v37 · 2026-07-28
canonical Dagger remote-delivery foundation
DevOps master f710474 normalizes every DevOps-owned GitHub Actions caller onto the reviewed immutable `frauthy/devops@4cf1a2fc5017182a9163e8bb2e3ecdb1d84c34cf` action. The generated workspace ledger covers 12 repositories and 45 workflows with zero policy violations.
Canonical resolution accepts authenticated private packages only for allowlisted `frauthy/*` repositories at verified immutable source SHAs. Installation uses the Frauthy GitHub Packages scope, disables lifecycle scripts, removes `NODE_AUTH_TOKEN` before repository code, and asserts the credential is absent.
DevOps E2E run 30409982948 and Delivery Foundation run 30409982964 passed at action source 4cf1a2f. The final normalized DevOps source was pushed after those action gates; full central CI remained non-terminal when GitHub API polling reached its rate limit, so no broader green claim is made.
Root, Protocol, Research, Market, Sandbox, Cloud, Admin, SDK, Site, and Infrastructure produced green hosted evidence during this migration. Brand's replacement canonical-action run remained non-terminal when polling stopped; no success is claimed for it.
This burst performed no Cloudflare, Neon, DNS, Terraform apply, package publication, GitHub environment mutation, or 1Password write. Site and Infrastructure production changes remain review- and evidence-gated.
v36 · 2026-07-20
Authenticated Admin and evidence-bound CI mesh
The reusable dispatch sender validates an allowlisted Frauthy repository, `push`, `refs/heads/master`, exact lowercase commit SHA, schema-1 payload, and deterministic idempotency key. The receiver rejects mismatches, deduplicates concurrent receipts, and checks out the exact source SHA.
Sender authority is isolated in `FRAUTHY_DISPATCH_TOKEN`; receiver checkout authority is isolated in read-only `FRAUTHY_CI_READ_TOKEN`. No workflow uses one token for both boundaries or inherits all caller secrets.
DEVOPS-5 remains open because no dedicated sender credential exists and no live sibling-push dispatch has occurred. Green missing-credential skips are not dispatch evidence.
DEVOPS-7 remains open because Workspace coverage run 29755242260 performed only the explicit credential check; source resolution, collection, and enforcement correctly skipped without `FRAUTHY_CI_READ_TOKEN`. The checked-in 69.64% baseline proves the complete historical data contract, not the live automated path.
Every sibling caller is pinned to reviewed DevOps dispatch workflow commit `d39572723b2815bd1175546210325959883c3200`, waits for its real terminal CI DAG, and removes the legacy inline `FRAUTHY_CI_TOKEN` / `peter-evans` sender.
No secret was created, copied, printed, or persisted. No Cloudflare or Neon account was assumed to exist; no Terraform apply, DNS change, deployment, image publication, or SDK/UI package publication occurred.
All implementation used isolated worktrees. Active UI and product checkouts, including untracked Project Management UI work, were preserved.
v35 · 2026-07-20
Terraform-owned topology and Dagger master delivery
The Dagger module is hermetic and loaded from an exact immutable DevOps commit. It verifies binary Site artifacts inside the pinned Bun container rather than transporting fonts through a text API.
DEVOPS-5 remains open pending a dedicated least-privilege `FRAUTHY_CI_TOKEN` and live cross-repository dispatch evidence. DEVOPS-7 remains open pending verified aggregate coverage enforcement.
No Cloudflare or Neon account was assumed to exist. No Terraform apply, DNS mutation, Pages deployment, database creation, secret write, container publication, or SDK/UI package publication occurred.
Active product and UI worktrees were preserved. This program used isolated worktrees and exact-master ancestry checks so concurrent work was not overwritten.
v34 · 2026-07-19
Infrastructure-owned Site Pages contract
No live Cloudflare API mutation, Terraform apply, Pages deployment, GitHub secret write, DNS change, or cache pruning occurred in this version.
v33 · 2026-07-19
Authenticated workspace installs and gated Site delivery
Active Root, Site, and Project Management UI checkouts were preserved. The untracked `research/packages/ui/ui` tree and all product UI SDK surfaces were untouched.
v32 · 2026-07-16
Site typed content architecture
No public UI SDK package changed or was published. The active Site, Brand, and Research UI checkouts were not modified; implementation and ledger ingestion used isolated latest-master worktrees.
v31 · 2026-07-16
Site production quality gates and interactive GP.Family lab
DEVOPS-7 remains open because its acceptance checklist also requires `orchestrate.yml` to produce the aggregate `coverage/summary.json` artifact. Site CI proved the final per-repo producer and ratchet, but `FRAUTHY_CI_TOKEN` is still absent and the dispatch step correctly skipped green.
