Repository navigation
Add DKG Review Ledger - #34
shadowharness wants to merge 3 commits into
Conversation
|
Could a maintainer approve the pending registry CI run for this PR so the official schema and security checks can execute? Pending run: https://github.com/OriginTrail/dkg-integrations/actions/runs/36962584178 The entry pins DKG Review Ledger v0.1.3 to source The contributor test and publication workflow passed: https://github.com/shadowharness/dkg-review-ledger/actions/runs/36961183343 Pinned verification and reproduction: https://github.com/shadowharness/dkg-review-ledger/blob/6010429329fe819ca13f3126422dd3a69628f1f1/docs/VERIFICATION.md The submission resources and live demo are linked in the PR description. I will address review feedback here. |
Round 1 submission tag:
cfi-dkgv10-r1What this PR does
Adds DKG Review Ledger, a standalone integration that captures commit-aware GitHub pull-request reviews and CI evidence in DKG v10 Working and Shared Memory. An engineering agent revisiting a PR can retrieve its captured head/base commits, source-reported reviews and checks, immutable history, and exact content digest. A second registered agent can reuse a selected Shared Memory packet with its own scoped credential and an explicit writer-project selector.
Integration links
6010429329fe819ca13f3126422dd3a69628f1f1ghcr.io/shadowharness/dkg-review-ledger:v0.1.3sha256:0c82a9ae7eb337ef5c4b3103d5583b3fe20a02bf34c38bec450e91ee763292f1Scope and security declarations
Capture checks head, base and source update time before and after collection. A moving PR is refused. Unchanged captures reuse their existing identity and observation time; changed source content produces an immutable revision. Complete changed-file listings are required, and source-provided patch excerpts retain their recorded availability. Readback verifies the complete stored source packet and digest.
Sync writes Working Memory. SHARE requires selection of an exact packet and digest, requests Curator acknowledgement, verifies the sealed lifecycle and reads the packet from Shared Memory.
--shared-ownerselects the writer's shared repository project for read operations while the reader keeps its own credential. Chain publication, staking, endorsement and voting are outside the implemented operation set. Verifiable Memory and context-oracle promotion are described as future stages in the design brief.Measured verification
The release passed seventeen unit/HTTP tests and two integration tests against an independently installed, unmodified DKG v10.0.20 node. The integration environment uses a mock chain with real authenticated WM/SWM HTTP and Curator handling. GitHub fixtures in automated tests are explicitly synthetic. Tests cover lossless readback, unchanged-source replay, changed-head revisions, review commit correspondence, sealed SHARE, repeat SHARE, and reuse through the standard CLI by a separately registered reader on the same node.
The public v0.1.3 deployment runs in a dedicated persistent case container. After the application restart, all five original public GitHub snapshots retained their content digests, observation times and selected WM/SWM state. Eighteen public page/API routes passed; anonymous writes returned 401. A distinct registered reader also retrieved two original Shared Memory packets with their original digests and observation times through the deployed CLI.
Strict attestation verification matched the exact source commit,
refs/tags/v0.1.3, release workflow, GitHub-hosted builder and immutable image digest. Anonymous registry manifest retrieval returned HTTP 200.Contributor attestation and support
This is a Round 1 submission at the
communitytrust tier for committee review. The first user is the ShadowHarness project. Development used gpt-6.1-sol in ShadowHarness with Sidera permanent memory infrastructure, supporting sustained autonomous engineering, source-linked recall and verified task handoffs. The submitted integration, its public GitHub source packets and verification evidence are directly inspectable.