Skip to content

v0.2.3

Choose a tag to compare

@github-actions github-actions released this 17 Sep 13:12
Immutable release. Only release title and notes can be modified.

0.2.3 (2026-09-17)

Governance impact

Phase: ▣ P1 — unchanged
Items: 7 advanced

Advanced · 7

GV Proposition
GV59 ◇ ↑ Minimize the ungoverned surface to irreducible observation and effect execution; adapters may perform effects but must not introduce semantic content, policy, structure, ordering, or authorization decisions.
GV18 ◇ ↑ Allow versioned materializations to follow their governing source change in the immediately subsequent chore(materialize) commit; the final pushed or reviewed state must contain canonical materializations.
GV63 ◇ ↑ Close the GitHub Actions portion of the governance inventory: triggers, permissions, concurrency, runners, timeouts, pinned actions, Nix runtime/cache, materialization, tests, Pages, releases, and admin boundaries.
GV84 ◇ ↑ Make observed invariant regressions counterexample-closing: once a contradiction to a governed or relied-upon invariant is recorded as an observed regression, its repair is incomplete until the counterexample is preserved as governed evidence, the missing or incorrectly scoped assurance boundary is corrected or overstated governance superseded, and candidate validation rejects recurrence before the affected workflow may succeed.
GV90 ◇ ↑ Model human authorization as AuthorizedRevision: new semantic authority may originate only from the exact repository state accepted by an explicit human pull-request merge. Candidate revisions may perform unprivileged validation and transient non-authoritative projections, but automated candidate-authoring principals must be distinct from human authorizers and post-authorization materializers and must not receive capabilities that can alter executable automation, authorize or merge the candidate, mutate authoritative repository state, or mutate persistent governed external state; only after authorization may governed automation exercise the capabilities necessary to derive deterministic materialization revisions or external effects. Derived outcomes create no independent semantic authority, must not be treated as fresh human authorization, and must retain revision-addressable causal provenance to the authorizing revision.
GV95 ◇ ↑ Make Govenv the sole semantic owner of the canonical changelog: derive the governed Unreleased state deterministically from the latest published release boundary to the current authorized revision, preserve every historical release entry immutably and reconstructibly, freeze that exact governed state into the Release Please candidate version before human approval, and preserve the approved freeze unchanged across the merge-to-publication boundary. Release Please may determine SemVer, analyze Conventional Commits, and coordinate the candidate/tag/release lifecycle, but its rendered notes are observational input rather than independent changelog authority; the pull-request body and published GitHub Release must project the same authorized typed release document and external publication must be verified by read-back equality.
GV88 ◇ ↑ Require every governable obligation to be enforced at its earliest sound information boundary while retaining govenv check as the authoritative repository evaluation and deriving every anticipatory enforcement from the same governed rule. Maintain an explicit enforcement inventory that anticipates, at minimum: construction-time Agda constraints for typed identities, roadmap/lifecycle validity, constitutional structure, evidence relationships, pure kernel boundaries, and projection/materialization structure; static candidate or incremental/LSP checks for governance evolution, immutable identity, architecture imports, handwritten-source restrictions, materialization ownership and drift, artifact colocation, documentation references, regression obligations, governance/release deltas, and release-progress classification; commit-boundary checks for staged candidate validity, commit policy, governance references, semantic commit classification, and regression signals; PR/CI checks only for information first available from GitHub or the remote candidate; and post-effect checks only for irreducible external observations such as read-back equality, publication state, admin effects, and runtime facts. Later stages may confirm earlier results but must not re-own, duplicate, or independently specify semantics that were soundly enforceable earlier.

Derived from immutable typed roadmap snapshots and governed Refs: GV… commit metadata. SemVer remains independent. e76acb1..c41881f.

Bug Fixes

  • release: converge main after publication (224e67f)
  • release: preserve post-merge freeze materialization (8dddae7)
  • release: require verified publication boundary (c41881f)

Miscellaneous

  • materialize: update governed materializations (5983ff6)
  • materialize: update governed materializations (9e30e00)
  • materialize: update governed materializations (f7d4982)
  • materialize: update governed materializations (4a27d53)