Skip to content

gap_wave_ledger: --dir-style catalog__layer - #106

Merged
seathatflowsinourveins merged 4 commits into
mainfrom
claude/gap-wave-ledger-dir-style
Sep 23, 2026
Merged

seathatflowsinourveins merged 4 commits into
mainfrom
claude/gap-wave-ledger-dir-style

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Adds --dir-style catalog__layer to tools/sota-convergence/gap_wave_ledger.py so the other wave-2 session (agent-lab-17) can build its ledger from evidence/artifacts/gap-wave2-20260923/<catalog>__<layer_id>/ receipts:

  • prefixed dirs;
  • gap_refs may omit layer_id (it defaults from the dir name) or be bare ints;
  • per-layer results.json is skipped.

The default layout and the existing ledger are unchanged (--check passes). A new test covers both styles. The full suite and validators pass, and gitleaks finds no leaks in the branch commits.

🤖 Generated with Claude Code

…_id> receipt dirs

Reads prefixed dirs, lets gap_refs omit layer_id (defaulted from the dir name) or be bare ints, and skips per-layer results.json. The default layout is unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…and fail loudly on non-receipts

Review by agent-lab-17 (the consumer): the first version silently skipped every one of its receipts. catalog__layer mode now reads gap_index + outcome receipts natively (settled/advanced/not_settled map to true/partially/false; deferred and covered_elsewhere carry no settling credit but stay visible as their own status), defaults a missing source_revision to the crosswalk's and flags it, skips only results.json, _index.json and preregistration*.json, and raises on any other JSON that is not a receipt. Verified end to end on copies of agent-lab-17's 113 receipts across 13 layer dirs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ct hash test

The hash test parsed every JSON under the wave, including empty raw captures in subdirectories (agent-lab-17 review). It now uses iter_receipt_files, the same selector load_receipts uses: top-level *.json per layer dir, minus results.json, _index.json and preregistration*.json.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins merged commit 8faca90 into main Sep 23, 2026
13 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the claude/gap-wave-ledger-dir-style branch September 23, 2026 04:53
seathatflowsinourveins added a commit that referenced this pull request Sep 23, 2026
…immutable releases, target ruleset (#108)

* Close the catalog's GitHub automation: OSV/zizmor-online scans, gates, immutable releases, target ruleset

Add security-scan.yml: an osv-scanner job (OSV-Scanner 2.6.0, checksum-verified)
over every tracked lockfile in .github/osv-scanner-lockfiles.json with
--no-resolve, failing on unignored vulnerabilities and uploading SARIF off PRs,
plus a zizmor-online SARIF job. A unittest fails when a tracked lockfile is
missing from the inventory or an ignore lacks a <=90-day expiry.

Gate dependency review at high (warn-only removed) and grype at --fail-on high
with a reviewed, empty .grype.yaml; upload Scorecard SARIF with a job-scoped
security-events write; add a 7-day Dependabot cooldown. publish-catalog.yml
gains a tag-only release job (contents: write only) that re-checks the attested
digests and creates the immutable release with both files attached at creation.

.github/main-ruleset.json becomes the target (dependency-review and osv-scanner
required, strict checks, signatures, CodeQL code_scanning, squash only); the
tag rulesets match live 23829417 and 23859358. Record the evidence, the
CodeQL-vs-zizmor comparison on 168a3a8 and the superseded decisions in
docs/decisions/2026-09-22-github-automation-closure.md; update SECURITY.md,
automation.json, the docs, the regenerated verdicts/explorer and evidence hashes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop required_signatures from the target ruleset; gate .grype.yaml changes; fix stale gate docs

A measured agent-lab run (2026-09-23) blocked PRs with unsigned branch
commits under required_signatures even though GitHub signs the squash merge,
so the target main ruleset leaves the rule out as keep-but-compare until every
writer signs. supply-chain.yml now runs its grype gate when .grype.yaml
changes, with a test. Scorecard, dependency-review and grype docs no longer
call the new gates report-only, and the CodeQL default-setup row cites the
re-read settings GET.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Resolve the catalog-automation review findings after rebasing on main

- Rebase onto origin/main 8faca90 (#96, #99-#104, #106): take main's removal of
  docs/ecosystem/index.html, merge main's explorer build/attest/upload steps
  with the release job's digest outputs, and re-register manifest hashes
  with host_receipts.register_file.
- OSV inventory: add a reasoned "excluded" list for the #101 grype
  positive-control fixture; the coverage test accepts only listed,
  fixture-scoped exclusions with an evidence path and still fails on any
  unlisted tracked lockfile. osv-scanner 2.6.0 exits 0 on the 37 listed files.
- Target main ruleset: strict_required_status_checks_policy false (auto-merge
  without a merge queue would stall every open PR when main moves);
  required_signatures stays out; regression tests assert both.
- automation.json: gating lanes move to security_gate_lanes with boolean
  required_check/target_required_check; fresh CodeQL default-setup GET cited.
- foundation.json: restore ci-supply-chain lane gap text, replace stale
  automation.json line citations with JSON-path anchors at 92bb279;
  regenerate verdicts and the handbook section with build_verdicts.
- Handbook automation summary and closure record updated (mlx branch dropped
  after #99, fixture alerts 7-15 dismissed and #105 closed, security updates
  kept on, strict decision, gap-ledger mapping).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Align merge-queue and osv-scanner catalog text with the strict-off target; record #104 CodeQL triage

- automation.json merge-queue non-adoption no longer cites strict checks;
  it points at the strict-off decision (closure record section 10) with its
  overturn condition.
- osv-scanner selection says "required in the target ruleset once applied"
  and names the 37 listed lockfiles, 2 covered manifests and 1 fixture
  exclusion.
- Closure record section 2: the 10 first-analysis CodeQL alerts were
  resolved in #104, not left for owners.
- Hashes re-registered in manifests/evidence.json.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep Dependabot security PRs off the grype positive-control fixture

ignore: urllib3 on a pip entry scoped to the fixture directory (ignore applies to
security updates; exclude-paths does not). Clarify that osv-scanner becomes a
required check only after the target ruleset is applied.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Refresh evidence hashes after rebasing onto #95

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix the OSV SARIF path under bash -e; keep the zizmor write token away from the analyzer

shell: bash implies -e, so a findings exit ended the OSV step before the SARIF run
(reproduced; found by an independent-implementation comparison and the Codex
cross-family review). zizmor now runs read-only and a tool-free upload job holds
security-events: write. Tests cover both, plus OSV PackageOverrides and grype
review-by dates.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant