Skip to content

ci: enforce vendor-neutral public PR metadata - #419

Merged
masarray merged 1 commit into
mainfrom
maintenance/public-metadata-neutrality-guard-20260926
Sep 26, 2026
Merged

masarray merged 1 commit into
mainfrom
maintenance/public-metadata-neutrality-guard-20260926

Conversation

@masarray

Copy link
Copy Markdown
Owner

Purpose

Protect public ARSAS PR titles and descriptions using the same one-way forbidden-identifier fingerprint matcher that already scans Git-tracked source, documentation, filenames, and CI. Public metadata is currently not covered by the tracked-file scan.

Changes

  • Check GITHUB_EVENT_PATH on pull_request events and reject restricted identifiers in the PR title or description, while failing closed on missing event metadata.
  • Add deterministic negative cases for the title and body, and a neutral positive case, without embedding any restricted product name in tracked files.
  • State that public PR titles, descriptions, comments and release notes use vendor-neutral wording without changing recorded measurement values.
  • Retain the existing hash-based content/path gate, clean-room restrictions, licensing/CLA, and physical/engine provenance.

Scope and acceptance

Exactly 3 files: scripts/verify-source-clean.ps1, scripts/test-source-clean-guard.ps1, CONTRIBUTING.md. Base 7ef6cadaaa15fb47dc234fe9519bbdb0163a8036. No IEC 61850 runtime, engine, lock, release, tag or firmware change.

Run the full Windows Build ARSAS workflow on exact PR head and verify the new negative/positive metadata fixtures. The published 1.6.37 release note is a separate metadata-edit task because the connected GitHub actions do not expose release updates; historical Git commit identities must not be rewritten to cosmetically remove archived words.

@masarray
masarray marked this pull request as ready for review September 26, 2026 12:36
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@masarray
masarray merged commit b897203 into main Sep 26, 2026
8 checks passed

Copy link
Copy Markdown
Owner Author

Final public-surface audit (2026-09-26, actual main SHA b897203fad3b9276492bd3f6220e6c86d14c59df):

  • GitHub code search for the restricted product identifier on the current default branch: 0 matches; the recursive current-main tree is complete (1,031 blobs), with 0 restricted path names.
  • Nine affected historical PR title/body records and three previously identified public discussion comments have been revised to vendor-neutral language while retaining test counts, file and commit references.
  • This PR adds the existing fingerprint-based rejection of restricted identifiers in new PR titles/descriptions. Exact-head CI 8/8 green, including source-clean negative/positive fixtures and 1,319/1,319 app tests.
  • Actual merged-main push CI 2/2 green: Build ARSAS (source/provenance fixtures, 1,319/1,319 app tests, portable package smoke) and Smart Discovery Post-Merge Production Verification (988/988 engine + 1,319/1,319 app tests).
  • Outstanding archival surfaces: a single auto-generated line in the v1.6.37 release description still contains the old external product label. The connected GitHub actions do not expose release-body editing and the browser edit attempt found no authenticated GitHub profile; the maintainer must update that single release-notes line manually without altering tag/assets. Existing historical Git commit messages also contain the old label; they are intentionally not rewritten because that would invalidate published commit/tag/release and field-evidence identity. Do not claim literal absence from all Git history.

No application/engine/reporting/Discovery code, release binary, tag or historical numeric measurement was changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant