Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
name: BoJ Server Build Trigger
on:
push:
Expand All @@ -8,10 +9,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Trigger BoJ Server (Casket/ssg-mcp)
run: |
# Send a secure trigger to boj-server to build this repository
curl -X POST "http://boj-server.local:7700/cartridges/ssg-mcp/invoke" -H "Content-Type: application/json" -d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\\"}"}
continue-on-error: true
permissions: read-all
permissions:
contents: read
3 changes: 2 additions & 1 deletion .github/workflows/guix-nix-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@
name: Guix/Nix Package Policy
on: [push, pull_request]

permissions: read-all
permissions:
contents: read

jobs:
check:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/mirror.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,8 @@ on:
branches: [main]
workflow_dispatch:

permissions: read-all
permissions:
contents: read

jobs:
mirror-gitlab:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/npm-bun-blocker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@
name: NPM/Bun Blocker
on: [push, pull_request]

permissions: read-all
permissions:
contents: read

jobs:
check:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/rsr-antipattern.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,8 @@ on:
branches: [main, master, develop]


permissions: read-all
permissions:
contents: read

jobs:
antipattern-check:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/scorecard-enforcer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,8 @@ on:
- cron: '0 6 * * 1' # Weekly on Monday
workflow_dispatch:

permissions: read-all
permissions:
contents: read

jobs:
scorecard:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/secret-scanner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,8 @@ on:
push:
branches: [main]

permissions: read-all
permissions:
contents: read

jobs:
trufflehog:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/security-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@
name: Security Policy
on: [push, pull_request]

permissions: read-all
permissions:
contents: read

jobs:
check:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/ts-blocker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@
name: TypeScript/JavaScript Blocker
on: [push, pull_request]

permissions: read-all
permissions:
contents: read

jobs:
check:
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/wellknown-enforcement.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,8 @@ on:
workflow_dispatch:


permissions: read-all
permissions:
contents: read

jobs:
validate:
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/workflow-linter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,8 @@ on:
- '.github/workflows/**'
workflow_dispatch:

permissions: read-all
permissions:
contents: read

jobs:
lint-workflows:
Expand Down Expand Up @@ -53,7 +54,8 @@ jobs:
fi
done
if [ $failed -eq 1 ]; then
echo "Add 'permissions: read-all' at workflow level"
echo "Add 'permissions:
contents: read' at workflow level"
exit 1
fi
echo "All workflows have permissions declared"
Expand All @@ -63,7 +65,7 @@ jobs:
echo "=== Checking Action Pinning ==="
# Find any uses: lines that don't have @SHA format
# Pattern: uses: owner/repo@<40-char-hex>
unpinned=$(grep -rn "uses:" .github/workflows/ | \
unpinned=$(grep -rnE "^[[:space:]]+uses:" .github/workflows/ | \
grep -v "@[a-f0-9]\{40\}" | \
grep -v "uses: \./\|uses: docker://\|uses: actions/github-script" || true)

Expand Down
22 changes: 22 additions & 0 deletions .machine_readable/contractiles/dust/Dustfile.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# Dustfile — Cleanup and Hygiene Contract

[dustfile]
version = "1.0.0"
format = "a2ml"

[cleanup]
stale-branch-policy = "delete-after-merge"
artifact-retention = "90-days"
cache-policy = "clear-on-release"

[hygiene]
linting = "required"
formatting = "required"
dead-code-removal = "encouraged"
todo-tracking = "tracked-in-issues"

[reversibility]
backup-before-destructive = true
rollback-mechanism = "git-revert"
data-retention-policy = "preserve-30-days"
22 changes: 22 additions & 0 deletions .machine_readable/contractiles/trust/Trustfile.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# Trustfile — Integrity and Provenance Contract

[trustfile]
version = "1.0.0"
format = "a2ml"

[provenance]
source-control = "git"
forge = "github"
ci-verified = true
signing-policy = "commit-signing-preferred"

[integrity]
spdx-compliant = true
license-audit = "required"
dependency-pinning = "sha-pinned"

[verification]
reproducible-builds = "goal"
sbom-generation = "required"
attestation = "sigstore-preferred"
13 changes: 13 additions & 0 deletions .machine_readable/integrations/feedback-o-tron.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# Feedback-o-Tron Integration — Autonomous Bug Reporting

[integration]
name = "feedback-o-tron"
type = "bug-reporter"
repository = "https://github.com/hyperpolymath/feedback-o-tron"

[reporting-config]
platforms = ["github", "gitlab", "bugzilla"]
deduplication = true
audit-logging = true
auto-file-upstream = "on-external-dependency-failure"
18 changes: 18 additions & 0 deletions .machine_readable/integrations/proven.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# Proven Integration — Formally Verified Safety Library

[integration]
name = "proven"
type = "safety-library"
repository = "https://github.com/hyperpolymath/proven"
version = "1.2.0"

[binding-policy]
approach = "thin-ffi-wrapper"
unsafe-patterns = "replace-with-proven-equivalent"
modules-available = ["SafeMath", "SafeString", "SafeJSON", "SafeURL", "SafeRegex", "SafeSQL", "SafeFile", "SafeTemplate", "SafeCrypto"]

[adoption-guidance]
priority = "high"
scope = "all-string-json-url-crypto-operations"
migration = "incremental — replace unsafe patterns as encountered"
15 changes: 15 additions & 0 deletions .machine_readable/integrations/verisimdb.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# VeriSimDB Feed — Cross-Repo Analytics Data Store

[integration]
name = "verisimdb"
type = "data-feed"
repository = "https://github.com/hyperpolymath/nextgen-databases"
data-store = "verisimdb-data"

[feed-config]
emit-scan-results = true
emit-build-metrics = true
emit-dependency-graph = true
format = "hexad"
destination = "verisimdb-data/feeds/"
18 changes: 18 additions & 0 deletions .machine_readable/integrations/vexometer.a2ml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# SPDX-License-Identifier: PMPL-1.0-or-later
# Vexometer Integration — Irritation Surface Analysis

[integration]
name = "vexometer"
type = "friction-measurement"
repository = "https://github.com/hyperpolymath/vexometer"

[measurement-config]
dimensions = 10
emit-isa-reports = true
lazy-eliminator = true
satellite-interventions = true

[hooks]
cli-tools = "measure-on-error"
ui-panels = "measure-on-interaction"
build-failures = "measure-on-failure"
24 changes: 24 additions & 0 deletions EXPLAINME.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
// SPDX-License-Identifier: PMPL-1.0-or-later
= WokeLang — Show Me The Receipts
:toc:
:icons: font

The README makes claims. This file backs them up.

[quote, README]
____
WokeLang is a programming language designed for **human collaboration**, **empathy**, and **safety**—without sacrificing power or performance. It combines:
____

== File Map

[cols="1,2"]
|===
| Path | What's There

| `test(s)/` | Test suite
|===

== Questions?

Open an issue or reach out directly — happy to explain anything in more detail.
4 changes: 4 additions & 0 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -25,3 +25,7 @@ clean:
validate:
@echo "Checking SPDX headers..."
@grep -rL "SPDX-License-Identifier" src/ --include='*.rs' || echo "All files have SPDX headers"

# Run panic-attacker pre-commit scan
assail:
@command -v panic-attack >/dev/null 2>&1 && panic-attack assail . || echo "panic-attack not found — install from https://github.com/hyperpolymath/panic-attacker"
Loading
Loading