Skip to content

docs: make BandScope public surface rehearsal-first and license-aware - #1125

Open
seonghobae wants to merge 7 commits into
developfrom
docs/public-repository-surface-20260902
Open

docs: make BandScope public surface rehearsal-first and license-aware#1125
seonghobae wants to merge 7 commits into
developfrom
docs/public-repository-surface-20260902

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Turn BandScope's public repository surface into a rehearsal-first, product-facing entry point without changing runtime behavior or competing with current feature, MIR, supply-chain, Figma, or workspace writers.

  • keep one exact Ask DeepWiki badge and the public docs/index.md landing source;
  • rewrite the README around the brand-source promise: help time-constrained band players understand what to play, when to enter, what to simplify, and what to verify before rehearsal;
  • organize value around song → section → role, visible confidence, editable analysis, local-first operation, and rehearsal outputs rather than leading with repository/security internals;
  • retain the truthful current workspace, setup, verification, architecture, security, dependency, SBOM, governance, GitHub-bootstrap, and cross-platform documentation paths;
  • preserve the existing repository MIT license and distinguish it from third-party/native/model licenses;
  • fail closed on a confirmed transitive commercial-policy defect: runtime soundfile>=0.13.1 is BSD-3-Clause at the Python wrapper, but its documented platform-wheel/runtime path relies on and can bundle LGPL libsndfile. Issue licensing: replace bundled libsndfile LGPL runtime path #1129 owns replacement/removal; the public README and landing do not present the current analysis stack as fully compliant with ContextualWisdomLab's commercial inbound-license baseline.

Review repairs

Current README review findings are addressed on exact head 53e4bbb33e4d02e5290369ffe18b6f6505368272:

  • the required docs/workflow/github-bootstrap-execution-policy.md reference is restored, so the README remains compatible with the repository's documentation/bootstrap quickcheck contract;
  • Quick start now states the exact package.json runtime floor/ceiling: Node >=22.13 <23 and npm 10.9.9 rather than a vague Node/npm prerequisite;
  • the earlier Pages-navigation finding remains resolved by durable GitHub URLs for root documents.

All currently returned inline review threads are resolved after these repairs. Any new finding must be evaluated against the unchanged current head before integration.

Evidence used

The rewrite was checked against:

  • docs/brand-story.md for audience, one-line promise, rehearsal-first UX, confidence language, and anti-DAW/anti-authority positioning;
  • ARCHITECTURE.md for song → section → role, local-first boundaries, shared contracts, security/supply-chain ownership, and cross-platform verification;
  • root package.json for exact Node/npm runtime requirements and the quickcheck/docs gates;
  • services/analysis-engine/pyproject.toml for the current Python floor and runtime dependency set;
  • root LICENSE for the MIT project grant;
  • current SoundFile 0.13.1 upstream documentation for the BSD wrapper versus LGPL libsndfile native runtime distinction.

No notation-grade transcription, analysis accuracy, customer, certification, deployment, adoption, or commercial-readiness claim was invented.

Licensing due diligence

The root MIT license is preserved as the grant for BandScope-owned source. It is not used to relabel third-party native code or model artifacts. The SoundFile/libsndfile distinction is treated as an executable dependency-chain issue rather than checking only the top-level Python package metadata.

Issue #1129 requires an actual commercially approved replacement/removal with equivalent real-audio behavior and mandatory Windows/macOS evidence. Suppressing SBOM entries, choosing another LGPL build, or moving the dependency across a process/container boundary does not close it.

Coordination

This remains the existing public repository surface lane. No duplicate README PR was created. The branch is based on protected develop and owns README.md plus docs/index.md; runtime/dependency replacement work stays outside this documentation branch and is tracked by #1129.

Current authority

Protected base for this PR remains develop@749511c3ad4000090048718f685c6bee6b3d2c25; exact current head is 53e4bbb33e4d02e5290369ffe18b6f6505368272.

Fresh exact-head repository workflows—including CI, security audit, Security Scan, SAST, SBOM, build-baseline, release, Bandit, and secret scanning—are newly queued after the review repair and are therefore non-passing until terminal. Predecessor-head results do not transfer. Mergeability, exact base, review threads, and then-live governance must be re-read before integration.

Verification boundary

GitHub Pages is complete only after this source integrates through protected develop, the intended Pages configuration is enabled through organization-owned governance, and the resulting public HTTPS URL/content is re-read successfully.

Exact-current protected CI, security, SAST, SBOM, coverage, cross-platform build, review/thread, and governance evidence remains authoritative. Documentation source alone is not a release or commercial-readiness receipt.

@seonghobae seonghobae added the documentation Improvements or additions to documentation label Sep 1, 2026 — with ChatGPT Codex Connector
devin-ai-integration[bot]

This comment was marked as resolved.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 6bf0af93-0ed3-45fd-8ff1-48d03de04aaf

📥 Commits

Reviewing files that changed from the base of the PR and between 749511c and 145020e.

📒 Files selected for processing (3)
  • README.md
  • SECURITY.md
  • docs/index.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks labels Sep 1, 2026 — with ChatGPT Codex Connector
@seonghobae seonghobae changed the title docs: add public Pages landing and DeepWiki badge docs: make BandScope public surface rehearsal-first and license-aware Sep 1, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae added the status: blocked Blocked by conflict, dependency, or required prerequisite label Sep 2, 2026 — with ChatGPT Codex Connector
@seonghobae seonghobae removed the status: needs-review Open pull request requiring current-head review or checks label Sep 2, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Devin Review

Comment thread SECURITY.md
Comment on lines +13 to +15
- If that private repository feature is unavailable to you, contact the
ContextualWisdomLab repository maintainers through an established private
channel. Do not substitute a public issue, pull-request comment, or discussion.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Private fallback lacks a destination

When GitHub private reporting is unavailable, established private channel names no address, form, or channel. Reporters cannot find the fallback destination.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@touhidzaman007

Copy link
Copy Markdown

Zero-trust release lane note (touhidzaman007)

Unresolved Devin thread on SECURITY.md remains valid: private fallback still says "established private channel" with no address/form/channel.

Authoritative sources checked:

  • PR head SECURITY.md
  • origin/develop SECURITY.md (contains seonghobae@example.com placeholder — not usable)
  • Org ContextualWisdomLab/.github/SECURITY.md ("email the lab maintainers directly" — no address)

Status: SECURITY_CONTACT_BLOCKED — will not invent a contact. Need owner-provided canonical private reporting destination, then re-run exact-head proof / merge gate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: docs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants