|
| 1 | +<!-- |
| 2 | +SPDX-License-Identifier: MPL-2.0 |
| 3 | +SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) |
| 4 | +--> |
| 5 | + |
| 6 | +# Changelog |
| 7 | + |
| 8 | +All notable changes to `hypatia` will be documented in this file. |
| 9 | + |
| 10 | +This file is generated from conventional commits by the |
| 11 | +[`changelog-reusable.yml`](https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml) |
| 12 | +workflow (`hyperpolymath/standards#206`). Adopt the workflow in this repo's CI to keep this file in sync automatically — see |
| 13 | +[`templates/cliff.toml`](https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml) |
| 14 | +for the canonical config. |
| 15 | + |
| 16 | +The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); |
| 17 | +this project aims to follow [Semantic Versioning](https://semver.org/spec/v2.0.0.html). |
| 18 | + |
| 19 | +## [Unreleased] |
| 20 | + |
| 21 | +### Added |
| 22 | + |
| 23 | +- feat(rules): AffineScript hand-port pitfalls — HANDLE-as-fn-name + OCaml float ops (#332) |
| 24 | +- feat(rules): wire 4 new rule modules through the facade (#326) |
| 25 | +- feat(rules): ResearchExtensions (RE001-RE010) — 10 rules from Snyk/StepSecurity/Endor/academic literature (#325) |
| 26 | +- feat(rules): BranchProtection (BP001-BP007) — 7 rules from CIS GH / Scorecard / NIST SSDF (#323) |
| 27 | +- feat(rules): SupplyChain (SC001-SC011) — 11 rules from Scorecard/SLSA/OWASP/Endor (#322) |
| 28 | +- feat(rules): WorkflowHardening (WH001-WH012) — 12 rules from actionlint/zizmor/literature (#321) |
| 29 | +- feat(rules): BaselineHealth BH004-BH007 — four follow-on baseline-rot detectors (#320) |
| 30 | +- feat(rules): BuildSystemRules — cross-repo lint from affinescript#361 (#317) |
| 31 | +- feat(rules): lang-policy refresh 2026-05-25 — ban ReScript, retarget TS, reject MPL-1.0 (#318) |
| 32 | +- feat(rules): BaselineHealth (BH001-BH003) — detect red-baseline conditions estate-wide (#316) |
| 33 | + |
| 34 | +### Fixed |
| 35 | + |
| 36 | +- fix(supply_chain): replace exponential Levenshtein with iterative DP (#329) |
| 37 | +- fix(code_scanning_alerts): break CSA001 self-referential echo loop (#328) |
| 38 | +- fix(self): clear 113 dogfood findings — exempt fixtures + harden 9 prod unwraps (#324) |
| 39 | +- fix(pkg): retire Nix-mirror per Guix-primary ruling (standards#101) (#289) |
| 40 | +- fix(governance)!: banned_language ban is total — no exceptions (#280) |
| 41 | +- fix(reconcile): --verify no longer crashes JSON-encoding its result (#272) |
| 42 | +- fix(scanner): rebuild stale escript to prevent silent false negatives (#278) |
| 43 | +- fix(neural): wire LearningScheduler→force_cycle + RBF restore at init (#275) |
| 44 | +- fix(ci): bump a2ml/k9-validate-action pins to canonical (#269) |
| 45 | +- fix(ci): sync hypatia-scan.yml to canonical (#268) |
| 46 | + |
| 47 | +### Documentation |
| 48 | + |
| 49 | +- docs: second-pass bucketing — security/, standards/, specs/ (#319) |
| 50 | +- docs: tidy root + adopt rsr-template-repo doc taxonomy (#315) |
| 51 | +- docs(arch): add as-built MOF M2 metamodel + TOGAF overview (#273 gap 4) (#291) |
| 52 | +- docs(arch): add boundary-design-options.adoc (#273 gap 2, decision-ready) (#295) |
| 53 | + |
| 54 | +### CI |
| 55 | + |
| 56 | +- ci: dedupe scheduled-cron triggers + drop dead branch refs in tests.yml + verify-proofs.yml (#331) |
| 57 | +- ci: redistribute concurrency-cancel guard to read-only check workflows (#277) |
| 58 | +- ci(secret-scanner): drop duplicate --fail from trufflehog extra_args (#227) |
| 59 | +- ci(gossamer): cover all test/gossamer/*.test.mjs in loader-smoke (#225) |
| 60 | + |
| 61 | +## Pre-history |
| 62 | + |
| 63 | +Prior commits to this file's introduction are recorded in git history but not formally classified into Keep-a-Changelog sections. To backfill, run `git cliff -o CHANGELOG.md` locally using the canonical [`cliff.toml`](https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml) — this is one-shot mechanical work. |
| 64 | + |
| 65 | +--- |
| 66 | + |
| 67 | +<!-- This file was seeded by the 2026-05-26 estate tech-debt audit follow-up (Row-2 Phase 3); see [`hyperpolymath/standards/docs/audits/2026-05-26-estate-documentation-debt.md`](https://github.com/hyperpolymath/standards/blob/main/docs/audits/2026-05-26-estate-documentation-debt.md). --> |
0 commit comments