Skip to content

[B2] Replace generic self-built governance checks with mature OSS #1156

Description

@SisyphusZheng

Part of #1155 and #1192. Target: continuous Beta.2.x cleanup; residual closure in beta.2.3.

Objective

Alongside each verified responsibility migration, replace generic repository-owned governance with pinned mature tools and delete duplicated custom machinery.

Scope

  • Renovate for supported Deno/npm/JSR/GitHub Actions dependency updates
  • Gitleaks and GitHub secret protection
  • markdownlint-cli2 and lychee
  • actionlint and zizmor
  • CodeQL and OpenSSF Scorecard
  • publint and Are The Types Wrong against packed artifacts
  • CODEOWNERS, issue forms, PR templates, and generated release notes
  • AutoFlow/checker inventory and deletion of generic duplicate authority

Acceptance

  • Mature tools run reproducibly and fail CI non-zero for owned violations.
  • Replaced custom implementation, tests, tasks, and workflow steps are removed in the same migration.
  • Remaining repository-owned checks map to named OpenElement invariants.
  • No duplicate generic authority remains.

Boundary

This issue does not block Alpha compiler/runtime work. It is also not a Beta.2.1 completion gate: Beta.2.1 carries only the supporting/non-blocking inventory (owned by #1320's scope), and the first concrete executable migration preparation begins in Beta.2.2. Do not build wrapper frameworks, long-lived dual paths, or broad repository-owned equivalence suites around mature tools.

Source audit and deletion candidates (2026-09-08)

See docs/architecture/infrastructure-reduction.md in planning PR #1342. This is a bounded audit, not completed migration.

Accepted upstream-contribution priority — 2026-09-08

Select replacement tools for the most credible sustained upstream-contribution path, not lowest local glue. Existing publint/ATTW are already installed: reduce overlap and contribute real generic gaps. Evaluate dependency-cruiser/lychee with OE/Deno constraints. Scope Oxc/TS7 executable preparation in Beta.2.2 (decorators, diagnostics, source maps, declarations, Deno resolution), not production backend replacement; full production migration remains independently qualified Alpha work. Each migration names recipient/version/native harness/reproducer/patch boundary and OE remainder.

Use docs/architecture/infrastructure-reduction.md and VERSION_PLAN as scope. Prepare useful generic fixes for contribution through normal authorization; no invented bugs, cosmetic PR quota, or upstream-response release dependency. No migration is completed by this update.

Approved executable maturation — 2026-09-09

  • Beta.2.2: inventory TS syntax, TypeChecker, CLI, declaration and pack consumers.
  • Run representative Oxc TSX -> existing PartProgram comparison with properties/computed/events/conditional/keyed regions and adversarial provenance/Unicode spans. Reuse current grammar/determinism/source-map tests; hold emitter and authoring contract stable initially.
  • Qualify TS7 CLI type/declaration/resolution separately from Deno check and old Compiler API. Inspect deno pack staging and generated-code strictness exceptions; verify final declarations/maps in independent consumers.
  • Evaluate upstream CEM extraction separately from OE hydration/layer policy; do not merely port the bespoke scanner to Oxc.
  • Record binding/install/OS/CPU/Deno requirements, parse/analysis/emit/total costs and portable upstream gaps.
  • Alpha: actively implement independently qualified Oxc frontend and TS7 type/declaration adoption. Temporary differential paths have an exit; no permanent dual production frontend or public generic AST API. Documented blockers allow deferral, not silent abandonment.
  • Close only when adopted replacements retire old owners and deferred scope has explicit disposition. Correctness, provenance, diagnostics, maps and runtime behavior are hard gates; local speed/LOC are not the only benefits.

Scope: docs/architecture/alpha-maturation.md and VERSION_PLAN (planning PR #1342). Upstream contribution potential can justify bounded extra integration cost; no invented defects, PR quota or upstream-response release dependency. This update changes planned work, not implementation status.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    architecturecigovernanceRepository governance and policy ownershiptoolsv0.44v0.44 compiled OpenElement architecture train

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions