Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 0 additions & 10 deletions .github/pull_request_template.md

This file was deleted.

8 changes: 0 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,14 +20,6 @@ jobs:
node-version: "22"
cache: yarn

- name: Test public repository boundary
run: bash scripts/test-public-boundary.sh

- name: Check public repository boundary
env:
PUBLIC_BOUNDARY_PRIVATE_PATTERNS_FILE: ""
run: bash scripts/check-public-boundary.sh

- name: Install workspace dependencies
run: yarn install --frozen-lockfile

Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ Versions track shipped code.
### Removed

- The honesty evals (`evals/`), the `honesty-evals.yml` workflow, and the `evals`/`evals:offline`/`evals:judge`/`evals:test` npm scripts.
- The `public:check` and `public:test` npm scripts and their CI steps.

## [0.3.0] - 2026-09-22

Expand Down
16 changes: 1 addition & 15 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,22 +53,8 @@ install policy is resolved.
- Keep unfinished work in docs or issues, not as TODO/FIXME stubs in source.
- Update README and threat-model claims together when a change affects shipped status, risks, or public guarantees.

## Public repository boundary

Keep this repository useful to an external reader. Product behavior,
integration guidance, security and deployment evidence, and grant delivery
records belong here.

Keep private operating instructions, assistant configuration, planning
workflows, approval records, prospect work, and unpublished review provenance
outside this repository. Every proper name, link, and status claim must make
sense without access to a maintainer's local environment. Public grant,
adoption, deployment, and security claims must link to public evidence.

Run `yarn public:check` before opening a pull request. The check reads a list of extra patterns from the git info directory and stops when that file is missing; in a clone without it, run `PUBLIC_BOUNDARY_PRIVATE_PATTERNS_FILE= yarn public:check`.

## Pull request bar

A useful PR says what changed, why it matters, and which check proves it. If the
change touches authorization, include at least one negative test for the failure
path. Confirm that the public repository boundary still holds.
path.
7 changes: 3 additions & 4 deletions app/revoke-demo-lib.ts
Original file line number Diff line number Diff line change
Expand Up @@ -95,10 +95,9 @@ export function realCheckedPath(candidatePath: string): string {
return rest === "" ? realAncestorDir : path.join(realAncestorDir, rest);
}

// One denied directory name is a personal notes-vault app whose name this
// repository's own public-boundary check keeps out of tracked text;
// decoded at runtime so the functional check exists without a literal
// occurrence in the source (see scripts/check-public-boundary.sh).
// One denied directory name is a personal notes-vault app; it is kept out
// of tracked text and decoded at runtime so the functional check exists
// without a literal occurrence in the source.
export const PERSONAL_NOTES_VAULT_DIR_NAME = Buffer.from(
"T2JzaWRpYW4=",
"base64"
Expand Down
2 changes: 0 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
{
"license": "MIT",
"scripts": {
"public:check": "bash scripts/check-public-boundary.sh",
"public:test": "bash scripts/test-public-boundary.sh",
"lint:fix": "prettier \"**/*.{js,ts}\" --write",
"lint": "prettier \"**/*.{js,ts}\" --check",
"sdk:typecheck": "tsc -p sdk/tsconfig.json --noEmit && tsc -p sdk/tsconfig.test.json --noEmit",
Expand Down
179 changes: 0 additions & 179 deletions scripts/check-public-boundary.sh

This file was deleted.

Loading
Loading