You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Protected shipped Inkspan truth remains exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. Root npm and Office source versions remain 0.6.0; source metadata does not prove registry publication. Historical branch/check/tag/release evidence is not authority for future publication. Do not create v0.6.0 while the protected-main defects tracked below remain unintegrated.
The protected release workflow must bind checkout to the event/tag SHA, verify local HEAD, require the tag SHA to equal the then-current protected-main tip, rebuild/test tagged source, and produce exact package/SBOM/checksum/provenance evidence before registry verification. Immediately before release, refetch the exact protected tip, live governance, versions, CHANGELOG, workflow source, tags/releases and every applicable release/security/provenance gate.
Ready PR #362 remains the sole canonical accessibility/product release-blocking repair lane against protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. Its current exact head is 11d5cfecdcc0949ec98e6ca110d482124bff00c4.
The branch repairs protected-main accessibility defects in the editor presentation boundary and their print-fidelity interaction:
dark active-toolbar 13px --cwl-accent text on --cwl-accent-soft moves from about 4.13:1 to about 5.06:1 by using #58a6ff on #163356;
the editable .cwl-editor__content textbox receives a visible keyboard :focus-visible indicator: 2px --cwl-accent with -2px offset, with forced-colors mapped to CanvasText; and
@media print explicitly removes that interactive focus outline so a focused editor does not leak focus chrome into paged output.
Focus / print-fidelity TDD lineage
08b576eef322f9dc180a3613c9f062b46af9df24: test-only RED contract for editable focus visibility.
44807c9e2c84e307bc6a2d077138b5b33cf94615: narrow visible-focus CSS GREEN repair.
97cce9648703f0ebf7b38dc13a964a8f2b3d1c24: browser RED contract for print-media focus chrome.
082c19eda773ad78f01b50e0be98a6dc38d0976c: narrow print CSS GREEN repair.
e56301cc2e338df1ba6156c3b5fed910d5e536c2: last fully verified source generation before later branch movement.
The browser contract loads dist/cwl-editor.css, tabs to the textbox, requires the 2px solid screen focus outline, switches that same focused element to print media, and requires no printed outline. It runs through the dependency-locked Chromium/Firefox/WebKit gate. This is component evidence, not a host-wide WCAG certification.
A later writer briefly introduced ARCHITECTURE.md protected-capability maturity edits plus src/architectureProtectedCapabilityMaturity.test.ts on #362. That scope is already owned by existing Draft PR #156 (docs: reconcile protected capability maturity). #362 therefore forward-restored ARCHITECTURE.md and removed the duplicate test rather than rebasing or force-pushing. compare_commits(e56301c..., 11d5cfe...) returns an empty file list, so the four post-e56301c... commits are net tree-neutral while preserving non-destructive history and the single-writer boundary.
All evidence for e56301cc2e338df1ba6156c3b5fed910d5e536c2 became predecessor evidence when the head moved, even though the net tree is identical. For exact current head 11d5cfecdcc0949ec98e6ca110d482124bff00c4 at the latest 2026-08-20 UTC refetch:
CI 32344528267: completed / success. Build-and-test job 96350377576 explicitly checked out exact head 11d5cfecdcc0949ec98e6ca110d482124bff00c4, passed 151 test files / 845 tests with 100% aggregate statement/branch/function/line coverage, packed-package consumer verification and demo build. Office Python 3.11–3.14 and dependency-locked Chromium/Firefox/WebKit jobs are terminal success.
unresolved inline review threads: 0; both CodeRabbit threads are resolved.
The earlier scanner-queue snapshot and .github#712 queue escalation are historical incident evidence only; the sole current-head scanner generations have since completed successfully and now supersede that queued state. Pending, queued, skipped, cancelled, absent, neutral, failed, stale, predecessor, status-only or model-only evidence remains non-passing.
Protected main still gives the release browser-release-evidence job a 30-minute ceiling while that job performs the same playwright install --with-deps chromium firefox webkit system-dependency setup that previously exhausted 30 minutes under Ubuntu/Azure package-mirror latency in real Inkspan browser job 95570983695; an unchanged-source rerun later passed. This is a release reliability defect, not permission to skip browser evidence.
The exact protected-main release inventory today is four assets: one npm tarball, one Office wheel, inkspan.spdx.json, and SHA256SUMS. That is the current release authority at main@3b38ead2d00f44eb578d0689087b9293b3dabe1e.
Existing Draft PR #285 is already the active writer for .github/workflows/release.yml, so no competing release-workflow PR was created. On #285:
RED f9ab67c65357192f4433e972476d425b9405bca1 added src/releaseWorkflowSyntax.test.ts coverage requiring a finite 60-minute release browser budget while the workflow still declared 30;
GREEN current head 599d2eb86bf60750a26dcfa6b0d69facc1588cc4 changes that browser-release ceiling from 30 to 60 minutes while preserving the rest of the active branch's release contract;
the same active test(diagnostics): add hostile-input and browser assurance #285 branch also carries a package-specific SBOM evolution with five assets: one npm tarball, one Office wheel, editor-package.spdx.json, office-package.spdx.json, and SHA256SUMS;
that five-asset inventory is active-PR truth only and does not replace the current protected-main four-asset release contract unless and until test(diagnostics): add hostile-input and browser assurance #285 and its dependencies integrate under live governance;
Do not split or duplicate the .github/workflows/release.yml writer merely to accelerate release. v0.6.0 stays frozen until the then-live protected release workflow no longer carries the known browser-admission defect and all release gates are proven on one exact protected lineage. The release asset inventory must always be re-read from that then-live protected workflow; neither today's four-asset contract nor #285's active five-asset proposal may be assumed after later integration movement.
Central review-control plane
Protected central review/control-plane truth is signed and protected .github/main@55a8b576725451dfe0a21a57d36a2f1a41619b24; its parent 6479989bbff475404cc2cccc468d5fb1d6c632e5 and earlier aa8503f4383e8328d89104796bc3e9f7da810376 are predecessor evidence only and do not define the live control plane. Existing foreign incident ContextualWisdomLab/.github#814 remains the owner of scheduled selection, exact-name claim/receipt recovery, acknowledgement publication, dispatch and downstream review-generation failures.
Inkspan issue-comment 5352555668 is predecessor evidence bound to #362 head e56301cc2e338df1ba6156c3b5fed910d5e536c2 and must not be promoted. After all repository-owned workflows for exact current #362 head became terminal-success, exactly one replacement request was submitted as issue-comment 5353399090, bound to repository ContextualWisdomLab/inkspan, PR #362, head 11d5cfecdcc0949ec98e6ca110d482124bff00c4, and protected base 3b38ead2d00f44eb578d0689087b9293b3dabe1e.
At the latest fresh refetch, that request has no durable acknowledgement/reaction and there is still no formal same-head OpenCode review. The review gate therefore remains absent / non-passing. Do not submit a duplicate same-head request. Require a durable receipt, observed exact checkout SHA, passing same-head coverage/docstring evidence, and a formal same-head verdict. If routing/receipt/dispatch proves incomplete under the central contract, continue existing owner .github#814; do not patch Inkspan product source around the control plane or weaken review/coverage gates.
Governance boundary
Immediately before any Inkspan lifecycle action, refetch exact head/base, protected main, live branch protection/rules/permissions available through supported tools, formal reviews/threads and every applicable repository/central workflow. The branch endpoint reports main as protected, while the available branch-protection summary does not expose all organization rulesets or review requirements.
#362 is not acceptance-clean while the same-head OpenCode/independent-review requirement or any then-live governance gate is non-passing. #285 is not integration-ready while its stack/current-head workflow evidence is non-passing. Never self-approve, invent reviewer/secret/authority, duplicate a same-head request, transfer predecessor evidence, force-push, destructively rebase, weaken a gate or bypass governance.
Required dependency order
Hold tag/publication while fix(a11y): repair editor contrast and keyboard focus #362 remains the canonical protected-main product blocker and while the known protected release-workflow browser-admission defect remains unintegrated.
For fix(a11y): repair editor contrast and keyboard focus #362, require terminal exact-head Inkspan CI/Security/SAST/package/browser/Office evidence. Satisfied for current exact head 11d5cfecdcc0949ec98e6ca110d482124bff00c4 by CI 32344528267, Security Scan 32344528097, and SAST Semgrep 32344528210.
Exactly one same-head OpenCode request is now outstanding as comment 5353399090; require durable receipt, fresh central generation with observed checkout SHA, passing same-head coverage/docstring evidence and a formal same-head verdict. Do not duplicate it.
Continue .github#814 as the foreign review-control-plane owner if that exact request proves incomplete under the central contract.
On the resulting exact protected Inkspan tip, regenerate accessibility, CI, security, coverage, package, browser/Office fidelity, SBOM/provenance, reproducibility, rollback and operational evidence. Active-PR/predecessor evidence does not transfer.
Immediately before tagging, refetch protected main, live governance, versions, CHANGELOG, workflow source, tags/releases and every release gate.
Create v0.6.0 only through supported tag/release authority at that unchanged protected tip; never synthesize release identity with a branch ref.
Require exactly the asset inventory declared by the then-current integrated protected release workflow. At current protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e, that is exactly four assets: one npm tarball, one Office wheel, inkspan.spdx.json, and SHA256SUMS. test(diagnostics): add hostile-input and browser assurance #285's five-asset package-specific SBOM inventory is active-PR truth only until protected integration; if that inventory becomes protected truth, refetch and enforce that exact five-asset set instead.
Publish npm/PyPI only through registry-side OIDC Trusted Publishing, without long-lived publication tokens or skip-existing semantics.
Verify public registry digests against the exact release artifacts. On partial publication or mismatch, record an incident and do not rebuild different bytes under 0.6.0.
The currently supported Inkspan connector mutation surface does not expose safe Git tag or GitHub Release creation. Branch-ref mutation must not fabricate release identity.
Acceptance
Close only when one exact protected lineage has: repaired protected-main contrast and editor focus visibility/print interaction; current DTCG contract; executable exact-checkout release workflow with the known browser-admission defect removed; aligned root/Office/tag versions; all applicable exact-head CI/security/accessibility/browser/Office/package/SBOM/provenance/reproducibility/review/rollback/operational gates; the exact asset inventory required by the then-live protected release workflow (currently four assets on protected main, while #285's five-asset form is non-authoritative until integration); and public npm/PyPI digests matching those exact artifacts. Branch CI, metadata, pending review dispatch, predecessor/model/status evidence or unmerged repairs are insufficient.
Release operational-acceptance boundary
Protected shipped Inkspan truth remains exact
main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. Root npm and Office source versions remain0.6.0; source metadata does not prove registry publication. Historical branch/check/tag/release evidence is not authority for future publication. Do not createv0.6.0while the protected-main defects tracked below remain unintegrated.The protected release workflow must bind checkout to the event/tag SHA, verify local
HEAD, require the tag SHA to equal the then-current protected-main tip, rebuild/test tagged source, and produce exact package/SBOM/checksum/provenance evidence before registry verification. Immediately before release, refetch the exact protected tip, live governance, versions, CHANGELOG, workflow source, tags/releases and every applicable release/security/provenance gate.Canonical Inkspan product release blocker: #362
Ready PR #362 remains the sole canonical accessibility/product release-blocking repair lane against protected
main@3b38ead2d00f44eb578d0689087b9293b3dabe1e. Its current exact head is11d5cfecdcc0949ec98e6ca110d482124bff00c4.The branch repairs protected-main accessibility defects in the editor presentation boundary and their print-fidelity interaction:
--cwl-accenttext on--cwl-accent-softmoves from about 4.13:1 to about 5.06:1 by using#58a6ffon#163356;.cwl-editor__contenttextbox receives a visible keyboard:focus-visibleindicator: 2px--cwl-accentwith-2pxoffset, with forced-colors mapped toCanvasText; and@media printexplicitly removes that interactive focus outline so a focused editor does not leak focus chrome into paged output.Focus / print-fidelity TDD lineage
08b576eef322f9dc180a3613c9f062b46af9df24: test-only RED contract for editable focus visibility.44807c9e2c84e307bc6a2d077138b5b33cf94615: narrow visible-focus CSS GREEN repair.0a5f18b59e08598e72a0e6f60c6fb88b787a040e: packed-stylesheet Playwright screen-focus acceptance.94b9a239f92c6cbe6748e808dc380f97e2224fab: cross-engine focus configuration.97cce9648703f0ebf7b38dc13a964a8f2b3d1c24: browser RED contract for print-media focus chrome.082c19eda773ad78f01b50e0be98a6dc38d0976c: narrow print CSS GREEN repair.e56301cc2e338df1ba6156c3b5fed910d5e536c2: last fully verified source generation before later branch movement.The browser contract loads
dist/cwl-editor.css, tabs to the textbox, requires the 2px solid screen focus outline, switches that same focused element to print media, and requires no printed outline. It runs through the dependency-locked Chromium/Firefox/WebKit gate. This is component evidence, not a host-wide WCAG certification.Source-ownership convergence on #362
A later writer briefly introduced
ARCHITECTURE.mdprotected-capability maturity edits plussrc/architectureProtectedCapabilityMaturity.test.tson #362. That scope is already owned by existing Draft PR #156 (docs: reconcile protected capability maturity). #362 therefore forward-restoredARCHITECTURE.mdand removed the duplicate test rather than rebasing or force-pushing.compare_commits(e56301c..., 11d5cfe...)returns an empty file list, so the four post-e56301c...commits are net tree-neutral while preserving non-destructive history and the single-writer boundary.Exact-current-head repository evidence for #362
All evidence for
e56301cc2e338df1ba6156c3b5fed910d5e536c2became predecessor evidence when the head moved, even though the net tree is identical. For exact current head11d5cfecdcc0949ec98e6ca110d482124bff00c4at the latest 2026-08-20 UTC refetch:32344528267: completed / success. Build-and-test job96350377576explicitly checked out exact head11d5cfecdcc0949ec98e6ca110d482124bff00c4, passed 151 test files / 845 tests with 100% aggregate statement/branch/function/line coverage, packed-package consumer verification and demo build. Office Python 3.11–3.14 and dependency-locked Chromium/Firefox/WebKit jobs are terminal success.32344528097: completed / success.32344528210: completed / success.The earlier scanner-queue snapshot and
.github#712queue escalation are historical incident evidence only; the sole current-head scanner generations have since completed successfully and now supersede that queued state. Pending, queued, skipped, cancelled, absent, neutral, failed, stale, predecessor, status-only or model-only evidence remains non-passing.Release-workflow reliability owner: #285
Protected
mainstill gives the releasebrowser-release-evidencejob a 30-minute ceiling while that job performs the sameplaywright install --with-deps chromium firefox webkitsystem-dependency setup that previously exhausted 30 minutes under Ubuntu/Azure package-mirror latency in real Inkspan browser job95570983695; an unchanged-source rerun later passed. This is a release reliability defect, not permission to skip browser evidence.The exact protected-main release inventory today is four assets: one npm tarball, one Office wheel,
inkspan.spdx.json, andSHA256SUMS. That is the current release authority atmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e.Existing Draft PR #285 is already the active writer for
.github/workflows/release.yml, so no competing release-workflow PR was created. On #285:f9ab67c65357192f4433e972476d425b9405bca1addedsrc/releaseWorkflowSyntax.test.tscoverage requiring a finite 60-minute release browser budget while the workflow still declared 30;599d2eb86bf60750a26dcfa6b0d69facc1588cc4changes that browser-release ceiling from 30 to 60 minutes while preserving the rest of the active branch's release contract;editor-package.spdx.json,office-package.spdx.json, andSHA256SUMS;feat/writing-diagnostics-package@cb49b1a6d646b5ba15f6aa88e568adf323fe05fc;Do not split or duplicate the
.github/workflows/release.ymlwriter merely to accelerate release.v0.6.0stays frozen until the then-live protected release workflow no longer carries the known browser-admission defect and all release gates are proven on one exact protected lineage. The release asset inventory must always be re-read from that then-live protected workflow; neither today's four-asset contract nor #285's active five-asset proposal may be assumed after later integration movement.Central review-control plane
Protected central review/control-plane truth is signed and protected
.github/main@55a8b576725451dfe0a21a57d36a2f1a41619b24; its parent6479989bbff475404cc2cccc468d5fb1d6c632e5and earlieraa8503f4383e8328d89104796bc3e9f7da810376are predecessor evidence only and do not define the live control plane. Existing foreign incidentContextualWisdomLab/.github#814remains the owner of scheduled selection, exact-name claim/receipt recovery, acknowledgement publication, dispatch and downstream review-generation failures.Inkspan issue-comment
5352555668is predecessor evidence bound to #362 heade56301cc2e338df1ba6156c3b5fed910d5e536c2and must not be promoted. After all repository-owned workflows for exact current #362 head became terminal-success, exactly one replacement request was submitted as issue-comment5353399090, bound to repositoryContextualWisdomLab/inkspan, PR #362, head11d5cfecdcc0949ec98e6ca110d482124bff00c4, and protected base3b38ead2d00f44eb578d0689087b9293b3dabe1e.At the latest fresh refetch, that request has no durable acknowledgement/reaction and there is still no formal same-head OpenCode review. The review gate therefore remains absent / non-passing. Do not submit a duplicate same-head request. Require a durable receipt, observed exact checkout SHA, passing same-head coverage/docstring evidence, and a formal same-head verdict. If routing/receipt/dispatch proves incomplete under the central contract, continue existing owner
.github#814; do not patch Inkspan product source around the control plane or weaken review/coverage gates.Governance boundary
Immediately before any Inkspan lifecycle action, refetch exact head/base, protected main, live branch protection/rules/permissions available through supported tools, formal reviews/threads and every applicable repository/central workflow. The branch endpoint reports
mainas protected, while the available branch-protection summary does not expose all organization rulesets or review requirements.#362 is not acceptance-clean while the same-head OpenCode/independent-review requirement or any then-live governance gate is non-passing. #285 is not integration-ready while its stack/current-head workflow evidence is non-passing. Never self-approve, invent reviewer/secret/authority, duplicate a same-head request, transfer predecessor evidence, force-push, destructively rebase, weaken a gate or bypass governance.
Required dependency order
11d5cfecdcc0949ec98e6ca110d482124bff00c4by CI32344528267, Security Scan32344528097, and SAST Semgrep32344528210.5353399090; require durable receipt, fresh central generation with observed checkout SHA, passing same-head coverage/docstring evidence and a formal same-head verdict. Do not duplicate it..github#814as the foreign review-control-plane owner if that exact request proves incomplete under the central contract.v0.6.0only through supported tag/release authority at that unchanged protected tip; never synthesize release identity with a branch ref.main@3b38ead2d00f44eb578d0689087b9293b3dabe1e, that is exactly four assets: one npm tarball, one Office wheel,inkspan.spdx.json, andSHA256SUMS. test(diagnostics): add hostile-input and browser assurance #285's five-asset package-specific SBOM inventory is active-PR truth only until protected integration; if that inventory becomes protected truth, refetch and enforce that exact five-asset set instead.skip-existingsemantics.0.6.0.Authority/tool boundary
The currently supported Inkspan connector mutation surface does not expose safe Git tag or GitHub Release creation. Branch-ref mutation must not fabricate release identity.
Acceptance
Close only when one exact protected lineage has: repaired protected-main contrast and editor focus visibility/print interaction; current DTCG contract; executable exact-checkout release workflow with the known browser-admission defect removed; aligned root/Office/tag versions; all applicable exact-head CI/security/accessibility/browser/Office/package/SBOM/provenance/reproducibility/review/rollback/operational gates; the exact asset inventory required by the then-live protected release workflow (currently four assets on protected main, while #285's five-asset form is non-authoritative until integration); and public npm/PyPI digests matching those exact artifacts. Branch CI, metadata, pending review dispatch, predecessor/model/status evidence or unmerged repairs are insufficient.