Skip to content

Clarify private preservation provenance - #1

Merged
VatsalSy merged 1 commit into
mainfrom
agent/private-preservation-provenance
Aug 3, 2026
Merged

Clarify private preservation provenance#1
VatsalSy merged 1 commit into
mainfrom
agent/private-preservation-provenance

Conversation

@VatsalSy

@VatsalSy VatsalSy commented Aug 3, 2026

Copy link
Copy Markdown
Member

What changed

  • remove the former Dropbox path from public provenance
  • describe private preservation material without publishing its location or operational metadata
  • clarify that redundant bundles and upstream dependency downloads are outside this source-only mirror

Why

The private preservation source has been compacted and moved out of Dropbox. The public repository should record the preservation boundary without exposing private storage infrastructure.

Validation

  • git diff --check
  • public README and provenance scanned for private hostnames, paths, storage IDs, and fleet terminology
  • all four published source trees remain unchanged

@VatsalSy
VatsalSy marked this pull request as ready for review August 3, 2026 12:46
Copilot AI review requested due to automatic review settings August 3, 2026 12:46
@VatsalSy
VatsalSy merged commit 4d03c97 into main Aug 3, 2026
@VatsalSy
VatsalSy deleted the agent/private-preservation-provenance branch August 3, 2026 12:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Not ready to approve

The updated provenance audit paragraph contains internally inconsistent phrasing and a stronger retention-policy claim than the README, which should be reconciled for clarity.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Pull request overview

This PR updates the public documentation to clarify the boundary between the GitHub “source-only mirror” and privately held preservation material, removing an explicit Dropbox path while keeping provenance intent intact.

Changes:

  • Removes the former Dropbox location from public provenance documentation.
  • Clarifies that snapshot archives/notes remain private and that redundant bundles + third-party release downloads are outside this mirror.
  • Tightens wording around what is (and is not) preserved/published.
File summaries
File Description
README.md Refines the public scope statement for what the mirror contains vs. what remains private.
PROVENANCE.md Replaces the explicit private path with a non-locating description and updates the audit/scope wording.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

Comment thread PROVENANCE.md
Comment on lines +9 to +12
The original source was re-audited on 2026-08-03. The four expanded source
trees matched this repository byte-for-byte, apart from empty directories that
Git cannot represent. Redundant bundle archives and unmodified third-party
release downloads were deliberately excluded from long-term retention.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants