Repository navigation
chore(licence): MPL-2.0 for code, CC-BY-SA-4.0 for prose - #74
Conversation
Owner ruling 2026-10-09: "mpl-2.0 code, and cc-by-sa-4.0 prose".
Applies docs/migrations/pmpl-to-mpl-sweep-runbook.adoc §5/§6 (standards) per file.
SPDX header PMPL-1.0-or-later -> MPL-2.0 (18 code/config files):
container/compose.example.toml
container/compose.toml
container/Containerfile
container/ct-build.sh
container/deploy.k9.ncl
container/entrypoint.sh
container/.gatekeeper.yaml
container/manifest.toml
container/vordr.toml
contractile.just
.devcontainer/Containerfile
.devcontainer/devcontainer.json
features/ssg/ssg-bootstrap.sh
.gitlab-ci.yml
Justfile
.machine_readable/contractiles/Justfile
.pre-commit-config.yaml
scripts/validate-template.sh
SPDX header MPL-2.0 -> CC-BY-SA-4.0 (30 prose files):
AUDIT.adoc
.claude/CLAUDE.md
container/README.adoc
.devcontainer/README.adoc
EXPLAINME.adoc
features/boj-server/README.adoc
features/panic-attacker/README.adoc
features/README.adoc
features/ssg/README.adoc
.machine_readable/README.adoc
MAINTAINERS.adoc
ROADMAP.adoc
src/aspects/integrity/README.adoc
src/aspects/observability/README.adoc
src/aspects/README.adoc
src/aspects/security/README.adoc
src/contracts/README.adoc
src/definitions/README.adoc
src/errors/README.adoc
src/interface/Abi/README.adoc
src/interface/ffi/README.adoc
src/interface/ffi/src/README.adoc
src/interface/ffi/test/README.adoc
src/interface/generated/abi/README.adoc
src/interface/generated/README.adoc
src/interface/README.adoc
src/README.adoc
TEMPLATE-STANDARDS-AUDIT.adoc
tools/invariant-path/README.adoc
www/.well-known/README.adoc
New CC-BY-SA-4.0 header (16 unlabelled .adoc files):
.claude/PROJECT.adoc
ARCHITECTURE.adoc
CHANGELOG.adoc
GOVERNANCE.adoc
PROOF-NEEDS.adoc
PROOF-STATUS.adoc
READINESS.adoc
README.adoc
SECURITY.adoc
TEST-NEEDS.adoc
TOPOLOGY.adoc
docs/reports/audit/audit-2026-04-15-post.adoc
docs/tech-debt-2026-05-26.adoc
llm-warmup-dev.adoc
llm-warmup-user.adoc
session/README.adoc
New MPL-2.0 header (4 unlabelled shell scripts):
.machine_readable/scripts/forge/git-cleanup.sh
scripts/invariant-path.sh
session/dispatch.sh
session/local-hooks.sh
Licence rule text updated to the two-tier rule:
.github/copilot-instructions.md
.github/GOVERNANCE.md
.github/pull_request_template.md
.machine_readable/ai/{.clinerules,.cursorrules,.windsurfrules,PLACEHOLDERS.adoc}
.machine_readable/compliance/reuse/dep5 (prose stanza added; .a2ml stanza kept to match those headers)
Justfile, .machine_readable/contractiles/Justfile ({{LICENSE}} -> MPL-2.0)
QUICKSTART-MAINTAINER.adoc
TEST-NEEDS.adoc
docs/practice/AI-CONVENTIONS.adoc
llm-warmup-dev.adoc
llm-warmup-user.adoc
stapeln.toml
docs/attribution/CITATION.cff
docs/attribution/CITATIONS.adoc
www/.well-known/ai.txt (PMPL "Emotional Lineage" line removed)
www/.well-known/humans.txt
Removed tracked duplicates (31 files; every difference was a licence header):
www/.well-known/.well-known/ (3)
verification/verification/ (28; its README title and copyright line moved
into verification/README.adoc)
Kept, deliberately:
- every .a2ml header (A2ML is retired; the deed migration owns them)
- .machine_readable/.machine_readable/ (nested copy; owner decision pending)
- docs/legal/EXHIBIT-{A,B}-*.txt (licence exhibit text)
- www/.well-known/{ai,humans,security}.txt stay MPL-2.0 (machine-read data)
- CODE_OF_CONDUCT.adoc (adapted from the Contributor Covenant; not relabelled)
- LICENSE, LICENSES/, .machine_readable/compliance/rust/deny.toml
- history: docs/tech-debt-2026-05-26.adoc body, docs/decisions/0001-*,
docs/STATE-VISUALIZER.adoc, docs/RSR_OUTLINE.adoc
- k9 example bodies, contractile.just:65, Justfile:224/:1057 (licence-file tooling)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (2)
📒 Files selected for processing (82)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔍 Hypatia Security ScanFindings: 59 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
"type": "scorecard_wrapper_missing_job_permissions",
"file": ".github/workflows/scorecard.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_job_level_scorecard_perms"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
The parent commit also deleted two tracked nested copies, verification/verification/ (28 files) and www/.well-known/.well-known/ (3 files). Those deletions are not part of the licence change, and they took this PR to 115 files, over CodeRabbit's 100-file review limit. This commit restores both trees exactly as they are on main (589e1be). A separate PR deletes them. After this commit the PR changes 84 files, all modified and none deleted, so the squash commit contains only the licence change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
🔍 Hypatia Security ScanFindings: 59 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
"type": "scorecard_wrapper_missing_job_permissions",
"file": ".github/workflows/scorecard.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_job_level_scorecard_perms"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
## Summary This removes two tracked duplicate trees, each nested inside the directory it copies: `verification/verification/` and `www/.well-known/.well-known/`. The removal was first part of the licence PR #74. It moved here so that #74 contains only the licence change and stays under CodeRabbit's 100-file review limit. The two PRs change no file in common, so they can merge in either order. ## Changes - **Deleted `verification/verification/`** (28 files), a copy of `verification/`. - **Deleted `www/.well-known/.well-known/`** (3 files), a copy of `www/.well-known/`. - Nothing else changes. 30 of the 31 files match their outer copy line for line, apart from SPDX and copyright lines. 15 of them carry the retired PMPL header. The 31st, `verification/verification/README.adoc`, also has a title line, `= Verification Pillar`. #74 adds that title and the copyright line to the outer `verification/README.adoc`. If this PR merges first, the outer README simply lacks the title until #74 lands; no content is lost. ## 📌 New pins - **Head SHA: `31fd364ba67f7497c715599b47cbb518357c76bb`** - None. No action `uses:`, `actions.lock`, lockfile or container digest is added or changed. ## RSR Quality Checklist ### Required - [ ] Tests pass: n/a. Only duplicate copies are deleted; no source, proof or test that is built or run changes. - [ ] Code is formatted: n/a, nothing is added. - [x] Linter is clean: no file is added or edited. - [x] No banned language patterns: nothing is added. - [ ] No `unsafe` blocks: n/a, no Rust changed. - [ ] No banned functions: n/a, no source or proofs added. - [ ] SPDX license headers: n/a, the PR only deletes files. - [x] No secrets or credentials. ### As Applicable - [ ] `.machine_readable/*.a2ml` updated: no. A2ML is retired. 9 of the deleted files are `.a2ml` duplicates (`verification/verification/0.1-AI-MANIFEST.a2ml` and one `0.2-AI-MANIFEST.a2ml` in each of its 8 subdirectories). Their outer copies are unchanged. - [ ] Documentation updated: n/a, no document refers to the deleted paths except the signed historical record below. - [ ] `TOPOLOGY.md`: n/a. - [ ] `CHANGELOG`: not updated, since only duplicates are removed. - [ ] New dependencies: none. - [ ] ABI/FFI: n/a. ## Testing - **Each deleted file was compared with its outer copy**, ignoring SPDX lines, copyright lines and bare `<!--` / `-->` lines. Result: 30 files have no difference. `verification/verification/README.adoc` differs only by its title line, which is described above. - Positive control: a copy of `verification/verification/proofs/0.2-AI-MANIFEST.a2ml` with one planted line reported 1 differing line. - Limit: the comparison is line-based. It shows that the outer copy keeps every non-licence line of the inner one. It says nothing about which licence header is correct, which is #74's subject. - **No dangling references:** `git grep -nE 'verification/verification|\.well-known/\.well-known' origin/main` matches only `docs/AFFIRMATION.adoc:213-214`, the signed affirmation that records this duplicate. It is left unchanged. - **No overlap with #74:** `comm -12` of the two PRs' file lists is empty. ## Red checks on this head - `governance / Actions lockfile verify` is red on `main` (`589e1be`) as well. It is fixed by #73 together with hyperpolymath/standards#1209, and this PR does not touch it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…facts (#77) ## Summary This carries out four owner decisions of 2026-10-09 that #74 and #76 left open: 1. **Delete the nested `.machine_readable/.machine_readable/` copy** (75 files), after checking its diverging files for anything worth keeping. 2. **Keep `.github/FUNDING.yml` (`github: hyperpolymath`) and delete `.github/funding.yml` (`github: metadatastician`).** 3. **Delete the unused `LICENSES/AGPL-3.0-or-later.txt`.** 4. **Delete the two PMPL exhibits in `docs/legal/`** and fix the three files that refer to them. It changes no file that #73, #74 or #76 changes in a conflicting way. `git merge-tree` against each of their heads is clean (see Testing), so the four PRs can merge in any order. ## Changes - **Deleted `.machine_readable/.machine_readable/`** (75 files). #40 (`cc60f66`) added it in a single commit. 53 of its files contain PMPL text. 17 differ from their outer copy beyond SPDX and copyright lines, and 3 exist only inside it: - **The 5 non-A2ML files are rattlescript-era template residue.** They name `rattlescript`, `k9-svc` and `.machine_readable/contractiles/k9/`, where the outer copies name `jaffascript` and `self-validating`. The files are `README.adoc`, `ai/PLACEHOLDERS.adoc`, `configs/git-cliff/cliff.toml`, `contractiles/self-validating/README.adoc` and `contractiles/self-validating/examples/setup-repo.k9.ncl`. - **The only content among those 5 that the outer copy lacked** was the README's title (`= .machine_readable Pillar`) and copyright line. Both are now appended to `.machine_readable/README.adoc`, after its existing comment lines. - **12 A2ML files diverge.** 2 of them name rattlescript, and 10 name neither repo. The 3 inner-only files are `ECOSYSTEM.a2ml`, `META.a2ml` and `STATE.a2ml` in the old root layout. A2ML is retired, so all of them go with the tree. Every outer A2ML file is unchanged. - **Deleted `.github/funding.yml`.** It differs from `.github/FUNDING.yml` only in letter case, so the two collide on a case-insensitive checkout (Windows, macOS). `FUNDING.yml` stays: `github`, `ko_fi` and `liberapay` all name `hyperpolymath`. - **Deleted `LICENSES/AGPL-3.0-or-later.txt`.** No file in the repo is AGPL-licensed. Every AGPL mention is a rule against it, or the deny list in `.machine_readable/compliance/rust/deny.toml`, which is kept. `LICENSES/` now holds `MPL-2.0.txt` and `CC-BY-SA-4.0.txt`. - **Deleted `docs/legal/EXHIBIT-A-ETHICAL-USE.txt` and `docs/legal/EXHIBIT-B-QUANTUM-SAFE.txt`**, the PMPL exhibits. Their references are fixed: - **`Justfile` and `.machine_readable/contractiles/Justfile`** (still byte-identical): `validate-rsr` now checks for `LICENSES/MPL-2.0.txt` and `LICENSES/CC-BY-SA-4.0.txt`. Before, it checked `licensing/exhibits/EXHIBIT-{A,B}-*.txt` and `licensing/texts/PMPL-1.0-or-later.txt`, under a `licensing/` directory that does not exist, so it always reported all three as missing. - **`docs/RSR_OUTLINE.adoc`**: the two exhibit rows in the file table and the two exhibit lines in the tree are replaced by one `LICENSES/` entry. The three places that described `LICENSE` as PMPL-1.0-or-later now say MPL-2.0, which is what `LICENSE` already contains on `main`. The rest of this template outline is untouched; its other stale claims are listed below. ### Not changed - `docs/legal/0.2-AI-MANIFEST.a2ml`, the remaining file in `docs/legal/`. It does not refer to the exhibits. - `docs/governance/MAINTENANCE-CHECKLIST.adoc:119`. It names `docs/legal/` as a folder, which still exists. - `LICENSE` and `LICENSES/MPL-2.0.txt`. Their "Exhibit A/B" text is the MPL-2.0 licence's own exhibits, not the PMPL files. - **Other stale claims in `docs/RSR_OUTLINE.adoc`**: the Palimpsest badges on line 5, ReScript listed as Tier 1, `guix.scm` OR `flake.nix`, "Python outside `salt/`" and "npm, Bun, pnpm, yarn (use Deno)", which contradicts the estate's Bun-only rule. They are left for a separate change, because this PR only fixes the references to the deleted files. ## 📌 New pins - **Head SHA: `da27c4fa1ee2368fcb32f0a3e4609aefa9a3b260`** - None. No action `uses:`, `actions.lock`, lockfile or container digest is added or changed. ## RSR Quality Checklist ### Required - [ ] Tests pass: n/a. No source, proof or test is changed. `validate-rsr` was run before and after; see Testing. - [ ] Code is formatted: n/a. The only code edit is one `for` line in each Justfile, and `just --summary` parses both. - [x] Linter is clean: standards `scripts/check-licence-consistency.sh` exits 0 (see Testing). - [x] No banned language patterns: nothing is added. - [ ] No `unsafe` blocks: n/a, no Rust changed. - [ ] No banned functions: n/a, no source or proofs changed. - [x] SPDX license headers present: each of the 4 edited files keeps its existing header. No file is added. - [x] No secrets or credentials. ### As Applicable - [ ] `.machine_readable/STATE.a2ml` / `ECOSYSTEM.a2ml` / `META.a2ml` updated: no. A2ML is retired, and the outer A2ML files are unchanged. - [x] Documentation updated: `docs/RSR_OUTLINE.adoc` and `.machine_readable/README.adoc`. - [ ] `TOPOLOGY.md`: n/a, the architecture is unchanged. - [ ] `CHANGELOG`: not updated, since only duplicates and unused licence files are removed. - [ ] New dependencies: none. - [ ] ABI/FFI: n/a. ## Testing All checks ran on this head `da27c4f` against `main` at `589e1be`. - **File list:** `git diff --name-status origin/main HEAD` shows 79 `D` and 4 `M` (the two Justfiles, `docs/RSR_OUTLINE.adoc` and `.machine_readable/README.adoc`). It shows no `A`. - **No dangling references:** `git grep -nIE '\.machine_readable/\.machine_readable|funding\.yml|AGPL-3\.0-or-later\.txt|EXHIBIT-[AB]|licensing/(exhibits|texts)'` on this head matches nothing. The same pattern matches a planted line, so it can find these paths. - **`validate-rsr`**, run with `just --justfile Justfile validate-rsr` because the root also holds a lowercase `justfile` (see below): - On `main` it reports 6 missing paths: the 3 exhibit and PMPL paths, and 3 old-layout A2ML paths. - On this head it reports only the 3 A2ML paths (`.machine_readable/{STATE,META,ECOSYSTEM}.a2ml`). They are missing on `main` too, and this PR does not touch them. - Positive control: with `LICENSES/CC-BY-SA-4.0.txt` removed from a copy of this head, it also reports `LICENSES/CC-BY-SA-4.0.txt` as missing. - No workflow under `.github/` runs `validate-rsr`. - **Standards `scripts/check-licence-consistency.sh`**, run from the standards clone at `1ffe86b3`: exit 0 on both `main` and this head. Its warning lines drop from 107 to 56, because the nested tree's PMPL headers are gone. - **AsciiDoc:** `asciidoctor --failure-level=WARN` reports no warnings on either edited `.adoc`, before or after. The README title parses as `.machine_readable Pillar`. The first table in `RSR_OUTLINE.adoc` goes from 21 rows to 20 and stays at 2 columns. - **No conflict with open PRs:** `git merge-tree --write-tree` of this head with #73 (`0bee4f4`), #74 (`97377c5`) and #76 (`31fd364`) exits 0 for each. Positive control: a planted conflicting edit to `.machine_readable/README.adoc` makes it exit 1. - **Docstrings:** standards `.githooks/docstring-scan.sh --range origin/main..HEAD --check` finds 0 touched functions. - **Code-scanning alerts this PR introduces**, checked by hand because `squabble verify-satisfied` does not evaluate them yet. Open alerts were keyed on (rule, path), for `refs/pull/77/merge` against `refs/heads/main`: 32 against 44. The PR-minus-main set is empty. Control: main-minus-PR has 12 keys (Scorecard, plus Hypatia CSA001/CSA003), which shows the diff can find a difference. ### Found while doing this, not fixed here The repo root holds both **`Justfile`** (the RSR template, 1,545 lines) and **`justfile`** (jaffascript's own 29-line runner for `affinescript check/run/build --face jaffa`). As a result, a bare `just` in the root fails with "multiple candidate justfiles", and on a case-insensitive checkout one file overwrites the other. Merging them needs an owner decision, so this PR leaves them alone. ## Red checks on this head All 27 check-runs (paginated) and both legacy statuses had reported at 2026-10-09T00:00Z. - `governance / Actions lockfile verify` is red on `main` (`589e1be`) as well. It is fixed by #73 together with hyperpolymath/standards#1209, and this PR does not touch it. - Every other check-run is green: 20 `github-actions` runs, CodeQL, Hypatia, SonarCloud, CodeFactor, GitGuardian and Semgrep. The only required context, `scan / gitleaks`, is green. - Statuses: CodeRabbit reports "Review rate limited", so it gave no review (it never blocks). Codeac reports "1 errors and 4 warnings" with state `success`, the same as on `main` `589e1be`. ## Screenshots n/a, no UI change. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
🔍 Hypatia Security ScanFindings: 59 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
"type": "scorecard_wrapper_missing_job_permissions",
"file": ".github/workflows/scorecard.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_job_level_scorecard_perms"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |



Summary
This puts jaffascript on the two-tier licence rule: MPL-2.0 for code, CC-BY-SA-4.0 for prose.
This relicenses existing files, at the owner's direction. The owner's instruction (2026-10-09) was "mpl-2.0 code, and cc-by-sa-4.0 prose". The edits follow standards
docs/migrations/pmpl-to-mpl-sweep-runbook.adoc§5 and §6: every file was opened and changed individually from an explicit list, and only a file's own SPDX declaration was flipped. There was no bulk substitution. The runbook makes owner sign-off on the per-repo change-list the hard gate, so this PR is held for the owner's merge: auto-merge is not armed. The full list is below.This PR's first commit also deleted two nested duplicate trees. That removal is now its own PR, #76, so this PR contains only the licence change and fits CodeRabbit's 100-file limit. The two PRs change no file in common.
Changes
verification/README.adocalso gains the title (= Verification Pillar) and copyright line of its nested copy, which chore: remove nested duplicate trees #76 deletes..adocfiles had no SPDX header and now carryCC-BY-SA-4.0.README.adocis one of them: its onlySPDX-License-Identifiertext was in body prose at line 138, not a header.MPL-2.0, on line 2 after the shebang. Their modes are unchanged andbash -npasses on each..github/copilot-instructions.md,.github/GOVERNANCE.mdfooter,.github/pull_request_template.md,.machine_readable/ai/.clinerules,.machine_readable/ai/.cursorrules,.machine_readable/ai/.windsurfrules,.machine_readable/ai/PLACEHOLDERS.adoc,docs/practice/AI-CONVENTIONS.adoc,QUICKSTART-MAINTAINER.adoc,TEST-NEEDS.adoc,llm-warmup-{dev,user}.adoc.stapeln.toml,docs/attribution/CITATION.cff,docs/attribution/CITATIONS.adocandwww/.well-known/humans.txtnow name MPL-2.0.www/.well-known/ai.txtstates both licences. The line "AI agents must preserve Emotional Lineage per PMPL Section 3" is gone, because PMPL no longer applies.{{LICENSE}}placeholder in the template-substitution recipe, in bothJustfileand.machine_readable/contractiles/Justfile, now becomesMPL-2.0..machine_readable/compliance/reuse/dep5(an unconsumed template):*.adoc *.mdstanza assigns CC-BY-SA-4.0. In dep5 the last matching stanza wins..machine_readable/*.a2mlstanza still says PMPL, to match those files' headers (see "Kept").Kept deliberately (runbook §6)
.a2mlheader. A2ML is retired, and the deed migration owns those files. The licence check lists them as warnings, and that is expected.verification/verification/andwww/.well-known/.well-known/keep their old headers here (15 PMPL), because chore: remove nested duplicate trees #76 deletes both trees..machine_readable/.machine_readable/, a nested copy of 75 files. The owner decided to delete it, and chore: remove nested .machine_readable copy and leftover licence artefacts #77 does.LICENSE(already the verbatim MPL-2.0 text) andLICENSES/. chore: remove nested .machine_readable copy and leftover licence artefacts #77 deletes the unusedLICENSES/AGPL-3.0-or-later.txtand the two PMPL exhibitsdocs/legal/EXHIBIT-{A,B}-*.txt.CODE_OF_CONDUCT.adoc, which is adapted from the Contributor Covenant and so was not relabelled.www/.well-known/{ai,humans,security}.txtkeep their MPL-2.0 header, because they are machine-read data rather than prose.docs/tech-debt-2026-05-26.adoc(body),docs/decisions/0001-*,docs/STATE-VISUALIZER.adoc,docs/RSR_OUTLINE.adoc,.machine_readable/compliance/rust/deny.toml, the k9 example bodies,contractile.just:65, andJustfile:224/:1057(licence-file tooling). chore: remove nested .machine_readable copy and leftover licence artefacts #77 updatesdocs/RSR_OUTLINE.adoc's description ofLICENSEand theJustfile:1057check, because both referred to the exhibits it deletes. Its changes merge cleanly with this PR.Full change-list (69 files relabelled)
PMPL-1.0-or-later → MPL-2.0
container/compose.example.tomlcontainer/compose.tomlcontainer/Containerfilecontainer/ct-build.shcontainer/deploy.k9.nclcontainer/entrypoint.shcontainer/.gatekeeper.yamlcontainer/manifest.tomlcontainer/vordr.tomlcontractile.just.devcontainer/Containerfile.devcontainer/devcontainer.jsonfeatures/ssg/ssg-bootstrap.sh.gitlab-ci.ymlJustfile.machine_readable/contractiles/Justfile.pre-commit-config.yamlscripts/validate-template.shMPL-2.0 → CC-BY-SA-4.0
AUDIT.adoc.claude/CLAUDE.mdcontainer/README.adoc.devcontainer/README.adocEXPLAINME.adocfeatures/boj-server/README.adocfeatures/panic-attacker/README.adocfeatures/README.adocfeatures/ssg/README.adoc.machine_readable/README.adocMAINTAINERS.adocROADMAP.adocsrc/aspects/integrity/README.adocsrc/aspects/observability/README.adocsrc/aspects/README.adocsrc/aspects/security/README.adocsrc/contracts/README.adocsrc/definitions/README.adocsrc/errors/README.adocsrc/interface/Abi/README.adocsrc/interface/ffi/README.adocsrc/interface/ffi/src/README.adocsrc/interface/ffi/test/README.adocsrc/interface/generated/abi/README.adocsrc/interface/generated/README.adocsrc/interface/README.adocsrc/README.adocTEMPLATE-STANDARDS-AUDIT.adoctools/invariant-path/README.adocverification/README.adocwww/.well-known/README.adocNew CC-BY-SA-4.0 header
.claude/PROJECT.adocARCHITECTURE.adocCHANGELOG.adocGOVERNANCE.adocPROOF-NEEDS.adocPROOF-STATUS.adocREADINESS.adocREADME.adocSECURITY.adocTEST-NEEDS.adocTOPOLOGY.adocdocs/reports/audit/audit-2026-04-15-post.adocdocs/tech-debt-2026-05-26.adocllm-warmup-dev.adocllm-warmup-user.adocsession/README.adocNew MPL-2.0 header
.machine_readable/scripts/forge/git-cleanup.shscripts/invariant-path.shsession/dispatch.shsession/local-hooks.sh📌 New pins
97377c577ca4c75d6a86e3dfe524a4efb26ebad6uses:,actions.lock, lockfile or container digest is added or changed.RSR Quality Checklist
Required
bash -npasses on all four.scripts/check-licence-consistency.shpasses (see Testing).unsafeblocks: n/a, no Rust changed.docs/attribution/CITATION.cffcarries its licence in itslicense:field, and.machine_readable/compliance/reuse/dep5is itself a licence declaration. Neither had a header before this PR.As Applicable
.machine_readable/*.a2mlupdated: no. A2ML is retired, and its headers are left for the deed migration.TOPOLOGY.md: n/a, the architecture is unchanged.CHANGELOG: not updated. The relicence is recorded in this PR and in the commit message, which lists every file.Testing
scripts/check-licence-consistency.sh(the governance "Licence consistency" job), run locally on this head97377c5from the standards clone at1ffe86b3: exit 0. It lists the kept.a2mlheaders and the 15 PMPL headers in the two nested trees as warnings, which is expected.a1c7c57: I planted aCargo.tomldeclaringPMPL-1.0-or-laterin a copy of the tree. The script reportedLicence-vs-manifest mismatchand exited 1. With the plant removed it exited 0 again.*.ipkg,*.cabaland similar files. jaffascript has none of them, and the check does not readstapeln.toml. Planting PMPL instapeln.tomlstill exited 0, so that file's licence was checked by hand.SPDX-License-Identifierline is in one of the 21 files named under Changes (the rule text, the declared metadata,ai.txt, the two Justfiles,dep5andverification/README.adoc). Measured withgit diff origin/main HEAD, counting^[-+]lines withoutSPDX-License-Identifierper file.97377c5is exact: after it,git diff --name-status origin/main HEADlists 84 files, allM, with noDorA..github/workflows/*, and this PR changes no workflow.Red checks on this head
governance / Actions lockfile verifyis red onmain(589e1be) as well. It is fixed by ci: restore block YAML so the actions-lock gate can read the pins #73 together with fix(governance): make the actions-lock ledger reachable under bash -e standards#1209, and this PR does not touch it.Hypatia(code scanning) fails because this PR edits both Justfiles, so their open alerts count as "in code changed by this pull request". The alerts predate this PR, with the same alert numbers onmain, and the check is not required. Deferred to CI: Hypatia SD024 + npx alerts on both Justfiles (deferred from #74) #75, which has acceptance criteria.🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf