diff --git a/ULTRAPLAN-2026-09-29.adoc b/ULTRAPLAN-2026-09-29.adoc new file mode 100644 index 00000000..4585b33e --- /dev/null +++ b/ULTRAPLAN-2026-09-29.adoc @@ -0,0 +1,374 @@ +// SPDX-License-Identifier: MPL-2.0 += Issue Backlog Triage — Current Inventory and Ultra-Plan +Jonathan D.A. Jewell +v1.0.0, 2026-09-29 +:toc: +:toclevels: 3 + +Status: *triage plan and issue inventory; no remote issue writes completed*. + +== 0. Decision summary + +On 2026-09-29, the live GitHub API returned *199 open issues*. This file lists every one, assigns a first-pass bucket, and gives an execution order. Carried-forward rows use the curated dispositions in `ULTRAPLAN-2026-09-24.adoc`; they are *not* represented as freshly re-audited. + +[cols="2,4,5",options="header"] +|=== +|Measure |Live count |Meaning +|Open issues |199 |Complete `gh issue list --state open` snapshot; every current open number is listed in §2. +|Unlabelled |78 |No GitHub label at all. +|Missing `scope:repo` / `scope:estate` |169 |Fails `docs/ISSUE-INTAKE-SPEC.adoc` Rule 5; must not be guessed silently. +|Unassigned |198 |No assignee recorded. +|Without milestone |199 |No milestone grouping. +|New since 2026-09-24 inventory |8 |#1049, #1050, #1054–#1059; assigned a first-pass bucket below. +|Prior-plan close candidates still open |8 |#637, #658, #708, #709, #715, #784, #808, #956; several are not yet safe to close. +|=== + +=== First-pass disposition totals + +[cols="2,1,5",options="header"] +|=== +|Bucket |Count |Interpretation +|ESTATE |91 |Carry-forward estate disposition plus #1049, #1055, #1056. +|KEEP / repo-local |75 |Prior repo-local disposition plus #1050, #1054, and #1058. +|DECIDE |13 |Prior decision items plus #1059; use #787 as the register. +|VERIFY |8 |Legacy verify items; current evidence required. +|CLOSE-CANDIDATE |8 |Old plan proposed closure; still open, not authorization to mass-close. +|PARK |3 |Retain with explicit trigger and revisit condition. +|INVALID |1 |#1057 “probe”: empty body, no actionable request. +|=== + +=== Provisional scope mapping for the label pass + +* `KEEP` → propose `scope:repo`; `ESTATE` → propose `scope:estate`. +* `DECIDE` → repo scope except #404, #497, #692, #787, #941, #1008, #1023, and #1028, which are estate-scope decisions; #1059 is repo-scope. +* `VERIFY` → estate scope for #438, #681, #887, #890, and #1013; repo scope for the remaining verify rows. +* `PARK` → estate scope. Close-candidate scope should be retained from the issue body/canonical survivor, not inferred from the fact that closure was proposed. +* `INVALID` → do not spend time classifying; close with a reason when permitted. + +This mapping is *proposed*, derived from the prior plan’s curated dispositions, and still needs human confirmation before the bulk label pass. + +NOTE: #1050 is an active repo-local P0 reproduction, not one of the eight legacy VERIFY rows. It is included under KEEP and promoted in the execution plan. + +== 1. Execution order (ultraplan) + +=== Phase 0 — remove noise / record easy proven resolution + +. *#1057 — close invalid.* Body is empty and title is only “probe”; no reproducible defect, decision, or campaign. A close/label attempt was made in this session and GitHub returned `403 Resource not accessible by integration`; it remains OPEN pending a write-capable session. No silent dismissal. +. *#956 — verify fixed, then close.* Read-only live endpoint `GET /repos/hyperpolymath/standards/rules/branches/main` now reports `required_status_checks` (along with `code_scanning`, `required_signatures`, `deletion`, and `non_fast_forward`); the issue thread records the 18-context gate. Close as fixed only after recording read-back evidence. +. *#637, #709, #715 — merge/close into #787.* The decision register is the surviving owner-decision surface; preserve any unresolved rows in #787 before closing source trackers. +. *#784 — close as answered by #968.* The census answered the hypothesis; cross-link #968 in the close comment. +. *#808 — subsume under #913.* First copy #808’s unique startup-death / zero-jobs mis-triage evidence into #913; then close #808 with the survivor link. Do not close silently. +. *#708 — do NOT close yet.* Its latest comment makes closure conditional on a post-fix weekly re-run and an artifact showing repo slugs, clean row counts, and an error count. Verify the scheduled run. +. *#658 — do NOT close yet.* Although the Deno→Bun campaign was superseded, its package decision remains represented as D10 on #787; preserve it until that ruling is answered or explicitly transferred. + +=== Phase 1 — contain live failures and contradiction risks + +. *P0 reproduce #1050* on a clean runner: missing `hypatia.sarif` is caller-visible; compare the current reusable SHA against its last known-good run and distinguish scanner build/cache failure from missing output conversion. Keep callers on known-good pins until verified. +. *P0 validate #1037* before touching the reported Dependabot PRs: re-enumerate the live PR population and effective ignore rules; do not merge a startup-killing bump based on the historic count alone. +. *P1 reproduce #1054* with exactly one JSON document: `[]` must pass only after scanner success; malformed, empty, multi-document, wrong-shape, and crash controls must fail closed. +. *P1 reconcile rule/implementation contradictions*: #1032, #1040, #1031, #1028, #1005. Cite governing ruling, current implementation, and authority precedence; ask the owner where policy is undecided. +. *P1 fix source/checker before propagation*: #1036, #1035, #1013, #1010. Reconfirm populations, then prepare a read-only exact-target manifest; no estate write is authorized by this triage pass. + +=== Phase 2 — split, merge, and refine + +. *#1055 split its two acceptance paths.* Keep the no-merge-base/orphan-ref gate and branch-disposition taxonomy in #1055. Move the #1005 AC2 pin-population remeasurement (28 mislabeled v4.38.1, 21 true v4.38.0, 15 v4.38.2) into #1005 as dated evidence; remove that unrelated acceptance criterion from #1055 only after copying it. +. *#1056 fold into existing canonical threads.* Move the four #994 class determinations to #994; move startup-death/Dependabot recurrence and recovery-path notes to #968. Close #1056 only after both cross-links exist. +. *#1058 split by artifact.* Keep the K9 envelope/contract/leash taxonomy in #1058. Move the `deed.abnf` contradictory ruling-header finding to the existing DEED campaign #837 (or its canonical grammar issue), with a link back. +. *#1059 stays a decision/architecture parent, not a duplicate of #1058.* Keep it for the cross-layer ruling (canon / deed / K9 / Nickel / environment / serialization, derivation invariant); link the K9 contract and KYAML sequence #1021–#1025. Batch owner choices through #787 where possible. +. Keep one actionable defect per issue. The 2026-09-24 cluster table remains the dedup reference for the other 191 carried-forward issues; shared component alone is not a reason to merge when acceptance criteria differ. + +=== Phase 3 — route and label the full backlog + +. Add `scope:repo` / `scope:estate` for all 169 currently missing scope only after checking the action location, not merely the affected population. Use carry-forward buckets below as proposals, not a blind API payload. +. Fill one primary type and area label, plus owner/status/priority where warranted. The title classifier cannot infer scope or evidence freshness. +. Assign one accountable owner per remaining actionable issue; route estate-only work to one existing umbrella/register. No milestone is required by intake policy unless it represents a real delivery window. +. Re-census after writes; completion means zero unscoped rows or an explicit exception, not merely “all got some label.” + +=== Phase 4 — evidence-based closure and follow-through + +. For every close: re-check open state, current default-branch HEAD or live platform state; locate fix/survivor; copy unique evidence; leave a factual closing comment; cross-link the survivor; then close. +. For every estate transfer: identify the canonical campaign/register and add evidence there before removing it from this repo’s actionable queue. +. Batch owner decisions by shared dependency; #787 is the register. Re-present decisions blocked more than 30 days as a single batch, consistent with `docs/ISSUE-INTAKE-SPEC.adoc`. +. Publish totals by bucket, missing evidence, unowned work, and blocked decisions after each phase. + +== 2. Complete open-issue inventory + +All 199 open issues returned by the snapshot are below exactly once. Current labels and update dates are live values. Legacy dispositions come from `ULTRAPLAN-2026-09-24.adoc`; the eight newer rows are first-pass proposals. `CLOSED` from the earlier plan is rendered as `CLOSE-CANDIDATE`, never as already closed. + +=== Invalid / trivial-close candidate (1) + +Close with a short factual reason once issue-write permission is available; no issue-body evidence to preserve. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/1057[#1057] |2026-09-28 |probe |— |New first pass +|=== + +=== Verify against current state (8) + +Reproduce or inspect current live state; close only if the exact acceptance criteria are met. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/438[#438] |2026-08-25 |Estate recovery: audit + revert unauthorized mass migrations (README .adoc→.md sweep; protected rescript/v-ecosystem repos) |documentation, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/479[#479] |2026-08-27 |[campaign] standards carve-out: evict products/impls, keep the canon (spec + policy + registry + template) |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/681[#681] |2026-08-29 |adaptive/must: 342 of 415 repos cannot merge a clean PR without --admin (unsatisfiable required contexts) |cicd, enhancement, governance, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/887[#887] |2026-09-22 |D65 — EstatePushing is an active org ruleset with zero rules |security |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/890[#890] |2026-09-22 |Optimus-Branch is enforcement:disabled on standards, hypatia and cicd-squabbler — 0 rules in force on main, while the ruleset count reads as governed |audit, governance, scope:estate, status:needs-ruling |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/935[#935] |2026-09-22 |actions-lock gate is permanently red on main, and its remediation contradicts canon rule 10 |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/963[#963] |2026-09-22 |main is red: actions.lock omits a transitive dependency of asana/push-signed-commits (actions/setup-python@v2) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1013[#1013] |2026-09-22 |code_scanning trim applied to hyperpolymath (77/77); metadatastician blocked by ONE inherited org ruleset, not 67 repos |— |Carry-forward from 2026-09-24 plan +|=== + +=== Prior plan: close candidate; revalidate before closing (8) + +These were proposed for closure in the 2026-09-24 plan but remain open. Re-check live acceptance evidence and copy unique evidence to the survivor before closing. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/637[#637] |2026-09-21 |[register] Owner-decision backlog — 17 issues blocked on a ruling, not on effort |meta:umbrella, status:needs-owner |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/658[#658] |2026-09-14 |Deno→Bun: all 30 deno.json locations assessed — 18 blocked on npm packages that do not exist |chore, migration, packaging, scope:estate |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/708[#708] |2026-09-17 |Lockfile Drift Detect anonymizes repos as _w, counts banners as entries, treats script errors as drift — and has only ever run once |bug, cicd, scope:repo |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/709[#709] |2026-09-14 |Owner decision batch 2026-08-31: 7 decisions from the triage wave, one reply resolves all |audit, decision, scope:estate, status:needs-owner |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/715[#715] |2026-09-14 |CI/CD regularisation: owner decisions O1–O10 (batch, non-blocking) |cicd, decision, status:needs-owner |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/784[#784] |2026-09-14 |Pin campaign may have startup-killed every repo carrying a stale actions.lock (hypothesis, needs census) |cicd, meta:campaign, tech-debt |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/808[#808] |2026-09-15 |RSR workflow templates use an illegal `uses: ../../` ref — every instantiated workflow is permanently dead (0 jobs) |— |Prior close proposal; revalidate +|https://github.com/hyperpolymath/standards/issues/956[#956] |2026-09-22 |standards/main has no required status checks — every gate this repo ships is advisory here |— |Prior close proposal; revalidate +|=== + +=== Owner ruling needed (13) + +Batch under the owner decision register (#787); state options, consequences, scope and decision owner. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/404[#404] |2026-09-21 |Estate licence cascade (PMPL -> MPL/CC-BY-SA axis) — per HANDOFF |documentation |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/497[#497] |2026-08-27 |[carve-out 8/9] ⚠️ OWNER-ONLY licence-flag items: 007 audits in public canon; PALIMPSEST.adoc narrative |documentation, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/692[#692] |2026-08-29 |policy: enforce Rust = Rust + Creusot without proof theatre |chore, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/787[#787] |2026-09-23 |Owner decision sheet D1–D72: one answerable place for #637 + #715 + #709 + #658 and this week's unfiled decisions |audit, bug, chore, cicd, decision, governance, meta:umbrella, scope:estate, status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/923[#923] |2026-09-22 |The Deno ruling is dated two ways across the estate (2026-08-26 vs 2026-09-22) |decision, migration, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/929[#929] |2026-09-22 |Seed CLAUDE.md claims the estate uses GitLab and not GitHub (flag only, owner decision) |decision |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/941[#941] |2026-09-22 |Hypatia RE001: adopt step-security/harden-runner estate-wide, or record WONTFIX (23 instances) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/944[#944] |2026-09-22 |Banned-language deed tools: port a2ml_to_deed.py + deed_lint.py off Python, or exempt permanently (2 files) |enhancement, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/991[#991] |2026-09-22 |AC4 arming policy: retired-filename blocks, stale-version warns (each CURRENT_VERSION bump is a measure-then-arm event) |governance, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1008[#1008] |2026-09-22 |rsr-template-repo Base ruleset repaired; 5-8 error-severity alerts remain (threshold semantics undetermined), and copilot_code_review may be a fifth unsatisfiable rule type |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1023[#1023] |2026-09-22 |KYAML step 4/6 — decide KYAML scope on the evidence (owner ruling) |decision |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1028[#1028] |2026-09-22 |Tag rulesets restrict `creation` with no bypass actors — an unknown number of repos can never ship a release |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1059[#1059] |2026-09-28 |decide the attestation/orchestration chain: canon → .deed → .k9 → Nickel → environment → serialization, with derivation (never restatement) as the invariant |— |New first pass +|=== + +=== Repo-local actionable (75) + +Keep in standards backlog; assign an owner and order by severity / dependencies. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/346[#346] |2026-08-27 |governance: hoist bridge-forbidden-phrases check into reusable workflow |meta:recurring |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/401[#401] |2026-08-27 |Docs: complete the audience-split education layer (docs/wikis/) |meta:recurring |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/409[#409] |2026-08-27 |promote CI-CRITICALITY tiers (Gate/Check/Advisory/Auto) → standards + rsr-template |cicd |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/446[#446] |2026-09-04 |Proposal: an honest, adoptable readiness/insight badge framework — grade our own work, and challenge the evaluators |design, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/463[#463] |2026-08-27 |Complete the per-language testing guides (Zig, BEAM, proofs) + Julia refresh + AffineScript SSOT |meta:campaign |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/495[#495] |2026-08-27 |[carve-out 6/9] Data out of spec dirs: grade data → archive, PORT-REGISTRY → verisim-data, retire SATELLITES.a2ml |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/646[#646] |2026-08-31 |AGENTIC.a2ml instructs agents to 'Never use AGPL' — contradicts Rules 3, 4 and 5 |governance, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/704[#704] |2026-08-31 |examples/web-project-deno.json template ships phantom npm:affinescript@^12.1.0, replicated across ≥12 repos — the purge phantoms are still propagating via scaffold |bug, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/732[#732] |2026-09-04 |AI-MANIFEST ply: relay items after #731 — two renames, CI wiring, migration, and one owner ruling |decision |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/791[#791] |2026-09-19 |githooks: validate-a2ml admits 0 of 222 files and validate-spdx rejects all 1,046 .adoc — neither was run against its own corpus |documentation, licensing |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/837[#837] |2026-09-19 |DEED conversion campaign — tracking & acceptance criteria (.a2ml → .deed) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/888[#888] |2026-09-21 |secret-scanner-reusable stages the estate baseline unconditionally, so it detonates on itself in every consumer with its own .gitleaks.toml |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/894[#894] |2026-09-22 |Gate table + criterion 1.2.1 ignore manifest.scm (estate Guix convention) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/895[#895] |2026-09-22 |Gate format cannot express partial modules or nested layouts (2 concrete cases) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/896[#896] |2026-09-22 |changelog-reusable can never start: called-job write perms are checked against caller TOP-LEVEL (own caller fails too) |bug |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/897[#897] |2026-09-22 |Canonical cliff.toml should strip ZWSP at generation (bot regens re-import GitHub-defused mentions) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/903[#903] |2026-09-22 |actions-lock cliff: ENFORCE_ACTIONS_LOCK_FROM=2026-10-01 reddens 163 callers with no human action |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/905[#905] |2026-09-22 |runtime-policy.yml's Deno branch emits only ::warning:: and cannot fail a job |bug, governance, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/906[#906] |2026-09-22 |workflow-lint's lock regex is blind to '- uses:' list items, so its green is partly vacuous |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/907[#907] |2026-09-22 |check-actions-lock-gate.sh unconditionally exempts actions/github-script, so @main passes today |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/908[#908] |2026-09-22 |root-allow.txt is registered in the exemption ratchet but absent on disk, so that ledger is inert |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/909[#909] |2026-09-22 |actions.lock never covers denoland/setup-deno |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/910[#910] |2026-09-22 |governance-reusable.yml still has 7 'ref: main' helper checkouts reached by 368 pinned callers |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/911[#911] |2026-09-22 |shell-e2e-reusable.yml has the repo's only 2 unpinned refs (owner's staged work: report only) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/913[#913] |2026-09-22 |76 'uses: ../../...' relative refs in vendored seeds are invalid syntax and cause startup death |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/914[#914] |2026-09-22 |46 genuinely unpinned third-party refs in the vendored seed trees |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/915[#915] |2026-09-22 |~138 files cannot carry a '#' SPDX header; 58 .json need REUSE sidecars |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/916[#916] |2026-09-22 |setup-deno pins are inconsistent and some look fabricated: one SHA labelled four different tags |migration, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/921[#921] |2026-09-22 |55 agent-instruction files assert 'TypeScript IS PERMITTED under Bun', contradicting the 2026-08-27 ban |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/922[#922] |2026-09-22 |No pinned Bun lint/format gate: staged JavaScript is a declared skip |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/925[#925] |2026-09-22 |check-ts-allowlist.deno.js cannot be deleted: 11 of the last 12 governance revisions still invoke it |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/926[#926] |2026-09-22 |k9-coordination-protocol vendors a Deno test harness: 260 Deno API lines across 10 files |migration, testing |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/928[#928] |2026-09-22 |language-policy.scm v2.0.0 has no wired regression test (needs a decision on guile in CI) |bug, governance, performance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/930[#930] |2026-09-22 |actions-lock gate's remedy text names a repo-relative path that exists in no consumer repo |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/932[#932] |2026-09-22 |validate-lint-format.sh: Rust and Nickel arms ask a different question than their tool |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/933[#933] |2026-09-22 |All 12 Rust crates fail cargo fmt --check (pre-existing formatting debt) |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/934[#934] |2026-09-22 |6 contractiles fail nickel typecheck: import path points one level off an existing file |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/936[#936] |2026-09-22 |Hypatia content_patterns/hardcoded_tmp: /tmp paths without mktemp (30 instances) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/937[#937] |2026-09-22 |Hypatia content_patterns/http_in_docs: plain-HTTP URLs in prose (11 instances) |automation, documentation |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/938[#938] |2026-09-22 |Hypatia content_patterns/npx_in_workflow: npx/npm in CI config (9 instances, stale rule + vendored) |automation, cicd, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/939[#939] |2026-09-22 |Hypatia shell-exec patterns: download_then_run_shell + eval_in_shell (13 instances) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/940[#940] |2026-09-22 |Hypatia content_patterns/known_fake_action_sha in vendored satellite examples (6 instances) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/942[#942] |2026-09-22 |Hypatia RE005: review exit-masking steps (`\|\| true` / continue-on-error) (20 instances) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/943[#943] |2026-09-22 |Hypatia workflow_hardening triage: secrets-inherit convention + WH013/WH006 false positives (7 instances) |automation, cicd, research, security |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/945[#945] |2026-09-22 |Hypatia misc: scorecard DependencyPinning + SD022 k9 spec stale path (2 instances) |automation, cicd, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/953[#953] |2026-09-22 |debt paydown: gate-scripts-without-tests re-baselined 30->40, todo-fixme 76->80 |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/955[#955] |2026-09-22 |Debt ratchet red on every PR since #820 — run-debtfile.sh --write emits a file check-debtfile-structure.sh rejects |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/957[#957] |2026-09-22 |PAT-refresh tripwire: live HYPATIA_SCAN_PAT will arm 6 unackable CSA findings in both gates |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/958[#958] |2026-09-22 |Debt-exception / Ratchet-exception trailers never survive the squash merge — 0 of 8 in the Debtfile's whole history |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/960[#960] |2026-09-22 |D73-C downstream: 21 launcher descriptors + trigger/ still name the deleted launcher-standard.a2ml |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/964[#964] |2026-09-22 |governance-reusable.yml dupkey helper pin 317101e0 is stale by 45 files — and its sparse-checkout scope is too wide for #962's freshness guard |governance, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/967[#967] |2026-09-22 |ci-pipeline detect is blind to 56 code-bearing repos (and probes Deno, not Bun) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/972[#972] |2026-09-22 |pre-commit hands validators git-QUOTED paths, so non-ASCII filenames are silently skipped (6 validators) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/975[#975] |2026-09-22 |21 baseline acks lapse on 2026-10-22 and 17 point at closed issues |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/976[#976] |2026-09-22 |detect: the Nickel probe matches RSR template boilerplate, silencing the zero-denominator refusal on 9 of 24 sampled repos |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/980[#980] |2026-09-22 |ci-pipeline.yml: the ledger pin's "same commit" invariant is unsatisfiable (12/12 merges are squash) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/981[#981] |2026-09-22 |validate-actions-lock prescribes a cure that can re-legitimise a blocked action version |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/992[#992] |2026-09-22 |check-lock-sync.sh and GitHub startup disagree for job-level-reusable-only callers, and the gate's error text is inverted |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/993[#993] |2026-09-22 |actions.lock policy: job-level reusable refs are reported, never required — and the pin bump that disarms the latent blocker |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/994[#994] |2026-09-22 |Cross-cutting governance reds surfaced by the actions.lock cure — 9 classes across 17 PRs (incl. a live gate for the retired A2ML) |cicd, governance, refactor |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/998[#998] |2026-09-22 |ci-pipeline.yml: standards does not call its own pipeline (AC6 of #986) |bug |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/999[#999] |2026-09-22 |config.ncl cannot be evaluated: std.record.merge does not exist |bug |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1000[#1000] |2026-09-22 |8 of 16 *.k9.ncl files lack the K9! line-1 sentinel |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1001[#1001] |2026-09-22 |os_detect.ncl: 'Apple_Darwin falls through to the wildcard in deployment_priority |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1014[#1014] |2026-09-22 |governance: the Hypatia scanner pin predates the consumer fixes it scans for — compiled-in suppression cannot cure a caller's gate failure |automation, chore, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1015[#1015] |2026-09-22 |check-action-pins-resolve.sh scans prose: a documentation example SHA fails the gate |bug |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1018[#1018] |2026-09-22 |rust-ci-reusable: explicit ref refs/pull/N/merge dies when the PR merges mid-run (absolute-zero #164 evidence) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1021[#1021] |2026-09-22 |KYAML step 2/6 — comment-preservation proof (shared by Y-2 and Y-3) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1022[#1022] |2026-09-22 |KYAML step 3/6 — a KYAML formatter/linter for arbitrary YAML |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1033[#1033] |2026-09-23 |gates.json: never_required_contexts cannot catch default-setup CodeQL by name |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1036[#1036] |2026-09-23 |Scorecard reconciler fails correct repos: gh actions-lock --verify is blind to job-level reusable refs (wrong in both directions) |bug, cicd |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1040[#1040] |2026-09-23 |apply-branch-gates: a gate workflow no PR can trigger still derives a required context |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1050[#1050] |2026-09-27 |hypatia-scan-reusable @2479cf7: scan produces no hypatia.sarif — "Path does not exist: hypatia.sarif" (caller-visible startup-shaped failure) |— |New first pass +|https://github.com/hyperpolymath/standards/issues/1054[#1054] |2026-09-28 |Hypatia reusable validation rejects clean [] and accepts multiple JSON documents |— |New first pass +|https://github.com/hyperpolymath/standards/issues/1058[#1058] |2026-09-28 |grammar artifacts: .k9 has no grammar or contract at all, and deed.abnf states both “sole normative” and “pending owner ruling” |— |New first pass +|=== + +=== Estate-scope / route to the right campaign (91) + +Keep the evidence, but do not treat as standards-repo implementation work unless this repo is the canonical fix source. Link the estate campaign/register. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/89[#89] |2026-08-27 |Epic: -iser regeneration-cartridge pattern — wire all 28 -isers into boj-server (unified gated adapter) |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/90[#90] |2026-09-03 |Roll unified-gated-adapter + SSE + regen-trigger into the iseriser scaffold |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/91[#91] |2026-08-27 |http-capability-gateway tier-2 production-wiring (ADR-0004) |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/92[#92] |2026-08-27 |Idris2 as source-of-truth: generate/verify Zig FFI from the ABI |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/93[#93] |2026-09-19 |Stop committing generated/* — gitignore + regenerate-on-trigger |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/124[#124] |2026-08-27 |Epic: estate proof-debt remediation (2026-05-18 reconciled audit) |major, meta:recurring, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/156[#156] |2026-09-19 |[#92 Class D] abbreviation / acronym-boundary drift across DB + cloud cartridges |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/252[#252] |2026-08-27 |[campaign] ReScript → AffineScript estate migration (UMBRELLA) |documentation, governance, meta:campaign, meta:recurring, meta:umbrella |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/272[#272] |2026-08-27 |[campaign #252] STEP 5 — TAIL BATCH: smallest tail-end repos (≤20 files × ~50 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/276[#276] |2026-08-27 |[campaign #252] STEP 6 — MID-TIER: 20-100 file repos (~15 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/278[#278] |2026-08-27 |[campaign #252] STEP 7 — LARGE REPOS: 100-500 file repos (~6 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/279[#279] |2026-08-27 |[campaign #252] STEP 8 — MEGAPORT: idaptik (516, was 1235) + panll (726) batched conversion |meta:campaign, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/281[#281] |2026-08-27 |[campaign #239] Estate seam audit: stale .claude/CLAUDE.md language tables + carve-out candidate pattern |meta:campaign, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/288[#288] |2026-08-27 |[campaign] Estate CodeQL weekly→monthly sweep (cut 3, standards#233 Option B — ~206 repos) |cicd, meta:campaign |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/306[#306] |2026-08-26 |ci(estate): Pages enablement decision needed across 48 repos (failing 'Setup Pages' on every push) |cicd, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/307[#307] |2026-08-27 |[campaign] .scm → .a2ml machine-readable convergence (104 repos remaining) |meta:recurring |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/309[#309] |2026-08-27 |[campaign] Python residual cleanup — ~45 estate-authored .py files remain (banned) |meta:recurring |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/323[#323] |2026-08-27 |[standing] Estate CodeQL cron drift detection + 6-week budget review |cicd, meta:campaign |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/324[#324] |2026-08-27 |[campaign] Long-tail non-canonical CodeQL cron sweep (~86 files / 30 repos) |cicd, meta:campaign |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/331[#331] |2026-09-08 |[campaign] Estate boj-build.yml sweep — repair or retire (~30 repos with malformed JSON + dead .local host + http://) |meta:campaign, refactor |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/342[#342] |2026-08-26 |audit: contractiles estate state 2026-06-02 — schema drift + trident-claim/on-disk mismatch |meta:recurring, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/343[#343] |2026-09-03 |audit: dotfile drift across estate (2026-06-02 sample) — .editorconfig / .gitignore / .gitattributes |status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/348[#348] |2026-08-27 |automation: hypatia ruleset + gitbots should be able to fan-out doc + 6a2 + contractile refreshes themselves |automation, enhancement, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/403[#403] |2026-08-26 |Build the Estate Manifesto & Atlas (front-door, owner-gated) |status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/408[#408] |2026-08-26 |policy: estate settings standard — merge opts, protection, required-checks = 🔴 Gate set (WS4) |status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/410[#410] |2026-08-27 |standard: MCP settings template = boj-server cartridge config (WS6) |chore, governance, scaffolding |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/411[#411] |2026-08-27 |standard: discussion + wiki templates + discussions-toggle policy (WS5/WS8) |documentation, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/460[#460] |2026-08-27 |[umbrella] Estate audit & optimization — make the enforcement real (Waves 0–6) |meta:recurring, meta:umbrella |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/462[#462] |2026-08-26 |Implement the DYADT production verifier (hyperpolymath/did-you-actually-do-that) |meta:campaign, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/493[#493] |2026-08-26 |[carve-out 4/9] rhodium-standard-repositories/ cleanup: de-vendor satellites/, merge templates into rsr-template-repo, delete the lying .gitmodules |status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/633[#633] |2026-08-26 |[umbrella] Estate control plane — close the automation loop (the last link was never connected) |cicd, meta:umbrella, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/634[#634] |2026-08-25 |[umbrella] Template family rationalisation — variant packs, not variant repos (measured: 6-file delta) |design, meta:umbrella, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/635[#635] |2026-08-25 |[umbrella] Surface the buried projects — DYADT is the worked example, the detector is the deliverable |meta:umbrella, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/636[#636] |2026-08-26 |[charter] git-logistics-office — the estate control plane (repo lifecycle: birth, enrollment, life, death) |design, meta:umbrella, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/645[#645] |2026-09-21 |Fix the scaffold that propagates 'License: PMPL-1.0-or-later' (runbook §7a source fix) |scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/653[#653] |2026-08-31 |40 referenced-but-absent files across 19 repos — triaged (estate sweep) |scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/657[#657] |2026-08-27 |MEASURED: a lockfile policy kills 77% of dead workflows — the wiped allowlist is only 10%, and the policy is invisible to the API |cicd, governance, research, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/659[#659] |2026-08-27 |Language policy is duplicated into ~372 per-repo CLAUDE.md files across 131 repos — fixing standards fixes one |governance, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/662[#662] |2026-08-31 |wordpress-tools PR #57 deleted 108 source files and added nothing — deletion scored as migration |bug, governance, scope:repo, status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/663[#663] |2026-08-27 |TypeScript retirement: measured — 308 of 613 .ts files were never exempt, and the largest exempt class is upstream forks |governance, migration, research, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/664[#664] |2026-08-31 |43% of estate .affine files are 200-byte Harvard Engine stubs — migration campaigns count deletions as ports |conformance, scope:estate, status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/668[#668] |2026-08-27 |gh search/code silently undercounts by up to 31% while reporting incomplete_results:false — adopt enumerate-then-filter as doctrine |automation, research, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/669[#669] |2026-08-31 |Orphaned/phantom action pins still live post-remediation: dtolnay ×35 repos (two orphaned SHAs), trufflehog ≥20, codeql-action ≥14 |bug, cicd, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/670[#670] |2026-08-27 |Dependabot bumps uses: without regenerating actions.lock — every remediated repo is newly exposed |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/674[#674] |2026-08-29 |Scorecard's PinnedDependencies is wrong for lockfile-enforced repos — 79 alerts on _pathroot, inline pinning would break CI |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/675[#675] |2026-08-31 |Estate sweep: Fork A 'postulate' damage confined to proven — but the Idris2/Agda keyword misconception is hand-authored and predates it by 4 months |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/677[#677] |2026-08-31 |Estate: 13 repos have a DAMAGED GIT OBJECT DATABASE (not the corrupt-index problem) — 1 with 9 unpushed commits at risk |chore, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/678[#678] |2026-08-31 |Estate: 132 repos track files their own .gitignore hides; template-sync sweep (92 repos) left a SILENT fake gate in 29 |chore, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/687[#687] |2026-08-29 |audit(hypatia): classify 61 structural-drift and canonical-home findings |automation, research |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/689[#689] |2026-08-31 |fix(rsr-certifier): complete or honestly gate the uncompilable satellite |bug, scaffolding |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/698[#698] |2026-08-31 |Banned languages appear in dev-environment definitions (guix.scm ×14, empty-linter mise.toml) |status:needs-owner |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/702[#702] |2026-08-31 |install-tools.sh regenerated estate-wide WITHOUT the #678 cure — fake exit-0 gate re-propagated to 245/248 copies (fix the template, not the copies) |bug, cicd, priority:p1, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/703[#703] |2026-08-31 |Duplicate checkout trees double-count every estate census — repos/ vs hyper-repos/ overlap on 213 names, _SET containers hold 412 nested repos |audit, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/705[#705] |2026-08-31 |proven: postulate cure is NOT on origin/main — 42 .idr files/360 sites still unparseable there; the full cure exists only as ~77 UNCOMMITTED working-tree files on a local branch |bug, priority:p1, scope:repo |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/706[#706] |2026-09-22 |mise.toml pins banned toolchains estate-wide — python in 543/573 files (249 repos); 59 files still pin deno despite the Deno→Bun ruling |audit, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/707[#707] |2026-08-31 |Phantom upload-artifact pin ea165f8d65b6db9a… (commit never existed, 422) live in 11 repos — spliced mutant of the healthy v4 SHA |bug, cicd, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/727[#727] |2026-09-03 |gh actions-lock fix mode prepends its banner above the SPDX header — blocks the central lock-refresh (plan §6.4) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/750[#750] |2026-09-08 |Deletion census: use `git ls-files --deleted`, never `git status` — the 83,441 figure was an empty-index artefact |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/751[#751] |2026-09-08 |Agent handover surface is lossy: `.claude/checkpoints/` prunes files and `developer/` is not a git repo |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/759[#759] |2026-09-09 |[decision] 72 of 111 rhodibot workflows still run the MUTATING variant on a weekly cron — the canary migration is 39/111 done |cicd, decision |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/792[#792] |2026-09-14 |Pin-consumption census TSV has TWO extractor defects — 145 of 1,434 rows carry a non-SHA in pin_sha, and every background rate quoted off it is contaminated |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/795[#795] |2026-09-15 |1,073 byte-identical Optimus-Branch.json replicas are a STALE, WEAKER policy than the canonical — and the design doc's canonical pointer does not resolve |bug, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/803[#803] |2026-09-22 |lockfile drift: 15 repo(s) as of 2026-09-22 |cicd, lockfile-drift |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/889[#889] |2026-09-21 |Repo metadata hygiene: 22 hyperpolymath repos have blank descriptions (5 public) |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/904[#904] |2026-09-22 |run_validator() is fail-open: 6 validators named by rsr-template-repo's pre-commit do not exist |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/917[#917] |2026-09-22 |234 .pre-commit-config.yaml files depend on Python, which LANGUAGE-POLICY bans |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/918[#918] |2026-09-22 |Mirror callers drifted across >=3 live SHAs (de-duplicate worktrees before counting) |tech-debt |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/919[#919] |2026-09-22 |Deno retirement sizing: 95 'deno task' definitions across 23 files in the 11 ledgered repos |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/924[#924] |2026-09-22 |rsr-template-repo has 62 unpinned workflow refs, including two @main and one feature branch |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/949[#949] |2026-09-22 |Estate health: 87% of default branches are red (388 of 447) — a red branch is no longer a signal |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/950[#950] |2026-09-22 |Mirror fleet: 27% of estate CI failures — destinations unprovisioned, advisory doctrine not implemented, 3 live caller refs |enhancement, security |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/968[#968] |2026-09-22 |actions.lock step-level desync: 39 repos with silently dead CI (startup_failure) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/969[#969] |2026-09-22 |actions.lock omits job-level reusable refs in 159 repos (no runtime impact; tracks upstream #129) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/987[#987] |2026-09-22 |Phantom blob-pin: 18 refs across 7 repos pin standards reusable workflows at non-commit SHAs (and the guard that detects this is itself blob-pinned) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1002[#1002] |2026-09-22 |Mirror to Git Forges: 3 of 7 forges failing, three different root causes |bug |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1003[#1003] |2026-09-22 |rsr-template-repo: no ruleset requires pull requests on any branch |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1004[#1004] |2026-09-22 |Estate census: 124 of 456 repos carry retired or unsatisfiable ruleset rules (report only) |governance, refactor |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1005[#1005] |2026-09-23 |Supply chain: 75 estate pins are spelled v4.38.0 but are the v4.38.1 tag target (estate-blocked) |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1006[#1006] |2026-09-22 |EstateTagging's workflows rule is vacuous (workflows: []), and no Integration can create a tag org-wide |cicd, enhancement |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1007[#1007] |2026-09-22 |EstatePushing is scoped ~ALL but binds to 6 of 68 repos — push rulesets reach private repos only |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1010[#1010] |2026-09-22 |ci: retire the dead A2ML validation gate (13 repos — the renamed-action population) |refactor, scope:estate |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1019[#1019] |2026-09-22 |CodeRabbit's unsigned pushes re-kill CI on every required_signatures repo — re-signing is triage, not repair |research |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1024[#1024] |2026-09-22 |KYAML step 5/6 — migrate estate-authored non-bot YAML |automation, refactor |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1025[#1025] |2026-09-22 |KYAML step 6/6 — workflows, only if step 4 rules them in scope |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1031[#1031] |2026-09-23 |CodeQL default setup and a committed advanced workflow cannot coexist — 3 metadatastician repos run both, and the advanced one is rejected at upload |— |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1032[#1032] |2026-09-23 |O6 propagation: four contradictions between the ruling and the committed rulesets |decision, governance |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1035[#1035] |2026-09-23 |27 Scorecard callers omit actions:read and will startup_failure on their next standards pin bump |cicd, meta:campaign |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1037[#1037] |2026-09-23 |48 open Dependabot PRs re-introduce the codeql-action v4.38.1 startup-killer, and the dependabot.yml ignore rule is being bypassed in 15 repos |cicd, enhancement |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/1049[#1049] |2026-09-26 |Estate listing: 35 repositories are below the RSR 7-topic minimum |— |New first pass +|https://github.com/hyperpolymath/standards/issues/1055[#1055] |2026-09-28 |Orphan refs: automated agents leave unrelated-history branches that no gate can see (8 arena/* refs estate-wide; #1005's AC2 population has drifted again) |— |New first pass +|https://github.com/hyperpolymath/standards/issues/1056[#1056] |2026-09-28 |slavia #100 closure: class determinations for #994, startup-death mechanics + Dependabot recurrence for #968 (comment-perms cross-file) |— |New first pass +|=== + +=== Deliberately parked (3) + +Retain with an explicit blocker/resume trigger; revisit only when that trigger changes. + +[cols="1,1,7,3,2",options="header"] +|=== +|Issue |Updated |Title |Current labels |Basis +|https://github.com/hyperpolymath/standards/issues/100[#100] |2026-08-27 |Phase E — Production wiring + staging validation + rollout/rollback runbook |major, requirements-target |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/239[#239] |2026-08-27 |[campaign] TypeScript → AffineScript estate migration (UMBRELLA) |documentation, governance, meta:campaign, meta:recurring, meta:umbrella, migration |Carry-forward from 2026-09-24 plan +|https://github.com/hyperpolymath/standards/issues/443[#443] |2026-08-25 |Estate campaign: roll SonarCloud across all repos (parked, resume later) |status:needs-owner |Carry-forward from 2026-09-24 plan +|=== + +== 3. Permission and execution note + +This session authenticated as `arena-ai-coding-agent[bot]`. Read-only issue census and live branch-rule read succeeded, but both `gh issue edit #1057 --add-label invalid` and the REST add-label call returned HTTP 403 `Resource not accessible by integration`. The issue was not labeled or closed; no other issue writes were attempted. This is a permission boundary, not an authentication failure. The inventory and plan are repository work; a maintainer with issue-write permission can apply the phases safely. + +== 4. Source and method + +* Live open census: `gh issue list --repo hyperpolymath/standards --state open --limit 500 --json number,title,createdAt,updatedAt,labels,assignees,milestone,url`. +* Live rule read: `gh api repos/hyperpolymath/standards/rules/branches/main`; response includes `required_status_checks` and `code_scanning`. +* Carry-forward buckets: issue-by-issue table in `ULTRAPLAN-2026-09-24.adoc`, not title-only guesses. +* Intake policy: `docs/ISSUE-INTAKE-SPEC.adoc`, especially Rules 1, 2, 3, 5, and 7. +* This is one repository’s issue list; estate-wide issues must be routed to a canonical campaign/register and do not authorize cross-repo writes. + +== 5. Completion gate + +Do not call the backlog under control until all 199 listed issues have a verified live disposition; all open issues have scope or an explicit exception; every duplicate/superseded item points to a survivor; every decision is reachable from #787; and a fresh API census reproduces the ending counts. Order: *inventory → triage → contain P0/P1 → owner decisions → repo fixes → estate campaigns → verified closures*.