Skip to content

Build the beginner Caldova Copilot workshop - #2

Merged
danielmeppiel merged 3 commits into
mainfrom
danielmeppiel-caldova-workshop-build
Sep 15, 2026
Merged

danielmeppiel merged 3 commits into
mainfrom
danielmeppiel-caldova-workshop-build

Conversation

@danielmeppiel

@danielmeppiel danielmeppiel commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Original, public, local-only workshop for tracked preparation issue #1. The starter is a six-document fictional board with no filter solution or active answer skills.

  • Thirteen beginner labs: manual prompting, three learner-authored skills, native review, APM packaging, release/versioning, and managed-configuration review. Full schedule: 5h40; the three-hour taster is explicitly incomplete.
  • Vanilla HTML/CSS/JS with pinned Node 24.21.0 LTS and Vite 7.3.6, baseline tests, responsive layout, and no backend or deployment.
  • Public fictional fixtures with immutable provenance, inert instructor examples/evals, strict staging/archive checks, app CI, and a tag-only draft-release workflow.

Current candidate and evidence

Candidate: e6bd7ea8ad6ba35a2c5dd425dc516c8ec683b4b1.

Current native CI passed at this SHA: clean npm ci, 21 tests, production build, and 28-document/13-lab contract checks. Local npm run check and unsolved-starter checks also passed. A generated CRLF copy passed all 17 package tests. Release staging fails when learner skills are absent. Prior local HTTP and desktop/375px browser checks remain applicable to the unchanged app. Workflow YAML parsed and action pins were verified.

The same code reviewer performed the original review and a bounded follow-up. Earlier CRLF and dangling-symlink defects were fixed. The follow-up found one CRLF-only negative-test mutation problem; it was corrected and verified in the real CRLF copy. No other high-confidence scoped finding was reported.

Policy-compliant packaging correction

The approved issue-plan addendum corrects the earlier unnecessarily restrictive zero-development-dependency assumption. Production dependencies: {} stays empty. One development input is pinned:

devexpgbb/zava-agent-config/plugins/secure-baseline#931cfb58663154415f8a13e14680f548114d4555

With compilation.source_attribution: true, ordinary checksum-verified APM 0.31.0 locking succeeded in the same governed checkout, with the available organization policy reporting enforcement=block. No policy was modified, skipped or weakened; no remote was removed and no sample was relocated to evade policy.

The full real rehearsal was repeated at the current candidate: stage → ordinary lock → remember-lock → fresh release staging → three native file audits → offline portable pack → actual archive verification. Fresh staging contained no apm_modules project cache. The normal and offline exports were byte-identical.

  • Exactly six files: three original skill entrypoints, plugin.json, empty mcp.json, and apm.lock.yaml.
  • Skill bytes match the inert original examples. No baseline instructions or agents were deployed into targets or exported as runtime content.
  • Source and embedded lock retain the exact dev commit/ref, is_dev: true, declared MIT license, content hash, and deployments: [].
  • Every actual archive entry, including the lock, was inspected: no absolute local paths, credentials, private policy-source details or session identifiers.
  • Actual wrong-version archive, wrong release tag and an added ZIP member were rejected. New exact-pin/provenance regressions failed against unfixed code first.
  • Instructor-sample ZIP SHA-256: 622022f52b1ae89de7685780b0bb2a74545658613b9675ea8be03a39feee513a.

This replaces the earlier NOT REHEARSED packaging limitation. It does not claim that structural packaging proves skill behavior or that every account has the same policy. The existing public organization policy was separately confirmed unchanged.

Remaining boundaries

Live WorkIQ, native cloud-review/automatic-dispatch comparisons, native tag/release execution, native plugin installation, enterprise policy activation, and Windows execution were not performed. Local CRLF simulation is not Windows execution. App CI remains independent of APM and WorkIQ.

No tag, release, global skill installation, admin setting, deployment, main-branch update, or primary-clone edit was made. The starter remains unsolved, and instructor samples remain outside active discovery/package source boundaries.

Candidate for human review and coordinated initial default-branch publication; this PR does not authorize publication or bypass any gate.

danielmeppiel and others added 2 commits September 15, 2026 22:15
Add the unsolved local document board, thirteen beginner labs, fictional fixtures, inert skill references, and guarded portable-plugin tooling.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@danielmeppiel

danielmeppiel commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor Author

Evidence record

  • record_type: verification
  • subject: PR Build the beginner Caldova Copilot workshop #2, candidate e6bd7ea8ad6ba35a2c5dd425dc516c8ec683b4b1
  • captured_at: 2026-09-15T20:52:19Z
  • captured_by: native GitHub CLI/API reads, checksum-pinned APM execution in the existing governed checkout, and independent archive inspection

The package-policy blocker is resolved. This record replaces the earlier
blocked-pack assessment. The organization policy was not weakened or changed.

Correlation

  • artifact_source_version: Git candidate e6bd7ea8ad6ba35a2c5dd425dc516c8ec683b4b1; not a deployed-service revision
  • seed_snapshot_version: not applicable to this static fictional document board
  • image_digest: not observed; no container or cloud deployment

Checks

check source result reference
Corrected candidate is committed and pushed git log, git status --short, gh pr view 2 pass PR #2, clean checkout at the stated full SHA
App, package regressions, build and documentation gh run view 35021983009 and its log pass Exact-head CI: 21 tests pass, production build, 28 documents, 13 labs, three inert skill examples
Existing policy remains unchanged GitHub contents and commit APIs, before/after comparison pass Policy blob 541cfd75ab763bb1571c965a78c2a1b91f91108a; policy repository HEAD 8d38ad09392fa130565581a8a0d541eab7bf2deb
Ordinary policy-active dependency resolution Checksum-verified APM 0.31.0 apm lock pass Existing policy reports enforcement: block; required public baseline resolves as the exact pinned development dependency
Complete real packaging path at the committed candidate package.mjs stage, apm lock, remember-lock, fresh release staging, three native file audits, offline portable pack, verify-package.mjs pass Repeated after the commit; release staging had no project apm_modules cache
Exact exported payload and provenance Native exporter, repository verifier, coordinator unzip and shasum reads pass Exactly three original skills plus plugin.json, mcp.json, and apm.lock.yaml; empty MCP; no baseline instructions or agents in runtime content
Development-only baseline stays out of active targets Lock metadata and filesystem inspection pass Public baseline at 931cfb58663154415f8a13e14680f548114d4555, is_dev: true, MIT, content hash retained, deployments: []; no generated baseline agent targets
Actual archive negative cases Repository verifier against actual modified archives and tag inputs pass Wrong version, wrong release tag and extra ZIP member rejected
Artifact public-safety and original skill bytes All-six-file inspection including embedded lock; byte comparison pass No absolute local paths, credentials, private policy details or session IDs; original skill bodies unchanged
Related participant guidance corrected File review and CI documentation checks pass Pinned development dependency versus runtime payload explained; stale positive-pack-not-rehearsed statement removed
Default-branch publication Native PR/base reference read not-run main remains the initial README at edcfa81ae4c77973d77bc4c86fc4a55f86b6acb4; full workshop and correction remain on this draft PR and in the local worktree

Reference archive SHA-256:
622022f52b1ae89de7685780b0bb2a74545658613b9675ea8be03a39feee513a.
This is an actual reference-skill rehearsal artifact, not a participant's work
or a published GitHub Release.

Unavailable signals

  • The hosted tag-to-release workflow was not triggered. Its equivalent local
    packaging path passed; those are different observations.
  • Windows execution, live WorkIQ, cloud-review comparisons, model-dispatch
    evaluations, native plugin installation and enterprise activation remain
    explicitly marked for their appropriate participant/facilitator rehearsals.
  • No current code-scanning success is claimed. The prior API read returned
    no analysis found (HTTP 404).
  • Default-branch publication has not been performed.

The earlier handoff mixed deployment-specific check names and rollback-image
requirements into this local-only workshop. Those are not additional workshop
requirements. The actual configured workflow is Local website and workshop checks; its check job succeeded at the stated candidate.

Advisory assessment

  • verdict: insufficient-evidence
  • rationale: The requested policy-resolution work is complete: the normal enforced path succeeds without a policy exception, bypass or relocation, and the runtime archive remains limited to the intended three skills. Workshop content and the correction are committed with passing native CI. The original delivery requirement to publish the material on the default branch is still outstanding, so this record does not claim the whole repository-delivery task is complete.
  • authority: advisory only; this record grants no approval

Resolve the required public baseline without deploying or exporting its guidance. Preserve exact lock provenance, rehearse offline three-skill export, and update the beginner packaging guidance. Refs #1.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@danielmeppiel
danielmeppiel marked this pull request as ready for review September 15, 2026 21:07
@danielmeppiel
danielmeppiel merged commit 7ab4082 into main Sep 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant