Skip to content

Govern replacement analysis, coverage, security, SBOM, and release provenance #19

Description

@zoeyrose

Architecture amendment — one authored content source (2026-08-13)

Initiative atrinik/atrinik#357 supersedes every future live-branch instruction below. atrinik/content@main is the sole mutable authored content source. Future authored changes belong only on main; supported Classic artifacts must be derived from the same immutable main revision. Do not create, restore, author, backport, validate, publish, select, profile, or channel content through a live 1.x branch or content-1x checkout.

Exact historical commits, release tags, artifacts, checksums, and archived comparisons remain valid evidence. This amendment does not alter the issue's other feature, implementation, validation, licensing, or acceptance requirements.

Important

This governance epic targets the fresh MIT Go/Rust/Protobuf/Astro replacement repositories and deliberate maintenance of the active atrinik/classic monorepo. The five former standalone component repositories are already archived and read-only; C23/Clang-only replacement assumptions below are historical.

Outcome

Apply consistent analysis, coverage, security, artifact, SBOM, provenance, and release gates across the organization without imposing a required check before its stable workflow exists.

Repository-specific validation

  • server: Go formatting/vet/static analysis, tests/race/fuzz builds, vulnerability/dependency-license review, deterministic generated/content conformance, release artifacts; aggregate Server validation.
  • client/editor/renderer/content-toolkit: rustfmt, Clippy-as-errors, unit/doc/integration/property/fuzz builds, cargo dependency/license/security policy, native SDL3/wgpu target checks, shader/generated drift, packages; exact aggregate checks per repository.
  • protocol: Buf format/lint/breaking, pinned generation drift, generated Go/Rust builds, cross-language conformance/negative/fuzz; Protocol validation.
  • website: locked install, lint/type/build/link/accessibility/performance/security/deployment dry-run; Website validation.
  • content/resources/sound: deterministic validation/build/package plus exact provenance/license manifests.
  • active atrinik/classic monorepo: preserve and consolidate its checks for critical maintenance and unified Classic 5.x releases beginning with v5.6.0; do not make C modernization part of the replacement program.
  • five archived former component repositories: keep them read-only with deliberate archival governance; their checks are historical evidence, not active required contexts.

Governance sequencing

  • Desired state includes replacement and maintained classic repositories in PR gates/release-tag protection/security policy.
  • A fresh aggregate required check is added only after its workflow exists and succeeds on the default branch; apply in a coordinated governance change.
  • CodeQL/scanning/language matrices match actual code and generated inputs.
  • Codecov/manual app access follows active replacement and classic code owners. Access to the five archived former component repositories is removed only after the UI-only setting is verified; eventual classic-monorepo retirement performs the same deliberate check.
  • Actions are least privilege, pinned/approved, and recorded in supply-chain inventory.
  • Release artifacts include checksums, SBOM, provenance/attestations, dependency/code/data/asset licenses/notices, and immutable tag policy.
  • Scheduled audit covers classic and replacement profiles until cutover and reports transitional blockers truthfully.
  • Live governance records the five former component repositories as archived/read-only and atrinik/classic as active. The 12 retired temporary history/* refs are not required checks, release inputs, or protected operating branches and must not be recreated.

Branch-qualified content governance

  • Treat content@main and content@1.x as separate governed release lines in one repository.
  • Default-branch organization rules continue to protect main. The exact refs/heads/1.x maintenance ruleset from merged/applied PR #26 (live ruleset 20571870) prevents deletion/non-fast-forward updates, requires linear pull-request history, and requires the currently emitted Conventional PR title check.
  • Do not require Content validation on 1.x until content#45 makes that workflow run on the maintenance branch and a successful check is observed; then tighten desired state in the same coordinated change.
  • Release workflows/concurrency/artifacts distinguish replacement main from v1.x classic maintenance and cannot update the other line.
  • Final 1.x freeze remains protected after the classic monorepo/support cohort retires; atrinik/content itself stays active.

Acceptance criteria

  • Publisher dry-run/apply converges with no unknown repository/rule deletion.
  • Every active required context exists exactly once and is produced by stable default-branch CI.
  • Security/dependency/license/provenance failures are actionable and bounded; generated/vendor exclusions are documented.
  • Replacement and classic release identities/packages/Codecov/security settings cannot be confused after canonical-name reuse.
  • Replacement cutover and eventual classic-support retirement update desired and live state together with auditable plan output.
  • Root remains orchestration-only; language-specific workflows live in owning repositories.
Preserved historical hardening proposal

Parent and roadmap

Outcome

Complete the native quality and release-security gates with separated CI signals, measured binary hardening, coverage ratchets, SBOMs, and verifiable provenance.

Scope

  • Add scoped clang-tidy, CodeQL/SARIF, coverage presets/reports, optimized tests, and scheduled deeper analysis/fuzzing/TSan where relevant.
  • Keep formatting, configure, compile, unit, protocol, runtime/content, analysis, fuzz, package, and artifact verification visibly separate.
  • Adopt and verify an appropriate compiler/linker hardening profile for ELF and PE artifacts.
  • Build releases from exact reviewed inputs and attach dependency/license/SBOM/provenance metadata plus install/startup smoke evidence.

Superseded path / cleanup target

Remove moving/unverified release inputs, ineffective hardening assumptions, permanent broad suppressions, and duplicate quality gates. Do not replace compiler warnings or sanitizers.

Acceptance criteria

  • PR and scheduled CI enforce the documented quality matrix with actionable separate checks.
  • Coverage and analysis operate as shrinking baselines/changed-code gates rather than vanity numbers.
  • Produced binaries pass explicit hardening inspection.
  • Every release artifact identifies exact source/image/submodule/dependency inputs and passes SBOM/license/provenance verification.

Validation baseline

Before: sanitizers and warnings are strong, but analysis, coverage, fuzz, optimized, and artifact provenance gates are incomplete.

After: the supported release matrix is continuously analyzed, hardened, reproducible, and inspectable.

Use the Atrinik GitHub-governance skill for workflow/check changes; run every new local preset/check, workflow syntax/policy validation, package smoke tests, binary inspection, and provenance verification.

This issue is a bounded child of atrinik/atrinik#167. The parent remains open until every sibling child is complete.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Fields

    Priority

    None yet

    Start date

    None yet

    Target date

    None yet

    Effort

    None yet

    Projects

    Status
    Backlog

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions