Skip to content

Consistency audit compliance

Which project currently meets which criterion. This page is regenerated weekly by the consistency audit workflow and committed by it, and it is the only generated file in docs/audits/ -- every criterion specification beside it is hand-written and changes only when a person changes it.

Read a table here together with the criterion it belongs to. The table says who passes and which issue tracks each failure; the specification says what is checked and why, what the check deliberately does not cover, and which template implements it, and is what to read first when picking up an issue. README.md indexes them all.

The generation timestamp below is load-bearing. When a run fails it leaves the previous run's verdicts in place, so this page goes on looking healthy while being stale -- check the date before trusting a verdict. The audit runs at 18:00 UTC every Sunday and can be dispatched by hand in between, so a timestamp older than the most recent Sunday 18:00 UTC means the last scheduled run failed, however many manual runs came before it. See ../consistency-audits.md for what a run does.

Generated 2026-10-07T03:03:29.543621+00:00 from scripts/audit-check.py; do not edit.

ci-review-automation

Criterion: ci-review-automation.md

Project Status Issue
actions compliant -
agent-python non-compliant agent-python#145
client-python non-compliant client-python#408
client-python-k3s compliant -
clingwrap non-compliant clingwrap#121
cloudgood non-compliant cloudgood#1
development compliant -
divergulent non-compliant divergulent#120
hunkydory compliant -
images N/A -
instar non-compliant instar#599
kerbside compliant -
kerbside-client non-compliant kerbside-client#5
kerbside-patches compliant -
library-utilities non-compliant library-utilities#62
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui non-compliant sfui#26
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#16
visual-digest-rust compliant -

Details for non-compliant projects:

  • agent-python (Status): pr-re-review.yml: the confirm step is conditional (if: steps.ref.outputs.merged == 'true'), so at least one checkout path goes unconfirmed; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request
  • client-python (Status): pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request
  • clingwrap (Status): pr-re-review.yml does not use shakenfist/actions/pr-bot-trigger@main, so it hand-rolls the trigger handling and does not inherit the action's fork pull request guard; pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request; the retired comment addresser is still deployed (.github/workflows/pr-address-comments.yml, tools/address-comments-with-claude.sh, tools/render-review.py, tools/review-schema.json); it is unused, and its workflow holds contents: write on the pull request branch
  • cloudgood (Status): Missing workflows: pr-re-review.yml
  • divergulent (Status): pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request
  • instar (Status): pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request
  • kerbside-client (Status): Missing pr-re-review.yml; Missing pr-retest.yml; No workflow uses shared action review-pr-with-claude@main
  • library-utilities (Status): pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request
  • sfui (Status): pr-re-review.yml does not use shakenfist/actions/pr-bot-trigger@main, so it hand-rolls the trigger handling and does not inherit the action's fork pull request guard; pr-re-review.yml does not confirm that the tree it checked out is the commit it resolved, so a push between the two is reviewed with no warning; pr-retest.yml: job trigger-retest does not export pr-bot-trigger's same-repo output, so the job that needs it cannot require a same-repository pull request; the retired comment addresser is still deployed (.github/workflows/pr-address-comments.yml, tools/address-comments-with-claude.sh, tools/render-review.py); it is unused, and its workflow holds contents: write on the pull request branch
  • uncalibrated-sextant (Status): Missing pr-re-review.yml; Missing pr-retest.yml; No workflow uses shared action review-pr-with-claude@main

console-logging

Criterion: console-logging.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

default-branch-naming

Criterion: default-branch-naming.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

delete-branch-on-merge

Criterion: delete-branch-on-merge.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#9
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#21
visual-digest-rust compliant -

Details for non-compliant projects:

  • kerbside-client (Status): Delete branch on merge is not enabled
  • uncalibrated-sextant (Status): Delete branch on merge is not enabled

dependency-name-normalization

Criterion: dependency-name-normalization.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

diagram-format

Criterion: diagram-format.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#126
cloudgood non-compliant cloudgood#9
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): 1 diagram(s) drawn in ASCII rather than mermaid (convert them, or mark a block that is genuinely better drawn by hand with an "audit-ok: diagram-format" comment above the fence): ARCHITECTURE.md:21
  • cloudgood (Status): 1 diagram(s) drawn in ASCII rather than mermaid (convert them, or mark a block that is genuinely better drawn by hand with an "audit-ok: diagram-format" comment above the fence): docs/memory-mapped-devices.md:729

Criterion: docs-external-links.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood non-compliant cloudgood#7
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar non-compliant instar#596
kerbside compliant -
kerbside-client N/A -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#7
visual-digest-rust compliant -

Details for non-compliant projects:

  • cloudgood (Status): 2 relative link(s) in docs/ that do not resolve to a file inside docs/ (use absolute https://github.com/... URLs, which survive the docs site import): docs/index.md -> more-fundamentals.md, docs/virtualization-history.md -> more-fundamentals.md
  • instar (Status): 1 relative link(s) in docs/ that do not resolve to a file inside docs/ (use absolute https://github.com/... URLs, which survive the docs site import): docs/plans/PLAN-differencing-phase-08-tests.md -> docs/plans/PLAN-differencing.md
  • uncalibrated-sextant (Status): 67 relative link(s) in docs/ that do not resolve to a file inside docs/ (use absolute https://github.com/... URLs, which survive the docs site import): docs/plans/PLAN-audit-cleanup-phase-02-structural.md -> ../../src/bootloader.rs, docs/plans/PLAN-audit-cleanup-phase-02-structural.md -> ../../src/renderer/mod.rs, docs/plans/PLAN-audit-cleanup-phase-02-structural.md -> ../../src/scene.rs, docs/plans/PLAN-audit-cleanup-phase-03-tests.md -> ../../Makefile, docs/plans/PLAN-audit-cleanup-phase-03-tests.md -> ../../scripts/screenshot.sh, docs/plans/PLAN-audit-cleanup-phase-03-tests.md -> ../../scripts/verify-release.sh, docs/plans/PLAN-audit-cleanup-phase-03-tests.md -> ../../src/scene.rs, docs/plans/PLAN-audit-cleanup.md -> ../../AGENTS.md, docs/plans/PLAN-audit-cleanup.md -> ../../ARCHITECTURE.md, docs/plans/PLAN-audit-cleanup.md -> ../../PUSH-AUDIT.md (+57 more)

docs-line-references

Criterion: docs-line-references.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar non-compliant instar#636
kerbside compliant -
kerbside-client compliant -
kerbside-patches non-compliant kerbside-patches#1839
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll non-compliant ryll#468
sfui compliant -
shakenfist non-compliant shakenfist#4481
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • instar (Status): 9 line(s) in the documentation cite code by line number, which goes stale on the next edit to that code (name the function or class instead, or use a GitHub permalink pinned to a commit sha): docs/quirks.md:4463, docs/quirks.md:4465, docs/quirks.md:4573, docs/quirks.md:4574, docs/quirks.md:4596, docs/quirks.md:4597, docs/quirks.md:4700, docs/resize.md:200, docs/resize.md:203
  • kerbside-patches (Status): 1 line(s) in the documentation cite code by line number, which goes stale on the next edit to that code (name the function or class instead, or use a GitHub permalink pinned to a commit sha): docs/kolla-ansible-tempest-jobs.md:71
  • ryll (Status): 25 line(s) in the documentation cite code by line number, which goes stale on the next edit to that code (name the function or class instead, or use a GitHub permalink pinned to a commit sha): docs/libvirt-spice-recommendations.md:103, docs/libvirt-spice-recommendations.md:255, docs/libvirt-spice-recommendations.md:450, docs/libvirt-spice-recommendations.md:456, docs/multi-mode-parity.md:83, docs/multi-mode-parity.md:84, docs/multi-mode-parity.md:88, docs/multi-mode-parity.md:89, docs/multi-mode-parity.md:90, docs/multi-mode-parity.md:92 (+15 more)
  • shakenfist (Status): 5 line(s) in the documentation cite code by line number, which goes stale on the next edit to that code (name the function or class instead, or use a GitHub permalink pinned to a commit sha): docs/operator_guide/agent_operations.md:41, docs/operator_guide/agent_operations.md:48, docs/operator_guide/agent_operations.md:62, docs/operator_guide/agent_operations.md:147, docs/operator_guide/agent_operations.md:160

eol-distro

Criterion: eol-distro.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images compliant -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

eol-producers

Criterion: eol-producers.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci compliant -
ryll N/A -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

expensive-lane-path-filter

Criterion: expensive-lane-path-filter.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#118
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui non-compliant sfui#14
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): 1 expensive lane(s) triggered by pull_request or merge_group without adequate path filtering: functional-tests.yml (no path filtering). Add a check_paths filter job (see kerbside functional-tests.yml) or, only for workflows backing no required status check, trigger-level paths-ignore, excluding docs/** and the review-tracking files; mark deliberate exceptions with an "audit-ok: no-path-filter" comment
  • sfui (Status): 1 expensive lane(s) triggered by pull_request or merge_group without adequate path filtering: functional-tests.yml (filter does not exclude docs/). Add a check_paths filter job (see kerbside functional-tests.yml) or, only for workflows backing no required status check, trigger-level paths-ignore, excluding docs/** and the review-tracking files; mark deliberate exceptions with an "audit-ok: no-path-filter" comment

export-repo-config

Criterion: export-repo-config.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood non-compliant cloudgood#3
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#7
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#19
visual-digest-rust compliant -

Details for non-compliant projects:

  • cloudgood (Status): Missing .github/workflows/export-repo-config.yml
  • kerbside-client (Status): Missing .github/workflows/export-repo-config.yml
  • uncalibrated-sextant (Status): Missing .github/workflows/export-repo-config.yml

fuzz-nightly-reporting

Criterion: fuzz-nightly-reporting.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar compliant -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

github-security

Criterion: github-security.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood non-compliant cloudgood#5
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#8
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#20
visual-digest-rust compliant -

Details for non-compliant projects:

  • cloudgood (Status): Secret scanning not enabled; Secret scanning push protection not enabled
  • kerbside-client (Status): Missing .github/workflows/codeql-analysis.yml; Secret scanning not enabled; Secret scanning push protection not enabled
  • uncalibrated-sextant (Status): Missing .github/workflows/codeql-analysis.yml; Secret scanning not enabled; Secret scanning push protection not enabled

llm-context-lint-ci

Criterion: llm-context-lint-ci.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#120
cloudgood non-compliant cloudgood#8
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui non-compliant sfui#25
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#6
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): skillsaw does not run from .pre-commit-config.yaml or a CI workflow
  • cloudgood (Status): skillsaw does not run from .pre-commit-config.yaml or a CI workflow
  • sfui (Status): skillsaw does not run from .pre-commit-config.yaml or a CI workflow
  • uncalibrated-sextant (Status): skillsaw does not run from .pre-commit-config.yaml or a CI workflow

llm-context-lint

Criterion: llm-context-lint.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

llm-doc-naming

Criterion: llm-doc-naming.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python non-compliant client-python#406
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • client-python (Status): 1 agent instruction file is named for a single tool rather than AGENTS.md (CLAUDE.md); AGENTS.md is tracked beside it, so it is a second set of instructions loaded with equal authority: merge what is still true into AGENTS.md and delete the original

llm-doc-structure

Criterion: llm-doc-structure.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

llm-tooling

Criterion: llm-tooling.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#1
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • kerbside-client (Status): Missing: AGENTS.md, ARCHITECTURE.md

merge-group-cancellation

Criterion: merge-group-cancellation.md

Project Status Issue
actions compliant -
agent-python N/A -
client-python N/A -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

merge-queue-config

Criterion: merge-queue-config.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

mermaid-lint-ci

Criterion: mermaid-lint-ci.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent N/A -
hunkydory N/A -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

npm-pin-indirect-dependencies

Criterion: npm-pin-indirect-dependencies.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory compliant -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

npm-undeclared-direct-dependency

Criterion: npm-undeclared-direct-dependency.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory compliant -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

npm-unused-declared-dependency

Criterion: npm-unused-declared-dependency.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory compliant -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

pin-indirect-dependencies

Criterion: pin-indirect-dependencies.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

plan-audit-phase

Criterion: plan-audit-phase.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python compliant -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory N/A -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#10
visual-digest-rust N/A -

Details for non-compliant projects:

  • uncalibrated-sextant (Status): 5 of 5 incomplete master plan(s) do not end with a phase running PUSH-AUDIT.md, which the plan-push-audit-phase shared block requires; each is named with the fix it needs: PLAN-locked-bootloader.md (no push audit phase; phase 3 is "3. Iteration, documentation, inventory closeout"), PLAN-display-mode-keystrokes.md (no push audit phase; phase 3 is "3. Iteration against ryll display-mode-ui, documentation,..."), PLAN-audit-cleanup.md (no push audit phase; phase 3 is "3. Test coverage and release verification"), PLAN-visual-digest.md (no push audit phase; phase 3 is "3. Repaint integration, format spec, closeout"), PLAN-continuous-digest.md (no push audit phase; phase 3 is "3. Docs, decoder coordination, closeout"); 2 plan(s) with no phases this check can read, not judged: PLAN-language-probes.md, PLAN-headless-readback-bug.md

plan-index

Criterion: plan-index.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python compliant -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory N/A -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client N/A -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci compliant -
ryll compliant -
sfui non-compliant sfui#24
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#9
visual-digest-rust N/A -

Details for non-compliant projects:

  • sfui (Status): docs/plans/index.md is missing, so none of the 3 plan(s) in docs/plans/ are registered
  • uncalibrated-sextant (Status): 7 status cell(s) outside the shared vocabulary (Proposed, Not started, In progress, Blocked, Complete, Abandoned, Superseded): Locked bootloader ("Complete (commits a7b261d through thi..."), Display-mode keystrokes ("Complete (commits 455d2b5 through thi..."), Audit cleanup ("Complete (commits 1482eb0 through thi..."), Visual on-screen digest ("Complete (commits 55844a5 through thi..."), Continuous multi-channel visual digest ("Complete (commits 8814fab through thi...") (+2 more)

plan-phase-references

Criterion: plan-phase-references.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python non-compliant client-python#382
client-python-k3s compliant -
clingwrap compliant -
cloudgood compliant -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar non-compliant instar#605
kerbside compliant -
kerbside-client compliant -
kerbside-patches non-compliant kerbside-patches#1826
library-utilities compliant -
occystrap compliant -
private-ci non-compliant private-ci#64
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#8
visual-digest-rust compliant -

Details for non-compliant projects:

  • client-python (Status): 1 plan phase reference(s) in documentation (describe the current behaviour, or link the master plan in docs/plans/ instead of citing a phase number): AGENTS.md:121
  • instar (Status): 1 plan phase reference(s) in documentation (describe the current behaviour, or link the master plan in docs/plans/ instead of citing a phase number): docs/development.md:1052
  • kerbside-patches (Status): 1 plan phase reference(s) in documentation (describe the current behaviour, or link the master plan in docs/plans/ instead of citing a phase number): ARCHITECTURE.md:67
  • private-ci (Status): 57 plan phase reference(s) in documentation (describe the current behaviour, or link the master plan in docs/plans/ instead of citing a phase number): docs/action-items-order.md:19, docs/dashboard-freshness.md:84, docs/dashboard-freshness.md:132, docs/dashboard-freshness.md:133, docs/dashboard-freshness.md:197, docs/dashboard-freshness.md:241, docs/dashboard-freshness.md:272, docs/dashboard-freshness.md:299, docs/dashboard-freshness.md:311, docs/dashboard-freshness.md:317 (+47 more)
  • uncalibrated-sextant (Status): 22 plan phase reference(s) in documentation (describe the current behaviour, or link the master plan in docs/plans/ instead of citing a phase number): AGENTS.md:104, AGENTS.md:126, AGENTS.md:145, ARCHITECTURE.md:3, ARCHITECTURE.md:10, ARCHITECTURE.md:16, ARCHITECTURE.md:29, ARCHITECTURE.md:44, ARCHITECTURE.md:137, ARCHITECTURE.md:236 (+12 more)

plan-source-references

Criterion: plan-source-references.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python non-compliant client-python#403
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory N/A -
images N/A -
instar non-compliant instar#606
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci compliant -
ryll compliant -
sfui N/A -
shakenfist non-compliant shakenfist#4397
uncalibrated-sextant compliant -
visual-digest-rust N/A -

Details for non-compliant projects:

  • client-python (Status): 2 of 4 plan reference(s) in source or configuration do not resolve (update the path, or use an absolute https://github.com/... URL for a plan in another repository): shakenfist_client/apiclient.py:185 -> docs/plans/PLAN-transient-capacity-refusals-phase-04-retry-after.md, shakenfist_client/tests/test_client_apiclient.py:2320 -> docs/plans/PLAN-transient-capacity-refusals-phase-04-retry-after.md
  • instar (Status): 2 of 243 plan reference(s) in source or configuration do not resolve (update the path, or use an absolute https://github.com/... URL for a plan in another repository): tools/ci/test-check-doc-phrases.sh:43 -> PLAN-differencingflow.md, tools/ci/test-check-doc-phrases.sh:142 -> /docs/plans/PLAN-example.md
  • shakenfist (Status): 3 of 367 plan reference(s) in source or configuration do not resolve (update the path, or use an absolute https://github.com/... URL for a plan in another repository): shakenfist/mariadb.py:3656 -> PLAN-claim-coverage-and-sizing-phase-02b-peak-measurement.md, shakenfist/tests/test_plan_phase_references.py:86 -> docs/plans/PLAN-thing.md, shakenfist/tests/test_plan_phase_references.py:88 -> docs/other/plans/PLAN-deep.md

plan-template

Criterion: plan-template.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent non-compliant divergulent#127
hunkydory N/A -
images N/A -
instar non-compliant instar#637
kerbside non-compliant kerbside#532
kerbside-client N/A -
kerbside-patches non-compliant kerbside-patches#1840
library-utilities N/A -
occystrap non-compliant occystrap#157
private-ci non-compliant private-ci#76
ryll non-compliant ryll#469
sfui N/A -
shakenfist non-compliant shakenfist#4482
uncalibrated-sextant non-compliant uncalibrated-sextant#12
visual-digest-rust N/A -

Details for non-compliant projects:

  • divergulent (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • instar (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • kerbside (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • kerbside-patches (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • occystrap (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • private-ci (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current); missing shared block plan-phase-landing (copy it verbatim from templates/shared-blocks/plan-phase-landing.md in the development repository)
  • ryll (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • shakenfist (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current)
  • uncalibrated-sextant (Status): shared block plan-file-conventions is stale (v1 embedded, v2 current); missing shared block plan-status-vocabulary (copy it verbatim from templates/shared-blocks/plan-status-vocabulary.md in the development repository); missing shared block plan-push-audit-phase (copy it verbatim from templates/shared-blocks/plan-push-audit-phase.md in the development repository); missing shared block plan-phase-landing (copy it verbatim from templates/shared-blocks/plan-phase-landing.md in the development repository)

push-audit

Criterion: push-audit.md

Project Status Issue
actions compliant -
agent-python N/A -
client-python N/A -
client-python-k3s compliant -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar non-compliant instar#597
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui non-compliant sfui#15
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#11
visual-digest-rust N/A -

Details for non-compliant projects:

  • instar (Status): missing shared block plan-references-in-code (copy it verbatim from templates/shared-blocks/plan-references-in-code.md in the development repository)
  • sfui (Status): missing shared block llm-doc-discipline (copy it verbatim from templates/shared-blocks/llm-doc-discipline.md in the development repository); missing shared block diagram-discipline (copy it verbatim from templates/shared-blocks/diagram-discipline.md in the development repository); missing shared block source-file-size (copy it verbatim from templates/shared-blocks/source-file-size.md in the development repository); missing shared block plan-references-in-code (copy it verbatim from templates/shared-blocks/plan-references-in-code.md in the development repository); missing shared block plan-phase-references (copy it verbatim from templates/shared-blocks/plan-phase-references.md in the development repository); missing shared block path-traversal-review (copy it verbatim from templates/shared-blocks/path-traversal-review.md in the development repository); missing shared block python-version-discipline (copy it verbatim from templates/shared-blocks/python-version-discipline.md in the development repository); missing shared block functional-test-coverage (copy it verbatim from templates/shared-blocks/functional-test-coverage.md in the development repository); AGENTS.md does not reference PUSH-AUDIT.md (an audit nothing points at does not get run)
  • uncalibrated-sextant (Status): missing shared block llm-doc-discipline (copy it verbatim from templates/shared-blocks/llm-doc-discipline.md in the development repository); missing shared block diagram-discipline (copy it verbatim from templates/shared-blocks/diagram-discipline.md in the development repository); missing shared block comment-proportion (copy it verbatim from templates/shared-blocks/comment-proportion.md in the development repository); missing shared block source-file-size (copy it verbatim from templates/shared-blocks/source-file-size.md in the development repository); missing shared block plan-references-in-code (copy it verbatim from templates/shared-blocks/plan-references-in-code.md in the development repository); missing shared block plan-phase-references (copy it verbatim from templates/shared-blocks/plan-phase-references.md in the development repository); missing shared block path-traversal-review (copy it verbatim from templates/shared-blocks/path-traversal-review.md in the development repository); missing shared block python-version-discipline (copy it verbatim from templates/shared-blocks/python-version-discipline.md in the development repository); missing shared block functional-test-coverage (copy it verbatim from templates/shared-blocks/functional-test-coverage.md in the development repository); AGENTS.md does not reference PUSH-AUDIT.md (an audit nothing points at does not get run)

pyproject-usage

Criterion: pyproject-usage.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client non-compliant kerbside-client#3
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Details for non-compliant projects:

  • kerbside-client (Status): 6 Python file(s) but no pyproject.toml

python-version

Criterion: python-version.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Criterion: readme-absolute-links.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#108
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): 5 relative link target(s) in README.md (use absolute URLs so the README renders off the repo landing page): AGENTS.md, ARCHITECTURE.md, RELEASE-SETUP.md, docs/, docs/index.md

readme-structure

Criterion: readme-structure.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

release-process

Criterion: release-process.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

renovate-lockstep-groups

Criterion: renovate-lockstep-groups.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

renovate

Criterion: renovate.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#117
cloudgood non-compliant cloudgood#2
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#2
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#13
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): renovate.json does not enable the pre-commit manager, so the hook revisions in .pre-commit-config.yaml are unmanaged and drift silently
  • cloudgood (Status): Missing: .github/workflows/renovate.yml, renovate.json
  • kerbside-client (Status): Missing: .github/workflows/renovate.yml, renovate.json
  • uncalibrated-sextant (Status): Missing: .github/workflows/renovate.yml, renovate.json

reusable-workflow-secrets

Criterion: reusable-workflow-secrets.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant compliant -
visual-digest-rust compliant -

review-coverage

Criterion: review-coverage.md

Project Status Issue
actions non-compliant actions#138
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent N/A -
hunkydory compliant -
images N/A -
instar N/A -
kerbside non-compliant kerbside#227
kerbside-client non-compliant kerbside-client#12
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll non-compliant ryll#456
sfui non-compliant sfui#42
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Details for non-compliant projects:

  • actions (Status): 130 of 140 in-scope files reviewed at HEAD (4 imported from shakenfist/development); 10 need review (threshold 5)
  • kerbside (Status): 137 of 254 in-scope files reviewed at HEAD (4 imported from shakenfist/development); 117 need review (threshold 5)
  • kerbside-client (Status): 3 of 15 in-scope files reviewed at HEAD (3 imported from shakenfist/development); 12 need review (threshold 5)
  • ryll (Status): 215 of 224 in-scope files reviewed at HEAD (2 imported from shakenfist/development); 9 need review (threshold 5)
  • sfui (Status): 3 of 52 in-scope files reviewed at HEAD (3 imported from shakenfist/development); 49 need review (threshold 5)

review-scope-completeness

Criterion: review-scope-completeness.md

Project Status Issue
actions compliant -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent N/A -
hunkydory compliant -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client compliant -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

rust-unwrap-lint

Criterion: rust-unwrap-lint.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar compliant -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant non-compliant uncalibrated-sextant#14
visual-digest-rust compliant -

Details for non-compliant projects:

  • uncalibrated-sextant (Status): clippy unwrap_used lint not set to warn or deny in Cargo.toml; clippy.toml missing allow-unwrap-in-tests = true

scheduled-workflow-health

Criterion: scheduled-workflow-health.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client compliant -
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist non-compliant shakenfist#4369
uncalibrated-sextant compliant -
visual-digest-rust compliant -

Details for non-compliant projects:

  • shakenfist (Status): 1 workflow(s) that fire unattended have failed on develop at least 3 times and never once succeeded, so whatever they are meant to do has never happened. The usual cause is an installation that was not finished -- a missing secret, or an organisation secret not granted to this repository -- and the reason is in the log of the linked run

scope-coverage

Criterion: scope-coverage.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development compliant -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

secret-handling

Criterion: secret-handling.md

Project Status Issue
actions compliant -
agent-python compliant -
client-python compliant -
client-python-k3s compliant -
clingwrap non-compliant clingwrap#111
cloudgood N/A -
development compliant -
divergulent compliant -
hunkydory compliant -
images N/A -
instar compliant -
kerbside compliant -
kerbside-client non-compliant kerbside-client#11
kerbside-patches compliant -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui compliant -
shakenfist compliant -
uncalibrated-sextant non-compliant uncalibrated-sextant#18
visual-digest-rust compliant -

Details for non-compliant projects:

  • clingwrap (Status): No secret scanner in CI; expected one of gitleaks, trufflehog, detect-secrets in a workflow
  • kerbside-client (Status): No secret scanner in CI; expected one of gitleaks, trufflehog, detect-secrets in a workflow
  • uncalibrated-sextant (Status): No secret scanner in CI; expected one of gitleaks, trufflehog, detect-secrets in a workflow

security-sanitization

Criterion: security-sanitization.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside N/A -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap compliant -
private-ci N/A -
ryll compliant -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

sfui-vendor

Criterion: sfui-vendor.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside non-compliant kerbside#516
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci non-compliant private-ci#58
ryll non-compliant ryll#438
sfui N/A -
shakenfist N/A -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Details for non-compliant projects:

  • kerbside (Status): kerbside/api/static/sfui: 5 commit(s) behind canonical; re-run tools/vendor.sh from an up to date sfui checkout
  • private-ci (Status): conductor/static/sfui: 12 commit(s) behind canonical; re-run tools/vendor.sh from an up to date sfui checkout
  • ryll (Status): ryll/src/web/assets/sfui: 5 commit(s) behind canonical; re-run tools/vendor.sh from an up to date sfui checkout

undeclared-direct-dependency

Criterion: undeclared-direct-dependency.md

Project Status Issue
actions N/A -
agent-python N/A -
client-python N/A -
client-python-k3s N/A -
clingwrap N/A -
cloudgood N/A -
development N/A -
divergulent N/A -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities N/A -
occystrap N/A -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

unused-declared-dependency

Criterion: unused-declared-dependency.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python non-compliant client-python#383
client-python-k3s compliant -
clingwrap compliant -
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Details for non-compliant projects:

  • client-python (Status): Declared but never imported: chardet (pyproject.toml:23), pyyaml (pyproject.toml:27), requests_toolbelt (pyproject.toml:22). Remove each, or record why it is installed with a "# not-imported: -- " comment in the dependencies array

version-file-gitignore

Criterion: version-file-gitignore.md

Project Status Issue
actions N/A -
agent-python compliant -
client-python compliant -
client-python-k3s N/A -
clingwrap non-compliant clingwrap#106
cloudgood N/A -
development N/A -
divergulent compliant -
hunkydory N/A -
images N/A -
instar N/A -
kerbside compliant -
kerbside-client N/A -
kerbside-patches N/A -
library-utilities compliant -
occystrap compliant -
private-ci N/A -
ryll N/A -
sfui N/A -
shakenfist compliant -
uncalibrated-sextant N/A -
visual-digest-rust N/A -

Details for non-compliant projects:

  • clingwrap (Status): clingwrap/_version.py is not covered by .gitignore

workflow-standards

Criterion: workflow-standards.md

Project flake8wrap Runners Static tags VM size Permissions Linting devpi fallback devpi IP Review marks Issue
actions N/A compliant compliant compliant compliant compliant N/A compliant compliant -
agent-python compliant compliant compliant compliant compliant compliant N/A compliant N/A -
client-python compliant compliant compliant non-compliant compliant compliant N/A compliant N/A client-python#378
client-python-k3s compliant compliant compliant compliant compliant compliant N/A compliant N/A -
clingwrap compliant compliant compliant non-compliant compliant compliant N/A compliant N/A clingwrap#125
cloudgood N/A N/A N/A N/A N/A compliant N/A N/A N/A -
development N/A compliant compliant compliant compliant compliant N/A compliant N/A -
divergulent compliant compliant compliant compliant compliant compliant N/A compliant N/A -
hunkydory N/A compliant compliant compliant compliant compliant N/A compliant N/A -
images N/A N/A N/A N/A N/A N/A N/A N/A N/A -
instar N/A compliant compliant compliant compliant compliant N/A compliant N/A -
kerbside compliant compliant compliant compliant compliant compliant compliant compliant compliant -
kerbside-client non-compliant compliant compliant compliant compliant non-compliant N/A compliant N/A kerbside-client#4, kerbside-client#6
kerbside-patches N/A compliant compliant compliant compliant compliant N/A compliant N/A -
library-utilities compliant compliant compliant compliant compliant compliant N/A compliant N/A -
occystrap compliant compliant compliant compliant compliant compliant N/A compliant N/A -
private-ci N/A N/A N/A N/A N/A N/A N/A N/A N/A -
ryll N/A compliant compliant compliant compliant compliant N/A compliant N/A -
sfui N/A compliant compliant compliant compliant compliant compliant compliant compliant -
shakenfist compliant compliant compliant compliant compliant compliant compliant compliant N/A -
uncalibrated-sextant N/A non-compliant compliant compliant non-compliant compliant N/A compliant N/A uncalibrated-sextant#15, uncalibrated-sextant#17
visual-digest-rust N/A compliant compliant compliant compliant compliant N/A compliant N/A -

Details for non-compliant projects:

  • client-python (VM size): 3 "vm" runner job(s) naming no size: code-formatting.yml:19 (self-hosted, vm), functional-tests.yml:23 (self-hosted, vm), supply-chain.yml:81 (self-hosted, vm). The conductor takes the runner size from the labels and falls back to the first CI_SIZES entry -- "xs", one vCPU and 2048 MB -- when it finds none, so an omitted size is a silent downgrade to the smallest runner rather than a free choice. Add the size the job actually wants (xs/s/m/l/xl, or m-bigdisk/xl-bigdisk when the job needs the disk); "xs" is a valid answer stated explicitly. A job which genuinely cannot name one marks the line "audit-ok: vm-runner-size" with the reason
  • clingwrap (VM size): 1 "vm" runner job(s) naming no size: functional-tests.yml:22 (self-hosted, vm, debian-13). The conductor takes the runner size from the labels and falls back to the first CI_SIZES entry -- "xs", one vCPU and 2048 MB -- when it finds none, so an omitted size is a silent downgrade to the smallest runner rather than a free choice. Add the size the job actually wants (xs/s/m/l/xl, or m-bigdisk/xl-bigdisk when the job needs the disk); "xs" is a valid answer stated explicitly. A job which genuinely cannot name one marks the line "audit-ok: vm-runner-size" with the reason
  • kerbside-client (flake8wrap): Missing shellcheck disable=SC2086 directive
  • kerbside-client (Linting): Missing .pre-commit-config.yaml
  • uncalibrated-sextant (Runners): 1 unmarked GitHub-hosted runner reference(s): pre-commit.yml:10 (ubuntu-latest). Move to a self-hosted runner, or mark deliberate exceptions with an "audit-ok: github-hosted-runner" comment
  • uncalibrated-sextant (Permissions): 1 workflow(s) missing top-level permissions: pre-commit.yml

Criteria with no automated check

These criteria are written down and judged by a person, so they have no table above. Each says why in its own page:

📝 Report an issue with this page