Fix protected lifecycle PR-target provenance - #161
Conversation
|
|
Ready for Human Review evidence for exact head cc865cf:\n\n- GitHub commit verification: verified, reason valid.\n- Complete local quality and zero-vulnerability audit passed.\n- Exact-head CI run 30743902543 passed, including authoritative macOS 14 and macOS 26 native and acceptance jobs.\n- Every required branch-protection context is green.\n- Sonar reports 96.0% new-code coverage, 0 new or accepted issues, 0 security hotspots, and 0.0% duplication.\n- Independent exact-head audit has zero unresolved findings.\n- GitHub review audit has zero unresolved threads and zero change requests.\n- Target remains dev and auto-merge remains disabled.\n\nThe non-required Lifecycle wake failures are the accepted pre-merge defect: pull_request_target executes the current protected dev implementation, not this PR head. After a maintainer manually merges this PR, protected replay of the stranded #158 record and #52 / PR #156 must pass with zero lifecycle effects while activation remains disabled.\n\nThis is the automation stop state. Only Niko or Oscharko may manually initiate the merge into dev. |
|
Ready for Human Review evidence for exact head cc865cf:
The non-required Lifecycle wake failures are the accepted pre-merge defect: pull_request_target executes the current protected dev implementation, not this PR head. After a maintainer manually merges this PR, protected replay of the stranded #158 record and #52 / PR #156 must pass with zero lifecycle effects while activation remains disabled. This is the automation stop state. Only Niko or Oscharko may manually initiate the merge into dev. |



Scope
v1codex/160-protected-provenancedevNone— standalone defect discovered while requalifying Exact migration inventory, one-time reconciliation, and activation orchestration #52/PR Governance: add exact migration inventory and dry-run orchestration #156.defect30740121335,30740137162, and30740176636after the human merge of PR Fix active lifecycle generation supersession after fact drift #159.Product and architecture alignment
semantic planning change was absorbed during implementation.
CONTEXT.md, accepted ADRs, and the issue QualityPlan.
why Existing Keiko evidence is not applicable.
Keiko.
layer.
Existing Keiko evidence is not applicable: this restores an existing repository-owned Native
governance protocol accepted by ADR-0011 and ADR-0012. No durable architecture or schema change was
made.
Acceptance criteria and evidence
head_branchis never authority while the exact protected graph, run/job, SHA, reachability, and attestation evidence authenticate writer and replaycc865cfb8f9fc42671d00a9b51f9915e4b90deedcc865cfb8f9fc42671d00a9b51f9915e4b90deedcc865cfb8f9fc42671d00a9b51f9915e4b90deedcc865cfb8f9fc42671d00a9b51f9915e4b90deedAcceptance journey evidence
Applicability:
Not applicable — accepted Issue #160 is a non-user-facing governance control-plane correction with no product UI or native runtime change.Automated checks exercise user-visible outcomes rather than incidental implementation
details.
Required failure, recovery, accessibility, visual, and platform observations are settled.
No user-visible journey applies. Failure, recovery, malformed, provenance, duplicate, and inert
outcomes are exercised at the owning control-plane boundary; accessibility and visual evidence are
excluded by the accepted Quality Plan.
Quality Plan settlement
covered.
attached or linked.
tests, logs, evidence, artifacts, issues, and this pull request.
Verification
npm ci --ignore-scriptsnpm run qualitynpm audit --audit-level=highmodes.
Additional affected checks and concise results:
Independent audit and findings
consistency; hostile metadata; stable run/attempt/PR association; OIDC/static graph preservation;
zero-effect semantics; exact scope, signature, and head.
cc865cfb8f9fc42671d00a9b51f9915e4b90deeda scoped follow-up that does not invalidate current acceptance.
Integrated epic acceptance
Not applicable — standalone defect #160 unblocks but does not deliver or change epic #49's integrated acceptance surface.Delivery
epic/standalone -> devpush, gate bypass, finding dismissal, or authority widening occurred.
producer.
policy.
Ready for Human Reviewbefore every requiredAcceptance Journey result and exact-head gate was complete.
For an epic or standalone pull request targeting
dev, complete only by Niko or Oscharko. Agentsmust leave this subsection untouched, stop at
Ready for Human Review, and must not enableauto-merge.
Plan, evidence, checks, findings, conversations, and residual risks on the commit above.
dev; no automated actor is performing it.Residual risks and follow-ups
intentionally pending because it must execute from the new protected
devcommit after amaintainer manually merges this PR. It must produce zero lifecycle effects while activation
remains disabled.
Closes #160