Skip to content

fix(kpi): restack provenance JSON byte integrity on d8bdcf main - #335

Closed
seonghobae wants to merge 1 commit into
mainfrom
fix/kpi-provenance-json-integrity-d8bdcf
Closed

fix(kpi): restack provenance JSON byte integrity on d8bdcf main#335
seonghobae wants to merge 1 commit into
mainfrom
fix/kpi-provenance-json-integrity-d8bdcf

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Purpose

Rebuild only PR #327's strict production-KPI provenance byte-integrity hardening onto the current protected-main lineage after #331 advanced main. No predecessor CI, review, scanner, coverage, model/status, production-KPI, release, deployment, legal-rights, or acquisition authority transfers.

Exact construction

  • protected main at the final pre-write refetch: d8bdcf79149635e5c34c992e91ce22b9a78c9b49;
  • source PR fix(kpi): restack provenance JSON byte integrity on 2d9d4e main #327 exact unchanged head at the final pre-write refetch: 46485f3024885746e58beff0ff559b426f06186a;
  • successor exact head: 57f1f229c16ef845f6ad8ff943eafde3d829c06a;
  • parent is exactly the protected-main SHA above;
  • net scope is exactly two paths: scripts/kpi-gate.mjs and test/kpi-provenance-json-integrity.test.ts;
  • successor blobs are exact source-head blobs 2ce57ef368f36a196645c94948dad3f2476ca5a0 and c8a072efd12f86c826c0b6d98b506ecee9817c76.

A fresh comparison from #327's construction base 2d9d4e26a81d043a1985fc2244efb2a311fcf1d0 to current protected main showed only the two production-environment-governance paths merged through #331, with no overlap on this KPI provenance slice. The protected scripts/kpi-gate.mjs blob was still the original 12363af16b4168efef2fd0e45bae6086d968bdf2, and the focused test path remained absent, immediately before construction.

KPI provenance integrity contract

Strict provenance remains raw bytes until fatal UTF-8 decoding and rejects escape-equivalent duplicate decoded JSON object names before JSON.parse or production-source identity, collection timestamp, record count, SHA-256/byte-size, verified snapshot, final identity, and least-authority KPI child-process decisions. Existing production-source/provenance binding remains unchanged.

This hardens evidence parsing only. It does not synthesize or claim a real 30-day production KPI window.

Evidence boundary

Keep Draft until this unchanged exact head receives fresh terminal-success application ci, reviewer-ci, protected-base-eligible central Security Scan, configured exact 100% owned production statement/branch/function/line coverage with realistic tests, and zero valid unresolved findings. Pending, queued, skipped, absent, neutral, failed, cancelled, stale, predecessor, status-only, model-only, or rate-limited evidence is non-passing.

Immediately before Ready or merge, independently re-resolve protected main, exact head/base/ancestry, workflow checkout SHAs, formal reviews/threads, live rulesets, exact central Security Scan revision/triggers/base filters/thresholds, releases, and active-writer state.

No force update, gate weakening, synthetic KPI/release/deployment/legal evidence, reviewer/secret invention, outbound-license choice, repair/self-modifying workflow, or acquisition-ready claim is introduced.

Supersedes #327 only after fresh exact-head verification and protected integration. Related: #3, #84.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: ea98f427-abd8-451f-89c5-05783fcbab99

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Superseded by consolidated current lineage PR #348, which carries this strict KPI provenance integrity and entrypoint coverage work on the current protected-main line. Closing the predecessor; its checks and reviews are historical only.

@seonghobae seonghobae closed this Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant