diff --git a/404.html b/404.html index d5cf66a..e380dd7 100644 --- a/404.html +++ b/404.html @@ -49,5 +49,5 @@
  • Get started with a specification or search integrations
  • Community and partners or the agentic controls
  • - + diff --git a/community/index.html b/community/index.html index 1c3491b..eb41ebc 100644 --- a/community/index.html +++ b/community/index.html @@ -335,6 +335,6 @@

    Read the field guide. Then run the companion examples.

    })(); - + diff --git a/demos/index.html b/demos/index.html index f4f8a86..99c13b9 100644 --- a/demos/index.html +++ b/demos/index.html @@ -299,7 +299,7 @@

    Where to go next

    - + diff --git a/extensions/ca2a/v0.1/index.html b/extensions/ca2a/v0.1/index.html index 026bcdb..76e0d5e 100644 --- a/extensions/ca2a/v0.1/index.html +++ b/extensions/ca2a/v0.1/index.html @@ -166,6 +166,6 @@

    This page is orientation

    - + diff --git a/go/agent-anomaly-detection/index.html b/go/agent-anomaly-detection/index.html index 3cb7264..899ee51 100644 --- a/go/agent-anomaly-detection/index.html +++ b/go/agent-anomaly-detection/index.html @@ -54,7 +54,7 @@

    Anomaly detection on agent behaviour

    - + diff --git a/go/agent-circuit-breaker/index.html b/go/agent-circuit-breaker/index.html index b9d8521..fa0ea7e 100644 --- a/go/agent-circuit-breaker/index.html +++ b/go/agent-circuit-breaker/index.html @@ -54,7 +54,7 @@

    Circuit breaker on agent loops

    - + diff --git a/go/agent-identity-credential/index.html b/go/agent-identity-credential/index.html index 8464503..8385929 100644 --- a/go/agent-identity-credential/index.html +++ b/go/agent-identity-credential/index.html @@ -54,7 +54,7 @@

    Agent identity credential

    - + diff --git a/go/agent-key-binding/index.html b/go/agent-key-binding/index.html index 2df5cec..e5880b2 100644 --- a/go/agent-key-binding/index.html +++ b/go/agent-key-binding/index.html @@ -54,7 +54,7 @@

    Agent key binding and custody

    - + diff --git a/go/agent-purpose-declaration/index.html b/go/agent-purpose-declaration/index.html index 54d33fe..4ff9557 100644 --- a/go/agent-purpose-declaration/index.html +++ b/go/agent-purpose-declaration/index.html @@ -54,7 +54,7 @@

    Declared agent purpose and scope

    - + diff --git a/go/agent-rate-limiting/index.html b/go/agent-rate-limiting/index.html index c7da2b5..7e05ed6 100644 --- a/go/agent-rate-limiting/index.html +++ b/go/agent-rate-limiting/index.html @@ -54,7 +54,7 @@

    Rate limiting on agent actions

    - + diff --git a/go/agent-session-revocation/index.html b/go/agent-session-revocation/index.html index f62577b..17531ce 100644 --- a/go/agent-session-revocation/index.html +++ b/go/agent-session-revocation/index.html @@ -54,7 +54,7 @@

    Agent session revocation

    - + diff --git a/go/agent-state-rollback/index.html b/go/agent-state-rollback/index.html index bc1e2e4..f452dff 100644 --- a/go/agent-state-rollback/index.html +++ b/go/agent-state-rollback/index.html @@ -54,7 +54,7 @@

    State rollback after an agent action

    - + diff --git a/go/agent-termination/index.html b/go/agent-termination/index.html index 2541c75..834bf4f 100644 --- a/go/agent-termination/index.html +++ b/go/agent-termination/index.html @@ -54,7 +54,7 @@

    Terminate a running agent

    - + diff --git a/go/attested-a2a-channel/index.html b/go/attested-a2a-channel/index.html index 708d5bf..9cea460 100644 --- a/go/attested-a2a-channel/index.html +++ b/go/attested-a2a-channel/index.html @@ -54,7 +54,7 @@

    Attested agent-to-agent channel

    - + diff --git a/go/behavioural-baseline/index.html b/go/behavioural-baseline/index.html index 4c164c6..d62a5b2 100644 --- a/go/behavioural-baseline/index.html +++ b/go/behavioural-baseline/index.html @@ -54,7 +54,7 @@

    Behavioural baseline for an agent

    - + diff --git a/go/blast-radius-containment/index.html b/go/blast-radius-containment/index.html index 9dc246c..99e8667 100644 --- a/go/blast-radius-containment/index.html +++ b/go/blast-radius-containment/index.html @@ -54,7 +54,7 @@

    Blast radius containment for agent execution

    - + diff --git a/go/capability-attenuation/index.html b/go/capability-attenuation/index.html index 84d52f5..c92016e 100644 --- a/go/capability-attenuation/index.html +++ b/go/capability-attenuation/index.html @@ -54,7 +54,7 @@

    Capability attenuation across the delegation chain

    - + diff --git a/go/capability-manifest/index.html b/go/capability-manifest/index.html index 509f5a0..dbda4b1 100644 --- a/go/capability-manifest/index.html +++ b/go/capability-manifest/index.html @@ -54,7 +54,7 @@

    Declared capability manifest

    - + diff --git a/go/context-provenance/index.html b/go/context-provenance/index.html index 5be2536..490c28a 100644 --- a/go/context-provenance/index.html +++ b/go/context-provenance/index.html @@ -54,7 +54,7 @@

    Context provenance for agent working memory

    - + diff --git a/go/continuous-usage-control/index.html b/go/continuous-usage-control/index.html index 0b688df..2497e43 100644 --- a/go/continuous-usage-control/index.html +++ b/go/continuous-usage-control/index.html @@ -54,7 +54,7 @@

    Continuous usage control after grant

    - + diff --git a/go/evidence-transparency-anchoring/index.html b/go/evidence-transparency-anchoring/index.html index 79f2b8b..a6959c7 100644 --- a/go/evidence-transparency-anchoring/index.html +++ b/go/evidence-transparency-anchoring/index.html @@ -54,7 +54,7 @@

    Transparency-log anchoring of evidence

    - + diff --git a/go/graceful-degradation/index.html b/go/graceful-degradation/index.html index 061fcf3..d6b8218 100644 --- a/go/graceful-degradation/index.html +++ b/go/graceful-degradation/index.html @@ -54,7 +54,7 @@

    Graceful degradation on policy engine failure

    - + diff --git a/go/index.html b/go/index.html index f287b75..266a9f2 100644 --- a/go/index.html +++ b/go/index.html @@ -405,7 +405,7 @@

    What this page does not do

    - + diff --git a/go/input-schema-validation/index.html b/go/input-schema-validation/index.html index 355bb4e..dd20852 100644 --- a/go/input-schema-validation/index.html +++ b/go/input-schema-validation/index.html @@ -54,7 +54,7 @@

    Schema validation of agent input

    - + diff --git a/go/model-weight-custody/index.html b/go/model-weight-custody/index.html index 34bba11..c3e1a97 100644 --- a/go/model-weight-custody/index.html +++ b/go/model-weight-custody/index.html @@ -54,7 +54,7 @@

    Model weight custody against the hosting operator

    - + diff --git a/go/output-encoding/index.html b/go/output-encoding/index.html index f7bd505..9413e6c 100644 --- a/go/output-encoding/index.html +++ b/go/output-encoding/index.html @@ -54,7 +54,7 @@

    Encoding and injection prevention

    - + diff --git a/go/output-personal-data/index.html b/go/output-personal-data/index.html index 009c0ad..d5d13fc 100644 --- a/go/output-personal-data/index.html +++ b/go/output-personal-data/index.html @@ -54,7 +54,7 @@

    Personal data protection in agent output

    - + diff --git a/go/policy-verdict-rationale/index.html b/go/policy-verdict-rationale/index.html index 8e6ffbe..1e21a78 100644 --- a/go/policy-verdict-rationale/index.html +++ b/go/policy-verdict-rationale/index.html @@ -54,7 +54,7 @@

    Policy verdict rationale

    - + diff --git a/go/prompt-injection-prevention/index.html b/go/prompt-injection-prevention/index.html index ca555b8..5406714 100644 --- a/go/prompt-injection-prevention/index.html +++ b/go/prompt-injection-prevention/index.html @@ -54,7 +54,7 @@

    Prompt injection prevention

    - + diff --git a/go/resource-allowlist/index.html b/go/resource-allowlist/index.html index 6211b0e..81ecde7 100644 --- a/go/resource-allowlist/index.html +++ b/go/resource-allowlist/index.html @@ -54,7 +54,7 @@

    Resource allowlist

    - + diff --git a/go/runtime-attestation-evidence/index.html b/go/runtime-attestation-evidence/index.html index d5e4c9a..5849f22 100644 --- a/go/runtime-attestation-evidence/index.html +++ b/go/runtime-attestation-evidence/index.html @@ -54,7 +54,7 @@

    Runtime attestation evidence

    - + diff --git a/go/structured-action-logging/index.html b/go/structured-action-logging/index.html index 74544a4..1c3e860 100644 --- a/go/structured-action-logging/index.html +++ b/go/structured-action-logging/index.html @@ -54,7 +54,7 @@

    Structured action logging

    - + diff --git a/go/tool-authorization/index.html b/go/tool-authorization/index.html index 946f62f..d1e7c71 100644 --- a/go/tool-authorization/index.html +++ b/go/tool-authorization/index.html @@ -54,7 +54,7 @@

    Tool authorization decision

    - + diff --git a/go/transaction-limits/index.html b/go/transaction-limits/index.html index 8ed4b27..93be5d8 100644 --- a/go/transaction-limits/index.html +++ b/go/transaction-limits/index.html @@ -54,7 +54,7 @@

    Transaction and spend limits

    - + diff --git a/go/verifiable-evidence-record/index.html b/go/verifiable-evidence-record/index.html index a933edd..b119945 100644 --- a/go/verifiable-evidence-record/index.html +++ b/go/verifiable-evidence-record/index.html @@ -54,7 +54,7 @@

    Signed, third-party-verifiable evidence record

    - + diff --git a/index.html b/index.html index 359ed7b..780d98e 100644 --- a/index.html +++ b/index.html @@ -416,6 +416,6 @@

    Help steward it

    - + diff --git a/marketplace/index.html b/marketplace/index.html index 6f90519..680fb5b 100644 --- a/marketplace/index.html +++ b/marketplace/index.html @@ -57,5 +57,5 @@ - + diff --git a/quickstart/index.html b/quickstart/index.html index c7ddb47..c3e2545 100644 --- a/quickstart/index.html +++ b/quickstart/index.html @@ -164,7 +164,7 @@

    Check real hardware evidence first

    - + diff --git a/registry/index.html b/registry/index.html index 0425fdd..fcdc1a6 100644 --- a/registry/index.html +++ b/registry/index.html @@ -296,7 +296,7 @@

    Three ways in

    - + diff --git a/telemetry/index.html b/telemetry/index.html index 092b8ef..0ae83c5 100644 --- a/telemetry/index.html +++ b/telemetry/index.html @@ -329,7 +329,7 @@

    The documents to implement against

    - + diff --git a/tools/DISCOVERY.md b/tools/DISCOVERY.md index 3aea6fd..e7fb41a 100644 --- a/tools/DISCOVERY.md +++ b/tools/DISCOVERY.md @@ -28,7 +28,7 @@ This fetches both catalogs at one public `agentrust-io/integrations` commit, rec ## Availability checks -After merging, the Public site availability workflow runs every six hours and can be dispatched manually. It reads the deployed sitemap, checks its pages, checks the home/robots/sitemap/AI-guide endpoints of all eight public hosts, and verifies that an unknown URL returns 404. Individual probes retry once. Results are retained as a workflow artifact for 14 days. Maintainers can use GitHub Actions failure notifications to investigate. +After merging, the Public site availability workflow runs every six hours and can be dispatched manually. It reads the deployed sitemap, checks its pages, checks the home/robots/sitemap/AI-guide endpoints of all eight public hosts, and verifies that an unknown URL returns 404. It also reads each MkDocs host's home page and fails, naming the host, if its design-system.css or supernav.js URL does not carry the current `CSS_VERSION` from tools/site_header.py. Individual probes retry once. Results are retained as a workflow artifact for 14 days. Maintainers can use GitHub Actions failure notifications to investigate. ```sh python tools/check-availability.py @@ -36,6 +36,10 @@ python tools/check-availability.py This checks public HTTP status, nonempty responses, challenge headers, and unexpected `X-Robots-Tag: noindex`. It does not measure browser rendering, all content changes, uptime percentages, real search-engine IP access, or field Core Web Vitals. Requests identify themselves as `AgenTrust-availability-check/1.0`; a generic Python user agent received HTTP 403 during the initial audit, while the declared monitor and sampled search/assistant user agents received 200. Do not treat user-agent substitution as proof of actual crawler access. +## Shared asset versions + +agentrust-io.com serves design-system.css and supernav.js with a four-hour cache, so every site loads them with `?v=` set to `CSS_VERSION` in tools/site_header.py. To ship a change to either file, bump `CSS_VERSION`, run `python tools/build-header.py`, `python tools/build-controls.py` and `python tools/build-discovery.py`, and bump the same number in the mkdocs.yml of weight-custody-manifest, agent-manifest, cmcp, ca2a, trace-spec, trace-tests and awesome-ai-governance; the availability check names any host that still lags. + ## Search-engine verification Use the site's verified Google Search Console and Bing Webmaster Tools properties to inspect indexing, canonical selection, submitted sitemaps, crawl errors, queries, and actual referrals. Those account reports were not inspected in this change. Browser preview was interrupted by a connection timeout, so the new catalog and 404 still need visual review. diff --git a/tools/build-controls.py b/tools/build-controls.py index c2cb87f..4580138 100644 --- a/tools/build-controls.py +++ b/tools/build-controls.py @@ -153,7 +153,7 @@ def head(title, description, canonical, robots, og_title, og_url, extra=''): - + diff --git a/tools/build-header.py b/tools/build-header.py index c0920ba..afe25c2 100644 --- a/tools/build-header.py +++ b/tools/build-header.py @@ -5,7 +5,7 @@ The header itself is defined once, in tools/site_header.py. Each page carries it between the site-header:start and site-header:end markers, and this script owns -everything between them, plus the design-system.css cache-bust. A hand edit +everything between them, plus the design-system.css and supernav.js cache-bust. A hand edit inside the markers fails CI; change site_header.py and re-run this instead. /go/ and /marketplace/catalog/ are generated by build-controls.py and @@ -42,6 +42,7 @@ BLOCK = re.compile(re.escape(site_header.START) + r'.*?' + re.escape(site_header.END), re.S) CSS = re.compile(r'/design-system\.css\?v=\d+') +SUPERNAV = re.compile(r'/supernav\.js(?:\?v=\d+)?(?