Skip to content

Harden the critical-appraisal ebook for safer public release - #8

Draft
rkalani1 wants to merge 1 commit into
mainfrom
codex/public-release-hardening-2026-07-30
Draft

Harden the critical-appraisal ebook for safer public release#8
rkalani1 wants to merge 1 commit into
mainfrom
codex/public-release-hardening-2026-07-30

Conversation

@rkalani1

Copy link
Copy Markdown
Owner

Summary

  • Clarify the license boundary: ISC for repository code, CC BY 4.0 only for publisher-controlled book content and cleared assets.
  • Add third-party notices, contribution/security policies, citation metadata, asset rights records, an SBOM, and a dated publication review.
  • Review all 28 chapters, correct identified content issues, replace weak-provenance figures with semantic HTML/CSS, and self-host cleared fonts.
  • Add hash-locked dependencies and fail-closed release gates for source, provenance, secrets, rendered output, active content, external egress, MathJax integrity, and exact deployment revision.

Validation

  • 27/27 adversarial release-gate mutation tests passed.
  • 24/24 ebook structural tests passed.
  • 43 bounded numerical/source checks passed.
  • Exact committed build passed: 32 HTML pages, 11.48 MiB, release SHA 6ad0cb9.
  • Gitleaks 8.30.1 scanned 1,051 reachable commits and about 1.64 GB of Git text with no detected leak.
  • Runtime, audit, and bootstrap lock audits found no known vulnerabilities; CFF and CycloneDX SBOM validation passed.

Release hold

Draft only. Do not merge or deploy until the owner confirms:

  1. the right to license the text, code, current images, and applicable AI-assisted output;
  2. UW, sponsor, employment, commissioned-work, and affiliation obligations;
  3. that no patient/source data or third-party confidential material was used; and
  4. whether to retain the existing public Git history or replace it with a clean-history publication repository.

This PR does not rewrite history. Historical assets were screened with bounded automated methods, not full raster OCR, source-data reconstruction, visual-similarity clearance, trademark clearance, or a legal chain-of-title opinion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant