Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
6ed3c49
Add SOVRINT governed SDK architecture
katrinapietro05-design Jun 26, 2026
0440885
Add SOVRINT SDK security profile
katrinapietro05-design Jun 26, 2026
bd22251
Add governance integrity and evidence interface guide
katrinapietro05-design Jun 26, 2026
9e39d0a
Add SOVRINT security profile schema
katrinapietro05-design Jun 26, 2026
5c17f9c
Add SOVRINT SDK audit event schema
katrinapietro05-design Jun 26, 2026
3564e70
Add strict SOVRINT SDK profile
katrinapietro05-design Jun 26, 2026
91fba4f
Add read-only SOVRINT SDK profile
katrinapietro05-design Jun 26, 2026
0e4551c
Add SOVRINT SDK extension manifest
katrinapietro05-design Jun 26, 2026
4f2347a
Add SOVRINT permission decision matrix
katrinapietro05-design Jun 26, 2026
4e05add
Add SOVRINT audit event example
katrinapietro05-design Jun 26, 2026
2b797e4
Add TypeScript SOVRINT governed-session helpers
katrinapietro05-design Jun 26, 2026
d87ab28
Export TypeScript SOVRINT helpers
katrinapietro05-design Jun 26, 2026
3ba7a5f
Add TypeScript SOVRINT helper tests
katrinapietro05-design Jun 26, 2026
93564bc
Add Python SOVRINT governed-session helpers
katrinapietro05-design Jun 26, 2026
793bad7
Export Python SOVRINT helpers
katrinapietro05-design Jun 26, 2026
0d488aa
Add Python SOVRINT helper tests
katrinapietro05-design Jun 26, 2026
75d39ff
Add Go SOVRINT governed-session helpers
katrinapietro05-design Jun 26, 2026
5c57a3e
Add Go SOVRINT helper tests
katrinapietro05-design Jun 26, 2026
5ba28ad
Add TypeScript governed-session recipe
katrinapietro05-design Jun 26, 2026
52984b2
Add Python governed-session recipe
katrinapietro05-design Jun 26, 2026
4c2f40a
Add Go governed-session recipe
katrinapietro05-design Jun 26, 2026
a456987
Add .NET governed-session recipe
katrinapietro05-design Jun 26, 2026
1481b22
Link TypeScript SOVRINT governed-session recipe
katrinapietro05-design Jun 26, 2026
7233001
Link Python governed-session recipe
katrinapietro05-design Jun 26, 2026
72ce3e1
Add SOVRINT SDK extension index
katrinapietro05-design Jun 26, 2026
5510bde
Add SOVRINT extension attribution
katrinapietro05-design Jun 26, 2026
9d5ec6a
Add SOVRINT extension changelog
katrinapietro05-design Jun 26, 2026
3dcf77b
Add cross-language SOVRINT extension validation
katrinapietro05-design Jun 26, 2026
1d98da7
Add SOVRINT extension API reference
katrinapietro05-design Jun 26, 2026
21978f1
Add SOVRINT deployment checklist
katrinapietro05-design Jun 26, 2026
9996d77
Add SOVRINT research profile template
katrinapietro05-design Jun 26, 2026
93ac26a
Add SOVRINT audit event taxonomy
katrinapietro05-design Jun 26, 2026
d7b1eb4
Expand SOVRINT extension manifest
katrinapietro05-design Jun 26, 2026
2f1e0ea
Add modular Python SOVRINT profile model
katrinapietro05-design Jun 26, 2026
9472e13
Add modular Python SOVRINT audit layer
katrinapietro05-design Jun 26, 2026
fb8bdcc
Add modular Python SOVRINT permission layer
katrinapietro05-design Jun 26, 2026
82e82e6
Add Python SOVRINT surface constraints
katrinapietro05-design Jun 26, 2026
d71b8cb
Add Python SOVRINT session projection
katrinapietro05-design Jun 26, 2026
9a25c92
Add modular Python SOVRINT tool guard
katrinapietro05-design Jun 26, 2026
b7c06e3
Expose Python SOVRINT runtime API
katrinapietro05-design Jun 26, 2026
da692a9
Route Python exports through modular SOVRINT runtime
katrinapietro05-design Jun 26, 2026
420b03a
Route Python SOVRINT helper through modular runtime
katrinapietro05-design Jun 26, 2026
6529670
Make Python SOVRINT facade lint-safe
katrinapietro05-design Jun 26, 2026
3f5cde1
Mark Python SOVRINT compatibility exports
katrinapietro05-design Jun 26, 2026
9f74d44
Mark modular Python SOVRINT exports explicitly
katrinapietro05-design Jun 26, 2026
a1d3114
Add formatted Python SOVRINT projection core
katrinapietro05-design Jun 26, 2026
d89a0c9
Route projection through formatted core
katrinapietro05-design Jun 26, 2026
1e5cac3
Add modular Go SOVRINT profile layer
katrinapietro05-design Jun 26, 2026
dbb93f5
Add Go SOVRINT audit event model
katrinapietro05-design Jun 26, 2026
dd99970
Add Go SOVRINT audit runtime
katrinapietro05-design Jun 26, 2026
983dbc1
Add Go SOVRINT permission contracts
katrinapietro05-design Jun 26, 2026
dfbcc80
Add Go SOVRINT permission evaluation
katrinapietro05-design Jun 26, 2026
83ccfa4
Add Go SOVRINT permission result mapping
katrinapietro05-design Jun 26, 2026
8e31f22
Add Go SOVRINT permission coordinator
katrinapietro05-design Jun 26, 2026
d02495c
Add Go SOVRINT session projection
katrinapietro05-design Jun 26, 2026
3fc4a97
Add Go SOVRINT slice utilities
katrinapietro05-design Jun 27, 2026
88fa133
Add Go SOVRINT session surface constraints
katrinapietro05-design Jun 27, 2026
960b8c4
Add Go SOVRINT tool contracts
katrinapietro05-design Jun 27, 2026
ae023e9
Add Go SOVRINT tool outcome helper
katrinapietro05-design Jun 27, 2026
96f673b
Add Go SOVRINT tool event recorder
katrinapietro05-design Jun 27, 2026
b2a7900
Add Go SOVRINT tool wrapper
katrinapietro05-design Jun 27, 2026
2073f30
Add Go SOVRINT tool execution
katrinapietro05-design Jun 27, 2026
ee616b8
Add Go SOVRINT tool completion stage
katrinapietro05-design Jun 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
165 changes: 165 additions & 0 deletions .github/workflows/sovrint-extension-validate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,165 @@
name: SOVRINT Extension Validation

on:
pull_request:
paths:
- "docs/sovrint/**"
- "sovrint/**"
- "nodejs/src/sovrint.ts"
- "nodejs/test/sovrint.test.ts"
- "nodejs/src/index.ts"
- "python/copilot/sovrint.py"
- "python/test_sovrint.py"
- "python/copilot/__init__.py"
- "go/sovrint.go"
- "go/sovrint_test.go"
- "cookbook/**/sovrint-governed-session.md"
- "SOVRINT_*.md"
- ".github/workflows/sovrint-extension-validate.yml"
push:
branches:
- main
- feat/sovrint-governed-sdk-profile-v1

permissions:
contents: read

jobs:
common-contracts:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Install validators
run: python -m pip install --disable-pip-version-check PyYAML==6.0.2 jsonschema==4.23.0

- name: Validate JSON and YAML contracts
run: |
python - <<'PY'
import json
from pathlib import Path

import yaml
from jsonschema import Draft202012Validator, FormatChecker

for path in Path("sovrint").rglob("*.json"):
json.loads(path.read_text(encoding="utf-8"))
print(f"valid json: {path}")

for path in Path("sovrint").rglob("*.yaml"):
yaml.safe_load(path.read_text(encoding="utf-8"))
print(f"valid yaml: {path}")

profile_schema = json.loads(
Path("sovrint/schemas/security-profile.schema.json").read_text(encoding="utf-8")
)
profile_validator = Draft202012Validator(
profile_schema,
format_checker=FormatChecker(),
)
for path in Path("sovrint/profiles").glob("*.json"):
profile = json.loads(path.read_text(encoding="utf-8"))
profile_validator.validate(profile)
if profile["audit"]["includeArguments"] is not False:
raise SystemExit(f"profile exposes arguments: {path}")
if profile["audit"]["includeResults"] is not False:
raise SystemExit(f"profile exposes results: {path}")
print(f"valid profile: {path}")

event_schema = json.loads(
Path("sovrint/schemas/audit-event.schema.json").read_text(encoding="utf-8")
)
event = json.loads(
Path("sovrint/examples/audit-event.example.json").read_text(encoding="utf-8")
)
Draft202012Validator(
event_schema,
format_checker=FormatChecker(),
).validate(event)
if event.get("metadata", {}).get("simulationOnly") is not True:
raise SystemExit("audit example must remain simulation-only")
print("valid audit event example")
PY

- name: Validate extension manifest paths
run: |
python - <<'PY'
from pathlib import Path

import yaml

manifest = yaml.safe_load(Path("sovrint/manifest.yaml").read_text(encoding="utf-8"))
listed = []
for value in manifest["components"].values():
listed.extend(value)
missing = [path for path in listed if not Path(path).exists()]
if missing:
raise SystemExit(f"manifest paths missing: {missing}")
print(f"validated {len(listed)} manifest paths")
PY

nodejs:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4

- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: nodejs/package-lock.json

- name: Install Node.js dependencies
working-directory: nodejs
run: npm ci

- name: Typecheck Node.js SDK
working-directory: nodejs
run: npm run typecheck

- name: Test SOVRINT TypeScript helpers
working-directory: nodejs
run: npx vitest run test/sovrint.test.ts

python:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Install Python SDK and test dependencies
run: python -m pip install --disable-pip-version-check -e "./python[dev]"

- name: Compile Python helper
run: python -m compileall -q python/copilot/sovrint.py

- name: Test SOVRINT Python helpers
run: pytest -q python/test_sovrint.py

go:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4

- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: go/go.mod

- name: Test SOVRINT Go helpers
working-directory: go
run: go test -run Sovrint ./...
25 changes: 25 additions & 0 deletions SOVRINT_CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# SOVRINT™ Extension Changelog

## v1.0 — 2026-06-26

Added:

- governed-session architecture and security documentation;
- governance, integrity, and evidence interface guide;
- strict and read-only JSON profiles;
- research profile constants in TypeScript, Python, and Go;
- shared profile and audit-event schemas;
- extension manifest and permission matrix;
- bounded audit-event example;
- TypeScript helper module and tests;
- Python helper module and tests;
- Go helper module and tests;
- TypeScript, Python, Go, and .NET recipes;
- root extension index and attribution;
- cross-language validation workflow.

Compatibility:

- upstream JSON-RPC protocol unchanged;
- existing SDK users unaffected unless they apply the SOVRINT helpers;
- existing package names and client/session APIs preserved.
24 changes: 24 additions & 0 deletions SOVRINT_EXTENSION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# SOVRINT™ Governed SDK Extension

**Author:** Katrina Pietroniro
**Version:** 1.0
**Status:** Additive and opt-in

This repository includes a governed-session extension around the existing Copilot SDK interfaces. The upstream JSON-RPC protocol remains unchanged.

The extension includes permission profiles, session-configuration helpers, custom-tool guards, bounded audit events, shared schemas, tests, and cross-language recipes.

## Documentation

- [Architecture](docs/sovrint/README.md)
- [Security profile](docs/sovrint/SECURITY_PROFILE.md)
- [Governance, integrity, and evidence interfaces](docs/sovrint/GOVERNANCE_INTEGRITY_EVIDENCE.md)

## Recipes

- [TypeScript](cookbook/nodejs/sovrint-governed-session.md)
- [Python](cookbook/python/sovrint-governed-session.md)
- [Go](cookbook/go/sovrint-governed-session.md)
- [.NET](cookbook/dotnet/sovrint-governed-session.md)

Existing SDK behavior remains unchanged unless an application applies the extension helpers.
8 changes: 8 additions & 0 deletions SOVRINT_EXTENSION_ATTRIBUTION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# SOVRINT™ Extension Attribution

**Author:** Katrina Pietroniro
**Initial integration date:** 2026-06-26

This attribution applies to the governed-session profiles, permission composition, session constraints, custom-tool guards, bounded audit events, interface documentation, schemas, tests, and recipes added under the SOVRINT extension.

The original Copilot SDK code remains attributed to its existing authors. Repository licensing remains unchanged.
107 changes: 107 additions & 0 deletions cookbook/dotnet/sovrint-governed-session.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
# SOVRINT Governed Session — .NET

The TypeScript, Python, and Go packages in this repository include first-class SOVRINT helper modules. This .NET recipe applies the same control principles through the documented native `SessionConfig` surface.

## Conservative profile

```csharp
using GitHub.Copilot.SDK;

const string SovrintSystemAppend = @"
Operate under a bounded SOVRINT governed-session profile.
Use only explicitly exposed tools and declared authority.
Treat observations, inferences, recommendations, governance decisions,
integrity findings, and accepted evidence as distinct classes.
Do not claim approval, verification, restoration, or EvidenceGrid acceptance
without an explicit external result.
";

static SessionConfig ApplySovrintStrictProfile(SessionConfig config)
{
if (config.SystemMessage?.Mode == SystemMessageMode.Replace)
{
throw new InvalidOperationException(
"The SOVRINT strict profile forbids system-message replacement."
);
}

var existing = config.SystemMessage?.Content;
config.SystemMessage = new SystemMessageConfig
{
Mode = SystemMessageMode.Append,
Content = string.Join(
Environment.NewLine + Environment.NewLine,
new[] { existing, SovrintSystemAppend }.Where(value => !string.IsNullOrWhiteSpace(value))
)
};

// An explicit empty allowlist exposes no inherited first-party tools.
config.AvailableTools = [];

// Caller-defined tools must be explicitly supplied after review.
config.Tools = [];

return config;
}

await using var client = new CopilotClient();
await client.StartAsync();

var config = ApplySovrintStrictProfile(new SessionConfig
{
Model = "gpt-5",
Streaming = true,
});

await using var session = await client.CreateSessionAsync(config);
await session.SendAsync(new MessageOptions
{
Prompt = "Summarize the supplied text without using tools."
});
```

## Read-oriented profile

A read-oriented deployment should provide an explicit `AvailableTools` allowlist containing only reviewed read operations. Do not infer tool safety from names alone; validate the actual SDK and CLI tool identifiers available in the deployed version.

```csharp
var config = new SessionConfig
{
Model = "gpt-5",
Streaming = true,
AvailableTools =
[
// Add only reviewed read-tool identifiers for the deployed CLI version.
],
SystemMessage = new SystemMessageConfig
{
Mode = SystemMessageMode.Append,
Content = SovrintSystemAppend + Environment.NewLine +
"Operate in read-only mode."
}
};
```

## Custom tools

Custom tools are application code. Wrap their handlers with application authorization and bounded audit recording before placing them in `SessionConfig.Tools`.

The wrapper should record only:

- session reference;
- tool name;
- invocation reference;
- decision;
- reason code;
- timestamp;
- evidence status.

It should not place arguments, results, credentials, prompts, or raw file contents into the audit event.

## Boundaries

- system-message append content is guidance, not a complete enforcement boundary;
- an empty tool allowlist is safer than inheriting an unknown tool surface;
- local application approval is not a global governance decision;
- an audit event is not EvidenceGrid acceptance;
- unknown or unsupported permission surfaces should fail closed.
Loading
Loading