fix: consolidate open-issue remediation and evidence gates - #320
Open
RafaelGorski wants to merge 19 commits into
Open
RafaelGorski wants to merge 19 commits into
RafaelGorski wants to merge 19 commits into
Conversation
- CHANGELOG.md: add missing [2.7.0] release-link definition - README.md: fix version badge 2.6.0 -> 2.7.0 - docs/docs.html: fix stale 2.6.0 version tokens (CSS/JS cache-bust, header/footer badges) -> 2.7.0 - docs/skills-health.*, srs-navigator package-lock.json: regenerated by the test runner to match current manifest versions - evals/tests/release-trains.test.mjs, evals/tests/release-preflight.test.mjs: update hardcoded v2.6 fixture tag to v2.7 to match the manifest's current version - evals/tests/distribution-drift.test.mjs: the 'holds for the links this repository ships today' test now builds its own summarize() call with the real, current release history (v2.6, v2.7) instead of the shared PUBLISHED_RELEASES fixture (frozen at the v2.4.1 era), which was causing the real CHANGELOG's [2.6.0] link to be falsely flagged as stranded. Other tests in the file keep the original shared fixture since they exercise synthetic version scenarios unrelated to the real repo state. Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1299/1299 passing (Plugin validation 1/1, Canvas extension 307/307, Skill evals 950/950, Canvas e2e 41/41). node scripts/check-distribution.mjs now reports only the pre-existing, third-party registry-listing-drift finding (requires re-submission at skills.sh, outside this repo's control). Addresses the failing-test findings from issue #227 (daily-eval digest). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
docs/assets/site.css: .skip-link foreground changed from --ink-heading (2.39:1 on --primary, below WCAG AA 4.5:1) to --on-primary (near-white, ~7.5:1 on --primary), matching the fix already used for .btn-primary and .learn-action.is-primary. Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1299/1299 passing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
docs/docs.html's 'Start in three steps' quick-start presented /live as
step 3 right after only installing the skills, contradicting README.md
('the SRS Navigator canvas app... installed separately from the
skills'). A first-time reader following only the quick-start would hit
a missing-canvas dead end at step 3. Step 03 now names the canvas as a
separate install, matching README.
Adds evals/tests/onboarding-parity.test.mjs as a drift guard (negative-
tested: reverting the docs.html wording makes it fail).
Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1301/1301 passing.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
#1 HIGH - command injection via unescaped github.ref_name/default_branch in shell run: blocks. Fixed in all 4 affected workflows plus the two additional inline occurrences of the same pattern: - .github/workflows/create-release.yml (branch guard + asset-verify summary line) - .github/workflows/release-canvas.yml (branch guard + asset-verify summary line) - .github/workflows/thursday-release.yml (branch guard) - .github/workflows/thursday-release-report.yml (branch guard) All now pass the GitHub Actions context values through env: and reference them as shell variables instead of interpolating the expression directly into run:. #2 LOW - package.json/package-lock.json version mismatch: already resolved (both now report 1.1.4). #3 (optional hardening - pin Actions to commit SHAs) intentionally deferred: correctly resolving 30 tag references to verified commit SHAs needs each SHA looked up and confirmed against the upstream repo, not guessed; doing that without verification risks a worse outcome (a wrong pin silently breaking releases) than the current low- confidence (5/10), non-exploit finding it addresses. Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1301/1301 passing; all 4 edited workflow files parse as valid YAML (python yaml.safe_load). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
… (CP-D/#218) The repository consolidated to a single skill (skills/problem-based-srs/, per the #50 consolidation) with nine reference actions, but docs/index.html still said 'Ten AgentSkills'. Updated to 'One AgentSkill ... walks a coding assistant through nine methodology steps'. Extended evals/tests/onboarding-parity.test.mjs with a guard against this claim reappearing. README.md was checked and does not contain this stale claim (only docs/index.html did). The badge in README.md already links the /releases index, not a per-tag URL, and node-count parity between docs/index.html's two spec illustrations (28 vs 29) was investigated: they caption two different demo assets (an earlier 'VagrantChefHubot' legacy-notation screenshot vs. the current .spec/crm-system.json), so left unchanged pending confirmation of which figure each caption actually intends, rather than guessing. Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1302/1302 passing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Six sub-issues (#173-#179) cite docs/spec/** specification and plan files that did not exist anywhere in the repository. All seven cited paths now resolve. Adds three new FRs for findings measured on 2026-08-16: duplicate release-claim markers on #139, the stale v1.1.1 marker on #138, and the six issues with no release-claim record. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Maps each phase item to the sub-issue that now tracks it and adds a registry section with the post-creation ledger measurement (127 boxes, 0 unparseable, 0 stale version mentions). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2f9904b2-f85c-46d6-8d9e-1ff6b74b2a08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 710294b3-21fc-4121-baa0-337f270b5f7e
This was referenced Sep 28, 2026
Closed
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification
pwsh -File .\run-tests.ps1 -NoOpenpassed twice from the same commitRemaining external evidence
Canonical issues requiring third-party registry recrawl, repository credentials, scheduled model execution, published-archive/manual recovery evidence, external participant observations, or final announcement/closure sequencing remain open intentionally.
This PR must not be merged automatically.