feat(remediation): bind immutable desired changes - #308
Conversation
Add desired-change/v1 as an opaque exact binding between one validated Git source snapshot, one canonical transformer version, cited evidence, and exact proposed bytes. Reject forged, ambiguous, oversized, and no-op claims while preserving deterministic mutation-isolated state. Keep construction package-private and leave R2/R4, renderer policy, resolver wiring, authority, credentials, I/O, persistence, mutation, and execution structurally absent. GSTACK-Checkpoint: 2026-07-22/e14-desired-change#1 Signed-off-by: Gnani Rahul Nutakki <gnani.nutakki@gmail.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Exact-head local verification for
Scope remains deliberately narrow: immutable |
|
Final exact committed-diff review completed after the included-review allowance reset: CodeRabbit reviewed all six changed files at |
Summary
desired-change/v1bound to one exact validatedGitSourceSnapshotAuthority boundary
Construction is package-private until a concrete deterministic transformer or declarative renderer receives separate review. This PR adds no R2/R4 transformation policy, Brain/resolver/runtime wiring, PR metadata, handler binding, actor, intent, PEP call, approval, credential, network, persistence, dispatch, mutation, or execution. R2 and R4 remain advisory-only.
Verification
make ci: zero lint issues, no Go vulnerabilities, 94.8% remediation coverageCloses #307