Skip to content

20억 매각 readiness evidence 확보 #5

Description

@seonghobae

Current authority — 2026-09-07 KST

Historical objective NOEMA-GOAL-ACQUISITION-2B-2026-07-02 remains a product objective, not valuation evidence. Noema protected source is GitHub-verified main@0dec8d84b1e4744e7a9c6a77e2e2631a183ee2ab, the normal merge of trust-source prerequisite #554. Protected central .github/main is GitHub-verified c9052e607e5f3cc76e73207e7786b21500721b79.

There are 10 open Noema PRs and all remain Draft: #526, #535, #536, #540, #542, #543, #547, #548, #550 and #553. #539 and #554 are protected truth and are no longer open prerequisites.

Current source order is dependency/overlap aware rather than a single linear stack:

  1. feat(workflow): add atomic durable task claim and checkpoint CAS #542 exact 4616b5e93e19d51973aea330aa4124b51725b795 owns the P0 durable workflow state/checkpoint/recovery boundary on current protected ancestry. Application CI, reviewer-ci and required Security Scan are terminal success; patch-validator-image remains in progress, so it is not yet merge authority.
  2. fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 exact 2eba9d6b1e3365f745dd43bb8e40e87b0f2ead3a owns the direct pinned workerd/esbuild commercial toolchain repair. Application CI, reviewer-ci and Security Scan are terminal success; image remains in progress. It overlaps ci(actions): isolate pull request concurrency #550 on CI/image workflow paths, so any integration must preserve both deltas through ordinary non-force convergence.
  3. fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535 was freshly repaired test-first. Predecessor 9ec7fbb0a20fb771516682946d49a2755035c171 still accepted stale NOEMA_LLM_MODEL=contextual-orchestrator and silently normalized it to orchestrator/free. Test-only b07258e710797bfbc9b40bb5e0aac10a310ddc89 requires fail-closed rejection; production df85cf813f596faa99700f5cb2269e6fb349d592 removes legacy-alias normalization and requires the exact orchestrator/free contract while leaving provider/model discovery, routing, retry and failover with contextual-orchestrator. Its new exact-head workflow generation is non-terminal.
  4. feat(reviewer): extract shared noema-core package (ADR-0014) #536/fix(reviewer): bind failed checks to actionable source evidence #548 overlap fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535 in reviewer/shared-core paths and must be integrated semantically rather than by overwriting one another. Their current pre-integration heads retain terminal application/reviewer/Security success but image is still in progress.
  5. ci(actions): isolate pull request concurrency #550 exact 3ed5bd956c84e6dd2ebe604dc226fea82145ac29 owns work-conserving workflow concurrency/publication handoff; application CI, reviewer and Security are terminal success while image is in progress. It overlaps fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535 on hourly-product-development and fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 on CI/image workflow paths.
  6. test(ci): forbid docs-only required-gate suppression #543/docs: fix stale "active PR #80" references in automation-threat-model.md #553/fix(acquisition): bind commercial source records #526 are narrower lanes on current protected ancestry. Their application/reviewer/Security generations are terminal success where observed, with image evidence still non-terminal. fix(acquisition): bind commercial source records #526 also shares CHANGELOG with several product/config lanes and therefore requires semantic preservation on integration.
  7. docs: reconcile protected runtime and commercial gap authority #547 exact 9e60f0434f7855f5d4a112cf5614d3fa07c2c43c remains the sole cross-lane docs/product-technical-gap-baseline.md writer. Its application CI and reviewer are terminal success, Security is queued and image is in progress; it should reconcile final current candidate/protected identities rather than become a parallel source owner.

No predecessor GREEN transfers across head or ancestry movement. Current review-thread evidence must be reread immediately before each merge; a resolved/empty thread set is necessary but not sufficient.

No GitHub release has yet been established as immutable Noema publication evidence. Repository checks, PR-head artifacts, reviewer output, issue prose, or a product-goal title therefore do not prove immutable publication, deployment, production KPI, customer/revenue, legal transfer, or final acquisition readiness.

Goal

Build independently verifiable commercial/acquisition evidence without collapsing distinct authority classes. Production, immutable release, customer/revenue, rights/transfer, deployment, live governance and operating evidence must exist before the final gate can pass.

Current owner boundaries

Foreign-owner provider routing, quarantine/security implementation and outbound policy remain outside Noema. A missing external control blocks only its evidence lane and never justifies weakening source gates.

Fail-closed acquisition path

exact protected source
→ current central workflow-source binding
→ unchanged exact-head + independently resolved live-base CI/security/review/image evidence
→ normal protected integration
→ protected-main operational receipts
→ immutable SemVer release + package/image/SBOM/provenance identities
→ explicit owner/legal outbound-rights and transfer evidence
→ governed production deployment + rollback/recovery proof
→ >=30-day authenticated production KPI evidence
→ customer/revenue/support/operating-cost evidence where material
→ transfer/data-room integrity audit
→ acquisition final gate

An earlier stage never proves a later stage.

Completion criteria

  • Repository-owned governance observation/fail-closed audit logic exists on protected main.
  • Canonical documentation graph and machine-readable API contract exist on protected lineage.
  • Exact-source patch quarantine and patch-validator local image/runtime/supply-chain implementation exist on protected lineage.
  • Pilot/commercial readiness evidence fails closed on ambiguous/placeholder/local-only authority.
  • Immutable central-workflow OIDC source binding has been rolled to current central authority through normally merged fix(trust): roll audited central workflow source to c9052e6 #554 at protected main@0dec8d84....
  • Every still-required downstream source lane reaches one unchanged exact head with all applicable terminal gates and zero valid unresolved findings, then integrates normally with all overlapping valid deltas preserved.
  • chore(governance): protect main and enforce release checks #27 proves/enforces stronger target governance or an accepted owner decision supersedes it.
  • chore(operations): provision and activate hourly maintainer App #29/[Fleet incident] Activate dedicated publication identity for the orchestrator-backed hourly loop #227 prove real independent Reviewer/Maintainer/publication identities and least-privilege installation state.
  • npm run readiness:audit passes on one exact integrated protected head with real required evidence.
  • Execute the patch-validator workflow from protected main and retain exact run/artifact identities.
  • Create immutable SemVer release/publication evidence bound to exact source/tag/artifact digests and bind SBOM, dependency-license inventory, NOTICE/attribution and provenance.
  • Obtain explicit owner/legal outbound-rights and contributor/IP transfer evidence; automation does not choose the outbound license.
  • chore(governance): configure protected production environment #40 proves protected production-environment governance and deploys the exact immutable release with rollback/recovery evidence.
  • Noema 판매 가능 목표: 30일 운영 KPI 로그 및 provenance 확보 #3 supplies >=30-day authenticated production evidence meeting the protected KPI contract.
  • Bind customer/pilot, revenue/pipeline, support ownership and operating-cost evidence to authenticated records where material.
  • Every required data-room entry resolves to exact retained bytes or authenticated external-evidence receipts.
  • NOEMA_RELEASE_UNDER_DILIGENCE_TAG=<tag> npm run acquisition:audit passes reproducibly against the immutable release under diligence.

Pending, queued, in-progress, stale, predecessor, synthetic, status-only, model-only or manually edited evidence never substitutes for the current authoritative class.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions