-
Notifications
You must be signed in to change notification settings - Fork 4
[ACP-HARDEN-230] 汎用private-to-public Evidence export contractを追加する #3662
Copy link
Copy link
Open
Labels
area:contractsSchemas and contractsSchemas and contractsassurance-control-planeAgent-neutral assurance control plane roadmapAgent-neutral assurance control plane roadmapcodex-readyIssue body is structured for Codex CLI executionIssue body is structured for Codex CLI executionpriority:p1Important next sliceImportant next slicerisk:highHigh risk PR (approval and gate labels required)High risk PR (approval and gate labels required)type:taskImplementation taskImplementation task
Description
Activity
Metadata
Metadata
Assignees
Labels
area:contractsSchemas and contractsSchemas and contractsassurance-control-planeAgent-neutral assurance control plane roadmapAgent-neutral assurance control plane roadmapcodex-readyIssue body is structured for Codex CLI executionIssue body is structured for Codex CLI executionpriority:p1Important next sliceImportant next slicerisk:highHigh risk PR (approval and gate labels required)High risk PR (approval and gate labels required)type:taskImplementation taskImplementation task
Parent: #3655
Depends on: ACP-HARDEN-130, ACP-HARDEN-210, ACP-HARDEN-220
Blocks: #3640
Codex lane:
evidence/private-public-export背景
現行
publication-evidence/v1はae-framework自身のbranch protection、npm、Marketplace公開に特化している。Private repository、customer-sensitive project、embargoed security/IP情報から、公開可能なEvidence metadataだけを決定的にexportする汎用contractは存在しない。Private Matchでは、strict allowlist、status非変換、lifecycle上限、deterministic serialization、source/artifact/Protocol/exporter digest、test-only分離、secret/customer/private path/vulnerability/IP gate、value-free omission log、人間publication approval分離が必要だった。
目的
Private Match固有Schemaをコピーせず、ae-frameworkの汎用Evidence export profile/candidate/bundle contractとして上流化する。
Codex CLI preflight
Proposed package and contracts
推奨package:
packages/evidence-export/@ae-framework/evidence-export推奨contracts:
private-export-candidate/v1public-evidence-bundle/v1evidence-export-profile/v1evidence-exporter-implementation/v1Human-decided boundary
実装タスク
execution-result/v1とartifact refsを使用し、statusをexact preservationする。publication-evidence/v1との役割差を文書化する。Acceptance criteria
Validation
pnpm -s run check:schemaspnpm -s run check:doc-consistencypnpm -s run verify:lite非目標
Stop condition