Skip to content

ci(release): reconcile legal readiness preflight with current main - #408

Open
seonghobae wants to merge 11 commits into
mainfrom
reconcile/release-legal-readiness-main-20260826
Open

ci(release): reconcile legal readiness preflight with current main#408
seonghobae wants to merge 11 commits into
mainfrom
reconcile/release-legal-readiness-main-20260826

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Why

Protected main@c3eff8d2fbd7e69dccbc3b1f7bf166969c209303 still has no repository license/COPYING evidence and Cargo.toml does not establish source-distribution license metadata. That is an acquisition/release-readiness blocker, but this repository writer must not invent legal terms, copyright ownership, assessment-content rights, or compatibility claims.

Historical PR #240 attempted a fail-closed evidence preflight from an old base, but it is now stale/unmergeable and its accumulated diff also contains unrelated session HTTP test changes. This current-main landing vehicle deliberately excludes that contamination.

TDD / exact scope

  • RED contracts: tests/test_release_legal_readiness.py and tests/test_check_release_legal_readiness.py require an explicit, deterministic, read-only readiness boundary and exercise missing/malformed/path-escape/symlink evidence.
  • GREEN implementation: scripts/check_release_legal_readiness.py reports machine-readable readiness/blockers without selecting or interpreting a license.
  • Manual operator workflow: .github/workflows/release-legal-readiness.yml is workflow_dispatch only, contents: read, exact protected-revision checkout, and intentionally fails while reviewed license evidence is absent.
  • Runtime CI path filters are extended only so changes to license/COPYING evidence, the checker, or the manual workflow cannot bypass the existing Python contract suite. Runtime job identities, coverage semantics, toolchains, PostgreSQL service, permissions, and concurrency behavior are otherwise unchanged.

The exact diff from the recorded protected base is five files only: the current CI path-filter additions plus the four legal-readiness files. No session/scoring/persistence/psychometric behavior is included.

Boundary / limitations

This PR does not choose a license, add license terms, change publish = false, publish a crate, establish copyright ownership, prove instrument rights, certify third-party compatibility, or claim legal sufficiency. Those remain explicit authorized-owner/legal-governance inputs. The preflight itself is evidence machinery, not a substitute for that decision.

Acceptance

Do not merge until the unchanged exact head passes Runtime CI including exact owned statement/branch coverage and the Python contracts, Security/SAST, SPDX SBOM, supply-chain provenance, every live required organization workflow, zero valid unresolved findings, and qualifying independent non-author/non-last-pusher approval under the active ruleset. Pending, queued, skipped, cancelled, absent, stale, predecessor, synthetic, or model-only evidence is not passing. Never self-approve or use administrator bypass.

Supersedes #240 as the clean current-main landing vehicle.


Open in Devin Review

@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 7c5e5b4d-b36e-4d36-86c8-fe4447063f93


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Open in Devin Review

Comment thread .github/workflows/ci.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant