Prepare repository for public contributions (advances #78) - #79
Merged
Conversation
Add Apache-2.0 licensing, contribution and security policies, code-owner governance, issue forms, Dependabot, and least-privilege validation CI.\n\nAdvances #78
vantasnerdan
added a commit
that referenced
this pull request
Aug 18, 2026
…diness Prepare repository for public contributions (advances #78)
vantasnerdan
added a commit
that referenced
this pull request
Aug 18, 2026
…diness Prepare repository for public contributions (advances #78)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Objective and issue
Prepare the repository-level license, contribution, conduct, security, CI, dependency, and review-governance surfaces needed before public contributions.
Canonical issue: #78
Issue relationship: Advances #78
Authoring agent: codex-public-readiness
Intended independent merger: @vantasnerdan, @axis-marbell, or @mlops-kelvin, excluding this implementing Codex session.
Change classification
Authority and scope
Base release and commit: accepted release
v0.160.0;mainat1b00c3a0c984e15e3637cf1b76dbfbc20b2b3f98.Accepted claims and canonical sources used: none; this PR changes no scientific claim, campaign, release, migration disposition, or generated scientific documentation.
Declared imports, assumptions, and conventions: Apache-2.0 is the owner-selected default project license. GPL-3.0-or-later tutorial material and CC-BY-SA-4.0 conduct-policy text remain separately identified in
THIRD_PARTY_NOTICES.md.Files or concerns intentionally out of scope: visibility mutation, history sanitization, PR #77, scientific authority, branch protection, security-feature activation, and collaborator permission changes. Those remain issue #78 gates.
New or materially changed public interfaces:
Unit-level disposition
Verification and sensitivity
Scientific mutation/numeric/formal checks are N/A: this PR changes no scientific statement, equation, solver, verifier, or public physics API.
The Gitleaks image resolved to digest
sha256:c00b6bd0aeb3071cbcb79009cb16a60dd9e0a7c60e2be9ab65d25e6bc8abbb7f.GitNexus impact
The index was refreshed from this isolated worktree.
detect_changes(scope="compare", base_ref="origin/main")reported 19 changed files, zero affected execution flows, and LOW risk. No framework function, class, or API symbol changes. The only indexed process, “Run → Check,” is unaffected.Memory, governance, and generated state
Durable contract:
memory/codex/efforts/public-contribution-readiness.md.Proposal/campaign/claim/release changes: none.
Generated outputs and synchronization commands: no generated scientific outputs changed;
scripts/render_docs.py --checkandscripts/render_memory.py --checkpassed via the full validator.Debt remaining inside the proposed merge unit: none.
Campaign frontier outside this merge unit: issue #78 publication transaction, especially rights-safe history sanitation.
Validation boundary
scripts/validate.sh --fullpasses because package/build metadata and public CI changed.git diff --checkpasses in a separate invocation.Author handoff
Independently inspect the license exceptions, exact CODEOWNERS set, least-privilege workflow, issue-first forms, and the successful Actions run. The riskiest assumption is that the two higher-dimensional tutorials are adaptations of the GPL-3.0-or-later source tutorial; the notices conservatively retain GPL terms.
After artifact merge, the next decisive action is an owner-authorized history-sanitation transaction for the Preparata publisher PDF/full extraction before any public visibility change. Do not merge this PR from this implementing session.
Reviewer disposition
To be completed by the independent reviewer.
Canonical issue predates PR: yes
Authoring or implementing agent: codex-public-readiness
Distinct merger: pending
Artifact merge:
Claim promotion: none
Goal completion: no
Merge as written:
Refactor or harvest:
Leave in PR history:
Next decisive action:
Head branch disposition: auto-delete after merge; preserve if closed-unmerged/failed.
Reviewer checks