Skip to content

epic(meta): coordinate repository audit remediation #403

Description

@LMLiam

Outcome

The repository audit finishes through a small, ordered set of outcome stacks. This epic owns only the programme completion rule, prerequisites between child epics, and the current implementation order.

Child epics

Each child epic repeats the order of its managed delivery issues.

Implementation order

This is the exhaustive programme order for managed delivery issues and retained audit slices. Closed entries remain in the list to preserve the completed sequence. Native dependencies remain authoritative. An external prerequisite can delay its issue without delaying an independent later issue.

  1. security(repo): enable secret scanning and push protection #402 — enable secret scanning and push protection (complete)
  2. bug(ci): make aggregate policy results explicit and tested #373 — make aggregate policy results explicit and tested (complete)
  3. bug(build): harden verified fixture download and replacement #380 — harden verified fixture download and replacement
  4. refactor(test): decouple matcher tests from incidental messages #331 — decouple matcher tests from incidental messages
  5. refactor(agent): make repository agent policy concise, neutral, and safe #375 — make repository agent policy concise, neutral, and safe
  6. test(compat): verify Adventure and Paper support boundaries #324 — verify Adventure and Paper support boundaries
  7. build(api): define and enforce Kotventure API stability #55 — define and enforce Kotventure API stability
  8. security(ci): separate untrusted PR execution from trusted publication #399 — separate untrusted pull-request execution from trusted publication
  9. security(build): verify and lock Gradle dependency resolution #409 — verify and lock Gradle dependency resolution
  10. security(build): validate the Gradle wrapper and bound distribution retries #411 — validate the Gradle wrapper and bound distribution retries
  11. chore(deps): define dependency update and vulnerability handling #404 — define dependency update and vulnerability handling
  12. test(snapshot): harden storage and cross-platform behaviour #381 — harden snapshot storage and cross-platform behaviour
  13. test(core): align and enforce the Ticker timing contract #382 — align and enforce the Ticker timing contract
  14. test(dsl): maintain compile-pass and compile-fail API fixtures #467 — maintain compile-pass and compile-fail API fixtures
  15. ci(conventions): define title and commit vocabulary #506 — define title and commit vocabulary
  16. docs(policy): align Alpha lifecycle, security support, and contribution guidance #388 — align Alpha lifecycle, security support, and contribution guidance
  17. refactor(meta): centralise module facts and enforce architecture boundaries #378 — centralise module facts and enforce architecture boundaries
  18. bug(build): publish and verify module-specific Java compatibility #372 — publish and verify module-specific Java compatibility
  19. build(publish): complete and consume the published module set #413 — complete and consume the published module set
  20. security(release): harden the Release Please control plane #406 — harden the Release Please control plane
  21. refactor(ci): centralise Release Please provenance #392 — centralise Release Please provenance
  22. security(ci): enforce trusted GitHub Actions references #397 — enforce trusted GitHub Actions references
  23. refactor(ci): replace custom approval with native CODEOWNERS review #395 — replace custom approval with native CODEOWNERS review
  24. refactor(ci): make event-specific workflow contracts explicit #448 — make event-specific workflow contracts explicit
  25. refactor(ci): simplify and expose PR metrics health #446 — simplify and expose pull-request metrics health
  26. security(ci): define honest analysis and merge-gate semantics #396 — define honest analysis and merge-gate semantics
  27. docs(meta): reconcile roadmap and epic status #390 — reconcile roadmap and epic status
  28. chore(repo): create deterministic first-party repository validation #391 — create deterministic first-party repository validation
  29. chore(agent): generate a concise Kotventure API index #420 — generate a concise Kotventure API index
  30. refactor(build): simplify Gradle build logic incrementally #379 — simplify Gradle build logic incrementally
  31. chore(agent): make CodeRabbit accurate, stable, and advisory #385 — make CodeRabbit accurate, stable, and advisory
  32. test(dsl): add bounded property and differential conformance tests #416 — add bounded property and differential conformance tests
  33. test(concurrency): stress high-risk state-machine contracts #417 — stress high-risk state-machine contracts
  34. feat(diagnostics): stabilise selected validation diagnostics #505 — stabilise selected validation diagnostics
  35. test(coverage): make module and patch coverage visible and ratcheted #414 — make module and patch coverage visible and ratcheted
  36. docs(architecture): record durable decisions and pull-request validation evidence #423 — record durable decisions and pull-request validation evidence
  37. build(release): produce reproducible and attestable release candidates #429 — produce reproducible and attestable release candidates
  38. build(release): verify reproducible release candidates #507 — verify reproducible release candidates
  39. build(release): attest published release artefacts #508 — attest published release artefacts
  40. ci(conventions): Adopt shared conventional validation action #342 — adopt the shared conventional validation action

Stack rules

Completion

Close this epic only when each retained native child outcome, including both #429 delivery slices, is complete or explicitly closed as not planned. The audit slices of #55 and #324 must also be complete. Broader roadmap work in those two issues does not block this epic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicTracking issue spanning many sub-issuespriority: highNeeds urgent attention

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions