Evidence ceiling E3Proof boundary

RELEASE GOVERNANCE

Published proof records remain separately identifiable.

The public protocol repository has an active default-branch ruleset and a published pub.2 release. Public Site 80 reports the ruleset exactly: pull-request workflow, review-thread resolution, deletion protection and non-fast-forward protection. The current ruleset does not contain a required-status-check rule, so Finality does not claim that it does.

Repository control

Current GitHub ruleset facts.

The active Protect main ruleset applies to the default branch. These are governance controls, not independent protocol assurance.

Pull request rule
ACTIVE
Review-thread resolution
REQUIRED
Non-fast-forward
BLOCKED
Deletion
BLOCKED
Current-user bypass
NEVER
Required status-check rule
NOT PRESENT

Workflow evidence

Workflows exist; ruleset enforcement is reported separately.

CI, CodeQL, Scorecard, fuzzing and release-provenance workflows may produce integrity evidence. Their existence or historical success does not make them required by the current branch ruleset and never creates E4/E5 independence.

01

CI / release workflows

PUBLIC REPOSITORY

02

CodeQL workflow

PRESENT

03

Scorecard workflow

PRESENT

04

ClusterFuzzLite workflows

PRESENT

05

Branch required-check rule

NOT PRESENT

Publication rule

Frozen protocol-publication identity is separate from Public Site 80.

The public repository exposes external-proof-v2.0.0-draft.1-pub.2 and release assets including a Sigstore bundle. Public Site 80 preserves rather than rewrites that frozen protocol-publication identity.

01

Current semantic release

FRP-2.0.0-draft.1

02

Current kernel

FSK-1.0.0

03

Frozen publication

external-proof-v2.0.0-draft.1-pub.2

04

Sigstore bundle

PUBLIC RELEASE ASSET

05

External evidence

ZERO

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.