Skip to content

Close Secure Development Assurance v0.1.3 field test - #171

Merged
hindermath merged 7 commits into
mainfrom
codex/assurance-v013-field-test-closeout
Sep 8, 2026
Merged

Close Secure Development Assurance v0.1.3 field test#171
hindermath merged 7 commits into
mainfrom
codex/assurance-v013-field-test-closeout

Conversation

@hindermath

Copy link
Copy Markdown
Owner

Zusammenfassung

  • dokumentiert den TuiVision-Feldtest des unveraenderten Presets secure-development-assurance-governance v0.1.3 mit der begrenzten Empfehlung ReleaseAccepted
  • revalidiert die getrennten RL-SE- und GSDB-Kontexte auf allen vier technischen Gates unter Bash und PowerShell
  • setzt die technische Jahreswiedervorlage auf 2027-09-08 sowie die regulatorische Scopepruefung auf 2026-12-31
  • dokumentiert C5, CRA und formale Produktkonformitaet fuer den aktuellen nichtkommerziellen Ausbildungs-/Beispielscope als N/A
  • haelt pilotAuthorization, projectAcceptance und generalRelease ausdruecklich Open

Lokale Evidence

  • exaktes 13-Preset-CheckOnly: Bash und PowerShell bestanden
  • preset list, preset info, Resolve des Evidence-Vertrags und specify check: bestanden
  • beide Kontexte: je vier Gate-Reviews pro Shell und beide Statuslaeufe Ready
  • Read-only-Nachweis: je Kontext 7/7 Roh-Hashes unveraendert
  • Vertrags-/Negativ-/LF-/CRLF-/BOM-/Shell-Paritaet: bestanden
  • acht generierte Agenten-/Command-Flaechen aus dem Tag-ZIP: bestanden
  • Komposition 13 -> Disable/Enable -> Remove -> gueltige 12 -> Reinstall 13: bestanden
  • unveraenderliches v0.1.3-ZIP: SHA-256 9023b442b4d82e25bee5a7fe9b73efb7f591a4f265f54061ae6e4a56b9b5c75f
  • Documentation Impact, Secret-Scan und Statistik-Paritaet: bestanden

Grenze

Keine Produkt-, API-, Runtime-, Dependency-, Paket-, Image- oder Testcode-Aenderung. Die zentrale v0.1.3-Preset-Abnahme wartet weiterhin auf github/spec-kit#4455 und die Zusammenfuehrung aller fuenf Projektberichte.

Copilot AI lite review requested due to automatic review settings September 8, 2026 14:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@hindermath

Copy link
Copy Markdown
Owner Author

Exact-head delivery evidence for d604f03ec13048e4415723c062cf5823bbecc07f:

  • immutable v0.1.3 ZIP SHA-256, exact 13-preset matrix in Bash/PowerShell, list/info/resolve/check: passed
  • two contexts, four gates each, Bash and PowerShell review/status: Ready; 7/7 raw hashes per context unchanged
  • preset contract/negative/LF/CRLF/BOM parity and eight generated agent/command surfaces: passed
  • isolated composition 13 -> disable/enable -> remove -> valid 12 -> immutable-tag reinstall to 13: passed
  • CI Build and Test: Ubuntu, macOS, Windows passed; each job executed restore, Release build, full solution tests including non-interactive example smoke tests, and DocFX
  • Maintenance TUI: Ubuntu, macOS, Windows passed; restore/build/tests/wrapper and maintenance regressions completed
  • DocFX Pages, Homogeneity, PowerShell Static Analysis, Security Supply Chain, Agent Secret Scan, Gitleaks, and Claude Code Review workflows: passed
  • no review threads or actionable review findings

The first CI attempt on head 9a2bf71 correctly detected stale RL-SE source hash EVD-038 after the approved regulatory-scope update. The remediation refreshed only that technical binding, its dependent matrix/receipt hashes, and old/new provenance; all 157 domain dispositions and human decisions remain unchanged. The exact-head rerun above is green.

pilotAuthorization, projectAcceptance, and generalRelease remain Open. The approved admin bypass is used only for the remaining formal reviewer requirement, not for any technical check.

@hindermath
hindermath merged commit a58c202 into main Sep 8, 2026
32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants