{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-sft-013","code":"wm-sft-013-software-change-pull-request","url":"https://ver.cy/models/wm-sft-013-software-change-pull-request/","name":"Software Change / Pull Request","alternateNames":[],"kind":"world-model","status":"published","version":"0.1.0","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.SFT.CHG"],"industry":["Cross-industry"],"navPath":"NAV.INF.SFT.CHG","tags":["software","change","pull","request","inf.sft.chg"],"facets":{}},"whatItIs":"A software change or pull request is a proposed set of changes to a source repository, presented for review and automated checks and then merged, revised or closed. Single commits outside a review, the build or release that later ships the change, and the defect or requirement that motivated it are separate subjects.","purpose":"Describe one persistent proposed software change through revisions, assessment and integration outcomes.","scope":{"in":["Master identity, accountable roles, intent and typed links","Revision-specific diff, review, check and policy evidence","Observed readiness, lifecycle outcomes, lineage and controlled record views"],"out":["Repository administration, commit storage and branch mutation owned by WM-SFT-005","Defect and requirement lifecycle, vulnerability exploitation, CI execution, deployment and release management","Enforcing branch policy, granting merge authority, performing merges/reverts, issuing compliance certification","Unreviewed direct commits without a proposal record; organization-wide change control"],"boundaries":[{"neighbor":"WM-SFT-005 Source Repository","distinction":"Honor incoming candidate CONTAINS: each proposal references its repository context. Repository identity, permissions and history remain mastered there; containment is not entity-kind inheritance."},{"neighbor":"WM-SFT-014 Defect","distinction":"Honor incoming candidate REFERENCE: a defect may reference a resolving proposal. Optional reciprocal traceability here does not close the defect or prove resolution."},{"neighbor":"Commit and patch-set records","distinction":"A persistent proposal can acquire multiple revisions and many input or resulting commits. Hash identity never replaces the scoped proposal key."},{"neighbor":"Build, release, deployment and attestation records","distinction":"Link their independently mastered evidence. Merge and check success do not prove release, deployment or artifact provenance compliance."},{"neighbor":"Operations change authorization","distinction":"Software integration proposal records evidence about code change; operational authorization remains separate even when references connect them."}]},"distinguishingFeatures":["A unit of proposed change with a review lifecycle, not a plain commit in history.","Belongs to a source repository and targets a branch, while builds and releases come later.","Carries review and check evidence that supports change control and audit.","Distinct from a change request in operations, which governs changes to running services."],"structure":{"bundles":[{"id":"SFT013-B1","name":"Proposed change","description":"What is proposed and why.","layers":[{"id":"SFT013-B1-L1","name":"Diff and intent","description":"The changes, their target and their motivation.","findings":[{"id":"SFT013-F01","name":"Source and target","description":"The source branch, the target branch and the commits included.","questions":[{"text":"Which branch or fork does the change come from, and which branch does it target?","id":"SFT013-Q01"},{"text":"Which commits and files does it change?","id":"SFT013-Q02"}]},{"id":"SFT013-F02","name":"Motivation","description":"The issue, defect or requirement the change addresses.","questions":[{"text":"Which issue, defect or requirement does the change address?","id":"SFT013-Q03"},{"text":"Who authored the change, and was any of it generated by a tool?","id":"SFT013-Q04"}]}]}]},{"id":"SFT013-B2","name":"Review and checks","description":"How the change was verified before merge.","layers":[{"id":"SFT013-B2-L1","name":"Review","description":"Human review and approvals.","findings":[{"id":"SFT013-F03","name":"Approvals","description":"Reviewers, their verdicts and required approvals.","questions":[{"text":"Who reviewed the change, and did the required reviewers approve it?","id":"SFT013-Q05"},{"text":"Were review comments resolved before merge?","id":"SFT013-Q06"}]}]},{"id":"SFT013-B2-L2","name":"Automated checks","description":"Tests, scans and policy checks on the change.","findings":[{"id":"SFT013-F04","name":"Check results","description":"Results of tests, builds and security scans.","questions":[{"text":"Which tests and scans ran on the final revision, and did they pass?","id":"SFT013-Q07"},{"text":"Were any failing checks overridden, and by whom?","id":"SFT013-Q08"}]}]}]},{"id":"SFT013-B3","name":"Outcome","description":"What happened to the change.","layers":[{"id":"SFT013-B3-L1","name":"Merge or closure","description":"The merge, rejection or abandonment of the change.","findings":[{"id":"SFT013-F05","name":"Final state","description":"Merged, closed or open, with the resulting commit.","questions":[{"text":"Was the change merged, closed or left open?","id":"SFT013-Q09"},{"text":"Which merge commit resulted, and was it later reverted?","id":"SFT013-Q10"}]}]}]}]},"agentConduct":{"may":["Open a pull request with a clear description of the change and its motivation.","Run and report automated checks on a change.","Review changes and comment on defects, risks and style.","Summarize a change for reviewers."],"mustNot":["Merge a change without the approvals and passing checks the repository requires.","Approve its own change where independent review is required.","Bypass branch protection or force-push over others' work.","Commit secrets, credentials or personal data in a change.","Hide that a change was generated or modified by an automated agent where the project requires disclosure."],"requiresHuman":["Approving changes to protected branches.","Overriding a failing required check.","Merging changes that affect security, licensing or production configuration."]},"ethics":{"considerations":["Review is a key defence against defects and supply-chain attacks that reach many users.","Contributor credit and licence terms must be respected for every change.","Review comments affect people's work and should address the code, not the person."],"affectedParties":["Contributors and reviewers","Maintainers of the repository","Users of the software","Downstream projects that depend on it"]},"owners":{"steward":"The maintainers of the target repository, who decide whether a change is merged.","roles":[{"name":"Contributor","responsibilities":["Supply intent and revision references; authorship does not confer integration authority"]},{"name":"Reviewer","responsibilities":["Assess identified material within delegated scope and disclose policy-required conflicts"]},{"name":"Repository maintainer","responsibilities":["Own applicable integration policy and authoritative outcome decisions"]},{"name":"Check producer","responsibilities":["Identify evaluated inputs, execution attempt and result provenance"]},{"name":"Record steward","responsibilities":["Control local mappings, access, correction and disposition"]},{"name":"Audit reader","responsibilities":["Inspect permitted evidence and report gaps without silently changing verdicts"]}],"masterSystems":["Source code hosting platform","Version control system","Continuous integration system"]},"relations":[{"target":"WM-SFT-005","type":"references","note":"Repository context implements the inverse navigation of the incoming candidate CONTAINS edge without owning repository administration. Binding version remains to be pinned."},{"target":"WM-SFT-014","type":"references","note":"Optional reciprocal traceability for the incoming defect REFERENCE edge; defect status and proof of resolution stay at its master."},{"target":"External review, check and policy masters","type":"references","note":"Bind evidence and applicable policy using versioned native identifiers; do not duplicate execution or enforcement."},{"target":"External build and release records","type":"references","note":"Link outcome evidence and attestation subjects; no mandatory build or delivery record for every proposal."},{"target":"PROV-O","type":"aligned","note":"Conceptual assertion, revision, activity and actor vocabulary mapping, without ontology conformance claim."},{"target":"SLSA provenance/v1","type":"aligned","note":"Interpret referenced build attestations under a pinned verifier profile; no SLSA level claim for a proposal."},{"target":"WM-SFT-005 Source Repository","type":"neighbor","note":"Honor incoming candidate CONTAINS: each proposal references its repository context. Repository identity, permissions and history remain mastered there; containment is not entity-kind inheritance."},{"target":"WM-SFT-014 Defect","type":"neighbor","note":"Honor incoming candidate REFERENCE: a defect may reference a resolving proposal. Optional reciprocal traceability here does not close the defect or prove resolution."},{"target":"Commit and patch-set records","type":"neighbor","note":"A persistent proposal can acquire multiple revisions and many input or resulting commits. Hash identity never replaces the scoped proposal key."},{"target":"Build, release, deployment and attestation records","type":"neighbor","note":"Link their independently mastered evidence. Merge and check success do not prove release, deployment or artifact provenance compliance."},{"target":"Operations change authorization","type":"neighbor","note":"Software integration proposal records evidence about code change; operational authorization remains separate even when references connect them."},{"target":"WM-SFT-005","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Identified by the repository plus the pull or merge request number assigned by the hosting platform.","Each revision is identified by its head commit hash."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["Recognized by a source branch, a target branch, a diff, a description and a review state.","Often confused with a commit, a branch or the issue it addresses."]},"capabilities":{"applicability":"required","items":["Can be opened, updated, reviewed, approved, merged, reverted or closed.","Can trigger automated builds, tests and scans.","Can link to issues and close them when merged."]},"hazards":{"applicability":"required","items":["Malicious or vulnerable code entering the main branch.","Leaked secrets in diffs or history.","Broken builds and outages from untested merges."]},"interfaces":{"applicability":"required","items":["Git version control and its patch formats.","Hosting platform APIs for pull or merge requests and reviews.","SLSA framework for build provenance of merged changes."]},"context":{"applicability":"required","items":["Used in open source and in-house software development.","Regulated industries use review records as evidence of change control."]}},"sources":[{"title":"Pull requests","url":"https://docs.github.com/en/pull-requests/reference/pull-requests","note":"GitHub"},{"title":"About protected branches","url":"https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches","note":"GitHub"},{"title":"Merge requests API","url":"https://docs.gitlab.com/api/merge_requests/","note":"GitLab"},{"title":"Changes","url":"https://gerrit-review.googlesource.com/Documentation/concept-changes.html","note":"Gerrit project"},{"title":"git-diff documentation","url":"https://git-scm.com/docs/git-diff","note":"Git project"},{"title":"Secure Software Development Framework Version 1.1","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf","note":"National Institute of Standards and Technology"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"SLSA Provenance","url":"https://slsa.dev/spec/v1.1/provenance","note":"SLSA project"},{"title":"Supply-chain Levels for Software Artifacts (SLSA), Open Source Security Foundation"},{"title":"ISO/IEC/IEEE 12207 Systems and software engineering - Software life cycle processes, ISO/IEC/IEEE"}],"openQuestions":["Run direct source retrieval and review current documentation against version-pinned target deployments; retain the frozen audit evidence and reassess any changed claims.","Implement nested schemas and profile-specific mappings with fixtures for rewritten revisions, moving targets, stale checks, skipped results, partial diffs, unknown outcomes and restricted artifacts.","Obtain independent second-provider review and qualified owner review of retention, licensing and regulated adoption; investigate mail-based and non-Git proposal profiles separately.","Exhaustive platform state machines, mail-based patch workflows and non-Git implementations","Nested data schemas, pinned neighbor versions, verified API bindings and executable fixtures","Current deployment/version certification and independent second-provider review","Jurisdiction-specific retention, licensing and regulated change-control applicability"],"resources":{"spec":"/models/wm-sft-013-software-change-pull-request/spec.yaml","agents":"/models/wm-sft-013-software-change-pull-request/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-013"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-sft-013-software-change-pull-request/spec.yaml","ver-cy/world-models/card-supplements/wm-sft-013-software-change-pull-request.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T12:34:35Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"The subject is an information or institutional record, not a physical object, so it has no physical properties to measure.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}