Skip to content

[2026 AI] Move model weights out of src and version them with provenance metadata #995

Description

@Nanle-code

Objective

Treat trained models as versioned artifacts with known provenance instead of loose files in the source tree.

Target area

src/lib/model_weights.json, src/ml

Context

src/lib/model_weights.json sits next to application code with no record of the training data, code version or date that produced it, and changes to it are nearly impossible to review.

Acceptance criteria

  • Weights move to models/<name>/<version>/ (or release assets) with a model.json manifest: training commit, dataset hash, metrics, created date.
  • The app loads models by manifest version, and a checksum is verified at load time.
  • The training script writes the manifest automatically.
  • PR review guidance for model updates is documented.
  • Automated tests cover the primary flow, at least one boundary case, and at least one failure case.
  • User-facing documentation or developer guidance is updated, including compatibility, security, or migration notes where applicable.

Pull request requirements

  • All continuous integration checks must pass before a pull request may be merged.
  • The branch must be free of merge conflicts with the target branch at the time of merge.
  • Do not request merge with failing workflows, skipped required checks, or unresolved conflicts.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    AIDevOpssecurityWallet, auth, or crypto paths; needs a CODEOWNERS review and is never a starter issue

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions