| content |
{"Commits":[{"Sha1":"cc01b358a {"Commits":[{"Sha1":"cc01b358aa703aa260970023b69448f58e59f14c","Message":"治理上线 ②④: 恢复 CI 硬门禁(豁免感知) + 文档对账机制 + Phase2 单测全绿\n\nPhase 1 — 治理门禁与文档真相机制:\n- ci.yml governance-audit 移除 job/verdict continue-on-error 转真硬门禁;\n 内联粗判换成 governance-gate.ts(豁免感知,逐 finding 判 effective fatal)\n + baseline-reconcile.ts(CLAUDE.md GOVERNANCE-BASELINE 受控块 vs reports 对账)\n- 新增 gate-integrity-check.ts 元门禁防止门禁被静默软化(独立脚本避免自指)\n- reports/governance-exemptions.json: 3 个 medium 登记 owner 签字带 expiry\n 受控豁免(content-review 状态机/hr_integration_sync_logs/pending_approval),\n CI 可见、2026-07-17 到期自动复现,非 continue-on-error 批量隐藏\n- CLAUDE.md v5.5 节降级为历史快照 + 插入机器校验 GOVERNANCE-BASELINE 受控块\n- 清除 ci.yml \"硬门禁由 .github 同名 job 承担\" 虚构安全网注释(该文件不存在)\n\nPhase 2 — 单测硬门禁恢复:\n- test:unit 基线 30 文件/137 测试失败(origin/main 既有, 全测试侧漂移、\n 无业务 bug) → 按 4 类诚实范式(import 收窄/收敛壳委托测试重写/tx-mock/\n canonical 断言对齐)逐文件对齐 canonical 修复\n- 独立全量验证: 518 文件 / 7355 测试 100% 绿、退出码 0\n- ci.yml unit-tests 移除 job+step continue-on-error → Unit Tests (HARD GATE);\n gate-integrity-check.ts 扩展纳入 unit-tests 保护(job+step 双向对抗验证通过)\n- 残留 continue-on-error 16→14(仅 14 个合法单项 audit step)\n\n纪律: 唯一业务文件改动 = dimension-transform.service.ts 给 2 个纯助手加\nexport(零行为变更, 范式①); 其余全为测试对齐 canonical, 无捏造 API、\n无为迁就测试改业务/状态机/schema。\n\n不含: 仓库内并行的 RLS 加固 / dual-customer-rollout / AGENTS·GEMINI·README\n等改动(非本工作流, 由对应 owner 单独提交)。\n\n验证: YAML 合法; governance-gate/baseline-reconcile/gate-integrity-check\n3 脚本 strict tsc rc=0 且运行 rc=0; meta-gate 注入对抗 rc=1、还原 rc=0;\n全量 test:unit rc=0。\n\nCo-Authored-By: Claude Opus 4.7 (1M context) \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"luoguoguo@gmail.com","AuthorName":"luoguoguo","CommitterEmail":"luoguoguo@gmail.com","CommitterName":"luoguoguo","Timestamp":"2026-05-18T17:43:17-07:00"}],"HeadCommit":{"Sha1":"cc01b358aa703aa260970023b69448f58e59f14c","Message":"治理上线 ②④: 恢复 CI 硬门禁(豁免感知) + 文档对账机制 + Phase2 单测全绿\n\nPhase 1 — 治理门禁与文档真相机制:\n- ci.yml governance-audit 移除 job/verdict continue-on-error 转真硬门禁;\n 内联粗判换成 governance-gate.ts(豁免感知,逐 finding 判 effective fatal)\n + baseline-reconcile.ts(CLAUDE.md GOVERNANCE-BASELINE 受控块 vs reports 对账)\n- 新增 gate-integrity-check.ts 元门禁防止门禁被静默软化(独立脚本避免自指)\n- reports/governance-exemptions.json: 3 个 medium 登记 owner 签字带 expiry\n 受控豁免(content-review 状态机/hr_integration_sync_logs/pending_approval),\n CI 可见、2026-07-17 到期自动复现,非 continue-on-error 批量隐藏\n- CLAUDE.md v5.5 节降级为历史快照 + 插入机器校验 GOVERNANCE-BASELINE 受控块\n- 清除 ci.yml \"硬门禁由 .github 同名 job 承担\" 虚构安全网注释(该文件不存在)\n\nPhase 2 — 单测硬门禁恢复:\n- test:unit 基线 30 文件/137 测试失败(origin/main 既有, 全测试侧漂移、\n 无业务 bug) → 按 4 类诚实范式(import 收窄/收敛壳委托测试重写/tx-mock/\n canonical 断言对齐)逐文件对齐 canonical 修复\n- 独立全量验证: 518 文件 / 7355 测试 100% 绿、退出码 0\n- ci.yml unit-tests 移除 job+step continue-on-error → Unit Tests (HARD GATE);\n gate-integrity-check.ts 扩展纳入 unit-tests 保护(job+step 双向对抗验证通过)\n- 残留 continue-on-error 16→14(仅 14 个合法单项 audit step)\n\n纪律: 唯一业务文件改动 = dimension-transform.service.ts 给 2 个纯助手加\nexport(零行为变更, 范式①); 其余全为测试对齐 canonical, 无捏造 API、\n无为迁就测试改业务/状态机/schema。\n\n不含: 仓库内并行的 RLS 加固 / dual-customer-rollout / AGENTS·GEMINI·README\n等改动(非本工作流, 由对应 owner 单独提交)。\n\n验证: YAML 合法; governance-gate/baseline-reconcile/gate-integrity-check\n3 脚本 strict tsc rc=0 且运行 rc=0; meta-gate 注入对抗 rc=1、还原 rc=0;\n全量 test:unit rc=0。\n\nCo-Authored-By: Claude Opus 4.7 (1M context) \u003cnoreply@anthropic.com\u003e\n","AuthorEmail":"luoguoguo@gmail.com","AuthorName":"luoguoguo","CommitterEmail":"luoguoguo@gmail.com","CommitterName":"luoguoguo","Timestamp":"2026-05-18T17:43:17-07:00"},"CompareURL":"luoanwu/juhi-omni-knowledge-hub/compare/8d19578e5c20ba6ef6405795d9bfad0ac5946fe6...cc01b358aa703aa260970023b69448f58e59f14c","Len":1}... |