Skip to content

Repository independence, provenance and maintainability hardening #380

Description

@masarray

Goal

Make the active ARSAS tree independently identifiable, reproducible and maintainable, without modifying the physical v1.6.40 release, claiming unverified copyright clearance, or falsifying third-party comparison provenance. This is the cross-cutting tracked maintenance program, not a request to rewrite Smart Discovery.

Completed or active scoped changes

Open acceptance checklist

  • Inventory every Git-tracked path and textual content (source, test, workflows, scripts, evidence, docs, website/templates, legal notices, images/assets); do not rely on code search result counts as proof of absence.
  • Classify every external product/brand identifier: unnecessary product-facing wording, internal name, synthetic fixture, honest black-box reference provenance, mandatory legal attribution, or potentially restricted asset. Record disposition per file, with a dated, reviewable manifest.
  • Migrate the historical convergence workflow/doc/evidence to neutral active contract names atomically with all references, JSON keys, tests, event paths and check-name compatibility. Preserve exact request counts, the 58-member ordered authority, engine/app SHA, physical/test dates, historical failures and original source link via immutable commit. Do not claim measurements came from a different reference.
  • Replace whole-file source-clean exclusions with narrowly justified, tested exceptions. Negative fixtures cover source, path, workflow, JSON, docs, extensionless policy files, split-token and mixed-case rejection; fix(source-clean): scan every tracked file and test rejection fixtures #384/perf(source-clean): execute full-tree fingerprint checks in compiled matcher #397/docs(provenance): make tracked asset inventory reviewable and CI-enforced #404 keep the scan exhaustive and fast.
  • Audit field-compatibility names (including SNTP profile) separately; neutral SNTP commissioning profile symbols landed with packet bytes unchanged (f10cfcd).
  • Audit third-party notices, licenses, bundled fonts/assets and website imagery; retain required attribution and independently produced fixtures. Review license consistency and sources, not keyword presence alone.
  • Resolve historical PR fix(release): lock qualified runtime lineage and public surfaces #331, fix(discovery): preserve canonical static DataSet authority after live model build #333, discovery: converge live IED workflow with opened SCL static reporting #339, model: prepare source-neutral DataSet capability index and parity fingerprints #340 and perf(scl): reuse short-lived save enrichment snapshot #327 individually against current main, documenting unique changes before closure. Disposition audit is recorded in this issue; none is an authority to reintroduce stale Discovery/runtime or engine locks.
  • Evaluate the separately scoped relaunch branch for private draft vs public site changes. Website changes are already identical to main; only the internal LinkedIn draft remains unique and is intentionally not restored. Deleting the branch would not erase Git/PR history.
  • Retire remaining unused release/CI scripts only after verifying exact consumers and archived provenance; no workflow should mutate an existing stable tag.
  • Protect main and required checks after verifying bot-driven website/evidence writes and external access controls; use a staged rollout.
  • Refactor pure semantic/validation components under tests before association/monitoring or UI orchestration changes. Each PR states behavior-preserving invariants and measured effects.

Non-regression & completion

  • v1.6.40 public tag/source/engine and binary SHA remain unchanged.
  • No modification of Smart Discovery, MMS, static RCB/DataSet authority, cyclic poll quarantine or accepted 58/58 runtime through this hygiene program.
  • Source clean, full Windows build/regression, deterministic guards, portable smoke, and post-merge production verification pass on the exact combined commit.
  • Physical evidence remains attributable and reviewable, including rejected prior candidates.
  • No "plagiarism-free", formal compliance or certified originality claim without an appropriate independent evidence review.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions