Skip to content

Complete user-account public entry and governance boundaries - #5

Draft
Riverbraid wants to merge 24 commits into
mainfrom
agent/public-entry-claim-precision
Draft

Complete user-account public entry and governance boundaries#5
Riverbraid wants to merge 24 commits into
mainfrom
agent/public-entry-claim-precision

Conversation

@Riverbraid

@Riverbraid Riverbraid commented Jul 27, 2026

Copy link
Copy Markdown
Owner

What changed

User-account public entry

  • Corrects the repository from organization configuration to GitHub user-account support configuration.
  • Records that profile/README.md is the organization-profile convention and does not prove rendering on the current Riverbraid user profile.
  • Adds USER_PROFILE_README_CANDIDATE.md as clean source text for a future public Riverbraid/Riverbraid root README.
  • Replaces public “proof path” wording with a bounded public evaluation path.
  • Separates Golds classification/coordination from registry membership, verification depth, and F3/F4 membership.

Governance and authority

  • Adds GOVERNANCE.md with a founder-led, evidence-constrained, forkable model; decision classes; conflict handling; succession; and explicit no-silent-adoption rules.
  • Adds MAINTAINERS.md with the current authority map, founder-maintained status, role vocabulary, and intentional CODEOWNERS deferral.
  • Adds FORKING.md with provenance, evidence-continuity, naming, support, compatibility, and non-inherited-authority rules.

Contribution, rights, security, and support

  • Adds INBOUND_CONTRIBUTION_RIGHTS.md and updates CONTRIBUTING.md to define contributor representations, target-license treatment, third-party/generated-material disclosure, and the current no-default-CLA/no-default-DCO posture.
  • Adds one root PULL_REQUEST_TEMPLATE.md covering exact subject, change class, authority, evidence, negative/degraded cases, claim effect, composition, security/privacy, rollback/recovery, contributor rights, and F0–F4 effect.
  • Updates SECURITY.md so sensitive vulnerability details and secrets are never routed into public issues. When no private route is verified, only a minimal routing placeholder is permitted.
  • Updates SUPPORT.md with repository-specific routing and explicit availability limits.

Version, release, and compatibility precision

  • Adds SUPPORTED_VERSIONS.md so silence, a default branch, a tag, or a historical pass cannot become an account-wide support claim.
  • Adds RELEASE_AND_COMPATIBILITY.md with explicit compatibility classes, source/release separation, non-composition, supersession, rollback, and supply-chain boundaries.
  • Updates the root README to index the shared policies and state that local repository policies may override inherited defaults.

Mechanical validation

  • Adds scripts/validate-community-health.mjs.
  • Adds .github/workflows/community-health-invariants.yml pinned to:
    • ubuntu-24.04;
    • Node 20.11.0;
    • actions/checkout@11d5960a326750d5838078e36cf38b85af677262;
    • actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020.
  • The validator requires 14 non-empty public/governance files and checks account type, profile routing, authority, CODEOWNERS deferral, rights, security routing, PR evidence fields, support/version boundaries, release compatibility, and prohibited overclaim language.

Exact-head validation

Current head:

40916bf7425821ed29e8cf405500387eaffe5129

Successful GitHub Actions results:

  • Existing Verify workflow: run 30288559207, job 90052332073.
  • Community Health Invariants: run 30288559466, job 90052333806.

The invariant job completed Validate shared community-health invariants successfully and emits COMMUNITY_HEALTH_INVARIANTS_PASS for the exact pull-request head.

No unresolved inline review threads were present at the final audit.

Remaining account-level gaps

  1. GitHub personal-profile rendering still requires a manually created public repository named exactly Riverbraid/Riverbraid with a non-empty root README.md. Issue Create the Riverbraid personal profile README repository #6 records the prepared source text and verification steps.
  2. Private vulnerability reporting, branch/ruleset protections, secret scanning, push protection, Dependabot, CodeQL, and related repository settings remain manual confirmations tracked in Riverbraid-Documentation#19.
  3. CODEOWNERS remains intentionally deferred until real additional maintainers, review capacity, fallback behavior, and required-review settings exist.

Boundary

This PR remains draft and unmerged.

It does not create a repository, convert the account, appoint maintainers, activate CODEOWNERS, configure repository settings, mutate registry pins, alter releases or tags, redefine protocol authority, upload or adopt the F0–F4 control package, or advance P0, F0, F1, F2, F3, or F4.

It establishes only a mechanically checked public governance and community-health candidate for this exact branch. It does not establish certification, production readiness, independent reproduction, external audit, profile-rendering completion, account-wide inheritance enforcement, account-wide support, full-constellation operation, or absence of defects.

@Riverbraid Riverbraid changed the title Tighten public entry and evaluation claim boundaries Correct user-account public entry and profile boundaries Jul 27, 2026
@Riverbraid Riverbraid changed the title Correct user-account public entry and profile boundaries Complete user-account public entry and governance boundaries Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant