Repository navigation
chore: remove nested .machine_readable copy and leftover licence artefacts - #77
Merged
hyperpolymath merged 2 commits intoOct 9, 2026
Conversation
…facts Owner decisions of 2026-10-09: - Delete .machine_readable/.machine_readable/ (75 files), a nested copy of .machine_readable/ that #40 (cc60f66) added in one commit. 17 of its files differ from their outer copy beyond licence lines: - The 5 non-A2ML ones are rattlescript-era template residue: they name rattlescript, k9-svc and .machine_readable/contractiles/k9/, where the outer copies name jaffascript and self-validating. The only content among them that the outer copy lacks is the README's title and copyright line, which move to .machine_readable/README.adoc. - Of the 12 A2ML ones, 2 name rattlescript and 10 name neither repo. A2ML is retired, so they go with the tree; the outer A2ML copies are unchanged. - Delete .github/funding.yml (github: metadatastician). It collides with .github/FUNDING.yml (github: hyperpolymath) on a case-insensitive checkout; FUNDING.yml is kept. - Delete LICENSES/AGPL-3.0-or-later.txt. No file is AGPL-licensed; the repo's only AGPL mentions forbid it. - Delete docs/legal/EXHIBIT-A-ETHICAL-USE.txt and EXHIBIT-B-QUANTUM-SAFE.txt, the PMPL exhibits. validate-rsr in both Justfiles now checks LICENSES/MPL-2.0.txt and LICENSES/CC-BY-SA-4.0.txt instead of the exhibits and the PMPL text (it looked under licensing/, which does not exist). docs/RSR_OUTLINE.adoc lists LICENSES/ in place of the exhibits and describes LICENSE as MPL-2.0, which it already is. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (83)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5 of 14 tasks
🔍 Hypatia Security ScanFindings: 59 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
"type": "scorecard_wrapper_missing_job_permissions",
"file": ".github/workflows/scorecard.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_job_level_scorecard_perms"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
hyperpolymath
enabled auto-merge (squash)
October 9, 2026 00:24
|
hyperpolymath
deleted the
claude/remove-nested-machine-readable-and-pmpl-exhibits
branch
October 9, 2026 00:25
🔍 Hypatia Security ScanFindings: 59 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
"type": "scorecard_wrapper_missing_job_permissions",
"file": ".github/workflows/scorecard.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_job_level_scorecard_perms"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
hyperpolymath
added a commit
that referenced
this pull request
Oct 9, 2026
## Summary This puts jaffascript on the two-tier licence rule: **MPL-2.0 for code, CC-BY-SA-4.0 for prose**. **This relicenses existing files, at the owner's direction.** The owner's instruction (2026-10-09) was "mpl-2.0 code, and cc-by-sa-4.0 prose". The edits follow standards `docs/migrations/pmpl-to-mpl-sweep-runbook.adoc` §5 and §6: every file was opened and changed individually from an explicit list, and only a file's own SPDX declaration was flipped. There was no bulk substitution. The runbook makes owner sign-off on the per-repo change-list the hard gate, so **this PR is held for the owner's merge**: auto-merge is not armed. The full list is below. This PR's first commit also deleted two nested duplicate trees. That removal is now its own PR, #76, so this PR contains only the licence change and fits CodeRabbit's 100-file limit. The two PRs change no file in common. ## Changes - **18 code/config files: PMPL-1.0-or-later → MPL-2.0** (SPDX header only). - **31 prose files: MPL-2.0 → CC-BY-SA-4.0.** 30 change only the SPDX header. `verification/README.adoc` also gains the title (`= Verification Pillar`) and copyright line of its nested copy, which #76 deletes. - **16 `.adoc` files had no SPDX header and now carry `CC-BY-SA-4.0`.