Skip to content

Add contract-driven native canary validation - #11

Merged
man4ish merged 2 commits into
mainfrom
hardening/contract-native-canary-20261004
Oct 4, 2026
Merged

man4ish merged 2 commits into
mainfrom
hardening/contract-native-canary-20261004

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Adds a manual-only, contents-read native validation workflow for exactly seven static-ready canary tools (14 native pairs). Includes deterministic plan/contract/fixture binding, bounded scientific checks, local OCI-to-SIF validation, schema-v1 identity, durable failures and exact terminal reconciliation. No publication path or package-write permission. Frozen reference factory and all 591 non-canary contracts unchanged. Local relevant suite: 765 passed. Full repository: 8307 passed, 13 skipped, zero failed. Ruff, actionlint and contract validator passed. Original local reference Dockerfile footprint commits deliberately excluded by basing this branch on origin/main.

@man4ish
man4ish merged commit affc866 into main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant