Skip to content

[WP02 · SubStep 02.05] Enforce desktop dependency admission and upgrade evidence - #9

Merged
deku2026 merged 3 commits into
mainfrom
wp02-05-dependency-policy
Sep 22, 2026
Merged

deku2026 merged 3 commits into
mainfrom
wp02-05-dependency-policy

Conversation

@deku2026

@deku2026 deku2026 commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

The desktop consumer now refuses unadmitted or floating dependencies, forbidden licences, internal Contracts and wrong publisher/feed identities. The owner policy closes all 91 existing NuGet package-version identities using committed locks and cached published metadata, while a reviewed input record requires scoped upgrade evidence and framework-major runtime assessment. Historical Git admissions prevent new reviews from changing bytes under an existing version.

The gate runs in the existing repository check and writes retained CI evidence. Exact dependency versions, product behavior, current Windows/Linux CI and publication mechanisms are unchanged.

Validation: cache-only locked restore, targeted C# build (zero warnings/errors), 12 offline dependency-policy cases, repository/provenance/effective declaration check, and whitespace review passed. No local runtime, public artifact downloads or toolchain provisioning were performed. Required CI remains the merge gate.

@deku2026
deku2026 merged commit 268c329 into main Sep 22, 2026
11 checks passed
@deku2026
deku2026 deleted the wp02-05-dependency-policy branch September 22, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant