Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
202 commits
Select commit Hold shift + click to select a range
d982729
docs: start milestone v1.5 Polyglot Receipt Protocol + Conformance Ve…
LakshmanTurlapati Jun 24, 2026
45a7552
docs: archive v1.4 research before v1.5 research cycle
LakshmanTurlapati Jun 24, 2026
2090b00
docs: v1.5 research files (STACK, FEATURES, ARCHITECTURE, PITFALLS)
LakshmanTurlapati Jun 24, 2026
2f22e43
docs: v1.5 research summary
LakshmanTurlapati Jun 24, 2026
5cb271a
docs: define milestone v1.5 requirements
LakshmanTurlapati Jun 24, 2026
a64a114
docs: create milestone v1.5 roadmap (7 phases)
LakshmanTurlapati Jun 24, 2026
d076c06
docs(50): capture phase context
LakshmanTurlapati Jun 25, 2026
9cba9a5
docs(state): record phase 50 context session
LakshmanTurlapati Jun 25, 2026
289310d
docs(phase-50): research protocol specification phase
LakshmanTurlapati Jun 25, 2026
dffcc2c
docs(50): research + validation strategy
LakshmanTurlapati Jun 25, 2026
f2a2c95
docs(50): create phase 50 plan — Protocol Specification (3 plans, 2 w…
LakshmanTurlapati Jun 25, 2026
55bbf69
docs(50): create phase plan
LakshmanTurlapati Jun 25, 2026
4080624
feat(50-01): write spec/generate-vector0.ts — vector #0 generator script
LakshmanTurlapati Jun 25, 2026
9e5c775
feat(50-01): run generator; commit spec/vector0-fixture.json
LakshmanTurlapati Jun 25, 2026
a6e1d9e
docs(50-01): complete plan 01 — vector #0 generator + fixture summary
LakshmanTurlapati Jun 25, 2026
5ecd824
docs(50-02): author spec/SPEC.md §1–§5 (terminology through verificat…
LakshmanTurlapati Jun 25, 2026
83ada05
docs(50-02): complete spec/SPEC.md §6–§9 + Appendix A (outputHash, ke…
LakshmanTurlapati Jun 25, 2026
73216d6
docs(50-02): complete protocol-specification plan 02 — SPEC.md summar…
LakshmanTurlapati Jun 25, 2026
984e181
feat(50-03): author JSON Schema draft 2020-12 for receipt body v1.1, …
LakshmanTurlapati Jun 25, 2026
995ed07
docs(50-03): author spec/CHANGELOG.md with per-version receipt schema…
LakshmanTurlapati Jun 25, 2026
4ae58cc
docs(50-03): complete JSON Schema + CHANGELOG plan — SUMMARY, STATE, …
LakshmanTurlapati Jun 25, 2026
8d42ead
chore: re-stamp latticeVersion from package.json (1.3.0 -> 1.4.0)
LakshmanTurlapati Jun 25, 2026
d2fd423
fix(50): correct payloadType length 38->36 in SPEC.md; close schema g…
LakshmanTurlapati Jun 25, 2026
28864cd
fix(50): correct final payloadType byte-length prose callout 38->36 (…
LakshmanTurlapati Jun 25, 2026
4176dd6
docs(phase-50): complete phase execution
LakshmanTurlapati Jun 25, 2026
03a96ca
docs(phase-50): reconcile VERIFICATION (13/13 passed) and ROADMAP che…
LakshmanTurlapati Jun 25, 2026
9f463be
docs(phase-50): code review report (findings resolved in 28864cd + d2…
LakshmanTurlapati Jun 25, 2026
e680380
docs(51): smart discuss context
LakshmanTurlapati Jun 25, 2026
ce8f76c
docs(51): research conformance vector generator phase
LakshmanTurlapati Jun 25, 2026
778850c
docs(51): research + validation strategy
LakshmanTurlapati Jun 25, 2026
5c5a7ae
docs(51): create phase 51 plan — conformance vector generator + commi…
LakshmanTurlapati Jun 25, 2026
0841d32
docs(51): create phase plan
LakshmanTurlapati Jun 25, 2026
b0197b2
chore(51-01): scaffold @lattice-conformance/generate private pnpm pac…
LakshmanTurlapati Jun 25, 2026
3724188
feat(51-01): define ConformanceVector type, main.ts flag gate, VEC-02…
LakshmanTurlapati Jun 25, 2026
9bfc7a8
docs(51-01): complete plan 51-01 — ConformanceVector scaffold summary…
LakshmanTurlapati Jun 25, 2026
3ac786f
test(51-02): add failing tests for RFC 8785 cross-checks and positive…
LakshmanTurlapati Jun 25, 2026
c73008b
feat(51-02): implement RFC 8785 cross-checks and positive vector gene…
LakshmanTurlapati Jun 25, 2026
00530ca
test(51-02): extend main.test.ts for VEC-03/VEC-05/byte-identity/file…
LakshmanTurlapati Jun 25, 2026
39166a0
feat(51-02): wire main.ts generator and commit 3 positive conformance…
LakshmanTurlapati Jun 25, 2026
9447721
docs(51-02): complete plan 02 — positive vectors + RFC 8785 cross-che…
LakshmanTurlapati Jun 25, 2026
d055eb7
test(51-03): add failing tests for negative vectors (VEC-04) and mani…
LakshmanTurlapati Jun 25, 2026
3f9b84f
feat(51-03): implement negative vector generator — 9 adversarial cons…
LakshmanTurlapati Jun 25, 2026
71499fa
feat(51-03): manifest writer, final main.ts wiring, 9 negative vector…
LakshmanTurlapati Jun 25, 2026
ff204fc
docs(51-03): complete plan 03 — negative vectors + MANIFEST.sha256 su…
LakshmanTurlapati Jun 25, 2026
55e2ab0
docs(51): commit verification report + fix VEC-03/VEC-05 checkbox drift
LakshmanTurlapati Jul 1, 2026
204bbfe
docs(52): smart discuss context
LakshmanTurlapati Jul 1, 2026
6a41336
docs(52): research phase domain — TS self-verification harness
LakshmanTurlapati Jul 1, 2026
ad11adf
docs(52): research + validation strategy
LakshmanTurlapati Jul 1, 2026
2fbdfe9
docs(52): create phase plan
LakshmanTurlapati Jul 1, 2026
6a07720
docs(52): pattern map + plan-checker doc fixes
LakshmanTurlapati Jul 1, 2026
56736d6
feat(52-01): scaffold conformance/verify-ts package + manifest self-c…
LakshmanTurlapati Jul 1, 2026
46e3117
feat(52-01): positive vector 4-step byte-identity re-derivation
LakshmanTurlapati Jul 1, 2026
de1c2f7
feat(52-01): negative vector verdict assertion + full workspace evidence
LakshmanTurlapati Jul 1, 2026
54f7ed9
docs(52-01): complete plan 01 — TypeScript self-verification harness …
LakshmanTurlapati Jul 1, 2026
bf9e152
docs(52-01): append self-check result to plan 01 summary
LakshmanTurlapati Jul 1, 2026
58d31c2
chore: merge executor worktree (worktree-agent-ac6e45ad47a168fda)
LakshmanTurlapati Jul 1, 2026
9b76529
feat: complete v1.5 Python conformance milestone
LakshmanTurlapati Jul 6, 2026
20b28d1
chore: remove REQUIREMENTS.md for v1.5 milestone
LakshmanTurlapati Jul 6, 2026
d17c097
docs: update retrospective for v1.5
LakshmanTurlapati Jul 6, 2026
2167011
chore: archive phase directories from v1.5 milestone
LakshmanTurlapati Jul 6, 2026
2017b29
docs(paper): refresh for v1.5 conformance
LakshmanTurlapati Jul 7, 2026
a53c1d2
fix: address conformance and package README review findings
LakshmanTurlapati Jul 7, 2026
5281037
Merge remote-tracking branch 'origin/main' into changeset-release/mai…
LakshmanTurlapati Jul 16, 2026
2724e2e
docs: start milestone v1.6 Protocol and Runtime Integrity Bridge
LakshmanTurlapati Jul 16, 2026
d79112b
docs: research milestone v1.6 integrity bridge
LakshmanTurlapati Jul 16, 2026
8a688a6
docs: define milestone v1.6 requirements
LakshmanTurlapati Jul 16, 2026
b642ce8
docs: create milestone v1.6 roadmap (6 phases)
LakshmanTurlapati Jul 16, 2026
14707f1
docs(57): smart discuss context
LakshmanTurlapati Jul 16, 2026
e96ee40
docs(57): add protocol research and validation
LakshmanTurlapati Jul 16, 2026
783a0f2
docs(57): refine executable validation
LakshmanTurlapati Jul 16, 2026
8a17fe5
docs(57): create phase plan
LakshmanTurlapati Jul 16, 2026
ba19245
feat(57-01): issue standard DSSE v1.4 receipts
LakshmanTurlapati Jul 16, 2026
d70c92f
feat(57-01): add bounded legacy receipt verification
LakshmanTurlapati Jul 16, 2026
ee50e58
feat(57-01): expose receipt profile policy types
LakshmanTurlapati Jul 16, 2026
b1a1623
docs(57-01): complete TypeScript protocol semantics plan
LakshmanTurlapati Jul 16, 2026
d4347ff
feat(57-02): mirror Python receipt profile bridge
LakshmanTurlapati Jul 16, 2026
f03f116
docs(57-02): complete Python protocol parity plan
LakshmanTurlapati Jul 16, 2026
ede1e1a
fix(57): align Python verifier input validation
LakshmanTurlapati Jul 16, 2026
4204596
docs(57): add code review report
LakshmanTurlapati Jul 16, 2026
46d855c
docs(phase-57): complete phase execution
LakshmanTurlapati Jul 16, 2026
6116387
docs(58): capture phase context
LakshmanTurlapati Jul 16, 2026
4c4b798
docs(58): correct canonical context paths
LakshmanTurlapati Jul 16, 2026
aad775d
docs(58): research conformance migration
LakshmanTurlapati Jul 16, 2026
67c370b
docs(phase-58): add validation strategy
LakshmanTurlapati Jul 16, 2026
48694d1
docs(58): map conformance migration patterns
LakshmanTurlapati Jul 16, 2026
6947c59
docs(58): create phase plan
LakshmanTurlapati Jul 16, 2026
3e52512
docs(58-01): publish v1.4 protocol contract
LakshmanTurlapati Jul 16, 2026
094ec1a
docs(58-01): freeze legacy corpus and migration path
LakshmanTurlapati Jul 16, 2026
2ed817b
docs(58-01): complete protocol contract and legacy evidence plan
LakshmanTurlapati Jul 16, 2026
e5160e0
feat(58-02): generate standalone v1.4 positives
LakshmanTurlapati Jul 16, 2026
5c43e40
feat(58-02): generate adversarial standard corpus
LakshmanTurlapati Jul 16, 2026
6a20e39
docs(58-02): complete standalone standard corpus plan
LakshmanTurlapati Jul 16, 2026
73857f3
feat(58-03): enforce exact generated evidence
LakshmanTurlapati Jul 16, 2026
baa4259
feat(58-03): bind normative fixture to standard vector
LakshmanTurlapati Jul 16, 2026
ddd036f
docs(58-03): complete exact conformance evidence plan
LakshmanTurlapati Jul 16, 2026
3e28c68
test(58-04): make TypeScript conformance profile-aware
LakshmanTurlapati Jul 16, 2026
1244e01
test(58-04): prove reciprocal Python TypeScript minting
LakshmanTurlapati Jul 16, 2026
7c5e206
test(58-04): add pinned independent DSSE oracle
LakshmanTurlapati Jul 16, 2026
2d695a3
docs(58-04): complete cross-language conformance plan
LakshmanTurlapati Jul 16, 2026
7372ffe
feat(58-05): enforce receipt policy before replay loads
LakshmanTurlapati Jul 16, 2026
c915aca
feat(58-05): expose CLI receipt profile policy
LakshmanTurlapati Jul 16, 2026
9e8d340
test(58-05): verify packed protocol consumers
LakshmanTurlapati Jul 16, 2026
c74c8f5
docs(58-05): complete CLI bridge consumer plan
LakshmanTurlapati Jul 16, 2026
d3e3b0d
ci(58-06): make conformance drift release blocking
LakshmanTurlapati Jul 16, 2026
43d338b
docs(58-06): reconcile v1.4 migration contract
LakshmanTurlapati Jul 16, 2026
a6c7ef5
docs(58-06): complete conformance closure plan
LakshmanTurlapati Jul 16, 2026
b820254
docs(59): capture authoritative runtime decisions
LakshmanTurlapati Jul 16, 2026
936dbe9
docs(59): research runtime state authority
LakshmanTurlapati Jul 16, 2026
474fe83
docs(59): define runtime validation architecture
LakshmanTurlapati Jul 16, 2026
81b5df4
docs(59): create phase plan
LakshmanTurlapati Jul 16, 2026
921f61b
feat(59-01): add authoritative state contracts
LakshmanTurlapati Jul 16, 2026
29dd1ce
docs(59-01): complete authoritative state contracts plan
LakshmanTurlapati Jul 16, 2026
18695c1
feat(59-02): add scoped artifact lifecycle
LakshmanTurlapati Jul 16, 2026
c57caea
docs(59-02): complete artifact lifecycle plan
LakshmanTurlapati Jul 16, 2026
1e82992
feat(59-03): classify exact route context membership
LakshmanTurlapati Jul 16, 2026
de952ab
feat(59-03): materialize authoritative context projection
LakshmanTurlapati Jul 16, 2026
18f9eca
docs(59-03): complete context materialization plan
LakshmanTurlapati Jul 16, 2026
59fdd48
feat(59-04): share pre-provider preparation
LakshmanTurlapati Jul 17, 2026
9805190
test(59-04): prove primary projection authority
LakshmanTurlapati Jul 17, 2026
7163fe4
docs(59-04): complete shared preparation plan
LakshmanTurlapati Jul 17, 2026
a7cb346
feat(59-05): rematerialize every fallback route
LakshmanTurlapati Jul 17, 2026
e4fa30d
feat(59-05): bind evidence to provider attempts
LakshmanTurlapati Jul 17, 2026
11ddfe8
docs(59-05): complete fallback evidence plan
LakshmanTurlapati Jul 17, 2026
94448bb
feat(59-06): persist provider outputs truthfully
LakshmanTurlapati Jul 17, 2026
89661b8
feat(59-06): append truthful session continuity
LakshmanTurlapati Jul 17, 2026
8de2d00
docs(59-06): complete output persistence plan
LakshmanTurlapati Jul 17, 2026
83c8cc2
feat(59-07): redact authoritative replay evidence
LakshmanTurlapati Jul 17, 2026
8295005
feat(59-07): bound authoritative telemetry
LakshmanTurlapati Jul 17, 2026
48c0fc8
docs(59-07): complete replay observability plan
LakshmanTurlapati Jul 17, 2026
459b93b
docs(59-07): advance replay observability state
LakshmanTurlapati Jul 17, 2026
2a1263a
feat(59-08): finalize authoritative public contracts
LakshmanTurlapati Jul 17, 2026
e16496f
docs(59-08): complete authoritative public contracts plan
LakshmanTurlapati Jul 17, 2026
35a017f
docs(59-08): advance authoritative public contracts state
LakshmanTurlapati Jul 17, 2026
da89c5d
test(59-09): close authority and lifecycle invariant matrix
LakshmanTurlapati Jul 17, 2026
98caf04
test(59-09): stabilize public lookup import
LakshmanTurlapati Jul 17, 2026
273fe08
docs(59-09): complete authority and lifecycle closure
LakshmanTurlapati Jul 17, 2026
ad90489
docs(59-09): advance authority closure state
LakshmanTurlapati Jul 17, 2026
aa4dac3
docs(phase-59): complete authoritative runtime state
LakshmanTurlapati Jul 17, 2026
ab802d1
docs(60): establish audit and cost context
LakshmanTurlapati Jul 17, 2026
37312ab
docs(phase-60): add validation strategy
LakshmanTurlapati Jul 17, 2026
bd75799
docs(60): create phase plan
LakshmanTurlapati Jul 17, 2026
ad4762c
feat(60-01): add receipt issuance policy
LakshmanTurlapati Jul 17, 2026
c6318ea
feat(60-01): enforce runtime receipt policy
LakshmanTurlapati Jul 17, 2026
07502a7
docs(60-01): complete runtime receipt policy plan
LakshmanTurlapati Jul 17, 2026
c27d87a
feat(60-03): preserve invalid eval stages
LakshmanTurlapati Jul 17, 2026
167887d
fix(60-03): enforce eval failure precedence
LakshmanTurlapati Jul 17, 2026
fc85ad7
docs(60-03): complete evaluation integrity plan
LakshmanTurlapati Jul 17, 2026
e8f0909
feat(60-02): enforce agent receipt policy
LakshmanTurlapati Jul 17, 2026
28e8f56
feat(60-02): converge crew audit issuance
LakshmanTurlapati Jul 17, 2026
dc044e7
docs(60-02): complete cross-surface audit policy
LakshmanTurlapati Jul 17, 2026
5890d12
feat(60-04): add structured cost kernel
LakshmanTurlapati Jul 17, 2026
331f348
feat(60-04): converge route cost decisions
LakshmanTurlapati Jul 17, 2026
c95e985
docs(60-04): complete shared cost integrity
LakshmanTurlapati Jul 17, 2026
440d486
feat(60-05): unify provider usage cost
LakshmanTurlapati Jul 17, 2026
a986e47
feat(60-05): enforce agent cost preflight
LakshmanTurlapati Jul 17, 2026
2ba4010
docs(60-05): complete provider and agent cost plan
LakshmanTurlapati Jul 17, 2026
ed269ec
test(60-06): close audit cost integrity matrix
LakshmanTurlapati Jul 17, 2026
778e89b
docs(60-06): complete integrity closure
LakshmanTurlapati Jul 17, 2026
069188f
docs(60-06): advance integrity closure state
LakshmanTurlapati Jul 17, 2026
f55be09
docs(phase-60): complete audit evaluation and cost integrity
LakshmanTurlapati Jul 17, 2026
21073b1
docs(61): capture phase context
LakshmanTurlapati Jul 17, 2026
26c64b3
docs(61): research agent receipt closure
LakshmanTurlapati Jul 17, 2026
211f82c
docs(phase-61): add validation strategy
LakshmanTurlapati Jul 17, 2026
b4f5ce8
docs(61): map agent receipt patterns
LakshmanTurlapati Jul 17, 2026
5fc7097
docs(61): create phase plan
LakshmanTurlapati Jul 17, 2026
89db1d4
feat(61-01): attach managed iteration receipts
LakshmanTurlapati Jul 17, 2026
aa17877
feat(61-01): attach terminal agent receipts
LakshmanTurlapati Jul 17, 2026
702d033
docs(61-01): complete agent receipt attachment plan
LakshmanTurlapati Jul 17, 2026
c37f736
docs(61-01): update receipt closure progress
LakshmanTurlapati Jul 17, 2026
e4a5f59
feat(61-02): persist agent receipt ledger
LakshmanTurlapati Jul 17, 2026
5493099
feat(61-02): fail closed on invalid agent recovery
LakshmanTurlapati Jul 17, 2026
7556757
docs(61-02): complete agent recovery evidence plan
LakshmanTurlapati Jul 17, 2026
049f82b
docs(61-02): update recovery closure progress
LakshmanTurlapati Jul 17, 2026
703373e
feat(61-03): reuse child terminal receipts
LakshmanTurlapati Jul 17, 2026
77ff5f1
feat(61-03): reuse parent terminal receipt
LakshmanTurlapati Jul 17, 2026
ac388d7
docs(61-03): complete crew receipt reuse plan
LakshmanTurlapati Jul 17, 2026
25eca7a
docs(61-03): update crew receipt closure progress
LakshmanTurlapati Jul 17, 2026
e7455ff
test(61-04): prove public agent receipt closure
LakshmanTurlapati Jul 17, 2026
03c8ad3
docs(61-04): complete public receipt closure plan
LakshmanTurlapati Jul 17, 2026
470608f
docs(61-04): close agent receipt plans
LakshmanTurlapati Jul 17, 2026
173e32e
docs(phase-61): complete phase execution
LakshmanTurlapati Jul 17, 2026
ddf1382
docs(62): capture phase context
LakshmanTurlapati Jul 17, 2026
79dc649
docs(state): record phase 62 context session
LakshmanTurlapati Jul 17, 2026
86e44a0
docs(phase-62): add operational research and validation
LakshmanTurlapati Jul 17, 2026
e009004
docs(62): create phase plan
LakshmanTurlapati Jul 17, 2026
953f8f3
feat(62-01): establish packed consumer authority
LakshmanTurlapati Jul 17, 2026
26548e9
ci(62-01): validate packed consumers on supported Node lines
LakshmanTurlapati Jul 17, 2026
1910a2b
docs(62-01): complete packed consumer interop plan
LakshmanTurlapati Jul 17, 2026
5cf7d12
feat(62-02): bound provider output tokens
LakshmanTurlapati Jul 17, 2026
b48cfa0
ci(62-02): add bounded packed provider canary
LakshmanTurlapati Jul 20, 2026
e0fbfed
docs(62-02): complete bounded provider canary plan
LakshmanTurlapati Jul 20, 2026
98505fb
ci(62-03): enforce production comment hygiene
LakshmanTurlapati Jul 20, 2026
3a29937
chore(62-03): rewrite production comments as durable rationale
LakshmanTurlapati Jul 20, 2026
1c7f2b9
docs(62-03): complete production comment hygiene plan
LakshmanTurlapati Jul 20, 2026
2f217b7
chore(62-04): synchronize v1.6 release identity
LakshmanTurlapati Jul 20, 2026
da353f2
docs(62-04): publish v1.6 bridge guidance
LakshmanTurlapati Jul 20, 2026
b52ef8c
docs(62-04): complete v1.6 release closure
LakshmanTurlapati Jul 20, 2026
f340dab
docs(phase-62): verify operational release closure
LakshmanTurlapati Jul 20, 2026
47c4d38
docs(v1.6): repair conformance verification records
LakshmanTurlapati Jul 20, 2026
a1bb201
docs(v1.6): record passed milestone audit
LakshmanTurlapati Jul 20, 2026
5468e60
chore: archive v1.6 milestone files
LakshmanTurlapati Jul 20, 2026
6ca5194
chore: remove requirements for v1.6 milestone
LakshmanTurlapati Jul 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
42 changes: 34 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,9 @@
# Lattice PR-Time CI Workflow
# Closes CI-01 (install + typecheck + test + test:types + lint:packages) and CI-02 (40-char SHA pinning).
# Decisions traced to .planning/phases/25-pr-time-ci-workflow/25-CONTEXT.md:
# D-01 ubuntu-only, D-02 Node 24 only, D-03 sequential gate order,
# D-04 tarball leak audit, D-05 source-import rename audit, D-06 workflow safety audit,
# D-07 pnpm-store cache only, D-08 single ci job ubuntu-latest, D-09 PR-only cancel concurrency,
# D-10 contents: read root permissions, D-11 hard ban on the pwn-request trigger,
# D-12 40-char SHA pinning, D-13 pnpm/action-setup + setup-node order.
# This workflow has ZERO OIDC capability and ZERO secrets references.
# The primary job runs deterministic workspace gates on Node 24. Packed
# consumers run separately on every supported Node line so package exports are
# exercised exactly as downstream applications load them.
# Third-party actions are pinned to full commit SHAs. Root permissions are
# read-only, and this workflow has no OIDC capability or secrets references.
name: ci

on:
Expand Down Expand Up @@ -74,3 +71,32 @@ jobs:

- name: Audit workflows for OIDC and PR-target drift
run: node scripts/check-workflow-safety.mjs

- name: Validate production comment hygiene
run: pnpm check:comment-hygiene

packed-consumer:
name: packed-consumer-node-${{ matrix.node }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
node: ['24', '26']
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10

- name: Set up pnpm
uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
with:
node-version: ${{ matrix.node }}
cache: 'pnpm'

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Validate packed runtime and CLI consumer
run: pnpm check:packed-consumer
131 changes: 131 additions & 0 deletions .github/workflows/conformance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,131 @@
name: conformance

on:
pull_request:
branches: [main]
paths:
- "spec/**"
- "conformance/**"
- "clients/python/**"
- "packages/lattice/src/receipts/**"
- "packages/lattice/src/replay/materialize.ts"
- "packages/lattice/src/replay/materialize.test.ts"
- "packages/lattice/src/storage/fingerprint.ts"
- "packages/lattice/src/index.ts"
- "packages/lattice/src/audit.ts"
- "packages/lattice/package.json"
- "packages/lattice/tsdown.config.ts"
- "packages/lattice-cli/**"
- "scripts/check-protocol-package-consumer.mjs"
- "scripts/lib/packed-packages.mjs"
- "scripts/check-package-version-surfaces.mjs"
- "scripts/stamp-package-version.mjs"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- ".github/workflows/conformance.yml"
push:
branches: [main]
paths:
- "spec/**"
- "conformance/**"
- "clients/python/**"
- "packages/lattice/src/receipts/**"
- "packages/lattice/src/replay/materialize.ts"
- "packages/lattice/src/replay/materialize.test.ts"
- "packages/lattice/src/storage/fingerprint.ts"
- "packages/lattice/src/index.ts"
- "packages/lattice/src/audit.ts"
- "packages/lattice/package.json"
- "packages/lattice/tsdown.config.ts"
- "packages/lattice-cli/**"
- "scripts/check-protocol-package-consumer.mjs"
- "scripts/lib/packed-packages.mjs"
- "scripts/check-package-version-surfaces.mjs"
- "scripts/stamp-package-version.mjs"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- ".github/workflows/conformance.yml"

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
conformance:
name: conformance
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10

- name: Set up pnpm
uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
with:
node-version: "24"
cache: "pnpm"

- name: Set up Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1
with:
python-version: "3.13"

- name: Install Node dependencies
run: pnpm install --frozen-lockfile

- name: Install Python client
run: python -m pip install -e "clients/python[test]"

- name: Verify unchanged nested legacy manifest
working-directory: conformance/vectors/legacy
run: sha256sum --check MANIFEST.sha256

- name: Verify aggregate exact manifest coverage
run: pnpm --filter @lattice-conformance/verify-ts test:manifest

- name: Typecheck conformance generator
run: pnpm --filter @lattice-conformance/generate typecheck

- name: Test conformance generator
run: pnpm --filter @lattice-conformance/generate test

- name: Verify generated artifacts without mutation
run: pnpm --filter @lattice-conformance/generate check:generated

- name: Assert generated evidence remains clean
run: >-
git diff --exit-code --
spec/vector0-fixture.json
conformance/vectors/legacy/MANIFEST.sha256
conformance/vectors/standard
conformance/vectors/MANIFEST.sha256

- name: Typecheck TypeScript conformance harness
run: pnpm --filter @lattice-conformance/verify-ts typecheck

- name: Run TypeScript receipt conformance harness
run: pnpm --filter @lattice-conformance/verify-ts test

- name: Run Python receipt conformance harness without oracle
run: >-
python -m pytest clients/python/tests -q
--ignore=clients/python/tests/test_dsse_oracle.py

- name: Run exact securesystemslib oracle
run: python -m pytest clients/python/tests/test_dsse_oracle.py -q

- name: Run reciprocal cross-mint parity
env:
LATTICE_RUN_CROSS_MINT: "1"
PYTHON: python
run: pnpm --filter @lattice-conformance/verify-ts test:cross-mint

- name: Run clean packed protocol consumer
run: pnpm check:packed-consumer
92 changes: 92 additions & 0 deletions .github/workflows/provider-canary.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
name: provider-canary

on:
schedule:
- cron: '30 7 * * 3'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: provider-canary
cancel-in-progress: false

jobs:
canary:
name: packed provider canary
runs-on: ubuntu-latest
environment: provider-canary
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10

- name: Set up pnpm
uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
with:
node-version: '24'
cache: 'pnpm'

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Run bounded packed canary
id: provider-canary
continue-on-error: true
run: node scripts/run-provider-canary.mjs
env:
LATTICE_CANARY_OPENAI_MODEL: ${{ vars.PROVIDER_CANARY_OPENAI_MODEL }}
LATTICE_CANARY_OPENAI_API_KEY: ${{ secrets.PROVIDER_CANARY_OPENAI_API_KEY }}
LATTICE_CANARY_OPENAI_BASE_URL: ${{ vars.PROVIDER_CANARY_OPENAI_BASE_URL }}
LATTICE_CANARY_OPENAI_INPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_OPENAI_INPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_OPENAI_OUTPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_OPENAI_OUTPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_OPENAI_MAX_SPEND_USD: ${{ vars.PROVIDER_CANARY_OPENAI_MAX_SPEND_USD }}
LATTICE_CANARY_ANTHROPIC_MODEL: ${{ vars.PROVIDER_CANARY_ANTHROPIC_MODEL }}
LATTICE_CANARY_ANTHROPIC_API_KEY: ${{ secrets.PROVIDER_CANARY_ANTHROPIC_API_KEY }}
LATTICE_CANARY_ANTHROPIC_INPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_ANTHROPIC_INPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_ANTHROPIC_OUTPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_ANTHROPIC_OUTPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_ANTHROPIC_MAX_SPEND_USD: ${{ vars.PROVIDER_CANARY_ANTHROPIC_MAX_SPEND_USD }}
LATTICE_CANARY_GEMINI_MODEL: ${{ vars.PROVIDER_CANARY_GEMINI_MODEL }}
LATTICE_CANARY_GEMINI_API_KEY: ${{ secrets.PROVIDER_CANARY_GEMINI_API_KEY }}
LATTICE_CANARY_GEMINI_INPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_GEMINI_INPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_GEMINI_OUTPUT_PRICE_PER_1K_USD: ${{ vars.PROVIDER_CANARY_GEMINI_OUTPUT_PRICE_PER_1K_USD }}
LATTICE_CANARY_GEMINI_MAX_SPEND_USD: ${{ vars.PROVIDER_CANARY_GEMINI_MAX_SPEND_USD }}

- name: Write sanitized summary
if: always()
shell: bash
run: |
node --input-type=module <<'NODE'
import { appendFile, readFile } from "node:fs/promises";
const report = JSON.parse(await readFile("provider-canary-report.json", "utf8"));
const lines = [
"## Packed provider canary",
"",
`Package: \`${report.packageVersion}\``,
"",
"| Family | Status | Code |",
"|---|---|---|",
...report.families.map(
({ family, status, code }) => `| ${family} | ${status} | ${code} |`,
),
"",
];
await appendFile(process.env.GITHUB_STEP_SUMMARY, lines.join("\n"), "utf8");
NODE

- name: Retain sanitized report
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: provider-canary-report
path: provider-canary-report.json
if-no-files-found: error
retention-days: 30

- name: Enforce canary result
if: steps.provider-canary.outcome == 'failure'
run: exit 1
21 changes: 9 additions & 12 deletions .github/workflows/registry-drift.yml
Original file line number Diff line number Diff line change
@@ -1,32 +1,29 @@
# Lattice Registry Drift Workflow
# Phase 33 -- D-19 -- CAPS-04
#
# Weekly cron + manual dispatch. Auto-opens a refresh PR when the
# OpenRouter snapshot diverges from the committed
# packages/lattice/src/capabilities/registry.generated.ts.
#
# PR-time ci.yml does NOT call OpenRouter (per D-19 -- keeps PR loop
# network-free and fast). Drift is checked weekly on a predictable
# PR-time ci.yml does NOT call OpenRouter, which keeps the PR loop
# network-free and fast. Drift is checked weekly on a predictable
# cadence (Monday 06:00 UTC) or manually via workflow_dispatch.
#
# Permissions discipline (Phase 28 inheritance):
# Permissions discipline:
# - Workflow-level: contents: read (default-locked-down)
# - Job-level: contents: write + pull-requests: write (minimum needed)
# - NO OIDC token-mint scope anywhere (this workflow does not publish;
# blast-radius mitigation per Phase 28 SUMMARY)
# - NO OIDC token-mint scope anywhere because this workflow does not publish
#
# All third-party actions SHA-pinned per CI-02. peter-evans/create-pull-request
# pinned to v8.1.1 SHA per A4 (Node 24 runner support).
# All third-party actions are SHA-pinned. peter-evans/create-pull-request is
# pinned to the v8.1.1 commit for Node 24 runner support.
#
# Prerequisite repo setting:
# Settings -> Actions -> General -> Workflow permissions ->
# "Allow GitHub Actions to create and approve pull requests" (must be enabled)
# Inherited from Phase 29 (changesets/action Version Packages flow needs the same setting).
# The changesets Version Packages flow requires the same repository setting.
name: registry-drift

on:
schedule:
- cron: '0 6 * * 1' # Monday 06:00 UTC (D-19)
- cron: '0 6 * * 1' # Monday 06:00 UTC
workflow_dispatch:

permissions:
Expand Down Expand Up @@ -61,7 +58,7 @@ jobs:
run: node scripts/refresh-model-registry.mjs

- name: Open refresh PR
# SHA pin per CI-02; v8.1.1 per A4 (Node 24 runner support).
# Pinned to the v8.1.1 commit for Node 24 runner support.
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1
with:
token: ${{ secrets.GITHUB_TOKEN }}
Expand Down
13 changes: 7 additions & 6 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,5 @@
# Lattice Release Workflow
# Phase 28: REL-01..REL-06, PUB-01
#
# Two-job pattern (Phase 28 SC-1):
# Two-job pattern:
# version-pr: opens/updates the changesets release PR; needs contents:write
# and pull-requests:write but NO id-token. Triggered by pushes
# to main.
Expand All @@ -11,13 +9,13 @@
# Runs in environment npm-publish so the required reviewer
# (LakshmanTurlapati) approves each release.
#
# OIDC trust tuple registered on npmjs.com in Phase 27:
# OIDC trust tuple registered on npmjs.com:
# (repository: fullselfbrowsing/Lattice,
# workflow_filename: release.yml,
# environment: npm-publish)
# Both packages have this tuple, so pnpm publish exchanges the GitHub OIDC
# token for an npm short-lived publish credential with no static npm secret.
# All third-party actions SHA-pinned per CI-02 / Phase 25 D-12.
# All third-party actions are pinned to full commit SHAs.
name: release

on:
Expand Down Expand Up @@ -119,11 +117,14 @@ jobs:
- name: Audit core package boundary
run: node scripts/check-core-package-boundary.mjs

- name: Validate packed runtime and CLI consumer
run: pnpm check:packed-consumer

- name: Publish to npm with provenance
# pnpm publish picks up the OIDC token from
# ACTIONS_ID_TOKEN_REQUEST_URL + ACTIONS_ID_TOKEN_REQUEST_TOKEN that
# the runner injects when id-token:write is set, exchanges it with
# npm using the trust tuple registered in Phase 27, and signs the
# npm using the registered trust tuple and signs the
# tarball with Sigstore for provenance.
run: pnpm -r publish --access public --provenance --no-git-checks

Expand Down
5 changes: 5 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,8 @@ node_modules/
dist/
coverage/
examples/work-inbox/.lattice/

__pycache__/
*.py[cod]
*.egg-info/
.pytest_cache/
Loading