Repository navigation
ci: prepare prospective decision metadata with pinned PyYAML - #745
seathatflowsinourveins wants to merge 2 commits into
Conversation
664c428 to
2579f7c
Compare
|
Dependency limit exceeded — report not shown. This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report. Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard. Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account. |
2579f7c to
bb3832b
Compare
|
Closed with a record by the PR triage of 2026-10-07 (the command center's ruling, item review-ns2604-coop-20261007T023012Z (the command center's PR-triage ruling of 2026-10-07; proposal by github-ci-finalize, triage-20261007.json)). Not merged; the branch What it holds: docs/decisions/2026-10-05-ci-decision-metadata.md; docs/decisions/decision-metadata-index.json; scripts/decision_metadata.py with tests/test_decision_metadata.py; evidence/artifacts/github-ci-r5-20261005.json; scripts/validate.py and scripts/currency_due.py (modified); .github/requirements-ci.txt (PyYAML 6.0.3, hash-pinned) Superseded by: not superseded; unprioritized under the 2026-10-07 PR triage (confidence: high that nothing supersedes it: scripts/decision_metadata.py and the index are absent on main, and validate.py, currency_due.py and requirements-ci.txt are unchanged since its base) Reopen trigger: The repository adopts machine-readable MADR metadata for new decision records. Reopen with |
Scope
Prepare prospective MADR metadata validation for decision paths introduced after R5's actual main landing tree, a deterministic index, and advisory review-date reporting. Add PyYAML 6.0.3 through the existing Linux CI binary-only, hash-locked requirements installer after #735 landed.
Partial draft: the validate.yml caller remains #706-owned. The decision documents the one-line opt-in and full-history prerequisite after R5 lands. Default integrity and arbitrary-file scanning remain stdlib-only. This draft changes no workflow and claims no hosted metadata enforcement. It stays draft for the command center's Claude read.
1796303f957c522e78b92667e553c06840fae3a2(current-main rebase; includes Adaptive paper engine: exchange-calendars XNYS as the primary session calendar (never-rebuild), overnight-cap fail-open fixed #735 merge095d4fad)lane:foundationSOTA sources
ba1cc08a..., CP3130f29edc4..., CP314c458b6d0...; full SHA256 values in the lock and receipt.Evidence-class table
Local commands run
Private paths are sanitized; actual commands/results are retained in the lane record and compact receipt. The 199 local tests and integrity check are fresh on main1796303f. Pip and unchanged upstream parser evidence are reused from the prior receipt with matching input hashes; no repeat install or parser execution.
Failed attempts
The native OpenHands SDK builder job
ns2604-ci-r5-write-20261005started at 2026-10-05T14:03:00Z and ended at 2026-10-05T14:28:00Z after its 1,500-second (25-minute) limit. Preparation exited 0; the native start/wait command exited 1, and independent service observation reportedResult=timeout. The attempt is UNFINISHED: no run report, no repository edits, and requests and usage UNKNOWN.ExecMainStatus=0does not establish completion. Native journal and frozen source inputs remain retained privately. No SDK retry.The lane root's cited-source implementation and later tests are separate integration/synthetic evidence and do not stand in for the failed SDK attempt or unchanged upstream tests. This follows the acceptance evidence policy and user A18. Exact structured attempt metadata and earlier failed test conditions/corrections remain in
evidence/artifacts/github-ci-r5-20261005.json. The earlier #735 rebase conflicted only in the registry; the current-main rebase was clean. Main's registry copy was taken and this branch's evidence re-registered both times, without a hand merge.Decision record
docs/decisions/2026-10-05-ci-decision-metadata.md names the alternatives, actual-landing baseline, non-success pending/unknown states, owner wiring, source correction and overturn conditions. Receipt: evidence/artifacts/github-ci-r5-20261005.json.
Host evidence
No evidence/hosts or platform-status change. Native pip performed a dry-run only; parser upstream acceptance is reused historical evidence with matching inputs.
Checklist