Merge current main into development guidance

Reconcile the read-only guidance output with the machine-readable skill index,
adopt linked sample references required by bounded retrieval, and update the
guidance regression fixture for the retrieval helper dependency. Permit only
the known endpoint-DLP metadata stream during read-only evidence capture.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 638b66d2-9f06-4f60-8781-808709e1485c
This commit is contained in:
Jesper Schulz-Wedde 2026-09-18 12:04:06 +02:00
commit 8f025ac679
127 changed files with 5251 additions and 136 deletions

View file

@ -22,8 +22,10 @@
stable metadata, Git HEAD/refs/index and ignored/untracked files are compared.
Links/reparse points, hard links, external Git storage in targets,
submodules and sparse checkouts are rejected rather than followed. Windows
alternate data streams are included in the evidence by name, length, and
hash; direct stream paths remain rejected. Run in quiescent repositories.
alternate data streams are rejected except for the known endpoint-DLP
metadata stream `sec.endpointdlp`, which is ignored because endpoint
protection may add or refresh it asynchronously without changing file
content. Direct stream paths remain rejected. Run in quiescent repositories.
The knowledge checkout may itself be a linked Git worktree; its Git storage
identity is recorded explicitly.
#>