fix(ai): bind model scope to immutable geometry
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Jens
2026-08-09 10:54:52 +02:00
parent f41392a415
commit b76cd1837b
19 changed files with 431 additions and 58 deletions
+4 -2
View File
@@ -1115,8 +1115,10 @@ This file now starts with the current implementation status. Older preparation/b
112 Ruff findings and add real frontend lint.
- [ ] P2-02: fix CRS ingest, metre buffering and Area geometry/CRS updates;
auditably quarantine or repair the four legacy Geel detections.
- [ ] P2-03: isolate coverage by source/theme/layer/zone, make official source
identity server-attested and replace mutable-name legal/model scope checks.
- [ ] P2-03: isolate coverage by source/theme/layer/zone and make official
source identity server-attested. The mutable-name YOLO scope bypass is fixed
with a model/checksum-bound geometry manifest; equivalent legal-scope checks
still require the same review.
- [ ] P2-04: make derived persistence transactional, require complete
RunManifest hashes and expose every fallback/persistence failure.
- [ ] P2-05: remove every protected-test feedback path, introduce a test vault