Skip to content

docs: harmonize governance and contribution authority - #749

Open
logbie wants to merge 2 commits into
devfrom
docs/sawako-log-19-governance
Open

logbie wants to merge 2 commits into
devfrom
docs/sawako-log-19-governance

Conversation

@logbie

@logbie logbie commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Align contribution governance with Brad's approved LOG-10 policy and dev/CEO delegations, tracked by Paperclip LOG-19. Feature branches target dev; Yomi reviews the current revision and exact-commit CI remains required.

Changes

  • Add identical versioned common contribution policy and reconcile contributor, agent, testing, security and AI guidance.
  • Add the PR evidence checklist; preserve project-specific technical and Apache-2.0 guidance.
  • Keep existing policy and technical contracts; replace contradictory authority wording.

Compatibility and risk

Documentation change is R0. No language/runtime, palette, licensing or product behavior changes in this documentation commit.
This PR is stacked on unmerged CI PR 748, and targets dev. Review the documentation commit separately from that dependency; the full base diff still includes its independently reviewed CI work. Do not merge either past its review/control gates.

Independent GitHub approval identity is deferred: shared logbie cannot approve its own PR. Yomi review and protected-branch requirements remain binding. No bypass.

Validation

Documentation commit: 0bc00fef6e32790a5fd53ee908dccaec70d48d69.
Behavior tests N/A — the new commit edits prose and PR guidance only; required Actions are not waived.
Local git diff --check, changed-Markdown local-path checks and common-policy equality checks passed. Repository hygiene passed.
External URLs and heading anchors were not network-validated. Actions on this new SHA are pending; no old-head pass is claimed.
Three pre-existing broken local security links were corrected to maintained documentation.

Checklist

  • Owned documentation branch targets dev; no direct protected-branch push.
  • Scope, local checks, documentation-only exception and dependency are explicit.
  • No new credential, workflow, runtime or production changes in the documentation commit.
  • Current-SHA required Actions all passed; skipped/unrun checks explicitly recorded.
  • Yomi reviewed this revision and all triggered bot feedback is dispositioned.
  • Immediately-before-merge checks/reviews and independent approval controls satisfied.

The owner tracks pending Actions/bot feedback on Paperclip LOG-19 with a scheduled monitor. Main/release/tag/deploy decisions follow GOVERNANCE.md; this PR grants no merge permission.


Devin Review

Co-Authored-By: Paperclip <noreply@paperclip.ing>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 339bd007-e776-4bd7-8920-6c1553b9c21b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T13:55:40.714374Z 0bc00fe PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0bc00fef6e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
branches: [ main ]
pull_request:
branches: [ main ]
branches: [ main, dev ]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run Docker validation for dev-targeted PRs

Adding dev here and to the config-lint workflow does not update .github/workflows/docker-image.yml, whose pull_request.branches remains [main]. Consequently, a PR into the newly mandated dev target that changes src/**, Cargo files, Docker scripts, or another listed runtime path can merge without the consumer-image static-link and smoke tests running on that revision. Add dev to the Docker Runtime Validation pull-request filter as well.

Useful? React with 👍 / 👎.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Devin Review

Comment thread .github/workflows/ci.yml
branches: [ main ]
pull_request:
branches: [ main ]
branches: [ main, dev ]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Docker runtime checks miss dev pull requests

For a dev pull request changing runtime sources, CI runs but Docker image validation does not. Docker Runtime Validation still selects only main pull requests, leaving image builds and consumer smoke tests unverified before merging.

Learn more

The Docker validation workflow is separate from the normal CI workflow. Its pull request trigger selects runtime and packaging paths but only targets main. Its validation job builds a musl-linked Docker image and runs a consumer smoke test. Routing ordinary contributions into dev while enabling only normal CI there leaves this affected suite absent until promotion.

Example: A PR into dev changes src/main.rs so the static musl build fails. Regular CI runs, but the Docker workflow never starts. The failure is first detected when the change is promoted toward main.

Recommended fix: Add dev to the Docker workflow's pull_request.branches while retaining its existing path filters. Check whether any other path-filtered required workflows must also follow the new PR target.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.


Follow [GOVERNANCE.md](../../GOVERNANCE.md) for feature → `dev` PRs,
Yomi review, exact-commit Actions evidence, bot feedback and promotion authority.
Use the [canonical PR checklist](../../.github/pull_request_template.md).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Competing pull request templates

The guide still presents an earlier PR template before linking the new checklist. Its generic testing fields omit the current SHA, individual Actions results, and Yomi review, leaving contributors with conflicting examples.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants