Skip to content

fix: consolidate open-issue remediation and evidence gates - #320

Open
RafaelGorski wants to merge 19 commits into
mainfrom
rafaelgorski-resolve-open-issues
Open

RafaelGorski wants to merge 19 commits into
mainfrom
rafaelgorski-resolve-open-issues

Conversation

@RafaelGorski

Copy link
Copy Markdown
Owner

Summary

Verification

  • pwsh -File .\run-tests.ps1 -NoOpen passed twice from the same commit
  • deterministic evals: 974/974 per consolidated runner
  • canvas unit tests: 307/307
  • Playwright E2E: 41/41
  • plugin validation: passed
  • new behavior-proof scripts: 100% line/branch/function coverage
  • live 28-root release-claim census: green
  • live release issue gate: green

Remaining external evidence

Canonical issues requiring third-party registry recrawl, repository credentials, scheduled model execution, published-archive/manual recovery evidence, external participant observations, or final announcement/closure sequencing remain open intentionally.

This PR must not be merged automatically.

GitHub Copilot and others added 19 commits September 27, 2026 05:04
- CHANGELOG.md: add missing [2.7.0] release-link definition
- README.md: fix version badge 2.6.0 -> 2.7.0
- docs/docs.html: fix stale 2.6.0 version tokens (CSS/JS cache-bust,
  header/footer badges) -> 2.7.0
- docs/skills-health.*, srs-navigator package-lock.json: regenerated by
  the test runner to match current manifest versions
- evals/tests/release-trains.test.mjs,
  evals/tests/release-preflight.test.mjs: update hardcoded v2.6 fixture
  tag to v2.7 to match the manifest's current version
- evals/tests/distribution-drift.test.mjs: the 'holds for the links this
  repository ships today' test now builds its own summarize() call with
  the real, current release history (v2.6, v2.7) instead of the shared
  PUBLISHED_RELEASES fixture (frozen at the v2.4.1 era), which was
  causing the real CHANGELOG's [2.6.0] link to be falsely flagged as
  stranded. Other tests in the file keep the original shared fixture
  since they exercise synthetic version scenarios unrelated to the real
  repo state.

Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1299/1299 passing
(Plugin validation 1/1, Canvas extension 307/307, Skill evals 950/950,
Canvas e2e 41/41). node scripts/check-distribution.mjs now reports only
the pre-existing, third-party registry-listing-drift finding (requires
re-submission at skills.sh, outside this repo's control).

Addresses the failing-test findings from issue #227 (daily-eval digest).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
docs/assets/site.css: .skip-link foreground changed from --ink-heading
(2.39:1 on --primary, below WCAG AA 4.5:1) to --on-primary (near-white,
~7.5:1 on --primary), matching the fix already used for .btn-primary and
.learn-action.is-primary.

Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1299/1299 passing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
docs/docs.html's 'Start in three steps' quick-start presented /live as
step 3 right after only installing the skills, contradicting README.md
('the SRS Navigator canvas app... installed separately from the
skills'). A first-time reader following only the quick-start would hit
a missing-canvas dead end at step 3. Step 03 now names the canvas as a
separate install, matching README.

Adds evals/tests/onboarding-parity.test.mjs as a drift guard (negative-
tested: reverting the docs.html wording makes it fail).

Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1301/1301 passing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
#1 HIGH - command injection via unescaped github.ref_name/default_branch
in shell run: blocks. Fixed in all 4 affected workflows plus the two
additional inline occurrences of the same pattern:
- .github/workflows/create-release.yml (branch guard + asset-verify
  summary line)
- .github/workflows/release-canvas.yml (branch guard + asset-verify
  summary line)
- .github/workflows/thursday-release.yml (branch guard)
- .github/workflows/thursday-release-report.yml (branch guard)
All now pass the GitHub Actions context values through env: and
reference them as shell variables instead of interpolating the
expression directly into run:.

#2 LOW - package.json/package-lock.json version mismatch: already
resolved (both now report 1.1.4).

#3 (optional hardening - pin Actions to commit SHAs) intentionally
deferred: correctly resolving 30 tag references to verified commit
SHAs needs each SHA looked up and confirmed against the upstream repo,
not guessed; doing that without verification risks a worse outcome
(a wrong pin silently breaking releases) than the current low-
confidence (5/10), non-exploit finding it addresses.

Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1301/1301 passing;
all 4 edited workflow files parse as valid YAML (python yaml.safe_load).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
… (CP-D/#218)

The repository consolidated to a single skill (skills/problem-based-srs/,
per the #50 consolidation) with nine reference actions, but
docs/index.html still said 'Ten AgentSkills'. Updated to 'One AgentSkill
... walks a coding assistant through nine methodology steps'. Extended
evals/tests/onboarding-parity.test.mjs with a guard against this claim
reappearing.

README.md was checked and does not contain this stale claim (only
docs/index.html did). The badge in README.md already links the
/releases index, not a per-tag URL, and node-count parity between
docs/index.html's two spec illustrations (28 vs 29) was investigated:
they caption two different demo assets (an earlier 'VagrantChefHubot'
legacy-notation screenshot vs. the current .spec/crm-system.json), so
left unchanged pending confirmation of which figure each caption
actually intends, rather than guessing.

Verified: pwsh -File .\run-tests.ps1 -NoOpen -> 1302/1302 passing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Six sub-issues (#173-#179) cite docs/spec/** specification and plan files
that did not exist anywhere in the repository. All seven cited paths now
resolve. Adds three new FRs for findings measured on 2026-08-16:
duplicate release-claim markers on #139, the stale v1.1.1 marker on #138,
and the six issues with no release-claim record.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Maps each phase item to the sub-issue that now tracks it and adds a
registry section with the post-creation ledger measurement (127 boxes,
0 unparseable, 0 stale version mentions).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2f9904b2-f85c-46d6-8d9e-1ff6b74b2a08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3d7bec5a-ed63-4fb3-abc0-f5516fc75e08
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 710294b3-21fc-4121-baa0-337f270b5f7e

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants