{
  "schema_version": 1,
  "generated_at": "2026-07-30T07:43:53Z",
  "repository": "gesh75/argus",
  "release_merge_sha": "b75af239c441204699114ce34970e37b394b3c21",
  "current_main_sha": "6f4d8326e8b99dd56f04df23079657d30798ae84",
  "active_branch": "main",
  "head_sha": "6f4d8326e8b99dd56f04df23079657d30798ae84",
  "head_sha_semantics": "repository HEAD when the snapshot inputs were frozen; the generated snapshot is carried by the following Git commit",
  "source_commit": "6f4d8326e8b99dd56f04df23079657d30798ae84",
  "dirty": false,
  "release_target": "Argus 1.0 supervised defensive assessment release candidate",
  "maturity": "NOW complete; supervised defensive assessment release candidate; alpha runtime",
  "supported_deployment_modes": [
    "supervised, explicitly authorized isolated-lab assessment",
    "Python 3.12+ POSIX macOS/Linux controller",
    "V1 CLI with Docker sandbox by default",
    "localhost-only FastAPI console with server-owned live mode",
    "Phase 2A transactional audit diagnostics and local consistency anchor"
  ],
  "unsupported_deployment_modes": [
    "unattended, scheduled, or 24/7 operation",
    "V2 continuous mode as a supported product",
    "production or regulated deployment",
    "network-exposed or multi-user service",
    "local JSON anchor represented as WORM",
    "Windows-hosted audit writing"
  ],
  "test_results": {
    "baseline_collect": {
      "status": "passed",
      "count": 279,
      "python": "3.12.13",
      "dependency_source": "aegis/requirements.lock --require-hashes"
    },
    "baseline_full": {
      "status": "passed",
      "passed": 279
    },
    "release_boundary_focused": {
      "status": "passed",
      "passed": 51
    },
    "release_closeout_full": {
      "status": "passed",
      "passed": 292
    }
  },
  "lint_results": {
    "status": "passed-approved-baseline-comparison",
    "full_exit_code": 1,
    "baseline_findings": 25,
    "branch_findings": 20,
    "new_findings": 0,
    "changed_findings": 0,
    "removed_findings": 5,
    "baseline_comparison": "passed",
    "changed_python_files": "passed",
    "suppressions_added": false
  },
  "bandit": {
    "status": "passed",
    "severity": "medium",
    "confidence": "medium",
    "medium_or_high_findings": 0
  },
  "dependency_audit": {
    "status": "passed",
    "command": "pip-audit -r requirements.lock --strict --desc",
    "known_vulnerabilities": 0,
    "note": "The uv-created local Python 3.12 audit environment failed inside ensurepip before auditing; pinned pip-audit 2.10 completed successfully in the functional local tool environment. GitHub Python 3.12 remains authoritative."
  },
  "package_build": {
    "status": "passed",
    "artifacts": [
      "sdist",
      "wheel"
    ],
    "source": "clean git archive"
  },
  "wheel_smoke": {
    "status": "passed",
    "python": "3.12.13",
    "dependency_source": "aegis/requirements.lock --require-hashes",
    "commands": [
      "argus --help",
      "argus audit --help"
    ]
  },
  "codeql": {
    "status": "passed",
    "open_alerts": 0,
    "baseline_run": "https://github.com/gesh75/argus/actions/runs/30385808459",
    "release_closeout_run": "https://github.com/gesh75/argus/actions/runs/30523639583",
    "post_merge_run": "https://github.com/gesh75/argus/actions/runs/30523751784"
  },
  "open_pull_requests": [],
  "merged_pull_request": {
    "number": 17,
    "title": "fix: close Argus supervised release boundary",
    "url": "https://github.com/gesh75/argus/pull/17",
    "head_sha": "8f1fed7d88c821f926c332ea691f151c58d73dbd",
    "merge_sha": "b75af239c441204699114ce34970e37b394b3c21"
  },
  "open_issues": [
    {
      "number": 4,
      "title": "Move the HMAC audit signing key out-of-band from the tool runner",
      "url": "https://github.com/gesh75/argus/issues/4",
      "release_blocker": false
    }
  ],
  "blockers": [],
  "next_action": "NONE — NOW increment complete. Start no NEXT item without separate authorization and a fresh branch from current main.",
  "documentation_freshness": {
    "status": "final post-merge source snapshot",
    "generator": "scripts/generate_control_dashboard.py",
    "dashboard": "docs/index.html",
    "source_commit": "6f4d8326e8b99dd56f04df23079657d30798ae84"
  },
  "completed_milestones": [
    {
      "name": "Phase 1 safety freeze",
      "evidence": "PR #12",
      "state": "merged"
    },
    {
      "name": "Phase 2A transactional audit hardening",
      "evidence": "PR #13",
      "state": "merged"
    },
    {
      "name": "CodeQL enablement and alert closure",
      "evidence": "PRs #14 and #15",
      "state": "merged"
    },
    {
      "name": "Copilot repository safety context",
      "evidence": "PR #16",
      "state": "merged"
    },
    {
      "name": "Release-closeout recovery and V2 isolation",
      "evidence": "PR #17; merge b75af239c441204699114ce34970e37b394b3c21",
      "state": "merged; post-merge CI and CodeQL passed"
    }
  ],
  "roadmap": {
    "NOW": [
      "COMPLETE — supervised V1 release closeout merged as b75af239c441204699114ce34970e37b394b3c21"
    ],
    "NEXT": [
      "Complete one bounded operational V2 foundation",
      "Move HMAC signing out of the orchestrator"
    ],
    "LATER": [
      "Add an independently administered external anchor",
      "Add browser-executed DOM security coverage"
    ],
    "DEFERRED": [
      "Unattended continuous service",
      "Production, regulated, network-exposed, or multi-user deployment"
    ]
  },
  "blocker_matrix": [
    {
      "item": "Release verification",
      "state": "closed",
      "impact": "none; all local, PR, review, merge, post-merge CI, and CodeQL gates passed",
      "owner": "completed by sole implementation session"
    },
    {
      "item": "Out-of-band signer",
      "state": "deferred issue #4",
      "impact": "blocks higher-trust deployment, not supervised isolated-lab RC",
      "owner": "future separately authorized increment"
    },
    {
      "item": "Operational V2 lifecycle",
      "state": "deferred by Path A",
      "impact": "continuous mode remains experimental and unsupported",
      "owner": "future separately authorized increment"
    }
  ],
  "architecture": [
    "Operator CLI or localhost-only console",
    "Fail-closed guardrail: scope, tool firewall, arguments, budget, time, audit, output",
    "Docker sandbox by default; approved local exception only",
    "Read-only network, host, AD, and web collectors",
    "Optional AI analysis; never an authorization source",
    "Deterministic V1 chaining and CSV/Markdown/JSON reports",
    "Transactional Phase 2A audit log plus local non-WORM consistency anchor"
  ],
  "v1_execution_flow": [
    "operator supplies explicit targets and profile",
    "target scope is normalized and checked",
    "high-risk mode requires exact approval",
    "guardrail authorizes the tool and arguments",
    "sandbox executes a bounded collector",
    "output is sanitized and normalized",
    "planner may propose the next bounded profile",
    "findings and proof-tagged paths are reported",
    "every decision and execution boundary is audited"
  ],
  "v2_experimental_flow": [
    "specialized agent proposals",
    "incomplete target and collector integration",
    "experimental EvidenceGraph",
    "non-release-grade global correlation",
    "non-transactional graph persistence",
    "gated ContinuousRunner",
    "no supported CLI or unattended loop"
  ],
  "security_evidence": [
    "292-test hash-locked Python 3.12 release-closeout regression passed",
    "51 focused release, V2, web, and audit tests passed",
    "123 audit persistence, filesystem, anchor, CLI, and concurrency tests passed",
    "Ruff comparison found no new or changed findings; every changed Python file passed",
    "Bandit found no medium- or high-severity issue",
    "Dependency audit found no known vulnerability",
    "Clean sdist, wheel build, locked wheel install, and CLI smoke passed",
    "Phase 1 redirect, request-body, peer, live-mode, and DOM boundaries preserved",
    "Phase 2A strict replay, locking, durability, diagnostics, and recovery preserved",
    "PR CI and CodeQL passed on reviewed head 8f1fed7d88c821f926c332ea691f151c58d73dbd",
    "post-merge main CI 30523751828 and CodeQL 30523751784 passed",
    "post-merge open CodeQL alerts: 0",
    "exactly one independent read-only review completed; all three findings were resolved before merge"
  ],
  "control_links": [
    {
      "label": "Project control",
      "href": "control/PROJECT_CONTROL.md"
    },
    {
      "label": "Roadmap",
      "href": "control/ROADMAP.md"
    },
    {
      "label": "Decisions",
      "href": "control/DECISIONS.md"
    },
    {
      "label": "Runbook",
      "href": "control/RUNBOOK.md"
    },
    {
      "label": "Change log",
      "href": "control/CHANGELOG.md"
    },
    {
      "label": "Agent handoff",
      "href": "control/AGENT_HANDOFF.md"
    },
    {
      "label": "Machine status",
      "href": "control/STATUS.json"
    }
  ]
}
