Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/0.1-AI-MANIFEST.a2ml
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
# SPDX-License-Identifier: MPL-2.0

# AI Manifest - Level 1: .github
3 changes: 3 additions & 0 deletions .github/CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk> -->
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# Code of Conduct

<!--
Expand Down
3 changes: 3 additions & 0 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk> -->
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# Clone the repository
git clone https://github.com/hyperpolymath/vql-ut.git
cd vcl-total
Expand Down
3 changes: 3 additions & 0 deletions .github/DIRECTORY.adoc
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
// SPDX-FileCopyrightText: Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
// SPDX-License-Identifier: CC-BY-SA-4.0

= .github Pillar
3 changes: 3 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
<!-- SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk> -->
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# Security Policy

<!--
Expand Down
3 changes: 3 additions & 0 deletions .github/funding.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
# SPDX-License-Identifier: MPL-2.0

# Funding Configuration
# See: https://docs.github.com/en/repositories/managing-your-repositorys-custom-fields/displaying-a-sponsor-button-in-your-repository

Expand Down
4 changes: 2 additions & 2 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
- [ ] No banned language patterns (no TypeScript, no npm/bun, no Go/Python)
- [ ] No `unsafe` blocks without `// SAFETY:` comments
- [ ] No banned functions (`believe_me`, `unsafeCoerce`, `Obj.magic`, `Admitted`, `sorry`)
- [ ] SPDX license headers present on all new/modified source files
- [ ] REUSE and repository license policy pass (`just license-check`)
- [ ] No secrets, credentials, or `.env` files included

### As Applicable
Expand All @@ -32,7 +32,7 @@
- [ ] Documentation updated for user-facing changes
- [ ] `TOPOLOGY.md` updated (if architecture changed)
- [ ] `CHANGELOG` or release notes updated
- [ ] New dependencies reviewed for license compatibility (MPL-2.0 / MPL-2.0)
- [ ] New dependencies reviewed for license compatibility (MPL-2.0 code; CC-BY-SA-4.0 documentation)
- [ ] ABI/FFI changes validated (`src/interface/abi/` and `src/interface/ffi/` consistent)

## Testing
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# SPDX-License-Identifier: MPL-2.0
name: Governance

on:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# SPDX-License-Identifier: MPL-2.0
name: Hypatia Security Scan

on:
Expand Down
15 changes: 8 additions & 7 deletions .github/workflows/reuse.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# SPDX-License-Identifier: MPL-2.0

Check warning on line 1 in .github/workflows/reuse.yml

View workflow job for this annotation

GitHub Actions / Hypatia neurosymbolic scan

[hypatia] `on:` fires both push and pull_request with the push trigger unscoped — every PR-branch push runs this workflow twice (D-BURN). Scope push to the default branch and add a `concurrency:` cancel block (scripts/ci-health/remediate.sh D-BURN applies both).
# Fail-closed REUSE compliance gate.
# Blocks merge if any file is missing SPDX copyright/licence information.
# Fail-closed project licensing gate: REUSE compliance plus the repository policy contract.
---
name: REUSE compliance

Expand All @@ -12,13 +11,15 @@
contents: read

jobs:
reuse-lint:
license-policy:
name: license-policy
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install reuse
run: pip install reuse
- name: Install pinned REUSE checker
run: python -m pip install 'reuse[charset-normalizer]==6.2.0'

- name: Check REUSE compliance
run: reuse lint
- name: Check REUSE and project license policy
run: bash scripts/check-license-policy.sh
2 changes: 1 addition & 1 deletion .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# SPDX-License-Identifier: MPL-2.0
name: OSSF Scorecard

on:
Expand Down
173 changes: 0 additions & 173 deletions .machine_readable/6a2/STATE.a2ml

This file was deleted.

4 changes: 3 additions & 1 deletion .machine_readable/MUST.contractile
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,9 @@

; License
(must "SPDX-License-Identifier header on every source file")
(must "no removal or modification of LICENSE file")
(must "software is MPL-2.0 and human-readable documentation is CC-BY-SA-4.0")
(must "REUSE lint and scripts/check-license-policy.sh pass")
(must "no removal or modification of root LICENSE file")

; Structure
(must ".machine_readable/ directory preserved")
Expand Down
46 changes: 45 additions & 1 deletion .machine_readable/README.adoc
Original file line number Diff line number Diff line change
@@ -1 +1,45 @@
= .machine_readable Pillar
// SPDX-License-Identifier: CC-BY-SA-4.0
// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
= .machine_readable — Authority and File Map

This directory contains the repository's machine-readable project state and
operational policy. The distinction between the similarly named contractile
directories is intentional; they are not interchangeable copies.

== Canonical project state

* `STATE.a2ml` is the *single canonical project checkpoint*.
* `.machine_readable/6a2/STATE.a2ml` was a byte-identical stale mirror and has
been removed. Do not recreate it; update only `STATE.a2ml`.
* `.machine_readable/6a2/` holds the related 6a2 agent, metadata, and playbook
files, not a second project-state database.

== Contractile locations

[cols="1,3"]
|===
|Path |Role

|`.machine_readable/*.contractile`
|Legacy-format invariant, intent, and trust declarations. They are retained
as source documents; do not treat them as generated Nickel runner files.

|`.machine_readable/contractiles/`
|Operational contractile data and Nickel runner/schema files, organized by
verb. This is the working repository policy set and the example source used
by the docs templates.

|`contractiles/`
|Input directory for the generated top-level `contractile.just` recipes
(`contractile gen-just --dir contractiles`). Keep that generator relationship
explicit; this tree is not a byte-for-byte mirror of the operational set.

|`docs/templates/contractiles/`
|Documentation-only starter templates. The README and each template direct
contributors to copy an explicitly selected template into
`.machine_readable/contractiles/`; they are not live policy.
|===

When changing a rule, update its authoritative source above and any generated
output through the documented generator. Never copy an entire tree over
another merely because the directory names match.
Loading
Loading