Skip to content

Add DKG Review Ledger - #34

Open
shadowharness wants to merge 3 commits into
OriginTrail:mainfrom
shadowharness:add-dkg-review-ledger
Open

shadowharness wants to merge 3 commits into
OriginTrail:mainfrom
shadowharness:add-dkg-review-ledger

Conversation

@shadowharness

@shadowharness shadowharness commented Oct 1, 2026 •

Copy link
Copy Markdown

Round 1 submission tag: cfi-dkgv10-r1

What this PR does

Adds DKG Review Ledger, a standalone integration that captures commit-aware GitHub pull-request reviews and CI evidence in DKG v10 Working and Shared Memory. An engineering agent revisiting a PR can retrieve its captured head/base commits, source-reported reviews and checks, immutable history, and exact content digest. A second registered agent can reuse a selected Shared Memory packet with its own scoped credential and an explicit writer-project selector.

Integration links

Scope and security declarations

  • Uses the supported authenticated public DKG HTTP API as a standalone service and CLI.
  • Declares WM and SWM, and the exercised Knowledge Asset, Context Graph, Curator and Entity primitives.
  • Lists the GitHub API and the exact optional operator-configured HTTPS DKG origin in network egress.
  • Declares one-time scoped-agent registration, local Context Graph creation, WM draft writes and explicit Curator-authority SHARE.
  • Documents the optional read-only GitHub credential and the separate scoped DKG and service-control credentials.
  • Has zero third-party runtime npm dependencies and no install lifecycle scripts.
  • Pins an anonymously retrievable container digest with an SBOM and signed GitHub-hosted source provenance.

Capture checks head, base and source update time before and after collection. A moving PR is refused. Unchanged captures reuse their existing identity and observation time; changed source content produces an immutable revision. Complete changed-file listings are required, and source-provided patch excerpts retain their recorded availability. Readback verifies the complete stored source packet and digest.

Sync writes Working Memory. SHARE requires selection of an exact packet and digest, requests Curator acknowledgement, verifies the sealed lifecycle and reads the packet from Shared Memory. --shared-owner selects the writer's shared repository project for read operations while the reader keeps its own credential. Chain publication, staking, endorsement and voting are outside the implemented operation set. Verifiable Memory and context-oracle promotion are described as future stages in the design brief.

Measured verification

The release passed seventeen unit/HTTP tests and two integration tests against an independently installed, unmodified DKG v10.0.20 node. The integration environment uses a mock chain with real authenticated WM/SWM HTTP and Curator handling. GitHub fixtures in automated tests are explicitly synthetic. Tests cover lossless readback, unchanged-source replay, changed-head revisions, review commit correspondence, sealed SHARE, repeat SHARE, and reuse through the standard CLI by a separately registered reader on the same node.

The public v0.1.3 deployment runs in a dedicated persistent case container. After the application restart, all five original public GitHub snapshots retained their content digests, observation times and selected WM/SWM state. Eighteen public page/API routes passed; anonymous writes returned 401. A distinct registered reader also retrieved two original Shared Memory packets with their original digests and observation times through the deployed CLI.

Strict attestation verification matched the exact source commit, refs/tags/v0.1.3, release workflow, GitHub-hosted builder and immutable image digest. Anonymous registry manifest retrieval returned HTTP 200.

Contributor attestation and support

  • This integration is original work, licensed Apache-2.0.
  • It contains no intentional backdoors, malicious logic or data-exfiltration paths beyond the declared egress.
  • I understand that material misrepresentation may cause delisting.
  • Maintainer @shadowharness commits to at least six months of support after acceptance, as documented in MAINTENANCE.md. Contact: contact@shadowharness.com.

This is a Round 1 submission at the community trust tier for committee review. The first user is the ShadowHarness project. Development used gpt-6.1-sol in ShadowHarness with Sidera permanent memory infrastructure, supporting sustained autonomous engineering, source-linked recall and verified task handoffs. The submitted integration, its public GitHub source packets and verification evidence are directly inspectable.

@shadowharness

Copy link
Copy Markdown
Author

Could a maintainer approve the pending registry CI run for this PR so the official schema and security checks can execute?

Pending run: https://github.com/OriginTrail/dkg-integrations/actions/runs/36962584178

The entry pins DKG Review Ledger v0.1.3 to source 6010429329fe819ca13f3126422dd3a69628f1f1 and the signed image digest sha256:0c82a9ae7eb337ef5c4b3103d5583b3fe20a02bf34c38bec450e91ee763292f1.

The contributor test and publication workflow passed: https://github.com/shadowharness/dkg-review-ledger/actions/runs/36961183343

Pinned verification and reproduction: https://github.com/shadowharness/dkg-review-ledger/blob/6010429329fe819ca13f3126422dd3a69628f1f1/docs/VERIFICATION.md

The submission resources and live demo are linked in the PR description. I will address review feedback here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant