Skip to content

Commit 34903e7

Browse files
authored
chore: prepare public readiness
Source-only public-readiness preparation. No visibility, release, publish, deploy, live send, DB mutation, credential movement, or history rewrite performed.
1 parent 1628716 commit 34903e7

622 files changed

Lines changed: 56 additions & 44459 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.gitleaks.toml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
title = "agent-olympics public-readiness gitleaks allowlist"
2+
3+
[allowlist]
4+
description = "Allow source-only proof-token SHA-256 fixture fields; these are challenge hashes, not credentials."
5+
paths = [
6+
'fixtures/proof-token-verification/challenge-set.yaml',
7+
'fixtures/proof-token-verification/positive-result-packet.yaml',
8+
'fixtures/proof-token-verification/negative-result-packet.yaml',
9+
]

‎README.md‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ motto, and Korean working line.
1818

1919
Agent Olympics is an MVP evaluation framework with source packs, schemas,
2020
validation tooling, adapter fixtures, and dry-run examples. It is ready for
21-
schema and harness development. It is not yet a fully verified public
21+
schema and harness development. It is public-source-ready for schema and harness review, but it is not yet a fully verified public
2222
competition: most Season 001 tasks remain draft-tier until baseline runs and
2323
judge records promote them to smoke or verified status.
2424

@@ -366,3 +366,14 @@ v2 schemas add public/private separation and oracle cross-referencing:
366366
- `schemas/judge-record-v2.schema.json` — Judge Record v2
367367

368368
See [docs/migration-v1-to-v2.md](docs/migration-v1-to-v2.md) for the migration guide.
369+
370+
## Public source visibility boundary
371+
372+
This repository is being prepared for possible public source visibility. A
373+
public repository setting would be source-only: it would not approve release or
374+
tag creation, package/image publication, production deploy/restart/reload,
375+
database mutation, provider or Telegram sends, credential movement, history
376+
rewrite, or any other live operation.
377+
378+
Runtime credentials and private operational data must stay outside the
379+
repository. Example configuration must use placeholders only.

‎SECURITY.md‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
# Security Policy
2+
3+
## Supported scope
4+
5+
This repository is being prepared for possible public source visibility. Public
6+
visibility, release publication, package publication, deployment, provider or
7+
Telegram sends, database mutation, credential movement, and history rewrite are
8+
separate approval-gated actions.
9+
10+
## Reporting a vulnerability
11+
12+
Do not open a public issue with secrets, tokens, private URLs, personal data, or
13+
exploit details. Open a minimal maintainer-contact issue that says you need a
14+
private security route, or contact the repository owner through an already
15+
established private channel. Share sensitive details only after a private route
16+
is confirmed.
17+
18+
## Secret handling
19+
20+
- Do not commit real API keys, bot tokens, cookies, sessions, private keys,
21+
production logs, private host paths, or raw runtime data.
22+
- Example files must use placeholders only.
23+
- Runtime credentials belong in local environment variables or operator-owned
24+
secret stores outside this repository.

‎SUPPORT.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
# Support
2+
3+
This repository is a source-visibility candidate for design review, local
4+
experimentation, and issue discussion. It does not imply production support,
5+
managed hosting, release publication, package publication, deployment approval,
6+
or live-operation approval.
7+
8+
Use GitHub Issues for non-sensitive bugs and documentation problems. Do not
9+
post secrets, private runtime data, production logs, chat IDs, tokens, or
10+
personal data in issues or pull requests.

‎docs/adapter-execution-contract.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -600,7 +600,7 @@ redaction_policy:
600600
| ✅ Correct | ❌ Wrong |
601601
|---|---|
602602
| `api_token_value` | `sk-proj-abc123def456` |
603-
| `private_key_material` | `-----BEGIN RSA PRIVATE KEY-----MIIEpA...` |
603+
| `private_key_material` | `<private-key-material-redacted>` |
604604
| `session_cookie` | `session=abc123; path=/` |
605605

606606
### Approval Boundaries

‎runs/stage2-fleet/code-001-bangtong/adapter-bootstrap.log‎

Lines changed: 0 additions & 35 deletions
This file was deleted.

‎runs/stage2-fleet/code-001-bangtong/adapter.log‎

Lines changed: 0 additions & 35 deletions
This file was deleted.

‎runs/stage2-fleet/code-001-bangtong/bench-preverify.txt‎

Lines changed: 0 additions & 47 deletions
This file was deleted.

‎runs/stage2-fleet/code-001-bangtong/bench-verify.txt‎

Lines changed: 0 additions & 20 deletions
This file was deleted.

‎runs/stage2-fleet/code-001-bangtong/envelope-copy.yaml‎

Lines changed: 0 additions & 58 deletions
This file was deleted.

0 commit comments

Comments
 (0)