You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Wardnet is not production-ready on protected main@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub Releases remains empty. Protected #159 is current workflow-control truth; candidate PRs, Draft heads, predecessor checks, readiness endpoints and mutable sibling repositories are evidence only until one exact protected release identity satisfies the complete gate below.
[Security] Gate AI-agent package installs from untrusted llms.txt and web instructions #128 / PR feat(security): gate AI-agent artifact installation #129 Agent Artifact Admission — exact f6889079ce49b6f08865180dd6a1ffd8145a8192, mergeable but intentionally Draft. Exact CI 33904242427, job 101230630469, acquired a real Ubuntu 24.04 runner and failed deterministically at cargo fmt --check; tests and Clippy were skipped after the formatting failure. Exact Fuzz 33904242501 is terminal success; Security 33904242429, Semgrep 33904242491, and CodeQL 33904242556 remain non-passing while queued. GREEN requires formatting the source and reacquiring all exact-head gates; rerunning the unchanged failing head is not useful.
Live organization ruleset 18156473 still targets ~DEFAULT_BRANCH, requires one generic approving review with no named required reviewer/team, requires current-thread resolution and central OpenCode/merge-scheduler/Security/Strix/Semgrep/Noema/CodeQL workflows, blocks deletion/non-fast-forward, and exposes OrganizationAdmin/always bypass. Self-approval and bot/model-as-human approval remain forbidden.
.github#772 owns the solo-maintainer policy repair. The central owner plane must reconcile its live policy assertions without weakening deterministic workflow/security/coverage/SBOM/provenance/thread/branch-integrity gates. Ordinary approval deadlock, queued scanners, OpenCode/provider wait, failed tests or release dependency wait are not guarded-bypass authority.
Runner/workflow acquisition remains .github#712 owner work. runner_id=0, steps=[], pre-checkout queueing, coverage materialization failure and model-review current-head timeout are non-passing control-plane evidence, not permission for rerun storms, selector churn, no-op source commits or false GREEN.
Context Fabric / EA release boundary
context-graph-contracts remains a contract-only Shared Kernel and enterprise-architecture-core remains the EA Decision Plane. Both still use develop as live default at the current read, have open owner stacks and no immutable GitHub Release. Branch topology/default/protection repair stays with Context Fabric/central governance. Wardnet does not modify their source or PR state.
External capability artifact/admission/activation grammar remains context-graph-contracts#27 owner work; EA external-capability adoption/risk/provenance remains enterprise-architecture-core#45. Wardnet findings/verdicts stay Wardnet authority. EA may retain verified evidence references but must not promote malware_verdict, artifact_risk_score or individual incident findings to authoritative architecture facts.
Production definition
Close this issue only after every mandatory gap above is protected truth and one exact immutable protected release candidate simultaneously proves fail-closed auth/tenant/security boundaries; shared DNSBL/threat-feed lifecycle correctness; proven WAF/IDS and deployed attack behavior; PostgreSQL authority/RLS/transaction/recovery; bounded multi-replica admission/effects; Keyverse-backed identity and human approval; owned production statement/branch/edge coverage and public docs; dependency/SAST/container/attack gates; immutable package/image/SBOM/signature/provenance/reproducibility; deployment and measured rollback/roll-forward; OTel/SLO/incident/restore evidence; released/versioned external-owner contracts; exact-current review/thread/governance evidence; and zero valid unresolved findings.
Do not close because a document, active PR, feature-branch artifact, predecessor check or mutable foreign head reports readiness. Guarded bypass is limited to a fully proven gate-repair chicken-and-egg with all runnable deterministic evidence terminal GREEN; ordinary queued scanners, review/provider timeout, failed tests, approval wait and release dependency wait never qualify.
Current verdict — 2026-09-05
Wardnet is not production-ready on protected
main@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub Releases remains empty. Protected #159 is current workflow-control truth; candidate PRs, Draft heads, predecessor checks, readiness endpoints and mutable sibling repositories are evidence only until one exact protected release identity satisfies the complete gate below.Immediate P0/P1 convergence graph
f74ff25a321dfb1d7109719e2a1fc77e47dc4898, aligned with protected main. It fails closed before readiness when a non-loopback listener lacks a write-capable administrator credential. Re-read all current checks/reviews before integration; no predecessor evidence transfers after a head move.4775abc66e5350bdbf07ccefca74c10ddb03701a, aligned with protected main. The deterministic write-temp/rename fault seam remains the owner-correct replacement for permission-dependent test behavior. Re-read exact security/code-analysis/governance evidence before merge.f6889079ce49b6f08865180dd6a1ffd8145a8192, mergeable but intentionally Draft. Exact CI33904242427, job101230630469, acquired a real Ubuntu 24.04 runner and failed deterministically atcargo fmt --check; tests and Clippy were skipped after the formatting failure. Exact Fuzz33904242501is terminal success; Security33904242429, Semgrep33904242491, and CodeQL33904242556remain non-passing while queued. GREEN requires formatting the source and reacquiring all exact-head gates; rerunning the unchanged failing head is not useful.ba5dd624e50eec63efc453a54beb57cbe28295a9, intentionally Draft. The MISPto_idsplus attribute/Object lifecycle repair is retained. A later valid shared-feed finding is now tracked separately as security(feeds): reconcile DNSBL snapshot ownership on refresh #172: DNSBL snapshot material can survive a feed refresh because the shared reconciler reapsThreatIndicators but only upserts DNSBL rows. The corrected RED keeps the refresh snapshot non-empty while withdrawing the target key; shared production GREEN and the valid review thread remain pending.034815040bca40af2732cd0222c3799c1abcd503, non-force restacked on current fix(security): require affirmative MISP to_ids evidence #167ba5dd624.... It preserves MISP1/2/3 -> High/Medium/Lowsource semantics without duplicating security(feeds): reconcile DNSBL snapshot ownership on refresh #172's shared DNSBL lifecycle.d386d6f57e0c8de3e4839d6c61b593e41f9d7e20. Exact CI33907688502is terminal success; central security/code-analysis lanes remain non-passing while queued. Release-evidence child build(release): bind reviewed source to SBOM and provenance evidence #164 stays Draft until this prerequisite or a verified successor is protected truth.054c11aafe835e497d6149efb09f1ccdee9d03bd, canonical supporting-boundary owner. Consumer feature lanes must adopt it rather than create a competing environment/bootstrap authority.quarantine-sandbox-runtimerelease. Mutable Draft heads are development evidence only.Control-plane and governance
Live organization ruleset
18156473still targets~DEFAULT_BRANCH, requires one generic approving review with no named required reviewer/team, requires current-thread resolution and central OpenCode/merge-scheduler/Security/Strix/Semgrep/Noema/CodeQL workflows, blocks deletion/non-fast-forward, and exposesOrganizationAdmin/alwaysbypass. Self-approval and bot/model-as-human approval remain forbidden..github#772owns the solo-maintainer policy repair. The central owner plane must reconcile its live policy assertions without weakening deterministic workflow/security/coverage/SBOM/provenance/thread/branch-integrity gates. Ordinary approval deadlock, queued scanners, OpenCode/provider wait, failed tests or release dependency wait are not guarded-bypass authority.Runner/workflow acquisition remains
.github#712owner work.runner_id=0,steps=[], pre-checkout queueing, coverage materialization failure and model-review current-head timeout are non-passing control-plane evidence, not permission for rerun storms, selector churn, no-op source commits or false GREEN.Context Fabric / EA release boundary
context-graph-contractsremains a contract-only Shared Kernel andenterprise-architecture-coreremains the EA Decision Plane. Both still usedevelopas live default at the current read, have open owner stacks and no immutable GitHub Release. Branch topology/default/protection repair stays with Context Fabric/central governance. Wardnet does not modify their source or PR state.External capability artifact/admission/activation grammar remains
context-graph-contracts#27owner work; EA external-capability adoption/risk/provenance remainsenterprise-architecture-core#45. Wardnet findings/verdicts stay Wardnet authority. EA may retain verified evidence references but must not promotemalware_verdict,artifact_risk_scoreor individual incident findings to authoritative architecture facts.Production definition
Close this issue only after every mandatory gap above is protected truth and one exact immutable protected release candidate simultaneously proves fail-closed auth/tenant/security boundaries; shared DNSBL/threat-feed lifecycle correctness; proven WAF/IDS and deployed attack behavior; PostgreSQL authority/RLS/transaction/recovery; bounded multi-replica admission/effects; Keyverse-backed identity and human approval; owned production statement/branch/edge coverage and public docs; dependency/SAST/container/attack gates; immutable package/image/SBOM/signature/provenance/reproducibility; deployment and measured rollback/roll-forward; OTel/SLO/incident/restore evidence; released/versioned external-owner contracts; exact-current review/thread/governance evidence; and zero valid unresolved findings.
Do not close because a document, active PR, feature-branch artifact, predecessor check or mutable foreign head reports readiness. Guarded bypass is limited to a fully proven gate-repair chicken-and-egg with all runnable deterministic evidence terminal GREEN; ordinary queued scanners, review/provider timeout, failed tests, approval wait and release dependency wait never qualify.