chore: add governance, provenance ledger, and security scanning #208

Merged
manlycucumber merged 1 commit from chore/governance into develop 2026-07-01 06:34:48 +00:00
manlycucumber commented 2026-07-01 06:32:35 +00:00 (Migrated from github.com)

Phase 0 of the roadmap-authoring pass — the deferred governance batch for Core.

Adds:

  • CODEOWNERS — default owner + reserves a liturgical-data reviewer for corpus/precedence/provenance paths (per CONTRIBUTING).
  • CodeQL workflow — security scanning. CodeQL has no PHP analyzer, so it scans the Actions workflows (supply-chain/injection); PHP SAST stays with PHPStan (+ Psalm taint mode as a roadmap item).
  • FUNDING.yml — placeholder for a future Sponsor button.
  • SOURCES.md — the provenance ledger: every corpus datum cites an entry here; seeds the authoritative rubric/Missal/Breviary/Martyrology sources + the validation oracles, with clean-room licence status per source.
  • ERRATA.md — public corrections register, keyed to the data-version stamp.
  • KNOWN-LIMITATIONS.md — honest coverage/confidence register.
  • CITATION.cff — citation metadata.

Org-wide CONTRIBUTING (DCO + clean-room attestation), Code of Conduct, SECURITY, and the Liturgical correction issue form now live in the new Introibo-App/.github repo.

Docs/config only — no engine code changed.

Phase 0 of the roadmap-authoring pass — the deferred governance batch for Core. Adds: - **CODEOWNERS** — default owner + reserves a **liturgical-data reviewer** for corpus/precedence/provenance paths (per CONTRIBUTING). - **CodeQL workflow** — security scanning. CodeQL has no PHP analyzer, so it scans the **Actions workflows** (supply-chain/injection); PHP SAST stays with PHPStan (+ Psalm taint mode as a roadmap item). - **FUNDING.yml** — placeholder for a future Sponsor button. - **SOURCES.md** — the provenance ledger: every corpus datum cites an entry here; seeds the authoritative rubric/Missal/Breviary/Martyrology sources + the validation oracles, with clean-room licence status per source. - **ERRATA.md** — public corrections register, keyed to the data-version stamp. - **KNOWN-LIMITATIONS.md** — honest coverage/confidence register. - **CITATION.cff** — citation metadata. Org-wide **CONTRIBUTING** (DCO + clean-room attestation), **Code of Conduct**, **SECURITY**, and the **Liturgical correction** issue form now live in the new [Introibo-App/.github](https://github.com/Introibo-App/.github) repo. Docs/config only — no engine code changed.
github-advanced-security[bot] commented 2026-07-01 06:33:15 +00:00 (Migrated from github.com)

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. ### What Enabling Code Scanning Means: - The 'Security' tab will display more code scanning analysis results (e.g., for the default branch). - Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. - You will be able to see the analysis results for the pull request's branch on this [overview](/Introibo-App/Core/security/code-scanning?query=pr%3A208+is%3Aopen) once the scans have completed and the checks have passed. For more information about GitHub Code Scanning, check out [the documentation](https://docs.github.com/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning).
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Directorium/Core!208
No description provided.