feat: import bounded external test evidence - #199
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1c6f4b75ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dc4c34e082
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1a527ee777
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 40ad63eb08
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
Evidence boundary
Imported JUnit results are externally supplied, non-gating context. ScopeProof did not execute the tests or target-repository code. The artifact digest identifies imported bytes only. Importer identity is asserted, not authenticated. Explicit criterion mapping is organizational context, not proof. An import never changes a finding or decision, satisfies E3/E4, creates or preserves
Ready, records final acceptance, or carries a decision to another head.This pull request is engineering evidence only. It does not establish correctness, customer validation, accessibility conformance, authenticated identity, broad platform support, demand, adoption, or Stage 3 activity.
Verification
f6d888b5b033a045d2d8069b43cafafc3179436729d393e41a792e98f9bb051b.coverage 2, local state, worktrees, caches, and raw JUnit XML absent0.2.4.dev0, both CLIs correct, and both installed benchmarks returned zero mismatches; final-head hosted Python 3.11 and 3.13 compatibility lanes and the Windows package/storage/CLI lane are greenok; the server then stopped and the endpoint was unreachableReview
Automated review surfaced four P2 findings after initially green heads: a criteria-revision reset could preserve stale imports, individual limitation strings were unbounded, accumulated imports were unbounded, and re-analysis attachment could preload imports outside the append-only lifecycle. All four were reproduced with failing regressions and repaired in the shared core. No unresolved Critical or Important findings remain; all hosted checks are terminal green except the two intentional skips.
Product stage truth
closed_not_pursued_by_ownerowner_led_productization_activeUnsupported environments
Local installed-browser evidence is Chromium on macOS/POSIX. Hosted compatibility lanes provide Python and package/storage evidence, not real desktop workflow evidence. No real Windows or Linux desktop workflow, real screen-reader workflow, or accessibility-conformance claim is included.