Skip to content

[B2] Replace generic self-built governance checks with mature OSS #1156

Description

@SisyphusZheng

Part of #1155 and #1192. Target: v0.44.0-beta.3.

Objective

After framework, UI, and website architecture stabilizes, replace generic repository-owned governance with pinned mature tools and delete duplicated custom machinery.

Scope

  • Renovate for supported Deno/npm/JSR/GitHub Actions dependency updates
  • Gitleaks and GitHub secret protection
  • markdownlint-cli2 and lychee
  • actionlint and zizmor
  • CodeQL and OpenSSF Scorecard
  • publint and Are The Types Wrong against packed artifacts
  • CODEOWNERS, issue forms, PR templates, and generated release notes
  • AutoFlow/checker inventory and deletion of generic duplicate authority

Acceptance

  • Mature tools run reproducibly and fail CI non-zero for owned violations.
  • Replaced custom implementation, tests, tasks, and workflow steps are removed in the same migration.
  • Remaining repository-owned checks map to named OpenElement invariants.
  • No duplicate generic authority remains.

Boundary

This issue does not block Alpha compiler/runtime work. Do not build wrapper frameworks, long-lived dual paths, or broad repository-owned equivalence suites around mature tools.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    architecturecigovernanceRepository governance and policy ownershiptoolsv0.44v0.44 compiled OpenElement architecture train

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions