docs: make README product-first and integrator-friendly - #160
docs: make README product-first and integrator-friendly#160seonghobae wants to merge 13 commits into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughREADME가 증거 중심 HRIS/HCM 제품 범위, bounded context, 아키텍처 경계, 검증 절차, PII 보호 계약, 현재 상태, 문서 맵, 기여 지침 및 라이선스를 설명하도록 확장되었습니다. ChangesREADME 제품 및 저장소 기준
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This PR updates documentation and its integrity record without changing runtime, dependency, schema, API, workflow, release, permission, or product behavior; no actionable merge-blocking risk remains beyond normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Lifecycle repair — live state is now Draft and supersedes the stale |
Outcome
Refresh Orgmetra's protected-
developlanding page around its code-current HRIS/HCM responsibility instead of mixing the product story with stale active-PR state.npm ci,npm run validate);Evidence and licensing
The README is grounded in
docs/PRD.md,ARCHITECTURE.md,docs/TRACEABILITY.md, package metadata, repository workflows, and the existing rootLICENSE/NOTICE. The Apache-2.0 grant applies to Orgmetra-owned source; third-party packages and external systems retain their own terms. No certification, production deployment, employment-decision authority, or customer claim is invented.Repair chain
Fresh hosted validation first proved that the README manifest record was stale; the branch resealed it from the exact README bytes instead of weakening repository integrity. Fresh review then found an unsealed
docs/index.mdpublic landing candidate outside the validator's closed required-artifact set. That candidate was removed rather than widening the public surface without a publication/integrity contract, leaving the governed root README as the landing source.Current README maturity labels distinguish protected-main implementation, accepted architecture, and planned/active-PR boundaries, including separate Psychometrics Commons versus fast-mlsirm responsibilities. Validation scope is explicit so
npm run validateis not represented as complete PostgreSQL/package verification.The README also separates Orgmetra-local controls/trust-boundary documentation from vulnerability disclosure. Suspected vulnerabilities are directed to the organization-owned
ContextualWisdomLab/.github@main:SECURITY.mdreporting policy. No claim is made that repository-private vulnerability reporting is enabled unless live repository evidence establishes it.The feature snapshot's manifest seal matches its README bytes after that reporting repair (
sha256=10f4ad947efee5e54166cd31e18cf30d34489b7c13fd05cb565363c1a86271c5, 9,344 bytes, 141 lines). That seal is historical source evidence only and must be regenerated after protected-parent reconciliation.Live authority and lifecycle repair
a7d9e1aa0fb6e007e3b0cb8f495f4d4dc512e9e8;develop@9e3e4847510e1e612b48474ba42b177b8ed824df;develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f;The earlier non-Draft/mergeable wording is superseded. Protected
develophas advanced through #161 repository-quality workflow consolidation, so this README/manifest lane must reconcile that protected truth rather than overwrite it with either historical tree. A conflict or non-mergeable result is a repair finding, not a close condition.Historical exact-source evidence on
a7d9e1a...remains non-transferable: Foundation CI33586731896, Recovery Rehearsal33586731888, and Job-Analysis API Quality33586731749were terminal-success; Security Scan33586731818failed at Dependency Review support; SAST33586731773was non-terminal at the recorded snapshot. Those results cannot authorize a reconciled head.Required non-force reconciliation
Preserve the valid product-first README content, non-force adopt the then-current protected
develop, and resolve README/provenance conflicts semantically. Do not resurrect workflows removed by #161. After the final README bytes are chosen, regeneratemanifest.jsonfrom those exact bytes rather than selecting either stale manifest wholesale. Then reacquire every applicable exact-head Foundation/recovery/Security/SAST/CodeQL/review gate before Ready.Current diff intent remains README plus deterministic manifest only; no runtime, dependency, schema, API, workflow, release, certification, employment-decision, UI, or ecosystem-ownership behavior is claimed by this lane.
Do not force-rebase, self-approve, use routine administrator bypass, enable auto-merge on stale evidence, add no-op retrigger churn, transfer predecessor evidence, or treat temporary mergeability as authorization.