You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Architecture amendment — one authored content source (2026-08-13)
Initiative atrinik/atrinik#357 supersedes every future live-branch instruction below. atrinik/content@main is the sole mutable authored content source. Future authored changes belong only on main; supported Classic artifacts must be derived from the same immutable main revision. Do not create, restore, author, backport, validate, publish, select, profile, or channel content through a live 1.x branch or content-1x checkout.
Exact historical commits, release tags, artifacts, checksums, and archived comparisons remain valid evidence. This amendment does not alter the issue's other feature, implementation, validation, licensing, or acceptance requirements.
Important
This governance epic targets the fresh MIT Go/Rust/Protobuf/Astro replacement repositories and deliberate maintenance of the active atrinik/classic monorepo. The five former standalone component repositories are already archived and read-only; C23/Clang-only replacement assumptions below are historical.
Outcome
Apply consistent analysis, coverage, security, artifact, SBOM, provenance, and release gates across the organization without imposing a required check before its stable workflow exists.
Repository-specific validation
server: Go formatting/vet/static analysis, tests/race/fuzz builds, vulnerability/dependency-license review, deterministic generated/content conformance, release artifacts; aggregate Server validation.
content/resources/sound: deterministic validation/build/package plus exact provenance/license manifests.
active atrinik/classic monorepo: preserve and consolidate its checks for critical maintenance and unified Classic 5.x releases beginning with v5.6.0; do not make C modernization part of the replacement program.
five archived former component repositories: keep them read-only with deliberate archival governance; their checks are historical evidence, not active required contexts.
Governance sequencing
Desired state includes replacement and maintained classic repositories in PR gates/release-tag protection/security policy.
A fresh aggregate required check is added only after its workflow exists and succeeds on the default branch; apply in a coordinated governance change.
CodeQL/scanning/language matrices match actual code and generated inputs.
Codecov/manual app access follows active replacement and classic code owners. Access to the five archived former component repositories is removed only after the UI-only setting is verified; eventual classic-monorepo retirement performs the same deliberate check.
Actions are least privilege, pinned/approved, and recorded in supply-chain inventory.
Release artifacts include checksums, SBOM, provenance/attestations, dependency/code/data/asset licenses/notices, and immutable tag policy.
Scheduled audit covers classic and replacement profiles until cutover and reports transitional blockers truthfully.
Live governance records the five former component repositories as archived/read-only and atrinik/classic as active. The 12 retired temporary history/* refs are not required checks, release inputs, or protected operating branches and must not be recreated.
Branch-qualified content governance
Treat content@main and content@1.x as separate governed release lines in one repository.
Default-branch organization rules continue to protect main. The exact refs/heads/1.x maintenance ruleset from merged/applied PR #26 (live ruleset 20571870) prevents deletion/non-fast-forward updates, requires linear pull-request history, and requires the currently emitted Conventional PR title check.
Do not require Content validation on 1.x until content#45 makes that workflow run on the maintenance branch and a successful check is observed; then tighten desired state in the same coordinated change.
Release workflows/concurrency/artifacts distinguish replacement main from v1.x classic maintenance and cannot update the other line.
Final 1.x freeze remains protected after the classic monorepo/support cohort retires; atrinik/content itself stays active.
Acceptance criteria
Publisher dry-run/apply converges with no unknown repository/rule deletion.
Every active required context exists exactly once and is produced by stable default-branch CI.
Security/dependency/license/provenance failures are actionable and bounded; generated/vendor exclusions are documented.
Replacement and classic release identities/packages/Codecov/security settings cannot be confused after canonical-name reuse.
Replacement cutover and eventual classic-support retirement update desired and live state together with auditable plan output.
Root remains orchestration-only; language-specific workflows live in owning repositories.
Complete the native quality and release-security gates with separated CI signals, measured binary hardening, coverage ratchets, SBOMs, and verifiable provenance.
Scope
Add scoped clang-tidy, CodeQL/SARIF, coverage presets/reports, optimized tests, and scheduled deeper analysis/fuzzing/TSan where relevant.
Keep formatting, configure, compile, unit, protocol, runtime/content, analysis, fuzz, package, and artifact verification visibly separate.
Adopt and verify an appropriate compiler/linker hardening profile for ELF and PE artifacts.
Build releases from exact reviewed inputs and attach dependency/license/SBOM/provenance metadata plus install/startup smoke evidence.
Superseded path / cleanup target
Remove moving/unverified release inputs, ineffective hardening assumptions, permanent broad suppressions, and duplicate quality gates. Do not replace compiler warnings or sanitizers.
Acceptance criteria
PR and scheduled CI enforce the documented quality matrix with actionable separate checks.
Coverage and analysis operate as shrinking baselines/changed-code gates rather than vanity numbers.
Produced binaries pass explicit hardening inspection.
Every release artifact identifies exact source/image/submodule/dependency inputs and passes SBOM/license/provenance verification.
Validation baseline
Before: sanitizers and warnings are strong, but analysis, coverage, fuzz, optimized, and artifact provenance gates are incomplete.
After: the supported release matrix is continuously analyzed, hardened, reproducible, and inspectable.
Use the Atrinik GitHub-governance skill for workflow/check changes; run every new local preset/check, workflow syntax/policy validation, package smoke tests, binary inspection, and provenance verification.
This issue is a bounded child of atrinik/atrinik#167. The parent remains open until every sibling child is complete.
Architecture amendment — one authored content source (2026-08-13)
Initiative atrinik/atrinik#357 supersedes every future live-branch instruction below.
atrinik/content@mainis the sole mutable authored content source. Future authored changes belong only onmain; supported Classic artifacts must be derived from the same immutablemainrevision. Do not create, restore, author, backport, validate, publish, select, profile, or channel content through a live1.xbranch orcontent-1xcheckout.Exact historical commits, release tags, artifacts, checksums, and archived comparisons remain valid evidence. This amendment does not alter the issue's other feature, implementation, validation, licensing, or acceptance requirements.
Important
This governance epic targets the fresh MIT Go/Rust/Protobuf/Astro replacement repositories and deliberate maintenance of the active
atrinik/classicmonorepo. The five former standalone component repositories are already archived and read-only; C23/Clang-only replacement assumptions below are historical.Outcome
Apply consistent analysis, coverage, security, artifact, SBOM, provenance, and release gates across the organization without imposing a required check before its stable workflow exists.
Repository-specific validation
Server validation.Protocol validation.Website validation.atrinik/classicmonorepo: preserve and consolidate its checks for critical maintenance and unified Classic 5.x releases beginning withv5.6.0; do not make C modernization part of the replacement program.Governance sequencing
atrinik/classicas active. The 12 retired temporaryhistory/*refs are not required checks, release inputs, or protected operating branches and must not be recreated.Branch-qualified content governance
content@mainandcontent@1.xas separate governed release lines in one repository.main. The exactrefs/heads/1.xmaintenance ruleset from merged/applied PR #26 (live ruleset20571870) prevents deletion/non-fast-forward updates, requires linear pull-request history, and requires the currently emittedConventional PR titlecheck.Content validationon1.xuntil content#45 makes that workflow run on the maintenance branch and a successful check is observed; then tighten desired state in the same coordinated change.mainfrom v1.x classic maintenance and cannot update the other line.1.xfreeze remains protected after the classic monorepo/support cohort retires;atrinik/contentitself stays active.Acceptance criteria
Preserved historical hardening proposal
Parent and roadmap
Outcome
Complete the native quality and release-security gates with separated CI signals, measured binary hardening, coverage ratchets, SBOMs, and verifiable provenance.
Scope
Superseded path / cleanup target
Remove moving/unverified release inputs, ineffective hardening assumptions, permanent broad suppressions, and duplicate quality gates. Do not replace compiler warnings or sanitizers.
Acceptance criteria
Validation baseline
Before: sanitizers and warnings are strong, but analysis, coverage, fuzz, optimized, and artifact provenance gates are incomplete.
After: the supported release matrix is continuously analyzed, hardened, reproducible, and inspectable.
Use the Atrinik GitHub-governance skill for workflow/check changes; run every new local preset/check, workflow syntax/policy validation, package smoke tests, binary inspection, and provenance verification.
This issue is a bounded child of atrinik/atrinik#167. The parent remains open until every sibling child is complete.