Skip to content

chore(license): drop Palimpsest preamble, plain MPL-2.0 (batch 7/7)#101

Merged
hyperpolymath merged 1 commit into
mainfrom
license/drop-palimpsest-preamble-2026-06-01
Jun 1, 2026
Merged

chore(license): drop Palimpsest preamble, plain MPL-2.0 (batch 7/7)#101
hyperpolymath merged 1 commit into
mainfrom
license/drop-palimpsest-preamble-2026-06-01

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Owner-authorised. Drops Palimpsest preamble + FALLBACK framing, replaces with plain MPL-2.0 (Mozilla Public License Version 2.0). SPDX-License-Identifier in file headers remains MPL-2.0. Net 65 ins / 100 del.

Replaces LICENSE preamble 'PREFERRED LICENCE: Palimpsest License (PMPL-1.0)'
+ 'FALLBACK LICENCE: Mozilla Public License 2.0' framing with plain
MPL-2.0 text. SPDX-License-Identifier headers in source/doc files
remain MPL-2.0 unchanged.

Net: 65 insertions, 100 deletions. Owner-authorised explicitly via
the M1 foreign-WIP triage walkthrough.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath enabled auto-merge (squash) June 1, 2026 20:29
@hyperpolymath hyperpolymath merged commit bc11749 into main Jun 1, 2026
13 of 23 checks passed
@hyperpolymath hyperpolymath deleted the license/drop-palimpsest-preamble-2026-06-01 branch June 1, 2026 20:56
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Jun 1, 2026

🔍 Hypatia Security Scan

Findings: 134 issues detected

Severity Count
🔴 Critical 10
🟠 High 24
🟡 Medium 100

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action perpolymath/standards/.github/workflows/governance-reusable.yml@main\n needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "lean-verification.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "rust-cli.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in cflite_batch.yml",
    "type": "missing_timeout_minutes",
    "file": "cflite_batch.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in cflite_pr.yml",
    "type": "missing_timeout_minutes",
    "file": "cflite_pr.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in compilation_tests.yml",
    "type": "missing_timeout_minutes",
    "file": "compilation_tests.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant