Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
391 commits
Select commit Hold shift + click to select a range
e0c74ac
fix: omit unsupported embedding dimensions
jstar0 Jul 14, 2026
16aad38
fix: keep ANN projection active-only
jstar0 Jul 14, 2026
eda70a4
feat: record embedding request evidence
jstar0 Jul 14, 2026
3c9217e
docs: record production retrieval ablation evidence
jstar0 Jul 14, 2026
465f045
docs: record retrieval ablation local gates
jstar0 Jul 14, 2026
51a484b
ci: run PostgreSQL gates with pgvector
jstar0 Jul 14, 2026
a6b7862
docs: close production retrieval ablation checklist
jstar0 Jul 14, 2026
edfbb20
docs: design production retrieval runtime
jstar0 Jul 14, 2026
a11016e
docs: plan production retrieval runtime
jstar0 Jul 14, 2026
a39fd82
feat: add production retrieval projection schema
jstar0 Jul 14, 2026
ab3ce94
docs: close retrieval schema checklist
jstar0 Jul 14, 2026
3dc561f
feat: process durable retrieval projections
jstar0 Jul 14, 2026
80c98ac
docs: close retrieval worker checklist
jstar0 Jul 14, 2026
653c6eb
feat: coordinate governed runtime retrieval
jstar0 Jul 14, 2026
c80a399
docs: close retrieval coordinator checklist
jstar0 Jul 14, 2026
ee8e5ed
feat: expose opt-in production retrieval
jstar0 Jul 14, 2026
3cc7a53
docs: close retrieval runtime entrypoint checklist
jstar0 Jul 14, 2026
33a5eff
test: freeze production retrieval runtime cases
jstar0 Jul 14, 2026
bde15c2
docs: close retrieval acceptance checklist
jstar0 Jul 14, 2026
e06baca
docs: record production retrieval runtime evidence
jstar0 Jul 14, 2026
2fd8502
docs: close production retrieval local gates
jstar0 Jul 14, 2026
0ebf0ac
ci: use PostgreSQL 18 client tools
jstar0 Jul 14, 2026
7d4f041
docs: close production retrieval delivery checklist
jstar0 Jul 14, 2026
79d33c2
test: freeze independent retrieval batch
jstar0 Jul 14, 2026
7e23aec
fix: enforce forbidden retrieval hard gate
jstar0 Jul 14, 2026
356c3d0
fix: deduplicate retrieval scoring
jstar0 Jul 14, 2026
af2be48
test: clarify retrieval safety distractors
jstar0 Jul 14, 2026
689ddd0
docs: record independent retrieval evidence
jstar0 Jul 14, 2026
3402cb6
test: classify retrieval distractors correctly
jstar0 Jul 14, 2026
145993d
feat: support parallel retrieval profile migration
jstar0 Jul 14, 2026
3cecde4
docs: record retrieval profile migration evidence
jstar0 Jul 14, 2026
cf6335a
test: record PostgreSQL operational scale profile
jstar0 Jul 14, 2026
0526ef3
feat: rank governed retrieval by source authority
jstar0 Jul 14, 2026
72fccdd
docs: refresh retrieval evidence after authority ranking
jstar0 Jul 14, 2026
cef8bb0
test: align recovery labels with schema fifteen
jstar0 Jul 14, 2026
2892adc
test: verify candidate projection rollback
jstar0 Jul 14, 2026
45cc9f0
feat: compare versioned retrieval profiles
jstar0 Jul 15, 2026
47b39f6
fix: distinguish retrieval distractors from safety failures
jstar0 Jul 15, 2026
2289b88
docs: record retrieval profile promotion decision
jstar0 Jul 15, 2026
7c0d142
test: publish Grok process record atomically
jstar0 Jul 15, 2026
9dcfa85
