SZL Holdings · Doctrine v11 · Λ = Conjecture 1 (advisory, never "green"/theorem) · canonical a-11-oy.com
Org-wide governance, reusable workflows, templates, and security policy for SZL Holdings.
| Path | Purpose |
|---|---|
profile/README.md |
Org profile shown at https://github.com/szl-holdings |
.github/ISSUE_TEMPLATE/ |
Default issue templates cascaded to every repo without its own |
.github/PULL_REQUEST_TEMPLATE.md |
Default PR template |
.github/workflows/ |
22 reusable workflows — see WORKFLOWS.md |
.github/dependabot.yml |
Weekly dependency updates for this repo |
.github/CODEOWNERS |
Org-default ownership |
templates/ |
Copy-paste templates for product repos (README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY) |
security.txt |
RFC 9116 disclosure record (canonical copy; deploy under /.well-known/security.txt) |
SECURITY.md · CONTRIBUTING.md · CODE_OF_CONDUCT.md · SUPPORT.md |
Org-default community docs |
CITATION.cff |
Citation metadata |
assets/social/ |
1280×640 social-preview banners ready for upload via Settings → General → Social preview |
Twenty-two SHA-pinned, harden-runner-protected workflows that every product repo can call:
jobs:
codeql:
uses: szl-holdings/.github/.github/workflows/reusable-codeql.yml@<commit-sha>CI & release
| Workflow | What it does |
|---|---|
reusable-node-ci.yml |
Node lint + typecheck + test + build matrix |
reusable-docs-ci.yml |
Markdown lint + link-check for docs repos |
reusable-release-please.yml |
Conventional-commits release automation |
Security & supply chain
| Workflow | What it does |
|---|---|
reusable-codeql.yml |
CodeQL static analysis (JS, TS, Python) |
reusable-dependency-review.yml |
Block PRs that introduce vulnerable or non-permissive deps |
reusable-trivy.yml |
Trivy filesystem vulnerability scan |
reusable-gitleaks.yml |
Gitleaks secret scanning on every PR / push |
reusable-secret-scan.yml |
TruffleHog verified committed-secret scan |
reusable-sbom.yml |
CycloneDX + SPDX SBOM per release |
reusable-scorecard.yml |
OpenSSF Scorecard re-run + badge publish |
reusable-workflow-lint.yml |
actionlint + zizmor lint on all workflows |
pin-check-reusable.yml |
Enforce 40-char SHA pinning on third-party Actions |
Deploy & drift
| Workflow | What it does |
|---|---|
reusable-hf-deploy.yml |
GitHub → Hugging Face Space deployer (Dockerfile-derived file set) |
reusable-hf-candidate-plan.yml |
Build an exact, provider-free base-to-head HF deployment plan and revalidate the live PR pair |
reusable-hf-module-drift-check.yml |
Detect drift between a repo's source and its live HF Space |
reusable-anatomy-map-drift.yml |
Guard the shared SZL Anatomy map across its surfaces |
reusable-bundle-ref-check.yml |
Verify UDS bundle repository/ref point at published GHCR tags |
reusable-lockfile-registry-check.yml |
Reject lockfiles pinned to sandbox-internal registries |
Doctrine honesty guards
| Workflow | What it does |
|---|---|
reusable-overclaim-guard.yml |
Doctrine overclaim guard (Λ / Conjecture-1 claims) |
reusable-energy-provenance-guard.yml |
Energy-provenance honesty guard (measured-or-UNAVAILABLE) |
reusable-receipt-shape-guard.yml |
Receipt-shape honesty guard for committed attestation data |
All Actions are SHA-pinned and wrapped with step-security/harden-runner using a deny-by-default egress policy. See WORKFLOWS.md for inputs, secrets, and per-workflow examples.
- Private vulnerability reporting: security policy
- Email:
security@szlholdings.com - Canonical RFC 9116 record:
security.txt - Org-wide: branch protection rulesets, exact-head provenance checks, CODEOWNERS, OpenSSF Scorecard
- This repository's live security status is authoritative only in GitHub's Dependabot, secret-scanning, and CodeQL dashboards; organization-wide alert state is not asserted here, and this README does not freeze alert counts.
- Conventional Commits (
feat:,fix:,chore:,docs:,ci:,refactor:,test:) - Squash-merge into
main; release automation handled byrelease-please - All PRs run reusable security suite before merge
Apache-2.0 for this repo. Product repos under SZL Holdings may use different licenses — see each repo's LICENSE.
© 2026 SZL Holdings — github.com/szl-holdings · ORCID 0009-0001-0110-4173
Two step-by-step Word guides for getting the SZL ecosystem running from zero — hardware to buy, tools to install, accounts to create, secrets to set, and how to sign, build, deploy and test the UDS bundles.
| Guide | What it covers | File |
|---|---|---|
| Environment Setup Guide | What to buy (3 hardware options), what to install (with links + one command each), accounts, secret keys, and a 10-step first-time setup | docs/SZL_ENVIRONMENT_SETUP_GUIDE.docx |
| UDS Run Guide | Sign the 5 unsigned bundles, build Zarf packages, spin up k3d, deploy, verify, cleanup, the 90-second Warhacker demo script, and the founder action queue | docs/SZL_UDS_RUN_GUIDE.docx |
Mirrored on Hugging Face: SZLHOLDINGS/doctrine-v11 under founder-guides/.
The SZL substrate repos cross-link reciprocally. Two live products (a11oy + killinchu) sit on one signed substrate.
a11oy— command platform; signed-receipt substrate with built-in reasoning, policy & operator capabilities (TypeScript packages, MCP server)killinchu— drones & vessels field tool; counter-UAS + maritime picture; DSSE receipt per engagementlutar-lean— Lean 4 + Mathlib proofs of the Λ aggregator (749 decl / 14 axioms / 163 sorries; 8 formulas proven {F1,F4,F7,F11,F12,F18,F19,F22}, Λ = Conjecture 1)szl-papers— DOI-pinned thesis lineage (v1 → v23)ouroboros— bounded-recursion runtimeplatform— composing monorepo for the substrate runtimeuds-mesh— UDS span schemas + governance receiptsuds-bundles·szl-mesh— signed, airgap-deployable mesh bundlehatun-mcp— doctrine-aware Model Context Protocol servervsp-otel— OpenTelemetry exporter for Λ-axis spansdevelopers·docs-site·szl-cookbook— build-on-SZL hub, docs & recipesszl-trust— public proof portal ·khipu-consensus— BFT witnessing
Org page: github.com/szl-holdings · Doctrine v11 · 14 unique axioms · 749 declarations · 163 sorries · DOI 10.5281/zenodo.20434276
The SZL Holdings orbit mark (szl-brand kanchay/ 1.1.1, CC BY 4.0).