Repository navigation
gap_wave_ledger: --dir-style catalog__layer - #106
Merged
Merged
Conversation
…_id> receipt dirs Reads prefixed dirs, lets gap_refs omit layer_id (defaulted from the dir name) or be bare ints, and skips per-layer results.json. The default layout is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…and fail loudly on non-receipts Review by agent-lab-17 (the consumer): the first version silently skipped every one of its receipts. catalog__layer mode now reads gap_index + outcome receipts natively (settled/advanced/not_settled map to true/partially/false; deferred and covered_elsewhere carry no settling credit but stay visible as their own status), defaults a missing source_revision to the crosswalk's and flags it, skips only results.json, _index.json and preregistration*.json, and raises on any other JSON that is not a receipt. Verified end to end on copies of agent-lab-17's 113 receipts across 13 layer dirs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ct hash test The hash test parsed every JSON under the wave, including empty raw captures in subdirectories (agent-lab-17 review). It now uses iter_receipt_files, the same selector load_receipts uses: top-level *.json per layer dir, minus results.json, _index.json and preregistration*.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins
added a commit
that referenced
this pull request
Sep 23, 2026
…immutable releases, target ruleset (#108) * Close the catalog's GitHub automation: OSV/zizmor-online scans, gates, immutable releases, target ruleset Add security-scan.yml: an osv-scanner job (OSV-Scanner 2.6.0, checksum-verified) over every tracked lockfile in .github/osv-scanner-lockfiles.json with --no-resolve, failing on unignored vulnerabilities and uploading SARIF off PRs, plus a zizmor-online SARIF job. A unittest fails when a tracked lockfile is missing from the inventory or an ignore lacks a <=90-day expiry. Gate dependency review at high (warn-only removed) and grype at --fail-on high with a reviewed, empty .grype.yaml; upload Scorecard SARIF with a job-scoped security-events write; add a 7-day Dependabot cooldown. publish-catalog.yml gains a tag-only release job (contents: write only) that re-checks the attested digests and creates the immutable release with both files attached at creation. .github/main-ruleset.json becomes the target (dependency-review and osv-scanner required, strict checks, signatures, CodeQL code_scanning, squash only); the tag rulesets match live 23829417 and 23859358. Record the evidence, the CodeQL-vs-zizmor comparison on 168a3a8 and the superseded decisions in docs/decisions/2026-09-22-github-automation-closure.md; update SECURITY.md, automation.json, the docs, the regenerated verdicts/explorer and evidence hashes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop required_signatures from the target ruleset; gate .grype.yaml changes; fix stale gate docs A measured agent-lab run (2026-09-23) blocked PRs with unsigned branch commits under required_signatures even though GitHub signs the squash merge, so the target main ruleset leaves the rule out as keep-but-compare until every writer signs. supply-chain.yml now runs its grype gate when .grype.yaml changes, with a test. Scorecard, dependency-review and grype docs no longer call the new gates report-only, and the CodeQL default-setup row cites the re-read settings GET. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Resolve the catalog-automation review findings after rebasing on main - Rebase onto origin/main 8faca90 (#96, #99-#104, #106): take main's removal of docs/ecosystem/index.html, merge main's explorer build/attest/upload steps with the release job's digest outputs, and re-register manifest hashes with host_receipts.register_file. - OSV inventory: add a reasoned "excluded" list for the #101 grype positive-control fixture; the coverage test accepts only listed, fixture-scoped exclusions with an evidence path and still fails on any unlisted tracked lockfile. osv-scanner 2.6.0 exits 0 on the 37 listed files. - Target main ruleset: strict_required_status_checks_policy false (auto-merge without a merge queue would stall every open PR when main moves); required_signatures stays out; regression tests assert both. - automation.json: gating lanes move to security_gate_lanes with boolean required_check/target_required_check; fresh CodeQL default-setup GET cited. - foundation.json: restore ci-supply-chain lane gap text, replace stale automation.json line citations with JSON-path anchors at 92bb279; regenerate verdicts and the handbook section with build_verdicts. - Handbook automation summary and closure record updated (mlx branch dropped after #99, fixture alerts 7-15 dismissed and #105 closed, security updates kept on, strict decision, gap-ledger mapping). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Align merge-queue and osv-scanner catalog text with the strict-off target; record #104 CodeQL triage - automation.json merge-queue non-adoption no longer cites strict checks; it points at the strict-off decision (closure record section 10) with its overturn condition. - osv-scanner selection says "required in the target ruleset once applied" and names the 37 listed lockfiles, 2 covered manifests and 1 fixture exclusion. - Closure record section 2: the 10 first-analysis CodeQL alerts were resolved in #104, not left for owners. - Hashes re-registered in manifests/evidence.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep Dependabot security PRs off the grype positive-control fixture ignore: urllib3 on a pip entry scoped to the fixture directory (ignore applies to security updates; exclude-paths does not). Clarify that osv-scanner becomes a required check only after the target ruleset is applied. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Refresh evidence hashes after rebasing onto #95 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Fix the OSV SARIF path under bash -e; keep the zizmor write token away from the analyzer shell: bash implies -e, so a findings exit ended the OSV step before the SARIF run (reproduced; found by an independent-implementation comparison and the Codex cross-family review). zizmor now runs read-only and a tool-free upload job holds security-events: write. Tests cover both, plus OSV PackageOverrides and grype review-by dates. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
--dir-style catalog__layertotools/sota-convergence/gap_wave_ledger.pyso the other wave-2 session (agent-lab-17) can build its ledger fromevidence/artifacts/gap-wave2-20260923/<catalog>__<layer_id>/receipts:gap_refsmay omitlayer_id(it defaults from the dir name) or be bare ints;results.jsonis skipped.The default layout and the existing ledger are unchanged (
--checkpasses). A new test covers both styles. The full suite and validators pass, and gitleaks finds no leaks in the branch commits.🤖 Generated with Claude Code