docs(provenance): make tracked asset inventory reviewable and CI-enforced - #404
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 51022eabdf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
|
|
||
| $fullPath = Join-Path $RepoRoot ($relative.Replace("/", [IO.Path]::DirectorySeparatorChar)) | ||
| $actualSize = (Get-Item -LiteralPath $fullPath).Length |
There was a problem hiding this comment.
Read asset sizes from Git blobs
When a Windows checkout uses core.autocrlf=true, the four LF-only tracked SVGs are materialized with CRLF and therefore have larger worktree lengths even though their Git blobs are unchanged; both Windows build/release workflows invoke this verifier through verify-source-clean.ps1, so this comparison rejects a clean checkout. Read the canonical size from Git instead (git cat-file -h defines -s as “show object size,” so git cat-file -s :$relative is suitable) to keep the gate deterministic across checkout settings.
AGENTS.md reference: AGENTS.md:L1-L3
Useful? React with 👍 / 👎.
Extend the existing asset provenance register from category counts to a per-file machine-readable manifest for every tracked visual/font asset in scope. Record path, Git blob SHA, byte size, exact duplicate deployment, and an explicit unresolved/review disposition without claiming legal clearance or originality.
Add
scripts/verify-asset-provenance-manifest.ps1and invoke it only in the normal source-clean path (not-ScanOnlyrejection fixtures). CI now fails if a tracked asset is added, removed, or changes bytes without the provenance manifest being updated, and validates duplicate relationships plus summary counts.Audited source snapshot:
61ad333c2f61784ee49fda04b47f036206265cbc; 67 tracked asset paths, 44 unique Git blobs, 23 exact duplicate groups. This is inventory/provenance hardening only. No runtime C#, engine lock, release tag/assets, Smart Discovery behavior, reporting, SCL, or physical evidence changes.