Outcome
The repository audit finishes through a small, ordered set of outcome stacks. This epic owns only the programme completion rule, prerequisites between child epics, and the current implementation order.
Child epics
Each child epic repeats the order of its managed delivery issues.
Implementation order
This is the exhaustive programme order for managed delivery issues and retained audit slices. Closed entries remain in the list to preserve the completed sequence. Native dependencies remain authoritative. An external prerequisite can delay its issue without delaying an independent later issue.
security(repo): enable secret scanning and push protection #402 — enable secret scanning and push protection (complete)
bug(ci): make aggregate policy results explicit and tested #373 — make aggregate policy results explicit and tested (complete)
bug(build): harden verified fixture download and replacement #380 — harden verified fixture download and replacement
refactor(test): decouple matcher tests from incidental messages #331 — decouple matcher tests from incidental messages
refactor(agent): make repository agent policy concise, neutral, and safe #375 — make repository agent policy concise, neutral, and safe
test(compat): verify Adventure and Paper support boundaries #324 — verify Adventure and Paper support boundaries
build(api): define and enforce Kotventure API stability #55 — define and enforce Kotventure API stability
security(ci): separate untrusted PR execution from trusted publication #399 — separate untrusted pull-request execution from trusted publication
security(build): verify and lock Gradle dependency resolution #409 — verify and lock Gradle dependency resolution
security(build): validate the Gradle wrapper and bound distribution retries #411 — validate the Gradle wrapper and bound distribution retries
chore(deps): define dependency update and vulnerability handling #404 — define dependency update and vulnerability handling
test(snapshot): harden storage and cross-platform behaviour #381 — harden snapshot storage and cross-platform behaviour
test(core): align and enforce the Ticker timing contract #382 — align and enforce the Ticker timing contract
test(dsl): maintain compile-pass and compile-fail API fixtures #467 — maintain compile-pass and compile-fail API fixtures
ci(conventions): define title and commit vocabulary #506 — define title and commit vocabulary
docs(policy): align Alpha lifecycle, security support, and contribution guidance #388 — align Alpha lifecycle, security support, and contribution guidance
refactor(meta): centralise module facts and enforce architecture boundaries #378 — centralise module facts and enforce architecture boundaries
bug(build): publish and verify module-specific Java compatibility #372 — publish and verify module-specific Java compatibility
build(publish): complete and consume the published module set #413 — complete and consume the published module set
security(release): harden the Release Please control plane #406 — harden the Release Please control plane
refactor(ci): centralise Release Please provenance #392 — centralise Release Please provenance
security(ci): enforce trusted GitHub Actions references #397 — enforce trusted GitHub Actions references
refactor(ci): replace custom approval with native CODEOWNERS review #395 — replace custom approval with native CODEOWNERS review
refactor(ci): make event-specific workflow contracts explicit #448 — make event-specific workflow contracts explicit
refactor(ci): simplify and expose PR metrics health #446 — simplify and expose pull-request metrics health
security(ci): define honest analysis and merge-gate semantics #396 — define honest analysis and merge-gate semantics
docs(meta): reconcile roadmap and epic status #390 — reconcile roadmap and epic status
chore(repo): create deterministic first-party repository validation #391 — create deterministic first-party repository validation
chore(agent): generate a concise Kotventure API index #420 — generate a concise Kotventure API index
refactor(build): simplify Gradle build logic incrementally #379 — simplify Gradle build logic incrementally
chore(agent): make CodeRabbit accurate, stable, and advisory #385 — make CodeRabbit accurate, stable, and advisory
test(dsl): add bounded property and differential conformance tests #416 — add bounded property and differential conformance tests
test(concurrency): stress high-risk state-machine contracts #417 — stress high-risk state-machine contracts
feat(diagnostics): stabilise selected validation diagnostics #505 — stabilise selected validation diagnostics
test(coverage): make module and patch coverage visible and ratcheted #414 — make module and patch coverage visible and ratcheted
docs(architecture): record durable decisions and pull-request validation evidence #423 — record durable decisions and pull-request validation evidence
build(release): produce reproducible and attestable release candidates #429 — produce reproducible and attestable release candidates
build(release): verify reproducible release candidates #507 — verify reproducible release candidates
build(release): attest published release artefacts #508 — attest published release artefacts
ci(conventions): Adopt shared conventional validation action #342 — adopt the shared conventional validation action
Stack rules
Completion
Close this epic only when each retained native child outcome, including both #429 delivery slices, is complete or explicitly closed as not planned. The audit slices of #55 and #324 must also be complete. Broader roadmap work in those two issues does not block this epic.
Outcome
The repository audit finishes through a small, ordered set of outcome stacks. This epic owns only the programme completion rule, prerequisites between child epics, and the current implementation order.
Child epics
Each child epic repeats the order of its managed delivery issues.
Implementation order
This is the exhaustive programme order for managed delivery issues and retained audit slices. Closed entries remain in the list to preserve the completed sequence. Native dependencies remain authoritative. An external prerequisite can delay its issue without delaying an independent later issue.
Tickertiming contractStack rules
Completion
Close this epic only when each retained native child outcome, including both #429 delivery slices, is complete or explicitly closed as not planned. The audit slices of #55 and #324 must also be complete. Broader roadmap work in those two issues does not block this epic.