feat(uuid-v7): exempt registry-assigned Julia dependency UUIDs - #1138
Conversation
Julia names every dependency by the UUID the General registry assigned it, so a Julia repository cannot pass check-uuid-v7.sh however it is written. The standard already says external identifiers are preserved and typed explicitly; Project.toml dependency tables are such a typed context. The checker now skips the [deps], [weakdeps] and [extras] tables of Project.toml / JuliaProject.toml, and Julia Manifests. A package's own top-level `uuid =` is still checked, so new Julia packages mint v7 before registration. Scanned text is a subset of before: nothing that passed fails. Five new cases in uuid-v7-test.sh (16/16 pass). Mutants: the main checker fails exactly the two acceptance cases; a whole-file Project.toml exemption fails exactly the two narrowness cases. Standard revised to v1.1. Owner decision 2026-10-02 (selection UI): dependency tables only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (24)
|
| Layer / File(s) | Summary |
|---|---|
Document and implement UUID exclusions docs/UUID-V7-ESTATE-STANDARD.adoc, scripts/check-uuid-v7.sh, scripts/tests/uuid-v7-test.sh |
The standard and checker exclude Julia manifest UUIDs and UUIDs in the [deps], [weakdeps] and [extras] tables of Julia project files. The checker continues to evaluate the package’s top-level UUID. Tests cover these exclusions and confirm that other UUIDs remain checked. |
Priority: ⬇️ Low
Estimated code review effort: 2 (Simple) | ~10 minutes
Change: Feature
Suggested reviewers: joshuajewell
Merge Risk: 🔵 Low · up to 67e99
A Julia project can pass the UUID check despite having a non-v7 package UUID when a multiline string contains a dependency-table header. This narrow case warrants owner awareness but does not block merging.
Architecture Summary
Architecture risk: 🔵 Low · up to 67e99
The change affects 2 systems.
Changed systems: scripts, docs
Architecture concerns
No architecture-level concerns identified.
Review details
Systems and components
- observed — scripts (service) was modified; 2 changed files map to changed impact.
- observed — docs (service) was modified; 1 changed file maps to changed impact.
Before / after behavior
- observed — Modified behavior in docs/UUID-V7-ESTATE-STANDARD.adoc: The standard identifies Julia project dependency tables and Julia manifests as checker exclusions because their package UUIDs are registry-assigned. A package’s own top-level
uuidremains checked and must be v7 before first registration. - observed — Modified behavior in docs/UUID-V7-ESTATE-STANDARD.adoc: The revision history adds v1.1, recording the Julia dependency UUID exclusions and stating that repositories previously passing remain passing, while Julia repositories whose only findings were dependency UUIDs now pass; package-own UUIDs remain governed.
- observed — Modified behavior in scripts/check-uuid-v7.sh: Added
scannable_text, which outputs nothing for Julia manifest files, removes the[deps],[weakdeps]and[extras]tables from Julia project files, and passes other files through unchanged. - observed — Modified behavior in scripts/check-uuid-v7.sh: The UUID-match input now comes from
scannable_textinstead of directly grepping the file; the existing UUID pattern and empty-result fallback are unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Docstring Coverage | ✅ Passed | Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 … |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Title check | ✅ Passed | The title clearly and concisely describes the main change: exempting registry-assigned Julia dependency UUIDs from the UUID v7 check. |
| Description check | ✅ Passed | The description directly explains the Julia UUID exemption, the affected files, the tests, the governance requirements, and the migration impact. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
📝 Generate docstrings
- 🤖 Coding Agent task started for docstring generation.
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks each UUID line,
And leaves registry IDs behind.
The package’s own must meet the rule,
The tests check every table’s role.
The standard’s notes now match the tool.
Comment @coderabbitai help to get the list of available commands.
|
|
✅ Coding Agent task started: View task and status The task will inspect the CI failures, validate its fix, and commit the fix to this branch automatically.
⏭️ 3 check(s) skipped — already failing on `main` (not caused by this PR)
|
|
Open the task to resolve the delivery issue or retry. |
Replaces the AFFIRMATION.adoc template with a draft. The template's placeholders are the only error from `call-estate-audit / estate-audit` on main (run 37017560464). This addresses that box on #3. **For your review: this is your statement, so edit it freely before merging.** Each claim was produced in this session at anchor `a68b585`: - `Pkg.test()`: 377 pass, 1 skipped (the live sandbox test, which needs a token). It includes Aqua and JET. - `proofs/agda/check.sh` with Agda 2.6.4.3 and stdlib 2.1: type-checks with `--safe --without-K` and no postulates. - `proofs/agda/generate.jl` was re-run and gave no diff, so the proved table is the code's table. The *What we do NOT claim* section lists: - no live deposit has been made; - the Julia–Agda correspondence beyond the table is argued, not formalised; - the package is not yet registered; - the remaining reds on #3; - the tests ran on Julia 1.12.6 only. The audit's placeholder regex (`\{\{|rsr-template-repo|TODO: update|<PROJECT|YOUR_PROJECT|lorem ipsum|example\.com`) is clean on this file and matches the template (control). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj ### Deferred red checks (§5c) Each of these checks was already red on `main` before this PR. Each one is tracked on #3: - `lint-workflows`: tracked on #3, fixed by #6 (unpinned reusables on main) - `call-estate-audit / estate-audit`: tracked on #3. On `main` it fails with "AFFIRMATION.adoc contains template placeholders", which this PR fixes. On this PR it fails at a different step: `cicd-suite/actions/affirmation-check/check.sh` treats `%G?`=`E` (the signature cannot be checked) as a bad signature. The runner checks out GitHub's synthetic merge commit 34f875a. That commit is PGP-signed with GitHub's key, which the runner does not hold. The head commit c1d835f (then b4e528b) is `verified: true` on GitHub. The fix belongs in cicd-suite; it is the owner's decision. - `governance / UUID v7 conformance`: tracked on #3, fixed by hyperpolymath/standards#1138, then #8 - `Julia nightly - ubuntu-latest`: tracked on #3, fixed by #9 - `SonarQube`: tracked on #3, fixed by the owner creating the SonarCloud project **Caveat (unmeasured):** merging this probably will not turn `estate-audit` green on `main`. GitHub signs the squash commit with its own key, so the same checker is likely to read `%G?`=`E` there too. Clearing it needs the cicd-suite fix (owner decision; see #3). Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Fixes the `lint-workflows` red tracked on #3 ("reusable workflow calls not SHA-pinned"). ## What changes - Six `hyperpolymath/standards` reusable calls are pinned from `@main` to `e2e0f6d61c2d2a36ef516849dc1ca9223563479f`, which was standards `main` on 2026-10-02. The six are governance, scorecard, codeql, secret-scanner, hypatia-scan and mirror. - The `cicd-suite` `main-estate-audit` call is pinned to `5087cbb080cd6c5e9a79fee3fcc20acd82431bb4`, which was cicd-suite `main` on 2026-10-02. - `actions: read` is granted to the scorecard caller, at both the workflow and job level, and to the mirror caller, at the workflow level. Their pinned reusables request that scope. A reusable workflow cannot elevate past its caller, so without the grant those jobs fail at startup. I think this also explains the OSSF Scorecard `startup_failure` on #3. That is a hypothesis, which the Scorecard run on this PR will confirm or refute. `actions.lock` is unchanged. Its entries for these callers are already `[]`. The pages workflow is not touched, because a separate PR handles it. ## Checks run locally - `gh actions-lock --no-fix` exits 0, and its output is identical to main's. - Every workflow file parses as YAML. - No `uses: …@main` remains in `.github/workflows`. Refs #3 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj ### Deferred red checks (§5c) Each of these checks was already red on `main` before this PR. Each one is tracked on #3: - `call-estate-audit / estate-audit`: tracked on #3. #5 fixes main's placeholder error (#5's own run is blocked by a separate cicd-suite affirmation-check issue: the signature state `E`) - `governance / UUID v7 conformance`: tracked on #3, fixed by hyperpolymath/standards#1138, then #8 - `Julia nightly - ubuntu-latest`: tracked on #3, fixed by #9 - `SonarQube`: tracked on #3, fixed by the owner creating the SonarCloud project Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Part of the UUID v7 conformance red on #3. Owner decision 2026-10-02: re-mint the package UUID as v7 now, while that is still possible. ## What changes - `Project.toml`: `uuid` changes from `928c34ec-c44f-4801-ad1c-d3b833d76a91` (v4) to `01a0fd25-08dc-75f2-9446-d9ab13218ca1` (v7, from `UUIDs.uuid7()` on Julia 1.12.6). The General registry fixes a package's UUID at first registration, so this is the last chance to change it. - `docs/Project.toml`: same UUID update in its `[deps]` entry for the package. - `test/runtests.jl:508`: the fixture bucket id is now a v7-shaped literal. The test still exercises the same refusal of a bucket on another host. ## Status of the UUID check This PR does **not** turn `governance / UUID v7 conformance` green on its own. The remaining findings are dependency UUIDs assigned by the registry. They need hyperpolymath/standards#1138, which narrows the checker and is awaiting review by both estate owners. After #1138 merges, the governance caller pin has to move to the merge commit, because the reusable checks out the validator at `job.workflow_sha`. ## Checks run locally - `Pkg.test()`: 377 pass, 1 broken. The broken entry is the opt-in live sandbox test, which was skipped. - The checker from standards#1138 (`check-uuid-v7.sh .`) exits 0 on this tree. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj ### Deferred red checks (§5c) Each of these checks was already red on `main` before this PR. Each one is tracked on #3: - `call-estate-audit / estate-audit`: tracked on #3. #5 fixes main's placeholder error (#5's own run is blocked by a separate cicd-suite affirmation-check issue: the signature state `E`) - `governance / UUID v7 conformance`: tracked on #3, fixed by hyperpolymath/standards#1138, then #8 - `Julia nightly - ubuntu-latest`: tracked on #3, fixed by #9 - `SonarQube`: tracked on #3, fixed by the owner creating the SonarCloud project Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Closes the "Julia nightly" item on #3 by its second done-criterion: the nightly job is now reported as allowed to fail. - **What changes:** the job name changes from `Julia nightly - ubuntu-latest` to `Julia nightly (allowed to fail) - ubuntu-latest`, and a comment gives the reason. - **Unchanged:** the job was already `continue-on-error: true`, and it still runs. It still shows red while upstream is broken. Nothing is hidden. - **The upstream cause, on main run 37024620408:** JuliaInterpreter does not precompile on nightly (`MethodError: no method matching nteltype(::Core.SimpleVector)`), so JET is skipped. - **No stranded check:** `rules/branches/main` returns `[]`, so no required context refers to the old name. - **Local checks:** the workflow parses as YAML, and `gh actions-lock --no-fix` exits 0. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj ### Deferred red checks (§5c) Each of these checks was already red on `main` before this PR. Each one is tracked on #3: - `call-estate-audit / estate-audit`: tracked on #3. #5 fixes main's placeholder error (#5's own run is blocked by a separate cicd-suite affirmation-check issue: the signature state `E`) - `governance / UUID v7 conformance`: tracked on #3, fixed by hyperpolymath/standards#1138, then #8 - `Julia nightly (allowed to fail) - ubuntu-latest`: tracked on #3, fixed by this PR (the job is renamed to say it is allowed to fail; the upstream red stays visible) - `lint-workflows`: tracked on #3, fixed by #6 - `SonarQube`: tracked on #3, fixed by the owner creating the SonarCloud project Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…INTAINERS (#12) After the transfer to `metadatastician`, `call-estate-audit / estate-audit` (required-files-check) fails on main ee687b7: `MAINTAINERS never mentions the repository owner (metadatastician)`. This adds one sentence to `MAINTAINERS` and `MAINTAINERS.adoc` naming the owning organisation; @hyperpolymath stays the maintainer (owner decision 2026-10-02: transfer intended, add the org owner). It is independent of #11 (URLs) and touches no file #11 touches. Local check of the gate predicate (`grep -qiF metadatastician`): passes on both files here, fails on both on main (control). Measured on this PR: the Required Files step now passes, and estate-audit fails only at the Affirmation Document Gate, where the GitHub-signed commit reads `E`. That is fixed at source in hyperpolymath/cicd-suite#39 (draft, for review), but it reaches this repo only after three steps: 1. cicd-suite#39 merges. 2. cicd-suite repins its composites at that merge (hyperpolymath/cicd-suite#40). 3. This repo bumps `call-estate-audit` from `5087cbb` to the repin's merge SHA, plus any `actions.lock` entry the bump needs. Until then, `call-estate-audit / estate-audit` stays red for that reason alone. The other reds here are not caused by this PR and are tracked elsewhere: - Actions lockfile verify: the relock after Dependabot #10. - UUID v7 conformance: hyperpolymath/standards#1138. - OSSF Scorecard: the shared standards workflow. All of them are listed on #3. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>



Governance change: it needs review by both estate owners. Per
docs/UUID-V7-ESTATE-STANDARD.adoc, narrowing what the UUID v7 gate scans counts as weakening it, so this PR must not be auto-merged.Why
Julia names every dependency by the UUID the General registry assigned it, and a dependant cannot change that UUID. Today, therefore, no Julia repository can pass
check-uuid-v7.sh. Measured on hyperpolymath/ZenodoDeposits.jl: 14 findings, of which 12 are inProject.toml. The standard already says external identifiers are "preserve and type explicitly". A Julia dependency table is exactly that kind of typed context.What changes
scripts/check-uuid-v7.sh:scannable_text.Project.tomlandJuliaProject.toml, the[deps],[weakdeps]and[extras]tables are not scanned. A package's own top-leveluuid =is still checked.Manifest*.tomlandJuliaManifest*.tomlare not scanned. Every entry in them is a resolved dependency.scripts/tests/uuid-v7-test.sh: five new cases, all with UUIDs assembled at runtime as before. 16/16 pass.docs/UUID-V7-ESTATE-STANDARD.adoc: revised to v1.1. It now describes the exemption, assesses the migration impact, and says new Julia packages must mint their own UUID as v7 before registration..machine_readable/uuid-v7-estate-standard.a2ml(version "1.0.0") is deliberately not touched, under the estate A2ML doctrine. Its version string now trails the adoc.Evidence
bash scripts/tests/uuid-v7-test.shpasses 16/16, rc 0.[deps]case and the Manifest case.Project.tomlexempted): exactly the two narrowness cases fail, the own-uuidcase and the "exemption ends at the next table" case.sh scripts/check-uuid-v7.sh .on this repo gives rc 0. The docstring scan reports 100%.Owner decision 2026-10-02: exempt dependency tables only. Needed by metadatastician/ZenodoDeposits.jl#3, along with a v7 re-mint of that package's own UUID before registration.
🤖 Generated with Claude Code
https://claude.ai/code/session_01JPmNukJT5PUzQ9d74mhHhj
Deferred red check (§5c)
governance / Workflow security linter: this PR does not cause it. It is also red onmain, from a duplicate-key false positive inprovisioning-check-reusable.yml, and is tracked in Workflow security linter: duplicate-key checker false-positives on KYAML flow sequences (red on main since #1133) #1137.