Lean Pull-Request Verification and Evidence-Gated Publication Plan
Lean Pull-Request Verification and Evidence-Gated Publication Plan
Planning State
- architecture_applicability: architecture-bearing
- evidence: Six stories change one cumulative verification and publication capability across CLI tests, Turbo task ownership, GitHub workflow composition, cache trust, Candidate Evidence, and protected external mutation.
- dependency readiness: No Stack Required.
- branch/base intent: Not applicable.
- spec authority:
SPEC.md, immutable blob4df8d55a. - planning research:
ci-verification-publication-delivery-planning-research-report.md, retained at commit3c04c1ebe7b1106570db0996746130f8eb00162fonmain.
Post-completion policy amendment
On 2026-08-19, repository policy changed after IP-373 closeout: external-fork pull-request verification is unsupported and the fork cache lane is removed. Only same-repository pull requests may enter trusted affected verification. Stable Aggregate must fail and withhold Candidate Evidence whenever that trusted job does not succeed. Candidate Evidence authority retains its independent same-repository, non-fork provenance validation.
The initial situation, accepted solution, T4/T6 implementation log, and hosted matrices below are preserved as historical implementation evidence. Their fork-lane requirements and the unexecuted external-fork gate are superseded by this amendment; they do not describe the current workflow.
Initial Situation
The retained test portfolio has no explicit capability-and-safety inventory or one-primary-witness built-process command atlas. Root scripts and GitHub Actions still run repository suites outside singular Turbo ownership. The protected portfolio runs for pull requests, main, and a weekly schedule. Deterministic CLI build is uncached. Trusted pull requests have signed cache access, while forks have neither trusted writes nor proven safe default-branch restore.
Pull-request verification already emits a 14-day tree-named artifact, and publication already has exact-tree checks, semantic classification, OIDC authority, serialization, reconciliation, and readback. The evidence payload also contains package identity, classification, and release intent, and package assembly occurs before publication. The target keeps the useful authority and recovery seams while removing verification replay and package data from Candidate Evidence.
Problem
The current topology repeats expensive work, preserves low-signal implementation history, and mixes verification authority with release artifacts. It cannot prove that publication consumes only a successful exact-tree receipt, and it does not give fork work safe cache reuse with isolated writes.
Solution Shape
- Retain one High-Signal Test per named public capability, contract, or Safety Invariant. Run displayed commands through the complete built
hiprocess; keep onehintparity smoke and three product-wide Safety Invariant witnesses. - Put every deterministic check behind package-owned Turbo tasks. One pull-request workflow runs affected work for the latest prospective tree and always exposes one Stable Aggregate Check.
- Give trusted lanes one signed cache namespace. Give Untrusted Fork CI restore-only default-branch reuse plus isolated pull-request writes, without the trusted signing key.
- Emit a minimal 14-day Candidate Evidence JSON receipt from the successful Stable Aggregate Check. Accept it only for the newest valid same-repository, non-fork, exact final tree.
- Keep
mainread-only until classification and authority pass. Runnpm pack --json --dry-runat publication time, then preserve existing OIDC mutation, reconciliation, and readback. - Schedule only individually named external-drift witnesses.
Resolved Decision Ledger
- Retained tests prove named public behavior or a Safety Invariant; age, line coverage, test count, and historical inventory do not preserve a test.
- Pure low-signal deletion does not require a replacement or RED/GREEN cycle.
- CLI Behavioral Tests execute the complete built
hi;hinthas one parity smoke. - Focused Tests remain only for dense pure rules or typed protocol decoding through exported APIs.
- The three public CLI safety witnesses are containment, no partial managed state after failure, and secret redaction.
- Pull-request verification is the only retained-portfolio lane. A newer revision cancels the previous run.
- Turbo owns affected selection, task identity, dependencies, and deterministic cache outputs.
- Fork code receives no trusted cache-signing or publication credential.
- Candidate Evidence carries authority identity only; it carries no package, build, cache, credential, classification, or release-intent data.
- Release impact remains exactly
none,baseline,npm, ormixed; unknown fails closed. - Publication performs package integrity, protected mutation, reconciliation, and readback without test replay.
- Beta, canary, staged publication, merge-queue replacement, and provider mutation during implementation remain parked.
- Planning-time backlog sync was a verified no-op because Linear already had epic IP-373 and children IP-374 through IP-379 with exact immutable-spec links, milestones, labels, parent relation, and native blockers. Closeout reconciliation later moved all seven items from Backlog to In Progress and added tailored PR #144/local-evidence comments.
Assumptions and Constraints
- The current
maincheckout is the implementation base; the spec declares no stack or branch/base requirement. - GitHub Free remains the provider constraint. Candidate Evidence is the publication guard while paid exact-merge enforcement is unavailable.
- Node 24.19.0, Bun 1.3.5, Turbo 2.9.14, npm 11.5.1 or newer, and current pinned Actions are the starting tool identities. A version change requires explicit task-hash and workflow review.
- The existing semantic classifier, stable release ordering, compatibility rules, immutable-version handling, credentials, reconciliation, and readback remain authoritative unless this spec directly changes them.
- Pull requests and implementation validation never publish. A real release requires a reviewed release intent and a separately ready product version even though code changes and safe validation are approved.
- Provider credentials, cache-signing keys, production variables, and user credentials are never printed, stored in evidence, or exposed to fork/ordinary verification.
- Pure deletion may proceed without RED only when no production behavior changes. Any newly discovered behavior change must add a concrete public RED to its task before code edits.
- Existing unrelated worktree changes are preserved. Workers own only their declared paths and must accommodate concurrent changes.
- GitHub billing can block hosted proof. It cannot change the accepted design or turn missing runtime evidence into a pass.
Codebase Findings
.github/workflows/behavior-contract.ymlowns the current protected verification fan-out, main replay, weekly replay, and candidate upload..github/workflows/release.ymlowns current PR refusal tests, evidence discovery, authority validation, Production environment, OIDC, and convergence.turbo.json, rootpackage.json, and package scripts contain both deterministic task identity and direct-suite bypasses.apps/cli/scripts/run-cli-verification.mjsand release-test policy files encode the old partition model.apps/cli/src/cli/public-output-contract.test.tsspawnsdistbut combines many modes and native fault cases.apps/cli/scripts/release-candidate.mjs,run-release-candidate.mjs,release-authority.mjs, andrelease-state.mjsare the current evidence and recovery seams.- The accepted pure/protocol seams include release classification, Candidate Evidence decoding, exact-tree authority, and convergence state.
- Current title inventories, source-spelling checks, exact-version fixtures, duplicate matrices, and lower-level native fault suites are deletion candidates after the public inventory is established.
External Research Used
- GitHub dependency caching reference: low-trust cache poisoning, restore-only behavior, and pull-request cache scope.
- GitHub workflow artifacts: per-artifact retention and cross-run download identity.
- npm trusted publishing: workflow/environment binding, GitHub-hosted runners, and
id-token: write. - Turbo 2.9.14 installed schema and source at
/Users/stefan/.opensrc/repos/github.com/vercel/turborepo/2.9.14: task inputs, outputs, affected selection, environment hashing, and signature verification.
Target Ownership Topology
Verification portfolio (apps/cli public-process tests + inventory)
owns: named High-Signal Tests and Safety Invariants
excludes: workflow scheduling, cache credentials, release policy
Deterministic task graph (package scripts + turbo.json)
owns: affected selection, task dependencies, inputs, outputs, environment identity
excludes: provider authority and external mutation
CI composition (.github/workflows)
owns: triggers, cancellation, trust lane, Stable Aggregate Check, artifact transfer
excludes: test inventory semantics and release-impact meaning
Candidate Evidence authority (apps/cli release evidence modules)
owns: receipt schema, exact-tree validation, freshness, origin, newest-match choice
excludes: packages, builds, classification, credentials, mutation
Publication convergence (apps/cli release modules + Production job)
owns: semantic classification, package integrity, OIDC mutation, reconciliation, readback
excludes: pull-request test replay and Candidate Evidence productionConclusion: each policy has one semantic owner; GitHub YAML composes the owners but does not reimplement them.
Declared Dependency Graph
Verification portfolio --package task seam--> Deterministic task graph
Deterministic task graph --affected result--> CI composition
CI composition --minimal JSON receipt--> Candidate Evidence authority
Candidate Evidence authority --validated exact tree + classification request--> Publication convergence
Publication convergence --existing provider adapters--> npm, baseline authority, GitHub tag/releaseAllowed edges use package scripts, exported evidence/classifier APIs, JSON files with validated schemas, and existing release adapter entrypoints. Forbidden edges are direct CI calls to Vitest/Bun suites, workflow-owned release classification, package/build data inside Candidate Evidence, fork access to trusted signing credentials, publication calls back into product verification, and scheduled calls to the retained portfolio.
Responsibility Acceptance Criteria
| Criterion | Owner | Observable assertion | Evidence | Due architecture wave |
|---|---|---|---|---|
| RAC-1 | Verification portfolio | Every retained test maps to one named public capability, contract, or Safety Invariant; deleted classes are absent. | Inventory validator plus built-process focused suite. | A1 |
| RAC-2 | Deterministic task graph | Every deterministic check is package-owned, cacheable by default, and selected by Turbo with declared root controls. | Turbo dry-run JSON and cache replay. | A1 |
| RAC-3 | CI composition | Only the latest pull-request tree runs retained verification; the Stable Aggregate Check exists for run and skip paths; schedules name external drift only. | Workflow policy tests and YAML inspection. | A1 |
| RAC-4 | Cache trust | Trusted lanes share signed identity; forks restore eligible default-branch entries, cannot write trusted artifacts, and isolate their writes. | Static threat matrix plus trusted/fork dry-run evidence. | A2 |
| RAC-5 | Candidate Evidence authority | The 14-day receipt contains only required identity fields and rejects missing, expired, failed, fork, repository, commit, or tree mismatch before mutation. | Exported protocol/authority tests. | A2 |
| RAC-6 | Workflow integration | Candidate Evidence is emitted only after Stable Aggregate success and consumed only for the exact final tree; no main/release suite replay exists. | Workflow policy tests and artifact fixtures. | A3 |
| RAC-7 | Publication convergence | none mutates nothing; selected products pass npm pack --json --dry-run, OIDC, serialization, reconciliation, and readback without tests. | Release classifier/integrity/convergence tests. | A3 |
| RAC-8 | Final closure | Ownership, dependency edges, public seams, and all prior criteria match the cumulative diff; the migration ledger is empty. | Final architecture/security review and validation bundle. | A4 |
Architecture Waves
A1 boundary establishment
public witnesses + affected Turbo + named drift
checkpoint RAC-1..RAC-3
A2 exact authority
cache trust + minimal Candidate Evidence
checkpoint RAC-1..RAC-5
A3 vertical integration
aggregate/evidence wiring + publication convergence
checkpoint RAC-1..RAC-7
A4 final closure
docs + live evidence + zero-drift proof RAC-1..RAC-8Each checkpoint compares actual owners, allowed and forbidden edges, public seams, and migration entries. A failed or regressed criterion blocks the next architecture wave.
Public Seam Contract
| Seam | Owner | Allowed consumers |
| --------------------------------------------------------------------------- | ---------------------------------- | ----------------------------------------------- | ------ | ------------------ | ------------------------------ |
| Built hi/hint process: exit, JSON/human output, repository effects | CLI | Behavioral Tests and operators |
| Package-owned build, lint, check-types, test, browser, policy tasks | Each workspace/root-policy package | Turbo only; root scripts and CI delegate |
| Stable Aggregate Check status | Pull-request workflow | GitHub merge UI and Candidate Evidence producer |
| Candidate Evidence JSON v1 | Candidate Evidence authority | main authority lookup and validator only |
| Release-impact result none | baseline | npm | mixed | Release classifier | Protected Publication Workflow |
| Package-integrity result | Publication convergence | Publication dispatcher only |
| External convergence/readback result | Existing release state machine | Release operator and audit evidence |
Any task that changes one of these seams must update this table before dependent work proceeds.
Migration Ledger
| ID | Temporary seam | Introduced by | Reason | Allowed consumers | Removal task | Expiry wave | Removal proof |
|---|---|---|---|---|---|---|---|
| M1 | Root scripts directly start repository suites. | Pre-existing | Historical orchestration. | Current CI only. | T2 | A1 | Root scripts delegate only to Turbo. |
| M2 | Protected portfolio runs on main and weekly schedule. | Pre-existing | Historical backstop. | Current workflow only. | T2/T3 | A1 | Trigger/policy proof shows PR-only portfolio and named drift workflow. |
| M3 | Deterministic CLI build is uncached. | Pre-existing | Old release identity coupling. | Current verification. | T2/T4 | A2 | Repeated identical task reports a valid cache hit. |
| M4 | Candidate Evidence carries package/classification/intent data. | Pre-existing | Old release-candidate transport. | Current release authority. | T5/T6 | A3 | Minimal schema rejects extra transported release artifacts and exact-tree flow passes. |
| M5 | Release PR guard and publication path run product tests. | Pre-existing | Old refusal/backstop proof. | Current release workflow. | T6/T7 | A3 | Workflow policy proves no direct test runner or retained task in main/publication jobs. |
No new temporary seam is planned. Final closure requires M1 through M5 removed.
Task Dependency Graph
T1 ───────────────────────────────────────────────┐
T2 ──┬─> T4 ──┐ │
├─> T5 ──┼─> T6 ─> T7 ─────────────────────┼─> T8 ─> T9
└─> T7A ─┘
T3 ───────────────────────────────────────────────┘Parallel Execution Waves
| Worker wave | Tasks | Start condition | Write overlap check |
|---|---|---|---|
| W1 | T1, T2, T3 | Accepted plan | Disjoint: CLI test corpus; root/Turbo/current workflow; new external-drift workflow/scripts. |
| W2 | T4, T5, T7A | T2 green and A1 checkpoint | Disjoint: cache action/config; evidence modules/tests; obsolete CI/release test cleanup. |
| W3 | T6 | T4, T5, and T7A green and A2 checkpoint | Workflow composition and its same-task operator docs. |
| W4 | T7 | T6 green | Publication scripts and same-task operator docs reuse the now-stable workflow contract. |
| W5 | T8 | T1, T3, T6, T7 green and A3 checkpoint | Docs ingest, plan, and implementation notes only. |
| W6 | T9 | T8 complete | Evidence-only live validation; no code writes. |
Tasks
T1: Retain the public behavior and Safety Invariant portfolio
- depends_on: []
- location:
apps/cli/src/**,apps/cli/scripts/**,apps/cli/test-fixtures/** - owned_paths: [
apps/cli/src/cli/behavioral-portfolio.test.ts,apps/cli/src/cli/safety-invariants.test.ts,apps/cli/src/**/*.test.ts,apps/cli/src/**/*.test.tsx,apps/cli/scripts/*test*,apps/cli/scripts/host-cache-test-title-inventory.json,apps/cli/test-fixtures/public-output/**] - wave_boundary: W1
- description: Create
apps/cli/src/cli/behavioral-portfolio.test.tsandapps/cli/src/cli/safety-invariants.test.ts. Retain one complete built-hiBehavioral Test per displayed command, onehintparity smoke, stable JSON meaning, the command atlas, one representative failure, the loopback Local Provider Substitute, and three product-wide safety witnesses. Keep Focused Tests only for exported dense pure rules or typed protocol decoding. Delete title inventories, source-spelling tests, exact-version churn, duplicate matrices, installed-tarball execution smoke, and lower-level native fault suites that lack a public witness. Do not change production behavior to preserve a deleted test. - validation: The retained built-process suite covers all commands and safety outcomes; forbidden test classes and tarball execution are absent.
- status: Complete
- log: 2026-08-18: Replaced the historical CLI suite with the retained two-file, 17-test built-process portfolio and classified deletion of 146 low-signal test/fixture/runner files. Review repairs added real per-command temporary-repository scenarios, executable
hintparity, application-stage rollback evidence, and fixture cleanup. The typed inventory/test was later culled; behavior-contract CLI seams use the real single-package fixture. - files edited/created:
apps/cli/src/cli/behavioral-portfolio.test.ts,apps/cli/src/cli/safety-invariants.test.ts; later deletedapps/cli/src/cli/verification-inventory.test.tsandapps/cli/test-fixtures/verification-inventory/high-signal-tests.json; deleted T1 files are enumerated bygit diff --name-status -- apps/cli | awk '$1=="D"{print $2}'. - backlog_item_id: IP-376
- backlog_item_url: https://linear.app/devpunks/issue/IP-376/retain-only-public-behavior-and-safety-witnesses
- relation_mode: native
- assigned_skills: [
tdd,codebase-design,quality-types,simplify] - implementation_skill_guidance:
- skill:
tdd; applicable_behavior: Treat pure deletion as not applicable; any production behavior change needs one real public-process RED before code. - skill:
codebase-design; applicable_behavior: Use the built CLI and exported pure/protocol APIs as the test seams; do not add private test hooks. - skill:
quality-types; applicable_behavior: Decode structured output into explicit valid states instead of string/flag bags. - skill:
simplify; applicable_behavior: Remove obsolete test helpers, fixtures, scripts, and imports created orphaned by this pruning only.
- skill:
- tdd_status: not_applicable
- tdd_target: Test-only portfolio consolidation and classified deletion; production behavior is unchanged. If a production edit becomes necessary, amend this task to required before editing.
- red_command:
- expected_red_failure:
- green_command:
bun run --cwd apps/cli build && bun run --cwd apps/cli test -- src/cli/behavioral-portfolio.test.ts src/cli/safety-invariants.test.ts - reason_not_testable: The accepted task deletes or reshapes tests without changing production behavior; AC-003 explicitly permits direct deletion.
- red_evidence:
- green_evidence: Historical: the original command passed 3 files and 18 tests. Final retained public-process proof is two files and 17 tests in the behavioral portfolio and safety invariants; the typed inventory/test was later culled. CLI typecheck/lint/format and fixture-clean scans passed.
- codebase_design_notes: One full-process harness is the deep Behavioral Test seam. Focused APIs remain only where pure rule/protocol density earns a smaller seam.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
- architecture_wave: A1
- behavior_owner: Verification portfolio
- integration_surface: Built
hi/hintexternal process and exported pure/protocol APIs - public_seam: Built CLI exit/output/filesystem results; unchanged production interface
- topology_delta: Replaces implementation-history coverage with named public witnesses.
- forbidden_ownership: CI trigger policy, cache credentials, release mutation
- temporary_seams: none
- responsibility_acceptance_criteria: [RAC-1]
T2: Establish package-owned Affected Verification and the Stable Aggregate Check
- depends_on: []
- location:
turbo.json, root/package scripts,scripts/behavior-contract/**,.github/workflows/behavior-contract.yml - owned_paths: [
turbo.json,package.json,apps/*/package.json,packages/*/package.json,scripts/behavior-contract/**,.github/workflows/behavior-contract.yml,docs/README.md,docs/runbooks/ci-verification-and-publication.md] - wave_boundary: W1
- description: Add a failing public workflow/task-graph witness, then make every deterministic build, lint, typecheck, test, browser, and repository policy check package-owned and cacheable by default with precise dependencies, inputs, outputs, environment identity, and shared root controls. Use a justified Turbo root policy task only for repository-wide controls that no package can honestly own. Root scripts only delegate with
turbo run. Replace the current fan-out with one pull-request-only affected entrypoint and stable aggregate job. Cancel superseded revisions. Keep the Stable Aggregate Check present when a path-owned proof is graph-skipped. Remove main/schedule retained-suite replay and the PR release guard from this workflow; T3 supplies named scheduled drift. Updatedocs/README.mdand the CI/publication runbook in this task with the new PR-only operator contract. - validation: Turbo dry-run JSON proves applicable build, lint, typecheck, test, browser, and repository-policy tasks plus graph skips;
check:repoproves the retained lint/format policy; identical local runs restore deterministic output. Workflow execution/skip/cancellation remains a T9 runtime observation. - status: Complete
- log: 2026-08-18: Replaced the workflow fan-out with pull-request-only Turbo Affected Verification and one always-present Stable Aggregate Check; package-owned deterministic tasks and one justified root policy task now declare cache inputs/outputs. Review repair removed stale package-qualified Turbo tasks and added a manifest-to-task invariant. The aggregate is documented as merge-facing status, not publication authority. The initial static workflow/task-graph witnesses were later culled under the strict TDD rule; final local proof is Turbo, lint/format, and the executable/runtime seams owned by later tasks.
- files edited/created:
.github/workflows/behavior-contract.yml,turbo.json, root/app/packagepackage.jsonmanifests,docs/README.md,docs/runbooks/ci-verification-and-publication.md, and deterministic wiki projections; later deletedscripts/behavior-contract/affected-verification.test.ts,scripts/behavior-contract/cli-release-task-graph.test.ts, andscripts/behavior-contract/root-suite.test.tsas low-signal static tests. - backlog_item_id: IP-375
- backlog_item_url: https://linear.app/devpunks/issue/IP-375/verify-only-the-affected-latest-pull-request-tree
- relation_mode: native
- assigned_skills: [
turborepo,tdd,codebase-design,audit-cicd-security] - implementation_skill_guidance:
- skill:
turborepo; applicable_behavior: Put logic in package tasks, make root/CI delegate withturbo run, and declare result-affecting inputs, outputs, environment, and dependency edges. - skill:
tdd; applicable_behavior: Capture a failing task-graph/workflow behavior witness before changing scripts or workflow topology. - skill:
codebase-design; applicable_behavior: Keep Turbo as the single selection seam and GitHub YAML as composition, not a second path policy engine. - skill:
audit-cicd-security; applicable_behavior: Preserve least privilege and do not execute contributor-controlled code in a privileged context.
- skill:
- tdd_status: required
- tdd_target: One prospective pull-request tree delegates all applicable deterministic proofs through Turbo and always reports one Stable Aggregate Check;
mainand schedules do not run the portfolio. - red_command: Historical (culled):
bun test scripts/behavior-contract/cli-release-task-graph.test.ts scripts/behavior-contract/root-suite.test.ts - expected_red_failure: Current root/workflow directly invokes suites, runs the portfolio on main/schedule, and marks deterministic CLI build uncached.
- green_command:
bun run check:repo && bunx turbo run build lint check check-types test test:browser '//#check:repo' --affected --dry=json - reason_not_testable:
- red_evidence: Historical: prescribed legacy graph tests exited 1; the new public witness then failed on non-pull-request triggers and missing global/root-policy graph controls before topology changes. Those configuration-shape witnesses were later culled, not retained as final proof.
- green_evidence: Historical: focused workflow/task-graph suite passed 9 tests and 130 assertions. Final retained non-test evidence:
bun run check:repopassed; affected Turbo dry-run resolved 63 applicable tasks with no configured<NONEXISTENT>package task; repeated//#check:reporeportedFULL TURBOcache hits. Hosted cancellation/skip evidence remains T9. - codebase_design_notes: Package tasks are the deep deterministic-work interface; Turbo owns selection and caching; the aggregate job translates task results into one GitHub status.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; integrated pull-request runtime acceptance is owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A1
- behavior_owner: Deterministic task graph and CI composition
- integration_surface: Package scripts, Turbo graph, GitHub pull-request workflow
- public_seam: Package task names and Stable Aggregate Check
- topology_delta: Removes root/direct-suite ownership and non-PR portfolio replay.
- forbidden_ownership: Workflow-owned path taxonomy, release classification, external mutation
- temporary_seams: removes M1, M2; advances M3
- responsibility_acceptance_criteria: [RAC-2, RAC-3]
T3: Schedule only named external-drift witnesses
- depends_on: []
- location:
.github/workflows/external-drift.yml,.github/workflows/release.yml,scripts/external-drift/** - owned_paths: [
.github/workflows/external-drift.yml,.github/workflows/release.yml,scripts/external-drift/**] - wave_boundary: W1
- description: Add a machine-readable witness registry and only two initial witnesses: scheduled/manual
macos-filesystem-capabilitiesin.github/workflows/external-drift.yml, which records current GitHub-hosted macOS atomic-rename, symlink, hardlink, mode, case-sensitivity, and FIFO observations unavailable from the Ubuntu pull-request lane; and manualnpm-trusted-publisher-oidc-exchangein.github/workflows/release.yml, which uses the Production environment and npm's exact trusted-workflow identity to prove the current GitHub-to-npm OIDC exchange without runningnpm publishor mutating a package, tag, release, or baseline. Manual release dispatch must skip the push-only evidence, plan, and Production jobs. Every future registry entry must name its owning workflow and external owner, explain why deterministic pull-request verification cannot prove it, define the public observation and result, declare credential needs, and define cleanup. The six timing/concurrency cases in the old fresh-title inventory do not qualify merely because they were previously classified as fresh; T1 deletes them unless their public behavior is retained elsewhere. Do not move old native/ambient partitions wholesale. Do not call the retained portfolio or deleted tests. - validation: The two adapters have local syntax/cleanup/preflight evidence; their named GitHub/npm observations are runtime-only T9 proof. The temporary static workflow contract was culled under the strict TDD rule.
- status: Complete
- log: 2026-08-19: The two registry-backed adapters remain individually named.
macos-filesystem-capabilitiesis scheduled and manually dispatchable in.github/workflows/external-drift.yml.npm-trusted-publisher-oidc-exchangeis manually dispatchable only in.github/workflows/release.ymlbecause npm Trusted Publishing binds@punks/clito that exact workflow. Manual release dispatch skipsrelease-evidence,release-plan, andproduction, which remain push-to-mainonly. Hosted RED run32254400786returned HTTP 404 from npm under the former external-drift workflow identity without mutation. The routing repair is locally green and awaits hosted confirmation. The temporary structural workflow witness remains culled under the strict TDD rule. - files edited/created:
.github/workflows/external-drift.yml,.github/workflows/release.yml,scripts/external-drift/witnesses.json,scripts/external-drift/macos-filesystem-capabilities.mjs,scripts/external-drift/npm-trusted-publisher-oidc-exchange.mjs, and the focused OIDC exchange test; previously deletedscripts/external-drift/external-drift-workflow.test.tsremains absent as low-signal workflow-shape coverage. - backlog_item_id: IP-379
- backlog_item_url: https://linear.app/devpunks/issue/IP-379/schedule-only-named-external-drift-witnesses
- relation_mode: native
- assigned_skills: [
tdd,audit-cicd-security,verify-behavior] - implementation_skill_guidance:
- skill:
tdd; applicable_behavior: First make a workflow-policy test fail on the current weekly full-suite trigger and missing named witness boundary. - skill:
audit-cicd-security; applicable_behavior: Give each scheduled witness only the credential/capability it needs and pin every external component. - skill:
verify-behavior; applicable_behavior: Treat unavailable provider/runtime evidence as blocked, never inferred from unit tests.
- skill:
- tdd_status: required
- tdd_target: The named workflow routes expose only registered
macos-filesystem-capabilitiesandnpm-trusted-publisher-oidc-exchangewitnesses and cannot invoke the retained portfolio or publish. - red_command: Historical (culled):
bun test scripts/external-drift/external-drift-workflow.test.ts - expected_red_failure: The current weekly trigger runs the complete protected verification portfolio and no named-drift workflow exists.
- green_command: Adapter syntax, cleanup, and fail-closed OIDC preflight checks; hosted observations are T9-owned.
- reason_not_testable:
- red_evidence: Historical: initial policy test failed because the legacy workflow scheduled the full portfolio and the named external-drift workflow did not exist. The static witness was later culled, rather than retained as behavioral proof.
- green_evidence: Historical: the structural witness passed 3 tests and 114 assertions. Final retained evidence is adapter syntax, local macOS cleanup, and fail-closed OIDC preflight; hosted observations remain owned by T9.
- codebase_design_notes: Each witness is a narrow external adapter check. There is no generic scheduled-suite abstraction.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; named hosted-witness runtime acceptance is owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A1
- behavior_owner: External-drift observation
- integration_surface: GitHub schedule/manual triggers and named adapters
- public_seam: Individually named witness result
- topology_delta: Replaces weekly retained-suite replay with explicit external observations.
- forbidden_ownership: General verification, release qualification, test quarantine
- temporary_seams: removes M2 schedule portion
- responsibility_acceptance_criteria: [RAC-3]
T4: Reuse deterministic results without trusted fork writes
- depends_on: [T2]
- location:
turbo.json, cache setup action/config, cache trust tests - owned_paths: [
turbo.json,.github/actions/turbo-cache/**,apps/cli/package.json,scripts/behavior-contract/cache-trust.test.ts] - wave_boundary: W2
- description: Test-drive one task identity across trusted internal pull requests,
mainauthority lookup, and release verification. Keep signed trusted remote-cache writes. Give forks eligible default-branch GitHub Actions cache restore in read-only mode and write only to their pull-request scope. Never expose the signing key or trusted token. Make deterministic CLI build and retained tasks cacheable; keep publication, provider mutation, and genuine external drift uncached. - validation: Cache access matrix and Turbo dry-run/hash evidence cover the complete deterministic build, lint, typecheck, retained test, browser, and repository-policy portfolio across internal pull request, trusted main/authority, release verification, and fork lanes. They prove identical trusted identity, signed restore/write, fork restore-only default reuse, isolated fork writes, and uncached mutation/external drift.
- status: Complete
- log: Added one executable cache-trust policy used by the composite action; trusted mode requires team/signing authority, normalizes surrounding signing-secret whitespace into
GITHUB_ENV, and rejects embedded multiline secrets. Forks reject credentials and use revision-isolated GitHub cache writes with default-compatible restore. Removed two obsolete cache/title-inventory tests and stale managed-assets fixture scripts. - files edited/created:
.github/actions/turbo-cache/action.yml,.github/actions/turbo-cache/cache-trust-policy.mjs,apps/cli/package.json,scripts/behavior-contract/cache-trust.test.ts,turbo.json; deletedscripts/behavior-contract/cli-host-capability-cache.test.tsandscripts/behavior-contract/cli-verification-cache.test.ts. - backlog_item_id: IP-374
- backlog_item_url: https://linear.app/devpunks/issue/IP-374/reuse-deterministic-verification-without-trusting-fork-writes
- relation_mode: native
- assigned_skills: [
turborepo,tdd,audit-cicd-security] - implementation_skill_guidance:
- skill:
turborepo; applicable_behavior: Preserve equal task hashes for equal inputs and signed artifact verification; cache only deterministic outputs. - skill:
tdd; applicable_behavior: Capture the failing trust-matrix/cacheability assertion before changing cache configuration. - skill:
audit-cicd-security; applicable_behavior: Model fork content as attacker-controlled and treat caches as transfer objects, not trust boundaries.
- skill:
- tdd_status: required
- tdd_target: Fork verification can restore eligible default-branch deterministic cache data but cannot write a trusted artifact or access a trusted credential.
- red_command:
bun test scripts/behavior-contract/cache-trust.test.ts - expected_red_failure: Prerequisite test maintenance first removes the deleted release-test-runner import without adding cache behavior. Rerun the RED command and record only its intended cache failure: fork default-branch restoration and isolated writes are absent.
- green_command:
bun test scripts/behavior-contract/cache-trust.test.ts && bunx turbo run build lint check check-types test test:browser '//#check:repo' --dry=json - reason_not_testable:
- red_evidence: The stale witness first imported T1's deleted release-test runner and was replaced without cache behavior. The executable cache policy module was then absent; follow-up REDs showed trusted mode accepted a missing signing key and the output boundary accepted newline-bearing cache identity. The static task-graph witness was later culled.
- green_evidence:
bun test scripts/behavior-contract/cache-trust.test.tspassed 5 tests. It covers normalized surrounding trusted-secret whitespace written only throughGITHUB_ENV, embedded multiline refusal, fork credential refusal, isolated revision writes, and default-compatible restore. The final review-fix exact affected graph passed 55/55 across 13 packages with remote caching disabled, 44 locally cached, in 39.796 seconds. Hosted trusted/fork scope remains T9. - codebase_design_notes: Cache setup is one adapter over Turbo identity. Trust affects restore/write capability, not the task's semantic inputs.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; integrated trusted/fork cache runtime acceptance is owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A2
- behavior_owner: Deterministic task graph/cache adapter
- integration_surface: Turbo remote cache and GitHub Actions cache scopes
- public_seam: Task hash, signed cache artifact, trust-lane restore/write mode
- topology_delta: Completes deterministic cacheability and explicit fork isolation.
- forbidden_ownership: Publication caching, secrets in cache, trust derived from artifact location alone
- temporary_seams: removes M3
- responsibility_acceptance_criteria: [RAC-2, RAC-4]
T5: Reduce Candidate Evidence to exact-tree authority
- depends_on: [T1, T2]
- location:
apps/cli/scripts/release-candidate.mjs,run-release-candidate.mjs,release-authority.mjs, decoders and tests - owned_paths: [
apps/cli/scripts/release-candidate.mjs,apps/cli/scripts/run-release-candidate.mjs,apps/cli/scripts/release-authority.mjs,apps/cli/scripts/run-release-authority.mjs,apps/cli/src/scripts/release-candidate*.ts,apps/cli/src/scripts/release-authority*.ts,apps/cli/src/scripts/release-verification-evidence*.ts,docs/README.md,docs/runbooks/ci-verification-and-publication.md] - wave_boundary: W2
- description: Test-drive a minimal Candidate Evidence schema with schema version, repository, workflow run id, pull-request number, head commit, tested Git tree, and successful conclusion. Name it with the tree and enforce 14-day freshness outside the payload. Remove artifact/package identity, build output, cache data, classification, intent, and credentials. Select only the newest valid successful same-repository non-fork receipt for the exact final main tree. Block every mismatch before mutation. Keep exported decoder/authority Focused Tests as direct package tests. Update
docs/README.mdand the CI/publication runbook in this task with the evidence fields, freshness, and refusal contract. - validation: Exported decoder/authority tests cover valid evidence and missing, expired, failed, fork, repository, duplicate/newest, commit, and tree mismatches; evidence fixture contains no forbidden data.
- status: Complete
- log: Reduced Candidate Evidence to seven exact identity fields, externalized 14-day freshness to artifact metadata, and added newest-valid exact-tree authority with repository/run/PR/head/fork/conclusion/artifact/duplicate refusal. M4 remains bounded until dependent T6/T7 replace current workflow convergence wiring.
- files edited/created:
apps/cli/scripts/release-candidate.{mjs,d.mts},apps/cli/scripts/release-authority.{mjs,d.mts},apps/cli/scripts/run-release-candidate.mjs,apps/cli/scripts/run-release-authority.{mjs,d.mts},apps/cli/src/scripts/release-candidate.test.ts,apps/cli/src/scripts/release-authority.test.ts,apps/cli/src/scripts/release-verification-evidence.test.ts, and CI/publication docs. - backlog_item_id: IP-377
- backlog_item_url: https://linear.app/devpunks/issue/IP-377/bind-publication-authority-to-the-exact-tested-git-tree
- relation_mode: native
- assigned_skills: [
tdd,quality-types,codebase-design,audit-cicd-security,simplify] - implementation_skill_guidance:
- skill:
tdd; applicable_behavior: Add one public decoder/authority failure at a time and record RED before each production slice. - skill:
quality-types; applicable_behavior: Make valid/invalid evidence and authority results explicit discriminated states validated once at the boundary. - skill:
codebase-design; applicable_behavior: Keep receipt decoding/selection behind one small exported authority seam. - skill:
audit-cicd-security; applicable_behavior: Verify producer repository, run, fork origin, conclusion, freshness, and exact tree before granting any capability. - skill:
simplify; applicable_behavior: Delete package-identity and reviewed-intent transport made obsolete by the minimal receipt.
- skill:
- tdd_status: required
- tdd_target: Authority accepts the newest successful same-repository, non-fork Candidate Evidence only when its tested tree equals the final main tree.
- red_command:
bun run --cwd apps/cli test -- src/scripts/release-candidate.test.ts src/scripts/release-authority.test.ts src/scripts/release-verification-evidence.test.ts - expected_red_failure: Current evidence requires and emits package/classification/intent data and does not match the minimal schema.
- green_command:
bun run --cwd apps/cli test -- src/scripts/release-candidate.test.ts src/scripts/release-authority.test.ts src/scripts/release-verification-evidence.test.ts - reason_not_testable:
- red_evidence: Missing public decoder/selector; legacy evidence required package/classification/intent state; a recovered selector RED showed an expired older receipt blocked a newer valid exact-tree receipt.
- green_evidence: Six retained CLI/evidence files passed 30 tests; Candidate Evidence focused suite passed 12 tests, CLI check/typecheck passed, and the minimal decoder rejects any extra release state. The typed inventory/test was later culled.
- codebase_design_notes: Candidate Evidence is a narrow typed authority token, not a release artifact envelope.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
- architecture_wave: A2
- behavior_owner: Candidate Evidence authority
- integration_surface: Stable Aggregate producer and
mainauthority consumer - public_seam: Minimal Candidate Evidence JSON v1 and authority decision
- topology_delta: Separates verification identity from package/release state.
- forbidden_ownership: Builds, package files, caches, classification, release intent, credentials, mutation
- temporary_seams: advances M4
- responsibility_acceptance_criteria: [RAC-5]
T6: Wire the Stable Aggregate Check to exact-tree publication authority
- depends_on: [T4, T5, T7A]
- location:
.github/workflows/behavior-contract.yml,.github/workflows/release.yml, workflow policy tests - owned_paths: [
.github/workflows/behavior-contract.yml,.github/workflows/release.yml,apps/cli/scripts/run-release-authority.mjs,apps/cli/scripts/run-release-authority.d.mts,docs/README.md,docs/runbooks/ci-verification-and-publication.md] - wave_boundary: W3
- description: Make the successful Stable Aggregate Check upload the minimal tree-named receipt for 14 days. On every main push, locate and validate the newest matching exact-tree receipt before classification or mutation. Extend the authority command only as needed to pass multiple downloaded sources through T5's exported newest-valid selector; do not duplicate that policy in YAML. A direct main commit without matching evidence stops. Remove the PR release guard and all product-test/package-assembly replay from main and release workflows. Apply trust-specific cache setup from T4 without giving ordinary or fork jobs production credentials. Preserve non-cancelled serialized release runs and the Production environment. Update
docs/README.mdand the CI/publication runbook in this task with the final trigger, artifact, authority, and refusal flow. - validation: The production authority adapter remains the single exact-tree Candidate Evidence composition path. Its provider-simulation test file with two tests was culled under the strict TDD rule; workflow trigger/cancellation/status/artifact/permissions and exact-tree authority behavior are T9 runtime observations. No static workflow-shape or provider-simulation test is retained.
- status: Complete
- log: 2026-08-18: Split trusted and fork pull-request lanes, applied the T4 cache adapter at each lane, and made Stable Aggregate produce a minimal tree-named Candidate Evidence artifact retained for 14 days. Main authority locates paginated exact-tree artifact sources and routes them through the exported authority adapter before release work. Security repair keeps required OIDC and signed-cache inputs only in the same-repository trusted lane, gives forks neither, moves production checkout/setup/install/credential use after immutable authority, and rebinds checkout to the validated tree. The default GitHub adapter now uses the invocation cwd. Final strict-TDD cull removed both provider-simulation tests; hosted authority evidence remains T9.
- files edited/created:
.github/workflows/behavior-contract.yml,.github/workflows/release.yml, retained productionapps/cli/scripts/run-release-authority.{mjs,d.mts},docs/README.md, anddocs/runbooks/ci-verification-and-publication.md; deleted low-signalapps/cli/src/scripts/run-release-authority.test.ts,scripts/behavior-contract/root-suite.test.ts, andscripts/behavior-contract/release-authority.test.ts. - backlog_item_id: IP-377
- backlog_item_url: https://linear.app/devpunks/issue/IP-377/bind-publication-authority-to-the-exact-tested-git-tree
- relation_mode: native
- assigned_skills: [
turborepo,tdd,audit-cicd-security,verify-behavior] - implementation_skill_guidance:
- skill:
turborepo; applicable_behavior: CI calls only declared Turbo tasks and preserves task identity across eligible trusted lanes. - skill:
tdd; applicable_behavior: Capture failing workflow-policy assertions for exact evidence and no replay before YAML changes. - skill:
audit-cicd-security; applicable_behavior: Use least permissions; treat PR artifacts as untrusted until identity, origin, freshness, conclusion, and tree are validated. - skill:
verify-behavior; applicable_behavior: Require actual workflow evidence for cancellation, status, artifact, and refusal; blocked hosted runs stay blocked.
- skill:
- tdd_status: required
- tdd_target: A successful latest PR aggregate emits minimal exact-tree evidence; main with missing or mismatched evidence performs no production mutation.
- red_command: Historical static workflow-policy command was culled. The superseded authority-adapter RED used
bun run --cwd apps/cli test -- src/scripts/run-release-authority.test.ts; final strict-TDD cull deleted that provider simulation. - expected_red_failure: Current workflow emits oversized release-candidate data, reruns tests/package assembly, and selects older first-parent candidates rather than exact final-tree authority.
- green_command:
bun run --cwd apps/cli check && bun run --cwd apps/cli check-types; hosted artifact/authority/refusal evidence remains T9. - reason_not_testable:
- red_evidence: Historical and superseded: the public adapter suite recorded refusal behavior before authority wiring changes. The prior source-shape workflow witnesses and final two provider-simulation tests were later deleted under strict TDD and are not current proof.
- green_evidence: Current retained CLI validation passes 9 files/69 tests, including
publisherEnvironmentPathscoverage for a release worktree and its primary-worktree publisher environment. The final review-fix exact affected graph passed 55/55 across 13 packages with remote caching disabled, 44 locally cached, in 39.796 seconds; security review isSAFE. The productionrun-release-authoritypath remains, but no provider simulation is claimed as current evidence. T9 owns hosted artifact/authority/refusal proof. - codebase_design_notes: Workflow YAML composes stable package/evidence seams. It does not decode release policy inline beyond safe shell plumbing.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; integrated Candidate Evidence runtime acceptance is owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A3
- behavior_owner: CI composition
- integration_surface: Pull-request aggregate, artifact store, main authority job, Production gate
- public_seam: Stable Aggregate Check and Candidate Evidence transport
- topology_delta: Connects PR-only authority to main without suite or package replay.
- forbidden_ownership: Release-impact semantics, package integrity implementation, mutation logic in YAML
- temporary_seams: removes M4 and M5 workflow portions
- responsibility_acceptance_criteria: [RAC-4, RAC-5, RAC-6]
T7: Publish selected products without replaying verification
- depends_on: [T6]
- location:
.github/workflows/release.yml,apps/cli/scriptsrelease classifier, dispatcher, package integrity, state/convergence modules and tests - owned_paths: [
.github/workflows/release.yml,package.json,apps/cli/package.json,apps/cli/scripts/release-publication.{mjs,d.mts},apps/cli/scripts/run-release-publication.mjs,apps/cli/scripts/release-convergence.{mjs,d.mts},apps/cli/scripts/release-state.{mjs,d.mts},apps/cli/scripts/release-dispatcher.{mjs,d.mts},apps/cli/scripts/release-execution-boundary.{mjs,d.mts},apps/cli/scripts/promote-baseline-authority.mjs,apps/cli/src/scripts/promote-baseline-authority.test.ts,apps/cli/src/scripts/release-publication.test.ts,apps/cli/src/scripts/release-dispatcher.test.ts,apps/cli/src/scripts/release-convergence.test.ts,docs/README.md,docs/runbooks/ci-verification-and-publication.md] - wave_boundary: W4
- description: Preserve semantic
none|baseline|npm|mixedclassification and fail closed on unknown. Require exact Candidate Evidence for the final and every releasable historical first-parent tree. Letrelease-planuse read authentication only to snapshot private anchor/evidence state, then scrub checkout headers, replaceoriginwith a credentialless local bare repository, and derive classification/artifacts with lifecycle scripts disabled. Production independently cross-checks every non-noneplan receipt against the envelope before static Git/changelog/artifact validation through the fixed current-tree Node adapter. Guard mutation with authenticated exact tag lookup, relative reviewed baseline identity and tag/release preflight, fail-closed npm reads, GitHub metadata repair/readback, prerelease marking, temporary archive cleanup, and complete-product-only durable-anchor advancement.noneperforms no provider or anchor mutation. Preserve OIDC Trusted Publishing, serialization, safe archive extraction, and direct provider readback without verification or classification replay. - validation: The final retained CLI suite passes 9 files/72 tests. It covers historical Candidate Evidence plus independent-plan cross-check, strict authenticated tag lookup, relative baseline identity/preflight, fail-closed npm reads, metadata repair, prerelease marking, temporary archive cleanup, and
none/complete-product anchor behavior. T9 supplies hosted Stable Aggregate, Candidate Evidence, Production, OIDC, and no-mutation observations. - status: Complete
- log: Final review closure added nine fail-closed fixes: read-auth-only anchor/evidence acquisition followed by local-origin credential scrub; exact historical Candidate Evidence and independent apply cross-check; strict authenticated tag lookup; relative reviewed baseline identity plus tag/release preflight; npm failure closure; GitHub metadata repair/readback; prerelease marking; temporary archive cleanup; and
none-only no-mutation with durable advancement limited to the last complete real product. Production still has no Bun/dependency install/historical build or classification replay. Obsolete replay entrypoints remain removed. - files edited/created:
.github/workflows/release.yml, root and CLIpackage.json,apps/cli/scripts/release-publication.{mjs,d.mts},apps/cli/scripts/run-release-publication.mjs,apps/cli/scripts/release-convergence.{mjs,d.mts},apps/cli/scripts/release-state.{mjs,d.mts},apps/cli/scripts/release-dispatcher.{mjs,d.mts},apps/cli/scripts/release-execution-boundary.{mjs,d.mts},apps/cli/scripts/promote-baseline-authority.mjs,apps/cli/src/scripts/promote-baseline-authority.test.ts,apps/cli/src/scripts/release-publication.test.ts,apps/cli/src/scripts/release-dispatcher.test.ts,apps/cli/src/scripts/release-convergence.test.ts, and the CI publication runbook/docs projection. - backlog_item_id: IP-378
- backlog_item_url: https://linear.app/devpunks/issue/IP-378/publish-selected-products-without-replaying-verification
- relation_mode: native
- assigned_skills: [
tdd,quality-types,codebase-design,audit-cicd-security,simplify] - implementation_skill_guidance:
- skill:
tdd; applicable_behavior: Test each public classifier/integrity/convergence result before changing the release implementation. - skill:
quality-types; applicable_behavior: Keep classification, integrity, authority, and convergence as explicit validated states; unknown states fail closed. - skill:
codebase-design; applicable_behavior: Keep package inspection and provider reconciliation behind existing release entrypoints, with remote adapters injected at their current seams. - skill:
audit-cicd-security; applicable_behavior: Keep OIDC and production capabilities out of ordinary jobs; mutation is uncached and begins only after authority and integrity pass. - skill:
simplify; applicable_behavior: Remove installed-tarball execution and obsolete pre-publication artifact assembly without changing recovery order.
- skill:
- tdd_status: required
- tdd_target: The public T6-envelope consumer refuses invalid current or historical provenance, missing/conflicting authenticated tags, and provider read failures; routes
noneto no mutation; scrubs planning to a local origin; and lets only the fixed Production adapter reconcile independently cross-checked products without verification replay. - red_command: After first adding public behavior tests,
bun run --cwd apps/cli test -- src/scripts/release-publication.test.ts src/scripts/release-convergence.test.ts. - expected_red_failure: The new public tests initially show that T6's envelope cannot be consumed by the release entrypoint,
release:verifystill replays product verification, andnonehas no proved no-mutation terminal result. - green_command:
bun run --cwd apps/cli test && bun run --cwd apps/cli test -- src/scripts/release-publication.test.ts src/scripts/release-dispatcher.test.ts. - reason_not_testable:
- red_evidence:
- green_evidence: Final local CLI passes 9 files/72 tests with check and typecheck green. Hosted Stable Aggregate, Candidate Evidence, protected
none, and npm OIDC are recorded under T9. Final security review isSAFE. - codebase_design_notes: Build-derived classification and historical execution belong only to planning after read-auth state is scrubbed to a local origin. Production is a fixed current-tree Node adapter that cross-checks independent evidence, validates immutable plan authority, reads providers, mutates the first incomplete product, verifies readback, and advances the durable tag only through a complete real product.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; integrated publication runtime acceptance is owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A3
- behavior_owner: Publication convergence
- integration_surface: Read-auth snapshot, scrubbed local origin, independent evidence envelope, release plan artifact, fixed current-tree Node adapter, npm OIDC, baseline and GitHub provider adapters
- public_seam: Classification result, integrity result, convergence/readback result
- topology_delta: Separates scrubbed-local-origin historical classification/build/pack from protected fixed-adapter mutation and removes verification, attestation, and legacy reconciliation replay.
- forbidden_ownership: Candidate Evidence production, retained tests, cached mutation, new release channels
- temporary_seams: removes M5 and remaining pre-publication assembly in M4
- responsibility_acceptance_criteria: [RAC-7]
T7A: Cull residual low-signal CI and publication tests
- depends_on: [T1, T2]
- location: Repository CI/release behavior-contract tests and the packaged-product operator validator made obsolete by the lean verification topology
- owned_paths: [
behavior-contract/cli.json,scripts/validate-packaged-product.mjs,scripts/behavior-contract/isolation.test.ts,scripts/behavior-contract/run-test-scope.ts,scripts/behavior-contract/run-test-scope.test.ts,scripts/behavior-contract/test-scope.ts,scripts/behavior-contract/test-scope.test.ts,scripts/behavior-contract/repository-test-inventory.mjs,scripts/behavior-contract/repository-test-inventory.test.ts,scripts/behavior-contract/cli-verification-cache-fixture.mjs,scripts/behavior-contract/cli-host-capability-cache-fixture.mjs,scripts/behavior-contract/packaged-product.test.ts,scripts/behavior-contract/cutover-repeat.test.ts] - wave_boundary: W2
- description: Delete obsolete push/full-suite topology inventories, their orphaned runners/cache fixtures, and exact-count/task-name classifications. Remove stale contract, package-validator, and isolation references to CLI tests deleted by T1; bind any durable CLI public contract only to the retained built-process portfolio. Reduce mixed files to public package-integrity and release outcomes only: remove exact command arrays, installed-tarball replay, source-spelling checks, exact patch/lock bytes, and exact gate decomposition. Do not replace deleted assertions with new existence, registration, source-string, or provider-simulation tests. Preserve only behavior tied to a named current publication invariant.
- validation: No retained test or validator references a deleted CLI witness, old suite partition, exact test count, workflow spelling, tarball execution, source layout, or historical gate decomposition; remaining focused behavior-contract tests pass through exported policy or public product seams. The strict TDD cull removed 14 pure-static files plus static portions of mixed files. The final review-fix exact affected graph passed 55/55 across 13 packages with remote caching disabled, 44 locally cached, in 39.796 seconds.
- status: Complete
- log: Removed obsolete scope/inventory/package-shape tests, their orphan runners/cache fixtures, stale CLI contract/validator/isolation references, and brittle source/order assertions. The strict TDD cull removed 14 pure-static files and static portions of mixed files, without replacement existence, registration, source-string, or provider-simulation tests. Rebound the durable CLI behavior contract to the retained built-process and Safety Invariant portfolio. The packaged-product command now completes without replaying deleted product tests.
- files edited/created: Updated
behavior-contract/cli.json,scripts/validate-packaged-product.mjs,scripts/behavior-contract/isolation.test.ts, andscripts/behavior-contract/cutover-repeat.test.ts; deletedscripts/behavior-contract/{run-test-scope.ts,run-test-scope.test.ts,test-scope.ts,test-scope.test.ts,repository-test-inventory.mjs,repository-test-inventory.test.ts,cli-verification-cache-fixture.mjs,cli-host-capability-cache-fixture.mjs,packaged-product.test.ts}. - backlog_item_id: IP-373
- backlog_item_url: https://linear.app/devpunks/issue/IP-373/deliver-lean-pull-request-verification-and-evidence-gated-publication
- relation_mode: native
- assigned_skills: [
tdd,simplify] - implementation_skill_guidance:
- skill:
tdd; applicable_behavior: Pure low-signal deletion needs no replacement test or RED/GREEN; the executable packaged-product validator repair uses its real failing command as RED and completion as GREEN. - skill:
simplify; applicable_behavior: Prefer deletion; preserve only the smallest current behavioral witness when a mixed file still protects a named publication invariant.
- skill:
- tdd_status: required
- tdd_target: The packaged-product operator validator completes without invoking deleted product-test suites; pure low-signal test deletion needs no replacement witness.
- red_command:
bun run validate:packaged-product - expected_red_failure: The validator invokes deleted
public-output-contract.test.tsandrenderer.test.tsfiles, so the supported command fails before completing product validation. - green_command:
bun run validate:packaged-product && bun test scripts/behavior-contract - reason_not_testable:
- red_evidence:
bun run validate:packaged-productexited 1 because Vitest could not find deletedsrc/cli/public-output-contract.test.tsandsrc/ui/renderer.test.ts. - green_evidence:
bun run validate:packaged-productexited 0; focused behavior-contract and retained CLI/evidence seams remained green after the cull; orphan reference scan and diff check were clean. Final cumulative local evidence is the review-fix exact affected graph: 55/55 across 13 packages, remote caching disabled, 44 locally cached, 39.796 seconds. The earlier 0-cached 58.463-second run and historical 140-test/963-assertion count are not current proof. - codebase_design_notes: Historical verification topology is not an owned public seam.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable; integrated release behavior remains owned by T9.
- runtime_cleanup: not_applicable
- architecture_wave: A2
- behavior_owner: Verification portfolio and packaged-product operator validation boundary
- integration_surface: CI/release behavior-contract test suite
- public_seam: None for deleted implementation-history assertions; retained package/publication outcomes only
- topology_delta: Removes obsolete tests that encode superseded CI and publication implementation shape.
- forbidden_ownership: Production code, unrelated API/backoffice/package tests, new topology policy
- temporary_seams: none
- responsibility_acceptance_criteria: [RAC-1, RAC-3]
T8: Document the implemented operator and architecture contract
- depends_on: [T1, T3, T6, T7, T7A]
- location:
docs/README.md, CI/release runbooks, routed wiki knowledge, implementation notes and plan evidence - owned_paths: [
docs/README.md,docs/runbooks/**,apps/wiki/content/docs/project/runbooks/**,apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/PLAN.md,apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/IMPLEMENTATION-NOTES.md,apps/wiki/index.md,apps/wiki/log.md,apps/wiki/content/**/meta.json,CHANGELOG.md] - wave_boundary: W5
- description: Run
docs-ingest-phase. Document PR-only Affected Verification, stable check meaning, cache trust lanes, Candidate Evidence fields/freshness, direct-main refusal, classification, package integrity, OIDC, serialization, reconciliation/readback, named external drift, and the billing/real-release gates. Fill plan evidence and implementation notes. Update changelog only if product/release behavior warrants it. - validation:
node apps/wiki/scripts/sync-content.mjsupdates the generated runbook projection; wiki build/content, scoped plan/notes formatting, andgit diff --checkpass. The root runbook documents the lean PR lane, seven-field current/historical Candidate Evidence, trust lanes, read-auth snapshot and local-origin scrub, mandatory durable-tag authority, independent Production cross-check, provider preflights/repair, package/archive safety, complete-product anchor recovery, OIDC, readback, and named-drift boundaries. T9 hosted/runtime proof remains explicitly open. - status: Complete
- log: 2026-08-19: Ingested the final split-job CI/publication operator contract, one-time durable-anchor seed procedure, and corrected named-witness routing into the root runbook and generated private wiki projection. The macOS witness belongs to
external-drift.yml; the npm OIDC witness belongs torelease.yml, whose manual dispatch cannot enter publication jobs. Kept changelog unchanged because this delivery changes protected verification/publication workflow rather than a released product version. - files edited/created:
docs/README.md,docs/runbooks/ci-verification-and-publication.md,apps/wiki/content/docs/project/runbooks/ci-verification-and-publication.md,apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/PLAN.md,apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/IMPLEMENTATION-NOTES.md, andapps/wiki/log.md. - backlog_item_id: IP-373
- backlog_item_url: https://linear.app/devpunks/issue/IP-373/deliver-lean-pull-request-verification-and-evidence-gated-publication
- relation_mode: native
- assigned_skills: [
docs-onboarding,writing-for-agents,writing-fragments,writing-beats,writing-shape,simplify] - implementation_skill_guidance:
- skill:
docs-onboarding; applicable_behavior: Keep operator runbooks indocs/and durable project/domain knowledge in the private wiki. - skill:
writing-for-agents; applicable_behavior: Make commands, authority boundaries, and stop conditions executable without hidden context. - skill:
writing-fragments; applicable_behavior: Reuse small authoritative source fragments instead of copying whole specs. - skill:
writing-beats; applicable_behavior: Explain operator sequence in causal order from PR evidence to readback. - skill:
writing-shape; applicable_behavior: Match each artifact to its purpose: runbook for action, concept/contract for durable knowledge, notes for execution evidence. - skill:
simplify; applicable_behavior: Remove stale instructions that describe main/schedule replay or installed-tarball execution.
- skill:
- tdd_status: not_applicable
- tdd_target: Documentation and durable evidence only after behavior tasks are green.
- red_command:
- expected_red_failure:
- green_command:
node apps/wiki/scripts/sync-content.mjs && bun run --cwd apps/wiki check:content && git diff --check - reason_not_testable: Docs and evidence bookkeeping do not introduce runtime behavior.
- red_evidence:
- green_evidence: Source projection sync, wiki content/full checks, scoped Oxfmt, and
git diff --checkpass. Final runtime proof is full CLI 9 files/72 tests plus hosted PR/cancellation, macOS, protectednone, and npm OIDC evidence under T9. Real product mutation remains conditional and unclaimed. - codebase_design_notes: Documentation mirrors the accepted owners and public seams; it does not invent a second architecture.
- review_mode: cli
- runtime_validation: not_required
- runtime_target: not_applicable
- runtime_evidence: not_applicable
- runtime_cleanup: not_applicable
- architecture_wave: A4
- behavior_owner: Documentation and closeout evidence
- integration_surface: Operator runbooks, private wiki, plan/notes
- public_seam: Documented commands and authority states
- topology_delta: Makes the implemented ownership model durable and operable.
- forbidden_ownership: New product decisions or release channels
- temporary_seams: records closure of M1-M5
- responsibility_acceptance_criteria: [RAC-8]
T9: Prove end-to-end behavior and final zero drift
- depends_on: [T8]
- location: Supported local CLI/process surfaces and GitHub Actions evidence; plan/implementation evidence fields only
- owned_paths: [
apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/PLAN.md,apps/wiki/content/docs/project/specs/cli/ci-verification-and-publication/IMPLEMENTATION-NOTES.md] - wave_boundary: W6
- description: A Luna-max non-code worker runs the supported built CLI/process checks and, when billing permits, the integrated runtime matrix: T2 superseded-revision cancellation plus executed/skipped Stable Aggregate paths; T3 manual
macos-filesystem-capabilitiesandnpm-trusted-publisher-oidc-exchange; T4 trusted signed cache hit/write plus fork default-branch restore-only and isolated writes for the same task identity; T6 tree-named 14-day Candidate Evidence, newest exact-tree acceptance, direct-main refusal, and mismatched-tree refusal before Production; and T7 no-mutationnone/authority refusal,npm pack --json --dry-runpackage integrity, and OIDC exchange. Real publication convergence/readback runs only when a separately ready reviewed release exists. It must not publish merely for validation. Map evidence to US-001 through US-006 and AC-001 through AC-033. Run final architecture and security audits. Record blocked paid-Actions or real-release proof distinctly; never infer a pass. - validation: Built CLI witnesses, Turbo dry-run/cache proof, executable policy/authority adapters, and hosted evidence for each named T2/T3/T4/T6/T7 scenario; conditional real-release convergence/readback is either proven from a separately authorized release or recorded as its exact external gate. Final migration ledger is empty and all due RAC criteria pass or name an external execution gate.
- status: Complete
- log: 2026-08-19: PR #145 run
32256807550passed the trusted lane and Stable Aggregate (55/55, 49 cached) and retained Candidate Evidence for tested treee87222547b4b20adbf75a27c43a950e10048d5f5; superseded run32256389904was cancelled. The macOS witness passed in32254400362. Mergebd01736ethen produced fail-closed release RED32257146346, exposing squash provenance without mutation. PR #146 run32258617884was green; release32258817830first refused the missing durable anchor and then exposed the empty-history metadata defect, again without publication. Exact non-product ownership proof permitted the one-time lightweight anchorrelease-authority/v1/bb4dcb27cedcd7ee11237de13955cab88c41e289, which remains the sole durable authority tag. After PR #147 run32259308638and mergec37a7d71, protected release32259491112passed evidence, plan, and Production with an empty-productnoneentry,firstIncomplete: null, andstatus: complete; no provider mutated and the anchor stayed atbb4dcb27. Manual OIDC witness32259801134passed withresult: observedandnpmTokenReceived: true, while evidence, plan, and Production were skipped. External-fork hosted cache isolation remains a named external execution gate. Real npm/baseline mutation remains conditional because no reviewed product release was ready. - files edited/created: Evidence-only updates in the IP-373 plan and implementation notes; no T9 code or provider state.
- backlog_item_id: IP-373
- backlog_item_url: https://linear.app/devpunks/issue/IP-373/deliver-lean-pull-request-verification-and-evidence-gated-publication
- relation_mode: native
- assigned_skills: [
verify-behavior,audit-cicd-security] - implementation_skill_guidance:
- skill:
verify-behavior; applicable_behavior: Exercise every supported end-to-end path and mark inaccessible hosted/provider scenarios blocked with exact evidence. - skill:
audit-cicd-security; applicable_behavior: Produce the required verdict, trust matrix, credential-to-storage trace, and exact file/line findings without retrieving secrets or publishing.
- skill:
- tdd_status: not_applicable
- tdd_target: Evidence-only validation of already implemented behavior.
- red_command:
- expected_red_failure:
- green_command:
bun run check && bun run check-types && bun run test && hi check --json - reason_not_testable: This task gathers final runtime, architecture, and security evidence; behavior was test-driven in prior tasks.
- red_evidence:
- green_evidence: Hosted PR run
32256807550passed 55/55 with 49 cached, Stable Aggregate, remote cache enabled, and exact-tree Candidate Evidence fore87222547b4b20adbf75a27c43a950e10048d5f5;32256389904proves current-workflow cancellation. macOS32254400362and npm OIDC32259801134passed. Protected release32259491112accepted exact authority frombb4dcb27through currentc37a7d71, classified the only entrynone, completed with no product or provider mutation, and retained the sole durable anchor. Full local CLI is 9 files/72 tests; check, typecheck, and the focused fail-closed OIDC test pass. Latest reviews are PASS/SAFE with no P1/P2 finding. External-fork hosted behavior and a conditional real product release remain explicit external execution gates, not inferred passes. - codebase_design_notes: Final proof checks cumulative ownership and public seams, not individual file presence.
- review_mode: cli
- runtime_validation: required
- runtime_target: Built CLI; T2 pull-request run/cancel/skip; both T3 manual witnesses; T4 trusted and fork cache lanes; T6 pull-request artifact plus main exact-match/direct/mismatch refusals; T7 protected
none, authority-refusal, package dry-run, and OIDC paths; conditional real-release convergence/readback. - runtime_evidence: PR #145 run
32256807550and cancellation32256389904prove latest-tree execution, cancellation, aggregate, cache reuse, and exact-tree artifact production. Release RED runs32257146346and32258817830failed closed before mutation and drove squash-provenance and empty-history repairs. PR #146 and #147 validation runs32258617884and32259308638passed. After exact non-product ownership proof and one-time anchor seeding atbb4dcb27cedcd7ee11237de13955cab88c41e289, protected release32259491112passed release-evidence, release-plan, and Production for currentc37a7d71: release kindnone, products{},firstIncomplete: null,status: complete, no npm/baseline/GitHub release mutation, and no anchor advance. Manual release witness32259801134received an npm token and skipped all publication jobs. No external-fork run exists, so hosted fork restore-only/write-isolation remains an external gate. No separately ready reviewed npm or baseline release existed, so real mutation/convergence was correctly not exercised. - runtime_cleanup: Close task-owned test PR/ref only when authorized; preserve durable run evidence and never delete production release state.
- architecture_wave: A4
- behavior_owner: Delivery validation
- integration_surface: All declared public seams
- public_seam: Evidence bundle only
- topology_delta: None; proves final cumulative topology.
- forbidden_ownership: Code changes, provider mutation, inferred passes
- temporary_seams: must be empty
- responsibility_acceptance_criteria: [RAC-1, RAC-2, RAC-3, RAC-4, RAC-5, RAC-6, RAC-7, RAC-8]
Testing Strategy
- T1 uses test-only consolidation. It records GREEN evidence and changes no production behavior. Any necessary production edit first amends T1 to a concrete RED/GREEN slice.
- T2 through T7 use vertical public-result slices. Workflow/config behavior is validated through executable adapters, Turbo dry-runs, and safe hosted seams; static configuration-shape tests are not retained.
- Focused Tests remain for exported dense pure rules and protocol decoding. Workflow source-string inventories and exact implementation order are not retained.
- Validate narrowest to widest: focused file, package build/typecheck/check, Turbo dry-run/cache, root checks, then safe hosted runtime evidence.
- No test or validation command publishes npm, baseline, tags, releases, or provider state.
Wave Validation Gates
A1 checkpoint
- RAC-1 through RAC-3 pass.
- W1 write scopes remain disjoint.
- Root scripts delegate through Turbo.
- Retained portfolio is PR-only; named drift is separate.
- M1 and M2 are removed; M3 is bounded to cache-trust work.
A2 checkpoint
- RAC-1 through RAC-5 pass, including regression of A1 evidence.
- Trusted/fork cache matrix has no lower-to-higher trust write path.
- Candidate Evidence schema is minimal and exact-tree authority is fail-closed.
- M3 is removed; M4 is bounded to workflow integration.
A3 checkpoint
- RAC-1 through RAC-7 pass, including regression of prior evidence.
- Main/publication has no retained test, browser, safety, focused, or tarball execution replay.
- OIDC, serialization, reconciliation, and readback remain intact.
- M4 and M5 are removed.
A4 final closure
- RAC-1 through RAC-8 pass.
- Migration ledger is empty.
bun run check,bun run check-types, relevant retained tests, wiki checks,git diff --check, and freshhi check --jsonpass or an exact unrelated/external blocker is classified.- Findings-first review, CI/CD security audit, and behavioral evidence have no unresolved in-scope Critical/High or correctness finding.
Review Routing
- After implementation, enter
delivery-phasereview with the immutable spec, this plan, current fixed commit, implementation notes, validation outputs, and architecture evidence. - Security review must inspect every workflow include/action and invoked release/cache script. It returns the exact required verdict and trust/object matrix.
- Accepted review findings enter at most three durable repair epochs. Focused validation follows the third repair.
- Docs ingest occurs only after clean implementation/review handoff, then closeout reconciles Linear, PR/commit, and final evidence.
Risks and Mitigations
- Old tests encode the old topology: classify against the accepted capability inventory; delete implementation-shape enforcement instead of teaching it the new spelling.
- Over-pruning removes unique public safety: establish inventory and three built-process safety witnesses before deletion.
- Turbo global inputs invalidate everything: keep only truly global root controls global; retain task-specific inputs and environment locally.
- Fork cache poisoning: forks receive no signature key or trusted write token; verify restore/write scopes and treat restored data as untrusted until signature/identity validation.
- Oversized Candidate Evidence survives through compatibility code: schema tests reject forbidden fields; publication rebuilds/inspects from the exact checkout.
- Workflow YAML reimplements domain policy: exported classifier/evidence modules own semantics; YAML only composes validated commands and files.
- Release recovery regresses: preserve immutable-version handling, ordering, reconciliation, and readback tests while deleting only test replay/package transport.
- Paid Actions is unavailable: complete local/static evidence and record hosted scenarios blocked. Do not weaken design or claim runtime proof.
- Accidental publication: all implementation/live tests stop before mutation; real release execution needs a separately ready reviewed release even though this delivery has broad code-change approval.
Backlog Projection
Live Linear reconciliation on 2026-08-18 confirmed:
- Epic IP-373, M14,
Kind/epic,Module/Factory governance. - M12: IP-375, IP-376, IP-379.
- M13: IP-374 blocked by IP-375; IP-377 blocked by IP-375.
- M14: IP-378 blocked by IP-377.
- IP-373 through IP-379 moved from Backlog to In Progress. Each received a tailored PR #144/local-evidence comment. They link the immutable spec and collectively cover US-001 through US-006 and AC-001 through AC-033.
- Delivery evidence is now complete for the available required paths. Linear status reconciliation is a closeout provider action outside this documentation edit.
No task-level Linear issues were created. Plan tasks continue to reference their owning story.
Unresolved Questions
None. External-fork verification is unsupported under the post-completion amendment. A future reviewed product release remains a conditional execution gate, not a planning decision or T9 blocker.