Skip to content

[WP02 · SubStep 02.05] Enforce desktop dependency admission and upgrade evidence - #9

Merged
deku2026 merged 1 commit into
mainfrom
wp02-05-dependency-policy
Sep 22, 2026
Merged

deku2026 merged 1 commit into
mainfrom
wp02-05-dependency-policy

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

The desktop consumer now rejects unadmitted/floating dependencies, forbidden licences, internal Contracts, wrong publishers/feeds and rewritten immutable versions. The owner policy closes all 91 existing NuGet package-version identities from locks and cached published metadata. Upgrade evidence seals actual inputs, and framework baseline versions are checked against accepted Git source.

The policy runs in the existing check with retained evidence. Source adaptation uses immutable ArcNotes b7358bd, with r4 provenance superseding and preserving r1/r2/r3. Exact package versions, application behavior and existing Windows/Linux CI remain unchanged.

Validation: cache-only locked restore, targeted C# build with zero warnings/errors, all 12 offline dependency-policy tests, repository/provenance/effective declarations and whitespace review passed. No local runtime, public downloads or toolchain provisioning. Required CI remains the merge gate.

@deku2026
deku2026 merged commit 1214224 into main Sep 22, 2026
11 checks passed
@deku2026
deku2026 deleted the wp02-05-dependency-policy branch September 22, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant