Source and corrections — 3 October 2026
Adapted from lawrencerowland/more-project-apps, branch codex/create-handover-pack-for-mountain-refuge-project, commit f7f084a00cce265589554dd8bc94058f4d39a3ba.
That repository name and revision are historical identifiers. The maintained implementation, explanation and usable pack are here in Governance Trio; no retrieval from the retired source repository is required.
The branch contributed eight unique files: a workflow, Makefile, manifest, digest list, SARIF example, purported PDF, Rego policy and schema. The useful contribution was a stage handover joining declared responsibility, reviews, an evidence inventory and checks. It belongs beside Governance Trio’s explanation of records and receipts; it supplies no Petri-net, SMC, planning or engineering theorem.
The original two digests matched the committed evidence bytes, but the pipeline never recomputed them. The digests were a flat JSON map while Rego looked under data.digests. set -e did not catch a failed OPA command piped into tee; the human-readable output parser could accept empty output. The file-backed Make target skipped subsequent checks, including after evidence changes or an earlier failure. Temporary orchestration probes reproduced false PASS after a failed policy command, reuse after edited evidence, and a successful make exit after a previous FAIL.
The original Ajv command omitted the schema’s draft-2020 selection; its floating latest OPA download was incompatible with the old Rego syntax. The new dependency-free bounded checker replaces that fragile tool chain, uses structured results, rereads evidence every run and treats execution failures as unknown/nonzero. It has no status cache or pipeline. The flat map convention is explicit and tested.
The .pdf was plain text with unearned verification claims; the SARIF had no checks or results. They are replaced with plainly fictional, unassessed text/JSON evidence. Unsupported snow-load periods, lift weights and anchor counts become open questions requiring real evidence. Signoffs remain declarations, with blank/duplicate assertions rejected; passing does not authenticate people. The placeholder registry subject and broad GitHub certificate regex did not bind provenance to the handover, so this version claims no attestation verification.
The Library source and downloaded pack share handover-model.js; the checked-in archive is generated by build-handover-pack.cjs. Regression tests cover failures, repeat runs, altered bytes, missing files, wrong map structure, unavailable hashing and stale browser results.