Skip to content

[Bug]: synchronize superseded release status documentation #114

Description

@pillowtalk-Qy

Observed behavior

Current main@4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d contains mutually contradictory release statements:

  • README.md says implementation stops at M5-06 although Gate C, visual QA, deployment, and the merged frontend are complete.
  • SECURITY.md calls the application a non-integrated Web/API baseline.
  • docs/real-vs-mock.md says there is no integrated runnable demo and lists already implemented Moss, orchestration, report, and UI behavior as absent.
  • docs/judge-map.md lists completed workbench and visual acceptance as remaining proof.
  • docs/known-issues.md reports production advisories as currently open although P0: remediate production dependency advisories blocking Gate C #102/PR P0: remediate production dependency advisories #104 remediated them and Gate C's production audit passed.
  • docs/security-audit-report.md retains its exact-subject historical NO-GO without an upfront resolution/supersession notice, so readers can mistake it for current release status.

Expected behavior

Current-status documentation must match merged main and distinguish historical exact-SHA audit results from the later remediation and Gate C PASS. It must preserve all Live/Fixture, MANUAL_REVIEW, STOP, Moss integration-fork, Clear402, wallet/signing, and no-hosted-Live limitations.

Reproduction

  1. Check out 4ec4e2d8c5e8fbbc08572f544461cbd5e1c24d7d.
  2. Compare the six files above with docs/gate-c-report.md, docs/visual-qa-report.md, closed P0: remediate production dependency advisories blocking Gate C #102, and main quality-gate run 31300536251.
  3. Observe that old statements describe completed or remediated work as current gaps.

Evidence

Scope

Writable only:

  • README.md
  • SECURITY.md
  • docs/real-vs-mock.md
  • docs/judge-map.md
  • docs/known-issues.md
  • docs/security-audit-report.md

Non-goals

  • No product, test, schema, dependency, lockfile, Gate verdict, STOP policy, trust-boundary, deployment, tag, media, or submission change.
  • Do not erase exact-subject historical audit evidence; add explicit resolution context.
  • Do not claim hosted Live, official Moss support, signing, authentication, safety, or RC tag completion.

Acceptance

  • Current-status statements match merged main and current public health.
  • Historical audit subject/verdict remain attributable and the resolved blocker links P0: remediate production dependency advisories blocking Gate C #102 and Gate C.
  • No active Known Issue claims remediated advisories remain open.
  • Integrated Fixture workflow and bounded standalone Live observation are described without conflation.
  • All local Markdown links resolve.
  • Claim-risk scan is manually classified.
  • pnpm check, production audit, public smoke, and git diff --check pass.
  • Exact-head CI passes before merge.

Security impact

Documentation-only correction. It reduces misleading release and evidence claims without changing runtime behavior or assurance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:docsDocumentation and evidence-boundary workarea:securitySecurity controls and boundariespriority:P1High prioritystatus:readyReady to starttype:bugDefect or regression

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions