Skip to content

chore(metadata): add public-surface desired state wave 2 - #1639

Draft
seonghobae wants to merge 11 commits into
mainfrom
chore/metadata-public-surface-wave-2-v2
Draft

chore(metadata): add public-surface desired state wave 2#1639
seonghobae wants to merge 11 commits into
mainfrom
chore/metadata-public-surface-wave-2-v2

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Outcome

Extend the organization-owned declarative repository metadata catalog for public repositories whose repository-facing source work is already active, rather than leaving descriptions, topics, DeepWiki intent, and Pages intent as one-off observations.

The source manifest now covers a broader wave than the original five-repository seed; config/repository-metadata.json is the authority for the exact repository set and preserves exact repository-name casing. The companion tests keep description constraints, topic normalization, DeepWiki URL formation, Pages intent, and source prerequisites fail closed.

Coordination / prerequisites

This PR intentionally does not duplicate repository-owned README or Pages-source writers. Keep this PR Draft until each applicable exact-cased Ask DeepWiki badge and Pages source prerequisite is present on the protected default branch. A desired-state declaration must not cause Pages to target source that has not integrated.

j-planner remains deliberately excluded from central legacy-docs Pages mutation because its working live site is rooted on the gh-pages branch; reconfiguring a verified working site without first extending the reconciler's source-path model would be destructive.

Control-plane boundary

Protected .github/main contains the least-privilege CWL_REPOSITORY_METADATA_TOKEN wiring from #1625. Live description/topic/Pages mutations remain blocked by external protected-environment/GitHub App provisioning tracked in #1579. This PR does not claim live convergence; after source prerequisites and credential provisioning, the existing reconcile workflow must apply and re-read exact repository settings plus published HTTPS Pages content before completion.

Current protected-base reconciliation — 2026-09-02

The branch is already reconciled non-destructively with protected main@6ba61e7fabb8f3794970746cb0f1ddfa136aad5f through merge commit 73ddb9ad02ca35686d938de29415f3ce0fcf8770. That commit has protected main as its second parent and preserves the branch's two intended files only. A fresh GitHub compare reports ahead_by=9, behind_by=0; changed files remain exactly config/repository-metadata.json and tests/test_repository_metadata_reconciliation.py. No force-push or destructive rebase was used.

Exact-head status

Fresh exact-head Repository Metadata Reconcile 33615232567, CodeQL 33615232487, Security Scan 33615232587, SAST Semgrep 33615232477, OSV 33615233106, Secret Scan 33615232512, SBOM 33615232596, Python Security 33615232524, and Scorecard 33615232514 are all queued and therefore non-passing. Keep this PR Draft while repository source prerequisites, the external settings credential path, or exact-head governance remain incomplete; predecessor evidence does not transfer.

No branch protection, required check, review, credential, secret, release, or target-repository source file is changed here. A manifest/workflow commit is not live metadata or Pages publication evidence.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Reconciliation pass found a concrete contract drift on this Draft head: config/repository-metadata.json adds the five wave-2 repositories, but inherited tests/test_repository_metadata_reconciliation.py::test_metadata_manifest_declares_exact_casing_and_public_surfaces still asserts the pre-wave exact repository set. That test will reject this manifest once the pytest lane executes. Please update the exact expected set/topics in the same writer before moving this PR out of Draft; do not weaken/remove the exact-set assertion. Current Actions for this head are still queued, so I am leaving the PR Draft and continuing independent repository work rather than treating queue state as completion.

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite labels Sep 1, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal found a control-plane gap that belongs in this desired-state lane (or a non-conflicting direct successor), not in a leaf one-off settings edit: the current repository-metadata.json schema and scripts/ci/reconcile_repository_metadata.py reconcile description/topics/DeepWiki/Pages but do not declare, apply, or verify repository homepage URLs. ContextualWisdomLab/newsdom-api is a concrete canary: live REST currently reports Pages enabled but homepage=https://contextwisdomlab.github.io/newsdom-api/ (missing ual), while public-surface PR #782 corrects the source-owned MkDocs namespace and explicitly leaves repository homepage convergence to the owner metadata path.

Please extend the reviewed desired state with an optional homepage field and fail-closed validation, apply it in the same single repository PATCH as description when either drifts, and verify live homepage equality after apply. Preserve null/unset as an explicit desired state rather than silently inventing a Pages URL, and add regression coverage for malformed/non-HTTPS/internal-only homepage values plus a no-op steady state. Do not make this a branch-selected/manual privileged path or bypass the dedicated CWL_REPOSITORY_METADATA_TOKEN contract. The current live connector does not expose this settings mutation directly, so owner-side API reconciliation is the correct capability boundary.

Copy link
Copy Markdown
Contributor Author

Additional public-surface evidence for the next metadata reconciliation pass: ContextualWisdomLab/g7 is a maintained fork of gnuboard/g7; live description is currently only 그누보드7, live topics are empty, homepage is https://sir.kr, and has_pages=false. A leaf badge writer is now open as g7#2; its effective diff is exactly one exact-cased DeepWiki badge line and must reach protected main before declaring deepwiki: true because the reconciler fails closed on missing default-branch badges. Once that prerequisite lands, recommended bounded settings desired state is a concise CMS/e-commerce description and evidence-backed topics such as cms, ecommerce, gnuboard, laravel, php, reactjs, typescript, and tailwindcss; no Pages publication intent is recommended for this upstream-derived fork absent a distinct ContextualWisdomLab-owned docs surface. I am not modifying this Draft writer's manifest while it is stale/non-mergeable.

Copy link
Copy Markdown
Contributor Author

Public-surface traversal found three additional source-complete candidates for this declarative metadata lane once their repository-owned source prerequisites are integrated: ELUNVERA (existing #2 carries the exact-cased DeepWiki badge and docs/index.md, but explicitly reports live Pages still disabled), EmbedRelay (existing #4 carries the buyer/integrator baseline and docs/index.md; publication remains unclaimed), and Orgmetra (existing #51 is the canonical protected-product-truth writer and is currently blocked on central Dependency Review/OpenCode/Strix evidence). Please extend this existing metadata writer rather than create a competing one when each prerequisite is present on the protected default branch. Keep this PR Draft/fail-closed until the reconciler can verify each badge/source on protected truth; do not use source-branch presence as live Pages evidence. Current manifest already contains ConceptWeave, PolicyWeave, and supply-chain-control-plane, so those should remain owned here rather than receiving another desired-state PR.

Copy link
Copy Markdown
Contributor Author

Future public-surface candidate discovered during org traversal: ContextualWisdomLab/OmniRoute currently exposes customer-facing description Personal fork of diegosouzapw/OmniRoute, ..., which violates the public-description rule by surfacing an ownership caveat. It is a public MIT fork, default release/v3.8.50, homepage https://omniroute.online, has_pages=false, topics ai-coding, api, fork, gateway, llm-orchestration, typescript, and currently has no open PR.

Desired settings after a source prerequisite lands: concise product responsibility such as AI gateway for routing coding agents across LLM providers with automatic fallback., preserve the useful existing topics (the fork provenance topic is fine as classification), preserve the upstream product homepage, and keep Pages disabled unless this fork develops a distinct organization-owned docs surface. The root README is a very large upstream-authored document and currently has no CWL DeepWiki badge; do not overwrite it wholesale from the central metadata lane. Coordinate a minimal exact-cased badge writer first, then add OmniRoute declaratively here or in the next successor metadata wave. No competing settings PR was created.

Copy link
Copy Markdown
Contributor Author

Additional source-complete metadata candidate discovered during this traversal: ContextualWisdomLab/noema already has the exact-cased DeepWiki badge and a product-first README on protected main, plus a protected docs/index.md that documents product responsibility, onboarding, API, deployment, runbook, threat model, traceability, releases, and gap status. The live repository description is still the narrower implementation-centric Noema review bot: OIDC-scoped GitHub App token broker for ContextualWisdomLab LLM pull request reviews., while current topics are bot, code-review, github-app, llm, oidc, python, typescript, homepage is null, and has_pages=false.

When this metadata writer next moves after the current five-prerequisite wave, add noema declaratively rather than opening a competing settings PR. A current customer-facing description consistent with protected product docs is Noema — evidence-producing credential and maintenance control plane for governed GitHub automation. Preserve useful current topics and add only bounded classification such as control-plane, security, and contextualwisdomlab; declare DeepWiki + Pages intent because both protected-source prerequisites are already present. Live completion still requires #1579 credential provisioning, settings apply/re-read, Pages deployment, and HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal identified three repositories for a later declarative metadata wave once their source prerequisites are on the protected default branch. Please do not add them to this Draft head until those prerequisites integrate, but keep them on the desired-state queue rather than solving settings ad hoc:

  • codec-carver: current description is already concise/current (긴 녹음을 메타데이터를 보존한 FLAC/Opus 조각으로 안전하게 변환하는 Python CLI.); preserve useful topics audio, audio-analysis, audio-conversion, cli, flac, metadata, opus, python, rust; add the organization ecosystem topic only if consistent with the manifest taxonomy; deepwiki: true; Pages intent should become true after codec-carver#516 (docs/index.md) and the required README badge are protected truth.
  • seedream_evasepic: current description and domain topics (claude-code-plugin, k-beauty, marketing, prompt-engineering, seedance, seedream) are already useful. It is an organization-maintained fork whose README is the primary public surface; seedream_evasepic#389 adds the exact DeepWiki badge. Treat DeepWiki intent as true but do not create a duplicate Pages site merely because has_pages=false; preserve the upstream-derived product boundary.
  • litellm-patched-proxy: current description is already product-aligned (Downstream LiteLLM proxy image with bounded health-check history queries and maintained production patches) and current topics (docker, litellm, llm, ops, sbom, security) are useful. litellm-patched-proxy#2 supplies the exact README DeepWiki badge plus docs/index.md; after protected integration, declare DeepWiki + Pages intent and converge live settings through the existing credentialed reconciler.

Live Pages/settings are still not claimed from these source PRs; completion remains protected integration + reconcile apply + REST/HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Two additional desired-state candidates should enter a later manifest wave only after their protected source prerequisites integrate:

  • pg-llm-batch: simplify the implementation-heavy live description to PostgreSQL-backed LLM batch engine for token-aware preparation, durable lifecycle state, and OpenAI-compatible batch delivery. Preserve useful existing topics (batch-processing, cli, litellm, llm, postgresql, python, token-usage) and add only the normal bounded ecosystem-role topic if that remains manifest policy. After pg-llm-batch#321 and the required exact DeepWiki source are protected truth, declare DeepWiki + Pages intent and verify live apply.
  • inkspan: current live description is narrower than the protected README's current responsibility. Suggested concise product wording: Inkspan — modular rich-text authoring, collaboration, persistence evidence, safe serialization, and Office rendering for applications and AI systems. Preserve the existing useful topics (collaborative-editing, markdown-editor, office-documents, prosemirror, react, tiptap, typescript, wysiwyg-editor). After inkspan#396 and required exact DeepWiki source are protected truth, declare DeepWiki + Pages intent and verify live apply.

Neither source PR is live Pages evidence; settings completion remains reconcile apply plus REST/HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Fresh metadata findings for later declarative reconciliation after protected source integration:

  • argos: replace the ownership-caveat live description Fork of vibemafiaclub/argos: ... with concise product wording such as Argos — team analytics for Claude Code and Codex usage, skills, sessions, and token consumption. Preserve homepage https://argos-ai.xyz and useful topics analytics, claude-code, codex, token-usage, typescript; remove generic fork from the normalized customer-facing taxonomy and add the normal ContextualWisdomLab ecosystem role if policy permits. argos#555 adds the exact DeepWiki badge and moves maintainer-only harness instructions out of README. Because Argos already has a dedicated hosted product site, Pages intent should remain false unless a distinct docs-site need emerges; do not publish duplicate Pages solely from has_pages=false.
  • hyosung-itx-slogan-brief: current description and bounded topics (brief, hyosung, marketing, slogan) are already appropriate. #8 supplies the exact README DeepWiki badge. This finite research/deliverable repository does not need a duplicate Pages site; preserve Pages intent false while allowing DeepWiki intent after protected integration.

Do not treat either source branch as live settings completion; reconcile only after protected truth and verify the resulting REST/public surface.

Copy link
Copy Markdown
Contributor Author

Fresh live-description audit found one remaining unrecorded ownership-caveat repository: vooster still exposes Fork of jesoos/vooster: 사람과 AI가 함께 제품 행동·유스케이스를 관리하는 vspec 도구 (Fastify API + Prisma + oclif CLI). in the customer-facing repository description. Existing canonical public-surface PR vooster#42 already owns the README/DeepWiki/docs source lane, so do not create a competing writer.

After that protected prerequisite integrates, reconcile vooster declaratively with concise product wording such as Vooster — collaborative product behavior and use-case specification tooling for human and AI teams. Preserve homepage https://v2.vooster.ai and useful topics ai-collaboration, cli, product-management, typescript, vspec; drop generic fork from the normalized customer-facing topic set and add the normal ContextualWisdomLab ecosystem-role topic only if manifest policy remains consistent. Keep Pages intent false while the dedicated product site remains the primary hosted surface unless a distinct CWL docs site is intentionally introduced. Verify live REST after apply; source integration alone is not completion.

Copy link
Copy Markdown
Contributor Author

Maintained-fork public-surface wave (declarative settings after each protected DeepWiki prerequisite integrates):

  • html4tree: current description is already concise/current (html4tree generates index.html files based on a file directory tree. Think Apache mod_autoindex.); preserve topics autoindex, file-tree, index-generator, kotlin, static-site; canonical html4tree#596 owns the exact README DeepWiki badge. Keep Pages false because this maintained utility fork has no distinct hosted docs surface that warrants duplication.
  • nonnest2: current Korean description already states its Vuong-test/non-nested model-comparison role; preserve topics model-comparison, psychometrics, r-package, statistics, vuong-test; canonical nonnest2#115 owns the exact README DeepWiki badge. Keep Pages false unless a distinct CWL documentation surface appears.
  • graphify: current upstream product site/README are the primary hosted surfaces; graphify#1 adds a small organization-owned exact DeepWiki surface without rewriting upstream docs. Preserve the dedicated Graphify product homepage and useful upstream/domain topics. Keep Pages false rather than publishing a duplicate site.

For all three, provenance/fork status remains visible through GitHub's native fork relationship and architecture/docs where needed; customer-facing description/topic normalization should focus on product responsibility. Source PR presence alone is not live settings completion.

@seonghobae seonghobae removed the enhancement New feature or request label Sep 2, 2026
@seonghobae seonghobae added the type: maintenance Maintenance, build, dependency, or operational upkeep label Sep 2, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal found three additional candidates for this existing desired-state lane; please absorb them here rather than opening a competing settings writer once their protected-branch prerequisites land:

  • g7: current live description is already concise/product-facing; preserve it or normalize to Gnuboard7 — Laravel 12 + React CMS and commerce platform maintained as a ContextualWisdomLab fork. Existing useful topics: cms, laravel, php, react, typescript, web-app; add bounded ecommerce, contextualwisdomlab if the taxonomy accepts them. has_pages=false. Canonical README writer is g7#3; I extended that same branch with the exact Ask DeepWiki badge for ContextualWisdomLab/g7. Do not reconcile Pages until that writer (and a docs/index.md prerequisite if Pages is intended) reaches the protected default branch.
  • html4tree: live description is the inherited implementation phrase html4tree generates index.html files based on a file directory tree. Think Apache mod_autoindex.; desired customer-facing wording can be html4tree — generate browsable static index pages from directory trees with a small Kotlin CLI. Preserve useful topics autoindex, file-tree, index-generator, kotlin, static-site; add cli, contextualwisdomlab if bounded. has_pages=false. Canonical writer html4tree#600 already has the exact DeepWiki badge, and I extended that same branch with docs/index.md as the Pages source prerequisite.
  • nonnest2: live description is already concise Korean product wording; preserve it or normalize to nonnest2 — Vuong-based distinguishability and relative-fit comparison for nested and non-nested statistical models in R. Preserve model-comparison, psychometrics, r-package, statistics, vuong-test; add contextualwisdomlab. has_pages=false. Canonical writer nonnest2#118 now carries the exact DeepWiki badge and a Pages-ready docs/index.md; its GPL-2/GPL-3 provenance/commercial boundary must remain explicit and must not be converted into a permissive-license claim.

All three are source-precondition coordination only: no live description/topic/Pages convergence is claimed until protected-default content is present and the existing reconciler can apply/re-read settings and published HTTPS content. The current PR is still Draft/conflicted, so this is intentionally coordination on the single existing owner lane rather than a duplicate metadata PR.

Copy link
Copy Markdown
Contributor Author

Follow-up to the earlier public-surface coordination: g7#3 has now been extended on the same canonical writer branch with docs/index.md in addition to the exact-cased Ask DeepWiki badge. The landing is product/onboarding/architecture/release-boundary focused and explicitly says source presence is not live Pages publication. Therefore the branch-level prerequisites for a later g7 Pages-intent reconciliation are now badge + Pages source; still do not claim or apply live Pages until that writer reaches the protected default branch and the existing settings reconciler can apply/re-read repository settings plus the published HTTPS endpoint.

Copy link
Copy Markdown
Contributor Author

Fresh source-ready candidate for this existing desired-state writer: noema now already satisfies the protected-source prerequisites on main (exact Ask DeepWiki badge in root README and a substantive docs/index.md public landing). Its live repository settings still expose the older narrow description Noema review bot: OIDC-scoped GitHub App token broker for ContextualWisdomLab LLM pull request reviews., homepage=null, has_pages=false, and topics bot, code-review, github-app, llm, oidc, python, typescript. Please absorb noema here rather than opening a competing settings PR: concise description Noema — evidence-producing credential and maintenance control plane for governed GitHub automation.; preserve useful existing topics while adding bounded role/ecosystem classification such as automation, control-plane, security, and contextualwisdomlab; deepwiki: true; pages: true. Update the exact-casing expected-set test with lowercase repository identity noema and preserve the existing fail-closed DeepWiki/Pages prerequisite tests. This is desired state only; do not claim live settings or Pages convergence until the protected owner-side reconciler applies and re-reads them.

Copy link
Copy Markdown
Contributor Author

Additional public-surface candidate for this existing desired-state writer: mightyETL. Live repository settings are currently description A microservices-based platform for real-time Change Data Capture (CDC) and bounded Extract-Transform-Load (ETL) operations., homepage empty, has_pages=false, with useful topics cdc, etl, java, kafka, microservices, postgresql, spring-boot. Canonical public-doc writer mightyETL#149 now owns the exact-cased Ask DeepWiki badge and, at new source commit a1dfca16a260e6f605d099499a064d7ddb330042, a substantive docs/index.md Pages landing. Keep mightyETL gated on #149 reaching protected develop; do not point Pages at unmerged source. After that prerequisite, preserve the current concise product description (or equivalent buyer-facing wording), preserve existing useful topics while adding only bounded taxonomy such as data-integration, change-data-capture, and contextualwisdomlab, and declare deepwiki: true / pages: true. Update exact-casing tests for mightyETL; source/manifest presence is not live convergence until the protected reconciler applies and re-reads settings plus published HTTPS content.

Copy link
Copy Markdown
Contributor Author

Current-base refresh evidence (2026-09-02): protected main is now 5c561a65cca3b925d533e4b40c5c3ac00f16524e. The previous PR head 49dc2f90dc1e81f1b3c7171449f56a5b3b0a5bea had fallen behind current protected main while still carrying only the intended config/repository-metadata.json and tests/test_repository_metadata_reconciliation.py deltas. I refreshed the writer non-destructively by creating merge head 4b9cba4adca32556649aa081f175ae5549ee6ae4 with the previous PR head and current protected main as parents, then advanced the branch with a normal non-force ref update. No force-push or destructive rebase was used. Fresh comparison is based on current protected main and still exposes only those two intended paths. Exact-head checks have re-triggered and several remain queued/pending, so this PR stays Draft and none of its desired-state entries are being treated as live description/topics/Pages convergence. Re-read exact-head checks, prerequisite protected README/docs sources, settings credential availability, and live repository/Pages state before promotion or merge.

Copy link
Copy Markdown
Contributor Author

Traversal reconciliation note (2026-09-02): ContextualWisdomLab/OmniRoute#1 currently says this metadata writer has already been given the desired customer-facing replacement, but the canonical config/repository-metadata.json on this PR does not yet contain an exact-cased OmniRoute entry. That mismatch should not be resolved by racing a settings write or by declaring the source prerequisite complete: #1 still owns the exact DeepWiki/public-navigation source and is not protected-default truth yet. When #1 integrates (or an equivalent verified successor carries its complete valid delta), add OmniRoute here as the single declarative settings owner, preserve the upstream homepage and useful existing topics, replace the ownership-caveat repository description with product-facing gateway wording, and keep Pages intent bounded to actual organization-owned docs rather than the upstream product site. Until then, treat #1's handoff wording as Proposed and do not claim live description/topics/Pages convergence.

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal added the missing source prerequisites to the existing single writer ContextualWisdomLab/quarantine-sandbox-runtime#1 rather than opening a competing docs PR: exact Ask DeepWiki badge in README.md and a product/architecture/onboarding docs/index.md landing now exist on that Draft branch at head a57f073dc85014fe025297c4796749d4f279c8f5.

Do not add/apply this repository to the settings manifest yet: protected develop still lacks those prerequisites and #1 remains Draft/pre-release. After #1 integrates and the exact badge + docs/index.md are reverified on protected source, absorb it into this existing desired-state lane with the current concise description (Source-agnostic, credential-free artifact analysis runtime for the ContextualWisdomLab security ecosystem.) unless protected product wording has changed, preserve useful automated-analysis/sandbox/security topics, and add evidence-based bounded topics such as rust, sandbox-runtime, artifact-analysis, and contextualwisdomlab only after verifying the shipped runtime/language. Pages intent should target <default>/docs only after protected prerequisites are true; live Pages publication still requires the normal settings reconciler and REST/endpoint verification.

Copy link
Copy Markdown
Contributor Author

Fresh protected-base repair: this Draft desired-state writer is now ahead_by=9 / behind_by=8 against current main@b4eec000d21084accb736d289eb64cfd78e7a91a. Comparing its previous merge base 6ba61e7f... to current main shows the eight base commits do not touch either branch-owned file (config/repository-metadata.json, tests/test_repository_metadata_reconciliation.py), so the writer can be reconciled without content arbitration. I will preserve the current two-file delta and create a normal two-parent merge commit with the unchanged PR head first and current protected main second, using the current-main tree plus those exact two branch blobs. No force-push/rebase; Draft/source-prerequisite/settings-credential boundaries remain unchanged; all prior checks become predecessor evidence and the new exact head must reacquire governance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant