Skip to content

batch C audit: remaining registry listed repositories #15

Description

@Riverbraid

Status

BATCH C AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED

Scope

Batch C covers the remaining Evaluation Kit registry listed repositories not covered in Batch A or Batch B:

  • Riverbraid-Action-Gold
  • Riverbraid-Audio-Gold
  • Riverbraid-Cognition
  • Riverbraid-Identity-Gold
  • Riverbraid-Integration-Gold
  • Riverbraid-Interface-Gold
  • Riverbraid-Judicial-Gold
  • Riverbraid-Lite
  • Riverbraid-Memory-Gold
  • Riverbraid-Network-Gold
  • Riverbraid-Security-Gold
  • Riverbraid-Standard-IO
  • Riverbraid-Storage-Gold
  • Riverbraid-Temporal-Gold
  • Riverbraid-Types
  • Riverbraid-Vision-Gold
  • Riverbraid-Weave-Gold
  • Riverbraid-Bridge-Gold
  • Riverbraid-Bio-Gold
  • Riverbraid-Flow-Gold

Confirmed public entry strengths

  • Many sampled Batch C repositories use the newer README boundary pattern with lifecycle category, normative source, claim boundary, Evaluation Kit link, Documentation link, authority boundary, and non-claims.
  • Standard verify.mjs samples exit nonzero when computed verification status is not VERIFIED.
  • Search did not return visible common secret markers, pull_request_target, permissions: write-all, pipe-to-shell patterns, or common nondeterminism markers.

Current finding state

  1. Riverbraid-Types README, package BOM issue, workflow target, and workflow secret coupling were remediated. Execution evidence remains required in Riverbraid-Types#2.
  2. Riverbraid-Standard-IO workflow target and secret coupling were remediated with a bounded scaffold check. Execution evidence remains required in Riverbraid-Standard-IO#2.
  3. Riverbraid-Weave-Gold README versus Evaluation Kit registry mismatch was resolved and Riverbraid-Weave-Gold#2 was closed as documentation-only resolved.
  4. Riverbraid-Security-Gold, Riverbraid-Storage-Gold, Riverbraid-Bridge-Gold, Riverbraid-Bio-Gold, and Riverbraid-Flow-Gold README surfaces were expanded to the Phase 4 boundary pattern.
  5. Several repos rely on package license fields or README license text rather than root LICENSE files. This remains part of the focused license audit.
  6. Several workflows use ubuntu-latest and tag-pinned actions. This is common but not maximum reproducibility hardening.
  7. Presence-check-only registry entries remain presence checks and are classified in docs/VERIFICATION_DEPTH_CLASSIFICATION.md.

Search-limited non-findings

Search did not return visible hits in Batch C for common private key markers, GitHub token markers, AWS secret marker, npm token marker, pull_request_target, permissions: write-all, secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.

This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.

Required follow-up

  • Run execution evidence for patched Types and Standard IO workflow targets.
  • Decide whether presence-check repositories should remain support surfaces or receive fuller verifiers under a separate gate.
  • Complete focused license audit.
  • Populate readiness matrix with evidence.
  • Preserve registry freshness lock until explicit registry succession gate exists.

Boundary

This issue records audit inventory only.
It does not claim Batch C is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions