Reference text

The protocol

A producer can only be trusted about small problems if it has a safe, disciplined way to announce that a problem is larger than first stated. Four rules make that possible.

Rule one

Widening costs nothing; external discovery costs everything

When a producer discovers that its own defect is wider than filed, recording that fact must be the cheapest available action. On this ledger a widening is displayed as a credit, not a black mark. The penalty attaches to the alternative: a defect widened by someone outside the organisation.

Rule two

Every defect carries a dated end

A defect is filed with the date by which it will be resolved. There is no way to save one without it. A problem with no end date is a condition, not a defect, and disclosing conditions is not disclosure.

Rule three

Every reclassification carries a count-neutrality proof

Moving a defect from a narrower scope to a wider one changes what is counted. The protocol requires the before count, what was added, what was removed, the resulting after count, and a written reconciliation. The numbers must reconcile arithmetically or the widening cannot be recorded. This prevents the oldest trick in disclosure: quietly redefining the population so the problem appears to shrink.

Rule four

Unversioned tooling produces an automatic statement

When an artifact is registered and its producing tool reported no version, the affected range cannot be narrowed by version. The protocol therefore writes a retroactive statement covering that tool's full output for the day, automatically, and places it in the review queue. Ambiguity resolves against the producer.

Append-only by construction

No record on this ledger can be edited or deleted, by anyone, including the people who filed it. Status changes, widenings, statements and review decisions are all stored as new dated entries. A correction is visible as a correction. That property is enforced where the records are stored, not in the pages that display them.

Machine-readable

The whole ledger is published as structured data at /api/public/ledger.json, including every neutrality proof in full, so an external referee or auditor can read it without asking permission.

What this is not

Not a bug tracker. There are no assignees, no triage, no sprint boards. It handles disclosure, and stops there.