Skip to content

Validate bounded cross-file artifact references - #11

Merged
Chumaniac merged 2 commits into
mainfrom
codex/publish-reference-integrity-20261009
Oct 9, 2026
Merged

Chumaniac merged 2 commits into
mainfrom
codex/publish-reference-integrity-20261009

Conversation

@Chumaniac

Copy link
Copy Markdown
Owner

What changed

Add bounded reference_exists checks for physical CSV deliveries. A citation ID must exactly match a declared unique string ID in another CSV; missing references and reference-capacity overflow become findings. Findings omit original IDs. README, contract documentation and a synthetic citation fixture describe the source capability.

Safety boundary

  • No credentials or private contents were added.
  • No new network, runtime execution or host mounts were introduced.
  • Reference indexes hold only SHA-256 fingerprints and row numbers, with a 100,000-cell ceiling.

Verification

  • 559 tests passed; one opt-in Docker test skipped.
  • Type check, lint and build passed.
  • Package dry-run includes the new runtime, contract fixture and documentation.
  • The synthetic reference-integrity CLI scenario passes.

Documentation

  • README, artifact contract documentation and changelog updated.
  • Source and public npm release remain separate claims; this PR does not publish a package.

@Chumaniac
Chumaniac merged commit ac2ccc0 into main Oct 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant