Status
BATCH C AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED
Scope
Batch C covers the remaining Evaluation Kit registry listed repositories not covered in Batch A or Batch B:
- Riverbraid-Action-Gold
- Riverbraid-Audio-Gold
- Riverbraid-Cognition
- Riverbraid-Identity-Gold
- Riverbraid-Integration-Gold
- Riverbraid-Interface-Gold
- Riverbraid-Judicial-Gold
- Riverbraid-Lite
- Riverbraid-Memory-Gold
- Riverbraid-Network-Gold
- Riverbraid-Security-Gold
- Riverbraid-Standard-IO
- Riverbraid-Storage-Gold
- Riverbraid-Temporal-Gold
- Riverbraid-Types
- Riverbraid-Vision-Gold
- Riverbraid-Weave-Gold
- Riverbraid-Bridge-Gold
- Riverbraid-Bio-Gold
- Riverbraid-Flow-Gold
Confirmed public entry strengths
- Many sampled Batch C repositories use the newer README boundary pattern with lifecycle category, normative source, claim boundary, Evaluation Kit link, Documentation link, authority boundary, and non-claims.
- Standard
verify.mjs samples exit nonzero when computed verification status is not VERIFIED.
- Search did not return visible common secret markers,
pull_request_target, permissions: write-all, pipe-to-shell patterns, or common nondeterminism markers.
Current finding state
Riverbraid-Types README, package BOM issue, workflow target, and workflow secret coupling were remediated. Execution evidence remains required in Riverbraid-Types#2.
Riverbraid-Standard-IO workflow target and secret coupling were remediated with a bounded scaffold check. Execution evidence remains required in Riverbraid-Standard-IO#2.
Riverbraid-Weave-Gold README versus Evaluation Kit registry mismatch was resolved and Riverbraid-Weave-Gold#2 was closed as documentation-only resolved.
Riverbraid-Security-Gold, Riverbraid-Storage-Gold, Riverbraid-Bridge-Gold, Riverbraid-Bio-Gold, and Riverbraid-Flow-Gold README surfaces were expanded to the Phase 4 boundary pattern.
- Several repos rely on package
license fields or README license text rather than root LICENSE files. This remains part of the focused license audit.
- Several workflows use
ubuntu-latest and tag-pinned actions. This is common but not maximum reproducibility hardening.
- Presence-check-only registry entries remain presence checks and are classified in
docs/VERIFICATION_DEPTH_CLASSIFICATION.md.
Search-limited non-findings
Search did not return visible hits in Batch C for common private key markers, GitHub token markers, AWS secret marker, npm token marker, pull_request_target, permissions: write-all, secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.
This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.
Required follow-up
- Run execution evidence for patched Types and Standard IO workflow targets.
- Decide whether presence-check repositories should remain support surfaces or receive fuller verifiers under a separate gate.
- Complete focused license audit.
- Populate readiness matrix with evidence.
- Preserve registry freshness lock until explicit registry succession gate exists.
Boundary
This issue records audit inventory only.
It does not claim Batch C is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.
Status
BATCH C AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED
Scope
Batch C covers the remaining Evaluation Kit registry listed repositories not covered in Batch A or Batch B:
Confirmed public entry strengths
verify.mjssamples exit nonzero when computed verification status is notVERIFIED.pull_request_target,permissions: write-all, pipe-to-shell patterns, or common nondeterminism markers.Current finding state
Riverbraid-TypesREADME, package BOM issue, workflow target, and workflow secret coupling were remediated. Execution evidence remains required inRiverbraid-Types#2.Riverbraid-Standard-IOworkflow target and secret coupling were remediated with a bounded scaffold check. Execution evidence remains required inRiverbraid-Standard-IO#2.Riverbraid-Weave-GoldREADME versus Evaluation Kit registry mismatch was resolved andRiverbraid-Weave-Gold#2was closed as documentation-only resolved.Riverbraid-Security-Gold,Riverbraid-Storage-Gold,Riverbraid-Bridge-Gold,Riverbraid-Bio-Gold, andRiverbraid-Flow-GoldREADME surfaces were expanded to the Phase 4 boundary pattern.licensefields or README license text rather than root LICENSE files. This remains part of the focused license audit.ubuntu-latestand tag-pinned actions. This is common but not maximum reproducibility hardening.docs/VERIFICATION_DEPTH_CLASSIFICATION.md.Search-limited non-findings
Search did not return visible hits in Batch C for common private key markers, GitHub token markers, AWS secret marker, npm token marker,
pull_request_target,permissions: write-all,secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.
Required follow-up
Boundary
This issue records audit inventory only.
It does not claim Batch C is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.