From 20dc1d7edcf37e0eb7f6b658e5a37f2e8d77a160 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 14:40:28 +0100
Subject: [PATCH 1/3] chore: estate-wide security compliance
---
.github/funding.yml | 4 ++
.github/workflows/abi-drift.yml | 1 +
.github/workflows/backend-assurance.yml | 1 +
.github/workflows/build.yml | 1 +
.github/workflows/codeql.yml | 1 +
.github/workflows/container-publish.yml | 1 +
.github/workflows/dogfood-gate.yml | 1 +
.github/workflows/e2e.yml | 1 +
.github/workflows/fuzz.yml | 1 +
.github/workflows/governance.yml | 1 +
.github/workflows/hcg-surface-drift.yml | 1 +
.github/workflows/hypatia-scan.yml | 1 +
.github/workflows/instant-sync.yml | 1 +
.github/workflows/lsp-dap-bsp.yml | 1 +
.github/workflows/mirror.yml | 2 +
.github/workflows/pages-deploy.yml | 1 +
.github/workflows/pages.yml | 1 +
.github/workflows/proofs.yml | 1 +
.github/workflows/publish.yml | 1 +
.github/workflows/push-email-notify.yml | 1 +
.github/workflows/readme-derive.yml | 1 +
.github/workflows/release.yml | 1 +
.github/workflows/scorecard.yml | 1 +
.github/workflows/secret-scanner.yml | 1 +
.github/workflows/truthfulness.yml | 1 +
.github/workflows/zig-test.yml | 1 +
GOVERNANCE.md | 60 +++++++++++++++++++++++++
27 files changed, 90 insertions(+)
create mode 100644 .github/funding.yml
create mode 100644 GOVERNANCE.md
diff --git a/.github/funding.yml b/.github/funding.yml
new file mode 100644
index 00000000..e4f7c077
--- /dev/null
+++ b/.github/funding.yml
@@ -0,0 +1,4 @@
+# Funding Configuration
+# See: https://docs.github.com/en/repositories/managing-your-repositorys-custom-fields/displaying-a-sponsor-button-in-your-repository
+
+github: metadatastician
diff --git a/.github/workflows/abi-drift.yml b/.github/workflows/abi-drift.yml
index 5208c388..a63a431e 100644
--- a/.github/workflows/abi-drift.yml
+++ b/.github/workflows/abi-drift.yml
@@ -33,6 +33,7 @@ concurrency:
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/backend-assurance.yml b/.github/workflows/backend-assurance.yml
index d5caa9f5..0b0c2c7d 100644
--- a/.github/workflows/backend-assurance.yml
+++ b/.github/workflows/backend-assurance.yml
@@ -34,6 +34,7 @@ concurrency:
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 24f3d890..0117e921 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -13,6 +13,7 @@ on:
pull_request:
types: [opened, synchronize, reopened]
permissions:
+ actions: read
contents: read
jobs:
sonarqube:
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index b7be216b..45a32c1f 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -18,6 +18,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml
index f5e3077e..7d2f7aaa 100644
--- a/.github/workflows/container-publish.yml
+++ b/.github/workflows/container-publish.yml
@@ -14,6 +14,7 @@ on:
workflow_dispatch:
permissions: read-all
+ actions: read
jobs:
build-and-push:
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index 3e653d3e..5d2b2221 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -21,6 +21,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml
index d18f4824..206256ed 100644
--- a/.github/workflows/e2e.yml
+++ b/.github/workflows/e2e.yml
@@ -19,6 +19,7 @@ on:
workflow_dispatch:
permissions: read-all
+ actions: read
concurrency:
group: e2e-${{ github.ref }}
diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml
index 2a1fab86..d98557e7 100644
--- a/.github/workflows/fuzz.yml
+++ b/.github/workflows/fuzz.yml
@@ -15,6 +15,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml
index 156264a8..cc62f6c8 100644
--- a/.github/workflows/governance.yml
+++ b/.github/workflows/governance.yml
@@ -27,6 +27,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/hcg-surface-drift.yml b/.github/workflows/hcg-surface-drift.yml
index cbfd55e4..f4677497 100644
--- a/.github/workflows/hcg-surface-drift.yml
+++ b/.github/workflows/hcg-surface-drift.yml
@@ -39,6 +39,7 @@ concurrency:
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 127905d2..44042905 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -18,6 +18,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
# security-events: write serves two purposes (write implies read):
# 1. read — lets the built-in GITHUB_TOKEN query this repo's own
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index ca978298..d52b810d 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -17,6 +17,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/lsp-dap-bsp.yml b/.github/workflows/lsp-dap-bsp.yml
index fcd2880a..60630baa 100644
--- a/.github/workflows/lsp-dap-bsp.yml
+++ b/.github/workflows/lsp-dap-bsp.yml
@@ -17,6 +17,7 @@ on:
workflow_dispatch:
permissions: read-all
+ actions: read
concurrency:
group: lsp-dap-bsp-${{ github.ref }}
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index 833f5258..2bd44bf5 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -7,6 +7,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
# Estate guardrail: cancel superseded runs so re-pushes / rebased PR
@@ -18,6 +19,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/pages-deploy.yml b/.github/workflows/pages-deploy.yml
index 6679fbb0..78eca2bd 100644
--- a/.github/workflows/pages-deploy.yml
+++ b/.github/workflows/pages-deploy.yml
@@ -12,6 +12,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml
index 1b09c482..442dcdaa 100755
--- a/.github/workflows/pages.yml
+++ b/.github/workflows/pages.yml
@@ -9,6 +9,7 @@ on:
branches: [main, master]
workflow_dispatch:
permissions:
+ actions: read
contents: read
pages: write
id-token: write
diff --git a/.github/workflows/proofs.yml b/.github/workflows/proofs.yml
index c517ec01..a69f86c4 100644
--- a/.github/workflows/proofs.yml
+++ b/.github/workflows/proofs.yml
@@ -35,6 +35,7 @@ on:
- cron: '17 6 * * 1' # Mondays 06:17 UTC
permissions:
+ actions: read
contents: read
concurrency:
diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml
index c3193136..2c9f32af 100644
--- a/.github/workflows/publish.yml
+++ b/.github/workflows/publish.yml
@@ -11,6 +11,7 @@ on:
- 'v*'
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 4b4e754b..112afd18 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -7,6 +7,7 @@ name: Push email notification
on:
push: {}
permissions:
+ actions: read
contents: read
jobs:
notify:
diff --git a/.github/workflows/readme-derive.yml b/.github/workflows/readme-derive.yml
index c4d627d6..c5a89370 100644
--- a/.github/workflows/readme-derive.yml
+++ b/.github/workflows/readme-derive.yml
@@ -21,6 +21,7 @@ on:
- .machine_readable/**/ECOSYSTEM.a2ml
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index d60fcb6d..5577dc96 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -12,6 +12,7 @@ on:
- 'v*'
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 6560bbb5..ddd724aa 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -26,6 +26,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml
index b3486fc4..4839d606 100644
--- a/.github/workflows/secret-scanner.yml
+++ b/.github/workflows/secret-scanner.yml
@@ -11,6 +11,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/truthfulness.yml b/.github/workflows/truthfulness.yml
index 72f9e316..6d25f18d 100644
--- a/.github/workflows/truthfulness.yml
+++ b/.github/workflows/truthfulness.yml
@@ -21,6 +21,7 @@ on:
workflow_dispatch:
permissions: read-all
+ actions: read
concurrency:
group: truthfulness-${{ github.ref }}
diff --git a/.github/workflows/zig-test.yml b/.github/workflows/zig-test.yml
index 1512cdae..4a3566e4 100644
--- a/.github/workflows/zig-test.yml
+++ b/.github/workflows/zig-test.yml
@@ -20,6 +20,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/GOVERNANCE.md b/GOVERNANCE.md
new file mode 100644
index 00000000..e27364c7
--- /dev/null
+++ b/GOVERNANCE.md
@@ -0,0 +1,60 @@
+# Governance
+
+## Overview
+
+This project is governed by the following principles and structures to ensure transparent, inclusive, and effective decision-making.
+
+## Roles and Responsibilities
+
+### Maintainers
+
+Maintainers are responsible for:
+- Reviewing and merging pull requests
+- Managing releases and versioning
+- Ensuring code quality and standards
+- Triaging issues and bug reports
+- Community engagement and support
+
+### Contributors
+
+Contributors are expected to:
+- Follow the code of conduct
+- Submit well-documented pull requests
+- Write tests for new functionality
+- Maintain existing tests
+- Update documentation as needed
+
+## Decision Making
+
+### Minor Changes
+- Can be made by any maintainer
+- Include bug fixes, documentation updates, dependency updates
+
+### Major Changes
+- Require discussion in issues or pull requests
+- Include new features, architectural changes, API changes
+- Need approval from at least 2 maintainers
+
+### Breaking Changes
+- Require RFC (Request for Comments) process
+- Need approval from majority of maintainers
+- Must include migration guide
+
+## Code of Conduct
+
+All participants are expected to follow our Code of Conduct. Violations can be reported to the maintainers.
+
+## Communication
+
+- **Issues**: For bug reports and feature requests
+- **Discussions**: For questions and general discussion
+- **Pull Requests**: For code contributions
+
+## Licensing
+
+All contributions are made under the terms of the repository's LICENSE file.
+By submitting a pull request, you agree to license your contributions accordingly.
+
+---
+
+*Last updated: 2026-07-18*
From ba42404d3e243bfe0c9e4291e5eae1e1296f2805 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 15:07:32 +0100
Subject: [PATCH 2/3] chore: remove duplicate GOVERNANCE files, keep
GOVERNANCE.md
---
.claude/worktrees/gov-red | 1 +
.claude/worktrees/zig-mutex | 1 +
.github/GOVERNANCE.md | 160 ------------------------------------
3 files changed, 2 insertions(+), 160 deletions(-)
create mode 160000 .claude/worktrees/gov-red
create mode 160000 .claude/worktrees/zig-mutex
delete mode 100644 .github/GOVERNANCE.md
diff --git a/.claude/worktrees/gov-red b/.claude/worktrees/gov-red
new file mode 160000
index 00000000..7add7bca
--- /dev/null
+++ b/.claude/worktrees/gov-red
@@ -0,0 +1 @@
+Subproject commit 7add7bcac05ea4cb2fc0af62ec106dcd4779d73e
diff --git a/.claude/worktrees/zig-mutex b/.claude/worktrees/zig-mutex
new file mode 160000
index 00000000..a1517a36
--- /dev/null
+++ b/.claude/worktrees/zig-mutex
@@ -0,0 +1 @@
+Subproject commit a1517a3677eed03e96e859d5aad0e957d5f156ac
diff --git a/.github/GOVERNANCE.md b/.github/GOVERNANCE.md
deleted file mode 100644
index 04150b1b..00000000
--- a/.github/GOVERNANCE.md
+++ /dev/null
@@ -1,160 +0,0 @@
-
-# Project Governance
-
-This document describes the governance model for **boj-server**.
-
----
-
-## Project Governance Model
-
-boj-server follows a **Benevolent Dictator For Life (BDFL)** governance model.
-This model is well-suited for solo maintainers and small project teams where rapid,
-consistent decision-making is more valuable than formal consensus processes.
-
-The BDFL has final authority on all project decisions, including technical direction,
-release schedules, contributor access, and community standards.
-
-> **Transition clause:** When the core team exceeds three active maintainers, this
-> project should transition to a **consensus-based governance model** with documented
-> voting procedures. That transition should itself be recorded as an Architecture
-> Decision Record (ADR) in `docs/decisions/`.
-
----
-
-## Decision Making
-
-### Day-to-day decisions
-
-- The BDFL makes final decisions on all matters.
-- Routine decisions (bug fixes, dependency updates, minor improvements) may be made
- by any maintainer with commit access.
-- Maintainers are expected to use good judgement and seek input on non-trivial changes.
-
-### Proposing changes
-
-- Contributors can propose changes by opening issues or pull requests.
-- Significant changes (new features, breaking changes, architectural shifts) should
- be discussed in an issue before implementation begins.
-- The BDFL will provide a clear accept/reject decision with reasoning.
-
-### Architecture Decision Records (ADRs)
-
-- Significant technical decisions are documented as ADRs in `docs/decisions/`.
-- ADR statuses: `proposed`, `accepted`, `deprecated`, `superseded`, `rejected`.
-- ADRs provide a historical record of why decisions were made and what alternatives
- were considered.
-- See `.machine_readable/META.a2ml` for the machine-readable ADR index.
-
----
-
-## Roles
-
-### BDFL (Benevolent Dictator For Life)
-
-- The project creator and ultimate decision-maker.
-- Sets the project's technical direction and long-term vision.
-- Has final say on all matters, including maintainer appointments and removals.
-- Responsible for ensuring the project adheres to RSR standards.
-
-### Maintainer
-
-- Has commit access to the repository.
-- Reviews and merges pull requests.
-- Triages issues and manages releases.
-- Upholds code quality, security standards, and the Code of Conduct.
-- Listed in [MAINTAINERS.md](MAINTAINERS.md).
-
-### Contributor
-
-- Anyone who submits pull requests, opens issues, or participates in discussions.
-- Does not have direct commit access.
-- Contributions are reviewed by maintainers before merging.
-- All contributors must follow the [Code of Conduct](CODE_OF_CONDUCT.md).
-
-### Bot
-
-- Automated agents managed via your bot orchestration system.
-- Perform automated code review, security scanning, dependency updates, and
- standards enforcement.
-- Bot actions are subject to the same quality and review standards as human
- contributions.
-- Configure your bots in `.machine_readable/bot_directives/`.
-
----
-
-## Becoming a Maintainer
-
-A contributor may be nominated to become a maintainer when they demonstrate:
-
-1. **Sustained quality contributions** -- a track record of well-crafted pull requests
- that follow project conventions and require minimal revision.
-2. **Understanding of RSR standards** -- familiarity with the Repository Structure
- Requirements, security policies, and CI/CD workflows used across the project.
-3. **Constructive participation** -- helpful issue triage, thoughtful code review
- comments, and mentoring of other contributors.
-4. **Reliability** -- consistent engagement over a meaningful period (typically 3+
- months of active contribution).
-
-### Process
-
-1. An existing maintainer nominates the candidate by opening a private discussion
- with the BDFL.
-2. The BDFL reviews the candidate's contribution history and community interactions.
-3. The BDFL approves or declines the nomination, with reasoning provided to the
- nominator.
-4. If approved, the new maintainer is added to [MAINTAINERS.md](MAINTAINERS.md) and
- granted appropriate repository access.
-
----
-
-## Removing a Maintainer
-
-A maintainer may be removed under the following circumstances:
-
-- **Inactivity**: No meaningful contributions or reviews for 12 or more consecutive
- months. The maintainer will be contacted before removal and offered the option to
- move to emeritus status voluntarily.
-- **Code of Conduct violation**: Behaviour that violates the
- [Code of Conduct](CODE_OF_CONDUCT.md), as determined through the enforcement
- process described therein.
-- **BDFL discretion**: The BDFL may remove a maintainer for other reasons (e.g.,
- repeated disregard for project standards, loss of trust). Reasoning will be
- documented privately.
-
-Removed maintainers are moved to the Emeritus section of
-[MAINTAINERS.md](MAINTAINERS.md) unless removal was due to a serious Code of Conduct
-violation.
-
----
-
-## Code of Conduct
-
-All participants in this project are expected to follow the
-[Code of Conduct](CODE_OF_CONDUCT.md). The Code of Conduct applies to all project
-spaces, including issues, pull requests, discussions, and any forum where the project
-is represented.
-
-Enforcement of the Code of Conduct is described in that document. The BDFL serves as
-the final arbiter in conduct disputes.
-
----
-
-## Amendments
-
-This governance document may be amended by the BDFL at any time. All amendments will
-be:
-
-1. Documented as an ADR in `docs/decisions/` explaining the rationale for the change.
-2. Committed to the repository with a clear commit message.
-3. Communicated to existing maintainers and contributors via the project's usual
- channels.
-
-Substantive changes (e.g., changing the governance model itself) should be discussed
-with the community before adoption, even though the BDFL retains final authority.
-
----
-
-Copyright (c) 2026 hyperpolymath. Licensed under MPL-2.0.
From f2b7cd1b944692e6cf905aed4a61b084dac2d64e Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Mon, 3 Aug 2026 19:53:09 +0100
Subject: [PATCH 3/3] fix(ci): remove invalid actions:read under scalar
permissions (4 workflows)
The estate compliance sweep inserted an indented 'actions: read' beneath
'permissions: read-all', which is invalid YAML (scalar followed by mapping
continuation) and would parse-kill all four workflows. read-all already
grants actions:read, so removal is semantically neutral.
Co-Authored-By: Claude Fable 5
---
.github/workflows/container-publish.yml | 1 -
.github/workflows/e2e.yml | 1 -
.github/workflows/lsp-dap-bsp.yml | 1 -
.github/workflows/truthfulness.yml | 1 -
4 files changed, 4 deletions(-)
diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml
index 7d2f7aaa..f5e3077e 100644
--- a/.github/workflows/container-publish.yml
+++ b/.github/workflows/container-publish.yml
@@ -14,7 +14,6 @@ on:
workflow_dispatch:
permissions: read-all
- actions: read
jobs:
build-and-push:
diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml
index 206256ed..d18f4824 100644
--- a/.github/workflows/e2e.yml
+++ b/.github/workflows/e2e.yml
@@ -19,7 +19,6 @@ on:
workflow_dispatch:
permissions: read-all
- actions: read
concurrency:
group: e2e-${{ github.ref }}
diff --git a/.github/workflows/lsp-dap-bsp.yml b/.github/workflows/lsp-dap-bsp.yml
index 60630baa..fcd2880a 100644
--- a/.github/workflows/lsp-dap-bsp.yml
+++ b/.github/workflows/lsp-dap-bsp.yml
@@ -17,7 +17,6 @@ on:
workflow_dispatch:
permissions: read-all
- actions: read
concurrency:
group: lsp-dap-bsp-${{ github.ref }}
diff --git a/.github/workflows/truthfulness.yml b/.github/workflows/truthfulness.yml
index 6d25f18d..72f9e316 100644
--- a/.github/workflows/truthfulness.yml
+++ b/.github/workflows/truthfulness.yml
@@ -21,7 +21,6 @@ on:
workflow_dispatch:
permissions: read-all
- actions: read
concurrency:
group: truthfulness-${{ github.ref }}