Status: experimental C14-D contract for issue #609.
IDKMesh needs a read-only GitHub publication surface that remains useful after a runner exits without copying raw evidence into Pages, comments, or other public surfaces. This contract defines a strict whitelist projection over canonical Product Spine state and optional digest-bound Run Evidence Report / CandidateReference details.
The implementation is idkmesh/github_public_evidence.py; the machine-readable
shape is schemas/github-public-evidence-v0.1.schema.json.
Projection requires a trusted GitHubPublicEvidencePolicy with:
owner/repository;data_classification = public;public_projection_enabled = true.The Product Spine project_id must match that repository. This policy is not
derived from issue text, worker output, model output, or provider metadata.
This module does not call GitHub to prove repository visibility. The caller must establish that the repository/data is actually public before constructing an enabling trusted policy. A false trusted policy is a configuration error, not evidence that the data was safe to publish.
Only these classes of information are projected:
Optional CandidateReference and Run Evidence Report objects are used only after their canonical digests match the Product Spine projection.
The projection never copies:
The schema carries explicit privacy flags for these exclusions.
A supplied candidate must match the exact retained
candidate_reference_digest.
For github_pull_request, the candidate repository must equal the publication
repository. The safe projection may then expose PR number, immutable head SHA,
and canonical GitHub URL.
For artifact_bundle, only the content digest is emitted. Locator and media
type are intentionally dropped because a locator may contain a private path,
signed URL, object key, or other environment detail.
A supplied Run Evidence Report must match:
Only closed-vocabulary evidence state/recommendation and aggregate counts are copied. Raw warnings, errors, checks, worker IDs, and verifier IDs are not public-projection inputs.
The projection is presentation evidence only. Every authority flag is fixed to
false:
Publishing a digest or verifier recommendation does not accept a candidate.
render_github_public_evidence_json() emits strict deterministic JSON with
sorted keys, no NaN values, and a 128 KiB UTF-8 ceiling. It performs no file,
network, GitHub, verification, decision, or repository mutation.
The renderer is itself a publication boundary: before serializing, it rejects any mapping whose root, run, attempt, candidate, or summary objects carry a key outside the v0.1 whitelist, and any mapping whose authority ceiling or privacy flags differ from the fixed values above. A hand-built or mutated mapping therefore cannot smuggle extra fields past the projection builder.
idkmesh/github_evidence_link.py) owns durable, commit-pinned
evidence links after runner teardown; this projection carries no links
beyond the canonical same-repository PR URL.