From 9abc9dd678849f9f560d0cfcbc43ecd600f6b5b1 Mon Sep 17 00:00:00 2001 From: Tom Softreck Date: Thu, 1 Oct 2026 22:17:16 +0200 Subject: [PATCH] ci: validate pinned Wellman source without build resolution [ticket-018] --- .github/workflows/wellman.yml | 34 ++++++++++++++ project/ticket-018/README.md | 31 +++++++++++++ project/ticket-018/intent.json | 84 ++++++++++++++++++++++++++++++++++ 3 files changed, 149 insertions(+) create mode 100644 .github/workflows/wellman.yml create mode 100644 project/ticket-018/README.md create mode 100644 project/ticket-018/intent.json diff --git a/.github/workflows/wellman.yml b/.github/workflows/wellman.yml new file mode 100644 index 0000000..b2f0eed --- /dev/null +++ b/.github/workflows/wellman.yml @@ -0,0 +1,34 @@ +name: wellman + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + metadata: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + with: + persist-credentials: false + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 + with: + python-version: "3.12" + - name: Check out dependency-free Wellman source + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + with: + repository: wellmanifest/wellman + ref: 58d7ae1ba768ead256e0e9a05fd641a0d8faec28 + path: .wellman-runtime + persist-credentials: false + - name: Verify the Wellman source revision + run: test "$(git -C .wellman-runtime rev-parse HEAD)" = '58d7ae1ba768ead256e0e9a05fd641a0d8faec28' + - name: Validate adopted requirements and Docs metadata + env: + PYTHONPATH: ${{ github.workspace }}/.wellman-runtime/src + run: python scripts/check-wellman.py diff --git a/project/ticket-018/README.md b/project/ticket-018/README.md new file mode 100644 index 0000000..7539971 --- /dev/null +++ b/project/ticket-018/README.md @@ -0,0 +1,31 @@ +# Ticket 018: Validate adopted Wellman source in CI + +- **ID**: ticket-018 +- **Owner**: agent:codex +- **Status**: IN_PROGRESS +- **Workflow state**: PUBLICATION +- **Created**: 2026-10-01 + +## Goal and scope + +Complete infrastructure dependency AC-05 of merged ticket-016. Run the existing +metadata checker on pull requests and pushes to main using verified Wellman +source at 58d7ae1ba768ead256e0e9a05fd641a0d8faec28. The read-only job uses +immutable action revisions and does not invoke pip or a build backend. + +## Acceptance criteria + +- [ ] AC-01: Exact Wellman source validates the adopted repository locally and in CI. +- [ ] AC-02: Managed governance accepts the infrastructure scope. +- [ ] AC-03: Independent protected delivery accepts and merges the tested head. + +## Authorization + +SESSION_EXECUTION_AUTHORIZATION: the owner requested installation, completion, +testing, push and protected merge of Wellmanifest adoption across Autogrammar. +This authorizes process invocation, not trusted merge approval. + +## Tracking boundary + +Raw output and receipts stay in private external state. This job preserves +existing product and governance gates and does not claim S3-S5 certification. diff --git a/project/ticket-018/intent.json b/project/ticket-018/intent.json new file mode 100644 index 0000000..8ab9add --- /dev/null +++ b/project/ticket-018/intent.json @@ -0,0 +1,84 @@ +{ + "schema": "new-project.intent/v3", + "ticket": "ticket-018", + "summary": "Validate adopted Wellman source in CI without build resolution", + "workstream": "infrastructure", + "classification": { + "kind": "SERVICE", + "priority": "P1", + "origin": "requested" + }, + "allowedPaths": [ + "project/ticket-018/**", + "TODO.md", + "project/TICKETS.md", + ".github/workflows/wellman.yml" + ], + "forbiddenPaths": [ + "project/ticket-*/user-*.md" + ], + "stacks": [], + "dependsOn": [ + "ticket-016" + ], + "conflictsWith": [], + "integrationTicket": null, + "delivery": { + "acceptedBaseSha": "b22c09ced0694902c79ca8e4e53d2fe591cad505", + "targetBranch": "main", + "outcome": "Run the adopted metadata checker in CI using exact dependency-free Wellman source, without pip dependency or build-backend resolution.", + "nonGoals": [ + "No changes to application code or adopted metadata", + "No new required-check policy or bypass of independent publication", + "No S3-S5 certification claim" + ], + "complexity": "S", + "estimatedMinutes": 20, + "budgets": { + "maxImplementationFiles": 1, + "maxAffectedComponents": 1, + "maxPublicInterfaceChanges": 0, + "maxRuntimeDependencies": 1 + }, + "architecture": { + "status": "accepted", + "decision": "Use a pinned checkout action for Wellman revision 58d7ae1ba768ead256e0e9a05fd641a0d8faec28, verify its Git SHA, and import its dependency-free source only in the metadata validation step.", + "components": [ + { + "name": "ci", + "paths": [ + ".github/workflows/wellman.yml" + ] + } + ], + "responsibilityChanges": false, + "interfaceChanges": [], + "dataChanges": [], + "ui": { + "impact": "none", + "states": [], + "evidence": [] + }, + "rollback": "Revert this workflow; keep existing governance and product checks." + }, + "runtimeDependencies": [ + "wellman@58d7ae1ba768ead256e0e9a05fd641a0d8faec28" + ], + "validation": [ + { + "criterion": "AC-01", + "commands": [ + "python scripts/check-wellman.py" + ], + "evidence": "The same pinned runtime and checker succeed locally and in the hosted metadata job." + }, + { + "criterion": "AC-02", + "commands": [ + "bash project/governance-check.sh --actor agent" + ], + "evidence": "Managed gate validates the infrastructure scope." + } + ] + } +}