todo2code

Ticket 021: Govern reproducible project analysis generation

Goal and scope

Repair the governance contract that currently leaves root-level generated analysis artifacts under project/ without an implementation workstream owner. This ticket authorizes only the minimum policy change needed before a separate integration ticket can restore generation safely.

The current managed project.sh remains a deterministic governance entry point. This ticket must not restore host-side pip install --upgrade, execute prefact, or embed repository-specific code2llm commands in the centrally managed wrapper. Analysis remains advisory and must run through an explicitly selected, content-addressed environment.

Architecture before implementation

Acceptance criteria

Participants

Approval boundary

The human approved this exact XS plan by replying kontynuuj after the approval request. Current state: IN_PROGRESS / VALIDATION. The approved plan exists in commit 477f64d before either implementation file changes; focused checks now pass. Merge evidence remains independently governed.

After main advanced through tickets 019/035, the human explicitly continued against exact replacement base 9658ebbaac2ebd213d12f42614e054949fa086ab. The implemented reconciliation preserves both Python-publication ownership and the generated-analysis patterns.

After main subsequently advanced through the protected ticket-039 closure, the human replied kontynuuj again and approved exact replacement base 9cfc3a8f90a9669ef5b37c44928e0b0e6a191ae5. The implementation diff and accepted architecture remain unchanged; only the approval binding is refreshed.

The unchanged bounded implementation was then independently reviewed and merged through the protected path. Chat approval authorized the interactive edit only; merge authority came from exact-head Validator App evidence and required checks.

Protected completion evidence