Add corrected profile 2.0.0 and experimental POSIX JSON CLI contract - #3
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
snapsynapse
marked this pull request as ready for review
September 8, 2026 00:49
This was referenced Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and behavior
GuideCheck's released content checks are frozen for compatibility. This candidate adds a guide-declared
2.0.0profile for corrected negation, independent prohibited-instruction occurrences, and effective execution-target checks. Unresolved execution blocks Level 3 even when a hash is declared. Repository-file evidence remains corroboration under the unchanged strict anchor policy.The separate experimental
--contract posix-json-v1selector wraps local verification in one terminal JSON record with operational and gate outcomes. Gate rejection exits 2, an otherwise unmet local Level 4 gate exits 3, and documented operational failures use specific exit categories. Omitting the selector retains the existing CLI behavior. The scanner is outside this pilot.Compatibility and validation
The software version is prepared as 2.0.0. Current-release metadata still identifies 1.0.0 as published; all 2.0.0 public surfaces explicitly identify a candidate. Published self-guide and manifest bytes remain unchanged.
Delivery boundary
Implements #2. This draft PR is the review and CI boundary. Main integration triggers Vercel production; main merge, final publication wording, the
v2.0.0tag, signed release assets, and production verification remain separate delivery steps. Adopter migrations are separate work.See
docs/release-2.0.0.mdfor delivery order and remaining gates. Existing signing/scorecard/citation and Level 5 work is outside this change.Candidate verification receipt
Candidate commit:
e36207679b128a07bf49563849a765528da83918.CI run 34172860779 passed both Python versions, including the installed-wheel consumer. The local CLI contract suite passed 233 checks.
Authenticated Vercel preview inspection matched the candidate deployment manifest and all source digests. Twenty-three of 24 public files matched exactly; the homepage matched after removing the exact observed Vercel feedback-script suffix. Browser form submission rendered the corrected profile and findings. Live hosted calls selected legacy, strict, and corrected profiles correctly, rejected a required-profile mismatch, and blocked unresolved execution. Live fixture manifests are unavailable example endpoints; successful Level 4 behavior is covered by controlled hosted tests, not claimed for those live fixtures.
Production and preview match on verifier identity, guide hash/level, summary, and finding-ID/severity sequence for GuideCheck and A11y's existing guides. This preserves two pre-existing findings: GuideCheck's self-guide DNS anchor mismatch (Level 3), and A11y's installer opacity exemption rejection under the 0.7.1 evaluator (Level 2, separate from its pinned 0.7.0 CI result). These are separate maintenance items; this PR does not rotate anchors or migrate consumers.