test: qualify projection outbox fault recovery
jstar0 Jul 15, 2026
a223d63
docs: record projection outbox fault profile
jstar0 Jul 15, 2026
40f1258
fix: normalize projection worker cancellation
jstar0 Jul 15, 2026
c564a39
docs: freeze server qualification scale profile
jstar0 Jul 15, 2026
3eb4615
feat: rebuild vector projections from current authority
jstar0 Jul 15, 2026
1119d6e
test: add server qualification scale profile
jstar0 Jul 15, 2026
c41edfa
fix: migrate through configured postgres pool
jstar0 Jul 15, 2026
9b9c061
docs: record server qualification scale profile
jstar0 Jul 15, 2026
02c0eca
docs: close server qualification delivery
jstar0 Jul 15, 2026
9bc3b88
test: freeze scoped HNSW recall profile
jstar0 Jul 15, 2026
1a217cd
test: inspect production scoped vector plan
jstar0 Jul 15, 2026
29a3429
test: attribute scale retrieval degradation
jstar0 Jul 15, 2026
b1ca093
test: replace HNSW hypothesis with lag attribution
jstar0 Jul 15, 2026
b918584
docs: correct vector degradation attribution
jstar0 Jul 15, 2026
2f97419
docs: close vector degradation attribution
jstar0 Jul 15, 2026
37e27a6
docs: design full LongMemEval retrieval qualification
jstar0 Jul 15, 2026
e1e889e
docs: plan full LongMemEval retrieval qualification
jstar0 Jul 15, 2026
cdb2cd9
feat: define full retrieval benchmark evidence
jstar0 Jul 15, 2026
722a8e6
feat: stream and score LongMemEval retrieval
jstar0 Jul 15, 2026
0f59bf5
feat: run full governed LongMemEval retrieval
jstar0 Jul 15, 2026
68ef9f4
docs: qualify full LongMemEval retrieval evidence
jstar0 Jul 15, 2026
831c956
docs: record full retrieval local acceptance
jstar0 Jul 15, 2026
b5154e6
docs: close full LongMemEval retrieval qualification
jstar0 Jul 15, 2026
4e2ac03
docs: design full LongMemEval reader QA
jstar0 Jul 15, 2026
c97a236
docs: keep reader QA scheduling streaming
jstar0 Jul 15, 2026
380acac
docs: plan full LongMemEval reader QA
jstar0 Jul 15, 2026
af5ea38
feat: define full reader QA evidence
jstar0 Jul 15, 2026
77ec433
feat: record provider usage for QA runs
jstar0 Jul 15, 2026
c49a132
feat: replay frozen LongMemEval rankings
jstar0 Jul 15, 2026
53f0ec7
feat: run resumable LongMemEval readers
jstar0 Jul 15, 2026
a40e541
feat: judge LongMemEval reader responses
jstar0 Jul 15, 2026
cd6d413
feat: report full LongMemEval reader QA
jstar0 Jul 15, 2026
ca778f0
feat: add full LongMemEval QA command
jstar0 Jul 15, 2026
ad283d8
fix: enforce zero-tool Grok turns
jstar0 Jul 15, 2026
d10a53c
docs: reject failed LongMemEval v2 run
jstar0 Jul 15, 2026
6c4261f
docs: qualify full LongMemEval reader QA
jstar0 Jul 15, 2026
91d173d
docs: record full reader QA local gates
jstar0 Jul 15, 2026
1c9a61a
docs: close full LongMemEval reader QA
jstar0 Jul 15, 2026
1db461f
docs: design PostgreSQL HA and PITR qualification
jstar0 Jul 15, 2026
47aad97
docs: plan PostgreSQL HA and PITR qualification
jstar0 Jul 15, 2026
7576fd9
test: freeze PostgreSQL HA and PITR case
jstar0 Jul 15, 2026
b26617c
feat: add HA and PITR evidence reports
jstar0 Jul 15, 2026
e89e886
test: add dedicated PostgreSQL replication harness
jstar0 Jul 15, 2026
a46d792
test: prove PostgreSQL standby failover
jstar0 Jul 15, 2026
423caeb
test: prove exact LSN point in time recovery
jstar0 Jul 15, 2026
414c116
docs: record PostgreSQL HA and PITR evidence
jstar0 Jul 15, 2026
2034963
docs: record PostgreSQL HA and PITR local gates
jstar0 Jul 15, 2026
b771629
docs: close PostgreSQL HA and PITR qualification
jstar0 Jul 15, 2026
618243b
docs: design active backlog dimensional migration
jstar0 Jul 15, 2026
ebfe97a
docs: plan active backlog dimensional migration
jstar0 Jul 15, 2026
e6ffe9f
feat: add dimensional projection classes
jstar0 Jul 15, 2026
8a78da4
feat: route dimensional vector projections
jstar0 Jul 15, 2026
c138bd6
feat: operate dimensional projection classes
jstar0 Jul 15, 2026
12c3949
test: qualify active backlog dimensional migration
jstar0 Jul 15, 2026
bb09826
fix: use available 2560 dimensional provider profile
jstar0 Jul 15, 2026
c3101dc
fix: parse vendor postgres version output
jstar0 Jul 15, 2026
86fb8d0
fix: sort dimensional migration latency samples
jstar0 Jul 15, 2026
c2d0aa7
docs: record dimensional migration evidence
jstar0 Jul 15, 2026
761e3af
docs: close dimensional migration qualification
jstar0 Jul 15, 2026
9d9fd2b
docs: finalize dimensional migration delivery checklist
jstar0 Jul 15, 2026
924c411
docs: design projection event retention pruning
jstar0 Jul 15, 2026
537fb18
docs: plan projection event retention pruning
jstar0 Jul 16, 2026
b864f6b
test: freeze projection retention qualification
jstar0 Jul 16, 2026
c4eb6e5
feat: add projection retention floor
jstar0 Jul 16, 2026
4820369
fix: require rebuild below retention floor
jstar0 Jul 16, 2026
66b6727
feat: prune projection events atomically
jstar0 Jul 16, 2026
10ca0bb
feat: expose audited projection pruning
jstar0 Jul 16, 2026
9dc6d08
test: add projection retention fault profile
jstar0 Jul 16, 2026
a04e978
test: parallelize retention catch-up
jstar0 Jul 16, 2026
8d0fc7d
docs: record projection retention evidence
jstar0 Jul 16, 2026
0c31816
fix: rebuild ablation profiles after retention
jstar0 Jul 16, 2026
8ebb3d5
docs: record projection retention release gates
jstar0 Jul 16, 2026
aee5b75
docs: close projection retention qualification
jstar0 Jul 16, 2026
1680de6
test: control source formation request deadline
jstar0 Jul 16, 2026
5bd5e18
docs: finalize projection retention delivery checklist
jstar0 Jul 16, 2026
cc31a78
docs: design memory eligibility retention
jstar0 Jul 16, 2026
508c819
docs: audit memory eligibility snapshots
jstar0 Jul 16, 2026
c436797
docs: clarify corrected memory validity
jstar0 Jul 16, 2026
2d8dcd7
docs: plan memory eligibility retention
jstar0 Jul 16, 2026
316dee3
test: freeze memory eligibility qualification
jstar0 Jul 16, 2026
69df504
feat: add memory eligibility authority
jstar0 Jul 16, 2026
9c37290
feat: enforce memory eligibility at retrieval
jstar0 Jul 16, 2026
288fd05
feat: govern memory validity and archive
jstar0 Jul 16, 2026
f8696b9
test: qualify memory eligibility failures
jstar0 Jul 16, 2026
cdd86a8
test: replay memory eligibility through clients
jstar0 Jul 17, 2026
be5d231
test: add memory eligibility formal profile
jstar0 Jul 17, 2026
abb4da5
docs: record memory eligibility offline replay
jstar0 Jul 17, 2026
083d940
docs: record memory eligibility release gates
jstar0 Jul 17, 2026
9ef6cac
ops: add secure W19 formal runner
jstar0 Jul 17, 2026
1da8318
feat: integrate Vermory with Hermes memory lifecycle
jstar0 Jul 17, 2026
a4169b3
docs: record real Codex eligibility replay
jstar0 Jul 17, 2026
2e97280
test: bind Codex evidence to W19 report
jstar0 Jul 17, 2026
33d349d
docs: record memory eligibility evidence
jstar0 Jul 17, 2026
2ed184e
docs: close memory eligibility qualification
jstar0 Jul 17, 2026
4a5c11b
feat: qualify Hermes continuity delivery
jstar0 Jul 17, 2026
4f5e04a
fix: bind Hermes resume and model audit evidence
jstar0 Jul 17, 2026
d65c0ab
docs: record Hermes real-client qualification
jstar0 Jul 17, 2026
d428741
docs: distinguish trajectory and delivery metadata
jstar0 Jul 17, 2026
5d488f5
feat: add conversation formation loop
jstar0 Jul 17, 2026
7dd6ea7
feat: support non-thinking provider requests
jstar0 Jul 17, 2026
fc7ca4b
fix: include required schema in provider prompts
jstar0 Jul 17, 2026
67b14b1
fix: redact failed formation audits on deletion
jstar0 Jul 17, 2026
cb78aed
docs: record conversation formation qualification
jstar0 Jul 17, 2026
b6c6154
docs: record W21 protected delivery
jstar0 Jul 17, 2026
6038cec
feat: add automatic conversation review loop
jstar0 Jul 17, 2026
012b381
docs: bind W22 evidence to implementation
jstar0 Jul 17, 2026
3e1f7b9
test: refreeze F02 normalized fixtures
jstar0 Jul 17, 2026
4a5a30c
docs: record W22 protected delivery
jstar0 Jul 17, 2026
53ae902
spec: freeze verified tool outcome formation
jstar0 Jul 17, 2026
bbad1ec
feat: form memory from verified tool outcomes
jstar0 Jul 18, 2026
7e76df6
fix: preserve shared formation evidence
jstar0 Jul 18, 2026
6a5bfb0
docs: qualify verified tool outcome formation
jstar0 Jul 18, 2026
477ba7a
docs: close W23 protected delivery
jstar0 Jul 18, 2026
3c73d9b
test: make request deadline persistence deterministic
jstar0 Jul 18, 2026
dae92af
test: freeze protected artifact signing case
jstar0 Jul 18, 2026
e4bb83b
ci: sign complete release snapshots with oidc
jstar0 Jul 18, 2026
3a06f80
docs: record protected artifact signing evidence
jstar0 Jul 18, 2026
8ecc27c
docs: establish repository collaboration standards
jstar0 Jul 18, 2026
3eb0c2a
docs: close protected signing checklist
jstar0 Jul 18, 2026
b2173fd
docs: move canonical repository to samekind
jstar0 Jul 18, 2026
3459f83
test: qualify cursor agent boundary
jstar0 Jul 18, 2026
ce0fe40
fix: keep cursor runner portable
jstar0 Jul 18, 2026
7b2658d
feat: add trusted workspace attachment boundary
jstar0 Jul 18, 2026
361bd8f
spec: freeze real utility comparison
jstar0 Jul 18, 2026
b815215
feat: wire W27 utility retrieval evaluation
jstar0 Jul 18, 2026
aea5f93
fix: qualify W27 vector retrieval evidence
jstar0 Jul 18, 2026
20ba728
feat: qualify W27 real utility evidence
jstar0 Jul 19, 2026
97b774f
feat: qualify LongMemEval vector retrieval
jstar0 Jul 19, 2026
f360122
fix: harden W28 embedding recovery
jstar0 Jul 19, 2026
2cd98ff
feat: expose retrieval worker embedding batches
jstar0 Jul 19, 2026
dbf3d15
docs: update qualified platform evidence
jstar0 Jul 19, 2026
f4ec942
fix: recover long vector projection outages
jstar0 Jul 19, 2026
77649b5
fix: align vector projection commit batches
jstar0 Jul 19, 2026
00c9b08
feat: support governed long embedding inputs
jstar0 Jul 19, 2026
837149e
test: track current retrieval schema
jstar0 Jul 19, 2026
f045d45
docs: qualify full vector retrieval
jstar0 Jul 20, 2026
ffcdcfe
feat: compare vector reader utility
jstar0 Jul 20, 2026
7a7f7f2
docs: freeze domestic reader utility run
jstar0 Jul 20, 2026
ae07103
docs: retain rejected domestic reader run
jstar0 Jul 20, 2026
be2953e
fix: stop disqualified reader runs
jstar0 Jul 20, 2026
34d0402
ci: bind signed snapshots to head revision
jstar0 Jul 21, 2026
e1449c3
fix: reject failed provider probes
jstar0 Jul 21, 2026
0a169ab
fix: use Vermory in probe reports
jstar0 Jul 21, 2026
8f18d0b
fix: restart OpenClaw service reliably
jstar0 Jul 21, 2026
307de4b
fix: pin OpenClaw bundled plugin root
jstar0 Jul 21, 2026
82e98de
docs: record OpenClaw bundled root verification
jstar0 Jul 21, 2026
ab99d7a
test: qualify three-client conversation bridges
jstar0 Jul 21, 2026
495fed0
docs: publish current capability evidence matrix
jstar0 Jul 22, 2026
193e55f
test: qualify real git workspace topology
jstar0 Jul 22, 2026
82609f0
feat: qualify browser web chat lifecycle
jstar0 Jul 22, 2026
bd635f0
docs: qualify three-client conversation bridge
jstar0 Jul 22, 2026
59a9dee
feat: add durable Linux service lifecycle
jstar0 Jul 22, 2026
ab1acc3
fix: preserve checkout during Linux acceptance
jstar0 Jul 22, 2026
8240914
fix: preserve protected serve defaults
jstar0 Jul 22, 2026
50d0676
fix: normalize PostgreSQL client version
jstar0 Jul 22, 2026
e04bd0a
fix: expose sanitized lifecycle evidence
jstar0 Jul 22, 2026
845401f
docs: qualify durable Linux lifecycle
jstar0 Jul 22, 2026
4be21af
ci: qualify native Linux arm64 lifecycle
jstar0 Jul 22, 2026
6021617
docs: qualify native Linux arm64 lifecycle
jstar0 Jul 22, 2026
7a2f394
test: qualify remote Git workspace topology
jstar0 Jul 22, 2026
ae803ea
build: add native Linux packages
jstar0 Jul 22, 2026
8b9df2b
fix: make RPM package scripts portable
jstar0 Jul 22, 2026
4a20942
ci: sign exact qualified Linux packages
jstar0 Jul 22, 2026
1496be4
docs: qualify native Linux packages
jstar0 Jul 22, 2026
8f7e1dd
docs: freeze database compatibility contract
jstar0 Jul 22, 2026
45dbdee
feat: enforce database schema compatibility
jstar0 Jul 22, 2026
4ec1586
docs: qualify database compatibility preflight
jstar0 Jul 22, 2026
7b196c1
test: freeze physical cross-host workspace contract
jstar0 Jul 22, 2026
85d4326
fix: preflight runtime schema before MCP and Web Chat
jstar0 Jul 22, 2026
3becbfb
fix: enforce tenant context in standalone runtimes
jstar0 Jul 22, 2026
ceafea6
fix: harden standalone runtime startup
jstar0 Jul 22, 2026
69ff909
docs: record physical cross-host workspace evidence
jstar0 Jul 22, 2026
78ab88f
docs: align W34 capability boundary
jstar0 Jul 22, 2026
7d0839d
feat: add authenticated remote web chat
jstar0 Jul 22, 2026
291291a
docs: record authenticated remote web chat qualification
jstar0 Jul 22, 2026
e656601
docs: keep runtime qualification counts separate
jstar0 Jul 22, 2026
f6723f7
feat: qualify signed Linux repositories
jstar0 Jul 22, 2026
2ba06ad
fix: stabilize native repository qualification
jstar0 Jul 22, 2026
87b358e
fix: bind package downloads and repository metadata
jstar0 Jul 22, 2026
1ead952
fix: read native RPM repository metadata
jstar0 Jul 22, 2026
eb073aa
fix: use native DNF5 package download
jstar0 Jul 22, 2026
eafe4b1
fix: capture DNF5 downloaded package bytes
jstar0 Jul 22, 2026
858e5af
fix: force DNF tamper verification
jstar0 Jul 22, 2026
78a6cbc
docs: record Linux repository qualification
jstar0 Jul 22, 2026
2ba918f
docs: align current I08 boundaries
jstar0 Jul 22, 2026
3720e55
feat: qualify Linux repository lifecycle
jstar0 Jul 22, 2026
b207698
fix: handle dormant service checks
jstar0 Jul 22, 2026
040d4b9
docs: record Linux repository lifecycle qualification
jstar0 Jul 22, 2026
48f67a3
docs: align post-I09 qualification boundaries
jstar0 Jul 22, 2026
bb3c919
feat: qualify external evaluation protocol
jstar0 Jul 22, 2026
989bea7
docs: record external evaluation protocol qualification
jstar0 Jul 22, 2026
812ba6b
feat: add macOS service rollback lifecycle
jstar0 Jul 22, 2026
47980be
test: add macOS lifecycle qualification runner
jstar0 Jul 22, 2026
3cc50b9
fix: harden macOS lifecycle evidence scan
jstar0 Jul 22, 2026
e8d2bd3
fix: clean macOS lifecycle launch agent residue
jstar0 Jul 22, 2026
2d6f06e
docs: qualify macOS authenticated service lifecycle
jstar0 Jul 23, 2026
1cae91e
feat: qualify durable fenced client operations
jstar0 Jul 23, 2026
bc0eb0e
docs: freeze long-running operation design
jstar0 Jul 23, 2026
8c7024c
docs: bind W36 evidence to exact commit
jstar0 Jul 23, 2026
4f275ba
ci: allow exact revision workflow dispatch
jstar0 Jul 23, 2026
2f67366
docs: support W36 fenced client lifecycle
jstar0 Jul 23, 2026
d7dd71d
docs: qualify W34 Grok cross-host continuity
jstar0 Jul 23, 2026
ee4d305
test: qualify real repository corpus
jstar0 Jul 23, 2026
0448767
docs: record Cursor account re-probe
jstar0 Jul 23, 2026
0befde7
docs: qualify real repository corpus
jstar0 Jul 23, 2026
51ffcb4
fix: preserve W34 evidence boundary
jstar0 Jul 23, 2026
996b0a7
docs: complete W37 delivery checklist
jstar0 Jul 23, 2026
6811b11
test: freeze official OpenClaw WebChat qualification
jstar0 Jul 23, 2026
95f29c6
docs: publish official OpenClaw qualification
jstar0 Jul 23, 2026
0087f90
docs: complete official OpenClaw checklist
jstar0 Jul 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 11 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Founding ownership. Add a second maintainer through a governance pull request
# before enabling required CODEOWNER reviews in branch protection.
* @jstar0

/.github/ @jstar0
/SECURITY.md @jstar0
/GOVERNANCE.md @jstar0
/docs/superpowers/specs/2026-07-11-vermory-product-constitution.md @jstar0
/internal/authn/ @jstar0
/internal/store/postgres/ @jstar0
/scripts/release-manifest.sh @jstar0
79 changes: 79 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
name: Reproducible defect
description: Report a public, reproducible Vermory defect with synthetic or authorized data.
title: "[Bug]: "
labels:
- bug
- needs-triage
body:
- type: markdown
attributes:
value: |
Do not use this form for credential exposure, cross-tenant leakage with real data, or another vulnerability whose public reproduction creates risk. Follow SECURITY.md instead.
- type: textarea
id: outcome
attributes:
label: Observed failure
description: What happened, and what user or operational task failed?
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected and forbidden behavior
description: State what should happen and what must never happen.
validations:
required: true
- type: dropdown
id: boundary
attributes:
label: Primary boundary
options:
- Workspace-backed continuity
- Conversation-backed continuity
- Global Defaults
- Bridge or rebind
- Formation or governance
- Retrieval or context delivery
- Deletion or lifecycle
- Authentication or tenant isolation
- Provider or client integration
- Packaging, deployment, or recovery
- Documentation or tooling
validations:
required: true
- type: input
id: revision
attributes:
label: Vermory revision or version
placeholder: commit SHA, tag, or vermory version output
validations:
required: true
- type: textarea
id: reproduction
attributes:
label: Minimal reproduction
description: Use synthetic or authorized minimized data. Include exact commands when safe.
render: shell
validations:
required: true
- type: textarea
id: environment
attributes:
label: Environment
description: OS, architecture, PostgreSQL version, client/provider version, and relevant non-secret configuration.
validations:
required: true
- type: textarea
id: evidence
attributes:
label: Redacted evidence
description: Logs, hashes, screenshots, or artifacts with credentials and private content removed.
- type: checkboxes
id: safety
attributes:
label: Safety confirmation
options:
- label: I removed credentials, private transcripts, tenant data, database dumps, and personal absolute paths.
required: true
- label: This can be discussed publicly without increasing security or privacy risk.
required: true
71 changes: 71 additions & 0 deletions .github/ISSUE_TEMPLATE/capability_proposal.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
name: Capability or architecture proposal
description: Propose a user-visible capability or a durable architecture decision.
title: "[Proposal]: "
labels:
- proposal
- needs-design
body:
- type: textarea
id: real_failure
attributes:
label: Real failure or workflow
description: Which real user, client, or operational workflow requires this change?
validations:
required: true
- type: textarea
id: outcome
attributes:
label: User-visible outcome
description: Describe what becomes possible or reliable without prescribing the implementation.
validations:
required: true
- type: textarea
id: expected_forbidden
attributes:
label: Expected and forbidden behavior
description: Include isolation, stale-state, deletion, privacy, and ambiguity behavior where relevant.
validations:
required: true
- type: dropdown
id: continuity
attributes:
label: Continuity scope
multiple: true
options:
- Workspace-backed continuity
- Conversation-backed continuity
- Global Defaults
- Cross-continuity bridge
- Operational or release boundary
validations:
required: true
- type: textarea
id: baseline
attributes:
label: Simpler baseline
description: What simpler implementation or existing behavior must be compared?
validations:
required: true
- type: textarea
id: acceptance
attributes:
label: Acceptance evidence
description: Name deterministic gates, real-client execution, negative controls, and explicit non-claims.
validations:
required: true
- type: textarea
id: migration
attributes:
label: Migration and rollback
description: Describe affected schema, data, clients, providers, or deployment profiles and how the change can be reversed.
- type: checkboxes
id: contract
attributes:
label: Product boundary
options:
- label: PostgreSQL remains the native semantic authority.
required: true
- label: Models may propose but cannot silently govern.
required: true
- label: The proposal does not rely on similarity alone to merge continuity or promote Global Defaults.
required: true
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Private security report
url: https://github.com/samekind/Vermory/security/advisories/new
about: Report leakage, credential exposure, deletion residue, or another security-sensitive issue privately.
- name: Contribution and repository workflow
url: https://github.com/samekind/Vermory/blob/main/CONTRIBUTING.md
about: Read the contribution, evidence, review, and delivery rules before opening an issue.
66 changes: 66 additions & 0 deletions .github/ISSUE_TEMPLATE/reality_case.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
name: Reality case or benchmark mapping
description: Contribute an authorized real trajectory, synthetic hard-gate case, or benchmark mapping.
title: "[Reality]: "
labels:
- reality-case
- needs-validation
body:
- type: dropdown
id: evidence_level
attributes:
label: Proposed evidence level
options:
- public
- withheld_local
- external sealed attestation
- official_dataset
- translated_proxy
- inspired_case
validations:
required: true
- type: textarea
id: source
attributes:
label: Source authorization and provenance
description: Explain why the source may be used, how it is minimized, and what must remain private.
validations:
required: true
- type: textarea
id: trajectory
attributes:
label: Multi-event trajectory
description: Describe anchors, event sequence, corrections, distractors, and the downstream task.
validations:
required: true
- type: textarea
id: assertions
attributes:
label: Expected and forbidden assertions
description: Prefer deterministic current-fact, stale-fact, scope, deletion, and artifact checks.
validations:
required: true
- type: textarea
id: baselines
attributes:
label: Relevant baselines
description: Identify no-context, full-history, summary, retrieval, external backend, or other comparable conditions.
validations:
required: true
- type: textarea
id: privacy
attributes:
label: Privacy and anonymization
description: State removed identifiers, path normalization, transcript minimization, and credential scanning.
validations:
required: true
- type: checkboxes
id: integrity
attributes:
label: Evidence integrity
options:
- label: I will not label repository-readable data as sealed.
required: true
- label: Failed baselines and attempts will remain in the evidence.
required: true
- label: The same generated output will not define the task, expected answer, and sole judgment.
required: true
53 changes: 53 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
version: 2
updates:
- package-ecosystem: gomod
directory: /
schedule:
interval: weekly
day: monday
time: "03:00"
timezone: Asia/Shanghai
open-pull-requests-limit: 5
groups:
go-runtime:
patterns:
- "*"

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
time: "03:30"
timezone: Asia/Shanghai
open-pull-requests-limit: 5
groups:
github-actions:
patterns:
- "*"

- package-ecosystem: npm
directory: /integrations/openclaw
schedule:
interval: weekly
day: monday
time: "04:00"
timezone: Asia/Shanghai
open-pull-requests-limit: 5
groups:
openclaw:
patterns:
- "*"

- package-ecosystem: pip
directory: /integrations/hermes
schedule:
interval: weekly
day: monday
time: "04:30"
timezone: Asia/Shanghai
open-pull-requests-limit: 5
groups:
hermes:
patterns:
- "*"
62 changes: 62 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
## Outcome

<!-- Describe the user-visible or operational result, not only the files changed. -->

## Why This Change

<!-- Link the issue, real failure, reality case, hypothesis, design, ADR, or security advisory. -->

## Scope

- Continuity mode or operational boundary:
- Authoritative state affected:
- Client/provider surface affected:
- Explicitly out of scope:

## Product Contract

- [ ] PostgreSQL remains the only native semantic authority.
- [ ] Models/providers cannot silently grant authority to their output.
- [ ] Tenant, continuity, lifecycle, privacy, and deletion gates remain enforced before delivery.
- [ ] Global Defaults remain thin and explicitly governed.
- [ ] Cross-continuity movement is explicit rather than similarity-driven.
- [ ] This change does not revive Gemini CLI as an active client target.
- [ ] Not applicable; this pull request does not change product behavior.

## Verification

<!-- List exact commands and results. Do not write only "tests pass". -->

```text
command -> result
```

## Evidence And Claim Boundary

- Evidence level: `none` / `public` / `withheld_local` / `sealed attestation`
- Real clients/models actually executed:
- Retained failures or negative controls:
- This pull request proves:
- This pull request does not prove:

## Security And Privacy

- [ ] No credential, OIDC token, private key, private transcript, database dump, full environment, or personal absolute path is included.
- [ ] Fixtures are synthetic or authorized and minimized.
- [ ] Deletion, leakage, source-injection, and wrong-binding impact has been considered.
- [ ] Security-sensitive details are handled privately when public disclosure would create risk.

## Migration And Rollback

<!-- Describe schema/config migration, compatibility, and rollback. Write "not applicable" with a reason when appropriate. -->

## Delivery Checklist

- [ ] The change is focused and unrelated cleanup is excluded.
- [ ] Frozen expectations were added or revised before capability implementation.
- [ ] Positive and negative tests cover the affected contract.
- [ ] `bash scripts/repository-policy.sh` passes.
- [ ] Affected local tests, full Go tests, race tests, and `go vet` pass as applicable.
- [ ] OpenClaw and Hermes checks pass when their surfaces are affected.
- [ ] Documentation, evidence, and failure records match the implementation.
- [ ] The latest pull-request head passes protected `test` and `sign-snapshot` checks.
Loading
Loading