Skip to content

chore: refresh org SBOM inventory - #1678

Draft
opencode-agent[bot] wants to merge 933 commits into
mainfrom
automation/sbom-inventory
Draft

opencode-agent[bot] wants to merge 933 commits into
mainfrom
automation/sbom-inventory

Conversation

@opencode-agent

@opencode-agent opencode-agent Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Automated central SBOM inventory refresh for live non-fork repositories. Review reciprocal, restricted, and NOASSERTION license evidence in docs/sbom/inventory.md against the product's actual distribution and hosted-service model.


Devin Review

Current blocking state (2026-09-08)

  • Exact head: e6b292ce5e104212eaa032579afff1514b865019; live main comparison is ahead 70 / behind 0. The effective customer-evidence delta remains docs/sbom/inventory.json and docs/sbom/inventory.md.
  • required-workflow-bootstrap is deterministically RED before policy analysis because the Contents API does not inline the 1,148,611-byte JSON and protected main's policy caps that evidence path at 1 MiB. This is not an Nginx finding.
  • Canonical owner repair #1946 sits at exact head 1cb8cceb8719eb054979d84141cda9a95c0c6873, ahead 5 / behind 0, with bounded Git Blobs fallback plus malicious-content and malformed-evidence tests. Both original and Ready-event same-head Security, SAST, Python Security, and CodeQL PR runs are terminal GREEN. Noema and Strix were materialized but failed on central orchestrator/free availability (HTTP 429 / zero ready routes); OpenCode's derived CHANGES_REQUESTED contains no leaf-source finding. Keep this inventory PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protected main, this branch non-force integrates that release, and new exact-head checks plus independent review are valid.
  • Noema's orchestrator/free HTTP 429 is a separate review-transport blocker. Keep this PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protected main, this branch non-force integrates that release, and all new exact-head checks plus independent review are valid.

@opencode-agent
opencode-agent Bot requested a review from seonghobae as a code owner September 2, 2026 04:27

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 3 potential issues.

⚠️ 3 issues in files not directly in the diff

⚠️ Partial inventory appears complete

With 34 of 63 SBOM fetches returning 404, repo_count reports all 63 while component totals cover only 29. The inventory presents partial organization evidence as complete.


⚠️ Permitted licenses trigger violations

For MPL-2.0 components without another prohibited license, flagged reports at least 137 policy violations. Governance therefore escalates expressly permitted dependencies.


⚠️ Permissive alternatives trigger violations

When an SPDX expression offers a permissive alternative, flagged rejects it because another alternative is copyleft. Seven selectable permissive dependencies become policy violations.

Devin Review

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep labels Sep 2, 2026 — with ChatGPT Codex Connector

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

⚠️ 1 issue in files not directly in the diff

⚠️ Restricted licenses escape policy review

Seven LicenseRef-NVIDIA-Proprietary components are marked unflagged. Unknown and non-standard licenses also disappear from the commercial-permissive policy review.

Devin Review

Copy link
Copy Markdown
Contributor

Diagnosis of the required-workflow-bootstrap failure on this branch (run 33989047645, 5 s, exit 2):

Pingora edge policy could not establish complete evidence: GitHub content evidence for docs/sbom/inventory.json exceeds the size contract

This is deterministic and content-blind, not an Nginx finding. The regenerated docs/sbom/inventory.json is 1,148,611 bytes (236 bytes on main). GitHub omits the diff patch for a file that large, .json is neither a documentation suffix nor a binary document format, so pingora_edge_policy.py must fetch the content, and the Contents API stops inlining at 1 MiB (encoding: "none"), which the policy turns into a fail-closed ContentSizeExceededError. Scanned offline with main's own scan_content, the file has zero denied forms and does not contain the string nginx at all. Every push of this branch will hit the same wall until the evidence route changes.

Fix: #1946 makes the policy follow the Contents response's blob sha to the Git Blobs API (bounded at 11 MiB, bound back to the same sha and size) and scan the bytes like any inline file. Once it is on main, one push that merges main into this branch re-binds the required workflow's trusted source and this context can pass on its merits; re-running the job before then reproduces the same exit 2.


Generated by Claude Code

cwl-noema-review[bot]
cwl-noema-review Bot previously approved these changes Sep 7, 2026

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR refreshes several workflow concurrency groups, adds a coordinator job for CodeQL dispatch, improves allowlist parsing to support multiple trusted actors, and enhances audit coverage reporting. The changes are consistent with the stated rationales, preserve the existing authorization invariants, and introduce no confirmed concrete regressions.

