Current accepted topology
The Context Fabric program has converged on main as the intended protected integration/default branch for both ContextualWisdomLab/context-graph-contracts and ContextualWisdomLab/enterprise-architecture-core. Historical guidance that kept develop as the long-term default/integration branch is superseded.
Fresh 2026-09-01 repository evidence:
context-graph-contracts
- repository
default_branch=develop;
develop@99cb5468ba3c15c5e79688f53dee74724fae2d13, reported protected;
main@99cb5468ba3c15c5e79688f53dee74724fae2d13, unprotected;
- current root/stack PRs explicitly require eventual protected
main integration and prohibit merging the stack through the obsolete develop integration model;
- no GitHub release exists yet.
enterprise-architecture-core
- repository
default_branch=develop;
develop@1c0fa8b15ceb9e72186274aeb255d6777eb84ef4, reported protected;
main@ca6889497728e1a3f09d68790a9096576e13a3ff is the active product line but is not the default/protected integration authority;
- current root/stack PRs explicitly require eventual protected
main integration and treat the historical main -> develop synchronization lane as superseded;
- no GitHub release exists yet.
Organization ruleset 18156473 targets ~DEFAULT_BRANCH. While repository metadata still names develop, the organization rule therefore follows the wrong long-term integration ref. This is a central control-plane defect, not a product-repository decision and not a reason to weaken release contracts.
Required safe transition
Execute in this order for each Context Fabric repository, refetching live state between every step:
- Pre-protect
main first. Apply the intended integration/release-grade controls to main before changing default metadata. Preserve deterministic required workflows/security/coverage/package/SBOM/provenance/thread-resolution/deletion/non-fast-forward controls and prohibit routine bypass.
- Preserve transition protection on
develop only as needed. Do not create a window where either integration candidate is unprotected while stacks are being reconstructed.
- Change repository default branch to
main only after its effective protection is proven.
- Re-read organization/repository rulesets after the switch. Verify
~DEFAULT_BRANCH now resolves to main and that no required control silently fell away.
- Rebuild Context Fabric stacks dependency-first from fresh protected
main. No predecessor-head review/check/package/provenance evidence transfers across base/default movement.
- Reacquire exact-head gates under the new topology. Merge through ordinary protected governance only when the unchanged candidate satisfies then-live policy.
- Release only from an exact protected integrated
main SHA. Version, package, SBOM, provenance, reproducibility, conformance/admission and release metadata must identify the same immutable source/artifact set.
Interaction with solo-maintainer review governance
.github#772 independently owns the scoped removal/replacement of the structurally impossible generic approving-review-count rule for the current solo-maintainer organization. Self-approval remains forbidden and bot/model output is not human approval. This issue must not wait for fictional reviewer provisioning; branch topology and deterministic protection are executable central governance work.
RED acceptance
- Accepted integration/default intent is
main.
- Repository metadata still says
develop.
- Organization ruleset
18156473 follows ~DEFAULT_BRANCH, therefore follows develop.
main is not yet the coherent protected default integration authority.
- Context Fabric PR stacks cannot safely integrate/release without either using the obsolete topology or targeting an unprotected branch.
GREEN acceptance
For both Context Fabric repositories:
main has integration/release-grade effective protection before the default switch;
- repository
default_branch=main;
~DEFAULT_BRANCH organization rules resolve to main and required deterministic controls remain enforced;
- any temporary
develop transition protection is explicit and may later be retired without weakening main;
- root PRs are rebuilt against fresh protected
main, descendants are restacked dependency-first, and all moved heads reacquire exact-current-head checks/reviews/artifacts;
- a protected-main post-integration workflow run proves repository CI/package/security evidence on the resulting exact merge SHA;
- no routine administrator bypass or stale/predecessor evidence is used.
Non-goals
- Retargeting current stacks to unprotected
main before protection exists.
- Merging through
develop merely because it is currently default.
- Recreating obsolete
main -> develop synchronization work.
- Weakening deterministic gates during migration.
- Treating open Context Graph/EA PR heads as released production contracts.
Current accepted topology
The Context Fabric program has converged on
mainas the intended protected integration/default branch for bothContextualWisdomLab/context-graph-contractsandContextualWisdomLab/enterprise-architecture-core. Historical guidance that keptdevelopas the long-term default/integration branch is superseded.Fresh 2026-09-01 repository evidence:
context-graph-contracts
default_branch=develop;develop@99cb5468ba3c15c5e79688f53dee74724fae2d13, reported protected;main@99cb5468ba3c15c5e79688f53dee74724fae2d13, unprotected;mainintegration and prohibit merging the stack through the obsoletedevelopintegration model;enterprise-architecture-core
default_branch=develop;develop@1c0fa8b15ceb9e72186274aeb255d6777eb84ef4, reported protected;main@ca6889497728e1a3f09d68790a9096576e13a3ffis the active product line but is not the default/protected integration authority;mainintegration and treat the historicalmain -> developsynchronization lane as superseded;Organization ruleset
18156473targets~DEFAULT_BRANCH. While repository metadata still namesdevelop, the organization rule therefore follows the wrong long-term integration ref. This is a central control-plane defect, not a product-repository decision and not a reason to weaken release contracts.Required safe transition
Execute in this order for each Context Fabric repository, refetching live state between every step:
mainfirst. Apply the intended integration/release-grade controls tomainbefore changing default metadata. Preserve deterministic required workflows/security/coverage/package/SBOM/provenance/thread-resolution/deletion/non-fast-forward controls and prohibit routine bypass.developonly as needed. Do not create a window where either integration candidate is unprotected while stacks are being reconstructed.mainonly after its effective protection is proven.~DEFAULT_BRANCHnow resolves tomainand that no required control silently fell away.main. No predecessor-head review/check/package/provenance evidence transfers across base/default movement.mainSHA. Version, package, SBOM, provenance, reproducibility, conformance/admission and release metadata must identify the same immutable source/artifact set.Interaction with solo-maintainer review governance
.github#772independently owns the scoped removal/replacement of the structurally impossible generic approving-review-count rule for the current solo-maintainer organization. Self-approval remains forbidden and bot/model output is not human approval. This issue must not wait for fictional reviewer provisioning; branch topology and deterministic protection are executable central governance work.RED acceptance
main.develop.18156473follows~DEFAULT_BRANCH, therefore followsdevelop.mainis not yet the coherent protected default integration authority.GREEN acceptance
For both Context Fabric repositories:
mainhas integration/release-grade effective protection before the default switch;default_branch=main;~DEFAULT_BRANCHorganization rules resolve tomainand required deterministic controls remain enforced;developtransition protection is explicit and may later be retired without weakeningmain;main, descendants are restacked dependency-first, and all moved heads reacquire exact-current-head checks/reviews/artifacts;Non-goals
mainbefore protection exists.developmerely because it is currently default.main -> developsynchronization work.