** `README.adoc` is one of them: its only `SPDX-License-Identifier` text was in body prose at line 138, not a header. - **4 shell scripts had no SPDX header and now carry `MPL-2.0`**, on line 2 after the shebang. Their modes are unchanged and `bash -n` passes on each. - **The licence rule text now states the two-tier rule** in every place that states it: `.github/copilot-instructions.md`, `.github/GOVERNANCE.md` footer, `.github/pull_request_template.md`, `.machine_readable/ai/.clinerules`, `.machine_readable/ai/.cursorrules`, `.machine_readable/ai/.windsurfrules`, `.machine_readable/ai/PLACEHOLDERS.adoc`, `docs/practice/AI-CONVENTIONS.adoc`, `QUICKSTART-MAINTAINER.adoc`, `TEST-NEEDS.adoc`, `llm-warmup-{dev,user}.adoc`. - **Declared metadata:** `stapeln.toml`, `docs/attribution/CITATION.cff`, `docs/attribution/CITATIONS.adoc` and `www/.well-known/humans.txt` now name MPL-2.0. - **`www/.well-known/ai.txt`** states both licences. The line "AI agents must preserve Emotional Lineage per PMPL Section 3" is gone, because PMPL no longer applies. - **The `{{LICENSE}}` placeholder** in the template-substitution recipe, in both `Justfile` and `.machine_readable/contractiles/Justfile`, now becomes `MPL-2.0`. - **`.machine_readable/compliance/reuse/dep5`** (an unconsumed template): - The code stanzas now say MPL-2.0. - A final `*.adoc *.md` stanza assigns CC-BY-SA-4.0. In dep5 the last matching stanza wins. - The `.machine_readable/*.a2ml` stanza still says PMPL, to match those files' headers (see "Kept"). ### Kept deliberately (runbook §6) - **Every `.a2ml` header.** A2ML is retired, and the deed migration owns those files. The licence check lists them as warnings, and that is expected. - **`verification/verification/` and `www/.well-known/.well-known/`** keep their old headers here (15 PMPL), because #76 deletes both trees. - **`.machine_readable/.machine_readable/`**, a nested copy of 75 files. The owner decided to delete it, and #77 does. - **`LICENSE`** (already the verbatim MPL-2.0 text) and **`LICENSES/`**. #77 deletes the unused `LICENSES/AGPL-3.0-or-later.txt` and the two PMPL exhibits `docs/legal/EXHIBIT-{A,B}-*.txt`. - **`CODE_OF_CONDUCT.adoc`**, which is adapted from the Contributor Covenant and so was not relabelled. - **`www/.well-known/{ai,humans,security}.txt`** keep their MPL-2.0 header, because they are machine-read data rather than prose. - **History and policy text that names PMPL as a fact:** `docs/tech-debt-2026-05-26.adoc` (body), `docs/decisions/0001-*`, `docs/STATE-VISUALIZER.adoc`, `docs/RSR_OUTLINE.adoc`, `.machine_readable/compliance/rust/deny.toml`, the k9 example bodies, `contractile.just:65`, and `Justfile:224`/`:1057` (licence-file tooling). #77 updates `docs/RSR_OUTLINE.adoc`'s description of `LICENSE` and the `Justfile:1057` check, because both referred to the exhibits it deletes. Its changes merge cleanly with this PR. <details><summary>Full change-list (69 files relabelled)</summary> **PMPL-1.0-or-later → MPL-2.0** - `container/compose.example.toml` - `container/compose.toml` - `container/Containerfile` - `container/ct-build.sh` - `container/deploy.k9.ncl` - `container/entrypoint.sh` - `container/.gatekeeper.yaml` - `container/manifest.toml` - `container/vordr.toml` - `contractile.just` - `.devcontainer/Containerfile` - `.devcontainer/devcontainer.json` - `features/ssg/ssg-bootstrap.sh` - `.gitlab-ci.yml` - `Justfile` - `.machine_readable/contractiles/Justfile` - `.pre-commit-config.yaml` - `scripts/validate-template.sh` **MPL-2.0 → CC-BY-SA-4.0** - `AUDIT.adoc` - `.claude/CLAUDE.md` - `container/README.adoc` - `.devcontainer/README.adoc` - `EXPLAINME.adoc` - `features/boj-server/README.adoc` - `features/panic-attacker/README.adoc` - `features/README.adoc` - `features/ssg/README.adoc` - `.machine_readable/README.adoc` - `MAINTAINERS.adoc` - `ROADMAP.adoc` - `src/aspects/integrity/README.adoc` - `src/aspects/observability/README.adoc` - `src/aspects/README.adoc` - `src/aspects/security/README.adoc` - `src/contracts/README.adoc` - `src/definitions/README.adoc` - `src/errors/README.adoc` - `src/interface/Abi/README.adoc` - `src/interface/ffi/README.adoc` - `src/interface/ffi/src/README.adoc` - `src/interface/ffi/test/README.adoc` - `src/interface/generated/abi/README.adoc` - `src/interface/generated/README.adoc` - `src/interface/README.adoc` - `src/README.adoc` - `TEMPLATE-STANDARDS-AUDIT.adoc` - `tools/invariant-path/README.adoc` - `verification/README.adoc` - `www/.well-known/README.adoc` **New CC-BY-SA-4.0 header** - `.claude/PROJECT.adoc` - `ARCHITECTURE.adoc` - `CHANGELOG.adoc` - `GOVERNANCE.adoc` - `PROOF-NEEDS.adoc` - `PROOF-STATUS.adoc` - `READINESS.adoc` - `README.adoc` - `SECURITY.adoc` - `TEST-NEEDS.adoc` - `TOPOLOGY.adoc` - `docs/reports/audit/audit-2026-04-15-post.adoc` - `docs/tech-debt-2026-05-26.adoc` - `llm-warmup-dev.adoc` - `llm-warmup-user.adoc` - `session/README.adoc` **New MPL-2.0 header** - `.machine_readable/scripts/forge/git-cleanup.sh` - `scripts/invariant-path.sh` - `session/dispatch.sh` - `session/local-hooks.sh` </details> ## 📌 New pins - **Head SHA: `97377c577ca4c75d6a86e3dfe524a4efb26ebad6`** - None. No action `uses:`, `actions.lock`, lockfile or container digest is added or changed. ## RSR Quality Checklist ### Required - [ ] Tests pass: n/a. No source, proof or test file is changed; every change is a comment header, rule text or metadata. - [ ] Code is formatted: n/a, for the same reason. The four shell scripts gained one comment line each, and `bash -n` passes on all four. - [x] Linter is clean: standards `scripts/check-licence-consistency.sh` passes (see Testing). - [x] No banned language patterns: no code was added. - [ ] No `unsafe` blocks: n/a, no Rust changed. - [ ] No banned functions: n/a, no source or proofs changed. - [x] SPDX license headers present: every file this PR touches has one, with two exceptions. `docs/attribution/CITATION.cff` carries its licence in its `license:` field, and `.machine_readable/compliance/reuse/dep5` is itself a licence declaration. Neither had a header before this PR. - [x] No secrets or credentials. ### As Applicable - [ ] `.machine_readable/*.a2ml` updated: no. A2ML is retired, and its headers are left for the deed migration. - [x] Documentation updated: the licence rule text is listed under Changes. - [ ] `TOPOLOGY.md`: n/a, the architecture is unchanged. - [ ] `CHANGELOG`: not updated. The relicence is recorded in this PR and in the commit message, which lists every file. - [ ] New dependencies: none. - [ ] ABI/FFI: n/a. ## Testing - **Standards `scripts/check-licence-consistency.sh`** (the governance "Licence consistency" job), run locally on this head `97377c5` from the standards clone at `1ffe86b3`: **exit 0**. It lists the kept `.a2ml` headers and the 15 PMPL headers in the two nested trees as warnings, which is expected. - Positive control, run on the first head `a1c7c57`: I planted a `Cargo.toml` declaring `PMPL-1.0-or-later` in a copy of the tree. The script reported `Licence-vs-manifest mismatch` and exited **1**. With the plant removed it exited 0 again. - Limit of this check: the manifest check reads only Cargo.toml, package.json, pyproject.toml, mix.exs, Project.toml, `*.ipkg`, `*.cabal` and similar files. jaffascript has none of them, and the check does not read `stapeln.toml`. Planting PMPL in `stapeln.toml` still exited 0, so that file's licence was checked by hand. - **No collateral edits:** across all 84 files, every changed line that is not an `SPDX-License-Identifier` line is in one of the 21 files named under Changes (the rule text, the declared metadata, `ai.txt`, the two Justfiles, `dep5` and `verification/README.adoc`). Measured with `git diff origin/main HEAD`, counting `^[-+]` lines without `SPDX-License-Identifier` per file. - **The restore commit `97377c5` is exact:** after it, `git diff --name-status origin/main HEAD` lists 84 files, all `M`, with no `D` or `A`. - The governance "Check SPDX headers + permissions" step reads only `.github/workflows/*`, and this PR changes no workflow. ## Red checks on this head - `governance / Actions lockfile verify` is red on `main` (`589e1be`) as well. It is fixed by #73 together with hyperpolymath/standards#1209, and this PR does not touch it. - `Hypatia` (code scanning) fails because this PR edits both Justfiles, so their open alerts count as "in code changed by this pull request". The alerts predate this PR, with the same alert numbers on `main`, and the check is not required. Deferred to #75, which has acceptance criteria. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
This carries out four owner decisions of 2026-10-09 that #74 and #76 left open:
.machine_readable/.machine_readable/copy (75 files), after checking its diverging files for anything worth keeping..github/FUNDING.yml(github: hyperpolymath) and delete.github/funding.yml(github: metadatastician).LICENSES/AGPL-3.0-or-later.txt.docs/legal/and fix the three files that refer to them.It changes no file that #73, #74 or #76 changes in a conflicting way.
git merge-treeagainst each of their heads is clean (see Testing), so the four PRs can merge in any order.Changes
.machine_readable/.machine_readable/(75 files). Fix/tooling gaps 20260521 #40 (cc60f66) added it in a single commit. 53 of its files contain PMPL text. 17 differ from their outer copy beyond SPDX and copyright lines, and 3 exist only inside it:rattlescript,k9-svcand.machine_readable/contractiles/k9/, where the outer copies namejaffascriptandself-validating. The files areREADME.adoc,ai/PLACEHOLDERS.adoc,configs/git-cliff/cliff.toml,contractiles/self-validating/README.adocandcontractiles/self-validating/examples/setup-repo.k9.ncl.= .machine_readable Pillar) and copyright line. Both are now appended to.machine_readable/README.adoc, after its existing comment lines.ECOSYSTEM.a2ml,META.a2mlandSTATE.a2mlin the old root layout. A2ML is retired, so all of them go with the tree. Every outer A2ML file is unchanged..github/funding.yml. It differs from.github/FUNDING.ymlonly in letter case, so the two collide on a case-insensitive checkout (Windows, macOS).FUNDING.ymlstays:github,ko_fiandliberapayall namehyperpolymath.LICENSES/AGPL-3.0-or-later.txt. No file in the repo is AGPL-licensed. Every AGPL mention is a rule against it, or the deny list in.machine_readable/compliance/rust/deny.toml, which is kept.LICENSES/now holdsMPL-2.0.txtandCC-BY-SA-4.0.txt.docs/legal/EXHIBIT-A-ETHICAL-USE.txtanddocs/legal/EXHIBIT-B-QUANTUM-SAFE.txt, the PMPL exhibits. Their references are fixed:Justfileand.machine_readable/contractiles/Justfile(still byte-identical):validate-rsrnow checks forLICENSES/MPL-2.0.txtandLICENSES/CC-BY-SA-4.0.txt. Before, it checkedlicensing/exhibits/EXHIBIT-{A,B}-*.txtandlicensing/texts/PMPL-1.0-or-later.txt, under alicensing/directory that does not exist, so it always reported all three as missing.docs/RSR_OUTLINE.adoc: the two exhibit rows in the file table and the two exhibit lines in the tree are replaced by oneLICENSES/entry. The three places that describedLICENSEas PMPL-1.0-or-later now say MPL-2.0, which is whatLICENSEalready contains onmain. The rest of this template outline is untouched; its other stale claims are listed below.Not changed
docs/legal/0.2-AI-MANIFEST.a2ml, the remaining file indocs/legal/. It does not refer to the exhibits.docs/governance/MAINTENANCE-CHECKLIST.adoc:119. It namesdocs/legal/as a folder, which still exists.LICENSEandLICENSES/MPL-2.0.txt. Their "Exhibit A/B" text is the MPL-2.0 licence's own exhibits, not the PMPL files.docs/RSR_OUTLINE.adoc: the Palimpsest badges on line 5, ReScript listed as Tier 1,guix.scmORflake.nix, "Python outsidesalt/" and "npm, Bun, pnpm, yarn (use Deno)", which contradicts the estate's Bun-only rule. They are left for a separate change, because this PR only fixes the references to the deleted files.📌 New pins
da27c4fa1ee2368fcb32f0a3e4609aefa9a3b260uses:,actions.lock, lockfile or container digest is added or changed.RSR Quality Checklist
Required
validate-rsrwas run before and after; see Testing.forline in each Justfile, andjust --summaryparses both.scripts/check-licence-consistency.shexits 0 (see Testing).unsafeblocks: n/a, no Rust changed.As Applicable
.machine_readable/STATE.a2ml/ECOSYSTEM.a2ml/META.a2mlupdated: no. A2ML is retired, and the outer A2ML files are unchanged.docs/RSR_OUTLINE.adocand.machine_readable/README.adoc.TOPOLOGY.md: n/a, the architecture is unchanged.CHANGELOG: not updated, since only duplicates and unused licence files are removed.Testing
All checks ran on this head
da27c4fagainstmainat589e1be.git diff --name-status origin/main HEADshows 79Dand 4M(the two Justfiles,docs/RSR_OUTLINE.adocand.machine_readable/README.adoc). It shows noA.git grep -nIE '\.machine_readable/\.machine_readable|funding\.yml|AGPL-3\.0-or-later\.txt|EXHIBIT-[AB]|licensing/(exhibits|texts)'on this head matches nothing. The same pattern matches a planted line, so it can find these paths.validate-rsr, run withjust --justfile Justfile validate-rsrbecause the root also holds a lowercasejustfile(see below):mainit reports 6 missing paths: the 3 exhibit and PMPL paths, and 3 old-layout A2ML paths..machine_readable/{STATE,META,ECOSYSTEM}.a2ml). They are missing onmaintoo, and this PR does not touch them.LICENSES/CC-BY-SA-4.0.txtremoved from a copy of this head, it also reportsLICENSES/CC-BY-SA-4.0.txtas missing..github/runsvalidate-rsr.scripts/check-licence-consistency.sh, run from the standards clone at1ffe86b3: exit 0 on bothmainand this head. Its warning lines drop from 107 to 56, because the nested tree's PMPL headers are gone.asciidoctor --failure-level=WARNreports no warnings on either edited.adoc, before or after. The README title parses as.machine_readable Pillar. The first table inRSR_OUTLINE.adocgoes from 21 rows to 20 and stays at 2 columns.git merge-tree --write-treeof this head with ci: restore block YAML so the actions-lock gate can read the pins #73 (0bee4f4), chore(licence): MPL-2.0 for code, CC-BY-SA-4.0 for prose #74 (97377c5) and chore: remove nested duplicate trees #76 (31fd364) exits 0 for each. Positive control: a planted conflicting edit to.machine_readable/README.adocmakes it exit 1..githooks/docstring-scan.sh --range origin/main..HEAD --checkfinds 0 touched functions.squabble verify-satisfieddoes not evaluate them yet. Open alerts were keyed on (rule, path), forrefs/pull/77/mergeagainstrefs/heads/main: 32 against 44. The PR-minus-main set is empty. Control: main-minus-PR has 12 keys (Scorecard, plus Hypatia CSA001/CSA003), which shows the diff can find a difference.Found while doing this, not fixed here
The repo root holds both
Justfile(the RSR template, 1,545 lines) andjustfile(jaffascript's own 29-line runner foraffinescript check/run/build --face jaffa). As a result, a barejustin the root fails with "multiple candidate justfiles", and on a case-insensitive checkout one file overwrites the other. Merging them needs an owner decision, so this PR leaves them alone.Red checks on this head
All 27 check-runs (paginated) and both legacy statuses had reported at 2026-10-09T00:00Z.
governance / Actions lockfile verifyis red onmain(589e1be) as well. It is fixed by ci: restore block YAML so the actions-lock gate can read the pins #73 together with fix(governance): make the actions-lock ledger reachable under bash -e standards#1209, and this PR does not touch it.github-actionsruns, CodeQL, Hypatia, SonarCloud, CodeFactor, GitGuardian and Semgrep. The only required context,scan / gitleaks, is green.success, the same as onmain589e1be.Screenshots
n/a, no UI change.
🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf