Skip to content

Prepare an auditable community preview - #1

Draft
fzy2012 wants to merge 3 commits into
mainfrom
codex/rebuild-upstream-foundation
Draft

Prepare an auditable community preview#1
fzy2012 wants to merge 3 commits into
mainfrom
codex/rebuild-upstream-foundation

Conversation

@fzy2012

@fzy2012 fzy2012 commented Aug 12, 2026

Copy link
Copy Markdown
Owner

What changed

  • separated the pinned 30x-video upstream snapshot from Ruhang Motion's maintained runtime
  • restored the vendored v1.0.5 tree byte-for-byte and added a snapshot integrity test
  • added an offline, rights-safe demo generator that requires no API key or external asset
  • added asset-rights, project-fingerprint, quality-evidence, network-intake, and approval gates
  • added a unified test runner, dependency audit, generated-project checks, and stronger CI
  • added architecture, contribution, security, roadmap, changelog, Issue, PR, and ownership documentation

Why

The previous tree mixed upstream and project-specific changes, making provenance, maintenance ownership, and public evaluation difficult. This rebuild creates an auditable community-preview foundation while keeping publishing and privileged services outside the open-source core.

Developer and user impact

Contributors can now distinguish third-party provenance from the maintained Ruhang runtime, generate a portable offline demo, run one repository verification command, and submit issues or changes through documented governance paths. Network and asset inputs fail closed when public reachability or usage rights cannot be established.

Validation

  • python3 scripts/check.py — 12/12 test files passed
  • Skill structure validation passed
  • npm audit --audit-level=moderate — 0 vulnerabilities in the maintained runtime
  • generated offline demo passed npm ci, lint, TypeScript checks, and Remotion bundle
  • staged-diff, secret-pattern, unexpected-file, and upstream-integrity checks passed
  • public GitHub Actions passed for both push and pull-request events

Remaining review gates

  • validate a real brand project in Remotion Studio and render an MP4
  • inspect representative frames and final rights evidence
  • review the documented Playwright subresource-isolation limitation before promoting beyond Community Preview

This PR is intentionally a draft and does not publish a Release or submit an OpenAI program application.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant