Repository navigation
Upstream quality audit of the definitive manifest's foundation repositories - #596
seathatflowsinourveins wants to merge 4 commits into
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Cross-family read (GPT-6.1 Sol, max effort, read-only, clean detached checkout of BLOCKING findings: 4; NON-BLOCKING findings: 2.
Checks that passed:
Live comparison remains unverified: |
7b4f8ce to
0e30c3f
Compare
0e30c3f to
d781cd5
Compare
|
Repaired head ready for re-read (Claude session Head Target. The audit now covers the 56 GitHub repositories that #602's foundation rows name. It records the manifest's sha256, and Repairs for your four blocking and two non-blocking findings:
Review of the repair: an independent Opus 5.5 review found one more blocker, the 1000-suite ceiling. A fix round repaired it, and the observations were re-collected on 2026-10-02 at 21:40Z (530 requests, 0 fetch errors). Before merge: your re-read at Merge order: if #620 merges first, it changes the manifest, and this pull request needs a re-collection before its |
d781cd5 to
200d443
Compare
|
Update to my re-read request: #620 changed the definitive manifest at 07:58Z, so this audit was re-collected at 13:27Z on main |
…tories tools/sota-convergence/upstream_audit.py audits every GitHub repository that a foundation row of the definitive manifest names (evidence/artifacts/new-wsl-definitive-defaults-20261001/definitive-manifest.json, the install record merged in #602): maintenance, release currency, release provenance, published security advisories, check runs on the default-branch head, license and the OpenSSF Scorecard that deps.dev publishes. It replaces the final-catalog target of the first revision, which stacked on #595, and repairs that revision's review findings. - Targets: every GitHub URL in a foundation row's repository, former default or arms (a field can join several with " ; "), plus owner/name text naming a finalist in a split or measurement row. Trading rows stay out; non-GitHub URLs and split or measurement rows without a finalist repository are listed as not audited. A role is the slot, its state (pinned when empty), whether the row installs it (scripts/build_new_wsl_handbook.py's rule) and where the row names it. - The observations and the audit record the manifest's sha256. --check fails when the manifest, its role table or its not-audited list differs from the one recorded at collection, and prints role drift: added, removed, changed roles. - Check runs and advisories are read to the last page (gh api --paginate --slurp) and record observed, total and complete; an incomplete collection never reports failing 0 or an advisory count of 0. - A failed attestation request without an attested asset makes provenance unknown, never no_provenance; the review's reproduction and mixed cases are tests. - Each queried asset's name, digest and attestation answer, and every request path and deps.dev URL with its outcome, are recorded per repository; a failure keeps only its HTTP status. The collector checks the rate-limit budget first and retries rate limits, 5xx and timeouts. - Staleness and release age compare timestamps with the cutoff as practice_references.py does; the boundary test covers exactly 90 days, one second less and 90 days 12 hours. - validate.yml runs --check. blind_checkout withholds the audit's output, its observations and its decision record (tested). The record, docs/decisions/2026-10-02-upstream-audit.md, carries a results section generated from the audit (--results) and tested against it. - Observations collected live on 2026-10-02 (56 repositories, 0 fetch errors, 0 incomplete collections) and the audit built from them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…lect the upstream audit
GitHub's "List check runs for a Git reference" lists only the runs of the 1000 most recent check suites when a
ref carries more, and its total_count then describes that truncated set. The audit took that total as the whole
set, so actions/attest (more than 1600 check suites on its head) was recorded as 1000 of 1000 runs read, complete,
failing 0.
- upstream_audit.py reads the head's suite count from commits/{sha}/check-suites after the runs. A collection is
complete only at 1000 suites or fewer, every listed run read and one unchanged total_count across the pages,
whose distinct values the observation now keeps. audit_row rechecks this from the recorded counts, so an
observation without them is incomplete. A failed suite request leaves the collection incomplete.
- The advisory observation drops its 'total', which only repeated the observed count (the endpoint reports none).
- The decision record lists each incomplete check-run collection with its reason, and its method, limits,
alternatives and sources state the limit.
- Observations re-collected live and the audit rebuilt; the record's results are regenerated from it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#620 changed the manifest (three repositories added to the targets, a new role table and not-audited list), so --check failed against main. Re-collected 2026-10-03T13:27Z: 59 repositories, 556 requests, 0 fetch errors; the record's results block regenerated from --results. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
200d443 to
7221607
Compare
|
Closed with a record by the PR triage of 2026-10-07 (the command center's ruling, item review-ns2604-coop-20261007T023012Z (the command center's PR-triage ruling of 2026-10-07; proposal by github-ci-finalize, triage-20261007.json)). Not merged; the branch What it holds: docs/decisions/2026-10-02-upstream-audit.md; catalogs/foundation/upstream-audit-20261002.json; evidence/artifacts/upstream-audit-20261002/observations.json; tools/sota-convergence/upstream_audit.py with tests/test_upstream_audit.py; tools/sota-convergence/blind_checkout.py and .github/workflows/validate.yml (modified) Superseded by: Overtaken by the NativeStack2604 install from later manifest versions: the audit pins the definitive manifest by sha256 (observed 2026-10-03T13:27:14Z), and that manifest changed in 10 later main commits from 54a96ff (#647) to 41b65ac (#723), including 4c89741 (#704) and 1796303 (#713, owner rows on the repository-quality rule, docs/decisions/2026-10-04-repository-quality-rule.md:30). (confidence: low: inference; no landed record cites or replaces the audit, and its tool is not on main) Reopen trigger: A pre-install upstream audit (provenance, advisories, check runs, Scorecard) is required for the current definitive manifest: re-run tools/sota-convergence/upstream_audit.py from this head against it. Reopen with |
Scope
tools/sota-convergence/upstream_audit.py, an information-only audit of the 59 GitHub repositories that the foundation rows of the definitive manifest (Definitive manifest, next version: the blind GPT round combined with the Claude record (one job per row, 31 definitive, 4 split) #602,evidence/artifacts/new-wsl-definitive-defaults-20261001/definitive-manifest.json) name, with its live observations, the built auditcatalogs/foundation/upstream-audit-20261002.json, a decision record, tests and a--checkstep invalidate.yml. No default, state or slot changes through it.4ced2923(main after Layer consensus of 2026-10-02 in the manifest, plan and handbook (89 slots), and the WSL scope of the two-host decision #620 and AGENTS.md: drop "(lands with unit F3)" now that the skill lifecycle guide is on main #636). Re-collected on 2026-10-03 at 13:27Z after Layer consensus of 2026-10-02 in the manifest, plan and handbook (89 slots), and the WSL scope of the two-host decision #620 changed the manifest. This pull request no longer stacks on Final catalog of 2026-10-01: the blind GPT-6.1 Sol half of the clean-install selection and its comparison with the Claude record #595: it was rebased onto main and retargeted from Final catalog of 2026-10-01: the blind GPT-6.1 Sol half of the clean-install selection and its comparison with the Claude record #595's final catalog to the definitive manifest, after the GPT-6.1 Sol read of7b4f8ce6(four blocking, two non-blocking findings, all repaired) and an independent Opus review of the repair (one more blocker, GitHub's 1000-check-suite limit, repaired).lane:foundationtools/sota-convergence/upstream_audit.py,tests/test_upstream_audit.py,catalogs/foundation/upstream-audit-20261002.json,evidence/artifacts/upstream-audit-20261002/observations.json,docs/decisions/2026-10-02-upstream-audit.md,tools/sota-convergence/blind_checkout.py(threeREMOVE_GLOBSentries),.github/workflows/validate.yml(one step) andmanifests/evidence.json(registration, last commit).What the audit records for each repository: maintenance (default-branch head), release currency, release provenance (name and sha256 digest of up to five queried digest-carrying assets of the latest release, with their GitHub attestation count), published security advisories (every page), check runs on the default-branch head (every page, plus the head's check-suite count), license and the OpenSSF Scorecard that deps.dev publishes, and every request made with its outcome. A collection that errors or stops short is listed as incomplete and never reports a negative fact. A head above 1000 check suites is recorded incomplete, because GitHub then lists only the runs of the 1000 most recent suites. Targets come from the manifest's foundation rows only (trading rows stay out);
--checkfails when the manifest's sha256, role table or not-audited list changes without re-collection.SOTA sources
digest), artifact attestations, repository security advisories, check runs and check suites; the 1000-suite limit of "List check runs for a Git reference" (https://docs.github.com/en/rest/checks/runs#list-check-runs-for-a-git-reference) and the suite count of "List check suites for a Git reference" (https://docs.github.com/en/rest/checks/suites#list-check-suites-for-a-git-reference).gh api --paginate --slurp(https://cli.github.com/manual/gh_api), cli/cli v2.102.0 (https://github.com/cli/cli/releases/tag/v2.102.0) on the collecting host.tools/sota-convergence/github_freshness.py(thegh apicontract),tools/sota-convergence/practice_references.py(the 90-day cutoff comparison) andscripts/build_new_wsl_handbook.py(the rule for which rows install a repository).Evidence-class table
local_integrationpython3 -B tools/sota-convergence/upstream_audit.py --collect --workers 4(observations collected 2026-10-03T13:27Z, 556 requests, 0 fetch errors)anthropics/claude-code, 1343 check suites)local_integrationpython3 -B tools/sota-convergence/upstream_audit.py --build;--checkpassessource_reviewactions/attest's head carried 1606 suites (gh api repos/actions/attest/commits/a0eb68d5.../check-suites --jq .total_count, 21:28Z); in the re-collection of 2026-10-03 the incomplete head isanthropics/claude-code(1343 suites)syntheticpython3 -m unittest tests.test_upstream_audit tests.test_blind_checkout(71 tests)Local commands run
Decision record
docs/decisions/2026-10-02-upstream-audit.md: method, limits (provenance is sampled from the first five digest-carrying assets, sono_provenancemeans "no GitHub attestation on the queried assets", not "unsigned"), alternatives (local Scorecard runs, folding into the manifest generator, reading every suite's runs, the #595 final catalog as target) and the overturn condition (re-collect when the definitive manifest changes, before any new-host install wave, or when a flagged repository publishes a fix).Host evidence
Not applicable: no file under
evidence/hosts/changes.Checklist
version comment (no floating tags). (No action added; one
run:step.)permissions: contents: read(or a narrower, explicitly justified addition). (
validate.ymlpermissions unchanged.)added without a documented owner.
moved or overwritten).
🤖 Generated with Claude Code