Skip to content

chore(metadata): add public-surface desired state wave 2 - #1639

Draft
seonghobae wants to merge 273 commits into
mainfrom
chore/metadata-public-surface-wave-2-v2
Draft

chore(metadata): add public-surface desired state wave 2#1639
seonghobae wants to merge 273 commits into
mainfrom
chore/metadata-public-surface-wave-2-v2

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Outcome

Extend the organization-owned declarative repository metadata catalog for public repositories whose repository-facing source work is already active, rather than leaving descriptions, topics, DeepWiki intent, homepage intent, and Pages intent as one-off observations.

config/repository-metadata.json remains the desired-state authority for the exact repository set and preserves exact repository-name casing. The companion tests keep description constraints, topic normalization, DeepWiki URL formation, homepage safety, Pages intent, and protected-source prerequisites fail closed.

Coordination / prerequisites

This PR intentionally does not duplicate repository-owned README or Pages-source writers. The manifest currently contains 31 exact-cased repositories. Fresh protected-default-branch inspection found both the exact DeepWiki badge and docs/index.md for only five: ThreadWeave, EgressWeave, psychometrics-commons, noema, and Veilpick. The other 26 remain source-incomplete on their protected branches.

RankWeave#40 carries both prerequisites on exact head 5f9c04bc7249395f9b7c15714cb2cfdfd917f509. pingora-gateway#1 likewise carries the exact DeepWiki badge and docs/index.md on 0da81a93f93e869c15bb7d34c55fc87479d16522; its desired state replaces the repository's eventual public “scaffold only” classification with the implemented candidate product boundary. Both are open-PR evidence and do not become protected-source prerequisites until ordinary merge. A desired-state declaration must not cause Pages to target source that has not integrated.

j-planner remains deliberately excluded from central legacy-docs Pages mutation because its working live site is rooted on the gh-pages branch; reconfiguring a verified working site without first extending the reconciler's source-path model would be destructive.

Control-plane boundary

Protected .github/main contains the least-privilege CWL_REPOSITORY_METADATA_TOKEN wiring from #1625. Live description/topic/homepage/Pages mutations remain blocked by external protected-environment/GitHub App provisioning tracked in #1579. This PR does not claim live convergence; after source prerequisites and credential provisioning, the existing reconcile workflow must apply and re-read exact repository settings plus published HTTPS Pages content before completion.

Current protected-base reconciliation — 2026-09-08

Protected main is exact 7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db. The branch had diverged at 22 ahead / 248 behind. GitHub generated conflict-free synthetic merge 37135edc61c6fab8909dc40c417342822a6c04c3 with parents protected main@7fd571db… and prior branch head c74d840f…; the writer branch was advanced to it with a non-force fast-forward.

The branch remains a non-force descendant of that reconciliation, and the effective protected-base delta remains limited to config/repository-metadata.json, scripts/ci/reconcile_repository_metadata.py, and tests/test_repository_metadata_reconciliation.py. Test-only 9f636ecc4c321d453d729d753bd64ddd70bad231 first required the exact pingora-gateway inventory entry; 6a8e8b2c279779ec7516a67ee96a02c7b9048468 then adds its reviewed desired state. GitHub reports this Draft mechanically mergeable against main; mechanical mergeability is not merge authorization. No force-push, destructive rebase, unrelated protected-main rollback, or target-repository lifecycle mutation was used.

Exact-head status

Current exact head is 6a8e8b2c279779ec7516a67ee96a02c7b9048468. Fresh same-head Repository Metadata Reconcile 34195535498, CodeQL PR 34195535453, Security Scan 34195535497, SAST Semgrep 34195535430, and Python Security 34195535547 are queued. These current-head states supersede all predecessor run IDs.

Keep this PR Draft because protected-source prerequisites and the external settings credential path are materially incomplete. Queued checks or absent independent approval alone are not the Draft rationale; they separately withhold merge authority. No branch protection, required check, review requirement, credential, secret, release, target-repository lifecycle, or target-repository source file is changed here. A manifest/workflow commit is not live metadata or Pages publication evidence.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Reconciliation pass found a concrete contract drift on this Draft head: config/repository-metadata.json adds the five wave-2 repositories, but inherited tests/test_repository_metadata_reconciliation.py::test_metadata_manifest_declares_exact_casing_and_public_surfaces still asserts the pre-wave exact repository set. That test will reject this manifest once the pytest lane executes. Please update the exact expected set/topics in the same writer before moving this PR out of Draft; do not weaken/remove the exact-set assertion. Current Actions for this head are still queued, so I am leaving the PR Draft and continuing independent repository work rather than treating queue state as completion.

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite labels Sep 1, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal found a control-plane gap that belongs in this desired-state lane (or a non-conflicting direct successor), not in a leaf one-off settings edit: the current repository-metadata.json schema and scripts/ci/reconcile_repository_metadata.py reconcile description/topics/DeepWiki/Pages but do not declare, apply, or verify repository homepage URLs. ContextualWisdomLab/newsdom-api is a concrete canary: live REST currently reports Pages enabled but homepage=https://contextwisdomlab.github.io/newsdom-api/ (missing ual), while public-surface PR #782 corrects the source-owned MkDocs namespace and explicitly leaves repository homepage convergence to the owner metadata path.

Please extend the reviewed desired state with an optional homepage field and fail-closed validation, apply it in the same single repository PATCH as description when either drifts, and verify live homepage equality after apply. Preserve null/unset as an explicit desired state rather than silently inventing a Pages URL, and add regression coverage for malformed/non-HTTPS/internal-only homepage values plus a no-op steady state. Do not make this a branch-selected/manual privileged path or bypass the dedicated CWL_REPOSITORY_METADATA_TOKEN contract. The current live connector does not expose this settings mutation directly, so owner-side API reconciliation is the correct capability boundary.

Copy link
Copy Markdown
Contributor Author

Additional public-surface evidence for the next metadata reconciliation pass: ContextualWisdomLab/g7 is a maintained fork of gnuboard/g7; live description is currently only 그누보드7, live topics are empty, homepage is https://sir.kr, and has_pages=false. A leaf badge writer is now open as g7#2; its effective diff is exactly one exact-cased DeepWiki badge line and must reach protected main before declaring deepwiki: true because the reconciler fails closed on missing default-branch badges. Once that prerequisite lands, recommended bounded settings desired state is a concise CMS/e-commerce description and evidence-backed topics such as cms, ecommerce, gnuboard, laravel, php, reactjs, typescript, and tailwindcss; no Pages publication intent is recommended for this upstream-derived fork absent a distinct ContextualWisdomLab-owned docs surface. I am not modifying this Draft writer's manifest while it is stale/non-mergeable.

Copy link
Copy Markdown
Contributor Author

Public-surface traversal found three additional source-complete candidates for this declarative metadata lane once their repository-owned source prerequisites are integrated: ELUNVERA (existing #2 carries the exact-cased DeepWiki badge and docs/index.md, but explicitly reports live Pages still disabled), EmbedRelay (existing #4 carries the buyer/integrator baseline and docs/index.md; publication remains unclaimed), and Orgmetra (existing #51 is the canonical protected-product-truth writer and is currently blocked on central Dependency Review/OpenCode/Strix evidence). Please extend this existing metadata writer rather than create a competing one when each prerequisite is present on the protected default branch. Keep this PR Draft/fail-closed until the reconciler can verify each badge/source on protected truth; do not use source-branch presence as live Pages evidence. Current manifest already contains ConceptWeave, PolicyWeave, and supply-chain-control-plane, so those should remain owned here rather than receiving another desired-state PR.

Copy link
Copy Markdown
Contributor Author

Future public-surface candidate discovered during org traversal: ContextualWisdomLab/OmniRoute currently exposes customer-facing description Personal fork of diegosouzapw/OmniRoute, ..., which violates the public-description rule by surfacing an ownership caveat. It is a public MIT fork, default release/v3.8.50, homepage https://omniroute.online, has_pages=false, topics ai-coding, api, fork, gateway, llm-orchestration, typescript, and currently has no open PR.

Desired settings after a source prerequisite lands: concise product responsibility such as AI gateway for routing coding agents across LLM providers with automatic fallback., preserve the useful existing topics (the fork provenance topic is fine as classification), preserve the upstream product homepage, and keep Pages disabled unless this fork develops a distinct organization-owned docs surface. The root README is a very large upstream-authored document and currently has no CWL DeepWiki badge; do not overwrite it wholesale from the central metadata lane. Coordinate a minimal exact-cased badge writer first, then add OmniRoute declaratively here or in the next successor metadata wave. No competing settings PR was created.

Copy link
Copy Markdown
Contributor Author

Additional source-complete metadata candidate discovered during this traversal: ContextualWisdomLab/noema already has the exact-cased DeepWiki badge and a product-first README on protected main, plus a protected docs/index.md that documents product responsibility, onboarding, API, deployment, runbook, threat model, traceability, releases, and gap status. The live repository description is still the narrower implementation-centric Noema review bot: OIDC-scoped GitHub App token broker for ContextualWisdomLab LLM pull request reviews., while current topics are bot, code-review, github-app, llm, oidc, python, typescript, homepage is null, and has_pages=false.

When this metadata writer next moves after the current five-prerequisite wave, add noema declaratively rather than opening a competing settings PR. A current customer-facing description consistent with protected product docs is Noema — evidence-producing credential and maintenance control plane for governed GitHub automation. Preserve useful current topics and add only bounded classification such as control-plane, security, and contextualwisdomlab; declare DeepWiki + Pages intent because both protected-source prerequisites are already present. Live completion still requires #1579 credential provisioning, settings apply/re-read, Pages deployment, and HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal identified three repositories for a later declarative metadata wave once their source prerequisites are on the protected default branch. Please do not add them to this Draft head until those prerequisites integrate, but keep them on the desired-state queue rather than solving settings ad hoc:

  • codec-carver: current description is already concise/current (긴 녹음을 메타데이터를 보존한 FLAC/Opus 조각으로 안전하게 변환하는 Python CLI.); preserve useful topics audio, audio-analysis, audio-conversion, cli, flac, metadata, opus, python, rust; add the organization ecosystem topic only if consistent with the manifest taxonomy; deepwiki: true; Pages intent should become true after codec-carver#516 (docs/index.md) and the required README badge are protected truth.
  • seedream_evasepic: current description and domain topics (claude-code-plugin, k-beauty, marketing, prompt-engineering, seedance, seedream) are already useful. It is an organization-maintained fork whose README is the primary public surface; seedream_evasepic#389 adds the exact DeepWiki badge. Treat DeepWiki intent as true but do not create a duplicate Pages site merely because has_pages=false; preserve the upstream-derived product boundary.
  • litellm-patched-proxy: current description is already product-aligned (Downstream LiteLLM proxy image with bounded health-check history queries and maintained production patches) and current topics (docker, litellm, llm, ops, sbom, security) are useful. litellm-patched-proxy#2 supplies the exact README DeepWiki badge plus docs/index.md; after protected integration, declare DeepWiki + Pages intent and converge live settings through the existing credentialed reconciler.

Live Pages/settings are still not claimed from these source PRs; completion remains protected integration + reconcile apply + REST/HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Two additional desired-state candidates should enter a later manifest wave only after their protected source prerequisites integrate:

  • pg-llm-batch: simplify the implementation-heavy live description to PostgreSQL-backed LLM batch engine for token-aware preparation, durable lifecycle state, and OpenAI-compatible batch delivery. Preserve useful existing topics (batch-processing, cli, litellm, llm, postgresql, python, token-usage) and add only the normal bounded ecosystem-role topic if that remains manifest policy. After pg-llm-batch#321 and the required exact DeepWiki source are protected truth, declare DeepWiki + Pages intent and verify live apply.
  • inkspan: current live description is narrower than the protected README's current responsibility. Suggested concise product wording: Inkspan — modular rich-text authoring, collaboration, persistence evidence, safe serialization, and Office rendering for applications and AI systems. Preserve the existing useful topics (collaborative-editing, markdown-editor, office-documents, prosemirror, react, tiptap, typescript, wysiwyg-editor). After inkspan#396 and required exact DeepWiki source are protected truth, declare DeepWiki + Pages intent and verify live apply.

Neither source PR is live Pages evidence; settings completion remains reconcile apply plus REST/HTTPS verification.

Copy link
Copy Markdown
Contributor Author

Fresh metadata findings for later declarative reconciliation after protected source integration:

  • argos: replace the ownership-caveat live description Fork of vibemafiaclub/argos: ... with concise product wording such as Argos — team analytics for Claude Code and Codex usage, skills, sessions, and token consumption. Preserve homepage https://argos-ai.xyz and useful topics analytics, claude-code, codex, token-usage, typescript; remove generic fork from the normalized customer-facing taxonomy and add the normal ContextualWisdomLab ecosystem role if policy permits. argos#555 adds the exact DeepWiki badge and moves maintainer-only harness instructions out of README. Because Argos already has a dedicated hosted product site, Pages intent should remain false unless a distinct docs-site need emerges; do not publish duplicate Pages solely from has_pages=false.
  • hyosung-itx-slogan-brief: current description and bounded topics (brief, hyosung, marketing, slogan) are already appropriate. #8 supplies the exact README DeepWiki badge. This finite research/deliverable repository does not need a duplicate Pages site; preserve Pages intent false while allowing DeepWiki intent after protected integration.

Do not treat either source branch as live settings completion; reconcile only after protected truth and verify the resulting REST/public surface.

Copy link
Copy Markdown
Contributor Author

Fresh live-description audit found one remaining unrecorded ownership-caveat repository: vooster still exposes Fork of jesoos/vooster: 사람과 AI가 함께 제품 행동·유스케이스를 관리하는 vspec 도구 (Fastify API + Prisma + oclif CLI). in the customer-facing repository description. Existing canonical public-surface PR vooster#42 already owns the README/DeepWiki/docs source lane, so do not create a competing writer.

After that protected prerequisite integrates, reconcile vooster declaratively with concise product wording such as Vooster — collaborative product behavior and use-case specification tooling for human and AI teams. Preserve homepage https://v2.vooster.ai and useful topics ai-collaboration, cli, product-management, typescript, vspec; drop generic fork from the normalized customer-facing topic set and add the normal ContextualWisdomLab ecosystem-role topic only if manifest policy remains consistent. Keep Pages intent false while the dedicated product site remains the primary hosted surface unless a distinct CWL docs site is intentionally introduced. Verify live REST after apply; source integration alone is not completion.

Copy link
Copy Markdown
Contributor Author

Maintained-fork public-surface wave (declarative settings after each protected DeepWiki prerequisite integrates):

  • html4tree: current description is already concise/current (html4tree generates index.html files based on a file directory tree. Think Apache mod_autoindex.); preserve topics autoindex, file-tree, index-generator, kotlin, static-site; canonical html4tree#596 owns the exact README DeepWiki badge. Keep Pages false because this maintained utility fork has no distinct hosted docs surface that warrants duplication.
  • nonnest2: current Korean description already states its Vuong-test/non-nested model-comparison role; preserve topics model-comparison, psychometrics, r-package, statistics, vuong-test; canonical nonnest2#115 owns the exact README DeepWiki badge. Keep Pages false unless a distinct CWL documentation surface appears.
  • graphify: current upstream product site/README are the primary hosted surfaces; graphify#1 adds a small organization-owned exact DeepWiki surface without rewriting upstream docs. Preserve the dedicated Graphify product homepage and useful upstream/domain topics. Keep Pages false rather than publishing a duplicate site.

For all three, provenance/fork status remains visible through GitHub's native fork relationship and architecture/docs where needed; customer-facing description/topic normalization should focus on product responsibility. Source PR presence alone is not live settings completion.

@seonghobae seonghobae removed the enhancement New feature or request label Sep 2, 2026
@seonghobae seonghobae added the type: maintenance Maintenance, build, dependency, or operational upkeep label Sep 2, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal found three additional candidates for this existing desired-state lane; please absorb them here rather than opening a competing settings writer once their protected-branch prerequisites land:

  • g7: current live description is already concise/product-facing; preserve it or normalize to Gnuboard7 — Laravel 12 + React CMS and commerce platform maintained as a ContextualWisdomLab fork. Existing useful topics: cms, laravel, php, react, typescript, web-app; add bounded ecommerce, contextualwisdomlab if the taxonomy accepts them. has_pages=false. Canonical README writer is g7#3; I extended that same branch with the exact Ask DeepWiki badge for ContextualWisdomLab/g7. Do not reconcile Pages until that writer (and a docs/index.md prerequisite if Pages is intended) reaches the protected default branch.
  • html4tree: live description is the inherited implementation phrase html4tree generates index.html files based on a file directory tree. Think Apache mod_autoindex.; desired customer-facing wording can be html4tree — generate browsable static index pages from directory trees with a small Kotlin CLI. Preserve useful topics autoindex, file-tree, index-generator, kotlin, static-site; add cli, contextualwisdomlab if bounded. has_pages=false. Canonical writer html4tree#600 already has the exact DeepWiki badge, and I extended that same branch with docs/index.md as the Pages source prerequisite.
  • nonnest2: live description is already concise Korean product wording; preserve it or normalize to nonnest2 — Vuong-based distinguishability and relative-fit comparison for nested and non-nested statistical models in R. Preserve model-comparison, psychometrics, r-package, statistics, vuong-test; add contextualwisdomlab. has_pages=false. Canonical writer nonnest2#118 now carries the exact DeepWiki badge and a Pages-ready docs/index.md; its GPL-2/GPL-3 provenance/commercial boundary must remain explicit and must not be converted into a permissive-license claim.

All three are source-precondition coordination only: no live description/topic/Pages convergence is claimed until protected-default content is present and the existing reconciler can apply/re-read settings and published HTTPS content. The current PR is still Draft/conflicted, so this is intentionally coordination on the single existing owner lane rather than a duplicate metadata PR.

Copy link
Copy Markdown
Contributor Author

Follow-up to the earlier public-surface coordination: g7#3 has now been extended on the same canonical writer branch with docs/index.md in addition to the exact-cased Ask DeepWiki badge. The landing is product/onboarding/architecture/release-boundary focused and explicitly says source presence is not live Pages publication. Therefore the branch-level prerequisites for a later g7 Pages-intent reconciliation are now badge + Pages source; still do not claim or apply live Pages until that writer reaches the protected default branch and the existing settings reconciler can apply/re-read repository settings plus the published HTTPS endpoint.

Copy link
Copy Markdown
Contributor Author

Fresh source-ready candidate for this existing desired-state writer: noema now already satisfies the protected-source prerequisites on main (exact Ask DeepWiki badge in root README and a substantive docs/index.md public landing). Its live repository settings still expose the older narrow description Noema review bot: OIDC-scoped GitHub App token broker for ContextualWisdomLab LLM pull request reviews., homepage=null, has_pages=false, and topics bot, code-review, github-app, llm, oidc, python, typescript. Please absorb noema here rather than opening a competing settings PR: concise description Noema — evidence-producing credential and maintenance control plane for governed GitHub automation.; preserve useful existing topics while adding bounded role/ecosystem classification such as automation, control-plane, security, and contextualwisdomlab; deepwiki: true; pages: true. Update the exact-casing expected-set test with lowercase repository identity noema and preserve the existing fail-closed DeepWiki/Pages prerequisite tests. This is desired state only; do not claim live settings or Pages convergence until the protected owner-side reconciler applies and re-reads them.

Copy link
Copy Markdown
Contributor Author

Additional public-surface candidate for this existing desired-state writer: mightyETL. Live repository settings are currently description A microservices-based platform for real-time Change Data Capture (CDC) and bounded Extract-Transform-Load (ETL) operations., homepage empty, has_pages=false, with useful topics cdc, etl, java, kafka, microservices, postgresql, spring-boot. Canonical public-doc writer mightyETL#149 now owns the exact-cased Ask DeepWiki badge and, at new source commit a1dfca16a260e6f605d099499a064d7ddb330042, a substantive docs/index.md Pages landing. Keep mightyETL gated on #149 reaching protected develop; do not point Pages at unmerged source. After that prerequisite, preserve the current concise product description (or equivalent buyer-facing wording), preserve existing useful topics while adding only bounded taxonomy such as data-integration, change-data-capture, and contextualwisdomlab, and declare deepwiki: true / pages: true. Update exact-casing tests for mightyETL; source/manifest presence is not live convergence until the protected reconciler applies and re-reads settings plus published HTTPS content.

Copy link
Copy Markdown
Contributor Author

Current-base refresh evidence (2026-09-02): protected main is now 5c561a65cca3b925d533e4b40c5c3ac00f16524e. The previous PR head 49dc2f90dc1e81f1b3c7171449f56a5b3b0a5bea had fallen behind current protected main while still carrying only the intended config/repository-metadata.json and tests/test_repository_metadata_reconciliation.py deltas. I refreshed the writer non-destructively by creating merge head 4b9cba4adca32556649aa081f175ae5549ee6ae4 with the previous PR head and current protected main as parents, then advanced the branch with a normal non-force ref update. No force-push or destructive rebase was used. Fresh comparison is based on current protected main and still exposes only those two intended paths. Exact-head checks have re-triggered and several remain queued/pending, so this PR stays Draft and none of its desired-state entries are being treated as live description/topics/Pages convergence. Re-read exact-head checks, prerequisite protected README/docs sources, settings credential availability, and live repository/Pages state before promotion or merge.

Copy link
Copy Markdown
Contributor Author

Traversal reconciliation note (2026-09-02): ContextualWisdomLab/OmniRoute#1 currently says this metadata writer has already been given the desired customer-facing replacement, but the canonical config/repository-metadata.json on this PR does not yet contain an exact-cased OmniRoute entry. That mismatch should not be resolved by racing a settings write or by declaring the source prerequisite complete: #1 still owns the exact DeepWiki/public-navigation source and is not protected-default truth yet. When #1 integrates (or an equivalent verified successor carries its complete valid delta), add OmniRoute here as the single declarative settings owner, preserve the upstream homepage and useful existing topics, replace the ownership-caveat repository description with product-facing gateway wording, and keep Pages intent bounded to actual organization-owned docs rather than the upstream product site. Until then, treat #1's handoff wording as Proposed and do not claim live description/topics/Pages convergence.

Copy link
Copy Markdown
Contributor Author

Fresh public-surface traversal added the missing source prerequisites to the existing single writer ContextualWisdomLab/quarantine-sandbox-runtime#1 rather than opening a competing docs PR: exact Ask DeepWiki badge in README.md and a product/architecture/onboarding docs/index.md landing now exist on that Draft branch at head a57f073dc85014fe025297c4796749d4f279c8f5.

Do not add/apply this repository to the settings manifest yet: protected develop still lacks those prerequisites and #1 remains Draft/pre-release. After #1 integrates and the exact badge + docs/index.md are reverified on protected source, absorb it into this existing desired-state lane with the current concise description (Source-agnostic, credential-free artifact analysis runtime for the ContextualWisdomLab security ecosystem.) unless protected product wording has changed, preserve useful automated-analysis/sandbox/security topics, and add evidence-based bounded topics such as rust, sandbox-runtime, artifact-analysis, and contextualwisdomlab only after verifying the shipped runtime/language. Pages intent should target <default>/docs only after protected prerequisites are true; live Pages publication still requires the normal settings reconciler and REST/endpoint verification.

Copy link
Copy Markdown
Contributor Author

Fresh protected-base repair: this Draft desired-state writer is now ahead_by=9 / behind_by=8 against current main@b4eec000d21084accb736d289eb64cfd78e7a91a. Comparing its previous merge base 6ba61e7f... to current main shows the eight base commits do not touch either branch-owned file (config/repository-metadata.json, tests/test_repository_metadata_reconciliation.py), so the writer can be reconciled without content arbitration. I will preserve the current two-file delta and create a normal two-parent merge commit with the unchanged PR head first and current protected main second, using the current-main tree plus those exact two branch blobs. No force-push/rebase; Draft/source-prerequisite/settings-credential boundaries remain unchanged; all prior checks become predecessor evidence and the new exact head must reacquire governance.

seonghobae and others added 2 commits September 2, 2026 23:25
Merge the exact-head Noema single-request and telemetry repair after queue admission prevented required checks from materializing.
* refactor(ci): extract shared quality-gate reusable workflow for 2 of 8 duplicated files

An audit of the 8 .github/workflows/*-quality-ci.yml files that share a
bootstrap-templated skeleton found only one pair -- javascript-coverage-quality-ci.yml
and organization-commercial-readiness-loop-quality-ci.yml -- where the shared shape
(exact-head checkout, an identical pinned six-package requirements heredoc, coverage
run --branch + --fail-under=100, compileall, git diff --exit-code) was genuinely the
same logic, differing only in timeout, pytest target, and coverage --include path.
Extract that into a new workflow_call-only exact-head-coverage-quality-gate.yml and
turn both callers into thin uses:/with: wrappers.

Verified first that no branch-protection required status check or the org's
required-workflow ruleset references either caller's job name, so restructuring them
is safe. Updated the contract tests that pinned the old inline text and added one for
the new gate's own contract and both callers' input wiring.

The other 6 files each encode a genuinely different policy (harden-runner presence, a
docstring gate, exact-head-verification mechanics, multi-Python-version matrices with
non-shared extra logic, or no coverage --fail-under step at all) so templatizing them
would weaken what they individually enforce. Left untouched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(ci): trigger the JS coverage gate on its own new contract test

javascript-coverage-quality-ci.yml's pytest_target is the whole tests
directory, so it already executes
tests/test_exact_head_coverage_quality_gate_contract.py -- but that
file was missing from the workflow's own path trigger, so an edit
scoped only to that test could merge without the gate that runs it
ever firing (Devin Review finding on PR #1683). Added the file to the
JS caller's path list, not the org-loop caller's: org-loop's
pytest_target is a narrower glob that never matches this filename, so
adding it there would trigger a job that doesn't actually exercise the
test. Pinned this with a new contract test.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

Copy link
Copy Markdown
Contributor Author

OmniRoute source-prerequisite repair advanced on the existing canonical writer ContextualWisdomLab/OmniRoute#1. Exact head d55e899cbf0ba0396464e0e379df54c2301b537e fixes the four valid 404 findings by replacing nonexistent main links with the actual default branch release/v3.8.50; CONTRIBUTING.md, AGENTS.md, docs/, and LICENSE were verified at that ref before the edit. All three inline threads are now resolved. Fresh exact-head Quality Gates and semgrep are successful; CodeQL PR, Security Scan, and SAST Semgrep remain queued. Do not add OmniRoute to this manifest until #1 reaches protected release/v3.8.50, and do not infer live Pages/settings convergence from the source branch.

Copy link
Copy Markdown
Contributor Author

Veilpick desired-state extension — exact head 5d49b85d7ce05a7ca8f6ab5e2d9bd520a324d13e

The canonical public-surface desired-state writer now includes exact-cased Veilpick.

  • Source prerequisite inspected at Veilpick #1, exact head a90964fb4275461f8bd9f9515f977af48c7c0382: README contains the exact linked Ask DeepWiki badge and docs/index.md exists.
  • RED contract commit: bef4d58438cbe7d21a0a7a998d30ba8c258d2a3a. The inventory test required Veilpick while the manifest still lacked it, so exact-set reconciliation was false.
  • Minimal GREEN commit: 5d49b85d7ce05a7ca8f6ab5e2d9bd520a324d13e. It adds only the Veilpick description, seven bounded topics, and deepwiki/pages=true.
  • Exact current file readback: manifest and test inventories both contain 29 repositories; exact set equality, repository casing, description constraints, topic constraints, required web-acquisition/rust topics, and public-surface intent all pass.
  • Live protected Veilpick state remains topics=[], homepage=null, has_pages=false. This PR records desired state only; it does not claim live publication.
  • chore(metadata): add public-surface desired state wave 2 #1639 remains Draft and mechanically mergeable. Current-head Repository Metadata Reconcile, CodeQL, Security Scan, Semgrep, and Python Security are queued/pending, so no merge or lifecycle mutation was attempted.

Per-language codeql-scan-dispatch runs were occupying the 60-job
ceiling: 149 queued handler runs across 60 PR@SHA tuples, and
duplicate cancel could not collapse them because the language is
absent from the run name, job name, and REST payload.

analyze-head shards still publish the required check name and still
fail pending to release the runner, but they no longer POST.
dispatch-current-head collects this run's language job ids and sends
one codeql-scan payload (matrix + required_jobs). The handler
concurrency group is {workflow}-{repository}-{PR}; language
independence is fail-fast: false on that run's job matrix.

ADR-0025's 2026-09-05 rejection of a full-matrix dispatch is
superseded. The sibling-cancel failure from
contextual-orchestrator#1049 / run 33938784437 is gone because
siblings are jobs in one run.
#2008 made required_jobs mandatory on the default-branch handler.
repository_dispatch runs that file, so payloads that lined up before
the merge still carry required_language + required_job_id and a
one-shard matrix. Validate now synthesizes required_jobs from those
scalars when the array is empty, the matrix length is 1, and the
language matches. A present required_jobs array still wins; missing
or mismatched identity still fails closed. Concurrency stays
{workflow}-{repository}-{PR} with no language suffix.

Developer experience: queued single-language dispatches validate
instead of all failing closed after the cutover.
User experience: required CodeQL compatibility checks for those
in-flight PRs can still complete.

Copy link
Copy Markdown
Contributor Author

Fresh live public-surface audit — 2026-09-08

  • Accessible repositories: 74
  • Active non-fork repositories: 63
  • Active non-fork repositories with missing live description: 0
  • Active non-fork repositories with empty live topics: 0
  • Live has_pages=true: 6kaefa, newsdom-api, scopeweave, ContextualWisdomLab.github.io, LineageWeave, j-planner
  • Live repository homepage set: 4kaefa, newsdom-api, scopeweave, ContextualWisdomLab.github.io
  • Newly published Pages/settings mutations by this run: 0

Exact PR head remains 5d49b85d7ce05a7ca8f6ab5e2d9bd520a324d13e, Draft and mergeable. Exact-head Metadata Reconcile, Security Scan, SAST Semgrep, and Python Security are terminal SUCCESS. CodeQL remains FAILURE: the actions shard dispatched successfully but retained VERDICT_STATE=pending; the python shard ended with dispatch outcome failure and no authenticated terminal verdict. This is not live Pages/settings convergence evidence, so no merge/publication claim was made.

* fix(codeql): keep a clean dispatch scan when status publish 403s

opencode-agent is installed with statuses:read, so POST /statuses to a
target repo returns HTTP 403 after the SARIF gate already passed. Treat
the completed dispatch scan job as terminal evidence and let the
required shard consume that public run on rerun instead of fail-closing
a clean scan.

* fix(codeql): dispatch remaining languages on workflow reruns

Attempt 2 of .github#2028 skipped Dispatch current-head because the
coordinator required github.run_attempt == 1, so no codeql-scan was
posted. Later attempts still skip when every language already has a
terminal opencode-agent verdict.

* test(codeql): require paginated dispatch evidence lookup

* test(codeql): require paginated dispatch job lookup

* fix(codeql): paginate exact dispatch evidence

* test(codeql): parse paginated gh endpoint options

* style(codeql): normalize pagination fixture spacing

* test(codeql): match paginated empty dispatch fixtures

Signed-off-by: Seongho Bae <me@seonghobae.me>

* fix(codeql): bind dispatch fallback to live base and required run

The completed-scan fallback matched only repo#PR@head plus language, so a
same-head retarget could consume a predecessor-base scan and a different
waiting required run could satisfy this shard. Encode live base SHA and
required_run_id in the public dispatch run-name, look up that identity
from the required shard, and POST the live base on later attempts.
Concurrency stays repository+PR per #2008/#2009.

---------

Signed-off-by: Seongho Bae <me@seonghobae.me>

Copy link
Copy Markdown
Contributor Author

2026-09-08 metadata inventory extension

Added litellm-patched-proxy to this existing canonical desired-state writer without creating a competing PR.

  • RED commit: 54709bb4e79748c618ed9eecc7c54984125797e6 — the executable inventory contract expected litellm-patched-proxy while the manifest did not, producing the intended set mismatch.
  • GREEN commit / current exact head: 6cbf3a292e8e31ae76a426a8e927cf0ef48e3d24.
  • Fresh contract readback: expected repositories 30, manifest repositories 30, missing 0, extra 0; required topics llm-proxy and supply-chain-security are present.
  • Owner-source evidence: litellm-patched-proxy#2 exact head dceca31d96f342c4c280dbf2ab7a13ebc07eead8 contains the exact-cased linked DeepWiki badge and docs/index.md.
  • Protected develop still has the predecessor public surface, and the live GitHub repository currently exposes a description plus topics docker, litellm, llm, ops, sbom, and security. This source/manifest change is not evidence that Pages has been published or settings have converged.
  • New exact-head Repository Metadata Reconcile, CodeQL, Security Scan, SAST Semgrep, and Python Security runs are queued. Draft status is unchanged. No lifecycle/status label, base, branch protection, or credential was changed.

seonghobae commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Metadata/public-surface repair update (fresh live evidence, 2026-09-08):

  • Added a RED-first homepage contract on this existing writer branch: b610b1deaa95983d88cacd9a35f6f62acc874997.
    • Current implementation failed exactly at schema acceptance, combined repository PATCH payload, and verify-time drift detection: 3 failed / 12 passed.
  • Added the minimal stdlib-only owner fix in 2706881424d4877908587633d48f30346c00e89a, then documented the responsibility and added homepage-only plus explicit-null no-op coverage in 466433b92ccf2df399d08528829f4952a9a104cf and fbbeed926affe53586777f71d44f66f398bc8a7a.
    • Optional homepage now accepts explicit null or a public HTTPS URL, rejects malformed/non-HTTPS/localhost/private/internal values, combines description and homepage drift into one repository PATCH, and verifies exact live convergence.
    • Fresh local exact-content verification: focused metadata tests 15 passed; full repository suite 2640 passed, 1 skipped, 21 subtests passed; git diff --check clean.
  • Source prerequisite Veilpick#1 was ordinary-squash-merged at exact head a1cf6cf2e239b0657376890f0631267ea01b28f2 after CodeQL, Semgrep, and Security Scan succeeded and all review threads were resolved. Protected develop@cdaae4519db95141b88080d23d3cbeab6cfca31b now has exactly one DeepWiki target link and docs/index.md.
    • Live settings remain topics=[], homepage=null, has_pages=false; no settings or Pages convergence is claimed.

Current #1639 exact head is fbbeed926affe53586777f71d44f66f398bc8a7a. Its exact-head workflows are queued, and external least-privilege credential provisioning remains owned by #1579, so this PR remains Draft without any lifecycle/status toggle.

Omitted homepage stays unmanaged; explicit null clears/unsets it. Concrete homepage values must remain evidence-backed rather than being silently derived from Pages intent.

Copy link
Copy Markdown
Contributor Author

Exact-head RCA and repair (2026-09-08):

  • Previous head fbbeed926affe53586777f71d44f66f398bc8a7a failed Repository Metadata Reconcile run 34186935157, job 101937060350 after all 39 focused tests passed: branch coverage was 99%, with the unexercised branch at scripts/ci/reconcile_repository_metadata.py:101 (whitespace-bearing homepage rejection).
  • Added the single missing invalid-homepage case on the existing writer branch in c74d840ffac41e1e2876a57f0f1d20e4034f15c4; production code is unchanged.
  • New exact-head runs are Repository Metadata Reconcile 34189376009, CodeQL PR 34189376047, Security Scan 34189375993, SAST Semgrep 34189376013, and Python Security 34189376014; all are queued/pending and predecessor evidence does not transfer.
  • Veilpick#1 merged normally at a1cf6cf2e239b0657376890f0631267ea01b28f2. Protected develop now contains the exact DeepWiki badge and docs/index.md, so its source prerequisite is satisfied. Live repository topics remain empty and has_pages=false; external least-privilege provisioning issue ops(metadata): provision least-privilege repository settings writer #1579 remains open, so no live convergence is claimed.

PR remains Draft. No lifecycle/base/status-label mutation, bypass, or source-neutral rerun was used.

seonghobae commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

RankWeave source-prerequisite handoff (2026-09-08)

  • canonical writer: ContextualWisdomLab/RankWeave#40
  • exact head: 5f9c04bc7249395f9b7c15714cb2cfdfd917f509
  • exact README entry: [![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/ContextualWisdomLab/RankWeave)
  • docs/index.md: present on the same head
  • ancestry: protected main@92323cb8b55baf5d840cb97fa8534a0e75ef234c; ahead 18 / behind 0
  • exact-head CI 34190448119, Security Scan 34190448165, SAST 34190448092, and CodeQL PR 34190448197: queued

This is source evidence on an open canonical PR, not protected-branch publication. Keep RankWeave source prerequisite unfulfilled in the metadata manifest until ordinary merge puts both assets on protected main. No live topics, homepage, or Pages change is claimed.

Copy link
Copy Markdown
Contributor Author

Fresh repository-facing readback — 2026-09-08

  • Accessible repositories: 77.
  • Active non-fork repositories: 64; public active non-fork: 57.
  • Missing live descriptions among active non-forks: 0.
  • Empty live topics among active non-forks: 1Veilpick.
  • Live has_pages=true among public active non-forks: 6kaefa, newsdom-api, scopeweave, ContextualWisdomLab.github.io, LineageWeave, j-planner.
  • Veilpick protected develop now has the exact DeepWiki badge and docs/index.md, but live topics remain empty, homepage remains null, and has_pages=false. Current manifest head 37135edc61c6fab8909dc40c417342822a6c04c3 already carries its desired description/topics/Pages intent; issue ops(metadata): provision least-privilege repository settings writer #1579 remains the external least-privilege apply-path prerequisite.
  • RankWeave#40@5f9c04bc7249395f9b7c15714cb2cfdfd917f509 remains Ready/mergeable with current source prerequisites on its head, but exact-head CI/Security/CodeQL/Semgrep are still queued, so it is not protected-source evidence yet.

No live settings/Pages mutation or publication is claimed.

Copy link
Copy Markdown
Contributor Author

Fresh live public-surface audit (2026-09-08 UTC) against all 77 accessible repositories found 57 active public non-forks. Exact protected-branch prerequisites (one exact-cased DeepWiki badge plus docs/index.md) currently converge for five repositories: ThreadWeave, EgressWeave, psychometrics-commons, noema, and Veilpick.

Veilpick#1 is now merged and protected develop contains both prerequisites, but the live repository still reports topics=[], homepage=null, and has_pages=false. This confirms that source integration is complete while repository settings/publication remain pending in this owner lane; source presence is not being treated as publication.

A next non-overlapping prerequisite lane is codec-carver#516@8f4fc67004cd834928b342b77a9697003b81ab18. CI, fuzz, Security Scan, and SAST Semgrep are terminal-success, unresolved inline threads are zero, and ordinary squash auto-merge is now enabled. The organization ruleset still requires one approving review, so it remains open/blocked without bypass. Add codec-carver to the exact manifest/test inventory only after protected main actually contains the badge and docs/index.md; predecessor/source-branch evidence must not be admitted.

newsdom-api still exposes the incorrect live homepage https://contextwisdomlab.github.io/newsdom-api/, but protected develop has neither the exact DeepWiki badge nor docs/index.md. Canonical source work remains in newsdom-api#548@042b5062166dc6392434ced7106eb52a7b66c52b, which has current failed workflows and unresolved substantive review findings. Do not add it to the apply manifest or claim homepage convergence yet.

Open PR/issue live searches for missing semantic aliases and missing priority labels all returned zero in this pass. Draft/Ready, status:*, bases, heads, and .github#1996 lifecycle were not mutated.

seonghobae commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Central-owner RCA and repair are now in .github#2041 at exact head a28006ee72931f8b54b1dfcd567fdf394635ec86.

The Security Scan failure on this PR was not introduced by its effective metadata delta. Run 34195535497 / job 101962314786 scanned stale event range 9330d41c…6a8e8b2c; the event base was 248 commits behind protected main@7fd571db…. Against the current live base, this PR changes only:

  • config/repository-metadata.json
  • scripts/ci/reconcile_repository_metadata.py
  • tests/test_repository_metadata_reconciliation.py

The two Gitleaks results were test fixtures already on current main. #2041 fixes the canonical .github workflow test-first by authenticating the canonical live base and event exact head, granting only pull-requests: read, rejecting base races, deriving git merge-base, and scanning only merge_base..exact_head. It keeps fork PR heads scannable as untrusted source and does not suppress the fixture or weaken the hard gate.

Exact-content validation for #2041: stale-base RED 2 failed, 2 passed; fork-admission RED 1 failed, 4 passed; missing-permission RED 1 failed, 4 passed; final related GREEN 66 passed; executable temporary Git graph GREEN 6 passed; final full suite 2996 passed, 1 skipped, 21 subtests passed; shell syntax and git diff --check clean. Remote blobs match the tested files.

#2041 is Ready for review admission, but hosted checks and independent approval are still pending, so neither PR has merge authority from this evidence. Keep #1639 alive; after #2041 merges to protected main, rerun this PR and verify the live three-file range.

Copy link
Copy Markdown
Contributor Author

Fresh repository-facing reconciliation on 2026-09-08 UTC against live GitHub repository objects:

  • the connector inventory returned 74 repositories; direct canonical reads additionally exposed Veilpick and the intentionally excluded fork BizPlanningWizard, so list enumeration alone is not a complete authority;
  • active public non-forks verified from the inventory plus direct Veilpick: 57;
  • missing live description: 0;
  • missing live topics: exactly Veilpick (topics=[], homepage=null, has_pages=false);
  • GitHub reports Pages enabled for 6 repositories: kaefa, newsdom-api, scopeweave, ContextualWisdomLab.github.io, LineageWeave, and j-planner;
  • LineageWeave and j-planner still expose homepage=null. LineageWeave#908@00e90e03ae1afb7f13ae843dd578694d0f72b325 owns the missing exact DeepWiki badge/public landing and remains Draft behind its explicit fix(agent-mention): enforce repository_dispatch property cap on current main #911 license prerequisite. j-planner remains correctly excluded from a destructive generic docs rewrite because its live site is rooted on gh-pages.

Protected Veilpick/develop already carries the badge/source prerequisites from merged #1, and this PR already carries its exact-cased desired-state entry. No duplicate source/settings writer was created. Live Pages content could not be independently re-read through the available public lookup path in this pass, so has_pages=true is recorded only as GitHub settings evidence, not claimed as successful content publication.

Classification readback is still converged: open PR/issue semantic-alias missing = 0 and priority missing = 0. No Draft/Ready, status:*, base/head, or .github#1996 mutation was made in this audit.

Copy link
Copy Markdown
Contributor Author

Owner-stack repair status for this metadata writer

  • Security owner #2041 is now non-force stacked on CodeQL Wake owner #2040; current exact head 5d35ffa50164591ad1ee0e8600cc053cc40e3d09, base fix/codeql-wake-target-app-token@e17d1e74e57789141feda99f542759dc99bde6cc, mergeable, four-file Gitleaks-only PR diff.
  • #2040 RED ff2f7ab4e8364cd8fcf189207c68787004974140 reproduced clean-scan no-credential/all-denied wake paths returning 0. GREEN e17d1e74… now fails closed unless one exact required-job rerun is accepted; focused contract 32 passed and diff check is clean.
  • The former #2041 CodeQL failure was traced to its unstacked branch executing the superseded single-token Wake step after the native Python scan/SARIF gate/status publication succeeded. Both valid deltas are now present in the stacked history.

Do not rerun or merge this metadata writer on predecessor evidence. Wait for both owner exact-head generations to become terminal, land the canonical CodeQL settlement stack first, then land the Gitleaks child and rerun this PR against protected main. No Pages/settings convergence is claimed yet.

Copy link
Copy Markdown
Contributor Author

Fresh public-surface readback across the current 64 active non-fork repositories returned by organization search:

  • missing descriptions: 0
  • missing topics: Veilpick only (topics=[])
  • GitHub repository setting has_pages=true: kaefa, newsdom-api, scopeweave, ContextualWisdomLab.github.io, LineageWeave, j-planner
  • LineageWeave and j-planner: has_pages=true but homepage=null
  • newsdom-api: homepage is still https://contextwisdomlab.github.io/newsdom-api/, which omits ual from ContextualWisdomLab and is not the canonical organization Pages host
  • Veilpick: exact live state remains homepage=null, has_pages=false, default develop, last push 2026-09-08T04:29:12Z

Direct HTTP publication could not be independently proven from the available public lookup path, so this is repository-setting evidence only. Preserve the existing source-prerequisite and security stack; do not claim Pages publication until the deployed URL returns current content. No manifest/source mutation was made while #1639 and its #2040#2041 prerequisites are active.

Copy link
Copy Markdown
Contributor Author

Fresh current-head handoff after concurrent integration (2026-09-08):

Label searches remain converged: open PR/Issue semantic alias missing 0, priority missing 0, and type: docs without documentation 0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants