Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
581 commits
Select commit Hold shift + click to select a range
19ee7d7
docs: refresh Noema commercial gap authority
seonghobae Sep 5, 2026
b4b0afa
docs: roll forward live Noema authority again
seonghobae Sep 5, 2026
75b1c9f
docs: bind latest central trust authority
seonghobae Sep 5, 2026
7cbdeee
merge: restack #548 on executable CodeGraph retry semantics
seonghobae Sep 5, 2026
fcd6f2d
docs: reconcile CodeGraph retry and stacked exact heads
seonghobae Sep 5, 2026
fa93ba3
merge: restack #548 on physical Docker checkout provenance
seonghobae Sep 5, 2026
3c0c075
docs: reconcile current reviewer and central trust authority
seonghobae Sep 5, 2026
2814e5e
test(docs): bind publisher threat controls to protected implementation
seonghobae Sep 5, 2026
107a973
docs: reflect protected atomic publisher controls
seonghobae Sep 5, 2026
63ea5c0
fix(docs): restore buyer-impact gap contract
seonghobae Sep 5, 2026
19315d9
merge: restack #548 on complete reviewer context
seonghobae Sep 5, 2026
faed0a8
docs(gap): record reviewer context liveness repair
seonghobae Sep 5, 2026
a7066ea
merge: restack #548 on fail-before-execution reviewer scope
seonghobae Sep 5, 2026
33aa1c7
docs: record fail-before-execution reviewer authority
seonghobae Sep 5, 2026
6f57924
fix(reviewer): preserve prompt-data boundary in failed-check lane
seonghobae Sep 5, 2026
7e2522e
merge: restack #548 on JSON-scope reviewer recovery
seonghobae Sep 5, 2026
201e9c7
docs: reconcile reviewer and central trust authority
seonghobae Sep 5, 2026
91c9891
docs: advance current central trust observation
seonghobae Sep 5, 2026
24c9993
merge: restack #548 on JSON-safe symbol recovery
seonghobae Sep 5, 2026
d4dd1f9
docs: reconcile JSON-safe reviewer recovery authority
seonghobae Sep 5, 2026
1209874
docs(reviewer): merge JSON-safe seed contract into #548
seonghobae Sep 5, 2026
bb7aacf
merge: restack #548 on reviewer recovery documentation
seonghobae Sep 5, 2026
ee0b035
docs: refresh commercial gap baseline to current reviewer stack
seonghobae Sep 5, 2026
f0685c2
test(workflow): cover failure authority boundaries
seonghobae Sep 5, 2026
7e5ff9c
test(workflow): cover both foreign snapshot identities
seonghobae Sep 5, 2026
dd73533
merge: restack #548 on exact Linux path identity prerequisite
seonghobae Sep 5, 2026
af5fae8
docs: refresh commercial gap authority after path-identity repair
seonghobae Sep 5, 2026
19c6fa2
test(workflow): fail on extra durable command payload
seonghobae Sep 5, 2026
10708af
fix(workflow): minimize durable command transport payload
seonghobae Sep 5, 2026
8c118cc
docs: reconcile workflow transport and central trust authority
seonghobae Sep 5, 2026
65a256b
test(reviewer): align #548 deterministic identity fixture
seonghobae Sep 5, 2026
bb8fe78
merge: restack #548 on reviewer hosted-RED repair
seonghobae Sep 5, 2026
77f621e
docs: record hosted reviewer RED and exact repair stack
seonghobae Sep 5, 2026
a545af0
test(actions): make spawn spy test callback async
seonghobae Sep 5, 2026
5c8c08a
docs: record commercial-loop hosted RED repair
seonghobae Sep 5, 2026
00e871e
test(workflow): pin command operation during transport
seonghobae Sep 5, 2026
1f7f5b9
fix(workflow): snapshot command operation for transport
seonghobae Sep 5, 2026
124bc77
docs(gap): record workflow command snapshot repair
seonghobae Sep 5, 2026
e88a379
test(workflow): reject nested claim payload leakage
seonghobae Sep 5, 2026
81abbab
test(workflow): cover nested checkpoint transport minimization
seonghobae Sep 5, 2026
f915d13
test(workflow): preserve fail-closed nested payload validation
seonghobae Sep 5, 2026
037ec4e
fix(workflow): minimize nested durable command payloads
seonghobae Sep 5, 2026
d3b42ac
merge: restack #548 on reviewer docstring repair
seonghobae Sep 5, 2026
da8a16a
docs: reconcile current reviewer and workflow authority
seonghobae Sep 5, 2026
d23a055
test(actions): align readiness fixtures with current authority
seonghobae Sep 5, 2026
1c0fc0a
docs: reconcile current commercial-loop RED evidence
seonghobae Sep 5, 2026
74a9493
test(workflow): cover missing durable state authority paths
seonghobae Sep 5, 2026
45e6450
docs: reconcile durable coverage and central trust authority
seonghobae Sep 5, 2026
cd3c9be
docs: reconcile governance and central trust authority
seonghobae Sep 5, 2026
6793a32
test(workflow): cover unexpected durable state errors
seonghobae Sep 5, 2026
4d8f314
test(reviewer): cover failed-check edge branches
seonghobae Sep 5, 2026
4507696
docs: reconcile live reviewer and trust evidence
seonghobae Sep 5, 2026
2fa21a1
merge: restack #548 on protected reviewer truth
seonghobae Sep 6, 2026
d4e3f27
merge: restack #542 on protected reviewer truth
seonghobae Sep 6, 2026
e6d6305
merge: restack #547 on protected reviewer truth
seonghobae Sep 6, 2026
b0f747a
merge: restack #553 on protected reviewer truth
seonghobae Sep 6, 2026
f6c6af5
merge: restack #543 on protected reviewer truth
seonghobae Sep 6, 2026
ebb9944
docs: promote merged semantic reviewer truth
seonghobae Sep 6, 2026
f1ca199
test: bind baseline to merged reviewer main
seonghobae Sep 6, 2026
2de27d2
merge: restack #550 on protected reviewer truth
seonghobae Sep 6, 2026
ffea69e
Restack Cloudflare toolchain on protected reviewer foundation
seonghobae Sep 6, 2026
e001564
docs: reconcile post-reviewer semantic restacks
seonghobae Sep 6, 2026
52b66ca
merge(reviewer): restack shared noema-core on protected reviewer foun…
seonghobae Sep 6, 2026
cf5dfa1
merge(context-fabric): restack shared noema-core on protected context…
seonghobae Sep 6, 2026
6f09d16
merge(context-fabric): restack required-gate regression on protected …
seonghobae Sep 6, 2026
ec3dbdf
merge(context-fabric): restack automation threat-model docs on protec…
seonghobae Sep 6, 2026
a0823f1
merge(context-fabric): restack failed-check evidence on protected con…
seonghobae Sep 6, 2026
158d818
merge(context-fabric): restack concurrency owner on protected context…
seonghobae Sep 6, 2026
6953eaa
merge(context-fabric): restack durable workflow authority on protecte…
seonghobae Sep 6, 2026
7224d65
fix(lockfile): rebind policy to protected context admission
seonghobae Sep 6, 2026
197fb05
merge(context-fabric): restack Cloudflare toolchain on protected cont…
seonghobae Sep 6, 2026
bc2853c
docs(adr): reconcile protected context admission authority
seonghobae Sep 6, 2026
3e66643
docs(gap): reconcile protected Context Fabric authority
seonghobae Sep 6, 2026
f5804e6
merge(context-fabric): reconcile docs with protected admission truth
seonghobae Sep 6, 2026
d655663
test(docs): bind active-work contract to protected Context Fabric head
seonghobae Sep 6, 2026
6551a86
test(reviewer): expose non-exact finding line admission
seonghobae Sep 6, 2026
5c20453
fix(reviewer): require exact positive finding lines
seonghobae Sep 6, 2026
02ec900
chore(reviewer): keep line-contract repair minimal
seonghobae Sep 6, 2026
fe0a66e
docs: refresh central trust and reviewer line authority
seonghobae Sep 6, 2026
2006f41
docs: record hosted CodeGraph isolation repair
seonghobae Sep 6, 2026
908d9cc
docs(release): restore noema-core Unreleased note
seonghobae Sep 6, 2026
2d9521f
docs(gap): record restored release traceability
seonghobae Sep 6, 2026
f6ec87a
fix(reviewer): retain self-cycle exclusion
seonghobae Sep 6, 2026
fc2655b
merge: converge automation threat model onto protected #533 truth
seonghobae Sep 6, 2026
c9c2d86
merge: converge exact-head gate regression onto protected #533 truth
seonghobae Sep 6, 2026
3cb7261
merge: converge failed-check evidence onto protected #533 truth
seonghobae Sep 6, 2026
6d6e0a4
merge: converge noema-core Shared Kernel onto protected #533 truth
seonghobae Sep 6, 2026
fec1025
chore(hourly): restack run-independence lane on protected main
seonghobae Sep 6, 2026
a1172fc
merge: converge noema-core Shared Kernel onto protected #552 truth
seonghobae Sep 6, 2026
12f8e3d
merge: converge workflow-concurrency lane onto protected #552 truth
seonghobae Sep 6, 2026
a6970ca
merge: converge exact-head gate regression onto protected #552 truth
seonghobae Sep 6, 2026
722fa12
merge: converge automation threat model onto protected #552 truth
seonghobae Sep 6, 2026
75f93fd
merge: converge failed-check evidence onto protected #552 truth
seonghobae Sep 6, 2026
797c6da
docs: refresh live commercial gap authority after protected #552
seonghobae Sep 6, 2026
1766380
docs: preserve current rights evidence while refreshing toolchain gap
seonghobae Sep 6, 2026
6553f6b
merge: reconcile documentation authority onto protected #552 truth
seonghobae Sep 6, 2026
93bfa5e
merge: converge durable workflow authority onto protected #552 truth
seonghobae Sep 6, 2026
424c149
fix(toolchain): rebind lock policy to current protected base
seonghobae Sep 6, 2026
591795a
merge: converge Cloudflare toolchain lane onto protected #552 truth
seonghobae Sep 6, 2026
a87e2f1
docs: refresh commercial gap exact-head authority
seonghobae Sep 6, 2026
fbd2d7b
test(docs): bind active-work contract to current protected heads
seonghobae Sep 6, 2026
b20f203
docs: restack current authority after OIDC trust merge
seonghobae Sep 6, 2026
049a57d
merge: restack reviewer evidence after #527 trust integration
seonghobae Sep 6, 2026
8415e3c
merge: restack noema-core after #527 trust integration
seonghobae Sep 6, 2026
f07679d
merge: restack exact-head gate regression after #527 trust integration
seonghobae Sep 6, 2026
4659f8b
merge: restack automation threat model after #527 trust integration
seonghobae Sep 6, 2026
ad0f512
merge: restack workflow concurrency after #527 trust integration
seonghobae Sep 6, 2026
7c8c269
fix(toolchain): rebind lockfile policy to protected #527 trust merge
seonghobae Sep 6, 2026
6b7f0a7
merge: restack toolchain boundary after #527 trust integration
seonghobae Sep 6, 2026
9236775
merge: restack durable workflow state after #527 trust integration
seonghobae Sep 6, 2026
f82fd75
docs: record post-527 exact candidate heads
seonghobae Sep 6, 2026
3ebbf94
docs: align active owner literals with contracts
seonghobae Sep 6, 2026
e203bb8
test(docs): require current central trust authority
seonghobae Sep 6, 2026
8b27bac
docs: record current central workflow trust prerequisite
seonghobae Sep 6, 2026
e2e4042
docs: restore canonical buyer-gap table contract
seonghobae Sep 6, 2026
8e7e0bb
test(workflow): reject deleted retained transition receipts
seonghobae Sep 6, 2026
35f80f2
fix(workflow): fail closed on deleted retained transition receipts
seonghobae Sep 6, 2026
8afef54
test(workflow): reject explicit empty transition ledger
seonghobae Sep 6, 2026
55194e1
fix(workflow): reject explicit empty transition ledger
seonghobae Sep 6, 2026
4185df2
test(workflow): reject missing initialized provenance root
seonghobae Sep 6, 2026
1909f23
fix(workflow): require initialized provenance root
seonghobae Sep 6, 2026
7a2fa97
test(docs): require current live authority identities
seonghobae Sep 6, 2026
788ab94
docs(authority): follow current central and runtime candidates
seonghobae Sep 6, 2026
a2d8b26
test(docs): require current central trust authority
seonghobae Sep 6, 2026
84876b4
docs: advance central trust authority baseline
seonghobae Sep 6, 2026
84a2cd0
fix(workflow): preserve legacy first-claim provenance
seonghobae Sep 6, 2026
42a0f6d
test(docs): require repaired workflow state head
seonghobae Sep 6, 2026
bf9a0e2
docs: record workflow legacy-provenance repair
seonghobae Sep 6, 2026
4aa7302
test(docs): require latest central trust authority
seonghobae Sep 6, 2026
bee3911
docs: follow latest central trust source
seonghobae Sep 6, 2026
2bb6076
test(workflow): cover malformed retained receipt rejection
seonghobae Sep 6, 2026
0ae16b6
test(docs): require current protected and candidate authority
seonghobae Sep 6, 2026
beece2d
docs: reconcile protected and active commercial authority
seonghobae Sep 6, 2026
cb240c1
docs: restack commercial authority onto protected main
seonghobae Sep 6, 2026
48bf2a9
test(docs): require current workflow trust authority
seonghobae Sep 6, 2026
9cb3e18
docs: align commercial gap baseline with current trust source
seonghobae Sep 6, 2026
129affe
test(docs): require latest protected trust source
seonghobae Sep 6, 2026
a27050f
test(docs): require current central trust authority
seonghobae Sep 6, 2026
8010d08
docs: bind gap baseline to current trust authority
seonghobae Sep 6, 2026
7f743f4
merge(main): restack durable workflow state after trusted source roll…
seonghobae Sep 6, 2026
232b602
test(docs): require post-trust-integration authority
seonghobae Sep 6, 2026
ba54ec0
docs: bind gap baseline after trust integration
seonghobae Sep 6, 2026
7b17b4e
merge(main): restack documentation authority after trust integration
seonghobae Sep 6, 2026
3ed5bd9
merge(main): restack workflow concurrency after protected trust integ…
seonghobae Sep 6, 2026
a016521
merge(main): restack automation threat model after protected trust in…
seonghobae Sep 6, 2026
e255bf1
merge(main): restack exact-head gate regression after protected trust…
seonghobae Sep 6, 2026
82366b2
merge(main): restack noema-core after protected trust integration
seonghobae Sep 6, 2026
e24d310
merge(main): restack reviewer evidence after protected trust integration
seonghobae Sep 6, 2026
4616b5e
test(workflow): isolate malformed retained receipt invariant
seonghobae Sep 6, 2026
6a7b2a3
docs: record post-trust branch convergence
seonghobae Sep 6, 2026
61632a6
fix(lockfile): bind policy to current protected base
seonghobae Sep 6, 2026
2eba9d6
merge(main): restack toolchain policy after protected trust integration
seonghobae Sep 6, 2026
2d2d86d
test(docs): bind post-trust authority to current candidates
seonghobae Sep 6, 2026
24167c3
docs: reconcile current workflow and toolchain candidates
seonghobae Sep 6, 2026
9e60f04
test(docs): bind active-work contract to current candidates
seonghobae Sep 6, 2026
b14b37c
merge(restack): rebase #543 onto protected main d9b2a95
seonghobae Sep 7, 2026
4c213e1
merge(restack): converge #553 on protected main d9b2a95
seonghobae Sep 7, 2026
6fe8f62
test(docs): require post-526 protected authority
seonghobae Sep 7, 2026
40ebb4b
docs(gap): bind baseline to protected #526 integration
seonghobae Sep 7, 2026
176c43e
merge(restack): converge #547 on protected main d9b2a95
seonghobae Sep 7, 2026
46439b1
merge(main): non-force restack durable workflow lane after #526
seonghobae Sep 7, 2026
29ed0a7
test(docs): require current active candidate identities
seonghobae Sep 7, 2026
d4f312d
docs: reconcile current candidate identities after #526
seonghobae Sep 7, 2026
aeb9c46
merge(main): non-force restack workflow concurrency after #526
seonghobae Sep 7, 2026
9bdf6c0
test(docs): require post-#526 workflow concurrency authority
seonghobae Sep 7, 2026
bc90d32
docs: record post-#526 workflow concurrency authority
seonghobae Sep 7, 2026
91db535
docs: fix workflow concurrency predecessor traceability
seonghobae Sep 7, 2026
3592f52
test(docs): bind baseline to live reviewer stack
seonghobae Sep 7, 2026
4690579
docs: reconcile live reviewer stack authority
seonghobae Sep 7, 2026
a5cd666
chore: restack noema-core foundation on protected main
seonghobae Sep 7, 2026
fdf1d8e
docs: preserve noema-core changelog on current main
seonghobae Sep 7, 2026
39cf653
test(docs): require current reviewer candidate heads
seonghobae Sep 7, 2026
5369143
test(docs): isolate current candidate requirements
seonghobae Sep 7, 2026
1bdcd9a
docs: reconcile reviewer candidate authority
seonghobae Sep 7, 2026
97f4270
docs: align stacked security routing with live ruleset
seonghobae Sep 7, 2026
184d446
test(docs): require current orchestrator consumer head
seonghobae Sep 7, 2026
fae764e
docs: track live orchestrator consumer authority
seonghobae Sep 7, 2026
49a7828
test(docs): require current claim-receipt candidate head
seonghobae Sep 7, 2026
92c56dc
docs: track current claim-receipt adapter and gate evidence
seonghobae Sep 7, 2026
5cd6341
Merge pull request #543 from ContextualWisdomLab/chore/paths-ignore-fix
seonghobae Sep 7, 2026
4fe6fe8
chore: restack noema-core on protected main
seonghobae Sep 7, 2026
c0d2c21
test(docs): require current protected and reviewer authority
seonghobae Sep 7, 2026
cb9606a
docs: reconcile protected and evidence authority
seonghobae Sep 7, 2026
d609b09
test(docs): advance claim-evidence candidate authority
seonghobae Sep 7, 2026
182fbed
docs: advance claim-evidence publication authority
seonghobae Sep 7, 2026
317edd9
test(docs): distinguish moving stack observation authority
seonghobae Sep 7, 2026
843d5c1
docs: bound moving-stack observation authority
seonghobae Sep 7, 2026
4c92578
merge(main): non-force restack threat-model docs after #543
seonghobae Sep 7, 2026
289fbb0
merge(main): non-force restack workflow concurrency after #543
seonghobae Sep 7, 2026
6cb43c1
merge(main): non-force restack durable workflow lane after #543
seonghobae Sep 7, 2026
1a1d270
test(docs): require post-543 independent-lane authority
seonghobae Sep 7, 2026
384da6f
test(docs): refresh moving reviewer observation
seonghobae Sep 7, 2026
2baf6f6
docs: reconcile post-543 current-main lanes
seonghobae Sep 7, 2026
572b8a9
test(docs): remove stale active-work SHA expectations
seonghobae Sep 7, 2026
02b003d
merge(main): converge documentation authority after #543
seonghobae Sep 7, 2026
513c586
test(docs): align post-trust authority with current protected lineage
seonghobae Sep 7, 2026
3b3df88
test(docs): align workflow-concurrency authority with current head
seonghobae Sep 7, 2026
eafc06f
test(docs): keep moving evidence stack observation-scoped
seonghobae Sep 7, 2026
08c84a1
test(docs): drop obsolete predecessor trust assertion
seonghobae Sep 7, 2026
4c1d174
Merge pull request #536 from ContextualWisdomLab/feat/noema-core-shar…
seonghobae Sep 7, 2026
fb44888
chore(restack): merge protected main into #548 branch
seonghobae Sep 7, 2026
31d2e5c
chore: converge #553 on current protected main
seonghobae Sep 7, 2026
210fd23
chore: converge #550 on protected #536 foundation
seonghobae Sep 7, 2026
240703d
test(docs): require post-536 live authority baseline
seonghobae Sep 7, 2026
305e9ab
docs: reconcile post-536 protected and active authority
seonghobae Sep 7, 2026
4b527be
test(docs): separate central head from reviewed workflow pin
seonghobae Sep 7, 2026
f16709f
test(docs): allow historical predecessor identity traceability
seonghobae Sep 7, 2026
21fcb81
test(docs): require post-536 convergence authority
seonghobae Sep 7, 2026
d112042
test(docs): bind workflow concurrency to post-536 head
seonghobae Sep 7, 2026
a1a006a
Merge d1120420cc200a70c685613f1520141e25ccd0c3 into 4c1d174adae3a3cc1…
seonghobae Sep 7, 2026
97b679c
test(docs): bind orchestrator consumer to current head
seonghobae Sep 7, 2026
02a770e
docs: reconcile current reviewer and gate authority
seonghobae Sep 7, 2026
c1fa3e6
test(docs): retire superseded active-work authority
seonghobae Sep 7, 2026
985d324
test(docs): track current orchestrator consumer head
seonghobae Sep 7, 2026
5380e91
merge(main): non-force converge durable workflow after #536
seonghobae Sep 7, 2026
9f2b8af
fix(workflow): preserve protected noema-core authority
seonghobae Sep 7, 2026
a13a795
test(docs): require converged durable workflow head
seonghobae Sep 7, 2026
71936b8
test(docs): retire pre-convergence durable head
seonghobae Sep 7, 2026
93ed5ca
test(docs): bind durable lane to current convergence
seonghobae Sep 7, 2026
1dc3690
docs: reconcile durable-workflow convergence authority
seonghobae Sep 7, 2026
e6de53a
Merge pull request #548 from ContextualWisdomLab/codex/noema-failed-c…
seonghobae Sep 7, 2026
c03d946
chore: converge automation threat model after reviewer evidence merge
seonghobae Sep 7, 2026
f2ec2dc
chore: converge workflow concurrency after reviewer evidence merge
seonghobae Sep 7, 2026
195fdd7
chore: converge durable workflow after reviewer evidence merge
seonghobae Sep 7, 2026
ddde268
docs: converge commercial authority after #548
seonghobae Sep 7, 2026
b50752b
test(docs): require post-#548 current authority
seonghobae Sep 7, 2026
871b44c
docs: repair post-#548 commercial authority baseline
seonghobae Sep 7, 2026
538a821
test(docs): require current #535 authority
seonghobae Sep 7, 2026
5f947e6
docs: refresh current #535 authority
seonghobae Sep 7, 2026
6b5b2c8
Merge pull request #550 from ContextualWisdomLab/codex/actions-concur…
seonghobae Sep 7, 2026
3bd9f54
docs: converge automation threat model after workflow concurrency merge
seonghobae Sep 7, 2026
c2bb6fa
merge(main): converge durable workflow execution after #550
seonghobae Sep 7, 2026
39f3683
Merge pull request #553 from ContextualWisdomLab/docs/fix-stale-pr80-…
seonghobae Sep 7, 2026
ca83929
merge(main): converge durable workflow execution after #553
seonghobae Sep 7, 2026
116ce85
test(toolchain): require post-#553 Cloudflare cleanup convergence
seonghobae Sep 7, 2026
e420b5d
fix(toolchain): implement direct Cloudflare runtime boundary
seonghobae Sep 7, 2026
fd8a38b
fix(ci): strip direct toolchain binaries from validator image
seonghobae Sep 7, 2026
d6394b2
feat(workflow): add atomic durable task claim and checkpoint CAS (#542)
seonghobae Sep 7, 2026
9aa2d9c
fix(toolchain): converge validator boundary after durable workflow in…
seonghobae Sep 7, 2026
c20d915
fix(ci): bind lockfile policy to current protected base
seonghobae Sep 7, 2026
05bc2d4
fix(ci): restore canonical lockfile regeneration evidence
seonghobae Sep 7, 2026
2e0d636
docs: converge commercial gap authority on durable workflow main
seonghobae Sep 7, 2026
85f1e9f
test(docs): require protected durable workflow authority
seonghobae Sep 7, 2026
a83e851
docs(runtime): record protected durable workflow authority
seonghobae Sep 7, 2026
099d7d8
fix(toolchain): replace Wrangler/Miniflare GPL-family path (#540)
seonghobae Sep 7, 2026
fb1cdc7
chore: converge commercial authority on protected main
seonghobae Sep 7, 2026
21dfa94
test(docs): require current protected commercial authority
seonghobae Sep 7, 2026
cc940c0
docs: make commercial baseline post-merge current by construction
seonghobae Sep 7, 2026
6525bf7
test(docs): align authority regressions with protected history
seonghobae Sep 7, 2026
30b7e7e
test(docs): distinguish active lanes from merged history
seonghobae Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
75 changes: 60 additions & 15 deletions .github/lockfile-change-policy.json
Original file line number Diff line number Diff line change
@@ -1,23 +1,68 @@
{
"baseSha": "6bc8ed016dc07f95d4e041a3b79ac00c4086b182",
"baseSha": "d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8",
"bulkChange": null,
"justification": "Remediate GHSA-2v37-7h3g-55p8 by advancing the single transitive nanoid package-lock node from 3.3.17 to the patched 3.3.18 release. Preserve all top-level lock metadata, PostCSS dependency declarations, and unrelated package nodes.",
"justification": "Replace the Wrangler/Miniflare/Sharp transitive development path with direct pinned workerd@1.20260625.1 and esbuild@0.28.1 dependencies for Noema Worker development and deployment tooling. The reviewed lockfile transition removes the Wrangler-owned Miniflare/Sharp/Libvips package set, preserves unchanged package objects and top-level lockfile metadata, and binds the exact protected-main base and regenerated head bytes.",
"packageDigests": {
"node_modules/nanoid": {
"afterSha256": "d05f52cccf4bb2b3faa241c82560bdff38872191f8c2fc9e0fe11d1863c6689c",
"beforeSha256": "eb31926c2b062d6831f465580d52d350ebd0ec8cb0ae8c9b36a92e1bec871af4"
}
"": {"afterSha256": "bc4820765f3986a162070a7c499943d4976663ce9dbf4bc0d039bc8111d14c87","beforeSha256": "bc4df75e5f7a57a7b5cbb8fca21fe3aada716dcd26e4bad5b889d93c5251e20c"},
"node_modules/@cloudflare/kv-asset-handler": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "baf9a6828aa48335b6b1ddc90c064891668bf48ed319cb98bad1aae065e5b110"},
"node_modules/@cloudflare/unenv-preset": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "3975dc435686ec2387ff6065520031589c8608c4040c1bffcfcf169693670bc6"},
"node_modules/@cspotcode/source-map-support": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "be3b4d0e114620b28f168efe57e2f082751ec98c255e5ff44642903ca8c8abc1"},
"node_modules/@img/colour": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "0ec9a3855c0d275ee3ddf26fc218c24bcd73c70ae1be64bc783adcee728fabd3"},
"node_modules/@img/sharp-darwin-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "33753afdce1a4ef04bdbe3955ee21f6f7ec2d0e24950d2d48853ac21d06e0207"},
"node_modules/@img/sharp-darwin-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "92c5e9c8a824389e0d714e015b25bbfe4304b1968f9fc4551c31aeaa84953d7e"},
"node_modules/@img/sharp-freebsd-wasm32": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "e93d997495809b38e24ee02aae3570fd5388f6f29aca13ecc5790df62c4bf2ee"},
"node_modules/@img/sharp-libvips-darwin-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "5cbb579d4f882d736f41709f4ab8df92b444cc24a04ddf4568b6248903988dea"},
"node_modules/@img/sharp-libvips-darwin-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "52cc3b0d34d5f51e30fc3018eea0cf640c5963e6b662cacf9f6c377cc35b6dda"},
"node_modules/@img/sharp-libvips-linux-arm": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "e5de57abbf3750ebae77db880bdee4dd9bd5823468fe4d6a54b6f0076508c120"},
"node_modules/@img/sharp-libvips-linux-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "b86ba40d539fb3254d0a045e330fa90141a3907deefadaf264ce4831512035a4"},
"node_modules/@img/sharp-libvips-linux-ppc64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "666eb414e63b3f4a6f2338f14d6f59127c6f73562659425004d9258a499160a8"},
"node_modules/@img/sharp-libvips-linux-riscv64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "c3e3d0a53cec8bb22b1319219dfcd6fc5d059cd2b133827668fac6e301f77c53"},
"node_modules/@img/sharp-libvips-linux-s390x": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "6273b939a75e550fe2088ac52d90f1bb9918f93330d6b83a7df7db46b7b41efd"},
"node_modules/@img/sharp-libvips-linux-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "21453f05d9d156d477d80b5f6726993033c6e7cc1ffba71d93042fa51648acb4"},
"node_modules/@img/sharp-libvips-linuxmusl-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "84a3b95e19257d67c939f31d82dc6549cad376ead8dc7a9e451e6cfb1d1b3b3e"},
"node_modules/@img/sharp-libvips-linuxmusl-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "4c5fa48ebba69feada47c1b31653a099b461543c104807afdcecf437a1f05f3e"},
"node_modules/@img/sharp-linux-arm": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "a65b10a97d8310bcb4d5e97be980320e91267d69b2b8fcd80aaa8134609e282c"},
"node_modules/@img/sharp-linux-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "07b70ea8a68735233da5aabe69863f359f77bf152addd717311907255038bd5c"},
"node_modules/@img/sharp-linux-ppc64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "5a3f8bb47ada74df86462a8eb4c283cf2f5fc072974c81db4d98a5bd2774bfc6"},
"node_modules/@img/sharp-linux-riscv64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "807f16be2b136919b9089a0df5fc506b3f66f2708205659eb7e11945a578e070"},
"node_modules/@img/sharp-linux-s390x": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "dea04183a47348ebf4455ffc9f7b56d750a388bd59900937a3501a5f886fb0b5"},
"node_modules/@img/sharp-linux-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "e8b884ec932accbb31472f9532d30d9dea8cf69e3665a02a47ff8a278f4a5d26"},
"node_modules/@img/sharp-linuxmusl-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "5d81370f988ddf9cfd71f818640fb1ddba3c61f34936ccd16f9318abb45e070a"},
"node_modules/@img/sharp-linuxmusl-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "dcb1c509e3d9a5a917cfe6b3868acfe372bd4045a4bdeedb3c265d1c9ab2c1d8"},
"node_modules/@img/sharp-wasm32": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "d372231a4a3a965acefef6e4082f35d7faafee7c0ac332d333267eed0230f73f"},
"node_modules/@img/sharp-webcontainers-wasm32": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "3950aee6b7b49d472361e907dd0a38966a4362a9dcd8e3a94cb91187965051da"},
"node_modules/@img/sharp-win32-arm64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "d7b719d77aad3ce761066678008a2b59ee708da1eac1edca5a52d595d064623c"},
"node_modules/@img/sharp-win32-ia32": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "6ac2a1af086a1bd93c725d3379a2d63abb1ccb96fa22d11c320fab8ee9323c0e"},
"node_modules/@img/sharp-win32-x64": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "83788206d3b5d601a59383a2e647e679ae3499f41a4c7c609f5d414fc876edf8"},
"node_modules/@jridgewell/trace-mapping": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "946e048fd4f5f06fd3a2558cecdd7a7e1a179d1c60f88c1a10deff92904cefb6"},
"node_modules/@poppinss/colors": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "9f6d9e5e656687bf9365aad30b1cd57e2005670d483825ff6a9041eb264c0a8c"},
"node_modules/@poppinss/dumper": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "4636d1e8ce5d92e9e6a74b8e331a1d0599151c423620605b7f0d391a6a324f45"},
"node_modules/@poppinss/exception": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "511ab6d7dda3a25412e2d6459b7458c52d35e8d5a38ccea9e8a1c767c2c2b6a3"},
"node_modules/@sindresorhus/is": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "9cf703780184209ca125688afa81e6cf6a49ca4cee7a6442648003875ffa7ede"},
"node_modules/@speed-highlight/core": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "b0d9aede1a43525b35c83c66cfe23301fefa32d437344a723f156bcb3bde75c6"},
"node_modules/blake3-wasm": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "2edd7b9afb0a3edfde7bf65df2176834db86926fb79bcb81757f823ece33e0e8"},
"node_modules/cookie": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "c83cc50b9edf74fff002ee1696f718a7893a2790be1c87668878d4259a9ed661"},
"node_modules/error-stack-parser-es": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "07d175e9a9ce5da0ce6a91827c6c941d31f51684281f0060b3dc3df25db6cc02"},
"node_modules/kleur": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "03d1698c44fce7057c0b68d8cba4bfad5ca7382a948e162d49d806f81ee4859c"},
"node_modules/miniflare": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "3e4f60462e1a727ae18971cc7805b70cee7a5e1ba6265490550d3cd545ce7c2e"},
"node_modules/path-to-regexp": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "206d20489bfee22f1bd8a9ef8b31f0c7bdf9544b7272decd73314db823528dd1"},
"node_modules/sharp": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "185d39448de75db02f7418462440e6b8755e9f1e94fd88b66712835a9f22153a"},
"node_modules/supports-color": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "1a548a2b86a1d2addc0f2fd3dc4a3da1f2a81cd8e94fe1f0d431de96989d234c"},
"node_modules/undici": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "ab97f8ae955e187ed30dae56574c6f24277da4c4068383998f42dd18990d6c9b"},
"node_modules/unenv": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "cd1ef9a2d07200fe1d861ae9a4f81c1b1990312c1c6d88ecf844246efb33f6fe"},
"node_modules/wrangler": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "b52ea831e8e92ebe06b3ed1776cc1f781f7de77ece30a4237a95ff477df65455"},
"node_modules/ws": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "8312a6b5d3e17eda63344fe09189e016ad35b526bbbef54af5468d22eb9902a6"},
"node_modules/youch": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "faaf7ca34f95ab4401519c3222a9b37ef594158220cdb37ea4f3c483817e81d4"},
"node_modules/youch-core": {"afterSha256": "398b676e47d03a29016ee92fe378b8b4f1b3e965390c4c64ce78d27f79df74d1","beforeSha256": "054aee49bedca6747ec8256719b1a9d6c5e834903f6606daa12ef8497dc70043"}
},
"schemaVersion": 3,
"sources": [
"https://github.com/advisories/GHSA-2v37-7h3g-55p8",
"https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz"
"https://registry.npmjs.org/wrangler/-/wrangler-4.105.0.tgz",
"https://registry.npmjs.org/miniflare/-/miniflare-4.20260625.0.tgz",
"https://registry.npmjs.org/sharp/-/sharp-0.35.3.tgz",
"https://registry.npmjs.org/workerd/-/workerd-1.20260625.1.tgz",
"https://registry.npmjs.org/esbuild/-/esbuild-0.28.1.tgz"
],
"targetPackages": [
"node_modules/nanoid"
],
"topLevelMetadataDigests": {
"afterSha256": "354c77096d1795b6f33b903ac8b54c3922a045279413f3e8681c78c1fe5278b1",
"beforeSha256": "354c77096d1795b6f33b903ac8b54c3922a045279413f3e8681c78c1fe5278b1"
}
"targetPackages": ["","node_modules/@cloudflare/kv-asset-handler","node_modules/@cloudflare/unenv-preset","node_modules/@cspotcode/source-map-support","node_modules/@img/colour","node_modules/@img/sharp-darwin-arm64","node_modules/@img/sharp-darwin-x64","node_modules/@img/sharp-freebsd-wasm32","node_modules/@img/sharp-libvips-darwin-arm64","node_modules/@img/sharp-libvips-darwin-x64","node_modules/@img/sharp-libvips-linux-arm","node_modules/@img/sharp-libvips-linux-arm64","node_modules/@img/sharp-libvips-linux-ppc64","node_modules/@img/sharp-libvips-linux-riscv64","node_modules/@img/sharp-libvips-linux-s390x","node_modules/@img/sharp-libvips-linux-x64","node_modules/@img/sharp-libvips-linuxmusl-arm64","node_modules/@img/sharp-libvips-linuxmusl-x64","node_modules/@img/sharp-linux-arm","node_modules/@img/sharp-linux-arm64","node_modules/@img/sharp-linux-ppc64","node_modules/@img/sharp-linux-riscv64","node_modules/@img/sharp-linux-s390x","node_modules/@img/sharp-linux-x64","node_modules/@img/sharp-linuxmusl-arm64","node_modules/@img/sharp-linuxmusl-x64","node_modules/@img/sharp-wasm32","node_modules/@img/sharp-webcontainers-wasm32","node_modules/@img/sharp-win32-arm64","node_modules/@img/sharp-win32-ia32","node_modules/@img/sharp-win32-x64","node_modules/@jridgewell/trace-mapping","node_modules/@poppinss/colors","node_modules/@poppinss/dumper","node_modules/@poppinss/exception","node_modules/@sindresorhus/is","node_modules/@speed-highlight/core","node_modules/blake3-wasm","node_modules/cookie","node_modules/error-stack-parser-es","node_modules/kleur","node_modules/miniflare","node_modules/path-to-regexp","node_modules/sharp","node_modules/supports-color","node_modules/undici","node_modules/unenv","node_modules/wrangler","node_modules/ws","node_modules/youch","node_modules/youch-core"],
"topLevelMetadataDigests": {"afterSha256":"354c77096d1795b6f33b903ac8b54c3922a045279413f3e8681c78c1fe5278b1","beforeSha256":"354c77096d1795b6f33b903ac8b54c3922a045279413f3e8681c78c1fe5278b1"}
}
2 changes: 1 addition & 1 deletion .github/workflows/central-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -429,7 +429,7 @@ jobs:
- name: Run independent PydanticAI review and publish current-head verdict
env:
GH_TOKEN: ${{ steps.noema_write_app.outputs.token }}
PYTHONPATH: ${{ github.workspace }}/reviewer
PYTHONPATH: ${{ github.workspace }}/reviewer:${{ github.workspace }}/packages/noema-core/src
NOEMA_REVIEW_TOKEN_SOURCE: noema-github-app
NOEMA_LLM_API_URL: ${{ vars.NOEMA_LLM_API_URL }}
NOEMA_LLM_MODEL: ${{ vars.NOEMA_LLM_MODEL }}
Expand Down
50 changes: 48 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@
- main

concurrency:
group: noema-ci-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
group: ${{ github.workflow }}-${{ github.repository }}-${{ github.event_name == 'pull_request' && github.event.pull_request.number || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
verify:
Expand Down Expand Up @@ -146,6 +146,52 @@
console.log(`Lockfile change control passed for ${result.changedPackages.length} changed package node(s).`);
NODE

- name: regenerate canonical lockfile in disposable workspace
id: regenerate_lockfile
shell: bash
run: |
set -euo pipefail
regeneration_root="$RUNNER_TEMP/noema-lockfile-regeneration"
rm -rf "$regeneration_root"
mkdir -p "$regeneration_root"
cp package.json package-lock.json .npmrc "$regeneration_root/"
(
cd "$regeneration_root"
npm install \
Comment thread
seonghobae marked this conversation as resolved.
--package-lock-only \
--ignore-scripts \
--no-audit \
--no-fund \
--legacy-peer-deps=false \
--install-links=false
)
cp "$regeneration_root/package-lock.json" "$RUNNER_TEMP/noema-package-lock-regenerated.json"
if cmp --silent package-lock.json "$RUNNER_TEMP/noema-package-lock-regenerated.json"; then
printf 'match=true\n' >> "$GITHUB_OUTPUT"
else
printf 'match=false\n' >> "$GITHUB_OUTPUT"
diff -u package-lock.json "$RUNNER_TEMP/noema-package-lock-regenerated.json" \
> "$RUNNER_TEMP/noema-package-lock-regeneration.diff" || true
fi

- name: upload regenerated lockfile evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: noema-lockfile-regeneration-${{ github.event.pull_request.head.sha || github.sha }}
path: |
${{ runner.temp }}/noema-package-lock-regenerated.json
${{ runner.temp }}/noema-package-lock-regeneration.diff
if-no-files-found: error
retention-days: 1

- name: require committed lockfile reproducibility
if: steps.regenerate_lockfile.outputs.match != 'true'
shell: bash
run: |
printf '::error::package-lock.json is not the canonical output of the pinned Node/npm toolchain.\n'
exit 1

- name: install
run: npm ci --legacy-peer-deps=false --install-links=false

Expand Down
Loading
Loading