Wave 39: centralize contributor and agent governance - #403
Conversation
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
ty-everett
left a comment
There was a problem hiding this comment.
Exact-head maintainer self-review completed as ty-everett at fcda716e370b0e3ab4b870ec2be93d5a2b38a771. GitHub does not permit an author to submit an APPROVE review on their own PR, so this anchored review records the required assessment without waiting for another maintainer. The complete diff preserves public API/runtime behavior, centralizes contributor and agent authority, records every historical disposition, and is supported by terminal-successful repository health, lint, formatting, build, typecheck, tests, artifacts, docs, conformance, coverage, patch coverage, mutation, CodeQL, Sonar zero-finding, Socket, container, browser/mobile, and merge-gate evidence. No review threads or requested changes remain.
Wave 39 (#403) landed after this branch was cut and now requires a generated root-policy pointer at every governed project, so add packages/helpers/air-gap/AGENTS.md and bump the scoped-pointer count to 44. Also clears the ten new SonarCloud findings the zero-findings gate reported: - S8786 in src/base64url.ts and tests/helpers.ts — `=+$` backtracks super-linearly on a long run of '='. btoa pads to a multiple of four, so a bounded `={0,2}$` strips the same padding in linear time. - S7749 in src/constants.ts — uneven numeric separator groups in `0x1_0000_0000`; `2 ** 32` states the u32 bound directly. - S5906 across four test files — `toHaveLength` reports better than comparing a raw `.length`. No behavior change: the frozen conformance vectors and all 100 tests pass unchanged, src coverage stays at 100%, and the mutation score is 89.77%. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Wave 39 (#403) landed after this branch was cut and now requires a generated root-policy pointer at every governed project, so add packages/helpers/air-gap/AGENTS.md and bump the scoped-pointer count to 44. Also clears the ten new SonarCloud findings the zero-findings gate reported: - S8786 in src/base64url.ts and tests/helpers.ts — `=+$` backtracks super-linearly on a long run of '='. btoa pads to a multiple of four, so a bounded `={0,2}$` strips the same padding in linear time. - S7749 in src/constants.ts — uneven numeric separator groups in `0x1_0000_0000`; `2 ** 32` states the u32 bound directly. - S5906 across four test files — `toHaveLength` reports better than comparing a raw `.length`. No behavior change: the frozen conformance vectors and all 100 tests pass unchanged, src coverage stays at 100%, and the mutation score is 89.77%. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Wave 39 (#403) landed after this branch was cut and now requires a generated root-policy pointer at every governed project, so add packages/helpers/air-gap/AGENTS.md and bump the scoped-pointer count to 44. Also clears the ten new SonarCloud findings the zero-findings gate reported: - S8786 in src/base64url.ts and tests/helpers.ts — `=+$` backtracks super-linearly on a long run of '='. btoa pads to a multiple of four, so a bounded `={0,2}$` strips the same padding in linear time. - S7749 in src/constants.ts — uneven numeric separator groups in `0x1_0000_0000`; `2 ** 32` states the u32 bound directly. - S5906 across four test files — `toHaveLength` reports better than comparing a raw `.length`. No behavior change: the frozen conformance vectors and all 100 tests pass unchanged, src coverage stays at 100%, and the mutation score is 89.77%. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>



Program and scope
fcda716e370b0e3ab4b870ec2be93d5a2b38a771Impact
Affected package candidates (not published here):
@bsv/sdk2.2.15,@bsv/templates1.9.6, and lockstep@bsv/wallet-toolbox,@bsv/wallet-toolbox-client, and@bsv/wallet-toolbox-mobile2.4.20. Changes are README/contribution-policy alignment only; runtime behavior is unchanged.Verification
pnpm health:check(113/113 governance tests; 0 findings/control errors),pnpm lint(0 warnings),pnpm format:check,pnpm typecheck,pnpm build,pnpm test,pnpm audit:security(0 vulnerabilities),pnpm check-versions,pnpm docs:facts:check,pnpm docs:build, contributor-policy tests (5/5), issue-form YAML parse, and affected artifact checks all passedmerge-gateSecurity and dependencies
Dependency evidence
Release and operations
Completion evidence
mainis verifiedConsolidation inventory
.githubfiles have explicit root replacement or retirement dispositions