Skip to content

chore: remove nested .machine_readable copy and leftover licence artefacts - #77

Merged
hyperpolymath merged 2 commits into
mainfrom
claude/remove-nested-machine-readable-and-pmpl-exhibits
Oct 9, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
claude/remove-nested-machine-readable-and-pmpl-exhibits

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

This carries out four owner decisions of 2026-10-09 that #74 and #76 left open:

  1. Delete the nested .machine_readable/.machine_readable/ copy (75 files), after checking its diverging files for anything worth keeping.
  2. Keep .github/FUNDING.yml (github: hyperpolymath) and delete .github/funding.yml (github: metadatastician).
  3. Delete the unused LICENSES/AGPL-3.0-or-later.txt.
  4. Delete the two PMPL exhibits in docs/legal/ and fix the three files that refer to them.

It changes no file that #73, #74 or #76 changes in a conflicting way. git merge-tree against each of their heads is clean (see Testing), so the four PRs can merge in any order.

Changes

  • Deleted .machine_readable/.machine_readable/ (75 files). Fix/tooling gaps 20260521 #40 (cc60f66) added it in a single commit. 53 of its files contain PMPL text. 17 differ from their outer copy beyond SPDX and copyright lines, and 3 exist only inside it:
    • The 5 non-A2ML files are rattlescript-era template residue. They name rattlescript, k9-svc and .machine_readable/contractiles/k9/, where the outer copies name jaffascript and self-validating. The files are README.adoc, ai/PLACEHOLDERS.adoc, configs/git-cliff/cliff.toml, contractiles/self-validating/README.adoc and contractiles/self-validating/examples/setup-repo.k9.ncl.
    • The only content among those 5 that the outer copy lacked was the README's title (= .machine_readable Pillar) and copyright line. Both are now appended to .machine_readable/README.adoc, after its existing comment lines.
    • 12 A2ML files diverge. 2 of them name rattlescript, and 10 name neither repo. The 3 inner-only files are ECOSYSTEM.a2ml, META.a2ml and STATE.a2ml in the old root layout. A2ML is retired, so all of them go with the tree. Every outer A2ML file is unchanged.
  • Deleted .github/funding.yml. It differs from .github/FUNDING.yml only in letter case, so the two collide on a case-insensitive checkout (Windows, macOS). FUNDING.yml stays: github, ko_fi and liberapay all name hyperpolymath.
  • Deleted LICENSES/AGPL-3.0-or-later.txt. No file in the repo is AGPL-licensed. Every AGPL mention is a rule against it, or the deny list in .machine_readable/compliance/rust/deny.toml, which is kept. LICENSES/ now holds MPL-2.0.txt and CC-BY-SA-4.0.txt.
  • Deleted docs/legal/EXHIBIT-A-ETHICAL-USE.txt and docs/legal/EXHIBIT-B-QUANTUM-SAFE.txt, the PMPL exhibits. Their references are fixed:
    • Justfile and .machine_readable/contractiles/Justfile (still byte-identical): validate-rsr now checks for LICENSES/MPL-2.0.txt and LICENSES/CC-BY-SA-4.0.txt. Before, it checked licensing/exhibits/EXHIBIT-{A,B}-*.txt and licensing/texts/PMPL-1.0-or-later.txt, under a licensing/ directory that does not exist, so it always reported all three as missing.
    • docs/RSR_OUTLINE.adoc: the two exhibit rows in the file table and the two exhibit lines in the tree are replaced by one LICENSES/ entry. The three places that described LICENSE as PMPL-1.0-or-later now say MPL-2.0, which is what LICENSE already contains on main. The rest of this template outline is untouched; its other stale claims are listed below.

Not changed

  • docs/legal/0.2-AI-MANIFEST.a2ml, the remaining file in docs/legal/. It does not refer to the exhibits.
  • docs/governance/MAINTENANCE-CHECKLIST.adoc:119. It names docs/legal/ as a folder, which still exists.
  • LICENSE and LICENSES/MPL-2.0.txt. Their "Exhibit A/B" text is the MPL-2.0 licence's own exhibits, not the PMPL files.
  • Other stale claims in docs/RSR_OUTLINE.adoc: the Palimpsest badges on line 5, ReScript listed as Tier 1, guix.scm OR flake.nix, "Python outside salt/" and "npm, Bun, pnpm, yarn (use Deno)", which contradicts the estate's Bun-only rule. They are left for a separate change, because this PR only fixes the references to the deleted files.

📌 New pins

  • Head SHA: da27c4fa1ee2368fcb32f0a3e4609aefa9a3b260
  • None. No action uses:, actions.lock, lockfile or container digest is added or changed.

RSR Quality Checklist

Required

  • Tests pass: n/a. No source, proof or test is changed. validate-rsr was run before and after; see Testing.
  • Code is formatted: n/a. The only code edit is one for line in each Justfile, and just --summary parses both.
  • Linter is clean: standards scripts/check-licence-consistency.sh exits 0 (see Testing).
  • No banned language patterns: nothing is added.
  • No unsafe blocks: n/a, no Rust changed.
  • No banned functions: n/a, no source or proofs changed.
  • SPDX license headers present: each of the 4 edited files keeps its existing header. No file is added.
  • No secrets or credentials.

As Applicable

  • .machine_readable/STATE.a2ml / ECOSYSTEM.a2ml / META.a2ml updated: no. A2ML is retired, and the outer A2ML files are unchanged.
  • Documentation updated: docs/RSR_OUTLINE.adoc and .machine_readable/README.adoc.
  • TOPOLOGY.md: n/a, the architecture is unchanged.
  • CHANGELOG: not updated, since only duplicates and unused licence files are removed.
  • New dependencies: none.
  • ABI/FFI: n/a.

Testing

All checks ran on this head da27c4f against main at 589e1be.

  • File list: git diff --name-status origin/main HEAD shows 79 D and 4 M (the two Justfiles, docs/RSR_OUTLINE.adoc and .machine_readable/README.adoc). It shows no A.
  • No dangling references: git grep -nIE '\.machine_readable/\.machine_readable|funding\.yml|AGPL-3\.0-or-later\.txt|EXHIBIT-[AB]|licensing/(exhibits|texts)' on this head matches nothing. The same pattern matches a planted line, so it can find these paths.
  • validate-rsr, run with just --justfile Justfile validate-rsr because the root also holds a lowercase justfile (see below):
    • On main it reports 6 missing paths: the 3 exhibit and PMPL paths, and 3 old-layout A2ML paths.
    • On this head it reports only the 3 A2ML paths (.machine_readable/{STATE,META,ECOSYSTEM}.a2ml). They are missing on main too, and this PR does not touch them.
    • Positive control: with LICENSES/CC-BY-SA-4.0.txt removed from a copy of this head, it also reports LICENSES/CC-BY-SA-4.0.txt as missing.
    • No workflow under .github/ runs validate-rsr.
  • Standards scripts/check-licence-consistency.sh, run from the standards clone at 1ffe86b3: exit 0 on both main and this head. Its warning lines drop from 107 to 56, because the nested tree's PMPL headers are gone.
  • AsciiDoc: asciidoctor --failure-level=WARN reports no warnings on either edited .adoc, before or after. The README title parses as .machine_readable Pillar. The first table in RSR_OUTLINE.adoc goes from 21 rows to 20 and stays at 2 columns.
  • No conflict with open PRs: git merge-tree --write-tree of this head with ci: restore block YAML so the actions-lock gate can read the pins #73 (0bee4f4), chore(licence): MPL-2.0 for code, CC-BY-SA-4.0 for prose #74 (97377c5) and chore: remove nested duplicate trees #76 (31fd364) exits 0 for each. Positive control: a planted conflicting edit to .machine_readable/README.adoc makes it exit 1.
  • Docstrings: standards .githooks/docstring-scan.sh --range origin/main..HEAD --check finds 0 touched functions.
  • Code-scanning alerts this PR introduces, checked by hand because squabble verify-satisfied does not evaluate them yet. Open alerts were keyed on (rule, path), for refs/pull/77/merge against refs/heads/main: 32 against 44. The PR-minus-main set is empty. Control: main-minus-PR has 12 keys (Scorecard, plus Hypatia CSA001/CSA003), which shows the diff can find a difference.

Found while doing this, not fixed here

The repo root holds both Justfile (the RSR template, 1,545 lines) and justfile (jaffascript's own 29-line runner for affinescript check/run/build --face jaffa). As a result, a bare just in the root fails with "multiple candidate justfiles", and on a case-insensitive checkout one file overwrites the other. Merging them needs an owner decision, so this PR leaves them alone.

Red checks on this head

All 27 check-runs (paginated) and both legacy statuses had reported at 2026-10-09T00:00Z.

Screenshots

n/a, no UI change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

…facts

Owner decisions of 2026-10-09:

- Delete .machine_readable/.machine_readable/ (75 files), a nested copy
  of .machine_readable/ that #40 (cc60f66) added in one commit. 17 of
  its files differ from their outer copy beyond licence lines:
  - The 5 non-A2ML ones are rattlescript-era template residue: they
    name rattlescript, k9-svc and .machine_readable/contractiles/k9/,
    where the outer copies name jaffascript and self-validating. The
    only content among them that the outer copy lacks is the README's
    title and copyright line, which move to .machine_readable/README.adoc.
  - Of the 12 A2ML ones, 2 name rattlescript and 10 name neither repo.
    A2ML is retired, so they go with the tree; the outer A2ML copies are
    unchanged.
- Delete .github/funding.yml (github: metadatastician). It collides
  with .github/FUNDING.yml (github: hyperpolymath) on a case-insensitive
  checkout; FUNDING.yml is kept.
- Delete LICENSES/AGPL-3.0-or-later.txt. No file is AGPL-licensed; the
  repo's only AGPL mentions forbid it.
- Delete docs/legal/EXHIBIT-A-ETHICAL-USE.txt and
  EXHIBIT-B-QUANTUM-SAFE.txt, the PMPL exhibits. validate-rsr in both
  Justfiles now checks LICENSES/MPL-2.0.txt and LICENSES/CC-BY-SA-4.0.txt
  instead of the exhibits and the PMPL text (it looked under licensing/,
  which does not exist). docs/RSR_OUTLINE.adoc lists LICENSES/ in place
  of the exhibits and describes LICENSE as MPL-2.0, which it already is.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 03be59f4-898c-48a8-9993-9ce4ecd21c2f
📥 Commits

Reviewing files that changed from the base of the PR and between bdef9a0 and 1164ded.

📒 Files selected for processing (83)
  • .github/funding.yml
  • .machine_readable/.machine_readable/0.1-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/6a2/0-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/6a2/AGENTIC.a2ml
  • .machine_readable/.machine_readable/6a2/ECOSYSTEM.a2ml
  • .machine_readable/.machine_readable/6a2/META.a2ml
  • .machine_readable/.machine_readable/6a2/NEUROSYM.a2ml
  • .machine_readable/.machine_readable/6a2/PLAYBOOK.a2ml
  • .machine_readable/.machine_readable/6a2/README.adoc
  • .machine_readable/.machine_readable/6a2/STATE.a2ml
  • .machine_readable/.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/6a2/anchor/ANCHOR.a2ml
  • .machine_readable/.machine_readable/6a2/anchor/README.adoc
  • .machine_readable/.machine_readable/CLADE.a2ml
  • .machine_readable/.machine_readable/ECOSYSTEM.a2ml
  • .machine_readable/.machine_readable/ENSAID_CONFIG.a2ml
  • .machine_readable/.machine_readable/META.a2ml
  • .machine_readable/.machine_readable/README.adoc
  • .machine_readable/.machine_readable/STATE.a2ml
  • .machine_readable/.machine_readable/ai/.clinerules
  • .machine_readable/.machine_readable/ai/.cursorrules
  • .machine_readable/.machine_readable/ai/.windsurfrules
  • .machine_readable/.machine_readable/ai/0.2-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/ai/AI.a2ml
  • .machine_readable/.machine_readable/ai/PLACEHOLDERS.adoc
  • .machine_readable/.machine_readable/ai/README.adoc
  • .machine_readable/.machine_readable/anchors/0.2-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/anchors/README.adoc
  • .machine_readable/.machine_readable/bot_directives/README.adoc
  • .machine_readable/.machine_readable/bot_directives/coverage.a2ml
  • .machine_readable/.machine_readable/bot_directives/debt.a2ml
  • .machine_readable/.machine_readable/bot_directives/methodology.a2ml
  • .machine_readable/.machine_readable/compliance/reuse/dep5
  • .machine_readable/.machine_readable/compliance/rust/deny.toml
  • .machine_readable/.machine_readable/configs/0.2-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/configs/README.adoc
  • .machine_readable/.machine_readable/configs/git-cliff/cliff.toml
  • .machine_readable/.machine_readable/contractiles/Adjustfile.a2ml
  • .machine_readable/.machine_readable/contractiles/Intentfile.a2ml
  • .machine_readable/.machine_readable/contractiles/Mustfile.a2ml
  • .machine_readable/.machine_readable/contractiles/README.adoc
  • .machine_readable/.machine_readable/contractiles/Trustfile.a2ml
  • .machine_readable/.machine_readable/contractiles/dust/Dustfile.a2ml
  • .machine_readable/.machine_readable/contractiles/intend/Intentfile.a2ml
  • .machine_readable/.machine_readable/contractiles/must/Mustfile.a2ml
  • .machine_readable/.machine_readable/contractiles/self-validating/README.adoc
  • .machine_readable/.machine_readable/contractiles/self-validating/examples/ci-config.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/examples/project-metadata.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/examples/setup-repo.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/methodology-guard.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/template-hunt.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/template-kennel.k9.ncl
  • .machine_readable/.machine_readable/contractiles/self-validating/template-yard.k9.ncl
  • .machine_readable/.machine_readable/contractiles/trust/Trustfile.a2ml
  • .machine_readable/.machine_readable/integrations/feedback-o-tron.a2ml
  • .machine_readable/.machine_readable/integrations/groove.a2ml
  • .machine_readable/.machine_readable/integrations/proven.a2ml
  • .machine_readable/.machine_readable/integrations/verisimdb.a2ml
  • .machine_readable/.machine_readable/integrations/vexometer.a2ml
  • .machine_readable/.machine_readable/policies/.maintenance-perms-ignore
  • .machine_readable/.machine_readable/policies/0.2-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/policies/MAINTENANCE-AXES.a2ml
  • .machine_readable/.machine_readable/policies/MAINTENANCE-CHECKLIST.a2ml
  • .machine_readable/.machine_readable/policies/README.adoc
  • .machine_readable/.machine_readable/policies/SOFTWARE-DEVELOPMENT-APPROACH.a2ml
  • .machine_readable/.machine_readable/scripts/0.2-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/scripts/forge/0.3-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/scripts/forge/README.adoc
  • .machine_readable/.machine_readable/scripts/forge/forge-sync.sh
  • .machine_readable/.machine_readable/scripts/forge/git-cleanup.sh
  • .machine_readable/.machine_readable/scripts/lifecycle/0.3-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/scripts/lifecycle/README.adoc
  • .machine_readable/.machine_readable/scripts/lifecycle/install-tools.sh
  • .machine_readable/.machine_readable/scripts/maintenance/maint-assault.sh
  • .machine_readable/.machine_readable/scripts/verification/0.3-AI-MANIFEST.a2ml
  • .machine_readable/.machine_readable/scripts/verification/README.adoc
  • .machine_readable/README.adoc
  • .machine_readable/contractiles/Justfile
  • Justfile
  • LICENSES/AGPL-3.0-or-later.txt
  • docs/RSR_OUTLINE.adoc
  • docs/legal/EXHIBIT-A-ETHICAL-USE.txt
  • docs/legal/EXHIBIT-B-QUANTUM-SAFE.txt
 _____________________________________________________________________
< Not saying it's bad... but the compiler just asked for a union rep. >
 ---------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 59 issues detected

Severity Count
🔴 Critical 6
🟠 High 26
🟡 Medium 27

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
    "type": "scorecard_wrapper_missing_job_permissions",
    "file": ".github/workflows/scorecard.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_job_level_scorecard_perms"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 33,
    "reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": 47,
    "reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": null,
    "reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
    "type": "WH014",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "high"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 9, 2026 00:24
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 8ea4db4 into main Oct 9, 2026
24 of 26 checks passed
@hyperpolymath
hyperpolymath deleted the claude/remove-nested-machine-readable-and-pmpl-exhibits branch October 9, 2026 00:25
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 59 issues detected

Severity Count
🔴 Critical 6
🟠 High 26
🟡 Medium 27

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
    "type": "scorecard_wrapper_missing_job_permissions",
    "file": ".github/workflows/scorecard.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_job_level_scorecard_perms"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 33,
    "reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": 47,
    "reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": null,
    "reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
    "type": "WH014",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "high"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit that referenced this pull request Oct 9, 2026
## Summary

This puts jaffascript on the two-tier licence rule: **MPL-2.0 for code,
CC-BY-SA-4.0 for prose**.

**This relicenses existing files, at the owner's direction.** The
owner's instruction (2026-10-09) was "mpl-2.0 code, and cc-by-sa-4.0
prose". The edits follow standards
`docs/migrations/pmpl-to-mpl-sweep-runbook.adoc` §5 and §6: every file
was opened and changed individually from an explicit list, and only a
file's own SPDX declaration was flipped. There was no bulk substitution.
The runbook makes owner sign-off on the per-repo change-list the hard
gate, so **this PR is held for the owner's merge**: auto-merge is not
armed. The full list is below.

This PR's first commit also deleted two nested duplicate trees. That
removal is now its own PR, #76, so this PR contains only the licence
change and fits CodeRabbit's 100-file limit. The two PRs change no file
in common.

## Changes

- **18 code/config files: PMPL-1.0-or-later → MPL-2.0** (SPDX header
only).
- **31 prose files: MPL-2.0 → CC-BY-SA-4.0.** 30 change only the SPDX
header. `verification/README.adoc` also gains the title (`= Verification
Pillar`) and copyright line of its nested copy, which #76 deletes.
- **16 `.adoc` files had no SPDX header and now carry `CC-BY-SA-4.0`.**
`README.adoc` is one of them: its only `SPDX-License-Identifier` text
was in body prose at line 138, not a header.
- **4 shell scripts had no SPDX header and now carry `MPL-2.0`**, on
line 2 after the shebang. Their modes are unchanged and `bash -n` passes
on each.
- **The licence rule text now states the two-tier rule** in every place
that states it: `.github/copilot-instructions.md`,
`.github/GOVERNANCE.md` footer, `.github/pull_request_template.md`,
`.machine_readable/ai/.clinerules`, `.machine_readable/ai/.cursorrules`,
`.machine_readable/ai/.windsurfrules`,
`.machine_readable/ai/PLACEHOLDERS.adoc`,
`docs/practice/AI-CONVENTIONS.adoc`, `QUICKSTART-MAINTAINER.adoc`,
`TEST-NEEDS.adoc`, `llm-warmup-{dev,user}.adoc`.
- **Declared metadata:** `stapeln.toml`,
`docs/attribution/CITATION.cff`, `docs/attribution/CITATIONS.adoc` and
`www/.well-known/humans.txt` now name MPL-2.0.
- **`www/.well-known/ai.txt`** states both licences. The line "AI agents
must preserve Emotional Lineage per PMPL Section 3" is gone, because
PMPL no longer applies.
- **The `{{LICENSE}}` placeholder** in the template-substitution recipe,
in both `Justfile` and `.machine_readable/contractiles/Justfile`, now
becomes `MPL-2.0`.
- **`.machine_readable/compliance/reuse/dep5`** (an unconsumed
template):
  - The code stanzas now say MPL-2.0.
- A final `*.adoc *.md` stanza assigns CC-BY-SA-4.0. In dep5 the last
matching stanza wins.
- The `.machine_readable/*.a2ml` stanza still says PMPL, to match those
files' headers (see "Kept").

### Kept deliberately (runbook §6)

- **Every `.a2ml` header.** A2ML is retired, and the deed migration owns
those files. The licence check lists them as warnings, and that is
expected.
- **`verification/verification/` and `www/.well-known/.well-known/`**
keep their old headers here (15 PMPL), because #76 deletes both trees.
- **`.machine_readable/.machine_readable/`**, a nested copy of 75 files.
The owner decided to delete it, and #77 does.
- **`LICENSE`** (already the verbatim MPL-2.0 text) and **`LICENSES/`**.
#77 deletes the unused `LICENSES/AGPL-3.0-or-later.txt` and the two PMPL
exhibits `docs/legal/EXHIBIT-{A,B}-*.txt`.
- **`CODE_OF_CONDUCT.adoc`**, which is adapted from the Contributor
Covenant and so was not relabelled.
- **`www/.well-known/{ai,humans,security}.txt`** keep their MPL-2.0
header, because they are machine-read data rather than prose.
- **History and policy text that names PMPL as a fact:**
`docs/tech-debt-2026-05-26.adoc` (body), `docs/decisions/0001-*`,
`docs/STATE-VISUALIZER.adoc`, `docs/RSR_OUTLINE.adoc`,
`.machine_readable/compliance/rust/deny.toml`, the k9 example bodies,
`contractile.just:65`, and `Justfile:224`/`:1057` (licence-file
tooling). #77 updates `docs/RSR_OUTLINE.adoc`'s description of `LICENSE`
and the `Justfile:1057` check, because both referred to the exhibits it
deletes. Its changes merge cleanly with this PR.

<details><summary>Full change-list (69 files relabelled)</summary>

**PMPL-1.0-or-later → MPL-2.0**

- `container/compose.example.toml`
- `container/compose.toml`
- `container/Containerfile`
- `container/ct-build.sh`
- `container/deploy.k9.ncl`
- `container/entrypoint.sh`
- `container/.gatekeeper.yaml`
- `container/manifest.toml`
- `container/vordr.toml`
- `contractile.just`
- `.devcontainer/Containerfile`
- `.devcontainer/devcontainer.json`
- `features/ssg/ssg-bootstrap.sh`
- `.gitlab-ci.yml`
- `Justfile`
- `.machine_readable/contractiles/Justfile`
- `.pre-commit-config.yaml`
- `scripts/validate-template.sh`

**MPL-2.0 → CC-BY-SA-4.0**

- `AUDIT.adoc`
- `.claude/CLAUDE.md`
- `container/README.adoc`
- `.devcontainer/README.adoc`
- `EXPLAINME.adoc`
- `features/boj-server/README.adoc`
- `features/panic-attacker/README.adoc`
- `features/README.adoc`
- `features/ssg/README.adoc`
- `.machine_readable/README.adoc`
- `MAINTAINERS.adoc`
- `ROADMAP.adoc`
- `src/aspects/integrity/README.adoc`
- `src/aspects/observability/README.adoc`
- `src/aspects/README.adoc`
- `src/aspects/security/README.adoc`
- `src/contracts/README.adoc`
- `src/definitions/README.adoc`
- `src/errors/README.adoc`
- `src/interface/Abi/README.adoc`
- `src/interface/ffi/README.adoc`
- `src/interface/ffi/src/README.adoc`
- `src/interface/ffi/test/README.adoc`
- `src/interface/generated/abi/README.adoc`
- `src/interface/generated/README.adoc`
- `src/interface/README.adoc`
- `src/README.adoc`
- `TEMPLATE-STANDARDS-AUDIT.adoc`
- `tools/invariant-path/README.adoc`
- `verification/README.adoc`
- `www/.well-known/README.adoc`

**New CC-BY-SA-4.0 header**

- `.claude/PROJECT.adoc`
- `ARCHITECTURE.adoc`
- `CHANGELOG.adoc`
- `GOVERNANCE.adoc`
- `PROOF-NEEDS.adoc`
- `PROOF-STATUS.adoc`
- `READINESS.adoc`
- `README.adoc`
- `SECURITY.adoc`
- `TEST-NEEDS.adoc`
- `TOPOLOGY.adoc`
- `docs/reports/audit/audit-2026-04-15-post.adoc`
- `docs/tech-debt-2026-05-26.adoc`
- `llm-warmup-dev.adoc`
- `llm-warmup-user.adoc`
- `session/README.adoc`

**New MPL-2.0 header**

- `.machine_readable/scripts/forge/git-cleanup.sh`
- `scripts/invariant-path.sh`
- `session/dispatch.sh`
- `session/local-hooks.sh`

</details>

## 📌 New pins

- **Head SHA: `97377c577ca4c75d6a86e3dfe524a4efb26ebad6`**
- None. No action `uses:`, `actions.lock`, lockfile or container digest
is added or changed.

## RSR Quality Checklist

### Required

- [ ] Tests pass: n/a. No source, proof or test file is changed; every
change is a comment header, rule text or metadata.
- [ ] Code is formatted: n/a, for the same reason. The four shell
scripts gained one comment line each, and `bash -n` passes on all four.
- [x] Linter is clean: standards `scripts/check-licence-consistency.sh`
passes (see Testing).
- [x] No banned language patterns: no code was added.
- [ ] No `unsafe` blocks: n/a, no Rust changed.
- [ ] No banned functions: n/a, no source or proofs changed.
- [x] SPDX license headers present: every file this PR touches has one,
with two exceptions. `docs/attribution/CITATION.cff` carries its licence
in its `license:` field, and `.machine_readable/compliance/reuse/dep5`
is itself a licence declaration. Neither had a header before this PR.
- [x] No secrets or credentials.

### As Applicable

- [ ] `.machine_readable/*.a2ml` updated: no. A2ML is retired, and its
headers are left for the deed migration.
- [x] Documentation updated: the licence rule text is listed under
Changes.
- [ ] `TOPOLOGY.md`: n/a, the architecture is unchanged.
- [ ] `CHANGELOG`: not updated. The relicence is recorded in this PR and
in the commit message, which lists every file.
- [ ] New dependencies: none.
- [ ] ABI/FFI: n/a.

## Testing

- **Standards `scripts/check-licence-consistency.sh`** (the governance
"Licence consistency" job), run locally on this head `97377c5` from the
standards clone at `1ffe86b3`: **exit 0**. It lists the kept `.a2ml`
headers and the 15 PMPL headers in the two nested trees as warnings,
which is expected.
- Positive control, run on the first head `a1c7c57`: I planted a
`Cargo.toml` declaring `PMPL-1.0-or-later` in a copy of the tree. The
script reported `Licence-vs-manifest mismatch` and exited **1**. With
the plant removed it exited 0 again.
- Limit of this check: the manifest check reads only Cargo.toml,
package.json, pyproject.toml, mix.exs, Project.toml, `*.ipkg`, `*.cabal`
and similar files. jaffascript has none of them, and the check does not
read `stapeln.toml`. Planting PMPL in `stapeln.toml` still exited 0, so
that file's licence was checked by hand.
- **No collateral edits:** across all 84 files, every changed line that
is not an `SPDX-License-Identifier` line is in one of the 21 files named
under Changes (the rule text, the declared metadata, `ai.txt`, the two
Justfiles, `dep5` and `verification/README.adoc`). Measured with `git
diff origin/main HEAD`, counting `^[-+]` lines without
`SPDX-License-Identifier` per file.
- **The restore commit `97377c5` is exact:** after it, `git diff
--name-status origin/main HEAD` lists 84 files, all `M`, with no `D` or
`A`.
- The governance "Check SPDX headers + permissions" step reads only
`.github/workflows/*`, and this PR changes no workflow.

## Red checks on this head

- `governance / Actions lockfile verify` is red on `main` (`589e1be`) as
well. It is fixed by #73 together with hyperpolymath/standards#1209, and
this PR does not touch it.
- `Hypatia` (code scanning) fails because this PR edits both Justfiles,
so their open alerts count as "in code changed by this pull request".
The alerts predate this PR, with the same alert numbers on `main`, and
the check is not required. Deferred to #75, which has acceptance
criteria.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant