Site production quality gates and interactive GP.Family lab
- Source
- Ledger event v31
Living Program Ledger
Immutable ingestion receipt
site
status → amber
ci → green (exact-head Site CI run 29545472697)
coverage → 97.06% unit line coverage (99/102); six production routes have Playwright smoke and axe coverage, Lighthouse performance/accessibility/best-practices/SEO floors of 95, and an enforcing DevOps coverage ratchet
Closed: SITE-1, SITE-2, SITE-5, SITE-6
Site master e547aa9 adds deterministic unit coverage, fourteen browser checks across six routes, axe scans with zero accepted violations, Lighthouse evidence uploads, and exact-pinned ESLint/Prettier tooling. The hosted run passed the reusable coverage workflow with a real LCOV artifact and its ratchet floor enforced.
The GP.Family page now contains a client-side SolidJS permission lab with editable identity input, trusted-domain mapping, four timed lifecycle stages, allow/deny verdicts, and an explicit `email_verified` fail-closed path. Browser tests verify allow, deny, and guard behavior.
The shared layout now emits a 1200x630 Frauthy social card through `og:image` and `twitter:image` metadata. Context-aware light, dark, and federated component palettes also resolved legacy WCAG contrast failures discovered by the new gate.
SITE-7, SITE-8, and the human-gated SITE-9 remain open; this burst did not claim component extraction, content-collection migration, or a production hosting decision.
devops
status → amber
coverage → All eleven configured coverage producers now have verified evidence, including Site at 97.06%; sibling per-repo ratchets are enforced, while workspace aggregate evidence remains blocked on live cross-repository orchestration
DEVOPS-7 remains open because its acceptance checklist also requires `orchestrate.yml` to produce the aggregate `coverage/summary.json` artifact. Site CI proved the final per-repo producer and ratchet, but `FRAUTHY_CI_TOKEN` is still absent and the dispatch step correctly skipped green.
DEVOPS-5 remains open pending a dedicated least-privilege `FRAUTHY_CI_TOKEN` and a successful live `repo-push` dispatch. No local OAuth token was copied into Actions.
Program-wide
No package was published, no production deployment occurred, and no active Brand or Research UI checkout was modified. Work was performed in isolated latest-master worktrees to preserve concurrent frontend changes.