Skip to content

Complete GitHub release enforcement for v0.5.x #23

Description

@Kitahl

The hardened Gauntlet + FOIL software tree is published as research software v0.5.0 on main.

Release PR #24 changed only the coherent release identity surface (VERSION, CITATION.cff, changelog, README/current Pages labels, visual-version/provenance marker, and showcase release-identity validator). Its exact candidate tree 0b9ecde6df507efc35a4f8c44b91261f755c81d9 passed Research software validation, CodeQL, full-history Gitleaks, runtime/dev/resolved-lock pip-audit, deterministic hash-lock regeneration, and exact --require-hashes installation before merge. The unchanged runtime/lock tree had already passed Linux/Windows/macOS portability validation.

Current main is ba03be52588a81356540611c792726db3f0e874d, authored/committed with the GitHub private noreply identity and pointing to the tested v0.5.0 tree 0b9ecde6df507efc35a4f8c44b91261f755c81d9.

A lightweight v0.5.0 tag and GitHub Release have now been published against that clean release commit/tree. The one-time release-bootstrap workflow restored main to the clean parent afterward, so no release-bootstrap file remains in reachable main history. The temporary API-created bootstrap SHA 136253943e600ce559302fd261980710643e031e may still be directly retrievable from GitHub's object/cache layer and should be included with the other obsolete pre-rewrite SHAs in any GitHub Support purge request.

Completed:

  • Harden Gauntlet + FOIL runtime/privacy/security/reproducibility CI.
  • Full-history Gitleaks gate and resolved dependency auditing.
  • Deterministic hash-locked dependency environment.
  • Linux/Windows/macOS portability validation for the unchanged runtime/lock tree.
  • Rewrite reachable branch/tag commit metadata to GitHub noreply identity.
  • Promote the coherent current software identity to 0.5.0 and pass the release candidate gates.
  • Publish lightweight v0.5.0 tag against the cleaned release tree.
  • Publish GitHub Release v0.5.0 with the research/evidence boundary stated in the notes.

Remaining GitHub administration/account/external-service controls (not writable through the currently connected GitHub tool or repository GITHUB_TOKEN):

  • Protect main with a ruleset/branch protection.
  • Require PRs before merge and require validation, CodeQL, Security gates, and Runtime portability checks where applicable.
  • Require conversation resolution and prohibit force pushes/deletion of main after history-cleanup work is complete.
  • Enable/verify GitHub native secret scanning and push protection.
  • Enable/verify Dependency Graph, Dependabot alerts, Dependabot security updates, code scanning, and private vulnerability reporting.
  • Set repository description to: Evidence-governed research toolkit with Gauntlet process assurance and FOIL adaptive reasoning support.
  • Set homepage to https://kitahl.github.io/The-Gauntlet/.
  • Add topics such as research-software, ai-assisted-research, verification, reproducibility, evaluation, foil.
  • Enable GitHub account email privacy / command-line email blocking so future commits cannot expose a personal address.
  • Request GitHub Support purge of obsolete cached/PR/direct-SHA objects if complete removal of old personal-email metadata is required.
  • Archive the stable evidence-bearing release (for example Zenodo) and add the DOI to CITATION.cff when minted.

Repository boundary: Mastermind implementation/runtime/control material remains outside this repository. Historical audit/benchmark prose may reference an external procedure, while tests/test_private_leaks.py enforces the runtime/control boundary.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions