Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
116 commits
Select commit Hold shift + click to select a range
b051aa3
ci: verify seven-repository convergence
raylee-hawkins Jul 22, 2026
6e6763a
fix(command-center): enforce immutable seven-repo checks
raylee-hawkins Jul 23, 2026
fee75e7
fix(command-center): reject workflow neutralization
raylee-hawkins Jul 23, 2026
c8f7fe0
chore(command-center): pin final reviewed source trees
raylee-hawkins Jul 23, 2026
f6485fb
chore(command-center): include final proof and Hoxline trees
raylee-hawkins Jul 23, 2026
beee6b5
fix(command-center): bind detached validation source
raylee-hawkins Jul 23, 2026
4f9e71d
chore(command-center): pin final website workflow tree
raylee-hawkins Jul 23, 2026
bd29952
chore(command-center): pin merge-resilient website tree
raylee-hawkins Jul 23, 2026
c06b4a7
chore(command-center): pin final platform merge-resilience tree
raylee-hawkins Jul 23, 2026
e6e91a0
ci(command-center): set validation import authority
raylee-hawkins Jul 23, 2026
fa95bbb
ci(command-center): bind platform checked observation
raylee-hawkins Jul 23, 2026
b0b0bf1
chore(command-center): seal reviewed convergence trees
raylee-hawkins Jul 23, 2026
e78929f
chore(command-center): refresh final authority content trees
raylee-hawkins Jul 23, 2026
9de52c3
ci(command-center): bind exact self observation
raylee-hawkins Jul 23, 2026
43fd17e
fix(command-center): separate final tree from authority content
raylee-hawkins Jul 23, 2026
90c3f8f
chore(command-center): seal final dual-identity source matrix
raylee-hawkins Jul 23, 2026
cc1032c
fix(command-center): fetch and verify authority content history
raylee-hawkins Jul 23, 2026
be46376
chore(command-center): refresh reviewed content selections
raylee-hawkins Jul 23, 2026
3afb59f
chore(command-center): seal consumer content identities
raylee-hawkins Jul 23, 2026
cd4ed1d
chore(command-center): seal final reviewed source matrix
raylee-hawkins Jul 23, 2026
f345b42
chore(command-center): seal final platform review identity
raylee-hawkins Jul 23, 2026
d636d19
fix(ci): bind command-center execution and authority identity
raylee-hawkins Jul 23, 2026
ac4677f
ci(command-center): match owning trust-boundary checks
raylee-hawkins Jul 23, 2026
d879a97
fix(ci): enforce controlled-test vocabulary
raylee-hawkins Jul 23, 2026
3764368
fix(ci): fail closed on vocabulary scan evasions
raylee-hawkins Jul 23, 2026
0dc7708
ci(command-center): require cross-repo claim parity
raylee-hawkins Jul 23, 2026
33cdace
fix(governance): normalize vocabulary security scans
raylee-hawkins Jul 23, 2026
cb76579
test(governance): keep vocabulary controls bounded
raylee-hawkins Jul 23, 2026
4c04ace
chore(command-center): select hardened source heads
raylee-hawkins Jul 23, 2026
76f2897
chore(command-center): review final convergence code heads
raylee-hawkins Jul 23, 2026
a93f3b9
chore(command-center): review final website identity logic
raylee-hawkins Jul 23, 2026
e806e91
chore(command-center): review final generator substitution guard
raylee-hawkins Jul 23, 2026
3a9a254
chore(command-center): seal hardened generated state
raylee-hawkins Jul 23, 2026
0940048
chore(command-center): review final Website projection repair
raylee-hawkins Jul 23, 2026
350602e
chore(command-center): seal final generated Website pair
raylee-hawkins Jul 23, 2026
eec78d8
chore(command-center): review final Platform and Website repairs
raylee-hawkins Jul 23, 2026
503d3af
chore(command-center): seal hardened Website data pair
raylee-hawkins Jul 23, 2026
841f37a
chore(command-center): review one-sided pair rejection
raylee-hawkins Jul 23, 2026
ab4a4e0
chore(command-center): review final projection model
raylee-hawkins Jul 23, 2026
da64b46
chore(command-center): seal final Website status pair
raylee-hawkins Jul 23, 2026
a591c8f
chore(command-center): seal final Hoxline Case Growth pair
raylee-hawkins Jul 23, 2026
a380396
chore(command-center): review merge-resilient Platform verifier
raylee-hawkins Jul 23, 2026
7ed69fa
chore(command-center): seal final Platform observation refresh
raylee-hawkins Jul 23, 2026
d4ed132
chore(command-center): review strategy-resilient source heads
raylee-hawkins Jul 23, 2026
bba6e6a
chore(command-center): seal strategy-resilient Website pair
raylee-hawkins Jul 23, 2026
4f8d7d2
chore(command-center): seal final strategy-resilient Hoxline pair
raylee-hawkins Jul 23, 2026
e7b3cfb
chore(command-center): review explicit observation verifier
raylee-hawkins Jul 23, 2026
8b7a498
chore(command-center): review rewritten-head Website verifier
raylee-hawkins Jul 23, 2026
b99a82c
chore(command-center): seal rewritten-head-safe Website pair
raylee-hawkins Jul 23, 2026
6878d9e
chore(command-center): review generator identity binding
raylee-hawkins Jul 23, 2026
842cf34
chore(command-center): review revision-substitution rejection
raylee-hawkins Jul 23, 2026
0868ba3
chore(command-center): seal final rewrite-resilient Website pair
raylee-hawkins Jul 23, 2026
2be25d5
chore(command-center): seal explicit-observation Hoxline pair
raylee-hawkins Jul 23, 2026
1050238
chore(command-center): review rewrite-resilient consumers
raylee-hawkins Jul 23, 2026
a54f2c1
chore(command-center): seal regenerated website pair
raylee-hawkins Jul 23, 2026
cbf4dae
chore(command-center): seal rewrite-resilient Hoxline pair
raylee-hawkins Jul 23, 2026
df00940
chore(command-center): seal schema-aware Hoxline pair
raylee-hawkins Jul 23, 2026
9d87c26
chore(command-center): review consumer-path generator repair
raylee-hawkins Jul 23, 2026
071ec49
chore(command-center): seal consumer-path provenance pair
raylee-hawkins Jul 23, 2026
aa09bc2
chore(command-center): seal final source observations
raylee-hawkins Jul 23, 2026
eeab391
ci(command-center): bound immutable checkout retries
raylee-hawkins Jul 23, 2026
5cf31d7
chore(command-center): record CI repair heads
raylee-hawkins Jul 23, 2026
5dd7630
chore(command-center): seal repaired website pair
raylee-hawkins Jul 23, 2026
6334b59
chore(command-center): seal final CI repair observations
raylee-hawkins Jul 23, 2026
657b041
fix(command-center): record exact repaired revisions
raylee-hawkins Jul 23, 2026
d5c8edc
chore(command-center): seal exact Hoxline CI source set
raylee-hawkins Jul 23, 2026
fbec4fd
chore(command-center): seal exact website source pair
raylee-hawkins Jul 23, 2026
44b179b
chore(command-center): seal final review source heads
raylee-hawkins Jul 23, 2026
207e186
chore(command-center): seal hardened platform source set
raylee-hawkins Jul 23, 2026
41dc7fe
chore(command-center): seal adversarial repair heads
raylee-hawkins Jul 23, 2026
b56c7d6
chore(command-center): seal detached-source repairs
raylee-hawkins Jul 23, 2026
51e4b09
chore(command-center): seal atomic detached-source pair
raylee-hawkins Jul 23, 2026
b87acd4
chore(ci): seal final website source identity
raylee-hawkins Jul 23, 2026
4d2bdfb
chore(ci): reseal website workflow identity
raylee-hawkins Jul 24, 2026
5c9e17c
chore(ci): seal executable checkout and hoxline heads
raylee-hawkins Jul 24, 2026
816a694
chore(ci): seal final reviewed identity matrix
raylee-hawkins Jul 24, 2026
d10bcaf
chore(ci): seal final platform selection head
raylee-hawkins Jul 24, 2026
d38a9d1
chore(ci): seal pinned platform manifest repair
raylee-hawkins Jul 24, 2026
b86cc46
chore(governance): seal content-resilient platform review
raylee-hawkins Jul 24, 2026
fc6c4b6
chore(governance): seal refreshed case-growth pair
raylee-hawkins Jul 24, 2026
4e69957
chore(governance): seal content-resilient platform tests
raylee-hawkins Jul 24, 2026
a9d1e8b
chore(governance): seal settled case-growth observations
raylee-hawkins Jul 24, 2026
c3bc356
chore(governance): seal merge-resilient platform review
raylee-hawkins Jul 24, 2026
c99c062
chore(governance): seal final merge-resilient observations
raylee-hawkins Jul 24, 2026
24244e7
fix(governance): bind authority origins to stored config
raylee-hawkins Jul 24, 2026
404b667
chore(convergence): refresh repaired source revisions
raylee-hawkins Jul 24, 2026
0c3d273
fix(governance): isolate command-center git authority
raylee-hawkins Jul 24, 2026
b93fb58
chore(convergence): select hardened authority content
raylee-hawkins Jul 24, 2026
cf27691
chore(convergence): seal final reviewed trees
raylee-hawkins Jul 24, 2026
7caeb64
chore(command-center): seal pair-containing review heads
raylee-hawkins Jul 24, 2026
6e3db50
chore(command-center): seal rewrite-resilient review heads
raylee-hawkins Jul 24, 2026
77b0a2d
chore(command-center): select rewritten website generator
raylee-hawkins Jul 24, 2026
c36c75e
chore(command-center): seal rewrite-resilient website pair
raylee-hawkins Jul 24, 2026
a09d08f
chore(command-center): seal repaired website workflow
raylee-hawkins Jul 24, 2026
1725ece
fix(ci): serialize convergence behind invariant checks
raylee-hawkins Jul 24, 2026
bfe47d1
chore(ci): select repaired convergence heads
raylee-hawkins Jul 24, 2026
b5ee643
chore(ci): select final repaired heads
raylee-hawkins Jul 24, 2026
5acb7fc
chore(ci): select claim-boundary repair
raylee-hawkins Jul 24, 2026
fce2b13
fix(ci): trigger command-center checks for every tracked path
raylee-hawkins Jul 24, 2026
40a73b5
chore(ci): refresh repaired seven-head manifest
raylee-hawkins Jul 24, 2026
396eb92
chore(ci): observe repaired platform head
raylee-hawkins Jul 24, 2026
eee9098
chore(ci): observe final platform repair
raylee-hawkins Jul 24, 2026
4a3508f
chore(ci): observe regenerated hoxline pair
raylee-hawkins Jul 24, 2026
f6d88ac
chore(ci): observe regenerated website pair
raylee-hawkins Jul 24, 2026
4db63ce
chore(command-center): record platform stabilization wave
raylee-hawkins Jul 24, 2026
5c6127f
chore(command-center): review generator code wave
raylee-hawkins Jul 24, 2026
d4e2631
chore(command-center): record generated consumer wave
raylee-hawkins Jul 24, 2026
b4e675d
chore(command-center): record final repair heads
raylee-hawkins Jul 24, 2026
86d66bc
chore(command-center): review website schema repair
raylee-hawkins Jul 24, 2026
f3dd6bc
chore(command-center): record final website repair heads
raylee-hawkins Jul 24, 2026
d7c92a8
chore(command-center): review website lineage-fetch repair
raylee-hawkins Jul 24, 2026
e7bdfda
chore(command-center): bind finite generated pair wave
raylee-hawkins Jul 24, 2026
f82fda8
chore(command-center): review rewrite-projection repair
raylee-hawkins Jul 24, 2026
32269a3
chore(command-center): bind rewrite-resilient status pair
raylee-hawkins Jul 24, 2026
ba99c8d
chore(command-center): review projection governance binding
raylee-hawkins Jul 24, 2026
1f30d7b
chore(command-center): bind projection-governed status pair
raylee-hawkins Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
269 changes: 247 additions & 22 deletions .github/workflows/command-center-invariants.yml
Original file line number Diff line number Diff line change
@@ -1,28 +1,13 @@
name: command-center-invariants

on:
pull_request:
paths:
- "README.md"
- "profile/**"
- "architecture/**"
- "governance/**"
- "wiki/**"
- ".github/pull_request_template.md"
- ".github/workflows/command-center-invariants.yml"
- "scripts/verify-command-center-invariants.py"
pull_request: {}
push:
branches:
- main
paths:
- "README.md"
- "profile/**"
- "architecture/**"
- "governance/**"
- "wiki/**"
- ".github/pull_request_template.md"
- ".github/workflows/command-center-invariants.yml"
- "scripts/verify-command-center-invariants.py"
workflow_dispatch: {}
schedule:
- cron: "23 7 * * 1"

permissions:
contents: read
Expand All @@ -31,8 +16,248 @@ jobs:
command-center-invariants:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Checkout command-center authority
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
persist-credentials: false
fetch-depth: 0

- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
with:
python-version: "3.12"

- name: Install structural verifier dependency
run: python -m pip install --disable-pip-version-check PyYAML==6.0.2

- name: Verify command-center invariants
run: python scripts/verify-command-center-invariants.py
run: python scripts/verify-command-center-invariants.py --self-test

- name: Run hostile command-center unit tests
run: python -B -m unittest discover -s tests

- name: Verify patch whitespace
shell: bash
run: |
set -euo pipefail
if [[ "${{ github.event_name }}" == "pull_request" ]]; then
git diff --check "${{ github.event.pull_request.base.sha }}...${{ github.event.pull_request.head.sha }}"
else
git show --check --format= HEAD
fi

seven-repository-convergence:
needs: command-center-invariants
runs-on: ubuntu-latest
env:
PYTHONDONTWRITEBYTECODE: "1"
steps:
- name: Checkout workflow authority at the event revision
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
path: source-set/.github
fetch-depth: 0
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
with:
python-version: "3.12"

- name: Set up Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: "20"

- name: Install bounded verifier dependencies
run: python -m pip install --disable-pip-version-check PyYAML==6.0.2 pytest==8.3.5

- name: Resolve governance/CONVERGENCE_SOURCE_MANIFEST.json
shell: bash
run: |
set -euo pipefail
mkdir -p verification-work verification-artifacts
python -B source-set/.github/scripts/verify-command-center-invariants.py \
--emit-source-manifest verification-work/resolved-source-manifest.json \
--event-sha "${{ github.event.pull_request.head.sha || github.sha }}"

- name: Checkout six immutable sibling revisions without credentials
shell: bash
run: |
set -euo pipefail
python - verification-work/resolved-source-manifest.json > verification-work/sibling-revisions.tsv <<'PY'
import json
import sys

value = json.load(open(sys.argv[1], encoding="utf-8"))
for entry in value["repositories"]:
if entry["repository"] != ".github":
print(f'{entry["repository"]}\t{entry["revision"]}')
PY
while IFS=$'\t' read -r repo revision; do
test -n "$repo"
test -n "$revision"
mkdir "source-set/$repo"
git -C "source-set/$repo" init --quiet
git -C "source-set/$repo" remote add origin "https://github.com/HawkinsOperations/$repo.git"
fetch_complete=0
for attempt in 1 2 3 4 5 6; do
if
git -C "source-set/$repo" fetch --quiet origin "$revision"
then
fetch_complete=1
break
fi
if [ "$attempt" -lt 6 ]; then
sleep 5
fi
done
test "$fetch_complete" -eq 1
git -C "source-set/$repo" checkout --quiet --detach "$revision"
test "$(git -C "source-set/$repo" rev-parse HEAD)" = "$revision"
done < verification-work/sibling-revisions.tsv

- name: Verify the exact clean detached source set
shell: bash
run: |
set -euo pipefail
python -B source-set/.github/scripts/verify-command-center-invariants.py \
--verify-source-set source-set \
--resolved-manifest verification-work/resolved-source-manifest.json \
--source-revisions-output verification-artifacts/source-revisions.json
readarray -t authority_shas < <(python - verification-work/resolved-source-manifest.json <<'PY'
import json
import sys

value = json.load(open(sys.argv[1], encoding="utf-8"))
by_repo = {entry["repository"]: entry["revision"] for entry in value["repositories"]}
print(by_repo[".github"])
print(by_repo["hawkinsoperations-proof"])
print(by_repo["hawkinsoperations-platform"])
PY
)
test "${#authority_shas[@]}" -eq 3
printf 'HAWKINS_COMMAND_CENTER_IMMUTABLE_OBSERVED_SHA=%s\n' "${authority_shas[0]}" >> "$GITHUB_ENV"
printf 'HAWKINS_PROOF_IMMUTABLE_MANIFEST_SHA=%s\n' "${authority_shas[1]}" >> "$GITHUB_ENV"
printf 'HAWKINS_PLATFORM_IMMUTABLE_OBSERVED_SHA=%s\n' "${authority_shas[2]}" >> "$GITHUB_ENV"

- name: Detect durable sibling main-content drift
if: github.event_name != 'pull_request'
run: >-
python -B source-set/.github/scripts/verify-command-center-invariants.py
--verify-remote-main-content source-set
--resolved-manifest verification-work/resolved-source-manifest.json

- name: Verify detection authority and hostile paths
shell: bash
run: |
set -euo pipefail
python -B source-set/hawkinsoperations-detections/scripts/verify_detection_contract.py
python -B source-set/hawkinsoperations-detections/scripts/verify_detection_promotion_matrix.py \
--validation-registry source-set/hawkinsoperations-validation/validation/VALIDATION_REGISTRY.yml \
--proof-index source-set/hawkinsoperations-proof/proof/indexes/DETECTION_PROOF_STATUS_INDEX.yml \
--require-sibling-handoffs
python -B -m unittest discover -s source-set/hawkinsoperations-detections/tests

- name: Verify validation authority and fail-closed parity
shell: bash
run: |
set -euo pipefail
python -B source-set/hawkinsoperations-validation/scripts/verify_validation_registry.py --detections-root source-set/hawkinsoperations-detections --detections-ref "$(git -C source-set/hawkinsoperations-detections rev-parse HEAD)" --source-manifest source-set/hawkinsoperations-validation/validation/SOURCE_AUTHORITY_MANIFEST.json
python -B source-set/hawkinsoperations-validation/scripts/verify_all_validation_packages.py --source-contract required
python -B source-set/hawkinsoperations-validation/scripts/verify_validation_contract.py
python -B source-set/hawkinsoperations-validation/scripts/verify_wazuh_logtest_registry.py
python -B source-set/hawkinsoperations-validation/scripts/verify_ho_lab_wazuh_001.py
python -B source-set/hawkinsoperations-validation/scripts/verify_cross_repo_claim_parity.py --repo-root source-set --enforce
PYTHONPATH="$GITHUB_WORKSPACE/source-set/hawkinsoperations-validation" python -B -m unittest discover -s source-set/hawkinsoperations-validation/tests

- name: Verify proof authority and reverse inventory
shell: bash
run: |
set -euo pipefail
python -B source-set/hawkinsoperations-proof/scripts/verify_detection_proof_status_index.py
python -B source-set/hawkinsoperations-proof/scripts/verify_proof_integrity.py
python -B -m unittest discover -s source-set/hawkinsoperations-proof/tests

- name: Verify platform source contract and seven-source convergence
shell: bash
run: |
set -euo pipefail
python -B source-set/hawkinsoperations-platform/scripts/verify-public-status-source-contract.py --format json
python -B source-set/hawkinsoperations-platform/scripts/ho_factory.py \
hoxline-case-growth-convergence-verify --repo-root source-set --format json
python -B -m unittest discover -s source-set/hawkinsoperations-platform/tests

- name: Install Hoxline from the checked immutable source
run: python -m pip install --disable-pip-version-check -e source-set/hoxline

- name: Verify Hoxline Case Growth pair and replay integrity
shell: bash
run: |
set -euo pipefail
python -B -m compileall -q source-set/hoxline/src source-set/hoxline/tests
python -B -m unittest discover -s source-set/hoxline/tests
python -B -m pytest -q source-set/hoxline/tests
python -B -m hoxline.cli case-growth index \
--repo-root source-set \
--format json \
--paired-output-base verification-work/current-case-growth-index
python -B -m hoxline.cli case-growth verify \
--repo-root source-set \
--snapshot verification-work/current-case-growth-index.json
python -B -m hoxline.cli case-growth verify \
--repo-root source-set \
--snapshot source-set/hoxline/examples/case-growth/current-case-growth-index.json
python -B -m hoxline review batch run \
--index source-set/hoxline/examples/review/multi-artifact-review-index-v1.json \
--output verification-work/batch \
--force \
--format json
python -B -m hoxline review batch verify \
--run verification-work/batch/batch-machine-state.json

- name: Install Website dependencies from the checked lockfile
run: npm ci --prefix source-set/hawkinsoperations-website

- name: Verify Website rendering-only status plane and static build
shell: bash
run: |
set -euo pipefail
npm --prefix source-set/hawkinsoperations-website run public-status:generate:check
npm --prefix source-set/hawkinsoperations-website run public-status:verify
npm --prefix source-set/hawkinsoperations-website run public-status:self-test
npm --prefix source-set/hawkinsoperations-website run public-status:owner-self-test
npm --prefix source-set/hawkinsoperations-website run public-status:source-checkout-test
npm --prefix source-set/hawkinsoperations-website run public-status:freshness-reachability-test
npm --prefix source-set/hawkinsoperations-website run public-status:dirty-provenance-test
npm --prefix source-set/hawkinsoperations-website run public-status:nested-claim-test
npm --prefix source-set/hawkinsoperations-website run public-status:strict-json-test
npm --prefix source-set/hawkinsoperations-website run public-status:eol-self-test
npm --prefix source-set/hawkinsoperations-website run check:site
npm --prefix source-set/hawkinsoperations-website run typecheck
npm --prefix source-set/hawkinsoperations-website run build

- name: Write closed-schema verification summary
run: >-
python -B source-set/.github/scripts/verify-command-center-invariants.py
--write-verification-summary
verification-artifacts/verification-summary.json

- name: Validate upload artifacts
run: >-
python -B source-set/.github/scripts/verify-command-center-invariants.py
--validate-artifacts
verification-artifacts
--artifact-source-set
source-set

- name: Upload sanitized convergence records
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: seven-repository-convergence-${{ github.run_id }}
path: |
verification-artifacts/source-revisions.json
verification-artifacts/verification-summary.json
if-no-files-found: error
retention-days: 14
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
__pycache__/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Trigger checks for every tracked file scanned

When a push or PR changes only this newly tracked .gitignore—or any other path outside the workflow's allowlist—neither event starts this workflow, even though tracked_vocabulary_findings() uses git ls-files to enforce its policy across the entire repository. Such a change can therefore introduce content that the verifier would reject without running the required check; remove the path filters or expand them to every scanned tracked path.

Useful? React with 👍 / 👎.

*.py[cod]
15 changes: 14 additions & 1 deletion governance/COMMAND_CENTER_INVARIANTS.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,19 @@
"governance/PR_REVIEW_AUTHORITY.md",
"governance/CROSS_REPO_PROMOTION_MAP.md",
"wiki/11_ORG_SYSTEM_MAP.md",
".github/pull_request_template.md"
".github/pull_request_template.md",
".github/workflows/command-center-invariants.yml",
"scripts/verify-command-center-invariants.py",
"governance/CONVERGENCE_SOURCE_MANIFEST.json"
],
"cross_repo_repositories": [
".github",
"hawkinsoperations-detections",
"hawkinsoperations-validation",
"hawkinsoperations-platform",
"hawkinsoperations-proof",
"hawkinsoperations-website",
"hoxline"
],
"invariants": {
"github_repo_role": ".github is reviewer routing and governance shell only",
Expand All @@ -26,6 +38,7 @@
"ledger_public_safe_status": "NOT_PUBLIC_SAFE",
"reviewer_metrics_pipeline": "Reviewer metrics pipeline keeps Lifetime Governed Cases separate from detection activity, validation cases, proof records, blocked claims, and Project Board reconciliation status",
"reviewer_metrics_counts": "Reviewer metrics values are authority-owned snapshots in proof/platform records; front-door text must route to those records instead of copying changing counts",
"cross_repo_convergence": "Read-only verification checks exactly seven repositories at an explicit immutable PR-head matrix, records and verifies every checked revision, fails closed on drift, and does not write main, merge, mutate the Lifetime Case Ledger, or promote proof/public status",
"ho_det_001_public_ceiling": "CONTROLLED_TEST_VALIDATED",
"runtime_signal_public_promotions": "runtime-active, signal-observed, evidence-linked public proof, public-safe, production-ready, fleet-wide, AWS-live, Cribl-routed, Wazuh-routed, autonomous SOC, AI-approved, AI-decided, analyst-approved, and live Splunk claims remain blocked unless separately proven and approved",
"standing_controls": ".github#8 and .github#10 remain standing controls",
Expand Down
64 changes: 64 additions & 0 deletions governance/CONVERGENCE_SOURCE_MANIFEST.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
{
"schema": "hawkinsoperations-convergence-source-manifest-v1",
"manifest_id": "HAWKINSOPERATIONS_SEVEN_SOURCE_PR_HEAD_MATRIX_V1",
"repositories": [
{
"repository": ".github",
"canonical_repository": "HawkinsOperations/.github",
"revision_source": "github_event_sha",
"authority_content_revision": "6e6763a81d6af09c2e4588462b56117ce82c2f88",
"tree_source": "github_event_tree"
},
{
"repository": "hawkinsoperations-detections",
"canonical_repository": "HawkinsOperations/hawkinsoperations-detections",
"revision": "9e01f43fb350de3370f8c01a323dcdcdf2e33147",
"authority_content_revision": "f8bc0a0925113ca815bf5692081b5216162cc918",
"reviewed_tree_sha": "4135fc6fafb3bc842096ee58fa7dd53d24172b65"
},
{
"repository": "hawkinsoperations-validation",
"canonical_repository": "HawkinsOperations/hawkinsoperations-validation",
"revision": "677b704150b0f5f333c27913dd481b4be6a78ab7",
"authority_content_revision": "ebf52f7c6c9b78de767272cc56fccdc584f5c4e0",
"reviewed_tree_sha": "b4a12cfe4a67e5b66171f73cd228c2691789dcc6"
},
{
"repository": "hawkinsoperations-platform",
"canonical_repository": "HawkinsOperations/hawkinsoperations-platform",
"revision": "d2901f303a2047436d1ada2d97f2eb4310380585",
"authority_content_revision": "a667c4de8b478fe165c3ec612e642bbd5d879492",
"reviewed_tree_sha": "0ad3ad8ff804e6b0fff9c4bf5eb1c913a76f602c"
},
{
"repository": "hawkinsoperations-proof",
"canonical_repository": "HawkinsOperations/hawkinsoperations-proof",
"revision": "77b7874dd753369792330508fa3438cf397cd050",
"authority_content_revision": "042a918ad4a8473cd5abcfd575072fc094639682",
"reviewed_tree_sha": "68fc8c604ffebb392e2fa6b205a920e9560b424b"
},
{
"repository": "hawkinsoperations-website",
"canonical_repository": "HawkinsOperations/hawkinsoperations-website",
"revision": "ee30ae81d31e8f27fa779ddb42470f7d27db1f33",
"authority_content_revision": "5856f8e69527b5e61c3953b88a2ad4c088268655",
"reviewed_tree_sha": "672da08e0e5c42d7be543cb9bdcfa45ccb59daa2"
},
{
"repository": "hoxline",
"canonical_repository": "HawkinsOperations/hoxline",
"revision": "cd797da491f07b9a0130278d7245f51962dd82c0",
"authority_content_revision": "1cb97efc45ffe753389105645c25ed7fe57cf9e5",
"reviewed_tree_sha": "29dc0d921bbc342f30d8be46cf88f049ea591f0a"
}
],
"constraints": {
"exact_repository_count": 7,
"read_only": true,
"default_branch_fallback": false,
"require_detached_exact_revision": true,
"record_checked_revisions": true,
"consumer_outputs_are_not_authority": true,
"proof_ceiling": "CONTROLLED_REPO_CONVERGENCE_AND_LOCAL_FIXTURE_REVIEW_ONLY"
}
}
Loading
Loading