Skip to content

Docs/bindings roadmap top50 - #441

Merged
hyperpolymath merged 4 commits into
mainfrom
docs/bindings-roadmap-top50
May 28, 2026
Merged

Docs/bindings roadmap top50#441
hyperpolymath merged 4 commits into
mainfrom
docs/bindings-roadmap-top50

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

No description provided.

hyperpolymath and others added 2 commits May 28, 2026 10:58
Adds three satellite roadmap documents under `docs/` and cross-links
them from the main ROADMAP.adoc:

* `docs/bindings-roadmap.adoc` — 50 framework bindings, 5 tiers
  (idaptik blockers → estate near-term → web universals →
  backend/cloud → tooling/interop). Compiled from idaptik PR #107
  + estate-wide binding-need inventory.

* `docs/stdlib-roadmap.adoc` — 50 stdlib items, 5 tiers (idaptik
  runtime gaps → RSR rewires → universals → concurrency/async →
  conformance/introspection). Includes inventory snapshot of the
  current `stdlib/` directory.

* `docs/alib-roadmap.adoc` — 25 items, 3 tracks (T1 conformance
  implementation, T2 runner/infrastructure, T3 affine-aware
  contributions back to `hyperpolymath/aggregate-library`). Aligned
  with aLib v0.1.0 (20 ops × 6 categories).

Main ROADMAP gains a new `== Satellite roadmaps` section near the
top and three See Also entries at the bottom. Where this set
disagrees with CAPABILITY-MATRIX.adoc or ECOSYSTEM.adoc, those win.

Per-tier tracking issues and the umbrella tracker will follow as
separate PRs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ket rule

The bindings-roadmap mentioned `ws://` as the URI scheme for a WebSocket
binding entry. Semgrep's `javascript.lang.security.detect-insecure-websocket`
rule scans prose + table cells and flagged this as a CI failure on PR#410.

Per estate-wide secure-protocols-in-docs policy (2026-05-28), all
transport schemes in authored content must default to the encrypted
variant. Updated the wording from "raw `ws://`" to "encrypted `wss://`".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath marked this pull request as ready for review May 28, 2026 20:40
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 82 issues detected

Severity Count
🔴 Critical 4
🟠 High 10
🟡 Medium 68

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action perpolymath/standards/.github/workflows/governance-reusable.yml@main\n needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action ons/checkout@v6\n    needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action land/setup-deno@v2\n    needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in affine-vscode-publish.yml",
    "type": "unknown",
    "file": "affine-vscode-publish.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "unknown",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "unknown",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 8ff1b6b into main May 28, 2026
15 of 18 checks passed
@hyperpolymath
hyperpolymath deleted the docs/bindings-roadmap-top50 branch May 28, 2026 20:45
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 82 issues detected

Severity Count
🔴 Critical 4
🟠 High 10
🟡 Medium 68

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action perpolymath/standards/.github/workflows/governance-reusable.yml@main\n needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action ons/checkout@v6\n    needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action land/setup-deno@v2\n    needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in affine-vscode-publish.yml",
    "type": "unknown",
    "file": "affine-vscode-publish.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "unknown",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "unknown",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in ci.yml",
    "type": "unknown",
    "file": "ci.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit that referenced this pull request Jul 7, 2026
…tale hypatia pin) (#679)

## Problem — every PR carries two red checks

1. **`analyze (actions, none)`** — CodeQL, and per the workflow's own
comment a **required** check:
   ```
##[error]Loaded a configuration file for version '4.36.2', but running
version '4.36.3'
   ```
Root cause: dependabot #670/#673 bumped `analyze`/`upload-sarif` to
v4.36.3 (`54f647b7`) but left **`init`** at v4.36.2 (`8aad20d1`) — a
partial bump (dependabot treats init/analyze as separate actions). init
writes a config the newer analyze rejects. The stale `# v3.28.1`
comments hid the split.

2. **`hypatia / Hypatia Neurosymbolic Analysis`** — `Cache not found for
input keys: hypatia-scanner-v2-… → exit 1`.
Root cause: the wrapper pinned the standards reusable at `d135b05` — the
known estate CI-red master-cause pin. Fixed upstream in standards
**#428** (GITHUB_TOKEN), **#441** (un-stale scanner cache — our exact
symptom), #445, #453.

## Fix (2 files, 3 lines)
- `codeql.yml`: `init` → `54f647b7 # v4.36.3` (same SHA as analyze);
comments corrected to the SHAs' real version.
- `hypatia-scan.yml`: reusable pin `d135b05` → `5fa7a834e` (#453, latest
commit touching the reusable).

YAML validated. This PR's own check run is the live test — `analyze
(actions, none)` and `hypatia` should both go green here.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant