Skip to content

docs(licence-policy): A5 — scaffold-placeholder leak is NOT licence debt#140

Merged
hyperpolymath merged 1 commit into
mainfrom
licence-debt/policy-sync-a5
May 19, 2026
Merged

docs(licence-policy): A5 — scaffold-placeholder leak is NOT licence debt#140
hyperpolymath merged 1 commit into
mainfrom
licence-debt/policy-sync-a5

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Final step of the #3 campaign — the human SoT + machine mirror sync. Additive A5 (Rules 1–3 + A1–A4 unchanged): PLMP/PMLP sentinel = unsubstituted-scaffold leak (process bug, not licence debt); doubled suffix = same family (A3 refined). .machine_readable/licensing-policy.toml updated to match ([scaffold_placeholder], [guard] hard_fails_on/warns_on). Pairs with the rsr-template-repo guard PR. 🤖 Generated with Claude Code

Additive (Rules 1–3 + A1–A4 unchanged). Documents that
PLMP-/PMLP-1.0-or-later is an intentional scaffold placeholder
sentinel whose survival is an unsubstituted-scaffold leak (process
bug), not licence debt — and that PMPL-1.0-or-later-or-later is the
same scaffold-substituter family (A3 refined accordingly). Mirrors the
machine-readable licensing-policy.toml ([scaffold_placeholder], [debt]
note, [guard] hard_fails_on/warns_on) so humans + tools agree.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath merged commit 4aed5f8 into main May 19, 2026
13 of 15 checks passed
@hyperpolymath hyperpolymath deleted the licence-debt/policy-sync-a5 branch May 19, 2026 07:29
@github-actions
Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 101 issues detected

Severity Count
🔴 Critical 63
🟠 High 28
🟡 Medium 10

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in security-policy.yml",
    "type": "missing_workflow",
    "file": "security-policy.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance-reusable.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Python file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/a2ml-templates/state-scm-to-v2.py",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/a2ml/bindings/deno/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/lol/test/vitest.config.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/k9-svc/bindings/deno/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "believe_me undermines formal verification (1 occurrences, CWE-704)",
    "type": "believe_me",
    "file": "/home/runner/work/standards/standards/lol/src/abi/Locale.idr",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "critical"
  },
  {
    "reason": "Wildcard CORS -- restrict to specific origins or use env var (1 occurrences, CWE-942)",
    "type": "js_wildcard_cors",
    "file": "/home/runner/work/standards/standards/consent-aware-http/examples/reference-implementations/deno/aibdp_middleware.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant