Skip to content

v0.8 — Observability, Automation & Platform APIs planning and implementation tracker #209

Description

@ammarheidari

Authority and live stage

Live workstreams

Current canonical evidence

W62

  • final protected-main baseline before downstream activation: 6987a90a2bbf77d9ecb9125cf47a85a0ba059c58;
  • post-merge quality and CodeQL: SUCCESS.

W63 Slice 1

  • PR feat(history): establish W63 historical metrics provider core #232 final exact head: 62c0dbeef5f36ccb985c6a39a61d09de53a7841f;
  • protected-main merge: b2eb6b25008eb1cbbe2359a0da97ee5abd4e6f5d;
  • exact-head quality/dependency/v0.3/v0.4/v0.5-persistence/CodeQL/supply-chain: SUCCESS;
  • fresh CODEOWNER approval + Codex exact-head review: CLEAN;
  • post-merge quality #1574: SUCCESS;
  • post-merge CodeQL #1416: SUCCESS;
  • W63 Slice 2 now owns deterministic rollup/retention worker + HA lease/fencing.

W67 Slice 1

Parallelism now admitted

  • W63 Slice 2 continues retention/rollup/HA coordination.
  • W64 may proceed on live evidence normalization/contracts; history-backed trend/SLO paths remain dependent on W63 Slice 2 semantics.
  • W65 may proceed on a closed bounded policy grammar/evaluator and aggregate evidence; no arbitrary code/unbounded scan/raw payload persistence.
  • W66 may proceed on typed notifier profiles, delivery state and SSRF/destination policy before any real outbound adapter.
  • W67 may proceed on additional read-only parity, machine JSON/pagination and safe auth/profile handling.

Dependency maintenance

Dependabot PRs #226/#227/#228 attempted split CodeQL 4.38.2 updates and fail by construction because init/autobuild/analyze cannot mix action versions. They are closed as superseded by atomic PR #235, which updates all three pinned steps together.

Hard boundaries

  • no automation client receives privileged bypass;
  • no unbounded/high-cardinality telemetry or raw protected-data export;
  • no arbitrary notifier/provider endpoint proxy;
  • no arbitrary-code data-quality predicates;
  • no generic rollback; compensation requires an explicit safe inverse;
  • no OIDC-dependent CLI mutation/approval flow until a governed non-browser auth design exists;
  • release/tag/OCI/GitHub Release publication remains separately owner-gated.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions