{ "schema": "okf-repository-publication-contract.v1", "modified": "2026-08-18", "locale": "en-GB", "time_zone": "Europe/London", "repository": { "name": "okf-ons", "url": "https://github.com/chris-page-gov/okf-ons", "role": "large-corpus-producer", "root_index": "README.md", "lifecycle": "active" }, "semantic_contract": { "path": "source/ontology-crosswalk.json", "profile": "https://chris-page-gov.github.io/okf-ons/okf-bundle.yamlld" }, "source_families": [ { "id": "frozen-statistics-metadata", "label": "Frozen public statistics metadata", "description": "Versioned metadata-only snapshots acquired from the registered ONS, Nomis, Explore Local Statistics and Open Geography lanes.", "kind": "structured-data-folder", "paths": ["source/demo-snapshot/**", "source/metadata-enrichment-*/**", "source/provider-datapacks/**"], "formats": ["application/json"], "origin": "acquired", "authority": "mixed", "snapshot_policy": "immutable-checksummed", "inventory": { "method": "content-addressed-manifest", "manifest_path": "source/demo-snapshot/snapshot.json", "identity": ["relative-path", "bytes", "sha256", "source-identifier", "source-version"] }, "rights": { "status": "mixed", "evidence": ["https://www.ons.gov.uk/methodology/geography/licences"], "limitations": ["Record-level source and rights status remain authoritative; attribution does not imply endorsement."] }, "sensitivity": { "status": "public-no-personal-data", "assessment": "The snapshots contain public discovery metadata only and exclude statistical observations, credentials and private data.", "evidence": ["https://github.com/chris-page-gov/okf-ons/blob/main/README.md"] }, "extraction": { "mode": "versioned-adapter", "network_access": "separate-authorised-step", "command_ids": ["acquire-snapshot"], "limitations": ["Ordinary builds use frozen inputs without network access; live acquisition is separately bounded and resumable."] }, "invalidates": ["source", "semantic", "runtime", "application", "browser", "release", "deployment"], "limitations": ["The live Pages deployment remains the governed demo snapshot until an explicit release switches it."] }, { "id": "ons-publication-controls", "label": "ONS publication and evaluation controls", "description": "Authored source registers, ontology mappings, standards, evaluation contracts, documentation and application sources.", "kind": "mixed", "paths": ["source/*.json", "evaluation/**", "pages/**", "docs/**", "accessibility.md"], "formats": ["application/json", "text/markdown", "text/html", "text/css", "text/javascript"], "origin": "authored", "authority": "editorial", "snapshot_policy": "pinned-revision", "inventory": { "method": "pinned-source-register", "manifest_path": "source/source-register.json", "identity": ["relative-path", "source-identifier", "source-version"] }, "rights": { "status": "approved", "evidence": ["https://github.com/chris-page-gov/okf-ons/blob/main/LICENSE"], "limitations": ["Third-party source rights remain recorded separately from repository code licensing."] }, "sensitivity": { "status": "public-no-personal-data", "assessment": "The public repository controls contain technical, governance and synthetic evaluation material only.", "evidence": [] }, "extraction": { "mode": "deterministic-local", "network_access": "prohibited", "command_ids": ["build-bundle"], "limitations": [] }, "invalidates": ["source", "semantic", "runtime", "documentation", "application", "browser", "release", "deployment"], "limitations": ["Deterministic validation proves structure and frozen-input integrity, not statistical truth or human verification."] } ], "boundaries": { "authored": [ {"path": "source/demo-snapshot/**", "role": "source-envelope", "source_family_id": "frozen-statistics-metadata"}, {"path": "source/metadata-enrichment-*/**", "role": "source-envelope", "source_family_id": "frozen-statistics-metadata"}, {"path": "source/provider-datapacks/**", "role": "source-envelope", "source_family_id": "frozen-statistics-metadata"}, {"path": "source/*.json", "role": "source-register", "source_family_id": "ons-publication-controls"}, {"path": "evaluation/**", "role": "policy", "source_family_id": "ons-publication-controls"}, {"path": "src/**", "role": "generator"}, {"path": "scripts/**", "role": "generator"}, {"path": "pages/**", "role": "content", "source_family_id": "ons-publication-controls"}, {"path": "tests/**", "role": "test"}, {"path": "docs/**", "role": "documentation", "source_family_id": "ons-publication-controls"}, {"path": "README.md", "role": "documentation"}, {"path": "accessibility.md", "role": "documentation", "source_family_id": "ons-publication-controls"}, {"path": "AGENTS.md", "role": "policy"}, {"path": "CHANGELOG.md", "role": "changelog"}, {"path": "okf.publication.json", "role": "publication-contract", "source_family_id": "ons-publication-controls"}, {"path": ".github/workflows/**", "role": "workflow"} ], "generated": [ {"path": "bundle/okf-bundle.yamlld", "role": "semantic-yaml-ld", "plane": "semantic", "required": true, "build_command_ids": ["build-bundle"], "check_command_ids": ["check-bundle"]}, {"path": "bundle/okf-bundle.jsonld", "role": "semantic-json-ld", "plane": "semantic", "required": true, "build_command_ids": ["build-bundle"], "check_command_ids": ["check-bundle"]}, {"path": "bundle/data/**", "role": "semantic-shards", "plane": "runtime", "required": true, "build_command_ids": ["build-bundle"], "check_command_ids": ["check-bundle", "check-okf"]}, {"path": "bundle/okf-explorer.json", "role": "explorer-runtime", "plane": "application", "required": true, "build_command_ids": ["build-bundle"], "check_command_ids": ["check-bundle"]}, {"path": "bundle/checksums.json", "role": "checksum-manifest", "plane": "release", "required": true, "build_command_ids": ["build-bundle"], "check_command_ids": ["check-bundle"]}, {"path": "bundle/**", "role": "site", "plane": "deployment", "required": true, "build_command_ids": ["build-bundle", "assemble-pages"], "check_command_ids": ["check-okf", "check-entrypoints"]} ] }, "planes": [ {"id": "source", "depends_on": [], "paths": ["okf.publication.json", "source/**", "evaluation/**", "src/**", "scripts/**", "tests/**"], "command_ids": ["acquire-snapshot", "check-publication-contract"]}, {"id": "semantic", "depends_on": ["source"], "paths": ["source/ontology-crosswalk.json", "bundle/okf-bundle.yamlld", "bundle/okf-bundle.jsonld"], "command_ids": ["build-bundle", "check-bundle"]}, {"id": "runtime", "depends_on": ["semantic"], "paths": ["bundle/data/**", "bundle/concepts/**", "bundle/index.md"], "command_ids": ["build-bundle", "check-bundle", "check-okf"]}, {"id": "documentation", "depends_on": ["source"], "paths": ["README.md", "AGENTS.md", "CHANGELOG.md", "docs/**", "accessibility.md"], "command_ids": ["check-publication-contract"]}, {"id": "application", "depends_on": ["runtime"], "paths": ["pages/**", "bundle/okf-explorer.json"], "command_ids": ["test-pages", "check-javascript"]}, {"id": "browser", "depends_on": ["application", "documentation"], "paths": ["pages/**"], "command_ids": ["test-pages"]}, {"id": "release", "depends_on": ["runtime", "documentation", "browser"], "paths": ["bundle/checksums.json", "CHANGELOG.md"], "command_ids": ["check-bundle", "check-okf"]}, {"id": "deployment", "depends_on": ["release"], "paths": [".github/workflows/pages.yml", "bundle/**"], "command_ids": ["assemble-pages", "check-entrypoints"]} ], "tooling": { "commands": [ {"id": "acquire-snapshot", "kind": "acquire", "planes": ["source"], "command": "python scripts/acquire_snapshot.py --help", "source": "README.md", "review_status": "reviewed-local-guidance", "network": "acquisition", "mutates": "source-and-generated", "timeout_minutes": 360}, {"id": "check-publication-contract", "kind": "check", "planes": ["source", "documentation"], "command": "python scripts/check_publication_contract.py", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 2}, {"id": "build-bundle", "kind": "build", "planes": ["semantic", "runtime", "application", "release", "deployment"], "command": "python scripts/build_bundle.py --snapshot-dir source/demo-snapshot --output bundle", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "generated-only", "timeout_minutes": 15}, {"id": "check-bundle", "kind": "check", "planes": ["semantic", "runtime", "release"], "command": "python scripts/build_bundle.py --snapshot-dir source/demo-snapshot --output bundle --check", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 15}, {"id": "check-okf", "kind": "check", "planes": ["runtime", "release", "deployment"], "command": "python scripts/check_okf_v02.py bundle", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 5}, {"id": "test-pages", "kind": "test", "planes": ["application", "browser"], "command": "python -m pytest -q tests/test_pages.py", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 5}, {"id": "check-javascript", "kind": "check", "planes": ["application"], "command": "node --check pages/app.js", "source": "AGENTS.md", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 2}, {"id": "assemble-pages", "kind": "build", "planes": ["deployment"], "command": "cp -R pages/. bundle/", "source": ".github/workflows/pages.yml", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "generated-only", "timeout_minutes": 2}, {"id": "check-entrypoints", "kind": "check", "planes": ["deployment"], "command": "test -f bundle/index.html", "source": ".github/workflows/pages.yml", "review_status": "reviewed-local-guidance", "network": "none", "mutates": "none", "timeout_minutes": 2} ] }, "lockstep": { "controlled_paths": ["okf.publication.json", "source/**", "evaluation/**", "src/**", "scripts/**", "pages/**", ".github/workflows/**"], "documentation_paths": ["README.md", "AGENTS.md", "docs/**", "accessibility.md"], "changelog_path": "CHANGELOG.md", "check_command_id": "check-publication-contract", "dependency_update_policy": "assess-release-bound-bytes-no-blanket-exemption", "unknown_path_policy": "fail-closed" }, "ci": { "provider": "github-actions", "workflow_paths": [".github/workflows/pages.yml"], "impact_routing": "full-suite", "parallelism": "serial", "unknown_path_policy": "full-suite", "browser": { "ordinary": {"policy": "not-applicable", "engines": [], "command_ids": [], "exception_justification": "The repository currently has deterministic static-page tests but no governed real-browser command."}, "cross_engine": {"policy": "not-applicable", "engines": [], "command_ids": [], "installation": {"policy": "none", "command_ids": []}} } }, "publication": { "mode": "automatic-protected-main", "scope": "bounded-demonstrator", "authority": { "decision": "Protected main publishes the metadata-only governed demo snapshot through the existing Pages workflow.", "evidence_paths": ["README.md", ".github/workflows/pages.yml"] }, "candidate_policy": "promote-exact-assured-bytes-without-rebuild", "targets": [ {"id": "github-pages", "kind": "github-pages", "workflow_path": ".github/workflows/pages.yml", "public_base_url": "https://chris-page-gov.github.io/okf-ons/", "exact_commit_required": true, "promote_without_rebuild": true} ] }, "verification": { "required": false, "browser": "not-applicable", "exact_commit_required": false, "identity_checks": [], "journeys": [], "console_policy": "not-applicable", "command_ids": [] }, "limitations": [ "The ignored bundle directory is generated once in CI and the same workspace bytes are validated, assembled and uploaded; there is no checked-in generated baseline for a clean pre-build --check.", "A future immutable bundle baseline or release artefact could enable a clean pre-build --check without committing the full generated tree.", "Static page tests do not satisfy the separate real-browser exact-commit publication verification required before presenting a public URL as verified.", "Declared command strings are untrusted metadata and must be reviewed against repository guidance before execution." ] }