Current effective governance
Protected main is exact 87c4daa1830bac5a5228b6036752ad5633232085 at this refresh and carries a valid GitHub signature. The effective default-branch merge authority is inherited organization ruleset 18156473, CWL Central required workflows, enforcement: active, targeting ~DEFAULT_BRANCH. The live ruleset payload was updated 2026-09-04T21:34:39.804+09:00.
The current pull-request rule requires:
required_approving_review_count: 1;
- stale-review dismissal after pushes;
- resolved review threads;
- extra approval for unattributed changes;
- no separate latest-push approval (
require_last_push_approval: false); and
- merge or squash integration methods.
The live required-workflow set is 7, all owned by ContextualWisdomLab/.github@refs/heads/main:
opencode-review.yml
pr-review-merge-scheduler.yml
security-scan.yml
strix.yml
sast-semgrep.yml
noema-review.yml
codeql-pr.yml
close-empty-pr.yml, scorecard-pr.yml, and osv-scanner-pr.yml are not in this exact ruleset payload; codeql-pr.yml is. Historical 6/9/10-workflow snapshots must not be carried forward after a ruleset change. The ruleset also prohibits deletion and non-fast-forward updates and exposes an OrganizationAdmin bypass; that capability is not routine merge authority for this writer.
Repository-native product gates
Protected-main repository-native CI remains separate product evidence under AGENTS.md: exact-head Python repository contracts, rustfmt, Rust tests, strict Clippy, rustdoc and independent exact production coverage must retain their own executable evidence. Applicable Manifest V3 Compatibility evidence remains separate as well.
Those repository-native product gates are not enumerated in the organization ruleset workflow array. Do not assume the central merge scheduler transitively substitutes for them without executable proof. Issue #279 separately owns safe docs-only heavy-lane partitioning; runner admission, path partitioning, central required workflows and product-source failures remain distinct causal classes.
Current blockers / owner paths
The generic one-approval requirement remains structurally incompatible with the documented solo-maintainer organization unless a genuinely independent eligible human authority exists. Central .github#772 remains the canonical repair owner: remove or replace only the impossible human-approval deadlock while preserving deterministic workflow/security/coverage/thread/branch-integrity gates, self-approval prohibition and routine bypass prohibition.
Issue #212 separately records the current MV3 sandbox-helper ownership gap: #43 proves the helper mechanics on its own leaf generation, while #148 proves that current sandbox-preserving consumer source fails closed under the unchanged protected workflow. Runner admission, workflow-source defects, human-approval governance and product-source failures remain separate causal classes.
Current exact-head OriginWeave PRs also expose a repeated central CodeQL dispatch/verdict handoff failure after successful leaf CI/Security/Semgrep. That control-plane recurrence is handed to ContextualWisdomLab/.github#712; an unavailable or unpublished central verdict remains incomplete evidence and must not be synthesized locally.
Acceptance
- Before every integration decision, re-read protected main, the live ruleset, exact PR head/base, formal reviews, unresolved threads, repository-native product gates, and all then-required central workflows.
- Never hard-code a historical workflow count or membership. Bind the decision to the current ruleset payload and its update time.
- A queued, skipped, cancelled, absent, predecessor, synthetic/status-only, model-only, author-only or wrong-head result is never passing evidence.
- Verify whether repository-native CI/exact owned-production coverage and applicable MV3 evidence are transitively enforced by the central scheduler; if not, repair governance centrally rather than weakening product evidence.
- Follow
.github#772 for the one-approval solo-maintainer deadlock. If the live approval count changes, validate that exact new rule rather than carrying the old value forward.
- Preserve deletion/non-fast-forward protection, resolved-thread enforcement, exact-head binding, self-approval prohibition and normal merge policy. Use bypass only under a separately proven emergency/chicken-and-egg governance policy, never for routine product integration.
Keep this issue open until the effective protected-main gate is both structurally satisfiable and demonstrably enforces the intended deterministic OriginWeave product/security evidence on unchanged exact heads.
Current effective governance
Protected
mainis exact87c4daa1830bac5a5228b6036752ad5633232085at this refresh and carries a valid GitHub signature. The effective default-branch merge authority is inherited organization ruleset18156473,CWL Central required workflows,enforcement: active, targeting~DEFAULT_BRANCH. The live ruleset payload was updated 2026-09-04T21:34:39.804+09:00.The current pull-request rule requires:
required_approving_review_count: 1;require_last_push_approval: false); andThe live required-workflow set is 7, all owned by
ContextualWisdomLab/.github@refs/heads/main:opencode-review.ymlpr-review-merge-scheduler.ymlsecurity-scan.ymlstrix.ymlsast-semgrep.ymlnoema-review.ymlcodeql-pr.ymlclose-empty-pr.yml,scorecard-pr.yml, andosv-scanner-pr.ymlare not in this exact ruleset payload;codeql-pr.ymlis. Historical 6/9/10-workflow snapshots must not be carried forward after a ruleset change. The ruleset also prohibits deletion and non-fast-forward updates and exposes an OrganizationAdmin bypass; that capability is not routine merge authority for this writer.Repository-native product gates
Protected-main repository-native CI remains separate product evidence under
AGENTS.md: exact-head Python repository contracts, rustfmt, Rust tests, strict Clippy, rustdoc and independent exact production coverage must retain their own executable evidence. Applicable Manifest V3 Compatibility evidence remains separate as well.Those repository-native product gates are not enumerated in the organization ruleset workflow array. Do not assume the central merge scheduler transitively substitutes for them without executable proof. Issue #279 separately owns safe docs-only heavy-lane partitioning; runner admission, path partitioning, central required workflows and product-source failures remain distinct causal classes.
Current blockers / owner paths
The generic one-approval requirement remains structurally incompatible with the documented solo-maintainer organization unless a genuinely independent eligible human authority exists. Central
.github#772remains the canonical repair owner: remove or replace only the impossible human-approval deadlock while preserving deterministic workflow/security/coverage/thread/branch-integrity gates, self-approval prohibition and routine bypass prohibition.Issue #212 separately records the current MV3 sandbox-helper ownership gap: #43 proves the helper mechanics on its own leaf generation, while #148 proves that current sandbox-preserving consumer source fails closed under the unchanged protected workflow. Runner admission, workflow-source defects, human-approval governance and product-source failures remain separate causal classes.
Current exact-head OriginWeave PRs also expose a repeated central CodeQL dispatch/verdict handoff failure after successful leaf CI/Security/Semgrep. That control-plane recurrence is handed to
ContextualWisdomLab/.github#712; an unavailable or unpublished central verdict remains incomplete evidence and must not be synthesized locally.Acceptance
.github#772for the one-approval solo-maintainer deadlock. If the live approval count changes, validate that exact new rule rather than carrying the old value forward.Keep this issue open until the effective protected-main gate is both structurally satisfiable and demonstrably enforces the intended deterministic OriginWeave product/security evidence on unchanged exact heads.