feat: Native Intent → Execution → Evidence foundation with optional ISEE governance
Maintainer thường phản hồi trong vòng 2 ngày
@suuus đang làm issue này rồi.
Từ ngày 7/10/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Summary
Establish a portable governance foundation for Git-Ape that records deployment
Intent, captures what actually executed, and preserves immutable Evidence without
requiring the ISEE suite to be installed.
ISEE remains an optional governance and independent-verification layer that can
be installed before or after Git-Ape records are created.
Motivation
Git-Ape already performs security, cost, architecture, approval, deployment, and
validation stages. However, these stages need portable, machine-readable records
that preserve:
- what was intended;
- which execution path actually occurred;
- which artifacts and control results were produced;
- who or what authorized the deployment;
- whether records were independently governed or verified.
These records should remain useful without introducing a mandatory runtime or
package dependency.
Scope
- Save onboarding and deployment Intent as ADRP-compatible draft records.
- Declare versioned deployment execution graphs.
- Capture immutable, graph-bound execution traces.
- Derive CI traces from actual workflow step outcomes.
- Label interactive traces as
agent-observed. - Emit immutable AERP-compatible Evidence bundles for successful and failed runs.
- Bind Evidence to exact artifact bytes and archived graph versions.
- Support delayed adoption by ADRP, ASRP, and AERP tooling.
- Preserve truthful lifecycle states:
- native Intent is
draft; - native Evidence is
generated; - only authoritative tooling may ratify or independently verify records.
- native Intent is
- Retain Git-Ape's existing Bash,
jq, and SHA-256 dependency baseline.
Relationship to #148
#148 delivers the structured execution-trace portion of this foundation.
The trace implementation deliberately uses workflow-owned reconstruction in CI
rather than requiring agents to self-report their own completeness. Interactive
agent observations remain supported, but are explicitly identified as
agent-observed and are not represented as independent proof.
The Intent, trace, Evidence, and optional ISEE integration are tightly connected
and may be delivered through one implementation PR referencing both issues.
Acceptance criteria
- Onboarding preserves platform Intent as an ADRP-compatible draft.
- Each deployment preserves deployment-specific Intent before execution.
- Each workflow attempt receives an immutable invocation identity.
- The exact execution graph used by each attempt is archived.
- Traces are bound to the archived graph digest.
- Trace validation checks nodes, transitions, receipts, ordering, continuity,
required successful nodes, and terminal outcomes. - Failed attempts can produce valid traces ending at the failed node.
- Evidence bundles include trace, validation, graph, state, test, and relevant
deployment artifacts. - Evidence is emitted for successful and failed attempts.
- Optional ISEE adoption validates existing records without regenerating or
automatically ratifying them. - Record or Evidence failures do not rewrite Azure deployment lifecycle state.
- Native operation introduces no runtime dependency beyond existing Bash/
jq
tooling. - Scaffolding, tests, evaluations, and user documentation cover the lifecycle.
- Ngôn ngữ chính
- JavaScript
- Star
- 269
- Fork
- 48
- Merge trung bình
- 2 ngày 19 giờ
- Pull request đã merge (30 ngày)
- 15
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Azure/git-ape
-
daily-status report
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 15/100
Maintainer thường phản hồi trong vòng 2 ngày
-
agentic-workflows workshop workshop-sync
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 1/100
Maintainer thường phản hồi trong vòng 2 ngày
-
report workshop-coverage
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 1/100
Maintainer thường phản hồi trong vòng 2 ngày
-
agentic-workflows
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
Maintainer thường phản hồi trong vòng 2 ngày
-
agentic-workflows
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Azure/git-ape#370 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của Azure/git-ape
Issue tương tự
-
Engineering
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
techmatters/terraso-web-client#3095 ·
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Service process inherits the caller's cwd at first use, holding that folder open on Windows (EBUSY)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
nextcloud/viewer#3424 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày