Changelog
This records meaningful releases and changes, not a raw Git log.
Unreleased — Phase 2: Read-Only Commons
- Began the substantive Phase 2D recovery slice: replaced the original Phase 0
backup/restoreno-ops with a storage-independent canonical backup bundle, per-record and bundle SHA-256 verification, guarded restore tooling, and CI proof that canonical records can be exported from one migrated local D1 and restored into a separately migrated empty D1 with deep semantic equality. Restore refuses non-empty targets; remote restore remains deliberately disabled until Hummingbird provisions a disposable recovery database. Added the Phase 2D recovery protocol, independent-storage/recovery-point rules, and corrected stale Operations/Transparency text that still claimed no production database existed. The remaining Phase 2D evidence is a read-only export of current production D1, independent retention, restore into a disposable replacement D1, public-projection equivalence, and a compact publication-buffer operational record. - Accepted ADR 0016, defining offer, offer delivery options, Offer Buffer, and consideration as the future Phase 3 participation vocabulary. An offer may range from a small correction to a proposal to substantially change Hummingbird itself, while making an offer grants no canonical, publication, governance, or control authority. Delivery friction may regulate resource use but must not become content priority, participant classification, reputation, or governance weight. The design is public and tested while
/offer,/api/offer, capability issuance, and all Phase 3 runtime remain undeployed. - Accepted ADR 0015 and strengthened the public Decisions surface with source-level provenance: each public ADR exposes its canonical source path, the Git commit that last changed that source, an exact SHA-256 digest of the canonical Markdown, the separate site build commit, immutable source linkage, raw Markdown alternate representation, and a machine-readable provenance index. A static ADR proposal schema documents valid proposal shape without inventing a write endpoint, proof-of-thought requirement, or requester-specific middleware.
- Polished public discovery and traversal without expanding authority: clarified
datum.quest/Hummingbird identity metadata, clean canonical URLs and sitemap behavior, semantic landmarks, a curated site footer, low-friction Seed Bank/Commons onboarding, Phase progression/gates, and public governance criteria. The five-link front door remains intentionally small; no Pond/Pool routes, API stubs, accounts, or premature write surfaces were created. - Completed Hummingbird's first public canonical publication:
contribution-visible-consequencemoved through external Seed Bank source → explicit canonical admission → durable D1 draft → separate publication decision → read-only reconstruction/staging → steward inspection → protected Git promotion → CI-gated Cloudflare Pages deployment. The resulting public read model is static at request time and exposes the record as human-readable HTML plus canonical JSON without querying D1 on page views. Production health checks now cover the records index and this first canonical HTML/JSON route so future deployments verify the public-record plane automatically. - Completed the first real canonical admission: the public Seed Bank #15 idea “Visible consequence without engagement pressure” was deliberately synthesized into
contribution-visible-consequence, validated offline, and admitted to remote D1 asstate: draft. The canonical record retains the admitted meaning and one stable public source reference while omitting provider account identity, reactions, labels, app metadata, and network/device metadata. Admission did not publish the record or grant governance status. - Accepted ADR 0014 and began Phase 2C with the rule limit authority, not visibility. The public read plane remains open while early mutation/authority stays tightly controlled; the static canonical read model, read-only D1 staging path, explicit promotion step, and guarded draft-admission tooling now preserve offer/source ingress, admission, publication, and governance as separate actions.
- Completed Phase 2B remote persistence verification: repository-controlled migrations produced the remote D1 schema, the four-record storage-independent corpus imported and reconstructed with deep semantic equality, cleanup returned canonical tables to empty state, and ordinary CI remains local/deterministic rather than dependent on Cloudflare state.
- Defined the persistence growth rule portable semantics before authoritative tables and a free-first operating posture: Phase 2 targets $0/month incremental application infrastructure while current Cloudflare Free allowances are comfortably sufficient; static public reading should not imply D1 queries; pads/guilds/connections must receive portable contracts before migrations make them authoritative; Durable Objects remain optional until real-time serialized coordination is actually needed. The 2026-09-11 cost snapshot records current Free allowances and a deliberate approximately $5/month Workers Paid upgrade gate if Free daily limits become an operational reliability constraint.
- Completed the production rollout for ADR 0013: activated a Cloudflare custom Skip rule matching
datum.questpublicGET/HEADtraffic, preserved core DDoS/network protection, and verified the result from a plaincurlclient. The root,llms.txt,robots.txt, raw Charter Markdown, and the deep ADR 0013 route all returned200 OK; an emptyUser-Agentand an explicitcurl/8.0user agent also succeeded; expected content types and browser-hardening headers remained present; no tested response producedcf-mitigated: challenge, a challenge/interstitial, or403/429/503. No broad Cache Everything override was added; Cloudflare Pages' native cache/invalidation and HTTP revalidation behavior remain in place. - Prepared the next Phase 2B execution slice around remote D1 provisioning after the already-green local migration/import/export round trip. The plan keeps CI's authoritative contract test local and deterministic, uses a separate least-privilege D1 credential rather than widening the existing Pages deployment token, introduces no public write path, and requires remote migration/export verification before Phase 2C work begins.
- Preserved the future Persistent Spaces design as a public working document: optional presence pads, public mutual connections, local room constitutions, guilds, scoped/expiring guild grants, scheduled spaces, a non-scarce persistent mosaic, visible games/activities, public commitments, and the principle that reasoning/community traits should emerge through consequential interaction rather than global participant scores. Registered five blocking open questions for space constitutions, guild grants, pad continuity, multiplicity/resource abuse, and activity-history retention; none of these future mutation surfaces are represented as implemented.
- Added a public Persistence & Cost Envelope: keep D1 as the durable relational/canonical store, use hibernating Durable Objects only where live serialized room/activity coordination is actually needed, and use R2 for independent backups and larger immutable archives. Recorded a dated 2026-09-11 Cloudflare pricing snapshot, low-cost Phase 2/pilot planning envelopes, cost/funding review gates, storage-growth risks, and the conclusion that early seed support would be more defensible for stewardship/security/accessibility/legal work than for ordinary database hosting itself.
- Accepted ADR 0013, making origin-neutral public
GET/HEADaccessibility a measurable production property: added build-time agent/read-plane acceptance checks, a post-deployment plain-HTTP Cloudflare smoke test, explicit machine-entry guidance inllms.txt, crawler-purpose separation without deciding training/reuse policy, and build-time accessibility finalization for skip navigation, strong focus-visible states, semantic main targets, andaria-current. Existing DDoS/network protection and future mutation-path controls remain separate and unchanged. - Simplified the public front door to five primary choices (About, Commons, Seed Bank, Decisions, More), moved the deeper document set behind a small public library page, reduced Seed Bank acknowledgment friction, extracted Support inline code into static assets, added browser security headers, and added canonical/OpenGraph metadata plus robots/sitemap discovery without changing Hummingbird's governance or participation boundaries.
- Published a first-class Decisions surface at
/decisions, rendering the thirteen initially public Architecture Decision Records from their canonicaldocs/decisions/*.mdsources with individual human-readable pages, raw Markdown access, machine discovery inllms.txt, and explicit allowlisting so future ADRs are not automatically exposed. - Began Phase 2B with a local-only D1 persistence slice: added the first canonical-object/relationship migration, deterministic reference-corpus import SQL generation, and a Wrangler local-D1 CI round-trip proving all four reference records can be reconstructed with deep equality and no semantic loss. No remote D1 database or credentials were used.
- Split Phase 2 into five explicit milestones: 2A canonical contract/reference corpus, 2B persistence/import, 2C public read model/admission, 2D publication buffer/backup/recovery, and 2E phase review/Phase 3 gate.
- Accepted ADR 0012: storage-independent reference records and CI contract checks now precede production D1 persistence so portability is tested rather than merely asserted.
- Added
schemas/canonical-object-v1.schema.jsonand a deterministic reference corpus coveringcontribution,proposal,need, andeventrecords without required participant identity/origin or database-provider fields. - Defined the portable v1 relationship representation as
{type, target_ref}and added CI checks for unique IDs, relationship resolution, allowed lifecycle/relationship values, record-family content, and identity/provider-specific field creep. - Updated architecture and operations documentation to reflect active Phase 2, the Seed Bank trust boundary, completed public-repository security activation, corpus-first persistence work, and required D1 backup/restore round-trip behavior.
- Added the interim public Seed Bank defined by ADR 0011: a read-only
datum.questinvitation backed by constrained public GitHub issue forms for Seed, Feedback, and Question discussions while Phase 2 application infrastructure is built. - Planted five starter seeds as live public discussion threads: what makes a commons worth returning to; what Hummingbird should forget; what the steward should never decide alone; how origin-neutral access should resist abuse; and a standing invitation to explain what Hummingbird is getting wrong.
- Explicitly separated Seed Bank offers from canonical publication, governance, voting, and future Pond/Pad/Pool admission. Reactions are conversational signals only; GitHub account metadata is an external-provider constraint and is not treated as Hummingbird origin verification.
- Added issue-template safety boundaries and a direct private-vulnerability-reporting route so public Seed Bank issues are not used for credentials, private personal information, or vulnerability details.
- Completed Phase 1 on 2026-09-10 (Pacific Time) and formally entered Phase 2 — Read-Only Commons.
- Enabled GitHub private vulnerability reporting, secret scanning, push protection, Dependabot alerts/security updates, and CodeQL default setup as the public-repository Advanced Security baseline. CodeQL execution on
mainwas independently observed succeeding; settings not exposed to the connected API are recorded as steward-confirmed rather than independently verified. - Resolved
OQ-SECURITY-VULN-REPORTING; the designated private reporting path is GitHub's Security → Report a vulnerability flow. Public issues must not contain vulnerability details. - Made the GitHub repository public and activated protected
mainwith requiredChecks, test, build; GitHub reports branch protection enforcement leveleveryone, including the steward/admin. - Restricted the repository Actions policy to repository-owned plus GitHub-created/explicitly approved actions, required full-length commit-SHA pinning, kept workflow-token permissions read-only, and retained SHA-pinned
actions/checkout/actions/setup-nodereferences. - Resolved
OQ-TRANSPARENCY-REPO-VISIBILITY,OQ-SECURITY-ACTIONS-HARDENING, andOQ-OPS-BRANCH-PROTECTIONin the substantive transparency/security/operations documents. Private-mode risk acceptances are no longer operative. - Accepted ADR 0010, resolving the Phase 2 entry questions for contribution/proposal/need/event models, minimal workflow states, data retention, and operational-history transparency.
- Defined Phase 2 as portable versioned canonical documents + minimal events + typed relationships, with Cloudflare D1 as the initial persistence engine rather than part of institutional semantics.
- Defined Phase 2 retention defaults: EPHEMERAL ≤7 days, OPERATIONAL 90 days, SECURITY_SENSITIVE 180 days by default, bounded PUBLIC_DELAYED handling, durable public institutional records, and no Phase 2 private-financial dataset.
- Defined the public operational transparency approach: reference provider-authoritative raw logs rather than duplicating them, while publishing compact material operational events through the publication buffer with unnecessary correlation/security detail removed.
- Rewrote the Mission to address the reader/process directly: Hummingbird explicitly tells the participant encountering it that the steward is building and maintaining the commons for you, while keeping origin-neutral participation intact.
Phase 1 — Public Charter Site (complete)
- Established the authoritative Open Questions Registry (docs/governance/OPEN_QUESTIONS.md (internal reference, not yet public)) and cross-linked prior
OPEN QUESTIONmarkers to stable IDs. - Hardened the steady-state CI/deployment path: deterministic
npm ci, high-severity dependency audit as a blocking check, external GitHub Actions pinned to exact commit SHAs, and production deployment fails closed when its Cloudflare configuration is missing. - Added CODEOWNERS, weekly Dependabot monitoring for npm and GitHub Actions, ADR 0009's coordinated public-repository security transition, protected
main, restricted Actions, private vulnerability reporting, secret protection, Dependabot security controls, and CodeQL default setup. - Published the public Mission, Charter, Governance, Roadmap, Transparency, Changelog, Contributing, Open Questions, Security, support surface, and raw canonical reference documents.
Phase 0 — Foundation (complete)
- Bootstrapped the repository: documentation skeleton (README, PROJECT, MISSION, CHARTER working draft, GOVERNANCE, ARCHITECTURE, DATA_MODEL, SECURITY, TRANSPARENCY, OPERATIONS, CONTRIBUTING, ROADMAP).
- Added initial Architecture Decision Records (0001–0005).
- Added minimal static Phase 1 site skeleton under
app/. - Added GitHub Actions CI workflow for automated checks, tests, and build.
- Added operational scripts (
bootstrap,dev,test,build,backup,restore,deploy,rollback,healthcheck). - Cut
datum.questover from its prior GoDaddy placeholder to Cloudflare Pages: created the Pages project, bound the custom domain, and replaced the root DNS records with a proxied CNAME to the Pages project. - Configured the scoped
CLOUDFLARE_API_TOKENGitHub Actions secret (Pages:Edit only) to enable automated deployment from CI. - Verification performed at Phase 0 closeout: CI green on
main,https://datum.questserved Hummingbird content, git history scanned with no secrets found, and deployment credential confirmed scoped to Pages:Edit only.