Skip to content

Restore authoritative Dependency Review evidence for PolicyWeave PR #1 #12

Description

@seonghobae

Fresh authority check — 2026-10-03

  • Canonical root writer remains PR #1, develop → protected main, at exact head 60fd7fb5c3177984a993102742bb16e36a909e2d; stacked PR #25 remains based on that exact head at af8c0da17cdfb4786867f4e85401dbbb811b581e.
  • PR feat: bootstrap PolicyWeave privacy policy workspace #1 exact-head CI 36241748023, SAST 36241747980, and CodeQL 36241747969 are terminal success. Required Security 36241747990 remains terminal failure because the authoritative base/head Dependency Review comparison returned HTTP 403 before the pinned action could run.
  • The canonical owner incident ContextualWisdomLab/.github#810 remains open and blocked. Its current exit criteria still require an authorized availability/configuration repair plus fresh HTTP 200 ordinary and stacked canaries; no released owner repair exists to consume.
  • Both PolicyWeave PRs remain Draft. PR feat: bootstrap PolicyWeave privacy policy workspace #1 has no qualifying independent approval; PR feat: cancel stale local draft imports #25 cannot integrate before its parent and likewise has no qualifying approval. Current inline-thread queries return zero unresolved threads.
  • The dependency pin, build-time placement, lock, and CycloneDX implementation described below is already present in the canonical writer history. This issue is deliberately kept open under its corrected title to track the remaining authoritative Dependency Review evidence and ordinary protected integration—not to recreate completed product-source work.
  • No blind rerun, lifecycle toggle, no-op commit, substitute scanner, synthetic status, protection weakening, merge, or issue closure was performed.

Exact-head security rerun — 2026-10-01

Required Security run 36241747990 was rerun without changing protected base 52f4fd6bb68f870d0519cf11dd471573a2f197c0 or PR #1 head 60fd7fb5c3177984a993102742bb16e36a909e2d. New dependency-review job 110221939186 reproduced the owner incident: authenticated exact-base/head compare returned HTTP 403, curl_exit=0; the pinned Dependency Review action was skipped and the required job failed closed. Scorecard, Trivy, and OSV passed again but do not replace the missing dependency diff.

The product source has no new repair delta for this owner-plane availability failure. PR #1 and this issue remain open/Draft pending ContextualWisdomLab/.github#810, a qualifying independent approval, and a fresh exact-head authoritative Dependency Review result. No gate weakening, synthetic success, issue closure, or merge is authorized.

Current integration state — 2026-09-30

The dependency pin/scope/SBOM repair from historical PR #13 is integrated into the product branch history. The canonical root writer remains PR #1, develop → protected main, exact head 60fd7fb5c3177984a993102742bb16e36a909e2d, tree 54c19ce3a7b46d8dda055bf778c6c7327fe8e0b9, protected base 52f4fd6bb68f870d0519cf11dd471573a2f197c0. Stacked Draft PR #25 is based on that unchanged head; it is not a replacement owner. PR #1 is Draft because required Security evidence is terminal-failing and qualifying approvals remain 0. This issue stays open; no valid delta is closed or retired.

Current exact-head CI 36241748023, Semgrep 36241747980, and CodeQL 36241747969 are terminal success. CI produced exact-head browser artifact 10913167115 (sha256:fdbe823578ce068ab23728f3835479ab8c689a51c68477704a777a0744bfb2a1) and exact-head CycloneDX artifact 10912873052 (sha256:4e06815ac5d0b6e128d8071fa18ca08ca707d153c2d1b684ab06d9bc44def2f7). Security 36241747990 is terminal failure: job 108815523383 verified the exact checkout, then the Dependency Review support request for the exact base/head returned HTTP 403, curl_exit=0; the pinned action was skipped and the workflow failed closed. Scorecard, Trivy and OSV success do not replace Dependency Review. All 17 inline threads are resolved, but there is no qualifying approval. Canonical owner incident: ContextualWisdomLab/.github#810.

Predecessor Direct-head CI 34682685358, attempt 1, job 103524109831, checked out the literal head f11fe7827160a5f54cc76101050c41f0c6e156f3 and completed successfully: clean install, lint, five local-preview pretests, 163 Vitest cases including dependency contracts, build, PostgreSQL 18.6 migration/concurrency/restart/restore and 23 browser passes plus 10 existing scoped skips.

The CycloneDX artifact 10294182797 is bound to that head with ZIP digest sha256:28fde2bad87569a4657119a708d42c2943fa52beec3ead42d0d3cf4e515ac39a. The ZIP was downloaded and its SHA-256 independently verified before parsing its single policyweave-dependency-sbom.cdx.json file.

CycloneDX 1.5 describes 244 installed components on that CI platform. Declared-license counts: MIT 186, Apache-2.0 21, ISC 13, BSD-2-Clause 8, MPL-2.0 5, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. No component lacks license metadata. The parsed inventory has no GPL/AGPL/SSPL license string. This is a scoped installed-component inventory, not the complete cross-platform lock graph and not a compatibility/legal approval.

The five MPL-2.0 components are @axe-core/playwright@4.13.0, axe-core@4.13.0, lightningcss@1.33.0, lightningcss-linux-x64-gnu@1.33.0 and lightningcss-linux-x64-musl@1.33.0; the CC-BY-4.0 component is caniuse-lite@1.0.30001810. Their SBOM optional scope must not be misread as proof that all distribution/NOTICE/attribution obligations are discharged. Review actual shipped output and the relevant dependency terms before release.

Predecessor Security run 34682687378, dependency-review job 103524153573, fails closed at the exact base/head compare with HTTP 403 and curl exit 0. Canonical incident: ContextualWisdomLab/.github#810. Successful OSV/Trivy/Scorecard or the presence of an SBOM cannot substitute for Dependency Review or the independent approval required by live branch protection. No issue close, protection change or synthetic status is authorized by this update.

Original problem and locked-version evidence — historical

At PolicyWeave PR #11 exact head b8171c9019dfbbd92c5d6ad71a0160bd8bfb11ee, package.json and the root package entry in package-lock.json used mutable latest declarations. The lock made npm ci reproducible for that tree, but manifest regeneration remained open to unreviewed major-version and license/provenance changes.

The manifest also placed @vitejs/plugin-react, typescript, and vite in runtime dependencies, although they are build/toolchain responsibilities for this static browser product.

The original locked-resolution evidence for those declarations was:

  • runtime group before correction: @vitejs/plugin-react@6.1.1, lucide-react@1.38.0, react@19.2.8, react-dom@19.2.8, vite@8.2.2;
  • development group: @eslint/js@10.0.1, @testing-library/jest-dom@7.0.1, @testing-library/react@16.3.3, @types/react@19.2.18, @types/react-dom@19.2.5, eslint@10.9.1, eslint-plugin-react-hooks@7.1.1, eslint-plugin-react-refresh@0.5.5, globals@17.11.0, jsdom@30.0.1, vitest@4.1.11.

The repository-level MIT grant does not relicense npm dependencies. Dependency-specific provenance/attribution is required, including license families such as BlueOak-1.0.0 already present in the lock.

Canonical repair contract — preserved

Use the existing product writer and preserve every valid prerequisite/foundation delta. The original PR #1–#11 stack has now integrated into develop; do not recreate it as a competing product tree or retire uncarried work.

  1. Add a RED manifest contract rejecting latest and build-only packages in runtime dependencies.
  2. Replace mutable declarations with explicit reviewed versions/ranges, beginning from locked evidence rather than silently upgrading.
  3. Move @vitejs/plugin-react, typescript and vite to devDependencies; verify other direct build-only responsibilities before changing them.
  4. Regenerate the lock from the corrected manifest and prove clean install, lint, unit tests, PostgreSQL contracts, production build and browser E2E at the same exact head.
  5. Produce/reconcile exact-head SBOM and license/provenance evidence. Fail closed on GPL/LGPL/AGPL, noncommercial, research-only, unknown or incompatible inbound components; never replace license review with a root MIT label.
  6. Update README, CHANGELOG, architecture/TRD and docs/product-technical-gap-baseline.md where the verified package and release boundary changes.

Exit evidence — unchanged

Completion requires the owner-side repair to be integrated through ordinary protection with exact-head checks, independent review, zero unresolved threads, immutable dependency/provenance evidence, and a consumer/release statement distinguishing application code from third-party obligations. An integrated side branch, a passing npm audit, optional/development scope or inventory metadata alone is not completion.

Historical PR #13 receipt — not current-head acceptance

PR #13 head eff7ec19f511cc5850f4fd1254f0a20d9c47fc9e pinned and classified the direct declarations. CI 34251045288 was terminal GREEN with separate browser/CycloneDX artifacts. It is historical evidence; that PR is now merged, not Draft/open.

The historical lock-entry inventory counted 267 package entries, including platform alternatives, rather than proving all 267 were installed together. Its recorded declared-license counts were MIT 200, Apache-2.0 21, MPL-2.0 14, ISC 13, BSD-2-Clause 8, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. Historical string-level screening found no GPL, LGPL, AGPL, SSPL, BUSL, Commons Clause, noncommercial or CC-BY-NC declaration.

That inventory is retained without promotion to compatibility approval. The recorded MPL-2.0 and CC-BY-4.0 development-toolchain transitive packages still require distribution/NOTICE/attribution and shipped-artifact review. Protected integration, qualifying approval and current organization Checks remain outstanding.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions