docs: refresh public README and Pages navigation - #908
seonghobae wants to merge 23 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughLineageWeave에 정적 공개 랜딩 페이지를 추가했습니다. 게시 스크립트는 랜딩 페이지를 검증하고 Changes공개 랜딩 페이지와 프로젝트 설명
랜딩 페이지 게시 및 검증
CI 트리거와 실행 환경 검증
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant GitHub Actions
participant publish_site
participant landing_source
participant output_index_html
GitHub Actions->>publish_site: 게시 작업 실행
publish_site->>landing_source: docs/index.html 검증
publish_site->>output_index_html: 랜딩 페이지 복사
output_index_html-->>GitHub Actions: 게시 결과 생성
Merge Risk: ⚪ Minimal · up to This refresh updates public documentation, Pages navigation, and explicit hosted-runner declarations without supplied evidence of a concrete correctness, security, availability, or deployment risk; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 4 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Codex <codex@localhost> Commit-Message-Assisted-by: Claude (via Claude Code)
Preserve the branch's explicit ubuntu-24.04 runner declarations while adopting protected main #923's docs-only Tests trigger filters.
Adopt #924's restored documentation-contract test triggering while preserving this branch's explicit ubuntu-24.04 hosted-runner declarations and public-surface delta.
seonghobae
left a comment
There was a problem hiding this comment.
Fresh protected-main review found a real convergence conflict, not a reason to close this PR. #908 modifies the same three repository-owned workflows that protected #931 later changed for Draft admission. GitHub now reports the PR non-mergeable. The valid #908 deltas are explicit ubuntu-24.04 runner pinning plus public-landing publication paths/tests; the valid protected deltas are ready_for_review/converted_to_draft handling, same-PR cancellation, and draft == false job admission. Neither side may be dropped. Repair must reconstruct the workflows with both contracts, preserve the public README/Pages/test delta, and retain protected tests/test_tests_workflow_contract.py. Pre-#931 hosted evidence does not transfer.
Merge the protected #931 workflow/contract blobs into the public-surface branch without dropping the branch's structural hosted-runner regression. This intentionally leaves the runner contract RED (`ubuntu-latest` vs required explicit `ubuntu-24.04`) so the follow-up can combine both valid contracts instead of choosing one side of the conflict.
2026-09-12 repository-facing exact auditThis existing PR is the canonical source writer for the remaining LineageWeave public-surface delta; no duplicate writer was created.
Live repository-facing settings remain After ordinary protected-main integration, the central |
|
2026-09-20 public-surface dependency readback Exact head remains The three central exact-head runs previously described as queued are terminal Central desired-state PR ContextualWisdomLab/.github#2110 now has an explicit reviewed workflow-path contract for this repository's existing |
seonghobae
left a comment
There was a problem hiding this comment.
Foreign publication consumer ContextualWisdomLab.github.io#245에서 유효한 owner-path gap이 드러났습니다. 현재 protected main@83eba56149eb802cd63642c507c324c9976ec78e의 scripts/build_ontology_site.py::_render_ontology_page()가 ontology index.html을 deterministic generated artifact로 소유하지만, 생성 <head>에는 CSP/referrer policy contract가 없습니다. #245는 생성된 복사본만 직접 수정하고 있어 다음 canonical regeneration에서 사라질 수 있습니다. Public Pages/workflow/test surface를 소유하는 이 #908 또는 명시적 LineageWeave successor가 causal owner에서 수리해야 합니다.
RED는 protected generator를 그대로 실행한 생성 결과가 합의된 security meta contract를 만족하지 못하는 것을 tests/test_ontology_site.py/publication fixture에서 재현하십시오. GREEN은 _render_ontology_page() 또는 그 canonical template가 정책을 생성하고, source→generated artifact→manifest→publish가 deterministic하게 이어지는 것입니다. Inline stylesheet가 현재 generator 계약이므로 CSP 세부값은 owner threat model과 실제 페이지 resource graph에 맞춰 최소 권한으로 정하십시오. consumer #245의 require-trusted-types-for 'script' 주장처럼 source와 불일치하는 directive를 무작정 복사하지 말고, script-src 'none'과 실제 sink/resource 요구에 근거해 contract를 정해야 합니다.
Acceptance는 generator unit test만으로 끝나지 않습니다. #911 등 기존 prerequisite를 정상 통합한 뒤 exact protected owner head에서 ontology build/publish checks와 security checks를 다시 획득하고, 실제 GitHub Pages가 그 exact generated blob을 제공하는지 HTTP/source digest까지 검증하십시오. 그 이후 GitHub.io downstream copy가 같은 bytes/contract를 소비하도록 versioned publication provenance를 연결해야 합니다. #245의 valid test/CHANGELOG/rationale를 owner successor가 완전 승계하기 전에는 #245를 단순 Close하지 마십시오.
Severity도 causal evidence에 맞춰야 합니다. 현재 확인된 것은 CSP 부재라는 defense-in-depth gap이며, exploitable content-injection primitive나 executable sink가 별도 RED로 입증되지 않은 상태에서 MEDIUM XSS라고 고정해서는 안 됩니다. injection 경로를 재현하지 못하면 hardening으로 doctoring하는 편이 맞습니다. 현재 owner gate: generator source authority FAIL / deterministic security contract FAIL / Pages exact-publication evidence FAIL.
Outcome
Refresh the public repository/Pages surface around LineageWeave's actual product responsibility while keeping evidence, license, and canonical-owner boundaries explicit. The root README/public landing becomes product-first, operator detail remains in its authoritative docs, publication fails closed when the source landing is absent, and repository-owned hosted jobs are pinned to an explicit supported image.
This PR does not introduce a release, customer, production deployment, benchmark superiority, certification claim, psychometric/statistical ownership, or model/provider routing implementation. TEPP/fast-mlsirm and contextual-orchestrator remain canonical owners.
Protected-main conflict repair
Fresh review
5116251331found a real convergence conflict after protected #931: #908 and currentmainboth modify Tests, PROV-O, and Ontology Pages workflows for different valid reasons. #908 needs explicitubuntu-24.04runners plus public-landing publication paths/tests; #931 needsready_for_review/converted_to_draft, same-PR cancellation, anddraft == falseadmission. Neither contract may be dropped.Realistic RED
01895d1b9cd37e8c625e28daadedf2a6a395840efirst merged the exact protected #931 workflow/contract blobs while retaining #908's structural hosted-runner regression. That deliberately made the branch'stests/test_github_hosted_runner_contract.pyfail because the protected workflows still declaredubuntu-latest.Causal convergence then combined both contracts:
53cbd8be9507c8a3bfb4f3bc249945beca7afc2b: Tests keeps fix(ci): defer repository-local jobs while PRs are Draft #931 Draft admission and pins both repository-owned jobs toubuntu-24.04;5e085c389731ab366210492a94f3aa7a3e1fdf78: PROV-O keeps fix(ci): defer repository-local jobs while PRs are Draft #931 Draft admission and pins its job toubuntu-24.04;00e90e03ae1afb7f13ae843dd578694d0f72b325: Ontology Pages keeps fix(ci): defer repository-local jobs while PRs are Draft #931 event/cancellation/Draft admission, restores docs: refresh public README and Pages navigation #908 public-landing paths/tests, and pins validate/publish toubuntu-24.04.The branch now contains protected
main@83eba56149eb802cd63642c507c324c9976ec78ewith no history rewrite and no gate weakening. The public README/Pages/test delta is preserved.Commercial-license prerequisite
Issue #910 remains the policy blocker for public-surface integration: the reachable
psycopg2-binaryLGPL-family path must be removed/replaced rather than hidden by attribution or a license exception. PR #911 is the active pg8000 replacement lane and is now Ready on its unchanged exact head for current-head validation; #908 must not land before that prerequisite is normally merged and the protected line is re-verified license-clean.Exact live boundary
main@83eba56149eb802cd63642c507c324c9976ec78e00e90e03ae1afb7f13ae843dd578694d0f72b325behind_by=033902990145and PROV-O33902990140: completedskippedunder Draft admission33902990079: both exact-head jobs completedskipped; GitHub resolved their runner labels asubuntu-24.04without allocating a runner33902990095, CodeQL33902990162, Security33902990087: terminalcancelledwith no exact-head GREEN verdictKeep Draft behind #911 and current-head governance. Do not transfer predecessor checks/reviews, weaken license inventory, or publish/release from this head.