Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
strace --version

- name: Install independent vector tool
uses: taiki-e/install-action@41049aa56687c35e0afa74eed4f09cec4f9afabf # v2.85.2
uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22
with:
tool: b3sum@1.8.5

Expand Down Expand Up @@ -177,7 +177,7 @@ jobs:
run: rustup show

- name: Install dependency policy tools
uses: taiki-e/install-action@41049aa56687c35e0afa74eed4f09cec4f9afabf # v2.85.2
uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22
with:
tool: cargo-deny@0.18.9,cargo-audit@0.22.0

Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ after its public API and format compatibility policies are established.

## [Unreleased]

- Update the repository-only YAML parser to yaml-rust2 0.13.0 and refresh its dependency admission, retaining existing workflow and Dependabot refusal expectations (#103).

- Update the development-only Markdown validation graph and exact admission policy to markdownlint-cli2 0.23.3, addressing the js-yaml, smol-toml and markdown-it advisories while documenting the separate remaining braces advisory (#106).

- Current durable-surface documentation distinguishes delivered recovery, fenced authenticated reads and explicit verification from pending ingestion, GC, compaction and general candidate-catalog retained-closure admission (#130).

- Retention verification refuses observed file or symlink substitutions of a selected namespace directory as typed corruption, preserving the original selected root evidence (#114).
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ before creating documentation or substantially changing an existing page. It
does not require rewriting pages that are merely below the bar; apply it when
a change would otherwise add new documentation debt.

Documentation validation uses `markdownlint-cli2` 0.23.2, `lychee` 0.21.0,
Documentation validation uses `markdownlint-cli2` 0.23.3, `lychee` 0.21.0,
and `actionlint` 1.7.12. Install those exact versions, then run the
repository-owned checks from the repository root:

Expand Down
12 changes: 6 additions & 6 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion docs/Documentation Standards.md
Original file line number Diff line number Diff line change
Expand Up @@ -541,7 +541,7 @@ git diff --check
git diff --cached --check
```

Use `markdownlint-cli2` 0.23.2. The repository-owned configuration records
Use `markdownlint-cli2` 0.23.3. The repository-owned configuration records
deliberate rule choices. The Rust checker selects tracked Markdown plus
nonignored new Markdown, disables configuration globs for that invocation,
and refuses a different tool version. It also runs `lychee` 0.21.0 offline
Expand Down
5 changes: 2 additions & 3 deletions docs/dependencies/documentation-toolchain.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
Keep uses three development-only tools to enforce deterministic documentation
and GitHub Actions facts:

- `markdownlint-cli2` 0.23.2 validates Markdown structure;
- `markdownlint-cli2` 0.23.3 validates Markdown structure;
- `lychee` 0.21.0 validates local links and fragments with network access
disabled;
- `actionlint` 1.7.12 validates GitHub Actions syntax and expressions.
Expand All @@ -20,8 +20,7 @@ The CI job pins Node.js 24.18.0 and installs exact tool releases. The committed
`scripts/documentation-tools/package-lock.json` pins every Markdownlint
transitive archive and Subresource Integrity digest. The installer uses
`npm ci` with lifecycle scripts disabled and refuses lockfile drift.
`markdownlint-cli2` 0.23.2 directly admits the patched `js-yaml` 5.2.2
release.
`markdownlint-cli2` 0.23.3 admits `js-yaml` 5.4.1, `smol-toml` 1.8.0 and `markdown-it` 15.0.1, addressing the corresponding previously reported parser advisories. The lock graph retains `braces` 3.0.3; [GHSA-vfj7-8cjw-p6xm](https://github.com/advisories/GHSA-vfj7-8cjw-p6xm) has no patched version listed as of 2026-10-03. Follow-up [#176](https://github.com/flyingrobots/keep/issues/176) tracks its disposition; this development-tool update does not claim a clean npm audit. The production documentation command supplies explicit Git-selected paths with `--no-globs`; its bounded runner reports tool failure rather than admitting failed validation.

`scripts/install_documentation_tools.sh` verifies the native release archives
before extraction:
Expand Down
68 changes: 0 additions & 68 deletions docs/dependencies/yaml-rust2-0.11.0.md

This file was deleted.

51 changes: 51 additions & 0 deletions docs/dependencies/yaml-rust2-0.13.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Dependency Admission: yaml-rust2 0.13.0

- Status: Accepted for repository-task YAML admission only
- Updated: 2026-10-03
- Owner: Keep repository verification
- Upstream: [Ethiraric/yaml-rust2](https://github.com/Ethiraric/yaml-rust2)

## Admitted use

Keep admits exactly pinned `yaml-rust2` 0.13.0 only behind the `xtask` crate's `repository-tasks` feature. The documentation-integrity task parses the CI workflow and Dependabot configuration through `YamlLoader::load_from_str`; fuzz-campaign workflow tests also consume that parser.

Workflow admission selects the documentation job's actual executable fields and admits only the reviewed steps, permissions, triggers and tool setup. Dependabot admission checks update scopes against the repository's tracked manifests. Comments, display strings and unrelated fields cannot substitute for those structural contracts.

The dependency is absent from Keep's published library graph, public API, content identities, durable formats and production storage behavior. Its typed parse error remains inside the private repository-task adapter.

## Why a dependency is needed

YAML includes quoted and block scalars, comments, aliases, nested collections and duplicate mapping keys. A maintained parser keeps admission structural without introducing a partial YAML implementation inside Keep.

Parsed values are never hashed, persisted or admitted as Keep domain types. The task reads fixed policy paths through the bounded, capability-relative, no-follow repository-file boundary before parsing.

## Features and resolved graph

The direct dependency disables default features and is optional. Only `repository-tasks` activates it; non-UTF-8 decoding through the upstream `encoding` feature is excluded.

The resolved normal dependency graph includes:

- `arraydeque` 0.5.1;
- `foldhash` 0.2.0;
- `hashbrown` 0.17.1; and
- `hashlink` 0.12.2.

## Upgrade and compatibility

PR #103 updates the previous 0.11.0 admission. Upstream raises its minimum supported Rust version to 1.85.0, below Keep's pinned 1.96.0, and updates hashlink and hashbrown. The MIT OR Apache-2.0 license expression is unchanged.

The published 0.13.0 source changes its active scanner's `map_or(false, ...)` expression to `is_some_and(...)` and corrects the `Marker::index` documentation to bytes. Its short-input decoder progress fix is inside the disabled `encoding` module; Keep does not claim that fix as an exercised runtime improvement.

The 0.13.0 Rust source contains no `unsafe` block. Keep-owned code continues to invoke safe APIs, and dependency-owned YAML types remain private to tooling.

Existing workflow, duplicate-key, Dependabot and CLI admission laws are exercised in debug and release, without editing their expectations. These are bounded tool-contract checks; they do not establish equivalence over every possible YAML input or strengthen Keep's storage claims.

The reviewed lockfile, license/source policy checks and security advisory checks remain required point-in-time admission evidence. Earlier green checks on 0.11.0 do not certify this graph.

## Failure and recovery boundaries

Malformed YAML, duplicate mapping keys, missing policy fields, unreviewed commands, oversized input, non-UTF-8 input and replaced repository roots remain typed refusal cases covered by the existing admission contracts. The task does not repair or rewrite workflow data. Parsing has no storage durability or recovery semantics.

Keep can remove this dependency without changing public or durable behavior by replacing it with a parser that preserves structural selection, duplicate-key refusal, the reviewed-command laws and the manifest-coverage contract.

Reopen this admission if the direct version, selected features, resolved graph, license, MSRV, repository-task-only boundary or admitted YAML use changes.
Loading
Loading