You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Audit ceg-open-prs-2026-09-17, findings CEG-263-001 (INVARIANT, High) and CEG-263-002 (COMPLETENESS, High). Owner class HUMAN; semantic owner CEG constellation dependency policy. Filed because this needs an architecture decision no agent may take — the audit's own authority resolution says PR intent does not supersede repository law.
The decision
PR #263 replaces the immutable Gate_SDK pin with a moving major tag:
PRESERVE-IMMUTABLE-SDK-IDENTITY is VIOLATED: CEG source revisions must deterministically identify the Gate SDK revision they were reviewed and tested with.
Why the tag is not equivalent to the pin
refs/tags/v1 does not point at the reviewed revision, and moves on each release:
v1 currently resolves to the same object as v1.1.0, not to the reviewed 69c6c67. Adopting it silently moves the SDK off the revision the code was tested against, and will move again at the next minor release.
Adopt moving-major policy. Land an explicit architecture decision that supersedes the immutable-pin law, and update the governing law plus validate_sdk_pin.py in a separately authorized change before this consumer PR implements it.
CEG-263-002 is blocked behind that choice
#263 changed only the two human-edited manifests and left the resolved lock untouched. On head 29bc0a2:
$ poetry check --lock
Error: pyproject.toml changed significantly since poetry.lock was last generated.
exit 1
poetry.lock still records reference/resolved_reference = 69c6c67… while pyproject.toml says rev = "v1". Which identity to lock to is the question above, so regenerating the lock now would silently decide the policy. Its second closing validation, docker compose -f docker-compose.prod.yml build api, is equally premature.
Once you pick a direction, CEG-263-002 is mechanical and I can do it: synchronize poetry.lock to the chosen identity and prove the production image builds from the repaired head.
Audit
ceg-open-prs-2026-09-17, findings CEG-263-001 (INVARIANT, High) and CEG-263-002 (COMPLETENESS, High). Owner classHUMAN; semantic ownerCEG constellation dependency policy. Filed because this needs an architecture decision no agent may take — the audit's own authority resolution says PR intent does not supersede repository law.The decision
PR #263 replaces the immutable Gate_SDK pin with a moving major tag:
Current repository law requires immutable SHA constellation pins, and the enforcement script rejects the change on #263's head
29bc0a2:PRESERVE-IMMUTABLE-SDK-IDENTITYisVIOLATED: CEG source revisions must deterministically identify the Gate SDK revision they were reviewed and tested with.Why the tag is not equivalent to the pin
refs/tags/v1does not point at the reviewed revision, and moves on each release:v1currently resolves to the same object asv1.1.0, not to the reviewed69c6c67. Adopting it silently moves the SDK off the revision the code was tested against, and will move again at the next minor release.Two ways to resolve — both need you
pyproject.toml,requirements.txt,poetry.lockandvalidate_sdk_pin.py. chore: pin constellation-node-sdk to @v1 (moving major tag) #263 closes or is reworked.validate_sdk_pin.pyin a separately authorized change before this consumer PR implements it.CEG-263-002 is blocked behind that choice
#263 changed only the two human-edited manifests and left the resolved lock untouched. On head
29bc0a2:poetry.lockstill recordsreference/resolved_reference = 69c6c67…whilepyproject.tomlsaysrev = "v1". Which identity to lock to is the question above, so regenerating the lock now would silently decide the policy. Its second closing validation,docker compose -f docker-compose.prod.yml build api, is equally premature.Once you pick a direction, CEG-263-002 is mechanical and I can do it: synchronize
poetry.lockto the chosen identity and prove the production image builds from the repaired head.Evidence:
E006,E013,E014,E015,E016,E017,E018,E026. Authorities:AUTH-IMMUTABLE-CONSTELLATION,AUTH-PROD-DEPENDENCY-COHERENCE,AUTH-USER-SCOPE.Related: #263.
Generated by Claude Code