Skip to main content

Catalog authoring and admission

Catalog source completeness, PR provenance, installed-package behavior and current vendor availability are separate results. The default pnpm run verify:provider-onboarding remains an offline source check; it does not certify the PR URL or refresh a dated roster/live record.

Catalog model defaults for context and output must be positive safe integers supported by source evidence. Unknown ceilings remain unresolved. This authoring constraint does not alter caller maxTokens: 0 semantics or optional per-model overrides. A scaffold intentionally contains invalid zero ceilings and TODO evidence until the author supplies real values.

Inspect an unfinished scaffold:

pnpm exec tsx tools/verify-provider-onboarding.ts --catalog-stage draft --catalog-file provider.json

This reports incomplete_draft and its validation problems. Successful draft inspection is not admission; every admission result has zero provider-count, package, publication, roster and live credit.

After filling the source fields, use the exact PENDING_PR marker while no PR exists. A guessed URL or arbitrary string is not provenance:

pnpm exec tsx tools/verify-provider-onboarding.ts --catalog-stage source --provider vendor-id

Without a provider/file selector, draft/source stages inspect the whole catalog. They stay offline. A canonical PR URL is only syntax at this stage; the output explicitly leaves provenance unverified. Existing dated evidence is retained without relabeling or requiring a breaking record migration. Paired (--catalog-stage source) and equals (--catalog-stage=source) options can be mixed; the same forms apply to provider, file and source-head selectors.

When a real introduction PR exists, put its actual URL in addedInPR, regenerate and commit the source, then inspect the immutable PR head:

pnpm exec tsx tools/verify-provider-onboarding.ts --catalog-stage review --provider vendor-id --source-head FULL_LOCAL_HEAD_SHA

The explicitly selected provenance stage uses authenticated, read-only gh api queries. It requires the actual repository/PR identity, an added-file association for this provider, the exact local source/PR head and equal provider-file blob. Uncommitted source, a stale/unrelated head, guessed/nonexistent PR or unrelated existing PR fails. GitHub API access failures fail closed. Association proof does not certify reviewer approval or current candidate CI.

After merge:

pnpm exec tsx tools/verify-provider-onboarding.ts --catalog-stage merged --provider vendor-id --source-head FULL_LOCAL_HEAD_SHA

This reports historical_catalog_file_introduction_verified: actual added-file association, merged state, merge ancestry in the selected local head and all five required checks completed SUCCESS at the introduction PR head. It does not certify current product identity or content continuity after later edits, deletion or replacement. Historical file introduction remains provable even if a later product reuses that path; the current source bytes are not silently equated with the old introduced blob. Current integration/product acceptance needs its separate evidence. The newest run of each required check must pass; missing, skipped, neutral or pending runs fail.

roster, live, package and release are deliberately not admission-command stages. Docs-only records cannot become authenticated roster or live receipts. Those claims require their separately authorized current account/model/route execution or installed-consumer evidence. This command makes no vendor calls and never changes an account, PR, branch, catalog record or remote thread.