Reviewed changed lines

  • .github/workflows/agent-mention-noema-dispatch.yml:17 (RIGHT): Moves concurrency from the job level to workflow level. The workflow has a single job and the job-level block is removed, so there is no same-group self-wait risk and queued runs coalesce earlier.
  • .github/workflows/agent-mention-opencode-dispatch.yml:17 (RIGHT): Moves concurrency from the job level to workflow level. The workflow has a single job and the job-level block is removed, so there is no same-group self-wait risk and queued runs coalesce earlier.
  • .github/workflows/codeql-scan-dispatch.yml:157 (RIGHT): Parses ALLOWED_DISPATCH_ACTOR as a comma-separated allowlist while requiring non-empty actors; an empty allowlist continues to admit nothing.
  • .github/workflows/codeql-scan-dispatch.yml:524 (RIGHT): The wake job condition reads validated output required_jobs and only proceeds when non-empty, avoiding a wake with missing job bindings.
  • .github/workflows/opencode-review-dispatch.yml:150 (RIGHT): Uses the same comma-separated allowlist parsing with a non-empty guard, permitting multiple trusted dispatch identities without weakening empty-list denial.

Adversarial validation

  • .github/workflows/agent-mention-noema-dispatch.yml:17 (RIGHT) falsified: Moving concurrency to workflow level could cause a run to wait on its own group when job-level and workflow-level groups match. — The diff removes the job-level concurrency block entirely, leaving only the workflow-level group, so no job requests the group its own run already holds.
  • .github/workflows/agent-mention-opencode-dispatch.yml:17 (RIGHT) falsified: Moving concurrency to workflow level could cause a run to wait on its own group when job-level and workflow-level groups match. — The diff removes the job-level concurrency block entirely, leaving only the workflow-level group, so no job requests the group its own run already holds.
  • .github/workflows/codeql-scan-dispatch.yml:157 (RIGHT) falsified: Parsing ALLOWED_DISPATCH_ACTOR with IFS=',' could produce an empty actor that is admitted. — The loop checks allowed_actor is non-empty before comparing against DISPATCH_ACTOR and DISPATCH_SENDER, so an empty allowlist admits nothing.
  • .github/workflows/codeql-scan-dispatch.yml:524 (RIGHT) falsified: Using validated output required_jobs in the wake condition could let a wake job run when no valid job ids were bound. — The wake job condition explicitly requires needs.validate-dispatch.outputs.required_jobs != '', preventing an empty jobs list from triggering the job.
  • .github/workflows/opencode-review-dispatch.yml:150 (RIGHT) falsified: Parsing ALLOWED_DISPATCH_ACTOR with IFS=',' could produce an empty actor that is admitted. — The loop checks allowed_actor is non-empty before comparing against DISPATCH_ACTOR and DISPATCH_SENDER, so an empty allowlist admits nothing.
  • Residual risk: Low. The audited probes attempted concrete regressions around deadlocks, empty allowlists, and malformed job wake inputs and were all falsified against the changed lines.

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: 5f264b19eea2559b4d8ce765e158d7d414bf90eb
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@opencode-agent

opencode-agent Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor Author

OpenCode Review Overview

  • Head SHA: ceea8ab13058fd2d9dcfa2d02bf563e61777169e
  • Workflow run: 34194023190
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES
  • Coverage gate: success
  • Model pool: exhausted
  • Verdict: REQUEST_CHANGES

@seonghobae
seonghobae marked this pull request as draft September 8, 2026 12:18
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: be20cfe5-ea7b-4e3d-a465-d3a130ded55b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread scripts/ci/codeql_ghas_configuration_identity.py Fixed
Comment thread scripts/ci/strix_evidence_binding.py Fixed
bash -c 'set -eu
cd "$1"
dist_dir="$(mktemp -d)"
python3 -m maturin build --offline --release -o "$dist_dir"
seonghobae and others added 5 commits September 26, 2026 18:01
Preserve #2385, #2359, and #2286 as explicit parents while composing their byte-identical overlapping locks and endpoint contract. This creates one exact-head bootstrap stack for the coverage-image, 100% coverage, AnyIO audit, and CodeQL dispatch failures without force-push, rebase, or delta disposal.
seonghobae and others added 30 commits September 28, 2026 03:43
…ete-source-grants-20260928

fix(license): authenticate complete libfuzzer source grants
…wed-helper-adoption-20260928

Adopt reviewed release license helper with exact identity guards
…library-20260928

fix(ci): bind sidecar Python to its matching shared runtime
…ar-runtime-adoption-20260928

fix(ci): adopt matching sidecar runtime in release helper
…2479)

* fix(ci): continue Strix runtime transport failures on same PR head

Connect the existing fail-closed provider classification to the bounded exact-head transport redispatch. Do not retry findings, scanner tooling errors, or sandbox failures. Reuse the central attempt and jitter contract. Ref #2477.

* test(ci): cover Strix runtime continuation budget branches

Exercise valid and invalid head identities and the exhausted retry budget directly so the central 100% branch coverage gate includes the new module.

* fix(ci): exclude mixed Strix sandbox failures from continuation

A sandbox bootstrap failure can coexist with an LLM connection signal. Keep that incomplete scan failed without scheduling another model scan; cover the mixed log case.
* fix(ci): prefetch locked Cargo fixtures for offline coverage

* fix(ci): force offline Cargo resolution in coverage sandbox

* fix(ci): discard untrusted Cargo home before coverage

* test(ci): cover cached Cargo fixture dependencies

* fix(ci): scope Cargo offline policy to trusted sandbox home
Remove the low-privilege coverage checkout and its tagged Docker image after every coverage attempt. Preserve other attempts and keep the existing review trust boundary.

Refs: #945
Keep the build directory unique to a run attempt so failing builds are cleaned by the always step without touching another attempt.

Refs: #945
…e cap (#2498)

* fix(pingora): bound decoded PNG size separately from the HTTP response cap

_is_complete_png rejected any PNG whose decoded scanlines exceed
MAX_RESPONSE_BYTES (16 MiB), a limit meant for REST responses. A valid
2238x2052 RGBA macOS screenshot decodes to 18.4 MB, so it was treated as
not-a-PNG, fell through to the text scan and failed as "not valid UTF-8".
This blocked five screenshots under a declared artifact prefix in
late-life-anxiety-reanalysis#257.

Add MAX_PNG_DECODED_BYTES (128 MiB) for the decoded-pixel bound and keep
the response cap unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011arF4D6VAoT48vh5HvyHtD

* chore: drop uv.lock that was committed by accident

The lockfile was generated by a local `uv run` and is not part of the PNG
bound fix. main has no root uv.lock, and adding one widens this PR into a
dependency change. tests/test_pingora_edge_policy.py passes without it
(100 passed).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N9qbK6d91C7LkriuTf7dR8

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Since #2437 the sidecar creates $RUNNER_TEMP/contextual-orchestrator-review/.venv
with a plain `python -m venv`. On cwlab-s1-04 that directory survived between
jobs, and `python -m venv` exits 0 over an environment whose pip package lost
__init__.py/__main__.py, leaving pip as a namespace package. From
2026-09-27T17:47Z every OpenCode review there failed at sidecar provisioning
with "No module named pip.__main__", so no verdict was published and required
opencode-review checks failed closed across the organization.

Use `venv --clear`. The new regression damages a real venv, reruns the
script's venv line, and requires `python -m pip --version` to work; it fails
on main with the production message.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW
…-verdict-rca-20260929

fix(ci): rebuild the review sidecar venv on persistent runner temp
…-cleanup-20260928

fix(ci): reclaim per-run OpenCode coverage resources
hourly-review-repair's dispatch-review-fixes job (reusable
pr-review-fix-scheduler.yml) was pinned to hosted ubuntu-24.04. On
2026-09-29, 12 of the last 18 hourly runs sat queued there for up to 12 h
behind the org-wide hosted concurrency limit while three of the four
cwlab-control runners were idle.

Select the CWL central control group (cwlab-control) only when the caller
is the central main hourly-review-repair workflow; any other caller keeps
hosted Ubuntu 24.04. The job only reads the API and dispatches autofix; a
new contract pins the single trusted checkout (called-workflow SHA,
persist-credentials false), no pull_request.head reference, and keeps the
dispatched autofix workflow off the control pool.

Runner group 6 now also allows
ContextualWisdomLab/.github/.github/workflows/pr-review-fix-scheduler.yml@refs/heads/main
(restricted_to_workflows stays true).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW
…duler-control-runner

fix(ci): run the central fix-scheduler dispatch on the control runners
One OpenCode runner serves every repository first-in first-out, so a
release PR waited behind about 180 other reviews on 2026-09-29. The
coordinator approved a reproducible operator action instead of a deferral
scheduler that could starve PRs.

The script classifies queued opencode-review-dispatch runs against the live
PR: stale (closed or moved head), keep (review-priority label applied by a
write/maintain/admin actor, so a fork cannot jump the queue), or deferred.
It prints backlog metrics, posts the cancel list to an issue before any
cancellation, and --apply cancels only runs still queued. Cancelled PRs are
re-dispatched by the scheduler or by rerunning their opencode-review job.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PtgtJk1WjqieqvLDb1w8uW
…-queue-priority-runbook

feat(ops): add an OpenCode dispatch-queue priority runbook

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants