This repository is not finished being set up. 35 substitution token(s) across 26 file(s) still have no value.
This repo was created from hyperpolymath/rsr-template-repo. The mint
(just repo-init) fills every token that has a single mechanical
answer — owner, repo, author, dates, licence, branch — and it has done
so here.
The tokens below are the ones it deliberately cannot answer. They need a decision or a fact that exists only in your head: what this project is for, what command builds it, which port the service listens on, whether a PGP key is held at all. The template’s own token vocabulary says as much — you cannot sensibly answer “required invariants” in a thirty-second bootstrap.
They were left visibly unfilled on purpose. The alternatives were both worse: inventing plausible values would put confident falsehoods into a security policy and an architecture document, and silently deleting the sections would hide the fact that a decision is owed. A visible gap is honest; a fabricated answer is not.
This file is the only marker that the work is outstanding. Deleting it early does not finish the setup, it just conceals it — and the next person or agent to arrive will reasonably assume the repo is complete.
-
If you are a person: delete this file yourself once the last item is done.
-
If you are an agent: resolve what you legitimately can, leave the rest, and delete this file only when no token below remains anywhere in the tree. Do not delete it to make a gate go green.
Re-running the estate top-up tool will remove this file automatically once nothing is outstanding, so the safest way to finish is to fix the tokens and let the check confirm it.
.github/settings.yml is applied to the forge by a GitHub App. An
unfilled token here can be written into the repository’s real name or
description. This has fired before in this estate: illegal braces were
collapsed to dashes and a repo was renamed -REPO-, which then read
as deleted.
-
{{DESCRIPTION}}— One-line description used in .github/settings.yml. HIGH PRIORITY: settings.yml is applied by a GitHub App, so an unfilled token here can be written into forge metadata verbatim.
Author’s organisation. NOTE: no filled instance of this exists anywhere in the estate — consider deleting the field instead.
Appears in:
-
.machine_readable/contractiles/k9/examples/project-metadata.k9.ncl -
.machine_readable/contractiles/self-validating/examples/project-metadata.k9.ncl
Name of the conduct body. If there is no committee, rewrite the sentence rather than substituting a plural noun into ‘a \{{CONDUCT_TEAM}} member’.
Appears in:
-
.github/CODE_OF_CONDUCT.md
A downstream repo that consumes this one.
Appears in:
-
.machine_readable/INTENT.contractile
First named dependency, in .machine_readable/INTENT.contractile.
Appears in:
-
.machine_readable/INTENT.contractile
Second named dependency, in .machine_readable/INTENT.contractile.
Appears in:
-
.machine_readable/INTENT.contractile
One-line description used in .github/settings.yml. HIGH PRIORITY: settings.yml is applied by a GitHub App, so an unfilled token here can be written into forge metadata verbatim.
Appears in:
-
.github/settings.yml
SPDX identifier for this repo’s licence.
Appears in:
-
container/Containerfile -
container/manifest.toml -
docs/developer/ABI-FFI-README.adoc
Literally ‘monorepo’ or ‘standalone’.
Appears in:
-
.machine_readable/INTENT.contractile
The invariants this project guarantees. Not answerable in a bootstrap; it is the point of the repo.
Appears in:
-
QUICKSTART-DEV.adoc
A paragraph on what this deliberately is NOT for.
Appears in:
-
.machine_readable/INTENT.contractile
A paragraph on what this is for.
Appears in:
-
.machine_readable/INTENT.contractile
OpenSSF project ID, same registration.
Appears in:
-
TEMPLATE-STANDARDS-AUDIT.adoc
Public URL the PGP key can be fetched from. Same caveat as PGP_FINGERPRINT.
Appears in:
-
.well-known/security.txt
Port the container service listens on.
Appears in:
-
container/Containerfile -
container/compose.toml -
container/deploy.k9.ncl -
container/entrypoint.sh -
container/manifest.toml -
container/vordr.toml
One-line description, matching the forge description.
Appears in:
-
container/Containerfile -
container/manifest.toml
Taxonomy value for the subject domain.
Appears in:
-
.machine_readable/6a2/anchor/ANCHOR.a2ml -
.machine_readable/anchors/ANCHOR.a2ml
Taxonomy value (library, service, tool, lab…).
Appears in:
-
.machine_readable/6a2/anchor/ANCHOR.a2ml -
.machine_readable/anchors/ANCHOR.a2ml
One line: what this exists to do.
Appears in:
-
.machine_readable/6a2/anchor/ANCHOR.a2ml -
.machine_readable/anchors/ANCHOR.a2ml -
guix.scm
What this does that its alternatives do not.
Appears in:
-
.machine_readable/agent_instructions/methodology.a2ml -
.machine_readable/bot_directives/methodology.a2ml
Container registry to publish to.
Appears in:
-
container/compose.toml -
container/ct-build.sh -
container/deploy.k9.ncl
Initial-response SLA for a security or conduct report. Promise only what a solo maintainer can actually meet.
Appears in:
-
.github/CODE_OF_CONDUCT.md
Address for private vulnerability reports. Two competing values exist in
the estate (6759885+hyperpolymath@users.noreply.github.com and
security@hyperpolymath.org) — pick one deliberately.
Appears in:
-
.well-known/security.txt
Container service name.
Appears in:
-
container/.gatekeeper.yaml -
container/Containerfile -
container/compose.toml -
container/ct-build.sh -
container/deploy.k9.ncl -
container/entrypoint.sh -
container/manifest.toml -
container/vordr.toml
Version/tag for the container image.
Appears in:
-
container/deploy.k9.ncl -
container/manifest.toml -
container/vordr.toml