Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
155 commits
Select commit Hold shift + click to select a range
7d9df71
ci: verify workflow write permission
seonghobae Aug 27, 2026
480a48c
ci: stage ELUNVERA baseline payload 01
seonghobae Aug 27, 2026
210bc08
ci: stage ELUNVERA baseline payload 02
seonghobae Aug 27, 2026
b3e3c86
ci: stage ELUNVERA baseline payload 03
seonghobae Aug 27, 2026
58817b3
ci: stage ELUNVERA baseline payload 04
seonghobae Aug 27, 2026
a56287c
ci: stage ELUNVERA baseline payload 05
seonghobae Aug 27, 2026
23e1e5b
ci: stage ELUNVERA baseline payload 06
seonghobae Aug 27, 2026
a5e4845
ci: stage ELUNVERA baseline payload 07
seonghobae Aug 27, 2026
6d9df83
ci: stage ELUNVERA baseline payload 08
seonghobae Aug 27, 2026
0e431f5
docs: add ELUNVERA first-slice ADR, PRD, TRD, and product CI
seonghobae Aug 27, 2026
5aed277
ci: stage ELUNVERA baseline payload 09
seonghobae Aug 27, 2026
02cd2c7
feat: ship activation-queue home as first relationship-activation sur…
seonghobae Aug 27, 2026
2f642e1
ci: materialize verified ELUNVERA documentation baseline
seonghobae Aug 27, 2026
bf6a113
ci: pause ELUNVERA baseline bootstrap during payload repair
seonghobae Aug 27, 2026
dbe1387
ci: repair ELUNVERA baseline payload 07
seonghobae Aug 27, 2026
47ea3f8
ci: rerun verified ELUNVERA baseline materialization
seonghobae Aug 27, 2026
e8166dc
docs: establish ELUNVERA product and technical baseline
github-actions[bot] Aug 27, 2026
1c31ca4
ci: stage ELUNVERA contract repair patch
seonghobae Aug 29, 2026
3572e83
ci: run bounded ELUNVERA contract repair
seonghobae Aug 29, 2026
3eab23a
fix: align HTTP and event contract coherence
github-actions[bot] Aug 29, 2026
54d445f
ci: stage activation-queue review repair
seonghobae Aug 29, 2026
ab9d1e8
ci: verify activation-queue review repair
seonghobae Aug 29, 2026
18bed7f
ci: fix activation repair commit guard
seonghobae Aug 29, 2026
5c457f4
fix: harden activation queue review boundaries
github-actions[bot] Aug 29, 2026
2069f18
build: add hash-locked Python CI dependencies
seonghobae Aug 29, 2026
60e4315
build: enforce hash-locked CI installation
seonghobae Aug 29, 2026
b277897
build: update pytest to fixed release
seonghobae Aug 29, 2026
ca6e984
build: lock patched pytest wheel
seonghobae Aug 29, 2026
8dd9857
fix: require event provenance
seonghobae Aug 29, 2026
0601ef8
ci: verify required event provenance
seonghobae Aug 29, 2026
fe5b69c
chore: refresh required-provenance manifest
github-actions[bot] Aug 29, 2026
14351f1
ci: add exact-head document contract validation
seonghobae Aug 29, 2026
cbf281d
ci: refresh exact-head document manifest
seonghobae Aug 29, 2026
208f980
chore: refresh exact-head document manifest
github-actions[bot] Aug 29, 2026
bc7e86c
ci: trigger exact-head document contract validation
seonghobae Aug 29, 2026
b0dcb30
ci: repair remaining contract review findings
seonghobae Aug 29, 2026
41b7dd4
ci: fix bounded review repair workflow
seonghobae Aug 29, 2026
538e563
ci: surface and commit bounded review repairs
seonghobae Aug 29, 2026
a71a5da
ci: make review repair atomic
seonghobae Aug 29, 2026
d0ce17e
ci: launch independent atomic review repair
seonghobae Aug 29, 2026
44d7885
ci: stage deterministic contract review repair
seonghobae Aug 29, 2026
88ea9a9
ci: execute deterministic contract review repair
seonghobae Aug 29, 2026
5e8d712
ci: reconcile reviewed contract baseline atomically
seonghobae Aug 29, 2026
4f708cf
ci: finalize permanent contract validation baseline
seonghobae Aug 29, 2026
d317c4a
ci: gate PR 2 on exact-head evidence
seonghobae Aug 29, 2026
e4812e5
ci: enable review on develop pull requests
seonghobae Aug 29, 2026
8a42f56
docs(metadata): add Ask DeepWiki badge
seonghobae Sep 1, 2026
695acca
docs(metadata): add public documentation landing page
seonghobae Sep 1, 2026
1a82844
ci: remove one-shot reconciliation workflow
seonghobae Sep 2, 2026
3f068c8
ci: remove superseded reconciliation workflow
seonghobae Sep 2, 2026
11cc8cb
ci: remove superseded reconciliation workflow
seonghobae Sep 2, 2026
da7e64a
ci: remove temporary review repair workflow
seonghobae Sep 2, 2026
c5a0d39
ci: remove temporary review repair workflow
seonghobae Sep 2, 2026
10ca2d3
ci: remove temporary review repair workflow
seonghobae Sep 2, 2026
f8eda92
ci: remove one-shot review repair script
seonghobae Sep 2, 2026
9df5819
docs: license ELUNVERA source under Apache-2.0
seonghobae Sep 2, 2026
9484adf
docs: make ELUNVERA license boundary explicit
seonghobae Sep 2, 2026
4a152c4
docs: accept Apache-2.0 source license decision
seonghobae Sep 2, 2026
1a4ba8d
docs: record accepted license ADR
seonghobae Sep 2, 2026
c7f837f
docs: record source license and public landing
seonghobae Sep 2, 2026
a1b9070
docs: correct validation inventory and schema claim
seonghobae Sep 2, 2026
33e6f33
docs: close repository source-license gap
seonghobae Sep 2, 2026
1523282
docs: make public landing license-aware
seonghobae Sep 2, 2026
80ad3d8
test: forbid bundled demo data at runtime
seonghobae Sep 2, 2026
04730da
fix: start runtime without synthetic relationships
seonghobae Sep 2, 2026
b5ceb6e
chore: remove shipped synthetic relationship data
seonghobae Sep 2, 2026
6e8aab7
docs: reconcile commercialization baseline and DDD boundary
seonghobae Sep 2, 2026
50324d3
test: require truthful accessible empty state
seonghobae Sep 2, 2026
5898eca
fix: make empty state truthful and accessible
seonghobae Sep 2, 2026
aed26e0
test: hide internal product boundaries from customer UI
seonghobae Sep 2, 2026
eeb8948
fix: keep customer copy product-facing
seonghobae Sep 2, 2026
2f5161c
test: forbid serving repository internals
seonghobae Sep 2, 2026
596073b
fix: allowlist browser assets at HTTP boundary
seonghobae Sep 2, 2026
41a1b33
docs: record prototype security and UX repairs
seonghobae Sep 2, 2026
c3b1fc1
test: close inherited HEAD static-file bypass
seonghobae Sep 2, 2026
ab2e8a1
fix: apply route allowlist to HEAD requests
seonghobae Sep 2, 2026
748b3bf
test: reject untrusted hosts and simple POST media types
seonghobae Sep 2, 2026
b17e832
fix: harden loopback request trust boundary
seonghobae Sep 2, 2026
dde0580
test: keep deleted demo data out of queue fixtures
seonghobae Sep 2, 2026
d1f8729
test: require semantic relationship identifiers
seonghobae Sep 2, 2026
7be7d03
fix: use semantic relationship identifiers
seonghobae Sep 2, 2026
192629e
fix: propagate semantic relationship IDs to browser actions
seonghobae Sep 2, 2026
d548f4b
test: fail closed on relationship identity collisions
seonghobae Sep 2, 2026
4e8e445
fix: protect relationship aggregate identity
seonghobae Sep 2, 2026
30bc396
docs: record aggregate identity invariants
seonghobae Sep 2, 2026
9fc86f5
ci: validate docs on canonical main PRs
seonghobae Sep 2, 2026
b9101a7
ci: review canonical main pull requests
seonghobae Sep 2, 2026
40c694a
docs: align integration branch with protected main
seonghobae Sep 2, 2026
6b1c71c
docs: point public navigation at canonical main
seonghobae Sep 2, 2026
c43c978
docs: record identity and foundation integration gaps
seonghobae Sep 2, 2026
3516b06
docs: reserve ADR 0017 for relationship activation
seonghobae Sep 2, 2026
1cd3084
docs: reference collision-free activation ADR
seonghobae Sep 2, 2026
e225ccc
docs: align TRD identity and ADR authority
seonghobae Sep 2, 2026
33a8fc4
docs: retire colliding activation ADR number
seonghobae Sep 2, 2026
ed5451e
docs: record repaired ADR numbering
seonghobae Sep 2, 2026
888f68a
docs: record collision-free ADR migration
seonghobae Sep 2, 2026
8703232
docs: keep license ADR Proposed until integration
seonghobae Sep 2, 2026
ba50300
docs: align ADR index with Draft foundation status
seonghobae Sep 2, 2026
82e6488
docs: reconcile governance and Draft decision evidence
seonghobae Sep 2, 2026
9fcb3c2
docs: record canonical-main governance repairs
seonghobae Sep 2, 2026
c1bddee
chore: reseal exact foundation manifest
seonghobae Sep 2, 2026
df5bc9f
docs: align agent base with canonical main
seonghobae Sep 2, 2026
6a011d9
docs: align contribution base with canonical main
seonghobae Sep 2, 2026
8f33bb9
docs: make PRD branch authority canonical
seonghobae Sep 2, 2026
3f5966e
docs: align roadmap with canonical main
seonghobae Sep 2, 2026
2723797
docs: align foundation spec with canonical main
seonghobae Sep 2, 2026
728c416
docs: align implementation plan with canonical main
seonghobae Sep 2, 2026
cff9c6f
docs: record canonical branch authority reconciliation
seonghobae Sep 2, 2026
c2a1dd9
chore: reseal canonical branch manifest
seonghobae Sep 2, 2026
3cbe9e0
ci: guard canonical main authority
seonghobae Sep 2, 2026
86b87bf
docs: record branch-authority contract guard
seonghobae Sep 2, 2026
862222a
chore: reseal branch-authority manifest
seonghobae Sep 2, 2026
7f2765b
ci: support exact-head stacked product PRs
seonghobae Sep 2, 2026
0817786
docs: record stacked exact-head product CI
seonghobae Sep 2, 2026
2b53665
test: fail closed on invalid activation snapshots
seonghobae Sep 2, 2026
eff4772
fix: validate activation snapshots and terminal transitions
seonghobae Sep 2, 2026
56cecd6
docs: record activation snapshot invariants
seonghobae Sep 2, 2026
fea8eb2
docs: reconcile exact activation and Actions evidence
seonghobae Sep 2, 2026
d547d8d
test: reject malformed buyer-visible activation facts
seonghobae Sep 2, 2026
3aea358
fix: reject coerced activation source facts
seonghobae Sep 2, 2026
920b772
docs: record activation source-fact validation
seonghobae Sep 2, 2026
a9ee439
docs: trace fail-closed activation source facts
seonghobae Sep 2, 2026
589881e
docs: bind activation source invariants to ADR 0017
seonghobae Sep 2, 2026
3dce118
test(docs): fail closed on performance and locale contract drift
seonghobae Sep 2, 2026
589c572
docs(prd): adopt eight-locale and 20ms buyer contracts
seonghobae Sep 2, 2026
d9917c6
docs(trd): bind runtime, locale and translation contracts
seonghobae Sep 2, 2026
8675051
docs(ux): define eight-locale versioned translation UX
seonghobae Sep 2, 2026
2dea0a4
docs(test): enforce realistic 20ms and eight-locale evidence
seonghobae Sep 2, 2026
73f9b06
docs(gap): reconcile commercialization performance and i18n gaps
seonghobae Sep 2, 2026
7c0098c
docs(changelog): record commercialization contract repair
seonghobae Sep 2, 2026
d7cd411
chore(manifest): reseal commercialization contract evidence
seonghobae Sep 2, 2026
2eca10e
test(http): reject action type coercion
seonghobae Sep 2, 2026
31a280d
fix(http): fail closed on action value types
seonghobae Sep 2, 2026
6f68ace
docs(changelog): trace fail-closed action typing
seonghobae Sep 2, 2026
11943ce
docs(gap): record typed action boundary evidence
seonghobae Sep 2, 2026
6cc7029
ci(actions): restamp current head after startup failure
seonghobae Sep 4, 2026
7a4928a
ci(actions): restamp current head after startup failure
seonghobae Sep 4, 2026
0d98fc4
chore: refresh head after Actions startup failure
seonghobae Sep 4, 2026
e964db0
chore: refresh head after Actions startup failure
seonghobae Sep 4, 2026
5a99dd8
ci(actions): scope product checks by pull request
seonghobae Sep 4, 2026
223228f
ci(actions): scope document checks by pull request
seonghobae Sep 4, 2026
4a12ecd
ci: enforce tracked text hygiene
seonghobae Sep 30, 2026
85f0ff3
fix: harden relationship evidence contract
seonghobae Sep 30, 2026
5a51442
fix: address exact-head contract review
seonghobae Sep 30, 2026
b8de51c
merge: integrate canonical ELUNVERA foundation
seonghobae Oct 1, 2026
16e5832
test: reproduce activation concurrency and UI trust failures
seonghobae Oct 1, 2026
c7ee040
fix: serialize activation decisions and preserve command truth
seonghobae Oct 1, 2026
cb6e635
docs: record prototype integrity repair evidence
seonghobae Oct 1, 2026
bfc7b2f
test: reproduce ABA and ambiguous response failures
seonghobae Oct 1, 2026
86370d6
fix: reject stale snapshots after ABA transitions
seonghobae Oct 1, 2026
9565da8
fix: preserve accepted command truth on unreadable responses
seonghobae Oct 1, 2026
a1027c9
docs: bind ABA and ambiguous success repair evidence
seonghobae Oct 1, 2026
149dc16
test: reproduce ambiguous transport retry risk
seonghobae Oct 1, 2026
67b7186
fix: reconcile ambiguous transport outcomes before retry
seonghobae Oct 1, 2026
a16229f
docs: record fail-closed transport reconciliation
seonghobae Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .coderabbit.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
reviews:
auto_review:
enabled: true
base_branches:
- main
- develop
review_status: true
48 changes: 48 additions & 0 deletions .cwl/data-management.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
schema_version: '1.0'
repository: ContextualWisdomLab/ELUNVERA
product_name: ELUNVERA
authoritative_data_assets:
- asset_code: customer_relationship_record
description: Tenant-scoped parties, accounts, roles, relationships, evidence, and history.
data_classification: restricted_personal_and_commercial
system_of_record: true
- asset_code: commercial_opportunity_record
description: Opportunity process, stage, value, forecast, stakeholder, and outcome history.
data_classification: confidential_commercial
system_of_record: true
- asset_code: complaint_outcome_record
description: Complaint, remedy, customer response, satisfaction observation, and outcome history.
data_classification: restricted_customer_case
system_of_record: true
data_owner_role: elunvera_product_owner
data_steward_role: tenant_data_steward
critical_data_elements:
- party_identity_reference
- relationship_truth_status
- relationship_valid_time
- account_owner_assignment
- opportunity_stage_history
- monetary_amount_and_currency
- communication_preference
- complaint_status
quality_rule_references:
- docs/DATA_MODEL.md#18-data-quality-invariants
- docs/TEST_STRATEGY.md
retention_policy_references:
- docs/PRIVACY.md#8-retention-and-disposition
- docs/adr/0015-retention-disposition.md
lineage_producers:
- elunvera_api
- elunvera_worker
lineage_consumers:
- semantic_data_portal
- lineageweave
applicable_knowledge_areas:
- data_governance
- data_quality
- metadata_management
- data_security
- data_integration_and_interoperability
assessment_exclusions:
- code: production_runtime_evidence
reason: The repository baseline contains no implemented runtime.
38 changes: 38 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
## Product outcome

Describe the buyer- or operator-visible problem closed by this PR.

## Scope and boundaries

- Owning ELUNVERA responsibility:
- CWL dependencies consumed by contract:
- Explicitly excluded work:

## Evidence

- Exact head:
- Tests and commands actually run:
- Coverage and documentation denominators:
- Migration/restore/security/accessibility/model evidence, where applicable:

## Data and privacy

- Data assets and classifications changed:
- Tenant, purpose, retention, legal-hold, and export impacts:
- New event fields reviewed for PII/secrets:

## Contracts and docs

- [ ] OpenAPI/AsyncAPI/JSON Schema updated
- [ ] ADR updated or decision remains conformant
- [ ] `docs/product-technical-gap-baseline.md` updated
- [ ] `CHANGELOG.md` updated
- [ ] Doctoring and references updated

## Review gate

- [ ] Current-head checks complete
- [ ] Independent approval received
- [ ] Unresolved threads are zero
- [ ] No queued/pending/skipped check is represented as successful
- [ ] One-shot/self-modifying workflow removed after its purpose
66 changes: 66 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
name: product-ci

on:
pull_request:
push:
branches: [main]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: product-ci-${{ github.repository }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true

jobs:
activation-queue:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check out exact revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false

- name: Verify exact checkout
env:
EXPECTED_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"

- name: Set up Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # actions/setup-python@v6
with:
python-version: "3.12"

- name: Install hash-locked Python test dependencies
env:
PIP_DISABLE_PIP_VERSION_CHECK: "1"
run: >-
python -m pip install --no-input --only-binary=:all:
--require-hashes -r requirements-ci.txt

Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
- name: Run Python tests with complete production coverage
run: |
python -m coverage run --branch -m pytest -q
python -m coverage report \
--include='src/elunvera/*,scripts/serve.py' \
--fail-under=100

- name: Compile Python entry points
run: python -m py_compile scripts/serve.py src/elunvera/queue.py

- name: Set up Node
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # actions/setup-node@v5
with:
node-version: "24"

- name: Run browser tests with complete production coverage
run: >-
node --test --experimental-test-coverage
--test-coverage-include='web/*.js'
--test-coverage-lines=100
--test-coverage-branches=100
--test-coverage-functions=100
tests/test_app.mjs
Loading
Loading