Skip to content

docs: add AFFIRMATION.adoc (Profile A) as of 2026-10-07 - #113

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-2026-10-07
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-2026-10-07

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Adds AFFIRMATION.adoc (Profile A) for sanctify-php at anchor d7634557f35c330ca97c2ccb1fa997d4506b84f2, following hyperpolymath/standards docs/AFFIRMATION-STANDARD.adoc. Claude ran the checks at that anchor on 2026-10-07 and drafted the file. The owner affirms it with the signed commit in this PR, whose parent is the anchor.

The file's one-line characterisation: sanctify-php is a substantial but unfinished Haskell codebase for PHP hardening; at d7634557 it does not compile, so none of its security analyses has been run or verified.

Closes: none.

Type of change

  • 🐛 Bug fix
  • ✨ New feature
  • 💥 Breaking change
  • 🕳️ Soundness fix
  • 📖 Documentation
  • 🧹 Refactor / tech debt
  • ⚡ Performance
  • 🔧 Build / CI / tooling

📌 New pins

  • Head SHA: 47d7d2a6a0bf12fefa3e048fcacb933b0dfed4be. This is the owner's signed commit, the one CI runs on.
  • Anchor: d7634557f35c330ca97c2ccb1fa997d4506b84f2. It is the head's parent, and it was main when this PR opened.
  • No action uses: SHAs, actions.lock entries, lockfiles or container digests are added or changed.

How has this been verified?

  • git log -1 --format=%G? on the head printed G (the owner's SSH signing key). git rev-parse HEAD^ printed the anchor.
  • The opener script refuses to open the PR unless git ls-remote shows main at the anchor and the branch at the head above. It did not refuse.
  • asciidoctor -S safe --failure-level=WARN -o /dev/null AFFIRMATION.adoc returned rc=0 with no warnings. A planted out-of-sequence section in a scratch file returned rc=1, so the gate can fail.
  • The evidence inside the file was gathered at the anchor on 2026-10-07, and each claim names its command and output:
    • cabal build all stops with 11 errors (CI run 37603063882, GHC 9.8.2). Each error was re-checked locally.
    • Eight parser helpers are defined nowhere (grep count 0 for each). isWpdbObject is imported but not exported. transformAddTypeHints is declared twice.
    • Licence metadata is MPL-2.0 throughout. There are 20 modules, about 6,100 lines, and 109 declared it cases, none of them executed.
    • governance / Actions lockfile verify is red at the anchor: Dependabot chore(deps): bump hyperpolymath/smtp-notify-action from 0.3.0 to 0.5.0 in the actions group #112 bumped smtp-notify-action without updating actions.lock.

Checklist

  • My commits are signed (git commit -S). The head is G.
  • I ran the project's own checks/tests locally and they pass. Not ticked. This PR changes documentation only, and the file it adds records that the library does not compile at this anchor, so the suite cannot run.
  • New files carry the correct SPDX-License-Identifier. AFFIRMATION.adoc line 1 is CC-BY-SA-4.0 (prose). No existing file is touched.
  • Docs are updated, and no public claim now overstates what the code does. The file refutes "the parser is complete" and marks the README feature list as aspiration.
  • I have not introduced a soundness hole. No code changed.

Notes for reviewers

Merge form: a merge commit, and only while main is still at the anchor d7634557.

  • This repo allows merge commits. The AFFIRMATION-STANDARD v1.1 amendment (docs(affirmation): define the anchor for squash-only repositories standards#1212, open) says such a repo SHOULD land the signed commit that way, so the signed commit itself reaches main.
  • The anchor check also requires the merge commit's first parent to be the anchor, so merge before anything else lands on main.
  • If main has moved, do not merge and do not press Update branch. Ask for a re-anchor instead.

Automerge is deliberately not armed.

  • The one required check, scan / gitleaks, is not strict. An armed merge would therefore still fire after main moved past the anchor, and the affirmation would land unanchored.
  • This PR is held for the owner's merge.

After the merge, scripts/verify-affirmation-anchor.sh hyperpolymath/sanctify-php <N> (from standards#1212) should print ANCHORED.

🤖 Generated with Claude Code

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Drafted by Claude from local runs at the anchor; affirmed by the owner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ba5b0822-be4e-48de-a690-cea949843049
📥 Commits

Reviewing files that changed from the base of the PR and between d763455 and 47d7d2a.

📒 Files selected for processing (1)
  • AFFIRMATION.adoc
 _____________________________________________________________________
< No matter how far down the wrong road you have gone, turn back now. >
 ---------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit f9b26d8 into main Oct 9, 2026
32 of 35 checks passed
@hyperpolymath
hyperpolymath deleted the docs/affirmation-2026-10-07 branch October 9, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant