Repository navigation
Bind the Chat main dispatch revision by its descent to the producer - #318
Merged
Merged
Conversation
Protected run 36097764194 dispatched from Chat main at cab1cace, a descendant of the bound producer b1091054, so its artifacts cannot satisfy a tip-only lock. Bind the current Chat main tip f4fbb423 with its explicit parent walk to the producer. None of the five descent commits changes the workflow or a governed harness file; the producer, harness authority and workflow bytes are unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Provenance and ancestry binding require final human validation.
Review effort: Lite
Findings: None
What changed in this PR
Binds Chat main at f4fbb423 to the reviewed producer through a verified Git descent.
Changes:
- Updates the conformance lock and workflow fixtures.
- Adds descent ancestry authority and regression coverage.
- Documents the bound dispatch revision.
| File | Description |
|---|---|
tests/conformance-gaps.spec.ts |
Updates the expected workflow binding. |
tests/conformance-contract.spec.ts |
Adds descent authority fixtures and tip-only testing. |
docs/workflows/client-v1-cross-repository-conformance.md |
Documents the bound dispatch revision. |
conformance/client-v1-cross-repository-lock.json |
Records the dispatch digest and ancestry chain. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #40.
Protected Chat run 36097764194 dispatched from Chat
mainatcab1cace, not the bound producerb1091054. The GitHub evidence verifier requires every run, job, deployment, artifact and certificate to nameworkflow.sourceDigest, so that run's artifacts cannot lift the aggregate block. Because each platform record embeds the frozen lock's digest, the descent has to be bound before the dispatch, not added afterwards.This binds the current Chat
maintipf4fbb423through thesourceDescentmechanism from #295:Each link is a first-parent merge.
git diff b1091054 f4fbb423 -- .github/ scripts/ phase1-conformance.lock.jsonis empty, so the workflow bytes and governed harness files match the producer. The producer, harness authority, workflow digests and validator scripts are unchanged.tests/conformance-contract.spec.ts: the current-lock authority fixture now carries the real descent commits, read from Git. The tip-only refusal test uses the current lock with the descent removed.tests/conformance-gaps.spec.ts: the pinned workflow literal is updated.Validation: full
pnpm verifypasses locally (before the one-link extension tof4fbb423). The conformance and release specs pass after it (327 passed).Next: rotate both validator scopes to the merge, then dispatch at
f4fbb423straight away. If Chatmainmoves first, the descent needs one more link.🤖 Generated with Claude Code