DEVOPS-5 remains open pending a dedicated least-privilege `FRAUTHY_CI_TOKEN` and a successful live `repo-push` dispatch. No local OAuth token was copied into Actions.
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.
v30 · 2026-07-16
Portal quality program assessment
The evidence control room now consumes runtime evidence through adapters and a same-origin proxy, with explicit unavailable and fixture states.
DEVOPS-5 remains open pending a dedicated least-privilege FRAUTHY_CI_TOKEN; DEVOPS-7 remains open pending Site coverage and aggregate enforcement evidence.
v29 · 2026-07-15
CI mesh completion and Market container contract
Site master 617616d is the final original sibling caller of `frauthy/devops/.github/workflows/coverage.yml@master`; its first hosted invocation passed and explicitly deferred enforcement because Site has no coverage producer yet.
DEVOPS-5 remains open. `FRAUTHY_CI_TOKEN` is not configured, so Site's token-safe notification job skipped green and no live cross-repository dispatch was claimed.
DEVOPS-7 remains open until SITE-1 supplies Site coverage and the workspace orchestrator emits verified aggregate evidence.
The locally authenticated GitHub CLI token has broad OAuth scopes and was intentionally not copied into Actions; the live dispatcher still requires a dedicated least-privilege token.
This burst stayed outside the concurrent frontend program's ownership: no Brand, Site UI, Admin web, Cloud web, Market web, DevOps Portal, Research UI, or product `packages/ui` implementation was changed.
v24 · 2026-07-15
deconflicted backend gap burst
The live E2E workflow now makes its missing-token skip explicit and green, with regression coverage and Actions run 29446466987 as evidence.
v23 · 2026-07-15
Cloud runtime contract moved to Cloudflare
Runtime hosting decisions are now standardized on Cloudflare. Provider-specific deployment and persistence requirements should use Cloudflare primitives; prior Kubernetes/AWS/provider-selection placeholders are no longer authoritative.
v19 · 2026-07-14
Wave 14 Protocol platform and app initialization
Wave 14 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI code, tests, documentation, its gap checklist, and this Research ledger event changed; no UI-owned surface, product packages/ui, Portal, registry publication, release tag, or concurrent UI branch was touched.
v18 · 2026-07-14
Wave 13 Protocol mapping completion
Wave 13 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol mapping/lifecycle code, tests, dependency metadata, its gap checklist, and this Research ledger event changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v17 · 2026-07-14
Frontend SDK federation prerelease gate
Product UI PR 1 was reconciled with the concurrent quality-gate lane, revalidated, and merged as 4a38eb2. The published @frauthy/devops-ui@1.0.0-next.0 tag tree is byte-identical to merged master under packages/ui.
Frontend SDK Federation automated prerelease gate complete: seven Internal @frauthy/*-ui packages at 1.0.0-next.0, exact immutable tags and registry versions, seven verified Brand Portal libraries, 240 public components, and 634 catalog previews. Stable 1.0.0 promotion remains blocked only on the planned manual VoiceOver, NVDA, and TalkBack/touch-AT evidence.
v16 · 2026-07-14
Wave 12 Protocol LSP completion
Wave 12 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol LSP code/tests/documentation and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v15 · 2026-07-14
Wave 11 Protocol async contracts
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.
v14 · 2026-07-14
Wave 10 Protocol dev runner
Wave 10 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol CLI, Protocol documentation, and the Research ledger changed; no UI-owned, package publication, registry, or tag path was touched.
v13 · 2026-07-14
Wave 9 Protocol-SDK type contract
Wave 9 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol and core SDK are wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, product UI, registry publication, or tag path changed.
v12 · 2026-07-14
Wave 8 Protocol release readiness
Wave 8 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Protocol is wholly Gap Closure-owned; no Brand, packages/ui, frontend composition, Portal, or product UI path changed.
v11 · 2026-07-14
Wave 7 branch protection
The Frauthy organization is on GitHub Team. Commit b8a9769 adds a plan-aware provisioner and the authoritative 12-repository master-branch contract.
Live GitHub API read-back verified protection on all 12 master branches: strict exact CI contexts where workflows exist, required linear history, and force-push/deletion disabled. Brand and Root are structurally protected without invented contexts until their first master workflows succeed.
Administrator enforcement and required reviews remain disabled to avoid deadlocking the current solo-maintainer direct-push workflow; the documented policy calls for enabling them when the maintainer model changes.
Wave 7 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
v10 · 2026-07-14
Wave 6 Protocol and SDK coverage gates
Commit 895ddd9 records the six new baselines and makes workspace aggregation enforce floors while reporting targets. A real six-producer aggregate passed at 72.34% (6,525 of 9,020 lines).
DEVOPS-7 remains open until Site has a verified producer and orchestrate.yml emits a live workspace artifact. FRAUTHY_CI_TOKEN is still absent, so cross-repo orchestration and the E2E body skip green.
Wave 6 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, packages/ui, frontend composition, DevOps Portal, Research UI, or Sandbox UI path changed.
GitHub Actions billing is restored; all Protocol, SDK, and DevOps master workflows in this wave received runners and completed successfully.
v9 · 2026-07-14
Wave 5 coverage producers verified
Actions billing was restored by upgrading the organization to GitHub Team. Run 29337365623 passed all CI jobs, including the real DevOps coverage gate. DEVOPS-7 remains open for the remaining producers and live aggregate-orchestration artifact.
GitHub Packages authentication was verified through the local gh credential. Brand packages are available at 1.0.0-next.1 and all seven product UI packages at 1.0.0-next.0 with internal visibility.
Verification remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v8 · 2026-07-14
Wave 5 Cloud and Market coverage producers
The shared gate and workspace aggregator now honor the authoritative component targets: Cloud 70% and Market 80%. Seed evidence records both measured baselines. DEVOPS-7 remains open pending successful remote producer runs and the remaining aggregate coverage work.
Local gates passed: Cloud 208 tests with 30 live-service tests gated, Market 176 tests with 29 live-service tests gated, and DevOps 132 tests; all three typechecks passed.
GitHub marked the DevOps, Cloud, and Market jobs failed without starting a runner because recent account payments failed or the spending limit must be increased. This is recorded as a human-gated infrastructure blocker, not as code verification.
Wave 5 remained inside the ownership boundary in root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md; no Brand, packages/ui, web composition, Portal, Research UI, or Sandbox UI path changed.
v7 · 2026-07-13
Wave 4 Rust telemetry and real CI enforcement
The reusable coverage workflow now downloads caller artifacts without cross-repository tokens, enforces a persistent upward-only floor, and retains summary/state evidence for 90 days. DEVOPS-7 remains open pending threshold verification for the remaining producers and a live aggregate-orchestration artifact.
Wave 4 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. No Brand, product packages/ui, web composition, DevOps Portal, Research UI, or Sandbox UI path was changed.
GitHub Packages publication and UI release coordination remain owned by the concurrent Frontend SDK Federation.
v6 · 2026-07-13
Wave 3 cross-backend verification and observability
The conformance matrix uses canonical 41xxx ports and isolated Rust stateful cells. Both authorization backends completed all ten end-to-end assertions. DEVOPS-7 remains open because the reusable cross-repository coverage workflow still lacks real artifact aggregation and enforcement.
Wave 3 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v5 · 2026-07-12
Wave 2 deconflicted backend and CI mesh
Seven approved backend repositories call the shared tokenless contract. DEVOPS-1, DEVOPS-5, and DEVOPS-7 remain open until deferred Site/Brand/Research adoption, a dispatch token, and real coverage aggregation/enforcement are complete.
Wave 2 followed root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Brand, Site, product packages/ui, Cloud/Market web migration, Admin editor composition, DevOps Portal, Research UI, and Sandbox UI were intentionally untouched.
GitHub Packages publication remains blocked on a registry-compatible PAT in the concurrent federation session; no package publication is claimed here.
v4 · 2026-07-12
Wave 1 remote CI gate
Remote gate complete: SDK CI, infrastructure CI/image build, sandbox tokenless integration, and the manually-dispatched SDK staleness workflow are green.
v3 · 2026-07-12
Wave 1 deconflicted backend lanes
Shared conformance fixtures, callable conformance CI, corrected coverage paths, and a dry-run-safe publish workflow are implemented; all 125 tests pass.
The 41xxx e2e migration landed, but DEVOPS-11 remains open for its live stack and portal/Cuitty acceptance items.
Wave 1 was deconflicted from the concurrent Frontend SDK Federation. Brand, site, root, research UI, and all owned web/portal surfaces were intentionally untouched.
v1 · 2026-07-12
Baseline — workspace-wide gap audit
Seeded from the 2026-07-12 twelve-agent audit of all eleven repos plus the Cuitty capability catalog. Eleven gap-closure specs written; orchestration plan at root/specs/06-GAP-CLOSURE-ORCHESTRATION.md.