-
Notifications
You must be signed in to change notification settings - Fork 0
fix(governance): audit must fail on non-default branch scope drift #1200
Copy link
Copy link
Open
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Description
Activity
Metadata
Metadata
Assignees
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Owner-boundary defect from a live ScopeWeave canary
This is an organization-control-plane issue, not a request for a ScopeWeave leaf workaround.
Exact consumer evidence
On
ContextualWisdomLab/scopeweave#523:develop@2c328875e00e86537df3e965170be80532571cad;fix/server-tests-exact-head-522@2304fb64bfeccadf588db52e5d9b4bd2051af3dc;Changes must be made through a pull request, naming the central required workflows (Close Empty PR, Required Noema/OpenCode review, merge scheduler, SAST, Security Scan, Strix, etc.);Reference update failed, and fresh branch searches proved neither requested ref was created.This prevents the repository-owned writer from putting a verified CI-gate repair through a fresh normal PR branch.
Independently verified central audit gap
scripts/ci/audit_central_required_workflows.pycorrectly requires~DEFAULT_BRANCHto be present in the rulesetref_name.include, but it does not reject additional ref include patterns. Therefore a ruleset that contains~DEFAULT_BRANCHplus~ALL, a branch glob, or another unintended non-default target can pass the audit even though central pull-request/required-workflow rules are over-scoped.This audit gap is independently actionable even if the live ruleset ultimately proves correctly scoped. The ScopeWeave write denial is a canary that makes live scope verification urgent; it is not by itself proof that ruleset 18156473 is the only possible cause.
Required repair-first investigation
18156473and its exactconditions.ref_namethrough the existing central owner authority. Do not infer scope from remembered policy or the audit script.ref_name.includecontains~DEFAULT_BRANCHplus an unintended extra branch target. Current audit behavior should be shown to pass before the repair.~DEFAULT_BRANCH.Acceptance evidence
developremains fully protected;The
ContextualWisdomLab/.githubdedicated writer remains the source/settings owner for this repair. ScopeWeave should only regenerate exact-head evidence after the owner fix integrates.