations -See SECURITY.md for detailed security documentation. +See 3-practice/SECURITY.md for detailed security documentation. ==== Key Security Features diff --git a/rhodium-standard-repositories/examples/enterprise-service/CHANGELOG.adoc b/rhodium-standard-repositories/examples/enterprise-service/CHANGELOG.adoc index 0c302adf3..a5e0fc10f 100644 --- a/rhodium-standard-repositories/examples/enterprise-service/CHANGELOG.adoc +++ b/rhodium-standard-repositories/examples/enterprise-service/CHANGELOG.adoc @@ -27,7 +27,7 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. * Comprehensive test suite (>80% coverage) * Performance benchmarks with Criterion * Architecture documentation (ARCHITECTURE.md) -* Security policy (SECURITY.md) +* Security policy (3-practice/SECURITY.md) * Architecture Decision Records (ADRs) * SBOM generation support * Build provenance tracking diff --git a/rhodium-standard-repositories/examples/enterprise-service/README.adoc b/rhodium-standard-repositories/examples/enterprise-service/README.adoc index 35f650ecf..3d054f248 100644 --- a/rhodium-standard-repositories/examples/enterprise-service/README.adoc +++ b/rhodium-standard-repositories/examples/enterprise-service/README.adoc @@ -68,7 +68,7 @@ rhodium check --level gold All Bronze and Silver requirements plus: * [x] ARCHITECTURE.md with system design -* [x] SECURITY.md with security policies +* [x] 3-practice/SECURITY.md with security policies * [x] ADRs (Architecture Decision Records) * [x] SBOM generation support * [x] Build provenance tracking @@ -81,7 +81,7 @@ All Bronze and Silver requirements plus: === Documentation * ARCHITECTURE.md - System architecture and design -* SECURITY.md - Security policies and practices +* 3-practice/SECURITY.md - Security policies and practices * docs/adr/ - Architecture Decision Records * CONTRIBUTING.md - Contribution guidelines * CHANGELOG.md - Version history @@ -105,7 +105,7 @@ cargo bench === Security -See SECURITY.md for: - Vulnerability reporting - Security best practices +See 3-practice/SECURITY.md for: - Vulnerability reporting - Security best practices - Known limitations - Security roadmap === Next Steps diff --git a/rhodium-standard-repositories/examples/enterprise-service/docs/adr/002-in-memory-state-management.adoc b/rhodium-standard-repositories/examples/enterprise-service/docs/adr/002-in-memory-state-management.adoc index 7b412ad87..b4bae005c 100644 --- a/rhodium-standard-repositories/examples/enterprise-service/docs/adr/002-in-memory-state-management.adoc +++ b/rhodium-standard-repositories/examples/enterprise-service/docs/adr/002-in-memory-state-management.adoc @@ -186,7 +186,7 @@ Integration] *Important*: This is explicitly a temporary decision for demonstration purposes. Production deployments MUST use persistent storage. -See SECURITY.md for security implications. +See 3-practice/SECURITY.md for security implications. Decision made: 2025-11-01 Last updated: 2025-11-22 Review by: 2026-01-01 (or when moving to production) diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/.well-known/humans.txt b/rhodium-standard-repositories/examples/rhodium-minimal/.well-known/humans.txt index d89ebaa09..cff6e3b84 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/.well-known/humans.txt +++ b/rhodium-standard-repositories/examples/rhodium-minimal/.well-known/humans.txt @@ -42,7 +42,7 @@ Political Autonomy: No vendor lock-in Repository: https://gitlab.com/hyperpolymath/rhodium-standard-repositories Example: https://gitlab.com/hyperpolymath/rhodium-standard-repositories/-/tree/main/examples/rhodium-minimal Documentation: README.md -Security: SECURITY.md +Security: 3-practice/SECURITY.md Contributing: CONTRIBUTING.md Licence: LICENSE.txt (MIT + Palimpsest v0.8) diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/CHANGELOG.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/CHANGELOG.adoc index dfe38d361..7c21b3a3f 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/CHANGELOG.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/CHANGELOG.adoc @@ -34,7 +34,7 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. ===== Documentation * ✅ Comprehensive README.md -* ✅ SECURITY.md with vulnerability reporting +* ✅ 3-practice/SECURITY.md with vulnerability reporting * ✅ CONTRIBUTING.md with TPCF framework * ✅ CODE_OF_CONDUCT.md * ✅ LICENSE.txt (dual: MIT + Palimpsest v0.8) diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/CONTRIBUTING.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/CONTRIBUTING.adoc index a0ab6b4e4..51cccc12e 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/CONTRIBUTING.adoc @@ -286,7 +286,7 @@ perspectives - ✅ Focus on technical merit - ✅ Assume good intentions - ==== Questions? * *Technical*: Open a discussion in GitLab -* *Security*: See SECURITY.md +* *Security*: See 3-practice/SECURITY.md * *General*: Create an issue with `+question+` label ==== Stuck? diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/GOVERNANCE.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/GOVERNANCE.adoc index 34b89c3c7..d0ab401b8 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/GOVERNANCE.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/GOVERNANCE.adoc @@ -116,7 +116,7 @@ stewardship ==== Vulnerability Reporting -See SECURITY.md for process. +See 3-practice/SECURITY.md for process. ==== Security Response Team @@ -272,7 +272,7 @@ https://gitlab.com/hyperpolymath/rhodium-standard-repositories/-/issues * *TPCF Framework*: CONTRIBUTING.md * *RSR Specification*: ../../CLAUDE.md * *Code of Conduct*: CODE_OF_CONDUCT.md -* *Security Policy*: SECURITY.md +* *Security Policy*: 3-practice/SECURITY.md ''''' diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/Justfile b/rhodium-standard-repositories/examples/rhodium-minimal/Justfile index 8e95a2328..7965fc155 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/Justfile +++ b/rhodium-standard-repositories/examples/rhodium-minimal/Justfile @@ -100,7 +100,7 @@ check-docs: @echo "📚 Checking required documentation..." @test -f README.md || (echo "❌ Missing README.md" && exit 1) @test -f LICENSE.txt || (echo "❌ Missing LICENSE.txt" && exit 1) - @test -f SECURITY.md || (echo "❌ Missing SECURITY.md" && exit 1) + @test -f 3-practice/SECURITY.md || (echo "❌ Missing 3-practice/SECURITY.md" && exit 1) @test -f CONTRIBUTING.md || (echo "❌ Missing CONTRIBUTING.md" && exit 1) @test -f CODE_OF_CONDUCT.md || (echo "❌ Missing CODE_OF_CONDUCT.md" && exit 1) @test -d .well-known || (echo "❌ Missing .well-known/" && exit 1) diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/MAINTAINERS.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/MAINTAINERS.adoc index 707b0321c..c45d17e45 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/MAINTAINERS.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/MAINTAINERS.adoc @@ -54,7 +54,7 @@ _(None yet - be the first!)_ === 📞 Contact * *Technical Questions*: Open an issue -* *Security Issues*: See SECURITY.md +* *Security Issues*: See 3-practice/SECURITY.md * *General Discussion*: GitLab discussions ''''' diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/README.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/README.adoc index e90ea6e6f..716fe642a 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/README.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/README.adoc @@ -88,7 +88,7 @@ This minimal example demonstrates *Bronze-level RSR compliance*: * README.md (this file) * LICENSE.txt (dual: MIT + Palimpsest) -* SECURITY.md (vulnerability reporting) +* 3-practice/SECURITY.md (vulnerability reporting) * CONTRIBUTING.md (TPCF framework) * CODE_OF_CONDUCT.md * `+.well-known/+` directory @@ -214,7 +214,7 @@ See CONTRIBUTING.md for complete guidelines. === 🔒 Security -*Vulnerability Reporting*: See SECURITY.md +*Vulnerability Reporting*: See 3-practice/SECURITY.md *Security Contact*: `+.well-known/security.txt+` (RFC 9116 compliant) diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/docs/OVERVIEW.adoc b/rhodium-standard-repositories/examples/rhodium-minimal/docs/OVERVIEW.adoc index d4ac348b5..79e169132 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/docs/OVERVIEW.adoc +++ b/rhodium-standard-repositories/examples/rhodium-minimal/docs/OVERVIEW.adoc @@ -37,7 +37,7 @@ rhodium-minimal/ ├── .gitlab-ci.yml # CI/CD pipeline ├── README.md # Project documentation ├── LICENSE.txt # Dual: MIT + Palimpsest v0.8 -├── SECURITY.md # Vulnerability reporting +├── 3-practice/SECURITY.md # Vulnerability reporting ├── CONTRIBUTING.md # TPCF framework ├── CODE_OF_CONDUCT.md # Community standards ├── MAINTAINERS.md # Project team diff --git a/rhodium-standard-repositories/examples/rhodium-minimal/src/main.rs b/rhodium-standard-repositories/examples/rhodium-minimal/src/main.rs index ea81eab9b..0c13a4b63 100644 --- a/rhodium-standard-repositories/examples/rhodium-minimal/src/main.rs +++ b/rhodium-standard-repositories/examples/rhodium-minimal/src/main.rs @@ -49,7 +49,7 @@ fn check_compliance() -> Result<(), io::Error> { ("Documentation", vec![ "README.md present", "LICENSE.txt (dual: MIT + Palimpsest)", - "SECURITY.md with vulnerability reporting", + "3-practice/SECURITY.md with vulnerability reporting", "CONTRIBUTING.md with TPCF framework", "CODE_OF_CONDUCT.md", ]), diff --git a/rhodium-standard-repositories/examples/standard-library/README.adoc b/rhodium-standard-repositories/examples/standard-library/README.adoc index 269a6fc00..64e4a6921 100644 --- a/rhodium-standard-repositories/examples/standard-library/README.adoc +++ b/rhodium-standard-repositories/examples/standard-library/README.adoc @@ -174,7 +174,7 @@ To see how this project could be enhanced to Gold level, see the `+examples/enterprise-service/+` project which adds: * ARCHITECTURE.md documenting system design -* SECURITY.md with security policies +* 3-practice/SECURITY.md with security policies * ADRs (Architecture Decision Records) * SBOM (Software Bill of Materials) * Provenance tracking diff --git a/rhodium-standard-repositories/rhodium-pipeline/README.adoc b/rhodium-standard-repositories/rhodium-pipeline/README.adoc index 6a8c17881..c6e1d8898 100644 --- a/rhodium-standard-repositories/rhodium-pipeline/README.adoc +++ b/rhodium-standard-repositories/rhodium-pipeline/README.adoc @@ -253,7 +253,7 @@ https://github.com/hyperpolymath/zerostep[zerostep] — VAE dataset normalizer b == Contributing -See link:docs/CONTRIBUTING.adoc[CONTRIBUTING.adoc] for guidelines. +See link:docs/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for guidelines. == Documentation diff --git a/rhodium-standard-repositories/rhodium-pipeline/docs/LICENSING.adoc b/rhodium-standard-repositories/rhodium-pipeline/docs/LICENSING.adoc index 77ae4d4a3..dfdf8f4e3 100644 --- a/rhodium-standard-repositories/rhodium-pipeline/docs/LICENSING.adoc +++ b/rhodium-standard-repositories/rhodium-pipeline/docs/LICENSING.adoc @@ -172,7 +172,7 @@ The template includes or references: By contributing to this project, you agree to license your contributions under the same dual-license terms (MIT OR PMPL-1.0-or-later). -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc] for details. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for details. == Questions diff --git a/rhodium-standard-repositories/rsr-audit.sh b/rhodium-standard-repositories/rsr-audit.sh index e595c6a7f..56dfcd12e 100755 --- a/rhodium-standard-repositories/rsr-audit.sh +++ b/rhodium-standard-repositories/rsr-audit.sh @@ -246,7 +246,7 @@ audit_category_2_documentation() { fi check_file_exists "LICENSE.txt" "LICENSE.txt present (must be .txt, not .md)" - check_file_exists "SECURITY.md" "SECURITY.md present" + check_file_exists "3-practice/SECURITY.md" "3-practice/SECURITY.md present" check_file_exists "CODE_OF_CONDUCT.md" "CODE_OF_CONDUCT.md present (or .adoc)" check_file_exists "CONTRIBUTING.md" "CONTRIBUTING.md present (or .adoc)" check_file_exists "MAINTAINERS.md" "MAINTAINERS.md present" @@ -269,12 +269,12 @@ audit_category_2_documentation() { check_file_contains "README.md" "License" "README.md has License section" fi - # SECURITY.md validation + # 3-practice/SECURITY.md validation if [[ -f "$REPO_PATH/SECURITY.md" ]]; then - check_file_contains "SECURITY.md" "Reporting" "SECURITY.md has vulnerability reporting" + check_file_contains "3-practice/SECURITY.md" "Reporting" "3-practice/SECURITY.md has vulnerability reporting" # Estate-tolerant: credit any documented response SLA phrasing, not just # the literal "24 hours" (repos use "Response Timeline", "business day", etc.) - check_file_contains "SECURITY.md" "24 hours\\|48 hours\\|72 hours\\|business day\\|[Rr]esponse [Tt]ime\\|SLA" "SECURITY.md has response timeline" + check_file_contains "3-practice/SECURITY.md" "24 hours\\|48 hours\\|72 hours\\|business day\\|[Rr]esponse [Tt]ime\\|SLA" "3-practice/SECURITY.md has response timeline" fi # CONTRIBUTING.md validation (TPCF) diff --git a/rhodium-standard-repositories/rsr-check.scm b/rhodium-standard-repositories/rsr-check.scm index 0d6e1ef91..557f2ff5c 100644 --- a/rhodium-standard-repositories/rsr-check.scm +++ b/rhodium-standard-repositories/rsr-check.scm @@ -190,19 +190,19 @@ (check 2 "2.1.2" "LICENSE.txt present (plain text)" (lambda () (file-exists? (repo-file "LICENSE.txt")))) - ;; 2.1.3 - SECURITY.md - (check 2 "2.1.3" "SECURITY.md present" - (lambda () (file-exists? (repo-file "SECURITY.md")))) + ;; 2.1.3 - 3-practice/SECURITY.md + (check 2 "2.1.3" "3-practice/SECURITY.md present" + (lambda () (file-exists? (repo-file "3-practice/SECURITY.md")))) ;; 2.1.4 - Code of Conduct (check 2 "2.1.4" "CODE_OF_CONDUCT present" (lambda () (or (file-exists? (repo-file "CODE_OF_CONDUCT.md")) - (file-exists? (repo-file "CODE_OF_CONDUCT.adoc"))))) + (file-exists? (repo-file "3-practice/CODE_OF_CONDUCT.adoc"))))) ;; 2.1.5 - Contributing (check 2 "2.1.5" "CONTRIBUTING present" (lambda () (or (file-exists? (repo-file "CONTRIBUTING.md")) - (file-exists? (repo-file "CONTRIBUTING.adoc"))))) + (file-exists? (repo-file "3-practice/CONTRIBUTING.adoc"))))) ;; 2.1.6 - Funding (check 2 "2.1.6" "FUNDING.yml present" @@ -271,12 +271,12 @@ (check 3 "3.5.1" "No node_modules/ (post-JavaScript)" (lambda () (not (dir-exists? (repo-file "node_modules"))))) - ;; SECURITY.md content - (check 3 "sec.1" "SECURITY.md has vulnerability reporting" - (lambda () (file-contains? "SECURITY.md" "[Rr]eport"))) + ;; 3-practice/SECURITY.md content + (check 3 "sec.1" "3-practice/SECURITY.md has vulnerability reporting" + (lambda () (file-contains? "3-practice/SECURITY.md" "[Rr]eport"))) - (check 3 "sec.2" "SECURITY.md has response timeline" - (lambda () (file-contains? "SECURITY.md" "[0-9]+ hours?")))) + (check 3 "sec.2" "3-practice/SECURITY.md has response timeline" + (lambda () (file-contains? "3-practice/SECURITY.md" "[0-9]+ hours?")))) ;; ============================================================================= ;; Category 4: Architecture Principles (10%) @@ -342,11 +342,11 @@ ;; Code of Conduct (check 10 "10.1.1" "CODE_OF_CONDUCT present" (lambda () (or (file-exists? (repo-file "CODE_OF_CONDUCT.md")) - (file-exists? (repo-file "CODE_OF_CONDUCT.adoc"))))) + (file-exists? (repo-file "3-practice/CODE_OF_CONDUCT.adoc"))))) (check 10 "10.1.2" "CoC addresses harassment" (lambda () (or (file-contains? "CODE_OF_CONDUCT.md" "[Hh]arass") - (file-contains? "CODE_OF_CONDUCT.adoc" "[Hh]arass")))) + (file-contains? "3-practice/CODE_OF_CONDUCT.adoc" "[Hh]arass")))) ;; Governance (check 10 "10.2.1" "GOVERNANCE document present" @@ -356,7 +356,7 @@ ;; TPCF framework (check 10 "10.3.1" "TPCF mentioned in CONTRIBUTING" (lambda () (or (file-contains? "CONTRIBUTING.md" "TPCF\\|[Pp]erimeter") - (file-contains? "CONTRIBUTING.adoc" "TPCF\\|[Pp]erimeter"))))) + (file-contains? "3-practice/CONTRIBUTING.adoc" "TPCF\\|[Pp]erimeter"))))) ;; ============================================================================= ;; Scoring & Tier Calculation diff --git a/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl b/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl index 590e21ca3..4b87f5b7b 100644 --- a/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl +++ b/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl @@ -26,7 +26,7 @@ rsr_standards = { required_files = [ { path = "LICENSE", description = "SPDX-compatible license (PMPL-1.0-or-later recommended)" }, { path = "README.adoc", description = "AsciiDoc README with project overview" }, - { path = "SECURITY.md", description = "Security policy and vulnerability reporting" }, + { path = "3-practice/SECURITY.md", description = "Security policy and vulnerability reporting" }, { path = "CONTRIBUTING.md", description = "Contribution guidelines" }, { path = "STATE.scm", description = "Current project state (Scheme format)" }, { path = "ECOSYSTEM.scm", description = "Ecosystem relationships (Scheme format)" }, diff --git a/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/README.adoc b/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/README.adoc index 59ac880cb..3b9cf3ef0 100644 --- a/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/README.adoc +++ b/rhodium-standard-repositories/satellites/ECOSYSTEM.scm/README.adoc @@ -351,7 +351,7 @@ ECOSYSTEM.scm/ │ └── scm-family.schema.json # Unified validation schema ├── CONTRIBUTING.md ├── CODE_OF_CONDUCT.md -├── SECURITY.md +├── 3-practice/SECURITY.md └── LICENSE # MIT ---- diff --git a/rhodium-standard-repositories/satellites/META.scm/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/META.scm/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/rhodium-standard-repositories/satellites/META.scm/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/META.scm/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/rhodium-standard-repositories/satellites/cccp/README.adoc b/rhodium-standard-repositories/satellites/cccp/README.adoc index a1f8c122c..e2fed8d39 100644 --- a/rhodium-standard-repositories/satellites/cccp/README.adoc +++ b/rhodium-standard-repositories/satellites/cccp/README.adoc @@ -270,7 +270,7 @@ Projects can display CCCP certification when they: CCCP is a living document. Contributions that align with its principles are welcome. -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc] for guidelines. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for guidelines. == License diff --git a/rhodium-standard-repositories/satellites/cccp/SECURITY.adoc b/rhodium-standard-repositories/satellites/cccp/SECURITY.adoc index 2ce85d158..2f9e87052 100644 --- a/rhodium-standard-repositories/satellites/cccp/SECURITY.adoc +++ b/rhodium-standard-repositories/satellites/cccp/SECURITY.adoc @@ -410,7 +410,7 @@ When using Standards, we recommend: * https://github.com/hyperpolymath/standards/security/advisories[Security Advisories] * link:CHANGELOG.md[Changelog] -* link:CONTRIBUTING.adoc[Contributing Guidelines] +* link:3-practice/CONTRIBUTING.adoc[Contributing Guidelines] * https://cve.mitre.org/[CVE Database] * https://www.first.org/cvss/calculator/3.1[CVSS Calculator] diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.gitlab-ci.yml b/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.gitlab-ci.yml index a7f843943..6c1395ab4 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.gitlab-ci.yml +++ b/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.gitlab-ci.yml @@ -18,9 +18,9 @@ validate: - echo "Validating project structure..." - test -f README.adoc - test -f LICENSE.txt - - test -f SECURITY.md - - test -f CODE_OF_CONDUCT.adoc - - test -f CONTRIBUTING.adoc + - test -f 3-practice/SECURITY.md + - test -f 3-practice/CODE_OF_CONDUCT.adoc + - test -f 3-practice/CONTRIBUTING.adoc - test -f 0-canon/GOVERNANCE.adoc - test -d curriculum - test -d agents diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/README.adoc b/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/README.adoc index 8b5759b67..8968045ab 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/README.adoc +++ b/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/README.adoc @@ -111,7 +111,7 @@ seven-tentacles/ == Contributing -We welcome contributions! Please see our link:CONTRIBUTING.adoc[contribution guidelines]. +We welcome contributions! Please see our link:3-practice/CONTRIBUTING.adoc[contribution guidelines]. === Priority Areas diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml index 569268988..e4ab025ee 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml +++ b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml @@ -215,9 +215,9 @@ jobs: run: | DOCS="" [ -f "README.md" ] || [ -f "README.adoc" ] && DOCS="$DOCS README" - [ -f "CONTRIBUTING.md" ] || [ -f "CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" + [ -f "CONTRIBUTING.md" ] || [ -f "3-practice/CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" [ -f "CHANGELOG.md" ] && DOCS="$DOCS CHANGELOG" - [ -f "SECURITY.md" ] && DOCS="$DOCS SECURITY" + [ -f "3-practice/SECURITY.md" ] && DOCS="$DOCS SECURITY" [ -d "docs" ] && DOCS="$DOCS docs/" echo "Documentation:$DOCS" - name: Check code comments diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/CONTRIBUTING.adoc index 39b5cf3ef..1c10a506d 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/CONTRIBUTING.adoc @@ -90,7 +90,7 @@ vendor/bin/php-cs-fixer fix Given the security-focused nature of this project: * *Do not* submit PRs that fix security vulnerabilities publicly -* Instead, follow the process in SECURITY.md +* Instead, follow the process in 3-practice/SECURITY.md * Security enhancements (new features) can be submitted normally === License diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/README.adoc b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/README.adoc index 45b2a7254..be12d86da 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/README.adoc +++ b/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/README.adoc @@ -240,9 +240,9 @@ MIT License - See link:LICENSE.txt[LICENSE.txt] for details. == Contributing -Contributions welcome! Please read link:CONTRIBUTING.adoc[CONTRIBUTING.adoc] first. +Contributions welcome! Please read link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] first. -For security vulnerabilities, see link:SECURITY.adoc[SECURITY.adoc]. +For security vulnerabilities, see link:3-practice/SECURITY.adoc[3-practice/SECURITY.adoc]. == RSR Compliance diff --git a/rhodium-standard-repositories/satellites/cccp/satellites/sanctify-php/.github/workflows/comprehensive-quality.yml b/rhodium-standard-repositories/satellites/cccp/satellites/sanctify-php/.github/workflows/comprehensive-quality.yml index 6b5e3cb23..2ff46e993 100644 --- a/rhodium-standard-repositories/satellites/cccp/satellites/sanctify-php/.github/workflows/comprehensive-quality.yml +++ b/rhodium-standard-repositories/satellites/cccp/satellites/sanctify-php/.github/workflows/comprehensive-quality.yml @@ -215,9 +215,9 @@ jobs: run: | DOCS="" [ -f "README.md" ] || [ -f "README.adoc" ] && DOCS="$DOCS README" - [ -f "CONTRIBUTING.md" ] || [ -f "CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" + [ -f "CONTRIBUTING.md" ] || [ -f "3-practice/CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" [ -f "CHANGELOG.md" ] && DOCS="$DOCS CHANGELOG" - [ -f "SECURITY.md" ] && DOCS="$DOCS SECURITY" + [ -f "3-practice/SECURITY.md" ] && DOCS="$DOCS SECURITY" [ -d "docs" ] && DOCS="$DOCS docs/" echo "Documentation:$DOCS" - name: Check code comments diff --git a/rhodium-standard-repositories/satellites/mustfile/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/mustfile/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/rhodium-standard-repositories/satellites/mustfile/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/mustfile/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/.git-hooks/pre-push b/rhodium-standard-repositories/satellites/palimpsest-license/.git-hooks/pre-push index da76ee589..c5beb84ff 100755 --- a/rhodium-standard-repositories/satellites/palimpsest-license/.git-hooks/pre-push +++ b/rhodium-standard-repositories/satellites/palimpsest-license/.git-hooks/pre-push @@ -213,7 +213,7 @@ else # Manual RSR check print_info "Performing manual RSR file check..." - REQUIRED_FILES="CLAUDE.md MAINTAINERS.md TPCF.md .well-known/security.txt .well-known/ai.txt .well-known/humans.txt CHANGELOG.md GOVERNANCE.md CONTRIBUTING.md CODE_OF_PRACTICE.md SECURITY.md" + REQUIRED_FILES="CLAUDE.md MAINTAINERS.md TPCF.md .well-known/security.txt .well-known/ai.txt .well-known/humans.txt CHANGELOG.md GOVERNANCE.md CONTRIBUTING.md CODE_OF_PRACTICE.md 3-practice/SECURITY.md" MISSING_FILES=0 for file in $REQUIRED_FILES; do diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/.github/CODEOWNERS b/rhodium-standard-repositories/satellites/palimpsest-license/.github/CODEOWNERS index 4b8d50b49..b2a563dbb 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/.github/CODEOWNERS +++ b/rhodium-standard-repositories/satellites/palimpsest-license/.github/CODEOWNERS @@ -2,7 +2,7 @@ # Format: [Path] [GitHub Username/Team] # Root files (README, LICENSE, etc.) -README.md LICENSE CONTRIBUTING.md CODE_OF_CONDUCT.md GOVERNANCE.md SECURITY.md @your-github-username +README.md LICENSE CONTRIBUTING.md CODE_OF_CONDUCT.md GOVERNANCE.md 3-practice/SECURITY.md @your-github-username CHANGELOG.md @your-github-username # License texts diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/.rvc/config.yml b/rhodium-standard-repositories/satellites/palimpsest-license/.rvc/config.yml index 048f239d2..6648f88c0 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/.rvc/config.yml +++ b/rhodium-standard-repositories/satellites/palimpsest-license/.rvc/config.yml @@ -427,7 +427,7 @@ exclusions: - ".git/" - ".well-known/" - "GOVERNANCE.md" - - "SECURITY.md" + - "3-practice/SECURITY.md" - "CODE_OF_PRACTICE.md" # Files to never modify diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/CLAUDE.md b/rhodium-standard-repositories/satellites/palimpsest-license/CLAUDE.md index d44cf250d..2d739eba0 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/CLAUDE.md +++ b/rhodium-standard-repositories/satellites/palimpsest-license/CLAUDE.md @@ -47,7 +47,7 @@ palimpsest-license/ ├── CODE_OF_CONDUCT.md # Community standards ├── GOVERNANCE.md # Decision-making process ├── MAINTAINERS.md # Project maintainers -├── SECURITY.md # Security policy +├── 3-practice/SECURITY.md # Security policy ├── FUNDING.md # Funding strategy ├── CLAUDE.md # AI assistant context │ diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/CODE_OF_PRACTICE.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/CODE_OF_PRACTICE.adoc index c43853b3c..8f3114197 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/CODE_OF_PRACTICE.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/CODE_OF_PRACTICE.adoc @@ -3,7 +3,7 @@ ____ *Note:* This Markdown version is maintained for backwards compatibility. The canonical version is now -link:./CODE_OF_CONDUCT.adoc[CODE_OF_CONDUCT.adoc] (AsciiDoc format, +link:./CODE_OF_CONDUCT.adoc[3-practice/CODE_OF_CONDUCT.adoc] (AsciiDoc format, renamed from CODE_OF_PRACTICE for RSR Gold compliance). ____ diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/CONTRIBUTING.adoc index 1a225b7a4..b16b059d7 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/CONTRIBUTING.adoc @@ -2,7 +2,7 @@ ____ *Note:* This Markdown version is maintained for backwards compatibility. -The canonical version is now link:./CONTRIBUTING.adoc[CONTRIBUTING.adoc] +The canonical version is now link:./CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] (AsciiDoc format) for RSR Gold compliance. ____ diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/LICENSE.txt b/rhodium-standard-repositories/satellites/palimpsest-license/LICENSE.txt index 911fc99c4..9e141d858 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/LICENSE.txt +++ b/rhodium-standard-repositories/satellites/palimpsest-license/LICENSE.txt @@ -85,7 +85,7 @@ CONTACT & GOVERNANCE Project Repository: https://github.com/palimpsest-license/palimpsest-license Governance Model: See GOVERNANCE.md Contributing Guidelines: See CONTRIBUTING.md -Security Policy: See SECURITY.md +Security Policy: See 3-practice/SECURITY.md Code of Practice: See CODE_OF_PRACTICE.md For legal inquiries or license clarification: diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/MAINTAINERS.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/MAINTAINERS.adoc index 828db24e6..b3dea17a5 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/MAINTAINERS.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/MAINTAINERS.adoc @@ -193,7 +193,7 @@ required * *Email*: security@palimpsest-license.org * *PGP Key*: [Link to public key] -* *Disclosure Policy*: See SECURITY.md +* *Disclosure Policy*: See 3-practice/SECURITY.md ==== Legal & Governance diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/CURRENT_STATE_INVENTORY.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/CURRENT_STATE_INVENTORY.adoc index e14edeeff..69f6c6b53 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/CURRENT_STATE_INVENTORY.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/CURRENT_STATE_INVENTORY.adoc @@ -27,7 +27,7 @@ consent framework |`+CODE_OF_CONDUCT.md+` |✅ COMPLETE |Community standards -|`+SECURITY.md+` |✅ COMPLETE |Security policy +|`+3-practice/SECURITY.md+` |✅ COMPLETE |Security policy |=== ==== 1.2 Documentation diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/DOCUMENT_REVIEW_SYSTEM.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/DOCUMENT_REVIEW_SYSTEM.adoc index 2873316eb..bb240ac4f 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/DOCUMENT_REVIEW_SYSTEM.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/DOCUMENT_REVIEW_SYSTEM.adoc @@ -210,7 +210,7 @@ Critical legal documents: - `+LICENSE_CORE/AGREEMENTS/AGI-consent.md+` Governance: - `+GOVERNANCE.md+` - `+CONTRIBUTING.md+` - -`+CODE_OF_CONDUCT.md+` - `+CODE_OF_PRACTICE.md+` - `+SECURITY.md+` +`+CODE_OF_CONDUCT.md+` - `+CODE_OF_PRACTICE.md+` - `+3-practice/SECURITY.md+` Documentation: - `+docs/ethics.md+` - `+docs/ethics-FAQ.md+` - `+docs/jurisdiction-comparison.md+` - All files in `+GUIDES_v0.4/+` (may diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/RECONCILIATION_AUDIT.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/RECONCILIATION_AUDIT.adoc index 039edccd7..519f19fa7 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/RECONCILIATION_AUDIT.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/PROJECT_MANAGEMENT/RECONCILIATION_AUDIT.adoc @@ -55,7 +55,7 @@ Melange browser support |Governance structure |GitHub |Complete council framework -|Press/lobby kit |GitHub |More developed than GitLab `+outreach/+` +|Press/lobby kit |GitHub |More developed than GitLab `+3-practice/outreach/+` |=== ''''' diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/README.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/README.adoc index 671ccb069..0271abf33 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/README.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/README.adoc @@ -51,7 +51,7 @@ See link:LICENSE[LICENSE] for details. == Contributing -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc]. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc]. == Metadata diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/README.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/README.adoc index 1d0c7194e..d77dd1efc 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/README.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/README.adoc @@ -47,7 +47,7 @@ bof-meetings/ │ └── qa-preparation.md # Comprehensive Q&A prep ├── stakeholders/ # Stakeholder identification │ └── key-stakeholders.md # Individuals and orgs by conference -└── outreach/ # Communication materials +└── 3-practice/outreach/ # Communication materials ├── email-invitation-tier1.md # Personal invitations (VIPs) ├── email-templates-collection.md # All email templates ├── mailing-list-announcements.md # Conference list drafts @@ -141,10 +141,10 @@ before) ==== For Outreach Coordinators [arabic] -. *Use email templates* from `+outreach/email-templates-collection.md+` +. *Use email templates* from `+3-practice/outreach/email-templates-collection.md+` . *Send mailing list announcements* 4-6 weeks before conference . *Execute social media campaign* per -`+outreach/social-media-campaign.md+` +`+3-practice/outreach/social-media-campaign.md+` . *Track engagement* using stakeholder database . *Follow up* using `+follow-up-action-plan.md+` diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/follow-up-action-plan.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/follow-up-action-plan.adoc index eecb748e3..54067a694 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/follow-up-action-plan.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/bof-meetings/follow-up-action-plan.adoc @@ -32,7 +32,7 @@ information * [ ] *Connect interested parties* to relevant working groups * [ ] *Invite to mailing list* for ongoing discussions -*Template*: See `+outreach/email-followup-attendees.md+` *Responsible*: +*Template*: See `+3-practice/outreach/email-followup-attendees.md+` *Responsible*: Lead organizer ''''' @@ -62,7 +62,7 @@ questions * [ ] *Conference-specific report* (for IETF: post to datatracker; for RIPE: RIPE Labs article) -*Templates*: See `+outreach/templates/+` *Publication channels*: - +*Templates*: See `+3-practice/outreach/templates/+` *Publication channels*: - palimpsest-license.org/blog - GitHub discussions - Conference mailing lists - Social media (Mastodon, Twitter/X, LinkedIn) diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/scripts/generate-structure.sh b/rhodium-standard-repositories/satellites/palimpsest-license/scripts/generate-structure.sh index e075fc8c4..7a6266e96 100755 --- a/rhodium-standard-repositories/satellites/palimpsest-license/scripts/generate-structure.sh +++ b/rhodium-standard-repositories/satellites/palimpsest-license/scripts/generate-structure.sh @@ -45,7 +45,7 @@ palimpsest-license/ ├── CODE_OF_CONDUCT.md # Community standards ├── GOVERNANCE.md # Decision-making process ├── MAINTAINERS.md # Project maintainers -├── SECURITY.md # Security policy +├── 3-practice/SECURITY.md # Security policy ├── FUNDING.md # Funding strategy ├── CLAUDE.md # AI assistant context │ diff --git a/rhodium-standard-repositories/satellites/palimpsest-license/standards/TPCF.adoc b/rhodium-standard-repositories/satellites/palimpsest-license/standards/TPCF.adoc index 77cdaf83b..7ab5519da 100644 --- a/rhodium-standard-repositories/satellites/palimpsest-license/standards/TPCF.adoc +++ b/rhodium-standard-repositories/satellites/palimpsest-license/standards/TPCF.adoc @@ -288,7 +288,7 @@ The Palimpsest License project maintains TPCF compliance through: review requirements) * [x] *Contribution guidelines published* (CONTRIBUTING.md) * [x] *Maintainer roster maintained* (MAINTAINERS.md) -* [x] *Security disclosure process* (SECURITY.md, security.txt) +* [x] *Security disclosure process* (3-practice/SECURITY.md, security.txt) * [x] *Code of Practice* (CODE_OF_PRACTICE.md) * [x] *Governance model* (GOVERNANCE.md) * [x] *CI/CD security checks* (.github/workflows/) @@ -304,7 +304,7 @@ sensitivity) * *TPCF Original Paper*: [Link to academic paper on graduated trust] * *Palimpsest Governance*: GOVERNANCE.md * *Contributing Guide*: CONTRIBUTING.md -* *Security Policy*: SECURITY.md +* *Security Policy*: 3-practice/SECURITY.md ''''' diff --git a/rhodium-standard-repositories/satellites/robot-repo-automaton/README.adoc b/rhodium-standard-repositories/satellites/robot-repo-automaton/README.adoc index f6507e947..c6b35ee58 100644 --- a/rhodium-standard-repositories/satellites/robot-repo-automaton/README.adoc +++ b/rhodium-standard-repositories/satellites/robot-repo-automaton/README.adoc @@ -51,7 +51,7 @@ See link:LICENSE[LICENSE] for details. == Contributing -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc]. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc]. == Metadata diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/MAINTAINERS.adoc b/rhodium-standard-repositories/satellites/rsr-certifier/MAINTAINERS.adoc index 660c7b666..476a228c9 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/MAINTAINERS.adoc +++ b/rhodium-standard-repositories/satellites/rsr-certifier/MAINTAINERS.adoc @@ -52,7 +52,7 @@ To become a maintainer: === Contact -* *Security Issues*: See SECURITY.md +* *Security Issues*: See 3-practice/SECURITY.md * *General*: Open an issue * *Private*: maintainers@rsr-certified.dev diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/README.adoc b/rhodium-standard-repositories/satellites/rsr-certifier/README.adoc index 0090f9508..3b8b53cc3 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/README.adoc +++ b/rhodium-standard-repositories/satellites/rsr-certifier/README.adoc @@ -401,7 +401,7 @@ kubectl apply -f container/k8s/deployment.yaml |Planned |`silver.security_policy` -|SECURITY.md present +|3-practice/SECURITY.md present |Planned |`silver.changelog` @@ -493,7 +493,7 @@ We follow the RSR Tri-Perimeter Contribution Framework: == Security -See link:SECURITY.md[SECURITY.md] for our security policy and vulnerability reporting process. +See link:3-practice/SECURITY.md[3-practice/SECURITY.md] for our security policy and vulnerability reporting process. == License diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/ROADMAP.adoc b/rhodium-standard-repositories/satellites/rsr-certifier/ROADMAP.adoc index 1df58d323..2e80d3bab 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/ROADMAP.adoc +++ b/rhodium-standard-repositories/satellites/rsr-certifier/ROADMAP.adoc @@ -117,7 +117,7 @@ RSR-Certified is in active development with a functional core engine and substan [%interactive] * [ ] `silver.contributing` - CONTRIBUTING.md validation * [ ] `silver.code_of_conduct` - CODE_OF_CONDUCT.md validation -* [ ] `silver.security_policy` - SECURITY.md validation +* [ ] `silver.security_policy` - 3-practice/SECURITY.md validation * [ ] `silver.changelog` - CHANGELOG presence and format * [ ] `silver.ci_config` - CI/CD configuration detection (GitHub Actions, GitLab CI, etc.) * [ ] `silver.issue_templates` - Issue/PR template validation diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/docs/RSR_ALIGNMENT.adoc b/rhodium-standard-repositories/satellites/rsr-certifier/docs/RSR_ALIGNMENT.adoc index e7c369a1d..cfa3e7437 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/docs/RSR_ALIGNMENT.adoc +++ b/rhodium-standard-repositories/satellites/rsr-certifier/docs/RSR_ALIGNMENT.adoc @@ -57,7 +57,7 @@ Standard Repositories] framework. * [x] README → `+bronze.readme+` * [x] LICENSE → `+bronze.license+` -* [x] SECURITY.md → `+silver.security_policy+` +* [x] 3-practice/SECURITY.md → `+silver.security_policy+` * [x] CODE_OF_CONDUCT.md → `+silver.code_of_conduct+` * [x] CONTRIBUTING.md → `+silver.contributing+` * [ ] .well-known/ directory → _Planned for Rhodium tier_ @@ -99,7 +99,7 @@ This repository (`+git-rsr-certified+`) aims to achieve *RSR Gold ✓ README.md ✓ CONTRIBUTING.md ✓ CODE_OF_CONDUCT.md -✓ SECURITY.md +✓ 3-practice/SECURITY.md ✓ CI/CD (.github/workflows/) ✓ Containerized deployment ✓ Dependency management (Cargo.lock) diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/rhodium.rs b/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/rhodium.rs index 9d10ee3ab..11299e04d 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/rhodium.rs +++ b/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/rhodium.rs @@ -284,8 +284,8 @@ impl ComplianceCheck for ThreatModelCheck { } } - // Check SECURITY.md for threat model section - let security_path = path.join("SECURITY.md"); + // Check 3-practice/SECURITY.md for threat model section + let security_path = path.join("3-practice/SECURITY.md"); if security_path.exists() { if let Ok(content) = std::fs::read_to_string(&security_path) { let content_lower = content.to_lowercase(); @@ -295,7 +295,7 @@ impl ComplianceCheck for ThreatModelCheck { name: self.name().to_string(), tier: self.tier(), passed: true, - message: "Threat model found in SECURITY.md".to_string(), + message: "Threat model found in 3-practice/SECURITY.md".to_string(), details: None, }); } diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/silver.rs b/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/silver.rs index fbbc33331..327902580 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/silver.rs +++ b/rhodium-standard-repositories/satellites/rsr-certifier/engine/src/compliance/silver.rs @@ -33,7 +33,7 @@ impl ComplianceCheck for ContributingCheck { } async fn check_local(&self, path: &Path) -> Result { - let files = ["CONTRIBUTING.md", "CONTRIBUTING.adoc", "CONTRIBUTING.rst", ".github/CONTRIBUTING.md"]; + let files = ["CONTRIBUTING.md", "3-practice/CONTRIBUTING.adoc", "CONTRIBUTING.rst", ".github/CONTRIBUTING.md"]; for name in files { let file_path = path.join(name); @@ -347,7 +347,7 @@ impl ComplianceCheck for CiConfigCheck { } } -/// Check for SECURITY.md +/// Check for 3-practice/SECURITY.md pub struct SecurityPolicyCheck; #[async_trait::async_trait] @@ -365,7 +365,7 @@ impl ComplianceCheck for SecurityPolicyCheck { } async fn check_local(&self, path: &Path) -> Result { - let files = ["SECURITY.md", ".github/SECURITY.md"]; + let files = ["3-practice/SECURITY.md", ".github/SECURITY.md"]; for name in files { let file_path = path.join(name); @@ -389,8 +389,8 @@ impl ComplianceCheck for SecurityPolicyCheck { name: self.name().to_string(), tier: self.tier(), passed: false, - message: "No SECURITY.md found".to_string(), - details: Some("Add SECURITY.md with vulnerability disclosure process".to_string()), + message: "No 3-practice/SECURITY.md found".to_string(), + details: Some("Add 3-practice/SECURITY.md with vulnerability disclosure process".to_string()), }) } @@ -424,7 +424,7 @@ impl ComplianceCheck for SecurityPolicyCheck { name: self.name().to_string(), tier: self.tier(), passed: false, - message: "No SECURITY.md found".to_string(), + message: "No 3-practice/SECURITY.md found".to_string(), details: None, }) } diff --git a/rhodium-standard-repositories/satellites/rsr-certifier/schemas/rsr-config.schema.json b/rhodium-standard-repositories/satellites/rsr-certifier/schemas/rsr-config.schema.json index f152d7357..a130fde00 100644 --- a/rhodium-standard-repositories/satellites/rsr-certifier/schemas/rsr-config.schema.json +++ b/rhodium-standard-repositories/satellites/rsr-certifier/schemas/rsr-config.schema.json @@ -66,7 +66,7 @@ "require_policy": { "type": "boolean", "default": true, - "description": "Require SECURITY.md file" + "description": "Require 3-practice/SECURITY.md file" }, "scan_secrets": { "type": "boolean", diff --git a/rhodium-standard-repositories/satellites/rsr-deployer/CONTRIBUTING.adoc b/rhodium-standard-repositories/satellites/rsr-deployer/CONTRIBUTING.adoc index d16ec0c1e..19f6bd8ff 100644 --- a/rhodium-standard-repositories/satellites/rsr-deployer/CONTRIBUTING.adoc +++ b/rhodium-standard-repositories/satellites/rsr-deployer/CONTRIBUTING.adoc @@ -31,7 +31,7 @@ Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├── -MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake +MAINTAINERS.md ├── README.adoc ├── 3-practice/SECURITY.md ├── flake.nix # Nix flake (Perimeter 1) └── Justfile # Task runner (Perimeter 1) .... diff --git a/rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml b/rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml index bb549c75b..010a5071b 100644 --- a/rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml +++ b/rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml @@ -191,9 +191,9 @@ jobs: run: | DOCS="" [ -f "README.md" ] || [ -f "README.adoc" ] && DOCS="$DOCS README" - [ -f "CONTRIBUTING.md" ] || [ -f "CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" + [ -f "CONTRIBUTING.md" ] || [ -f "3-practice/CONTRIBUTING.adoc" ] && DOCS="$DOCS CONTRIBUTING" [ -f "CHANGELOG.md" ] && DOCS="$DOCS CHANGELOG" - [ -f "SECURITY.md" ] && DOCS="$DOCS SECURITY" + [ -f "3-practice/SECURITY.md" ] && DOCS="$DOCS SECURITY" [ -d "docs" ] && DOCS="$DOCS docs/" echo "Documentation:$DOCS" - name: Check code comments diff --git a/rhodium-standard-repositories/satellites/state.scm/.gitlab-ci.yml b/rhodium-standard-repositories/satellites/state.scm/.gitlab-ci.yml index 2c5efdf20..22d8b1d21 100644 --- a/rhodium-standard-repositories/satellites/state.scm/.gitlab-ci.yml +++ b/rhodium-standard-repositories/satellites/state.scm/.gitlab-ci.yml @@ -68,9 +68,9 @@ pages: - mkdir -p public - asciidoctor README.adoc -o public/index.html - asciidoctor USAGE.adoc -o public/usage.html - - asciidoctor CONTRIBUTING.adoc -o public/contributing.html + - asciidoctor 3-practice/CONTRIBUTING.adoc -o public/contributing.html - asciidoctor 0-canon/GOVERNANCE.adoc -o public/governance.html - - asciidoctor CODE_OF_CONDUCT.adoc -o public/code-of-conduct.html + - asciidoctor 3-practice/CODE_OF_CONDUCT.adoc -o public/code-of-conduct.html artifacts: paths: - public diff --git a/rhodium-standard-repositories/satellites/state.scm/CHANGELOG.adoc b/rhodium-standard-repositories/satellites/state.scm/CHANGELOG.adoc index 969a160cc..64e798ac9 100644 --- a/rhodium-standard-repositories/satellites/state.scm/CHANGELOG.adoc +++ b/rhodium-standard-repositories/satellites/state.scm/CHANGELOG.adoc @@ -34,9 +34,9 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. ** Full unification support * *RSR compliance*: Rhodium Standard Repositories files ** LICENSE.txt (MIT + Palimpsest v0.8) -** SECURITY.md -** CODE_OF_CONDUCT.adoc -** CONTRIBUTING.adoc +** 3-practice/SECURITY.md +** 3-practice/CODE_OF_CONDUCT.adoc +** 3-practice/CONTRIBUTING.adoc ** 0-canon/GOVERNANCE.adoc ** flake.nix for Nix reproducibility ** Justfile for task automation diff --git a/rhodium-standard-repositories/satellites/state.scm/GOVERNANCE.adoc b/rhodium-standard-repositories/satellites/state.scm/GOVERNANCE.adoc index 0f08ba125..ac673a128 100644 --- a/rhodium-standard-repositories/satellites/state.scm/GOVERNANCE.adoc +++ b/rhodium-standard-repositories/satellites/state.scm/GOVERNANCE.adoc @@ -106,7 +106,7 @@ Nomination process: == Code of Conduct -All participants must follow the CODE_OF_CONDUCT.adoc. +All participants must follow the 3-practice/CODE_OF_CONDUCT.adoc. Violations are handled by the maintainer with escalation to external mediators if needed. @@ -123,5 +123,5 @@ This governance document may be changed through: == Contact * Issues: GitLab issue tracker -* Security: See SECURITY.md +* Security: See 3-practice/SECURITY.md * General: Project mailing list (if applicable) diff --git a/rhodium-standard-repositories/satellites/state.scm/PROJECT-STATUS.adoc b/rhodium-standard-repositories/satellites/state.scm/PROJECT-STATUS.adoc index ff25fadd9..9dc34a1db 100644 --- a/rhodium-standard-repositories/satellites/state.scm/PROJECT-STATUS.adoc +++ b/rhodium-standard-repositories/satellites/state.scm/PROJECT-STATUS.adoc @@ -94,9 +94,9 @@ STATE is actively maintained and under development. == Support * *Issues*: GitHub/GitLab issue tracker -* *Security*: See SECURITY.adoc -* *Contributing*: See CONTRIBUTING.adoc +* *Security*: See 3-practice/SECURITY.adoc +* *Contributing*: See 3-practice/CONTRIBUTING.adoc == Maintainers -See MAINTAINERS.adoc for current maintainers. +See 3-practice/MAINTAINERS.adoc for current maintainers. diff --git a/rhodium-standard-repositories/satellites/state.scm/README.adoc b/rhodium-standard-repositories/satellites/state.scm/README.adoc index 2b24f17ca..b48fd6866 100644 --- a/rhodium-standard-repositories/satellites/state.scm/README.adoc +++ b/rhodium-standard-repositories/satellites/state.scm/README.adoc @@ -188,9 +188,9 @@ Comparison: * `README.adoc` - This documentation * `USAGE.adoc` - Comprehensive usage guide * `CHANGELOG.adoc` - Version history -* `CONTRIBUTING.adoc` - Contribution guidelines +* `3-practice/CONTRIBUTING.adoc` - Contribution guidelines * `0-canon/GOVERNANCE.adoc` - Project governance -* `CODE_OF_CONDUCT.adoc` - Community standards +* `3-practice/CODE_OF_CONDUCT.adoc` - Community standards === Infrastructure diff --git a/rhodium-standard-repositories/satellites/state.scm/spec/README.adoc b/rhodium-standard-repositories/satellites/state.scm/spec/README.adoc index 00ebf67aa..7e5f332fb 100644 --- a/rhodium-standard-repositories/satellites/state.scm/spec/README.adoc +++ b/rhodium-standard-repositories/satellites/state.scm/spec/README.adoc @@ -97,7 +97,7 @@ The ABNF grammar can be used with ABNF parser generators: === Contributing -See link:../CONTRIBUTING.adoc[CONTRIBUTING.adoc] for contribution guidelines. +See link:../CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc] for contribution guidelines. Specification changes require: diff --git a/rhodium-standard-repositories/satellites/well-known-ecosystem/README.adoc b/rhodium-standard-repositories/satellites/well-known-ecosystem/README.adoc index 747c67ea1..dc1b4ffde 100644 --- a/rhodium-standard-repositories/satellites/well-known-ecosystem/README.adoc +++ b/rhodium-standard-repositories/satellites/well-known-ecosystem/README.adoc @@ -51,7 +51,7 @@ See link:LICENSE[LICENSE] for details. == Contributing -See link:CONTRIBUTING.adoc[CONTRIBUTING.adoc]. +See link:3-practice/CONTRIBUTING.adoc[3-practice/CONTRIBUTING.adoc]. == Metadata diff --git a/rhodium-standard-repositories/spec.scm/compliance-criteria.scm b/rhodium-standard-repositories/spec.scm/compliance-criteria.scm index 425b4a722..fb3aef5e9 100644 --- a/rhodium-standard-repositories/spec.scm/compliance-criteria.scm +++ b/rhodium-standard-repositories/spec.scm/compliance-criteria.scm @@ -39,7 +39,7 @@ (criteria ((id . "2.1.1") (name . "readme") (description . "README.md or README.adoc")) ((id . "2.1.2") (name . "license") (description . "LICENSE.txt (plain text)")) - ((id . "2.1.3") (name . "security") (description . "SECURITY.md")) + ((id . "2.1.3") (name . "security") (description . "3-practice/SECURITY.md")) ((id . "2.1.4") (name . "coc") (description . "CODE_OF_CONDUCT.md/.adoc")) ((id . "2.1.5") (name . "contributing") (description . "CONTRIBUTING.md/.adoc")) ((id . "2.1.6") (name . "funding") (description . "FUNDING.yml")) diff --git a/rhodium-standard-repositories/spec.scm/tiers.scm b/rhodium-standard-repositories/spec.scm/tiers.scm index a55d8a8f6..be5ce6e50 100644 --- a/rhodium-standard-repositories/spec.scm/tiers.scm +++ b/rhodium-standard-repositories/spec.scm/tiers.scm @@ -41,7 +41,7 @@ (required-files "README.md" "README.adoc" ; one of "LICENSE.txt" - "SECURITY.md" + "3-practice/SECURITY.md" ".gitignore" ".gitattributes") (ci-cd . #t) @@ -50,8 +50,8 @@ (silver (includes . bronze) (required-files - "CODE_OF_CONDUCT.md" "CODE_OF_CONDUCT.adoc" - "CONTRIBUTING.md" "CONTRIBUTING.adoc" + "CODE_OF_CONDUCT.md" "3-practice/CODE_OF_CONDUCT.adoc" + "CONTRIBUTING.md" "3-practice/CONTRIBUTING.adoc" "0-canon/GOVERNANCE.adoc" "MAINTAINERS.md" "FUNDING.yml") diff --git a/rhodium-standard-repositories/spec.scm/version.scm b/rhodium-standard-repositories/spec.scm/version.scm index 206c2de86..638017970 100644 --- a/rhodium-standard-repositories/spec.scm/version.scm +++ b/rhodium-standard-repositories/spec.scm/version.scm @@ -78,7 +78,7 @@ ;; - Banned: TypeScript, Node/npm, Go, Python (except SaltStack), Java/Kotlin, Swift ;; ;; 4. REQUIRED FILES (by tier) -;; - Bronze: README, LICENSE.txt, SECURITY.md, .gitignore, .gitattributes +;; - Bronze: README, LICENSE.txt, 3-practice/SECURITY.md, .gitignore, .gitattributes ;; - Silver: +0-canon/GOVERNANCE.adoc, MAINTAINERS.md, FUNDING.yml, .well-known/security.txt ;; - Gold: +STATE.scm, META.scm, ECOSYSTEM.scm, .well-known/{ai,humans,provenance} ;; - Rhodium: +Formal verification, community recognition diff --git a/rhodium-standard-repositories/templates/.well-known/humans.txt.template b/rhodium-standard-repositories/templates/.well-known/humans.txt.template index f92396c95..21adb0c1b 100644 --- a/rhodium-standard-repositories/templates/.well-known/humans.txt.template +++ b/rhodium-standard-repositories/templates/.well-known/humans.txt.template @@ -104,7 +104,7 @@ This project preserves human authorship through: - Provenance chains (.well-known/provenance.json) All contributors credited in CONTRIBUTORS.md. -Security researchers recognized in SECURITY.md. +Security researchers recognized in 3-practice/SECURITY.md. /* CONTACT */ diff --git a/rhodium-standard-repositories/templates/.well-known/security.txt.template b/rhodium-standard-repositories/templates/.well-known/security.txt.template index 57a8cbd7c..e8a94d9fe 100644 --- a/rhodium-standard-repositories/templates/.well-known/security.txt.template +++ b/rhodium-standard-repositories/templates/.well-known/security.txt.template @@ -15,6 +15,6 @@ Hiring: {careers-url, if applicable} # Additional Information # This project follows Rhodium Standard Repository (RSR) security practices. -# See SECURITY.md for full vulnerability reporting procedures and response SLA. +# See 3-practice/SECURITY.md for full vulnerability reporting procedures and response SLA. # Encryption key fingerprint: {PGP-key-fingerprint} # We support responsible disclosure and recognize security researchers. diff --git a/rhodium-standard-repositories/templates/CODEOWNERS.template b/rhodium-standard-repositories/templates/CODEOWNERS.template index 13759eaf4..cd2bd90eb 100644 --- a/rhodium-standard-repositories/templates/CODEOWNERS.template +++ b/rhodium-standard-repositories/templates/CODEOWNERS.template @@ -1,6 +1,6 @@ # SPDX-License-Identifier: MPL-2.0 # Solo-maintained hyperpolymath repo: no owner lines by policy. -# See hyperpolymath/standards CODEOWNERS-POLICY.adoc (Rule 1). +# See hyperpolymath/standards 3-practice/CODEOWNERS-POLICY.adoc (Rule 1). # Sole-maintainer review is moot; SPDX headers carry attribution. # # Multi-owner repos only: add path lines scoped to genuine co-owners diff --git a/rhodium-standard-repositories/templates/CONTRIBUTING.adoc.template b/rhodium-standard-repositories/templates/CONTRIBUTING.adoc.template index 25270d25c..0afcfbc38 100644 --- a/rhodium-standard-repositories/templates/CONTRIBUTING.adoc.template +++ b/rhodium-standard-repositories/templates/CONTRIBUTING.adoc.template @@ -314,7 +314,7 @@ git commit --no-verify # Use sparingly! == 🤝 Code of Conduct -All contributors must follow our link:CODE_OF_CONDUCT.adoc[Code of Conduct]. +All contributors must follow our link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct]. **In summary**: @@ -351,13 +351,13 @@ We track contributions transparently: - **Contributors**: All contributors listed in link:CONTRIBUTORS.md[CONTRIBUTORS.md] - **Attribution**: Git history preserves authorship -- **Recognition**: Security researchers in link:SECURITY.md[Security Hall of Fame] +- **Recognition**: Security researchers in link:3-practice/SECURITY.md[Security Hall of Fame] == ❓ Questions? - **General questions**: link:{repo-url}/-/discussions[Discussions] - **Bug reports**: link:{repo-url}/-/issues[Issues] -- **Security issues**: link:SECURITY.md[Security policy] +- **Security issues**: link:3-practice/SECURITY.md[Security policy] - **Licence questions**: link:LICENSE-MIT[MIT] or link:LICENSE-PALIMPSEST[Palimpsest] == 🙏 Thank You! diff --git a/rhodium-standard-repositories/templates/FEEDBACK.md.template b/rhodium-standard-repositories/templates/FEEDBACK.md.template index 7325b2af6..789a0a96b 100644 --- a/rhodium-standard-repositories/templates/FEEDBACK.md.template +++ b/rhodium-standard-repositories/templates/FEEDBACK.md.template @@ -70,7 +70,7 @@ See link:ETHICS.md[ETHICS.md] for details. === Private Channels - **Email**: {feedback-email} -- **Security vulnerabilities**: link:SECURITY.md[Security policy] +- **Security vulnerabilities**: link:3-practice/SECURITY.md[Security policy] - **Ethical concerns**: {ethics-email} === Surveys & Polls diff --git a/rhodium-standard-repositories/templates/GOVERNANCE.adoc.template b/rhodium-standard-repositories/templates/GOVERNANCE.adoc.template index c5dd44076..083b118fd 100644 --- a/rhodium-standard-repositories/templates/GOVERNANCE.adoc.template +++ b/rhodium-standard-repositories/templates/GOVERNANCE.adoc.template @@ -67,7 +67,7 @@ **Eligibility**: Anyone! Open to all. -**Start**: link:CONTRIBUTING.adoc[Contributing guide] +**Start**: link:3-practice/CONTRIBUTING.adoc[Contributing guide] === Stewards (Ethics Oversight) @@ -147,7 +147,7 @@ Stewards review for ethical implications. === Code of Conduct Violations -See link:CODE_OF_CONDUCT.adoc[Code of Conduct] for separate process. +See link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct] for separate process. == 🎓 Maintainer Succession @@ -260,9 +260,9 @@ This governance model is **not set in stone**. == 📚 References -- **TPCF**: link:CONTRIBUTING.adoc[Tri-Perimeter Contribution Framework] +- **TPCF**: link:3-practice/CONTRIBUTING.adoc[Tri-Perimeter Contribution Framework] - **Ethics**: link:ETHICS.md[Ethical Guidelines] -- **CoC**: link:CODE_OF_CONDUCT.adoc[Code of Conduct] +- **CoC**: link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct] - **MAA Framework**: link:CLAUDE.md[Mutually Assured Accountability] --- diff --git a/rhodium-standard-repositories/templates/LEARNING.md.template b/rhodium-standard-repositories/templates/LEARNING.md.template index ab88bfad7..5432ec84b 100644 --- a/rhodium-standard-repositories/templates/LEARNING.md.template +++ b/rhodium-standard-repositories/templates/LEARNING.md.template @@ -67,7 +67,7 @@ This document provides **learning pathways** for students, educators, and self-l - Navigate codebase - Submit your first contribution -**Tutorial**: link:CONTRIBUTING.adoc[Contributing guide] +**Tutorial**: link:3-practice/CONTRIBUTING.adoc[Contributing guide] == 📖 Learning Pathways diff --git a/rhodium-standard-repositories/templates/README.adoc.template b/rhodium-standard-repositories/templates/README.adoc.template index 40e61c24e..3beabaec0 100644 --- a/rhodium-standard-repositories/templates/README.adoc.template +++ b/rhodium-standard-repositories/templates/README.adoc.template @@ -284,7 +284,7 @@ We optimise for clarity and auditability: === 🤝 Code of Conduct -All contributors must follow our link:CODE_OF_CONDUCT.adoc[Code of Conduct]. Respect boundaries, attribution, and ethical standards. +All contributors must follow our link:3-practice/CODE_OF_CONDUCT.adoc[Code of Conduct]. Respect boundaries, attribution, and ethical standards. == 📝 Licence diff --git a/rhodium-standard-repositories/templates/SECURITY.md.template b/rhodium-standard-repositories/templates/SECURITY.md.template index fa3799d51..b877d83cd 100644 --- a/rhodium-standard-repositories/templates/SECURITY.md.template +++ b/rhodium-standard-repositories/templates/SECURITY.md.template @@ -170,7 +170,7 @@ We recognize security researchers who responsibly disclose vulnerabilities: Currently: ❌ No formal bug bounty program - We appreciate responsible disclosure -- Recognition in SECURITY.md and release notes +- Recognition in 3-practice/SECURITY.md and release notes - Attribution in CONTRIBUTORS.md ## 📞 Security Contacts diff --git a/rhodium-standard-repositories/templates/justfile.template b/rhodium-standard-repositories/templates/justfile.template index 8e69fab1f..016051625 100644 --- a/rhodium-standard-repositories/templates/justfile.template +++ b/rhodium-standard-repositories/templates/justfile.template @@ -617,6 +617,6 @@ help: @echo "" @echo "Documentation: README.adoc" @echo "Quick start: QUICKSTART-USER.adoc" - @echo "Contributing: CONTRIBUTING.adoc" + @echo "Contributing: 3-practice/CONTRIBUTING.adoc" # vim: set ft=just : diff --git a/scripts/build-registry.sh b/scripts/build-registry.sh index fd6799988..9f4e51553 100755 --- a/scripts/build-registry.sh +++ b/scripts/build-registry.sh @@ -79,12 +79,12 @@ foundations-readiness-grades|readiness|foundations-readiness-grades/|FRG — Fou component-readiness-grades|readiness|component-readiness-grades/|CRG — Component Readiness Grades|the X..A grading system for components toolchain-readiness-grades|readiness|toolchain-readiness-grades/|TRG — Toolchain Readiness Grades|per-toolchain readiness profile templates rhodium-standard-repositories|governance|rhodium-standard-repositories/|RSR — Rhodium Standard Repositories|the repository-compliance standard every repo is graded against -session-management-standards|governance|session-management-standards/|Session Management Standards|continuity / verify / handover protocols +session-management-standards|governance|3-practice/session-management-standards/|Session Management Standards|continuity / verify / handover protocols did-you-actually-do-that|governance|1-formats/sub-specs/did-you-actually-do-that/|DYADT — Did-You-Actually-Do-That|post-action agent-claim verification (Tier 4 accountability) ensaid-config|governance|1-formats/sub-specs/ensaid-config/|ENSAID Config|the ensaid configuration standard -accessibility|governance|accessibility/|Accessibility Standard|estate accessibility requirements -publication-pre-flight|governance|publication-pre-flight/|Publication Pre-Flight|submission gate (HOL + Zenodo checklists) -release-pre-flight|governance|release-pre-flight/|Release Pre-Flight (V1 Gate)|hard v1.0.0 audit requirements +accessibility|governance|3-practice/accessibility/|Accessibility Standard|estate accessibility requirements +publication-pre-flight|governance|3-practice/publication-pre-flight/|Publication Pre-Flight|submission gate (HOL + Zenodo checklists) +release-pre-flight|governance|3-practice/release-pre-flight/|Release Pre-Flight (V1 Gate)|hard v1.0.0 audit requirements hypatia-rules|integration|hypatia-rules/|Standards Hypatia Rules|the dogfooding rules that scan THIS repo (incl. drift detection) a2ml-templates|integration|1-formats/templates/|A2ML Templates|copy-in templates for the 7 A2ML files TSV diff --git a/scripts/build-scorecards.sh b/scripts/build-scorecards.sh index 578681eee..996f972d7 100644 --- a/scripts/build-scorecards.sh +++ b/scripts/build-scorecards.sh @@ -147,7 +147,7 @@ extract_checks() { # Why this exists: a check whose tool is absent is indistinguishable from a # check that ran and failed, so the verifier accused the repo of claiming a # fake pass. `xmllint` missing surfaced as exit 127; ripgrep missing made -# release-pre-flight/v1-audit.sh exit 2, so its greps matched nothing and +# 3-practice/release-pre-flight/v1-audit.sh exit 2, so its greps matched nothing and # returned 1. All seven were reported as "the pass is not real" — and all # seven passes were in fact real. # diff --git a/scripts/check-docs-presence.sh b/scripts/check-docs-presence.sh index deba5f775..031139e65 100755 --- a/scripts/check-docs-presence.sh +++ b/scripts/check-docs-presence.sh @@ -24,7 +24,7 @@ # default; GitHub-required community-health files stay Markdown): # README.adoc | README.md # LICENSE | LICENSE.txt | LICENSE.md -# CONTRIBUTING.md | CONTRIBUTING.adoc +# CONTRIBUTING.md | 3-practice/CONTRIBUTING.adoc # # Usage: check-docs-presence.sh [repo-root] # @@ -83,7 +83,7 @@ grace_missing="" have README.adoc README.md || blocking_missing="$blocking_missing README" have LICENSE LICENSE.txt LICENSE.md || blocking_missing="$blocking_missing LICENSE" -if ! have CONTRIBUTING.md CONTRIBUTING.adoc; then +if ! have CONTRIBUTING.md 3-practice/CONTRIBUTING.adoc; then # String comparison is sound here: YYYY-MM-DD sorts chronologically, and both # operands are format-validated above. if [[ "$TODAY" < "$ENFORCE_CONTRIBUTING_FROM" ]]; then @@ -104,7 +104,7 @@ if [ -n "$blocking_missing" ]; then echo "Required at the repository root (either extension where two are listed):" echo " README.adoc (or README.md)" echo " LICENSE (or LICENSE.txt / LICENSE.md)" - echo " CONTRIBUTING.md (or CONTRIBUTING.adoc)" + echo " CONTRIBUTING.md (or 3-practice/CONTRIBUTING.adoc)" echo echo "Estate policy: docs are AsciiDoc by default; see hyperpolymath/standards." exit 1 diff --git a/scripts/check-gate-tiers.sh b/scripts/check-gate-tiers.sh index ca0cc8f00..3adf8f0f3 100755 --- a/scripts/check-gate-tiers.sh +++ b/scripts/check-gate-tiers.sh @@ -65,7 +65,7 @@ STRICT=0 [ "${1:-}" = "--strict" ] && { STRICT=1; shift; } [ $# -eq 0 ] && { echo "usage: $0 [--strict] OWNER/REPO..." >&2; exit 2; } -# Job extraction is awk, not python3: LANGUAGE-POLICY.adoc bans Python with no +# Job extraction is awk, not python3: 3-practice/LANGUAGE-POLICY.adoc bans Python with no # exceptions, and a lint that enforces estate policy must not itself breach it. # Scope is deliberately narrow — `jobs:` at column 0, job ids at indent 2, and a # job-level `name:` at indent EXACTLY 4 (a step name lives at 6 or deeper). diff --git a/scripts/check-package-policy.sh b/scripts/check-package-policy.sh index 78ca70486..4e50f4759 100755 --- a/scripts/check-package-policy.sh +++ b/scripts/check-package-policy.sh @@ -10,7 +10,7 @@ # not detect a violation, and it claimed a pass over any input. # # POLICY — canonical source is `0-canon/rsr/ -# LANGUAGE-POLICY.adoc` §Package Management, NOT CLAUDE.md: +# 3-practice/LANGUAGE-POLICY.adoc` §Package Management, NOT CLAUDE.md: # # RULED 2026-05-18 (estate-wide): Guix primary + sealed-container escape; # NO Nix mirror. One packager per repo. A `flake.nix` that only mirrors a @@ -26,7 +26,7 @@ # This script previously cited CLAUDE.md and printed # `✅ Nix package management detected (fallback)`. CLAUDE.md's packaging # section is STALE — it still describes Nix as a fallback, in 472 copies -# estate-wide — and CLAUDE.md itself defers to LANGUAGE-POLICY.adoc as +# estate-wide — and CLAUDE.md itself defers to 3-practice/LANGUAGE-POLICY.adoc as # canonical, so the .adoc wins. Blessing a flake as compliant is what let the # 2026-07-21 remediation sweep ship `flake.nix` to 59 repos that should have # received Guix or a container. @@ -178,7 +178,7 @@ if [ -n "$NIX" ]; then echo "::error::Nix-only packaging is not compliant: ${NIX#"$ROOT"/}" echo - echo "Estate policy (LANGUAGE-POLICY.adoc, RULED 2026-05-18) is Guix primary" + echo "Estate policy (3-practice/LANGUAGE-POLICY.adoc, RULED 2026-05-18) is Guix primary" echo "+ sealed-container escape; NO Nix mirror. Replace the flake with:" echo " guix.scm | manifest.scm | channels.scm | .guix-channel (primary)" echo " Containerfile (escape hatch)" @@ -206,7 +206,7 @@ fi echo "::error::Package policy violation: no packaging found." echo -echo "Estate policy (LANGUAGE-POLICY.adoc, RULED 2026-05-18) is Guix primary" +echo "Estate policy (3-practice/LANGUAGE-POLICY.adoc, RULED 2026-05-18) is Guix primary" echo "+ sealed-container escape; NO Nix mirror. Add one of:" echo " guix.scm | manifest.scm | channels.scm | .guix-channel (primary)" echo " Containerfile (escape hatch)" diff --git a/scripts/tests/governance-gates-505-test.sh b/scripts/tests/governance-gates-505-test.sh index 277d9244b..b0c2d0688 100755 --- a/scripts/tests/governance-gates-505-test.sh +++ b/scripts/tests/governance-gates-505-test.sh @@ -65,7 +65,7 @@ assert "all docs present (pre-cutoff) passes" 0 "✅ Core documentation present" assert "all docs present (post-cutoff) passes" 0 "✅ Core documentation present" \ env DOCS_TODAY="$AFTER" "$DOCS" "$r" -r=$(mkrepo docs-md README.md LICENSE.txt CONTRIBUTING.adoc) +r=$(mkrepo docs-md README.md LICENSE.txt 3-practice/CONTRIBUTING.adoc) assert "alternate extensions accepted" 0 "✅ Core documentation present" \ env DOCS_TODAY="$AFTER" "$DOCS" "$r" diff --git a/standards-map.toml b/standards-map.toml index a2958fd73..89a667393 100644 --- a/standards-map.toml +++ b/standards-map.toml @@ -32,7 +32,7 @@ [map] repo = "hyperpolymath/standards" version = "1.0.0" -entry_count = 121 +entry_count = 122 generated = false # hand-curated; the district index.adoc files ARE generated checked_by = "scripts/check-standards-map.sh" @@ -553,7 +553,20 @@ gate = "canon-self-conformance" note = "consolidate, do NOT split: same owners, same cadence as the law" [[entry]] -from = "session-management-standards" +from = "3-practice" +target = "3-practice/ (district root; created by the district move)" +district = "3-practice" +kind = "district" +files = 101 +lifecycle = "versioned" +canonical = false +canon_slot = "" +canonical_doc = "" +gate = "" +note = "District root. This path did not exist before the district move, so it is a new top-level entry and GATE D assertion 2 requires a record for it. canonical = false: the district holds specs, it is not itself a standard." + +[[entry]] +from = "3-practice/session-management-standards/" target = "3-practice/session-management-standards/" district = "3-practice" kind = "policy" @@ -566,7 +579,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "outreach" +from = "3-practice/outreach/" target = "3-practice/outreach/" district = "3-practice" kind = "policy" @@ -579,7 +592,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "ai-instruction" +from = "3-practice/ai-instruction/" target = "3-practice/ai-instruction/" district = "3-practice" kind = "policy" @@ -592,7 +605,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "publication-pre-flight" +from = "3-practice/publication-pre-flight/" target = "3-practice/publication-pre-flight/" district = "3-practice" kind = "policy" @@ -605,7 +618,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "release-pre-flight" +from = "3-practice/release-pre-flight/" target = "3-practice/release-pre-flight/" district = "3-practice" kind = "policy" @@ -618,7 +631,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "CODEOWNERS-POLICY.adoc" +from = "3-practice/CODEOWNERS-POLICY.adoc" target = "3-practice/CODEOWNERS-POLICY.adoc" district = "3-practice" kind = "policy" @@ -631,7 +644,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "CODE_OF_CONDUCT.adoc" +from = "3-practice/CODE_OF_CONDUCT.adoc" target = "3-practice/CODE_OF_CONDUCT.adoc" district = "3-practice" kind = "policy" @@ -644,7 +657,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "CONTRIBUTING.adoc" +from = "3-practice/CONTRIBUTING.adoc" target = "3-practice/CONTRIBUTING.adoc" district = "3-practice" kind = "policy" @@ -657,7 +670,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "LANGUAGE-POLICY.adoc" +from = "3-practice/LANGUAGE-POLICY.adoc" target = "3-practice/LANGUAGE-POLICY.adoc" district = "3-practice" kind = "policy" @@ -670,7 +683,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "LICENCE-POLICY.adoc" +from = "3-practice/LICENCE-POLICY.adoc" target = "3-practice/LICENCE-POLICY.adoc" district = "3-practice" kind = "policy" @@ -683,7 +696,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "MAINTAINERS.adoc" +from = "3-practice/MAINTAINERS.adoc" target = "3-practice/MAINTAINERS.adoc" district = "3-practice" kind = "policy" @@ -696,7 +709,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "PROOF-NEEDS.adoc" +from = "3-practice/PROOF-NEEDS.adoc" target = "3-practice/PROOF-NEEDS.adoc" district = "3-practice" kind = "policy" @@ -709,7 +722,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "REMOTE-URL-POLICY.adoc" +from = "3-practice/REMOTE-URL-POLICY.adoc" target = "3-practice/REMOTE-URL-POLICY.adoc" district = "3-practice" kind = "policy" @@ -722,7 +735,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "SECURITY-ADVISORIES.adoc" +from = "3-practice/SECURITY-ADVISORIES.adoc" target = "3-practice/SECURITY-ADVISORIES.adoc" district = "3-practice" kind = "policy" @@ -735,7 +748,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "SECURITY.adoc" +from = "3-practice/SECURITY.adoc" target = "3-practice/SECURITY.adoc" district = "3-practice" kind = "policy" @@ -748,7 +761,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "SECURITY.md" +from = "3-practice/SECURITY.md" target = "3-practice/SECURITY.md" district = "3-practice" kind = "policy" @@ -761,7 +774,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "TEST-NEEDS.adoc" +from = "3-practice/TEST-NEEDS.adoc" target = "3-practice/TEST-NEEDS.adoc" district = "3-practice" kind = "policy" @@ -774,7 +787,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "TOOLING-VERSION-INTEGRITY-POLICY.adoc" +from = "3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc" target = "3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc" district = "3-practice" kind = "policy" @@ -787,7 +800,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "TRUST-DEFAULTS-POLICY.adoc" +from = "3-practice/TRUST-DEFAULTS-POLICY.adoc" target = "3-practice/TRUST-DEFAULTS-POLICY.adoc" district = "3-practice" kind = "policy" @@ -800,7 +813,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "ZIGZAG-TESTING.adoc" +from = "3-practice/ZIGZAG-TESTING.adoc" target = "3-practice/ZIGZAG-TESTING.adoc" district = "3-practice" kind = "policy" @@ -813,7 +826,7 @@ gate = "canon-self-conformance" note = "SPDX/licence policy is owner-only, flag-never-edit" [[entry]] -from = "accessibility" +from = "3-practice/accessibility/" target = "3-practice/accessibility/" district = "3-practice" kind = "policy" @@ -826,7 +839,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "immaculate-guide" +from = "3-practice/immaculate-guide/" target = "3-practice/immaculate-guide/" district = "3-practice" kind = "policy" @@ -839,7 +852,7 @@ gate = "canon-self-conformance" note = "outreach/ is a split-out candidate (non-normative)" [[entry]] -from = "testing-and-benchmarking" +from = "3-practice/testing-and-benchmarking/" target = "3-practice/testing-and-benchmarking/" district = "3-practice" kind = "policy" diff --git a/standards-update/README.adoc b/standards-update/README.adoc index 5a9b5c755..43785f9dc 100644 --- a/standards-update/README.adoc +++ b/standards-update/README.adoc @@ -220,7 +220,7 @@ All documentation must be AsciiDoc (`.adoc`) except for GitHub-required files: **Must be .md (GitHub community health):** -* `SECURITY.md` +* `3-practice/SECURITY.md` * `CONTRIBUTING.md` (can redirect to `.adoc`) * `CODE_OF_CONDUCT.md` * `CHANGELOG.md` @@ -269,7 +269,7 @@ standards/ ├── 1-formats/A2ML-REPO-TEMPLATE.adoc # Canonical structure for -a2ml repos ├── CODE_OF_CONDUCT.md # Template ├── CONTRIBUTING.md # Template -├── SECURITY.md # Template +├── 3-practice/SECURITY.md # Template ├── LICENSE.txt # PMPL-1.0-or-later + Palimpsest ├── ROADMAP.adoc └── README.adoc # This file diff --git a/tasks/tooling-integrity-lint.sh b/tasks/tooling-integrity-lint.sh index ab59bdc80..ee388c544 100644 --- a/tasks/tooling-integrity-lint.sh +++ b/tasks/tooling-integrity-lint.sh @@ -79,7 +79,7 @@ done < <(find "$WF_DIR" -maxdepth 1 -type f \( -name '*.yml' -o -name '*.yaml' \ echo "tooling-integrity-lint: R1(blocking)=$r1 R4(soft-gate)=$r4 strict=$STRICT" if [ "$r1" -gt 0 ]; then - echo "tooling-integrity-lint: FAIL — $r1 unversioned family-tool install(s). See TOOLING-VERSION-INTEGRITY-POLICY.adoc Rule 1" + echo "tooling-integrity-lint: FAIL — $r1 unversioned family-tool install(s). See 3-practice/TOOLING-VERSION-INTEGRITY-POLICY.adoc Rule 1" exit 1 fi if [ "$STRICT" -eq 1 ] && [ "$r4" -gt 0 ]; then diff --git a/templates/CODEOWNERS b/templates/CODEOWNERS index d5a80df4f..b5c4a06be 100644 --- a/templates/CODEOWNERS +++ b/templates/CODEOWNERS @@ -6,7 +6,7 @@ * @hyperpolymath # Security-sensitive files require explicit ownership -SECURITY.md @hyperpolymath +3-practice/SECURITY.md @hyperpolymath .github/workflows/ @hyperpolymath .machine_readable/ @hyperpolymath 1-formats/contractiles/ @hyperpolymath diff --git a/templates/MAINTAINERS.adoc b/templates/MAINTAINERS.adoc index 4821bfa87..dd9fa4f58 100644 --- a/templates/MAINTAINERS.adoc +++ b/templates/MAINTAINERS.adoc @@ -62,4 +62,4 @@ For questions about project governance: * link:0-canon/GOVERNANCE.adoc[Governance Model] * link:CODE_OF_CONDUCT.md[Code of Conduct] -* link:CONTRIBUTING.adoc[Contributing Guide] +* link:3-practice/CONTRIBUTING.adoc[Contributing Guide] diff --git a/toolchain-readiness-grades/SELF-ASSESSMENT.adoc b/toolchain-readiness-grades/SELF-ASSESSMENT.adoc index daefcac7b..125ae8db5 100644 --- a/toolchain-readiness-grades/SELF-ASSESSMENT.adoc +++ b/toolchain-readiness-grades/SELF-ASSESSMENT.adoc @@ -92,7 +92,7 @@ After grade D, the path to C requires: . *All Could rows PASSED.* . *Full Testing-Taxonomy 18 × 14 coverage* per - `testing-and-benchmarking/TESTING-TAXONOMY.adoc`. + `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc`. . *Six-Sigma test passing* — all tests in the Six-Sigma range (≤ 3.4 failures per million test runs) for at least 14 consecutive days. @@ -127,7 +127,7 @@ extraordinary by industry standards. | References (canonical examples) | ✅ | 25 audit files copied verbatim from 007 in `references/007/` | SPDX header on every file | ✅ | Verified | invariant-path doc-claims grounder run | ✅ | First run on `standards/` produced 519 grounded / 2597 ungrounded / 1 unknown / 3117 total — drives this self-assessment's gap analysis -| All file-path claims in spec resolve | 🟡 | Templates now exist; cross-repo references (e.g. to `feedback_branch_protection.md` in memory, `immaculate-guide/IMMACULATE-GUIDE.adoc` in standards) should resolve under multi-root grounding once that lands in invariant-path Phase A +| All file-path claims in spec resolve | 🟡 | Templates now exist; cross-repo references (e.g. to `feedback_branch_protection.md` in memory, `3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc` in standards) should resolve under multi-root grounding once that lands in invariant-path Phase A | External review by formal-methods community | ❌ | Not yet — Phase A of invariant-path must complete first; then a coordinated submission to LangSec / NCSC research / NIST / formal-methods Zulip | Adoption by at least one toolchain component | ❌ | 007 lexer is the obvious first candidate; not yet started |=== diff --git a/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc b/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc index 6d4ed4a78..69a1c9fa3 100644 --- a/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc +++ b/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc @@ -73,8 +73,8 @@ or relax any TRG-baseline requirement. TRG is grade-compatible with CRG; any difference is TRG being _stricter_, never weaker. * *RSR* — Rhodium Standard Repositories baseline. -* *Immaculate Guide* — `immaculate-guide/IMMACULATE-GUIDE.adoc`. -* *Testing Taxonomy* — `testing-and-benchmarking/TESTING-TAXONOMY.adoc` +* *Immaculate Guide* — `3-practice/immaculate-guide/IMMACULATE-GUIDE.adoc`. +* *Testing Taxonomy* — `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc` (18 categories × 14 aspects × 4 proof systems × 12 type levels). * *Standing priority order* (all hyperpolymath work, ranked): `dependability > security > interop > usability > performance > versatility > functional-extension`. @@ -266,7 +266,7 @@ Tests:: Every Could row has a behavioural test; component is dogfooded by the project's own CI on every push. CI green for at least 7 consecutive days at assessment time. *Full Testing-Taxonomy coverage* — 18 categories × 14 aspects × 4 proof systems × 12 type levels (per - `testing-and-benchmarking/TESTING-TAXONOMY.adoc`) wired up and + `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc`) wired up and passing for the component. Six-Sigma test passing:: All passing tests above MUST be in the *Six Sigma range* (≤ 3.4 failures per million test runs) for at least @@ -604,7 +604,7 @@ its *target semantics*. Specifically: === 6.3 "Five nines on the priority axes" Each axis of the standing priority order is measured per the methodology -in `testing-and-benchmarking/TESTING-TAXONOMY.adoc`. "Five nines" means the +in `3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc`. "Five nines" means the measured rate of correct, secure, interoperable, usable behaviour (etc.) is ≥ 99.999% over the assessment window. diff --git a/toolchain-readiness-grades/testing/LANGUAGE-TESTING-STANDARDS.adoc b/toolchain-readiness-grades/testing/LANGUAGE-TESTING-STANDARDS.adoc index 67f89bd46..5d96cc8ee 100644 --- a/toolchain-readiness-grades/testing/LANGUAGE-TESTING-STANDARDS.adoc +++ b/toolchain-readiness-grades/testing/LANGUAGE-TESTING-STANDARDS.adoc @@ -11,7 +11,7 @@ It sits above the per-language guides: this document says _what every language’s testing story MUST provide_; each per-language guide (built from `+toolchain-readiness-grades/testing/language-testing-guide-TEMPLATE.adoc+`) says _which concrete tools provide it_. The requirement categories align with the -CRG test taxonomy in `+testing-and-benchmarking/TESTING-TAXONOMY.adoc+`, +CRG test taxonomy in `+3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc+`, so a language’s testing maturity maps onto its Component/Toolchain Readiness Grade. @@ -317,7 +317,7 @@ releases. === Resources -* `+testing-and-benchmarking/TESTING-TAXONOMY.adoc+` — the CRG test +* `+3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc+` — the CRG test taxonomy. * `+docs/CICD-SIGNAL-DISCIPLINE.adoc+` — the same anti-theatre principle applied to CI gates: four tiers, machine-checkable invariants, and drift