docs: make BandScope public surface rehearsal-first and license-aware - #1125
docs: make BandScope public surface rehearsal-first and license-aware#1125seonghobae wants to merge 7 commits into
Conversation
|
Warning Review limit reachedNext included review available in 46 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| - If that private repository feature is unavailable to you, contact the | ||
| ContextualWisdomLab repository maintainers through an established private | ||
| channel. Do not substitute a public issue, pull-request comment, or discussion. |
Zero-trust release lane note (touhidzaman007)Unresolved Devin thread on SECURITY.md remains valid: private fallback still says "established private channel" with no address/form/channel. Authoritative sources checked:
Status: SECURITY_CONTACT_BLOCKED — will not invent a contact. Need owner-provided canonical private reporting destination, then re-run exact-head proof / merge gate. |
Summary
Turn BandScope's public repository surface into a rehearsal-first, product-facing entry point without changing runtime behavior or competing with current feature, MIR, supply-chain, Figma, or workspace writers.
docs/index.mdlanding source;song → section → role, visible confidence, editable analysis, local-first operation, and rehearsal outputs rather than leading with repository/security internals;soundfile>=0.13.1is BSD-3-Clause at the Python wrapper, but its documented platform-wheel/runtime path relies on and can bundle LGPL libsndfile. Issue licensing: replace bundled libsndfile LGPL runtime path #1129 owns replacement/removal; the public README and landing do not present the current analysis stack as fully compliant with ContextualWisdomLab's commercial inbound-license baseline.Review repairs
Current README review findings are addressed on exact head
53e4bbb33e4d02e5290369ffe18b6f6505368272:docs/workflow/github-bootstrap-execution-policy.mdreference is restored, so the README remains compatible with the repository's documentation/bootstrap quickcheck contract;package.jsonruntime floor/ceiling: Node>=22.13 <23and npm10.9.9rather than a vague Node/npm prerequisite;All currently returned inline review threads are resolved after these repairs. Any new finding must be evaluated against the unchanged current head before integration.
Evidence used
The rewrite was checked against:
docs/brand-story.mdfor audience, one-line promise, rehearsal-first UX, confidence language, and anti-DAW/anti-authority positioning;ARCHITECTURE.mdforsong → section → role, local-first boundaries, shared contracts, security/supply-chain ownership, and cross-platform verification;package.jsonfor exact Node/npm runtime requirements and the quickcheck/docs gates;services/analysis-engine/pyproject.tomlfor the current Python floor and runtime dependency set;LICENSEfor the MIT project grant;No notation-grade transcription, analysis accuracy, customer, certification, deployment, adoption, or commercial-readiness claim was invented.
Licensing due diligence
The root MIT license is preserved as the grant for BandScope-owned source. It is not used to relabel third-party native code or model artifacts. The SoundFile/libsndfile distinction is treated as an executable dependency-chain issue rather than checking only the top-level Python package metadata.
Issue #1129 requires an actual commercially approved replacement/removal with equivalent real-audio behavior and mandatory Windows/macOS evidence. Suppressing SBOM entries, choosing another LGPL build, or moving the dependency across a process/container boundary does not close it.
Coordination
This remains the existing public repository surface lane. No duplicate README PR was created. The branch is based on protected
developand ownsREADME.mdplusdocs/index.md; runtime/dependency replacement work stays outside this documentation branch and is tracked by #1129.Current authority
Protected base for this PR remains
develop@749511c3ad4000090048718f685c6bee6b3d2c25; exact current head is53e4bbb33e4d02e5290369ffe18b6f6505368272.Fresh exact-head repository workflows—including CI, security audit, Security Scan, SAST, SBOM, build-baseline, release, Bandit, and secret scanning—are newly queued after the review repair and are therefore non-passing until terminal. Predecessor-head results do not transfer. Mergeability, exact base, review threads, and then-live governance must be re-read before integration.
Verification boundary
GitHub Pages is complete only after this source integrates through protected
develop, the intended Pages configuration is enabled through organization-owned governance, and the resulting public HTTPS URL/content is re-read successfully.Exact-current protected CI, security, SAST, SBOM, coverage, cross-platform build, review/thread, and governance evidence remains authoritative. Documentation source alone is not a release or commercial-readiness receipt.