{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","research_id":"eoa_inverse_innovation_exp09_light_prior_art_20260804","cell_id":"deadweight_loss_reduction__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["risk-tiered approval dependency updates one approval two approvals patch updates","dependency update pull requests approval bottleneck reviewer queue","dependency bot pull request abandonment superseded review delay study"],"source_ids":["SRC1","SRC2","SRC3"],"no_result_note":"No retained source directly measures the proposed universal two-senior-approval baseline or the marginal protection supplied by its second approval."},"synonyms_and_historical_terms":{"queries":["automated dependency updates merge queue review burden Dependabot Renovate","low-risk change streamlined approval software supply chain","dependency update bot notification fatigue technical lag"],"source_ids":["SRC1","SRC3"],"no_result_note":null},"products_practices_and_standards":{"queries":["GitHub rulesets required approvals Dependabot auto-merge","Renovate automerge patch updates security controls","SLSA dependency update provenance approval"],"source_ids":["SRC2","SRC3","SRC4"],"no_result_note":null},"component_combination":{"queries":["patch dependency updates provenance tests vulnerability checks one reviewer","dependency update auto merge allowlist lockfile integrity approval","passing status checks mandatory pull request reviews dependency automerge"],"source_ids":["SRC2","SRC3","SRC4"],"no_result_note":"No retained source combines the proposal's full predicate set—provenance, registry allowlisting, lockfile integrity, privilege invariance, vulnerability and license checks, service criticality, one human approval, monitoring, and automatic rollback."}},"sources":[{"source_id":"SRC1","title":"Automating Dependency Updates in Practice: An Exploratory Study on GitHub Dependabot","publisher":"Runzhi He, Hao He, Yuxia Zhang, and Minghui Zhou via arXiv","url":"https://arxiv.org/abs/2206.07230","source_type":"PRIMARY_RESEARCH","claims_supported":["Dependency-update bots reduce technical lag but create update suspicion and notification fatigue.","Studied projects commonly reduced update frequency or open-pull-request limits after adoption, indicating workload and attention pressure.","Compatibility evidence was often too sparse to eliminate maintainers' uncertainty about automated updates."]},{"source_id":"SRC2","title":"Automating Dependabot with GitHub Actions","publisher":"GitHub","url":"https://docs.github.com/en/enterprise-cloud@latest/code-security/tutorials/secure-your-dependencies/automate-dependabot-with-actions","source_type":"OFFICIAL_GUIDANCE","claims_supported":["GitHub documents automated approval of Dependabot pull requests.","GitHub provides an example that enables automerge specifically for a named dependency's semantic-version patch updates.","Automerge can remain conditional on branch-protection approvals and passing required status checks."]},{"source_id":"SRC3","title":"Automerge configuration and troubleshooting","publisher":"Mend Renovate","url":"https://docs.renovatebot.com/key-concepts/automerge/","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["Renovate supports rule-based automerge for patch and minor dependency updates while excluding pre-1.0 dependencies in its example.","Renovate normally waits for passing status checks and recommends tests for regularly updated dependencies.","Mandatory pull-request reviews prevent Renovate from automerging until a review occurs, while configured bypass or approval mechanisms can remove that obstacle.","Renovate describes automated rebasing and repeated CI caused by lockfile conflicts, directly exposing maintenance rework.","Renovate can route failed automated updates to human reviewers while allowing qualifying passing updates to proceed automatically."]},{"source_id":"SRC4","title":"SLSA — Supply-chain Levels for Software Artifacts","publisher":"OpenSSF / The Linux Foundation","url":"https://slsa.dev/","source_type":"OFFICIAL_STANDARD","claims_supported":["Software dependencies can introduce supply-chain vulnerabilities, so integrity checks remain a material protected constraint.","SLSA supplies a vendor-neutral framework of controls for artifact integrity and prevention of unauthorized modification.","Provenance is an initial practical control for establishing supply-chain trust."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The general problem is visible: primary research reports dependency-update notification fatigue and workload-driven reductions in bot activity, while Renovate documents that mandatory reviews block otherwise eligible automerge and that dependency-update conflicts cause rebasing and repeated CI. The sources do not establish that organizations commonly impose exactly two senior approvals, nor that this approval count—rather than failed checks, ownership ambiguity, or substantive review—is the dominant cause of delay.","source_ids":["SRC1","SRC3"]},"closest_prior_art":[{"name":"Renovate risk-selected automerge for non-major dependency updates","source_ids":["SRC3"],"overlap":"Classifies patch or minor updates as candidates for automerge, relies on passing tests, excludes a riskier version category, automates rebasing, and sends failed cases to human review. It also documents mechanisms for bypassing mandatory reviews.","remaining_difference":"The proposal retains one human approval, specifies a broader compound eligibility envelope, excludes critical services and privilege changes, and frames deployment as an authorized reversible pilot with incidence measurement and explicit stop thresholds."},{"name":"GitHub Actions workflows for Dependabot auto-approval and patch-update automerge","source_ids":["SRC2"],"overlap":"Uses machine-readable Dependabot metadata to identify semantic-version patch updates, automate approval, and enable merging after required tests and approvals pass.","remaining_difference":"The documented examples do not evaluate one versus two senior approvals, require the proposal's entire provenance and governance predicate set, or prescribe a retrospective causal review and monitored rollback pilot."},{"name":"SLSA provenance and artifact-integrity controls","source_ids":["SRC4"],"overlap":"Supplies part of the proposal's protected security constraint through provenance, integrity, and assurance controls for software artifacts and dependencies.","remaining_difference":"SLSA does not prescribe dependency pull-request approval counts, risk-tiered reviewer allocation, queue measurement, or this pilot design."}],"prior_art_disposition":"SUBSTANTIAL_COLLISION","contrastive_claim_remaining":"Within a pre-specified class that satisfies the complete safeguard set, replacing two senior approvals with exactly one accountable maintainer approval will reduce approval-rule-attributable waiting, rebasing, expiration, and reviewer concentration without crossing pre-registered security or reliability thresholds; this narrower one-versus-two claim and its measured governance pilot were not found in the retained sources.","contrastive_claim_falsifier":"The claim fails if retrospective attribution shows no material delay caused by the second approval, if that approval frequently detects consequential defects or compromise indicators among otherwise eligible updates, or if an authorized pilot fails to reduce queueing and rework or exceeds any classification, bypass, reversion, security, reliability, or burden-shift stop threshold.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The bounded search covered the proposal directly, older bot and automerge terminology, first-party product practices, official supply-chain controls, and combinations of approval, patch scope, testing, provenance, and lockfile concerns. Four opened sources span four publisher groupings and include primary research, official guidance, first-party documentation, and an official standard.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"The broader maintenance-attention and review-friction problem is partly supported, although the exact two-senior-approval baseline remains unverified.","source_ids":["SRC1","SRC3"]},"distinct_testable_claim":{"status":"PASS","rationale":"Despite substantial intervention overlap, the marginal one-versus-two approval claim under the proposal's complete eligibility envelope is explicit and falsifiable through approval-level defect attribution and bounded outcome comparison.","source_ids":["SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"A read-only, at-most-100-PR retrospective from one repository group over a completed 90-day period is bounded, reversible, and capable of testing whether the second approval causes delay and contributes marginal protection before any policy change.","source_ids":["SRC1","SRC2","SRC3"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The authorized first step changes no workflow; any later pilot requires maintainer, security-owner, and service-owner approval, retains substantive controls, excludes higher-risk changes, preserves audit evidence, and defines immediate rollback conditions. Sparse safety events may limit inference but do not prohibit the retrospective test.","source_ids":["SRC2","SRC3","SRC4"]}},"screen_survival":false,"world_novelty_boundary":"This bounded public-web screen found substantial collision with established dependency-update automerge and risk-selection practices. It does not establish world novelty, patentability, market size, expert acceptance, realized value, or absence of additional prior art."}