Skip to content

docs: add faithful RUST-SPARK-STANCE.adoc#16

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/rust-spark-stance-2026-05-18
May 20, 2026
Merged

docs: add faithful RUST-SPARK-STANCE.adoc#16
hyperpolymath merged 1 commit into
mainfrom
docs/rust-spark-stance-2026-05-18

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Records the existing Idris2+Zig ABI seam (src/abi/*.idr + ffi/zig/) and SPARK/Ada admission path honestly. Seam was present but undocumented (silent-regress risk per estate audit). No proof escapes in the corpus; honest gaps (Zig template placeholders, Idris2 not in CI, owed octad invariants) recorded explicitly.

Refs hyperpolymath/standards#124

Records the existing Idris2+Zig ABI seam (src/abi/*.idr + ffi/zig/) and
SPARK/Ada admission path honestly. Seam was present but undocumented
(silent-regress risk per estate audit). No proof escapes in the corpus;
honest gaps (Zig template placeholders, Idris2 not in CI, owed octad
invariants) recorded explicitly.

Refs hyperpolymath/standards#124

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit 97ebe88 into main May 20, 2026
11 of 21 checks passed
@hyperpolymath
hyperpolymath deleted the docs/rust-spark-stance-2026-05-18 branch May 20, 2026 21:29
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 120 issues detected

Severity Count
🔴 Critical 18
🟠 High 64
🟡 Medium 38

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Stale AI task file -- delete or move to docs/",
    "type": "stale",
    "file": "SONNET-TASKS.md",
    "action": "delete",
    "rule_module": "root_hygiene",
    "severity": "high"
  },
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in security-policy.yml",
    "type": "missing_workflow",
    "file": "security-policy.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Action hyperpolymath/panic-attacker/.github/workflows/scan-and-report.yml@main needs attention",
    "type": "unpinned_action",
    "file": "security-scan.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "binary_to_term without :safe option -- deserialization attack (1 occurrences, CWE-502)",
    "type": "elixir_send_unsanitised",
    "file": "/home/runner/work/verisimdb/verisimdb/lib/verisim/query_cache.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "binary_to_term without :safe option -- deserialization attack (1 occurrences, CWE-502)",
    "type": "elixir_send_unsanitised",
    "file": "/home/runner/work/verisimdb/verisimdb/lib/verisim/query_planner_config.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "String.to_existing_atom with user input exhausts atom table -- use to_existing_atom (1 occurrences, CWE-400)",
    "type": "elixir_atom_from_user",
    "file": "/home/runner/work/verisimdb/verisimdb/elixir-orchestration/lib/verisim/query/vql_type_checker.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "HTTP URL in code -- use HTTPS for non-localhost (1 occurrences, CWE-319)",
    "type": "js_http_url_in_code",
    "file": "/home/runner/work/verisimdb/verisimdb/connectors/test-infra/seed/mongodb-init.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "getExn on external data -- use pattern matching (1 occurrences, CWE-754)",
    "type": "getexn_on_external",
    "file": "/home/runner/work/verisimdb/verisimdb/src/registry/Registry.res",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant