fix(kpi): restack provenance JSON byte integrity on 2d9d4e main - #327
fix(kpi): restack provenance JSON byte integrity on 2d9d4e main#327seonghobae wants to merge 2 commits into
Conversation
|
Important Review available on request
Reviews should be triggered manually for repositories with fewer than 10 stars. Select Trigger review above or comment ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by consolidated current lineage PR #348, which carries the same strict KPI provenance byte-integrity work plus the current production coverage contract. Closing this predecessor to keep one active writer; predecessor evidence does not transfer. |
Purpose
Restack only PR #323's strict production-KPI provenance byte-integrity hardening onto the current protected
mainafter #324 advanced the base. No predecessor CI, review, scanner, coverage, model/status, production-KPI, release, deployment, legal-rights, or acquisition authority transfers.Exact lineage
2d9d4e26a81d043a1985fc2244efb2a311fcf1d0;5a200e80cbf77fbb0f6dbd33242f56e869008f88;46485f3024885746e58beff0ff559b426f06186a;main;scripts/kpi-gate.mjsandtest/kpi-provenance-json-integrity.test.ts;12363af16b4168efef2fd0e45bae6086d968bdf2), while successor production/test blobs are exact predecessor-head blobs (2ce57ef368f36a196645c94948dad3f2476ca5a0,c8a072efd12f86c826c0b6d98b506ecee9817c76).KPI provenance integrity contract
Strict provenance remains raw bytes until fatal UTF-8 decoding and rejects escape-equivalent duplicate decoded JSON object names before
JSON.parseor production-source identity, collection timestamp, record count, SHA-256/byte-size, verified snapshot, final identity, and least-authority KPI child-process decisions. Existing production-source/provenance binding remains unchanged.This hardens evidence parsing only. It does not synthesize, substitute for, or claim a real 30-day production KPI window.
Evidence boundary
Keep this PR Draft until this unchanged exact head has fresh terminal-success application
ci,reviewer-ci, protected-base-eligible centralSecurity Scan, exact configured 100% owned production statement/branch/function/line coverage with realistic tests, and zero valid unresolved findings. Pending, queued, skipped, absent, neutral, failed, cancelled, stale, predecessor, status-only, model-only, or rate-limited evidence is non-passing.Immediately before Ready or merge, independently re-resolve protected main, exact head/base/ancestry, workflow checkout SHAs, reviews/threads, live rulesets, exact central Security Scan authority/triggers/base filters/thresholds, releases, and active-writer state.
No gate weakening, force update, synthetic KPI/release/deployment/legal evidence, reviewer/secret invention, outbound-license choice, or acquisition-ready claim is introduced.
Related: #323, #321, #315, #284, #3.