Summary
Restore deterministic validation for the organization CI, configuration, starter-template, and issue-form surfaces under the approved Track A v2 plan.
Baseline:
- Commit:
9dab73078d0c476892693e0d0c45843398a137d1
- Tree:
e9c6a55c98f957400ba37297a1d2dbf27e9cd7f4
- Plan SHA-256:
7d316fa04a93dbe406c3ca590dddf5b8d19853fc0fd54f39fa4cb586ae4027e4
- Profile:
core+metrics
Verified findings
.trunk/trunk.yaml declares Go 1.21.0, while its Gitleaks 8.30.1 build silently selected Go 1.25.13. A qualified Go 1.26.6 candidate built Gitleaks with the declared toolchain and passed the default-rule functional canary.
- Archive-only full-repository Trunk checks cannot run
git-diff-check; Track A requires a marker-protected task-owned real Git fixture.
workflow-templates/project-tracker.properties.json is orphaned after the deliberate Linear transition.
.github/workflows/static.yml deploys the whole repository and uses mutable action references without an owning runbook or issue.
- Four issue forms contain policy or governance links that no longer resolve.
- Renovate guidance still uses the legacy
baseBranches key and a stale ADR-0004 status statement.
Accepted boundaries
Track A acceptance criteria
Safety boundary
This issue does not authorize staging, source commits, push, pull request creation, merge, release, live workflow dispatch, settings mutation, hosted Renovate changes, Dependency Dashboard approval, cross-repository changes, or cleanup.
Related ownership
Summary
Restore deterministic validation for the organization CI, configuration, starter-template, and issue-form surfaces under the approved Track A v2 plan.
Baseline:
9dab73078d0c476892693e0d0c45843398a137d1e9c6a55c98f957400ba37297a1d2dbf27e9cd7f47d316fa04a93dbe406c3ca590dddf5b8d19853fc0fd54f39fa4cb586ae4027e4core+metricsVerified findings
.trunk/trunk.yamldeclares Go 1.21.0, while its Gitleaks 8.30.1 build silently selected Go 1.25.13. A qualified Go 1.26.6 candidate built Gitleaks with the declared toolchain and passed the default-rule functional canary.git-diff-check; Track A requires a marker-protected task-owned real Git fixture.workflow-templates/project-tracker.properties.jsonis orphaned after the deliberate Linear transition..github/workflows/static.ymldeploys the whole repository and uses mutable action references without an owning runbook or issue.baseBrancheskey and a stale ADR-0004 status statement.Accepted boundaries
Track A acceptance criteria
Safety boundary
This issue does not authorize staging, source commits, push, pull request creation, merge, release, live workflow dispatch, settings mutation, hosted Renovate changes, Dependency Dashboard approval, cross-repository changes, or cleanup.
Related ownership