Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
65 commits
Select commit Hold shift + click to select a range
4612722
Reproduce upstream Psychoinformatics site
leej3 Aug 6, 2026
a553741
Add Pixi-controlled upstream preview tasks
leej3 Aug 10, 2026
3978b54
Wire local SHACL Vue editor preview
leej3 Aug 10, 2026
b7fdbc3
Track SHACL Vue deployment compatibility commit
leej3 Aug 10, 2026
fb3c4c6
Add full recursive submodule checkout task
leej3 Aug 10, 2026
66b2fe4
Run the upstream editor against a local service stack
leej3 Aug 10, 2026
a35040d
Use leej3 mirrors for recursive submodules
leej3 Aug 10, 2026
3d95038
Make pixi serve start the complete local deployment
leej3 Aug 10, 2026
6e8516b
docs: record commit message preferences
leej3 Aug 10, 2026
5b8380a
docs: refine formatting preferences
leej3 Aug 10, 2026
59e6229
build: add Pixi-controlled Snapper hook
leej3 Aug 10, 2026
85b7f0e
style: normalize Markdown with Snapper
leej3 Aug 10, 2026
1746416
build: finalize reproducible local trial runtime
leej3 Aug 11, 2026
7920ded
docs: clarify the CURIE-only schema contract
leej3 Aug 11, 2026
b141b17
docs(clean-migration): record the upstream ancestry exception
leej3 Aug 11, 2026
e12b965
build(clean-migration): add deterministic CON projection
leej3 Aug 11, 2026
05d779a
feat(stack): isolate CON and upstream collections
leej3 Aug 11, 2026
f54cf5f
chore(submodules): pin the clean migration site
leej3 Aug 11, 2026
ca2b3c4
docs: start the full CON migration
leej3 Aug 11, 2026
4428a36
build(full-migration): generalize the CON contracts
leej3 Aug 11, 2026
7ce44a2
chore(submodules): pin the full CON migration site
leej3 Aug 11, 2026
dd496d5
docs: start milestone 3
leej3 Aug 12, 2026
eb46fb9
build(deps): pin the static editor runtime
leej3 Aug 12, 2026
be4fcb6
feat(preview): add static Pages editing
leej3 Aug 12, 2026
b1ed0c9
feat(zotero): pin public publication ingestion
leej3 Aug 12, 2026
bd0bc2c
fix(preview): harden editor reproducibility
leej3 Aug 12, 2026
526054b
chore(submodules): pin the Milestone 3 site
leej3 Aug 12, 2026
6b2f779
fix(preview): canonicalize editor RDF
leej3 Aug 12, 2026
2957a35
fix(ci): use the accepted Pixi version syntax
leej3 Aug 12, 2026
80ac1fa
fix(preview): reset generated editor plugins
leej3 Aug 12, 2026
67ae3b8
fix(ci): hydrate preservation refs in Pages builds
leej3 Aug 12, 2026
f6841f1
chore(submodules): refresh the hosted site snapshot
leej3 Aug 12, 2026
0027199
fix(ci): make annex hydration pristine-run safe
leej3 Aug 12, 2026
dd6e93d
chore(submodules): refresh the hosted site digest
leej3 Aug 12, 2026
b7cc0a3
fix(ci): preserve the audited Pages artifact
leej3 Aug 12, 2026
5359a7d
docs(milestone): open the Milestone 3 review
leej3 Aug 12, 2026
7a3b359
test(build): lock the CON image override contract
leej3 Aug 12, 2026
5bca07e
chore(submodules): pin the portable CON artifact
leej3 Aug 12, 2026
a910461
docs(milestone): record the portable preview evidence
leej3 Aug 12, 2026
adf608d
test(content): cover the poster preview shortcode
leej3 Aug 12, 2026
b1ca3a9
fix(build): reject CON link prefetching
leej3 Aug 12, 2026
075b9ed
chore(submodules): pin the poster-safe CON artifact
leej3 Aug 12, 2026
0df9ed8
docs(milestone): record the poster-safe review build
leej3 Aug 12, 2026
b5b879d
docs(milestone-3): resolve repository placement decisions
leej3 Aug 12, 2026
6fe0ecd
docs(milestone-4): activate downstream distribution
leej3 Aug 12, 2026
762f7d9
feat(release): add single-repository distribution engine
leej3 Aug 12, 2026
fa9f75d
fix(release): make editor builds independently reproducible
leej3 Aug 12, 2026
c6fa2ae
fix(release): install assembly dependency in clean runners
leej3 Aug 12, 2026
e7fe3de
fix(release): publish portable artifact checksums
leej3 Aug 12, 2026
86dd18b
fix(runtime): enforce declared Hugo compatibility
leej3 Aug 12, 2026
4cf1605
fix(ci): use setup-pixi version syntax
leej3 Aug 12, 2026
fc895c6
fix(runtime): support full consumer inputs
leej3 Aug 12, 2026
4aece03
fix(runtime): keep verified releases immutable
leej3 Aug 12, 2026
2eac81e
docs(milestone-4): align the updater interface
leej3 Aug 12, 2026
24218c1
fix(projection): preserve the reviewed control sidecar
leej3 Aug 12, 2026
c31871b
fix(runtime): accept packaged Hugo revision labels
leej3 Aug 13, 2026
06edee2
fix(runtime): restore editor links on record pages
leej3 Aug 13, 2026
0a0b089
fix(editor): bind record selectors to canonical PIDs
leej3 Aug 13, 2026
6af02ad
docs(milestone-4): record terminal implementation evidence
leej3 Aug 13, 2026
b4518be
fix(ci): skip legacy preview for milestone 4
leej3 Aug 13, 2026
1e1001e
fix(runtime): make local builds host-neutral
leej3 Aug 13, 2026
dc04a0c
docs(milestone-4): record local preview fixes
leej3 Aug 13, 2026
b8b35c0
docs(milestone-4): prepare comprehensive human review
leej3 Aug 13, 2026
947cb47
docs(review): accept opt-in engineering preview
leej3 Aug 13, 2026
d7e6f35
docs(licensing): adopt Orinoco Lite license matrix
leej3 Aug 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .githooks/pre-commit
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
#!/usr/bin/env bash
set -euo pipefail

exec pixi run pre-commit run --hook-stage pre-commit "$@"
96 changes: 96 additions & 0 deletions .github/workflows/con-pages-preview.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
name: CON Pages preview

on:
workflow_dispatch:
inputs:
deploy:
description: Deploy this exact ref to the github-pages environment
required: true
default: false
type: boolean

permissions:
contents: read

jobs:
build:
name: Build the backend-free CON artifact
runs-on: ubuntu-24.04
timeout-minutes: 45
permissions:
contents: read
concurrency:
group: con-pages-build-${{ github.ref }}
cancel-in-progress: true

steps:
- name: Check out the pinned recursive source tree
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
submodules: recursive

- name: Verify the accepted clean-migration checkpoints
shell: bash
run: |
set -euo pipefail
readonly parent_checkpoint=f54cf5fdb2b5ae4bf03fe6939246316fd9ec818d
readonly site_checkpoint=a122e506de9e4a13473edbe8d74a950d74032a16
readonly checkpoint_ref=refs/remotes/origin/codex/clean-migration

git fetch --no-tags --no-recurse-submodules origin \
refs/heads/codex/clean-migration:${checkpoint_ref}
test "$(git rev-parse "${checkpoint_ref}")" = "${parent_checkpoint}"

git -C submodules/centerforopenneuroscience.org fetch \
--no-tags --no-recurse-submodules origin \
refs/heads/codex/clean-migration:${checkpoint_ref}
test "$(git -C submodules/centerforopenneuroscience.org \
rev-parse "${checkpoint_ref}")" = "${site_checkpoint}"

- name: Install the locked Pixi environment
uses: prefix-dev/setup-pixi@f00437f565399d418b0acc85936d12c1fb668347 # v0.10.1
with:
cache: true
cache-write: true
locked: true
pixi-version: v0.73.0

- name: Run focused contracts
run: pixi run test-pages

- name: Build twice and exercise the static editor
run: pixi run test-pages-browser

- name: Upload the reviewed static artifact
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
include-hidden-files: true
path: build/pages-preview/orinoco-lite-dev

deploy:
name: Deploy the reviewed Pages artifact
needs: build
if: >-
inputs.deploy
runs-on: ubuntu-24.04
timeout-minutes: 10
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
permissions:
contents: read
id-token: write
pages: write
concurrency:
group: con-pages-deployment
cancel-in-progress: true

steps:
- name: Configure the Pages deployment
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0

- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0
85 changes: 85 additions & 0 deletions .github/workflows/orinoco-consumer-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: Orinoco consumer CI

on:
workflow_call:
inputs:
command:
description: "Consumer facade task: validate, build, or test-all"
type: string
required: false
default: test-all
runner:
description: GitHub-hosted runner label
type: string
required: false
default: ubuntu-24.04
artifact-name:
description: Optional name of an artifact to upload after the task
type: string
required: false
default: ""
artifact-path:
description: Consumer-relative artifact path
type: string
required: false
default: build/site
pixi-version:
description: Exact Pixi release used to run the locked consumer
type: string
required: false
default: v0.73.0

permissions:
contents: read

jobs:
consumer:
name: ${{ inputs.command }} (${{ inputs.runner }})
runs-on: ${{ inputs.runner }}
steps:
- name: Validate reusable-workflow inputs
shell: bash
env:
ORINOCO_COMMAND: ${{ inputs.command }}
ORINOCO_ARTIFACT_PATH: ${{ inputs['artifact-path'] }}
run: |
case "$ORINOCO_COMMAND" in
validate|build|test-all) ;;
*)
echo "command must be validate, build, or test-all" >&2
exit 2
;;
esac
case "$ORINOCO_ARTIFACT_PATH" in
/*|*..*|*\\*)
echo "artifact-path must be a safe repository-relative path" >&2
exit 2
;;
esac

- name: Check out the ordinary consumer repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Install locked Pixi
uses: prefix-dev/setup-pixi@f00437f565399d418b0acc85936d12c1fb668347
with:
pixi-version: ${{ inputs['pixi-version'] }}
cache: true
frozen: true

- name: Run the consumer facade
shell: bash
env:
ORINOCO_COMMAND: ${{ inputs.command }}
run: pixi run "$ORINOCO_COMMAND"

- name: Upload the requested consumer artifact
if: ${{ inputs['artifact-name'] != '' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: ${{ inputs['artifact-name'] }}
path: ${{ inputs['artifact-path'] }}
if-no-files-found: error
retention-days: 14
185 changes: 185 additions & 0 deletions .github/workflows/orinoco-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,185 @@
name: Orinoco release artifacts

on:
workflow_dispatch:
inputs:
version:
description: Release version matching release/runtime-source*.yaml
required: true
type: string
source-spec:
description: Reviewed runtime source specification
required: true
default: release/runtime-source.yaml
type: string
push:
tags:
- v*

permissions:
contents: read
id-token: write
attestations: write

jobs:
release-artifacts:
runs-on: ubuntu-24.04
steps:
- name: Check out the exact release source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Initialize only release-authorized components
shell: bash
run: |
git submodule sync -- \
submodules/pool.psychoinformatics.de-ui \
submodules/things-schemas
git submodule update --init --depth 1 -- \
submodules/pool.psychoinformatics.de-ui \
submodules/things-schemas
git -C submodules/pool.psychoinformatics.de-ui submodule update \
--init --depth 1 -- shacl-vue

- name: Install Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
with:
python-version: "3.12.13"

- name: Install exact Node and npm toolchain
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
with:
node-version: "22.23.2"

- name: Verify exact release toolchain
shell: bash
run: |
npm install --global npm@10.9.4
test "$(python --version)" = "Python 3.12.13"
test "$(node --version)" = "v22.23.2"
test "$(npm --version)" = "10.9.4"

- name: Build package artifacts
env:
SOURCE_DATE_EPOCH: "0"
run: |
python -m pip install --disable-pip-version-check \
build==1.3.0 PyYAML==6.0.2
find release/dist release/dist-repeat -mindepth 1 -delete 2>/dev/null || true
mkdir -p release/dist release/dist-repeat
python -m build packages/orinoco-lite --outdir release/dist
python -m build packages/orinoco-lite --outdir release/dist-repeat
PYTHONPATH=packages/orinoco-lite/src python -m orinoco_lite.release_package \
release/dist/orinoco_lite-*.tar.gz
PYTHONPATH=packages/orinoco-lite/src python -m orinoco_lite.release_package \
release/dist-repeat/orinoco_lite-*.tar.gz
cmp release/dist/orinoco_lite-*.whl \
release/dist-repeat/orinoco_lite-*.whl
cmp release/dist/orinoco_lite-*.tar.gz \
release/dist-repeat/orinoco_lite-*.tar.gz

- name: Assemble deterministic runtime archive
shell: bash
env:
INPUT_SPEC: ${{ inputs['source-spec'] }}
INPUT_VERSION: ${{ inputs.version }}
run: |
version="$INPUT_VERSION"
spec="$INPUT_SPEC"
if [ -z "$version" ]; then
version="${GITHUB_REF_NAME#v}"
fi
if [ -z "$spec" ]; then
if [ "$version" = "0.1.0" ]; then
spec="release/runtime-source.yaml"
elif [ -f "release/runtime-source-v$version.yaml" ]; then
spec="release/runtime-source-v$version.yaml"
else
echo "No reviewed runtime source spec for $version" >&2
exit 2
fi
fi
SPEC="$spec" VERSION="$version" python - <<'PY'
import os, pathlib, tomllib, yaml
value = yaml.safe_load(pathlib.Path(os.environ["SPEC"]).read_text())
if str(value.get("release")) != os.environ["VERSION"]:
raise SystemExit("runtime spec release does not match requested version")
package = tomllib.loads(pathlib.Path("packages/orinoco-lite/pyproject.toml").read_text())
if str(package["project"]["version"]) != os.environ["VERSION"]:
raise SystemExit("package version does not match requested version")
PY
editor_source="$(mktemp -d)"
cp -R submodules/pool.psychoinformatics.de-ui/. "$editor_source/"
PYTHONPATH=packages/orinoco-lite/src \
python -m orinoco_lite.release_editor \
--pool-ui "$editor_source" \
--overlay release/editor-v2 \
--shell build/runtime-editor-shell \
--licenses build/runtime-editor-licenses
find build/runtime-schema -mindepth 1 -delete 2>/dev/null || true
mkdir -p build/runtime-schema
PYTHONPATH=packages/orinoco-lite/src \
python -m orinoco_lite.release_schema \
--source-root submodules/things-schemas/src \
--entry submodules/things-schemas/src/demo-research-information/unreleased.yaml \
--destination build/runtime-schema
PYTHONPATH=packages/orinoco-lite/src \
python -m orinoco_lite release assemble \
--spec "$spec" \
--source-commit "$GITHUB_SHA" \
--output "release/dist/orinoco-runtime-$version.tar.gz"
mv build/runtime-editor-shell build/runtime-editor-shell-first
mv build/runtime-editor-licenses build/runtime-editor-licenses-first
editor_source_repeat="$(mktemp -d)"
cp -R submodules/pool.psychoinformatics.de-ui/. "$editor_source_repeat/"
PYTHONPATH=packages/orinoco-lite/src \
python -m orinoco_lite.release_editor \
--pool-ui "$editor_source_repeat" \
--overlay release/editor-v2 \
--shell build/runtime-editor-shell \
--licenses build/runtime-editor-licenses
diff -qr build/runtime-editor-shell-first build/runtime-editor-shell
diff -qr build/runtime-editor-licenses-first build/runtime-editor-licenses
PYTHONPATH=packages/orinoco-lite/src \
python -m orinoco_lite release assemble \
--spec "$spec" \
--source-commit "$GITHUB_SHA" \
--output "release/dist-repeat/orinoco-runtime-$version.tar.gz"
cmp "release/dist/orinoco-runtime-$version.tar.gz" \
"release/dist-repeat/orinoco-runtime-$version.tar.gz"
(
cd release/dist
find . -maxdepth 1 -type f ! -name SHA256SUMS -printf '%f\0' \
| sort -z | xargs -0 sha256sum > SHA256SUMS
)

- name: Attest the release artifact checksums
id: attestation
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8
with:
subject-checksums: release/dist/SHA256SUMS

- name: Include the provenance bundle in the release set
env:
ATTESTATION_BUNDLE: ${{ steps.attestation.outputs.bundle-path }}
run: cp "$ATTESTATION_BUNDLE" release/dist/orinoco-provenance-bundle.jsonl

- name: Verify the installed wheel and hermetic package contracts
run: |
echo "Full 199-record parity is consumer-owned and may report an intentional skip here."
python -m venv build/release-test
build/release-test/bin/pip install --disable-pip-version-check \
release/dist/orinoco_lite-*.whl
build/release-test/bin/python -c \
'import orinoco_lite,sys; assert str(orinoco_lite.__file__).startswith(sys.prefix)'
build/release-test/bin/python -m unittest discover \
-s packages/orinoco-lite/tests -v 2>&1 | tee build/release-tests.log

- name: Upload immutable release candidates
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: orinoco-lite-release-candidate
path: release/dist
if-no-files-found: error
retention-days: 14
Loading