You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Restore authoritative Dependency Review evidence for PolicyWeave PR #1 #12
Canonical root writer remains PR #1, develop → protected main, at exact head 60fd7fb5c3177984a993102742bb16e36a909e2d; stacked PR #25 remains based on that exact head at af8c0da17cdfb4786867f4e85401dbbb811b581e.
PR feat: bootstrap PolicyWeave privacy policy workspace #1 exact-head CI 36241748023, SAST 36241747980, and CodeQL 36241747969 are terminal success. Required Security 36241747990 remains terminal failure because the authoritative base/head Dependency Review comparison returned HTTP 403 before the pinned action could run.
The canonical owner incident ContextualWisdomLab/.github#810 remains open and blocked. Its current exit criteria still require an authorized availability/configuration repair plus fresh HTTP 200 ordinary and stacked canaries; no released owner repair exists to consume.
The dependency pin, build-time placement, lock, and CycloneDX implementation described below is already present in the canonical writer history. This issue is deliberately kept open under its corrected title to track the remaining authoritative Dependency Review evidence and ordinary protected integration—not to recreate completed product-source work.
No blind rerun, lifecycle toggle, no-op commit, substitute scanner, synthetic status, protection weakening, merge, or issue closure was performed.
Exact-head security rerun — 2026-10-01
Required Security run 36241747990 was rerun without changing protected base 52f4fd6bb68f870d0519cf11dd471573a2f197c0 or PR #1 head 60fd7fb5c3177984a993102742bb16e36a909e2d. New dependency-review job 110221939186 reproduced the owner incident: authenticated exact-base/head compare returned HTTP 403, curl_exit=0; the pinned Dependency Review action was skipped and the required job failed closed. Scorecard, Trivy, and OSV passed again but do not replace the missing dependency diff.
The product source has no new repair delta for this owner-plane availability failure. PR #1 and this issue remain open/Draft pending ContextualWisdomLab/.github#810, a qualifying independent approval, and a fresh exact-head authoritative Dependency Review result. No gate weakening, synthetic success, issue closure, or merge is authorized.
Current integration state — 2026-09-30
The dependency pin/scope/SBOM repair from historical PR #13 is integrated into the product branch history. The canonical root writer remains PR #1, develop → protected main, exact head 60fd7fb5c3177984a993102742bb16e36a909e2d, tree 54c19ce3a7b46d8dda055bf778c6c7327fe8e0b9, protected base 52f4fd6bb68f870d0519cf11dd471573a2f197c0. Stacked Draft PR #25 is based on that unchanged head; it is not a replacement owner. PR #1 is Draft because required Security evidence is terminal-failing and qualifying approvals remain 0. This issue stays open; no valid delta is closed or retired.
Current exact-head CI 36241748023, Semgrep 36241747980, and CodeQL 36241747969 are terminal success. CI produced exact-head browser artifact 10913167115 (sha256:fdbe823578ce068ab23728f3835479ab8c689a51c68477704a777a0744bfb2a1) and exact-head CycloneDX artifact 10912873052 (sha256:4e06815ac5d0b6e128d8071fa18ca08ca707d153c2d1b684ab06d9bc44def2f7). Security 36241747990 is terminal failure: job 108815523383 verified the exact checkout, then the Dependency Review support request for the exact base/head returned HTTP 403, curl_exit=0; the pinned action was skipped and the workflow failed closed. Scorecard, Trivy and OSV success do not replace Dependency Review. All 17 inline threads are resolved, but there is no qualifying approval. Canonical owner incident: ContextualWisdomLab/.github#810.
Predecessor Direct-head CI 34682685358, attempt 1, job 103524109831, checked out the literal head f11fe7827160a5f54cc76101050c41f0c6e156f3 and completed successfully: clean install, lint, five local-preview pretests, 163 Vitest cases including dependency contracts, build, PostgreSQL 18.6 migration/concurrency/restart/restore and 23 browser passes plus 10 existing scoped skips.
The CycloneDX artifact 10294182797 is bound to that head with ZIP digest sha256:28fde2bad87569a4657119a708d42c2943fa52beec3ead42d0d3cf4e515ac39a. The ZIP was downloaded and its SHA-256 independently verified before parsing its single policyweave-dependency-sbom.cdx.json file.
CycloneDX 1.5 describes 244 installed components on that CI platform. Declared-license counts: MIT 186, Apache-2.0 21, ISC 13, BSD-2-Clause 8, MPL-2.0 5, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. No component lacks license metadata. The parsed inventory has no GPL/AGPL/SSPL license string. This is a scoped installed-component inventory, not the complete cross-platform lock graph and not a compatibility/legal approval.
The five MPL-2.0 components are @axe-core/playwright@4.13.0, axe-core@4.13.0, lightningcss@1.33.0, lightningcss-linux-x64-gnu@1.33.0 and lightningcss-linux-x64-musl@1.33.0; the CC-BY-4.0 component is caniuse-lite@1.0.30001810. Their SBOM optional scope must not be misread as proof that all distribution/NOTICE/attribution obligations are discharged. Review actual shipped output and the relevant dependency terms before release.
Predecessor Security run 34682687378, dependency-review job 103524153573, fails closed at the exact base/head compare with HTTP 403 and curl exit 0. Canonical incident: ContextualWisdomLab/.github#810. Successful OSV/Trivy/Scorecard or the presence of an SBOM cannot substitute for Dependency Review or the independent approval required by live branch protection. No issue close, protection change or synthetic status is authorized by this update.
Original problem and locked-version evidence — historical
At PolicyWeave PR #11 exact head b8171c9019dfbbd92c5d6ad71a0160bd8bfb11ee, package.json and the root package entry in package-lock.json used mutable latest declarations. The lock made npm ci reproducible for that tree, but manifest regeneration remained open to unreviewed major-version and license/provenance changes.
The manifest also placed @vitejs/plugin-react, typescript, and vite in runtime dependencies, although they are build/toolchain responsibilities for this static browser product.
The original locked-resolution evidence for those declarations was:
runtime group before correction: @vitejs/plugin-react@6.1.1, lucide-react@1.38.0, react@19.2.8, react-dom@19.2.8, vite@8.2.2;
The repository-level MIT grant does not relicense npm dependencies. Dependency-specific provenance/attribution is required, including license families such as BlueOak-1.0.0 already present in the lock.
Canonical repair contract — preserved
Use the existing product writer and preserve every valid prerequisite/foundation delta. The original PR #1–#11 stack has now integrated into develop; do not recreate it as a competing product tree or retire uncarried work.
Add a RED manifest contract rejecting latest and build-only packages in runtime dependencies.
Replace mutable declarations with explicit reviewed versions/ranges, beginning from locked evidence rather than silently upgrading.
Move @vitejs/plugin-react, typescript and vite to devDependencies; verify other direct build-only responsibilities before changing them.
Regenerate the lock from the corrected manifest and prove clean install, lint, unit tests, PostgreSQL contracts, production build and browser E2E at the same exact head.
Produce/reconcile exact-head SBOM and license/provenance evidence. Fail closed on GPL/LGPL/AGPL, noncommercial, research-only, unknown or incompatible inbound components; never replace license review with a root MIT label.
Update README, CHANGELOG, architecture/TRD and docs/product-technical-gap-baseline.md where the verified package and release boundary changes.
Exit evidence — unchanged
Completion requires the owner-side repair to be integrated through ordinary protection with exact-head checks, independent review, zero unresolved threads, immutable dependency/provenance evidence, and a consumer/release statement distinguishing application code from third-party obligations. An integrated side branch, a passing npm audit, optional/development scope or inventory metadata alone is not completion.
Historical PR #13 receipt — not current-head acceptance
PR #13 head eff7ec19f511cc5850f4fd1254f0a20d9c47fc9e pinned and classified the direct declarations. CI 34251045288 was terminal GREEN with separate browser/CycloneDX artifacts. It is historical evidence; that PR is now merged, not Draft/open.
The historical lock-entry inventory counted 267 package entries, including platform alternatives, rather than proving all 267 were installed together. Its recorded declared-license counts were MIT 200, Apache-2.0 21, MPL-2.0 14, ISC 13, BSD-2-Clause 8, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. Historical string-level screening found no GPL, LGPL, AGPL, SSPL, BUSL, Commons Clause, noncommercial or CC-BY-NC declaration.
That inventory is retained without promotion to compatibility approval. The recorded MPL-2.0 and CC-BY-4.0 development-toolchain transitive packages still require distribution/NOTICE/attribution and shipped-artifact review. Protected integration, qualifying approval and current organization Checks remain outstanding.
Fresh authority check — 2026-10-03
develop→ protectedmain, at exact head60fd7fb5c3177984a993102742bb16e36a909e2d; stacked PR #25 remains based on that exact head ataf8c0da17cdfb4786867f4e85401dbbb811b581e.36241748023, SAST36241747980, and CodeQL36241747969are terminal success. Required Security36241747990remains terminal failure because the authoritative base/head Dependency Review comparison returned HTTP 403 before the pinned action could run.Exact-head security rerun — 2026-10-01
Required Security run 36241747990 was rerun without changing protected base
52f4fd6bb68f870d0519cf11dd471573a2f197c0or PR #1 head60fd7fb5c3177984a993102742bb16e36a909e2d. New dependency-review job110221939186reproduced the owner incident: authenticated exact-base/head compare returnedHTTP 403,curl_exit=0; the pinned Dependency Review action was skipped and the required job failed closed. Scorecard, Trivy, and OSV passed again but do not replace the missing dependency diff.The product source has no new repair delta for this owner-plane availability failure. PR #1 and this issue remain open/Draft pending ContextualWisdomLab/.github#810, a qualifying independent approval, and a fresh exact-head authoritative Dependency Review result. No gate weakening, synthetic success, issue closure, or merge is authorized.
Current integration state — 2026-09-30
The dependency pin/scope/SBOM repair from historical PR #13 is integrated into the product branch history. The canonical root writer remains PR #1,
develop→ protectedmain, exact head60fd7fb5c3177984a993102742bb16e36a909e2d, tree54c19ce3a7b46d8dda055bf778c6c7327fe8e0b9, protected base52f4fd6bb68f870d0519cf11dd471573a2f197c0. Stacked Draft PR #25 is based on that unchanged head; it is not a replacement owner. PR #1 is Draft because required Security evidence is terminal-failing and qualifying approvals remain 0. This issue stays open; no valid delta is closed or retired.Current exact-head CI 36241748023, Semgrep 36241747980, and CodeQL 36241747969 are terminal success. CI produced exact-head browser artifact
10913167115(sha256:fdbe823578ce068ab23728f3835479ab8c689a51c68477704a777a0744bfb2a1) and exact-head CycloneDX artifact10912873052(sha256:4e06815ac5d0b6e128d8071fa18ca08ca707d153c2d1b684ab06d9bc44def2f7). Security 36241747990 is terminal failure: job108815523383verified the exact checkout, then the Dependency Review support request for the exact base/head returnedHTTP 403,curl_exit=0; the pinned action was skipped and the workflow failed closed. Scorecard, Trivy and OSV success do not replace Dependency Review. All 17 inline threads are resolved, but there is no qualifying approval. Canonical owner incident: ContextualWisdomLab/.github#810.Predecessor Direct-head CI 34682685358, attempt 1, job
103524109831, checked out the literal headf11fe7827160a5f54cc76101050c41f0c6e156f3and completed successfully: clean install, lint, five local-preview pretests, 163 Vitest cases including dependency contracts, build, PostgreSQL 18.6 migration/concurrency/restart/restore and 23 browser passes plus 10 existing scoped skips.The CycloneDX artifact 10294182797 is bound to that head with ZIP digest
sha256:28fde2bad87569a4657119a708d42c2943fa52beec3ead42d0d3cf4e515ac39a. The ZIP was downloaded and its SHA-256 independently verified before parsing its singlepolicyweave-dependency-sbom.cdx.jsonfile.CycloneDX 1.5 describes 244 installed components on that CI platform. Declared-license counts: MIT 186, Apache-2.0 21, ISC 13, BSD-2-Clause 8, MPL-2.0 5, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. No component lacks license metadata. The parsed inventory has no GPL/AGPL/SSPL license string. This is a scoped installed-component inventory, not the complete cross-platform lock graph and not a compatibility/legal approval.
The five MPL-2.0 components are
@axe-core/playwright@4.13.0,axe-core@4.13.0,lightningcss@1.33.0,lightningcss-linux-x64-gnu@1.33.0andlightningcss-linux-x64-musl@1.33.0; the CC-BY-4.0 component iscaniuse-lite@1.0.30001810. Their SBOMoptionalscope must not be misread as proof that all distribution/NOTICE/attribution obligations are discharged. Review actual shipped output and the relevant dependency terms before release.Predecessor Security run
34682687378, dependency-review job103524153573, fails closed at the exact base/head compare with HTTP 403 and curl exit 0. Canonical incident: ContextualWisdomLab/.github#810. Successful OSV/Trivy/Scorecard or the presence of an SBOM cannot substitute for Dependency Review or the independent approval required by live branch protection. No issue close, protection change or synthetic status is authorized by this update.Original problem and locked-version evidence — historical
At PolicyWeave PR #11 exact head
b8171c9019dfbbd92c5d6ad71a0160bd8bfb11ee,package.jsonand the root package entry inpackage-lock.jsonused mutablelatestdeclarations. The lock madenpm cireproducible for that tree, but manifest regeneration remained open to unreviewed major-version and license/provenance changes.The manifest also placed
@vitejs/plugin-react,typescript, andvitein runtimedependencies, although they are build/toolchain responsibilities for this static browser product.The original locked-resolution evidence for those declarations was:
@vitejs/plugin-react@6.1.1,lucide-react@1.38.0,react@19.2.8,react-dom@19.2.8,vite@8.2.2;@eslint/js@10.0.1,@testing-library/jest-dom@7.0.1,@testing-library/react@16.3.3,@types/react@19.2.18,@types/react-dom@19.2.5,eslint@10.9.1,eslint-plugin-react-hooks@7.1.1,eslint-plugin-react-refresh@0.5.5,globals@17.11.0,jsdom@30.0.1,vitest@4.1.11.The repository-level MIT grant does not relicense npm dependencies. Dependency-specific provenance/attribution is required, including license families such as BlueOak-1.0.0 already present in the lock.
Canonical repair contract — preserved
Use the existing product writer and preserve every valid prerequisite/foundation delta. The original PR #1–#11 stack has now integrated into
develop; do not recreate it as a competing product tree or retire uncarried work.latestand build-only packages in runtime dependencies.@vitejs/plugin-react,typescriptandvitetodevDependencies; verify other direct build-only responsibilities before changing them.docs/product-technical-gap-baseline.mdwhere the verified package and release boundary changes.Exit evidence — unchanged
Completion requires the owner-side repair to be integrated through ordinary protection with exact-head checks, independent review, zero unresolved threads, immutable dependency/provenance evidence, and a consumer/release statement distinguishing application code from third-party obligations. An integrated side branch, a passing npm audit, optional/development scope or inventory metadata alone is not completion.
Historical PR #13 receipt — not current-head acceptance
PR #13 head
eff7ec19f511cc5850f4fd1254f0a20d9c47fc9epinned and classified the direct declarations. CI 34251045288 was terminal GREEN with separate browser/CycloneDX artifacts. It is historical evidence; that PR is now merged, not Draft/open.The historical lock-entry inventory counted 267 package entries, including platform alternatives, rather than proving all 267 were installed together. Its recorded declared-license counts were MIT 200, Apache-2.0 21, MPL-2.0 14, ISC 13, BSD-2-Clause 8, BlueOak-1.0.0 4, BSD-3-Clause 3, MIT-0 2, CC-BY-4.0 1 and CC0-1.0 1. Historical string-level screening found no GPL, LGPL, AGPL, SSPL, BUSL, Commons Clause, noncommercial or CC-BY-NC declaration.
That inventory is retained without promotion to compatibility approval. The recorded MPL-2.0 and CC-BY-4.0 development-toolchain transitive packages still require distribution/NOTICE/attribution and shipped-artifact review. Protected integration, qualifying approval and current organization Checks remain outstanding.