=")') def stamped(text, name, page, section): @@ -51,7 +52,11 @@ def stamped(text, name, page, section): raise SystemExit(f'{name}: the skip link needs an element with id="main"') if len(CSS.findall(text)) != 1: raise SystemExit(f'{name}: expected exactly one design-system.css link') + if len(SUPERNAV.findall(text)) != (0 if name in NO_SCRIPT else 1): + raise SystemExit(f'{name}: expected exactly one supernav.js script' if name not in NO_SCRIPT + else f'{name}: must not load supernav.js') text = BLOCK.sub(lambda _: site_header.render(page, section, script=name not in NO_SCRIPT), text) + text = SUPERNAV.sub(f'/supernav.js?v={site_header.CSS_VERSION}', text) return CSS.sub(f'/design-system.css?v={site_header.CSS_VERSION}', text) diff --git a/tools/check-availability.py b/tools/check-availability.py index 78f8e43..4720bda 100644 --- a/tools/check-availability.py +++ b/tools/check-availability.py @@ -2,13 +2,43 @@ from concurrent.futures import ThreadPoolExecutor import json from pathlib import Path +import re +import sys import time from urllib.error import HTTPError from urllib.request import Request, urlopen import xml.etree.ElementTree as ET +sys.path.insert(0, str(Path(__file__).resolve().parent)) +from site_header import CSS_VERSION # noqa: E402 + ROOT = Path(__file__).resolve().parents[1] BASE = 'https://agentrust-io.com' +DOCS_HOSTS = ['trace.', 'manifest.', 'cmcp.', 'ca2a.', 'governance.', 'tests.', 'wcm.'] +# Browsers keep both files for four hours, so each MkDocs site pins CSS_VERSION in +# its mkdocs.yml. A host still on an older number shows readers a stale top bar. +SHARED_ASSETS = ['design-system.css', 'supernav.js'] + + +def asset_versions(host): + """Report which shared asset URLs a docs host's home page references, and whether they are current.""" + url = f'https://{host}agentrust-io.com/' + try: + request = Request(url, headers={'User-Agent': 'AgenTrust-availability-check/1.0'}) + with urlopen(request, timeout=20) as response: + html = response.read().decode('utf-8', 'replace') + except Exception as exc: + return {'url': url, 'error': f'could not read home page: {exc}'} + found = {} + for asset in SHARED_ASSETS: + # MkDocs minifies HTML, so the attribute may be quoted or not. + refs = re.findall(r'https://agentrust-io\.com/' + re.escape(asset) + r'(?:\?v=(\d+))?(?=["\'\s>])', html) + found[asset] = sorted({v or 'unversioned' for v in refs}) or ['missing'] + lagging = [f'{asset} is {",".join(v)}' for asset, v in found.items() if v != [CSS_VERSION]] + result = {'url': url, 'expected_version': CSS_VERSION, 'found': found} + if lagging: + result['error'] = f'{host}agentrust-io.com lags CSS_VERSION {CSS_VERSION}: ' + '; '.join(lagging) + '. Bump ?v= in its mkdocs.yml.' + return result def probe(target): @@ -45,16 +75,19 @@ def main(): urls = {node.text for node in sitemap.findall('.//{http://www.sitemaps.org/schemas/sitemap/0.9}loc')} if not urls or any(not url.startswith(BASE + '/') for url in urls): raise ValueError('Unexpected live sitemap') - for prefix in ['', 'trace.', 'manifest.', 'cmcp.', 'ca2a.', 'governance.', 'tests.', 'wcm.']: + for prefix in [''] + DOCS_HOSTS: urls.update('https://' + prefix + 'agentrust-io.com' + path for path in ['/', '/robots.txt', '/sitemap.xml', '/llms.txt']) targets = [(url, 200) for url in sorted(urls)] + [(BASE + '/missing-availability-probe-404/', 404)] with ThreadPoolExecutor(max_workers=4) as pool: results = list(pool.map(probe, targets)) - Path('availability-results.json').write_text(json.dumps(results, indent=2) + '\n', encoding='utf-8') + versions = list(pool.map(asset_versions, DOCS_HOSTS)) + Path('availability-results.json').write_text(json.dumps(results + versions, indent=2) + '\n', encoding='utf-8') failures = [item for item in results if 'error' in item] + lagging = [item for item in versions if 'error' in item] print(f'{len(results)-len(failures)}/{len(results)} public HTTP probes passed') - if failures: - raise SystemExit(json.dumps(failures, indent=2)) + print(f'{len(versions)-len(lagging)}/{len(versions)} docs hosts load design-system.css and supernav.js at v={CSS_VERSION}') + if failures or lagging: + raise SystemExit(json.dumps(failures + lagging, indent=2)) if __name__ == '__main__': diff --git a/tools/site_header.py b/tools/site_header.py index abefa86..60eeb40 100644 --- a/tools/site_header.py +++ b/tools/site_header.py @@ -6,8 +6,13 @@ build-header's --check agree byte for byte. CI runs all three. The header styles live in design-system.css under `.hub-header`, and hub-nav.js -adds the mobile Menu toggle. CSS_VERSION is the design-system.css cache-bust for -every page; bump it here when that stylesheet changes. +adds the mobile Menu toggle. + +CSS_VERSION is the cache-bust for the two files every AgenTrust site loads from +agentrust-io.com: design-system.css and supernav.js. They are served with a +four-hour max-age, so bump it when either file changes. build-header.py stamps it +into the hub pages; the seven MkDocs sites pin the same number in mkdocs.yml, and +tools/check-availability.py names any of them that lags. """ from html import escape diff --git a/verify/index.html b/verify/index.html index a4e29f0..76306c7 100644 --- a/verify/index.html +++ b/verify/index.html @@ -181,7 +181,7 @@

    A port, held to its original

    - +