Skip to content

feat(contracts): inventory repository artifact bindings - #96

Draft
jsmarble wants to merge 1 commit into
mainfrom
codex/phase-5y-h2e-b-repository-inventory
Draft

feat(contracts): inventory repository artifact bindings#96
jsmarble wants to merge 1 commit into
mainfrom
codex/phase-5y-h2e-b-repository-inventory

Conversation

@jsmarble

Copy link
Copy Markdown
Owner

What changed

  • add a closed review-candidate inventory for all ten provenance-v2 repository-artifact bindings
  • independently execute the eight currently resolvable document/literal path programs in Node and workerd
  • verify the sole present repository artifact as an exact regular tracked file and record five missing files plus two missing approval-row sources
  • correct the deterministic-procedure allowlisted namespace and keep complete build-manifest, resolver, migration, and authority work pending
  • make contracts:check fail on missing-file/source-row arrival, symlink or path drift, untracked witnesses, byte/hash drift, generated drift, or public OpenAPI exposure

Why

ADR 0067 requires every repository-backed digest to resolve through a closed, build-pinned contract before it can participate in provenance authority. The prior root-binding plan named the programs but did not inventory current repository state or prove any exact-file witness. This slice establishes that fail-closed boundary without fabricating approval artifacts or enabling runtime authority.

Impact

This is dormant contract and test evidence only. It adds no Worker handler, route, binding, migration, D1 operation, remote resource, telemetry, visitor data, credential value, approval, or deployment capability. The artifact remains review_candidate, authority_refused, non-persisted, outside public OpenAPI, and explicitly incomplete.

Validation

  • two sequential architecture, contract/test, and security/privacy review rounds; final round found no P0-P2 issues
  • full npm run verify passed
  • 2,189 unit tests passed
  • 254 Worker-runtime tests passed
  • contracts/generated drift, format, lint, typecheck, docs, traceability, privacy, supply-chain, builds, browser/state/production/local-discovery, and accessibility gates passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants