Skip to content

docs(ci-posture): re-check all three applications against their own state - #239

Merged
sgort merged 4 commits into
accfrom
docs/ci-posture-ttl-2026-09-30
Sep 30, 2026
Merged

sgort merged 4 commits into
accfrom
docs/ci-posture-ttl-2026-09-30

Conversation

@sgort

@sgort sgort commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

What

I re-checked every ttl-editor, Linked Data Explorer and RONL Business API claim in docs/ci-posture-across-repos.md against each repository as it stood on 30 September 2026, one commit per repository. I corrected what had drifted and added the 24–25 September #119 work, which the page did not cover.

This builds on this morning's restructure (#238).

ttl-editor (first commit)

Checked at acc 8611de8, main 7d154ba. Sources:

  • rulesets and classic protection from the GitHub API
  • Node pins and the workflow list from the YAML
  • check-supply-chain: 17 references, all in agreement
  • check-previews: six previews, each on an open pull request
  • both mirror heads by ls-remote
  • npm run test:ci: 763 tests in 62 files, parallel run, all passing; useDsoImport.js also measured on its own
claim was now
Node version .nvmrc, one file one version in four places: .nvmrc, plus a '24.20.0' literal in zizmor.yml, dependency-audit.yml and sbom.yml
near the coverage floor three files two. useDsoImport.js is at 92.16% in the full suite but 80.39% from its own tests, so its margin depends on other test files (§3)
ttl-editor#117 conflicted mergeable and clean
zizmor v0.6.4 / 1.30.1 due about 23 Sep still not taken; ttl-editor#166 open since 23 Sep
#119, 24–25 Sep not covered new archive entry pairing ttl-editor #167–#170 with this repository's #220–#225, plus the audit and SBOM in the component table

Linked Data Explorer (second commit)

Checked at acc e17f24e, main 4148c9a. Sources:

  • rulesets and classic protection from the GitHub API
  • the eleven workflows from the YAML
  • check-supply-chain: 31 references
  • App Service runtimes from Azure
  • the acceptance frontend's preview environments
  • both mirror heads by ls-remote
  • both coverage runners: backend 1824 tests in 69 suites, frontend 1271 tests in 76 files, parallel runs, all passing
claim was now
Node version .nvmrc, one file dependency-audit.yml and sbom.yml pin 24.20.0 while .nvmrc is 24.21.0. Both were copied from ttl-editor; #221 fixes it
#80 unblocked 23 Sep merged 23 Sep; both App Services on 24-lts
#97 worded as open closed 23 Sep
Latest changelog status 1.9.12 1.9.12 and 1.9.0
files measured 49 / 68 52 / 75. The lowest files are unchanged; AssetLibrary.tsx now has one branch of slack, like GraphView.tsx
§5 mirror table 15 Sep heads today's heads for ttl-editor and Linked Data Explorer

The second commit also corrects the first commit's ttl-editor file count. It said 42, which counted every file in the report. The table counts only files with at least one branch, which gives 33.

The Node drift itself is fixed by merging #221, not by this pull request.

RONL Business API (third commit)

Checked at acc b958d9b, main ae4538b, after v2026.09.14 was promoted. Sources:

  • rulesets and classic protection from the GitHub API
  • the thirteen workflows from the YAML
  • check-supply-chain: 39 references
  • App Service runtimes from Azure
  • check-previews: six apps, no previews
  • Dependabot and Semgrep, read from their APIs
  • both mirror heads by ls-remote
  • all five test runners, parallel runs, all passing: backend 2310 tests with all 133 operations conformance-checked, frontend 1268, pa-cockpit 480, pa-demo 106, public-site 261
claim was now
Semgrep 25 findings to triage; required on acc 0 open Supply Chain findings after #286; 8 Code findings open on main only, fixed on acc by #293; required on both branches
Dependabot 8 alerts 3: minimatch, react-router ×2
Node .nvmrc, one file .nvmrc 22.23.2 for every deploy, plus a deliberate 24.21.0 literal in the three tooling workflows
backend coverage margin "comfortable", never measured edocs.service.ts at exactly 80.00% (60/75), both in the full run and with its own tests alone
§2 pinned-references table 11 / 23 / 31 17 / 31 / 39, for all three repositories

End of day (fourth commit)

RONL Business API at 142d909 (v2026.09.15):

  • Coverage: #295 brought every file in all five runners to 85% or above. I re-measured all five in parallel runs, all passing: backend 2370 tests, frontend 1318, pa-cockpit 515, pa-demo 106, public-site 265. No file in any runner is under 85%, and edocs.service.ts is at 98.67%. The enforced threshold is still branches: 80 in all five configs, and the doc now says so.
  • Semgrep: the promotion closed the 8 Code findings, so Semgrep shows 0 open. There is one new low-severity Supply Chain finding, dompurify, which Dependabot also reports as a fourth alert. A routine update to 3.4.16 closes it.
  • The clean-clone question: dropped. edocs.service.ts is no longer near the floor.

Linked Data Explorer:

Housekeeping:

  • Heads and mirror rows for Linked Data Explorer and RONL Business API are at today's heads, verified with ls-remote.
  • This commit also fixes a splice error from the third commit in §3, where the RONL Business API margins text had landed in the middle of a ttl-editor sentence.

…rd its #119 work

Every ttl-editor claim re-checked on 30 September 2026 at 8611de8 / 7d154ba:
rulesets and classic protection from the API, Node pins and workflows from the
YAML, check-supply-chain (17 references), check-previews (six previews, all on
open pull requests), both mirror heads by ls-remote, and the full suite with
coverage (763 tests in 62 files, parallel run, all passing).

Five claims moved:

- "One Node version, one file": zizmor.yml, dependency-audit.yml and sbom.yml
  each set node-version '24.20.0' literally beside .nvmrc. One version, four
  places, kept current by Renovate's node manager.
- Three files one branch from the floor: two. useDsoImport.js reads 92.16%
  (47/51) in the suite and 80.39% (41/51) from its own test file alone; the
  difference comes from other test files since 1d01186. Recorded in §3, with the
  margins table updated (42 files, lowest now ConceptsTab.jsx 80.56%).
- #117 "conflicted": now mergeable and clean.
- zizmor "due about 23 Sep": still not taken in ttl-editor. The action is at
  v0.6.3, zizmor at 1.29.0, and #166 has been open since 23 September.
- The 24-25 September #119 work was missing: the daily dependency audit, the
  rule against a new major's first release, the deferrals recorded as disabled
  rules, and the lockfile-sync step. It now has an archive entry pairing
  ttl-editor #167-#170 with this repository's #220-#225, and the ttl-editor
  component table names the audit and the release SBOM.

RONL Business API was not re-checked for this change.
Every Linked Data Explorer claim re-checked on 30 September 2026 at e17f24e /
4148c9a. Sources: rulesets and classic protection from the API, the eleven
workflows from the YAML, check-supply-chain (31 references), App Service
runtimes from Azure, the acceptance frontend's preview environments, both
mirror heads by ls-remote, and both coverage runners. Backend: 1824 tests in 69
suites. Frontend: 1271 tests in 76 files. Both ran in parallel, as usual, and
passed.

Six claims moved:

- "One Node version, one file": dependency-audit.yml and sbom.yml pin
  '24.20.0' while .nvmrc is 24.21.0. Both were ported from ttl-editor after
  .nvmrc had moved in #80, so the literal was never this repository's version.
  Renovate's #221 has been open since 24 September to fix it. The summary cell
  now shows a warning and links #221.
- #80 was listed as "unblocked 23 Sep". It merged that day, and both App
  Services read NODE|24-lts on 30 September.
- #97 was worded as if still open. It closed on 23 September.
- Changelog entry 1.9.0 also carries the legacy Latest status, not only 1.9.12.
- §3 "files measured": 52 and 75 now, counted by the table's own rule (files
  with at least one branch). The lowest files are unchanged.
  DocumentComposer/AssetLibrary.tsx now has the same one-branch slack as
  GraphView.tsx.
- The §5 mirror table still showed the 15 September heads. The ttl-editor and
  Linked Data Explorer rows now show today's heads, verified by ls-remote.

This also corrects the previous commit's ttl-editor row in the margins table.
It gave 42 files, which counted every file in the report; the table's rule
gives 33.

Also recorded: none of the preview environments is orphaned. The acceptance
frontend holds three, for #223, #226 and #230, all open. In zizmor, this
repository has taken action v0.6.4, but zizmor itself is still 1.29.0 here and
in ttl-editor.
@sgort sgort changed the title docs(ci-posture): re-check ttl-editor against its own state, and record its #119 work docs(ci-posture): re-check ttl-editor and Linked Data Explorer against their own state Sep 30, 2026
Every RONL Business API claim re-checked on 30 September 2026 at b958d9b /
ae4538b, after v2026.09.14 was promoted. Sources: rulesets and classic
protection from the API, the thirteen workflows from the YAML,
check-supply-chain (39 references), App Service runtimes from Azure,
check-previews (six apps, no previews), Dependabot and Semgrep from their APIs,
both mirror heads by ls-remote, and all five runners in the usual parallel run.
Backend: 2310 tests in 97 suites, with all 133 operations conformance-checked.
Frontend: 1268. pa-cockpit: 480. pa-demo: 106. public-site: 261. All passed.

Five claims moved:

- Semgrep "25 still to triage": triaged. The platform shows 0 open Supply
  Chain findings after #286. The 8 open Code findings are in the two
  check-og.mjs scripts, on main only; #293 suppressed them inline on acc. The
  summary said "required on acc", but scan has been required on main too since
  29 September.
- Dependabot: 3 open alerts, not 8 (minimatch, react-router x2).
- Node "one file": .nvmrc (22.23.2) covers every deploy. The three tooling
  workflows set 24.21.0 literally, on purpose.
- Backend margin "comfortable": never measured. edocs.service.ts sits at
  exactly 80.00% (60/75), in the full run and with its own test file alone.
  #256 did not list it, so the text asks for a clean-clone check. The doc also
  now gives the lowest file in each of the other four runners.
- §2's "Where it runs" table still gave 11, 23 and 31 pinned references, from
  before the September workflows. Corrected for all three repositories: 17, 31
  and 39, pinned in every workflow.

Also: the heads table and §5 mirror row are brought to today's heads, and the
conformance script's path is given in full.
@sgort sgort changed the title docs(ci-posture): re-check ttl-editor and Linked Data Explorer against their own state docs(ci-posture): re-check all three applications against their own state Sep 30, 2026
… LDE merges

RONL Business API, re-measured at 142d909 (v2026.09.15, promoted to main as
ae06c9e):

- #295 brought all 32 files that sat between 80 and 85 to 85 or above. All
  five runners were run in parallel, and no file in any of them is under 85%.
  Backend: 2370 tests, all 133 operations conformance-checked. Frontend: 1318.
  pa-cockpit: 515. pa-demo: 106. public-site: 265. edocs.service.ts went from
  80.00% to 98.67%.
- The enforced threshold is still `branches: 80` in all five configs, and the
  doc says so. 85 is a margin reached, not a threshold checked. The summary
  row reads "5 runners, every file >= 85%".
- The promotion closed the 8 Code findings; Semgrep shows 0 open. One new
  Supply Chain finding on main: dompurify, low, first reported 30 September.
  Dependabot reports it as a fourth alert, which a routine update (3.4.16)
  closes.
- The clean-clone question about edocs.service.ts is dropped. The file is no
  longer near the floor.

Linked Data Explorer:

- #221 merged (f638ae0), so the Node drift is closed. The summary cell,
  component row and paragraph, the §6 row, and the archive bullet now say so.
- #223 and #226 merged one at a time, each rebased by Renovate first. acc is at
  8a55d83.

Heads and §5 mirror rows for Linked Data Explorer and RONL Business API are
brought to today's heads, verified with ls-remote.

This also fixes a splice from the previous commit, which had dropped the RONL
Business API margins text into the middle of a ttl-editor sentence in §3.
@sgort
sgort merged commit dec2359 into acc Sep 30, 2026
10 checks passed
@sgort
sgort deleted the docs/ci-posture-ttl-2026-09-30 branch September 30, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant