chore(metadata): add public-surface desired state wave 2 - #1639
chore(metadata): add public-surface desired state wave 2#1639seonghobae wants to merge 11 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reconciliation pass found a concrete contract drift on this Draft head: |
|
Fresh public-surface traversal found a control-plane gap that belongs in this desired-state lane (or a non-conflicting direct successor), not in a leaf one-off settings edit: the current Please extend the reviewed desired state with an optional homepage field and fail-closed validation, apply it in the same single repository PATCH as description when either drifts, and verify live homepage equality after apply. Preserve |
|
Additional public-surface evidence for the next metadata reconciliation pass: |
|
Public-surface traversal found three additional source-complete candidates for this declarative metadata lane once their repository-owned source prerequisites are integrated: |
|
Future public-surface candidate discovered during org traversal: Desired settings after a source prerequisite lands: concise product responsibility such as |
|
Additional source-complete metadata candidate discovered during this traversal: When this metadata writer next moves after the current five-prerequisite wave, add |
|
Fresh public-surface traversal identified three repositories for a later declarative metadata wave once their source prerequisites are on the protected default branch. Please do not add them to this Draft head until those prerequisites integrate, but keep them on the desired-state queue rather than solving settings ad hoc:
Live Pages/settings are still not claimed from these source PRs; completion remains protected integration + reconcile apply + REST/HTTPS verification. |
|
Two additional desired-state candidates should enter a later manifest wave only after their protected source prerequisites integrate:
Neither source PR is live Pages evidence; settings completion remains reconcile apply plus REST/HTTPS verification. |
|
Fresh metadata findings for later declarative reconciliation after protected source integration:
Do not treat either source branch as live settings completion; reconcile only after protected truth and verify the resulting REST/public surface. |
|
Fresh live-description audit found one remaining unrecorded ownership-caveat repository: After that protected prerequisite integrates, reconcile |
|
Maintained-fork public-surface wave (declarative settings after each protected DeepWiki prerequisite integrates):
For all three, provenance/fork status remains visible through GitHub's native fork relationship and architecture/docs where needed; customer-facing description/topic normalization should focus on product responsibility. Source PR presence alone is not live settings completion. |
|
Fresh public-surface traversal found three additional candidates for this existing desired-state lane; please absorb them here rather than opening a competing settings writer once their protected-branch prerequisites land:
All three are source-precondition coordination only: no live description/topic/Pages convergence is claimed until protected-default content is present and the existing reconciler can apply/re-read settings and published HTTPS content. The current PR is still Draft/conflicted, so this is intentionally coordination on the single existing owner lane rather than a duplicate metadata PR. |
|
Follow-up to the earlier public-surface coordination: |
|
Fresh source-ready candidate for this existing desired-state writer: |
|
Additional public-surface candidate for this existing desired-state writer: |
|
Current-base refresh evidence (2026-09-02): protected |
|
Traversal reconciliation note (2026-09-02): |
|
Fresh public-surface traversal added the missing source prerequisites to the existing single writer Do not add/apply this repository to the settings manifest yet: protected |
|
Fresh protected-base repair: this Draft desired-state writer is now |
Outcome
Extend the organization-owned declarative repository metadata catalog for public repositories whose repository-facing source work is already active, rather than leaving descriptions, topics, DeepWiki intent, and Pages intent as one-off observations.
The source manifest now covers a broader wave than the original five-repository seed;
config/repository-metadata.jsonis the authority for the exact repository set and preserves exact repository-name casing. The companion tests keep description constraints, topic normalization, DeepWiki URL formation, Pages intent, and source prerequisites fail closed.Coordination / prerequisites
This PR intentionally does not duplicate repository-owned README or Pages-source writers. Keep this PR Draft until each applicable exact-cased Ask DeepWiki badge and Pages source prerequisite is present on the protected default branch. A desired-state declaration must not cause Pages to target source that has not integrated.
j-plannerremains deliberately excluded from central legacy-docsPages mutation because its working live site is rooted on thegh-pagesbranch; reconfiguring a verified working site without first extending the reconciler's source-path model would be destructive.Control-plane boundary
Protected
.github/maincontains the least-privilegeCWL_REPOSITORY_METADATA_TOKENwiring from #1625. Live description/topic/Pages mutations remain blocked by external protected-environment/GitHub App provisioning tracked in #1579. This PR does not claim live convergence; after source prerequisites and credential provisioning, the existing reconcile workflow must apply and re-read exact repository settings plus published HTTPS Pages content before completion.Current protected-base reconciliation — 2026-09-02
The branch is already reconciled non-destructively with protected
main@6ba61e7fabb8f3794970746cb0f1ddfa136aad5fthrough merge commit73ddb9ad02ca35686d938de29415f3ce0fcf8770. That commit has protected main as its second parent and preserves the branch's two intended files only. A fresh GitHub compare reportsahead_by=9,behind_by=0; changed files remain exactlyconfig/repository-metadata.jsonandtests/test_repository_metadata_reconciliation.py. No force-push or destructive rebase was used.Exact-head status
Fresh exact-head Repository Metadata Reconcile
33615232567, CodeQL33615232487, Security Scan33615232587, SAST Semgrep33615232477, OSV33615233106, Secret Scan33615232512, SBOM33615232596, Python Security33615232524, and Scorecard33615232514are all queued and therefore non-passing. Keep this PR Draft while repository source prerequisites, the external settings credential path, or exact-head governance remain incomplete; predecessor evidence does not transfer.No branch protection, required check, review, credential, secret, release, or target-repository source file is changed here. A manifest/workflow commit is not live metadata or Pages publication evidence.