chore: OSS standard polish — contributing triad, repo hygiene, pluto shrapnel, canonical docs - #183
Merged
Merged
Conversation
…luto shrapnel gone, canonical docs Five items, ~1 hour of work, closing every 'below standard' gap surfaced in the pre-v2.10 audit: 1. CONTRIBUTING.md, CODE_OF_CONDUCT.md (Contributor Covenant v2.1), SECURITY.md — the adoptability triad. Email for security reports is dev@motionvector.io with 72h ack. CI expectations written down; the bandit baseline is called a recorded debt list, not something to wave away. 2. Research receipts move from repo root to experiments/routing-research/ (all 8 files: expert_superset_*, prompt_predictor_*, step3b_*, moe_stability_results). They are research receipts behind FLEET-PLAN/CONCEPT claims, not product. README explains what they are and where the live registry actually lives. 3. 'pluto' shrapnel: config.py CORS whitelist had 4 hard-coded pluto.localhost entries (the pre-#101 rename); mflux_driver error text referenced .pluto_config.json which does not exist (real name is .spacepilot_config.json). Both fixed. The LEGACY compat paths (paths.py legacy_user_data_dir/cache_dir, cli.py LEGACY_CONFIG_FILE, PLUTO_MFLUX_BIN env alias) are intentionally kept — they are the 'read-only compat' rule for users whose config predates the rename. tests/test_mflux_driver.py updated to verify the canonical name is honored AND the legacy alias still works when canonical is unset. 4. Canonical-docs headers on the three specs a new contributor hits first: docs/LOCAL-SETUP.md (CANONICAL), docs/BUILD-PLAN.md (STATUS: partially stale, which phases are done as of which date), and docs/design/INFERENCE-SURFACE.md (CANONICAL SPEC for /v1). A reader cold-landing on docs/ now knows which doc is current vs. history without cross-diffing. 5. Regenerated landing/public/registry-snapshot.json from the current main (64 models, 94 variants, 9 measured) after the earlier session's auto-deploy stopcock wiped it. Tests: 1072 passed, 27 skipped locally, full suite.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes every gap from the pre-v2.10 audit on what 'production standard open source codebase' means for this repo. Five items:
1. CONTRIBUTING.md / CODE_OF_CONDUCT.md / SECURITY.md — the adoptability triad. Code of Conduct is Contributor Covenant v2.1. SECURITY.md routes reports to dev@motionvector.io with a 72-hour ack, names what's in and out of scope (loopback-only middleware is trusted; spot/LTX/Hunyuan routes refuse 501 today so there is no inference path to attack), and documents the repo's own security posture record (every compute-spending endpoint requires
X-SpacePilot-Token, subprocess is argv-lists only,resolve_outputcontainment). CONTRIBUTING.md explains the two project rules (execution over ceremony, strict tests before implementation), the commit shape, the repo's relationship tospacebarandlanding/, and how to readAGENTS.mdas the rulebook.2. Research receipts move from repo root to
experiments/routing-research/— all 8 files. With a README explaining they are provenance behind FLEET-PLAN/CONCEPT claims, not product, and where the live registry actually lives. Repo root was cluttered with 200 KB of non-product JSONs and CSVs.3. Pluto shrapnel —
config.pyCORS whitelist had 4 hard-codedpluto.localhostentries (pre-#101 rename);mflux_driver.pyerror text referenced.pluto_config.jsonwhich does not exist (real name is.spacepilot_config.json). Both fixed. The legitimate read-only compat paths are kept:paths.py legacy_user_data_dir/cache_dir,cli.py LEGACY_CONFIG_FILE, and thePLUTO_MFLUX_BINenv alias all still work for configs that predate the rename.tests/test_mflux_driver.pyupdated: canonical name is honored, AND the legacy alias still works when canonical is unset.4. Canonical-docs headers on the three specs a new contributor hits first:
docs/LOCAL-SETUP.md→ CANONICALdocs/BUILD-PLAN.md→ STATUS: partially stale, with which phases are done and as of which date, and the standing warning about hardcoded countsdocs/design/INFERENCE-SURFACE.md→ CANONICAL SPEC for /v1Repo is now self-guiding for a new reader without cross-diffing.
5. Landing registry-snapshot regenerated from current main (64 models, 94 variants, 9 measured) after an earlier session's auto-deploy stopcock wiped the file.
Tests: 1072 passed, 27 skipped, full suite locally, all five fixes in place.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.