docs: reconcile 0.1.0 program state - #2
Closed
CompleteDotTech wants to merge 2 commits into
Closed
Conversation
Truth-keeping reconciliation for OpenCoven#31 against live GitHub state: - OpenCoven#35 is closed (pairing via OpenCoven#54; custody hardening via OpenCoven#63/OpenCoven#68/OpenCoven#69) - Chat OpenCoven#27 is closed with the packed-consumer integration durable on protected main and release-artifact consolidation repins recorded - OpenCoven#38 in-repo enforcement contract credited to PRs OpenCoven#73/OpenCoven#74; remaining input is Chat-produced schema-v2 records on the frozen matrix - delivered-foundations list extended through PR OpenCoven#73 Advances OpenCoven#31 (truth-keeping mode; children OpenCoven#38/OpenCoven#40/OpenCoven#41 remain open).
Owner
Author
|
Recreated upstream as OpenCoven#78: OpenCoven#78. Closing this duplicate fork PR; review continues upstream. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Truth-keeping reconciliation of the 0.1.0 program map for the parent program OpenCoven#31. Children OpenCoven#38 (conformance), OpenCoven#40 (security review), and OpenCoven#41 (release execution) remain open, so this is a docs-only program-truth PR: no closure is claimed and nothing is closed. The first commit touches only
docs/ROADMAP.md(cd635b1); the second is an inertworkflow_dispatchCI bootstrap for fork runners (droppable in review).Assignee: @CompleteDotTech
Advances OpenCoven#31 (parent program; close after OpenCoven#38/OpenCoven#40/OpenCoven#41 complete)
Upstream PR (one click for a maintainer): https://github.com/OpenCoven/sdk/compare/main...CompleteDotTech:sdk:docs/program-reconciliation-31?expand=1
Checklist vs reality (findings)
hpke-bound-v1request binding through PR security(cave): bind protected Client v1 requests with hpke-bound-v1 OpenCoven/sdk#69 (163961f4e59cfdef51d2271fa98e7c514977203f).docs/ROADMAP.mdpreviously said [SDK 0.1.0][P0] Implement Cave pairing and secure credential custody OpenCoven/sdk#35 "remains open only for real-authority pairing/custody evidence" — corrected: that obligation now belongs to the [SDK 0.1.0][P0] Prove the packed SDK with cross-repository real-authority conformance OpenCoven/sdk#38 conformance record.main(squash merge0021d30d0cddc5d3f00a41c55d025cf3ce4611c5, pinning the HPKE-bound SDK merge163961f4e59cfdef51d2271fa98e7c514977203fand the Cave authority merge2a0ff9237e94e652e477b22f60fd6d721b9e6451), and release-artifact consolidation repinned the production integration to SDKacc3848with a locked manifest digest. The stale "commit950feb5/ branchfeat/native-sdk-integrationunreachable" caveat was removed.hpke-bound-v1(PR security(cave): bind protected Client v1 requests with hpke-bound-v1 OpenCoven/sdk#69), secure non-secret profiles (PR feat(core): add secure non-secret profiles OpenCoven/sdk#65), redacted diagnostics (PR feat(core): add redacted diagnostics OpenCoven/sdk#66), frozen packed public API baselines (PR build: freeze packed public API baselines OpenCoven/sdk#64), the frozen native conformance matrix (PR docs(release): freeze native conformance matrix OpenCoven/sdk#70), the conversational-control and offline-reads design specs (PRs docs: specify encrypted offline reads and tooling OpenCoven/sdk#71/docs: specify conversational control authority OpenCoven/sdk#72), and the cross-repository conformance evidence contract (PR test(conformance): add cross-repository evidence contract OpenCoven/sdk#73).aggregateRecord, currentlynull). Closure now requires Chat-produced passing schema-v2 conformance records across the frozendarwin-arm64,linux-x64, andwin32-x64matrix.#35andOpenCoven/chat#27unchecked although both issues are closed (verified live 2026-08-30). Every other checklist entry matches live state: [SDK 0.1.0][P0] Reconcile roadmap, contract truth, and public release scope OpenCoven/sdk#32/[SDK 0.1.0][P0] Source-lock the Cave Client v1 contract and correct compatibility health OpenCoven/sdk#33/[SDK 0.1.0][P0] Implement secure Cave discovery and compatibility negotiation OpenCoven/sdk#34/[SDK 0.1.0][P0] Implement canonical Cave reads and bounded pagination OpenCoven/sdk#36/[SDK 0.1.0][P0] Resolve CLI scope and implement native trust boundaries OpenCoven/sdk#37/[SDK 0.1.0][P1] Add non-secret profiles, redacted diagnostics, and public API governance OpenCoven/sdk#39/[SDK maintenance] Audit and safely retire superseded branches, worktrees, and stash state OpenCoven/sdk#45 checked; [SDK 0.1.0][P0] Prove the packed SDK with cross-repository real-authority conformance OpenCoven/sdk#38/[SDK 0.1.0][P0] Complete the first-release security review and ship/block disposition OpenCoven/sdk#40/[SDK 0.1.0][P0] Execute the first public release and validate registry provenance OpenCoven/sdk#41/[SDK post-0.1] Ship conversational control: create, send, stream, stop, retry, reconcile OpenCoven/sdk#42/[SDK post-0.1] Ship rich content, attachments, and explicitly confirmed privileged actions OpenCoven/sdk#43/[SDK post-0.1] Ship encrypted offline reads and advanced developer tooling OpenCoven/sdk#44 open. A maintainer tick of those two boxes re-aligns the parent map.Program rules 1–7
Re-checked against live state — no violations found: dependencies are named per child (1); no unit-test proxy is cited as final evidence where a live authority, native trust adapter, or packed consumer is required (2–3); redaction/no-secret rules are restated in the roadmap (4); no ambiguous-mutation replay is introduced (5); publication remains locked and intentionally disabled for all workspace packages (6); OpenCoven#41 external mutations still require fresh explicit authorization at execution time (7).
Evidence links
2a0ff9237e94e652e477b22f60fd6d721b9e6451, closing OpenCoven/coven-cave#4996.corepack pnpm@10.34.0 verify+git diff --checkgreen on the exact pushed head; fork CI is dispatched on this head viaworkflow_dispatch(see the Checks tab).