Skip to content

Harden the ML ebook for safer public release - #6

Draft
rkalani1 wants to merge 1 commit into
mainfrom
codex/public-release-hardening-2026-07-30
Draft

Harden the ML ebook for safer public release#6
rkalani1 wants to merge 1 commit into
mainfrom
codex/public-release-hardening-2026-07-30

Conversation

@rkalani1

@rkalani1 rkalani1 commented Jul 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • Clarify the license boundary: ISC for repository code, CC BY 4.0 only for publisher-controlled book content and cleared assets.
  • Add third-party notices, contribution/security policies, citation metadata, asset rights records, an SBOM, and a dated publication review.
  • Correct and review all 20 chapters, replace weak-provenance figures with semantic HTML/CSS, and tighten accessibility and responsive behavior.
  • Add hash-locked dependencies and fail-closed release gates for source, provenance, secrets, rendered output, active content, external egress, MathJax integrity, and exact deployment revision.

Validation

  • 27/27 adversarial release-gate mutation tests passed.
  • 24/24 ebook structural tests passed.
  • 96 bounded numerical/source checks passed.
  • Exact committed build passed: 24 HTML pages, 9.67 MiB, release SHA e6b00b0.
  • Gitleaks 8.30.1 scanned 576 reachable commits and about 489.21 MB of Git text with no detected leak.
  • Runtime, audit, and bootstrap lock audits found no known vulnerabilities; CFF and CycloneDX SBOM validation passed.

Release hold

Draft only. Do not merge or deploy until the owner confirms:

  1. the right to license the text, code, current images, and applicable AI-assisted output;
  2. UW, sponsor, employment, commissioned-work, and affiliation obligations;
  3. that no patient/source data or third-party confidential material was used; and
  4. whether to retain the existing public Git history or replace it with a clean-history publication repository.

This PR does not rewrite history. Historical assets were screened with bounded automated methods, not full raster OCR, source-data reconstruction, visual-similarity clearance, trademark clearance, or a legal chain-of-title opinion.

@rkalani1
rkalani1 force-pushed the codex/public-release-hardening-2026-07-30 branch from 5cebf59 to e6b00b0 Compare July 30, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant