Repository navigation
docs: affirm state at 465cec6 (AFFIRMATION, profile A) - #69
Merged
Merged
Conversation
Profile A affirmation per standards docs/AFFIRMATION-STANDARD.adoc; every claim produced by live runs at the anchor commit on 2026-10-07. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔍 Hypatia Security ScanFindings: 75 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 24,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 64,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 84,
"reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/mirror.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
6 tasks done
hyperpolymath
added a commit
that referenced
this pull request
Oct 7, 2026
) ## Summary Marks the AFFIRMATION landed in #69 as an **agent-authored DRAFT, not affirmed by the owner**. It adds a `:status:` attribute and a visible `[IMPORTANT]` block. The owner's rule (dev-notes `for-jonathan-todo.adoc` §7, 2026-10-07) is that an agent must not sign an affirmation. #69 was committed by an agent with the machine key, so it does not carry the owner's affirmation. Owner chose this correction on 2026-10-07. No claim in the file changes. ## Type of change - [x] 📖 Documentation. Two status lines only. ## 📌 New pins Head SHA: **dff2f0e3d3bde80ac96a866d2740b1b3602cf422**. No pins are added or changed. ## How has this been verified? - `git diff` shows 8 lines added and 0 removed. - The commit is `G` (signed). This status-marker commit is agent-signed by design; the owner's affirmation is still to come. - The standards `affirmation-check/check.sh` shows the document passes its content checks. Locally, signature verification reports the previous squash commit's GitHub web-flow signature as unverifiable, because the GitHub key is not in the local keyring. Treat that as a limit of the local copy, not a verdict. ## Checklist - [x] My commits are **signed**. - [x] No code changed. The only check that bears on this change is the affirmation checker (above). - [x] SPDX: the existing `CC-BY-SA-4.0` header is unchanged. - [x] No public claim now overstates anything. This PR exists to remove an overstatement. - [x] No soundness hole introduced. ## Notes for reviewers Next step for the owner: once you have reviewed the file, re-anchor it, then land it with `git commit -S` and remove the DRAFT lines. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Adds
docs/AFFIRMATION.adoc, a profile A (evidential) affirmation under standardsdocs/AFFIRMATION-STANDARD.adoc. It is anchored tomainat465cec698878c4eaf427c073e3c5e4b21c0f5f68. Every claim in it comes from live runs at that commit on 2026-10-07T10:27:03Z.Changes
docs/AFFIRMATION.adoc:bin/jaffa checkandcompilework onexamples/hello.affineand produce valid wasm. A planted unresolved name is rejected. Workflow validation passes.jaffa eval examples/hello.affinefails with "Unhandled effect: println";justrefuses to run because bothJustfileandjustfileexist;sorry/Admitted;tests/e2e.shchecks nothing (PASS=0);📌 New pins
Head SHA: b08c8fa. This PR adds no pins: no action
uses:SHAs, noactions.lockentries, no lockfile or container changes.RSR Quality Checklist
Required
just test):justcannot run here (two justfiles), and thetestrecipe is a stub, as the affirmation says. The real checks that were run are listed under Testing.unsafewithout// SAFETY:: n/a, no code.sorry/Admittedonly to describe the scanner false positive.CC-BY-SA-4.0.LICENSES/CC-BY-SA-4.0.txtexists..envfiles.As Applicable
Testing
bin/jaffa check|compile|eval examples/hello.affineand a planted-error control, run on the anchor commit (results in the file).bash tests/aspect_tests.shgives PASS=2 FAIL=1.bash tests/workflows/validate_workflows_test.shrc=0..github/actions/affirmation-check/check.shreports "Affirmation commit signature verified with a trusted key", then "AFFIRMATION document validation passed".G(signed), and its parent equals the anchor (465cec6).Screenshots
n/a.
🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf