You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Carrying WORKFLOW.md sections 3 and 5 into workflow-ci-contract (#1392) ran four whole-unit carried-content passes and two diff passes over 12 units. Eight findings were introduced by that change and fixed in it. The rest are pre-existing and were deliberately left alone, since pull requests 2, 3, 4, and 6 of the #1311 sequence own the text they sit in. This issue is where they wait, so a later round does not have to re-derive them.
Sections 3 and 5 are now read whole by every repository carrying the skill, which is what makes several of these worth more than they were.
WORKFLOW.md section 3
"Which changes those are is stated as a shape rather than a line count in GOVERNANCE.md "Operational Repositories", which owns the test and is the one place it is written." The pointer is wrong in both halves. That section carries only "a PR still exists for a change worth reviewing" and then defers, and the shape-not-line-count test is written in operational-vs-release-workflow's SKILL.md.
"the App" is a definite reference with no antecedent. Its first occurrence in the document is the Release Model paragraph, and D8.4 and S6 inherit the same undefined referent, so a reader cannot check what github.actor is compared against.
Resource Lifecycle's "An intermediate consumed only within the same run may rely on the retention backstop alone" swallows the rule it follows. Every workflow artifact is run-scoped, so the exception describes exactly the cross-job artifacts the delete-at-consumption rule governs. D5.1 repeats the phrasing, so both need the same fix.
"the registry" is named as the authority for workflowModel and releaseTrigger and never located. It is registry/repos.json, hub-hosted rather than carried, so a reader in a carrying repository cannot look up either field.
Validate-at-Entry's "assert it once in a dedicated entry job/step the downstream jobs needs:" fails when followed literally, since needs: takes job ids and a downstream job cannot needs: a step.
The section states the same classification rule once portably ("The default branch is the public-release ref") and once with the literal main ("a main-only weekly schedule", "The push is main-only"), with nothing saying which sentences are literal.
build-<target> is stated as universal while the section's own Seam Contract diagram names the .NET leaf dotnet-publish, which is what the tree ships. The naming convention has an existing exception the prose does not admit.
"The registered trusted-publishing policy therefore names the publisher, publish-release.yml." reads as an observed fact about the reader's repository rather than the obligation it is, so a reader who has the failure this paragraph prevents finds a sentence that appears already true of them.
"The run is never blanket-deleted (.artifacts[].id)." leaves the parenthetical unexplained, so a reader cannot tell whether it names a forbidden jq expression, an API field, or an example.
WORKFLOW.md section 5
S11 states merge-bot auto-merge as the required output, contradicting the same unit's 5A D8/D9 item and D8.3, which make auto-merge: false a conforming wrapper shape. The scenario is applicable to such a repository, so its predicted-versus-expected diff records a defect against a conforming pipeline.
5C's fence covers only a probe that "dispatches a workflow or re-runs a real publish", so its first bullet, "Open a trivial-change PR touching one target and confirm S1", instructs an agent to make an outward-facing write on the repository it is auditing. Assessment step 3 has the same gap for the deploy ref gate, the one probe 5C says the agent must not fire. The fence belongs once, as a property of every 5C probe.
The two record-the-verdict instructions spell the token N-A while the rest of the document and AUDIT.md spell it N/A, including a sentence three lines above the first one.
Assessment step 1's "Record pass/fail/N-A with file:line" drops 5A's own carve-out for evidence that is a repository setting rather than a file, which 5A then requires for the branch ruleset and for the Actions and Dependabot secret names.
5C's GOVERNANCE.md citation is the document's one unbackticked filename.
S1 and S4's "validate-release skipped (smoke), succeeds" reads as one job both skipped and successful. D2.2 exists to disambiguate it, and the table cites D2.2 only as a guarantee the scenario exercises, never as the gloss the cell needs.
WORKFLOW.md section 6
The buildcache bullet's "a per-branch registry buildcache (buildcache-<branch>; a multi-image repo adds a per-image tag)" drops the <repo>: half that makes GOVERNANCE.md's wording correct. The per-image differentiator is the cache repository, not the tag. D9.4 carries the same compression, so both move together.
The add-a-target bullet is unfollowable for a repository that calls the hub-hosted release task, since that task declares a closed input set and a caller cannot add an enable_library input or a build-library job to a workflow it does not own. The source-only bullet eleven lines later states the split correctly.
"the NBGV get-version step" names a job. The distinction is load-bearing under the naming rule requiring a job name: to end "job" and a step name: to end "step".
The operational bullet's "S1 applies to every PR" is unqualified, while S1's own row takes a build target as its input and an operational repository has none. The source-only and static-site bullets both qualify it.
"Section 3's package-registry seam" names no subsection that exists. Section 3 has The Seam Contract and Output Seam by Destination, and section 1 cites the latter precisely.
skill-lifecycle, "The Doc-Packaging Pattern"
"The section ends with the standard pointer sentence: ..." is wrong twice. The fleet's formula is three sentences rather than one, with a closing sentence that varies per section, so an author following this literally writes a pointer matching no section in the tree. And "ends with" is false for at least three of the pairings, where the pointer sits mid-section with subsections after it.
The moved-content list omits operational-vs-release-workflow, the fleet's largest such pairing and its only example of one skill packaging more than one section.
docs/fleet-map.md's P2 rollout checkbox describes the two-split shape G9 actually delivered, while the G9 Resolution bullet two hundred lines earlier now describes the current three-include shape. Updating the checkbox would misreport what that phase shipped, so the two were left disagreeing. Worth a decision on whether a closed checkbox tracks delivery or current state.
scripts/canonical_review.py has no prune, and its ledger says it is "written by scripts/canonical_review.py record, never by hand", so the five entries Carry WORKFLOW.md Sections 3 and 5 Into workflow-ci-contract as Generated Includes #1392 orphaned stay and report renders them. The designed behavior is to leave the call to a reader, and there is no supported way for that reader to act on it.
Carrying
WORKFLOW.mdsections 3 and 5 intoworkflow-ci-contract(#1392) ran four whole-unit carried-content passes and two diff passes over 12 units. Eight findings were introduced by that change and fixed in it. The rest are pre-existing and were deliberately left alone, since pull requests 2, 3, 4, and 6 of the #1311 sequence own the text they sit in. This issue is where they wait, so a later round does not have to re-derive them.Sections 3 and 5 are now read whole by every repository carrying the skill, which is what makes several of these worth more than they were.
WORKFLOW.mdsection 3GOVERNANCE.md"Operational Repositories", which owns the test and is the one place it is written." The pointer is wrong in both halves. That section carries only "a PR still exists for a change worth reviewing" and then defers, and the shape-not-line-count test is written inoperational-vs-release-workflow'sSKILL.md.github.actoris compared against.workflowModelandreleaseTriggerand never located. It isregistry/repos.json, hub-hosted rather than carried, so a reader in a carrying repository cannot look up either field.needs:" fails when followed literally, sinceneeds:takes job ids and a downstream job cannotneeds:a step.main("a main-only weekly schedule", "Thepushis main-only"), with nothing saying which sentences are literal.build-<target>is stated as universal while the section's own Seam Contract diagram names the .NET leafdotnet-publish, which is what the tree ships. The naming convention has an existing exception the prose does not admit.publish-release.yml." reads as an observed fact about the reader's repository rather than the obligation it is, so a reader who has the failure this paragraph prevents finds a sentence that appears already true of them..artifacts[].id)." leaves the parenthetical unexplained, so a reader cannot tell whether it names a forbidden jq expression, an API field, or an example.WORKFLOW.mdsection 5auto-merge: falsea conforming wrapper shape. The scenario is applicable to such a repository, so its predicted-versus-expected diff records a defect against a conforming pipeline.N-Awhile the rest of the document andAUDIT.mdspell itN/A, including a sentence three lines above the first one.file:line" drops 5A's own carve-out for evidence that is a repository setting rather than a file, which 5A then requires for the branch ruleset and for the Actions and Dependabot secret names.GOVERNANCE.mdcitation is the document's one unbackticked filename.WORKFLOW.mdsection 6buildcache-<branch>; a multi-image repo adds a per-image tag)" drops the<repo>:half that makesGOVERNANCE.md's wording correct. The per-image differentiator is the cache repository, not the tag. D9.4 carries the same compression, so both move together.enable_libraryinput or abuild-libraryjob to a workflow it does not own. The source-only bullet eleven lines later states the split correctly.get-versionstep" names a job. The distinction is load-bearing under the naming rule requiring a jobname:to end "job" and a stepname:to end "step".The Seam ContractandOutput Seam by Destination, and section 1 cites the latter precisely.skill-lifecycle, "The Doc-Packaging Pattern"operational-vs-release-workflow, the fleet's largest such pairing and its only example of one skill packaging more than one section.Declined in #1392, recorded here rather than lost
docs/fleet-map.md's P2 rollout checkbox describes the two-split shape G9 actually delivered, while the G9 Resolution bullet two hundred lines earlier now describes the current three-include shape. Updating the checkbox would misreport what that phase shipped, so the two were left disagreeing. Worth a decision on whether a closed checkbox tracks delivery or current state.scripts/canonical_review.pyhas no prune, and its ledger says it is "written byscripts/canonical_review.py record, never by hand", so the five entries Carry WORKFLOW.md Sections 3 and 5 Into workflow-ci-contract as Generated Includes #1392 orphaned stay andreportrenders them. The designed behavior is to leave the call to a reader, and there is no supported way for that reader to act on it.