Commit ffc1e0e
Pin the Julia supply chain and model the real trust boundaries (#35)
- Commit Manifest.toml (generated under Julia 1.10, same minor as e2e
CI) and stop ignoring it in .gitignore: the Julia layer computes every
number the product returns, so its transitive dependency graph is now
pinned by tree hash. CI's Pkg.instantiate/Pkg.test resolve from the
committed manifest by default — no workflow change needed.
- dependabot.yml: remove cargo/mix/npm/pip/nix entries — none of those
ecosystems exist in this Julia/Zig/Agda repo. Dependabot has no Julia
ecosystem; the committed Manifest + CI instantiate is the compensating
control. github-actions coverage kept.
- docs/THREAT-MODEL.md: add an Application-Specific Boundaries section
modelling the neural->symbolic boundary (LLM numeric fabrication, prompt
injection via user data, tool mis-routing, silent-null sub-types) and
the Zig FFI/C-ABI boundary (unvalidated inputs, memory safety, ABI
drift). Fix false claims: the Cargo.lock/deno.lock/gleam.toml asset row,
the nonexistent scorecard-enforcer.yml, and the "lockfiles committed"
mitigation (now true only for Manifest.toml).
PR 5 of 8 in the severity-ordered chain (fix/supply-chain-pinning).
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
-->
## Summary
<!-- Briefly describe what this PR does and why. Link to related issues
with "Closes #N". -->
## Changes
<!-- List the key changes introduced by this PR. -->
-
## RSR Quality Checklist
<!-- Check all that apply. PRs that fail required checks will not be
merged. -->
### Required
- [ ] Tests pass (`just test` or equivalent)
- [ ] Code is formatted (`just fmt` or equivalent)
- [ ] Linter is clean (no new warnings or errors)
- [ ] No banned language patterns (no TypeScript, no npm/bun, no
Go/Python)
- [ ] No `unsafe` blocks without `// SAFETY:` comments
- [ ] No banned functions (`believe_me`, `unsafeCoerce`, `Obj.magic`,
`Admitted`, `sorry`)
- [ ] SPDX license headers present on all new/modified source files
- [ ] No secrets, credentials, or `.env` files included
### As Applicable
- [ ] `.machine_readable/STATE.a2ml` updated (if project state changed)
- [ ] `.machine_readable/ECOSYSTEM.a2ml` updated (if integrations
changed)
- [ ] `.machine_readable/META.a2ml` updated (if architectural decisions
changed)
- [ ] Documentation updated for user-facing changes
- [ ] `TOPOLOGY.md` updated (if architecture changed)
- [ ] `CHANGELOG` or release notes updated
- [ ] New dependencies reviewed for license compatibility (MPL-2.0 /
MPL-2.0)
- [ ] ABI/FFI changes validated (`src/abi/` and `ffi/zig/` consistent)
## Testing
<!-- Describe how you tested these changes. -->
## Screenshots
<!-- If applicable, add screenshots or terminal output demonstrating the
change. -->
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 1549cfa commit ffc1e0e
4 files changed
Lines changed: 697 additions & 44 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
4 | 8 | | |
5 | 9 | | |
6 | 10 | | |
| |||
13 | 17 | | |
14 | 18 | | |
15 | 19 | | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
40 | 42 | | |
41 | 43 | | |
42 | 44 | | |
| |||
0 commit comments