Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
54 commits
Select commit Hold shift + click to select a range
dea7532
fix: reject runtime directives in declared binary artifacts
seonghobae Sep 26, 2026
6a32843
docs(edge): bind declared-binary runtime guard
seonghobae Sep 26, 2026
761be5b
test(security): require explicit AnyIO audit pin
seonghobae Sep 26, 2026
c59ef9a
fix(security): pin audited AnyIO runtime
seonghobae Sep 26, 2026
a895dc5
fix(security): regenerate Strix lock for AnyIO 4.14.2
seonghobae Sep 26, 2026
7d8a6bc
docs(gap): bind AnyIO security-lock carryover
seonghobae Sep 26, 2026
02d9796
fix(codeql): require complete terminal proof
seonghobae Sep 27, 2026
dddc1be
docs(codeql): clarify successful-job proof path
seonghobae Sep 27, 2026
72bcf3b
fix(codeql): bind terminal receipts to exact run
seonghobae Sep 27, 2026
3234b5b
fix(docs): remove trailing blank line
seonghobae Sep 27, 2026
5a77a8c
fix(codeql): bind fallback run to merge source
seonghobae Sep 27, 2026
1d07d46
docs(gap): record CodeQL terminal-proof repair
seonghobae Sep 27, 2026
2fb6ec7
fix(docs): preserve complete gap baseline
seonghobae Sep 27, 2026
bc640ec
fix: route trusted Noema consumer workflows to self-hosted pools
seonghobae Sep 27, 2026
df90cd2
fix: bound Noema runner adoption to the admitted consumer set
seonghobae Sep 27, 2026
24bdfe0
Merge pull request #2429 from ContextualWisdomLab/fix/noema-trusted-c…
seonghobae Sep 27, 2026
cc64858
test: restore isolated trusted Strix fixture runtime
seonghobae Sep 27, 2026
da4453e
fix(ci): admit telemetry consumer Noema on trusted runners
seonghobae Sep 27, 2026
c3e8614
Merge pull request #2431 from ContextualWisdomLab/fix/1565-noema-runn…
seonghobae Sep 27, 2026
f45015b
fix(ci): send Noema continuation to central handler
seonghobae Sep 27, 2026
7bc3e68
Merge pull request #2432 from ContextualWisdomLab/fix/1565-noema-cent…
seonghobae Sep 27, 2026
0d83b45
test: retain scanned source without executing consumer runtime
seonghobae Sep 27, 2026
fd2a03e
fix(ci): align CodeQL runner contract with trusted main routing (#2434)
seonghobae Sep 27, 2026
9096438
fix(ci): admit late-life trusted Noema consumer
seonghobae Sep 27, 2026
867e061
Merge remote-tracking branch 'origin/main' into fix/late-life-noema-r…
seonghobae Sep 27, 2026
680513a
merge: adopt current central runner routing for PR 2386
seonghobae Sep 27, 2026
efe6073
Merge remote-tracking branch 'origin/main' into fix/pr2386-current-ru…
seonghobae Sep 27, 2026
e5ecaaf
fix(ci): route trusted Strix metadata to control runners
seonghobae Sep 27, 2026
5db8ff9
Merge branch 'main' of https://github.com/ContextualWisdomLab/.github…
seonghobae Sep 27, 2026
3b36b89
Merge pull request #2436 from ContextualWisdomLab/fix/fmls2114-strix-…
seonghobae Sep 27, 2026
2917179
Merge pull request #2435 from ContextualWisdomLab/fix/late-life-noema…
seonghobae Sep 27, 2026
eb1bdc9
fix(ci): isolate review sidecar on lock-compatible Python (#2437)
seonghobae Sep 27, 2026
65d639a
Merge remote-tracking branch 'origin/main' into fix/pr2386-current-ru…
seonghobae Sep 27, 2026
5095d01
Merge branch 'main' of https://github.com/ContextualWisdomLab/.github…
seonghobae Sep 27, 2026
1804df3
Merge pull request #2386 from ContextualWisdomLab/codex/pingora-decla…
seonghobae Sep 27, 2026
ec38bff
Merge pull request #2430 from ContextualWisdomLab/test/strix-trusted-…
seonghobae Sep 27, 2026
5764a44
fix(ci): refresh trusted runtime for Strix evidence retries
seonghobae Sep 27, 2026
0a26cc0
test(ci): retain Strix scan job identity contract
seonghobae Sep 27, 2026
81dae9a
test(ci): refresh dispatch blob pin after sidecar Python repair (#2439)
seonghobae Sep 27, 2026
4076476
fix(codeql): scope verdict history to the required run (#2433)
seonghobae Sep 27, 2026
f6a50f6
Merge pull request #2438 from ContextualWisdomLab/codex/a3-strix-fres…
seonghobae Sep 27, 2026
8a6dece
fix(noema): continue capacity failures during sidecar preflight
seonghobae Sep 27, 2026
ca9269a
fix(noema): refuse nonregular preflight evidence without blocking
seonghobae Sep 27, 2026
de5d449
fix(noema): reuse stdlib-only preflight continuation from PR 2339
seonghobae Sep 27, 2026
618efe7
Merge commit 'f6a50f6a59a0d3a4a5bdbd9e574684c71bd6fbbf' into fix/revi…
seonghobae Sep 27, 2026
6492128
fix(codeql): use separate owned app publication and settlement tokens
seonghobae Sep 27, 2026
eb59914
Merge pull request #2440 from ContextualWisdomLab/fix/review-sidecar-…
seonghobae Sep 27, 2026
0538e10
merge: adopt complete CodeQL terminal proof foundation
seonghobae Sep 27, 2026
6952dcc
fix(codeql): publish owned failure receipts after failed gates
seonghobae Sep 27, 2026
23f36cd
Merge pull request #2444 from ContextualWisdomLab/fix/codeql-owned-ap…
seonghobae Sep 27, 2026
c9ca98d
merge: preserve release gate while adopting current CI controls
seonghobae Sep 27, 2026
a3ce442
fix(release): adopt verified integrated helper source
seonghobae Sep 27, 2026
64bb4e7
fix(release): validate evidence and preserve structured refusals
seonghobae Sep 27, 2026
7bc87db
fix(release): bind workflow to corrected evidence gate
seonghobae Sep 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/actions/orchestrator-free-sidecar/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,16 @@ runs:
ref: ${{ github.action_ref }}
path: ${{ runner.temp }}/cwl-control-plane
persist-credentials: false
- name: Set up lock-compatible sidecar Python
id: sidecar_python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
update-environment: false
- name: Provision contextual-orchestrator orchestrator/free
shell: bash --noprofile --norc -e -o pipefail {0}
env:
SIDECAR_PYTHON: ${{ steps.sidecar_python.outputs.python-path }}
CONTEXTUAL_ORCHESTRATOR_REQUIRE_ZDR: ${{ inputs.require_zdr }}
ORCHESTRATOR_CATALOG_LIMIT: ${{ inputs.catalog_limit }}
ORCHESTRATOR_CATALOG_ACCOUNT_CAP: ${{ inputs.catalog_account_cap }}
Expand Down
62 changes: 46 additions & 16 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@
# runner, then one coordinator POSTs repository_dispatch to
# codeql-scan-dispatch.yml (native, unrestricted, in
# ContextualWisdomLab/.github) with the remaining language matrix. The
# handler publishes codeql-dispatch/<language> and reruns only that exact
# failed job. On rerun the shard reads the terminal status once. Design:
# handler publishes a base/run/source-bound codeql-dispatch receipt and reruns
# only that exact failed job. On rerun the shard reads the terminal status once. Design:
# docs/adr/0025-codeql-required-workflow-dispatch-architecture.md. The
# merge-preview scan (analyze-merge) is required nowhere (PR #1766) and was
# dropped, not migrated.
Expand Down Expand Up @@ -153,6 +153,7 @@ jobs:
# closed PRs need no required check.
runs-on: ${{ fromJSON(github.workflow_ref == 'ContextualWisdomLab/.github/.github/workflows/codeql-pr.yml@refs/heads/main' && '{"group":"CWL central control","labels":["self-hosted","linux","x64"]}' || '"ubuntu-24.04"') }}
permissions:
actions: read
contents: read
id-token: write
pull-requests: read
Expand All @@ -163,7 +164,7 @@ jobs:
steps:
- name: Read current-head CodeQL dispatch verdict
# Shards never dispatch. They re-check the live head, consume an
# authenticated codeql-dispatch/<language> verdict when one exists,
# authenticated base/run/source-bound CodeQL verdict when one exists,
# and otherwise fail pending so the runner is released. One
# coordinator job POSTs the remaining language matrix after every
# shard has a job id.
Expand All @@ -182,6 +183,7 @@ jobs:
live_pr="$(gh api "repos/${TARGET_REPOSITORY}/pulls/${PR_NUMBER}")"
live_head="$(printf '%s' "$live_pr" | jq -r '.head.sha // empty')"
live_base="$(printf '%s' "$live_pr" | jq -r '.base.sha // empty')"
live_merge="$(printf '%s' "$live_pr" | jq -r '.merge_commit_sha // empty')"
live_state="$(printf '%s' "$live_pr" | jq -r 'if (.state | type) == "string" then .state else empty end')"
if ! [[ "$PR_HEAD_SHA" =~ ^[0-9a-fA-F]{40}$ && "$live_head" =~ ^[0-9a-fA-F]{40}$ ]] || [[ "$live_state" != "open" && "$live_state" != "closed" ]]; then
echo "::error::Could not validate live pull request state before CodeQL dispatch."
Expand All @@ -206,8 +208,9 @@ jobs:
echo "verdict=obsolete" >>"$GITHUB_OUTPUT"
exit 0
fi
if ! [[ "$live_base" =~ ^[0-9a-fA-F]{40}$ ]]; then
echo "::error::Could not validate live pull request base SHA before CodeQL verdict read."
if ! [[ "$live_base" =~ ^[0-9a-fA-F]{40}$ ]] ||
! [[ "$live_merge" =~ ^[0-9a-fA-F]{40}$ ]]; then
echo "::error::Could not validate live pull request base/source SHA before CodeQL verdict read."
exit 1
fi
if ! [[ "$REQUIRED_RUN_ID" =~ ^[1-9][0-9]*$ ]]; then
Expand All @@ -216,13 +219,17 @@ jobs:
fi

statuses="$(gh api "repos/${TARGET_REPOSITORY}/commits/${PR_HEAD_SHA}/statuses")"
verdict_state="$(printf '%s' "$statuses" | jq -r --arg ctx "codeql-dispatch/${LANGUAGE}" '
expected_context="codeql-dispatch/${LANGUAGE}/${live_base}"
expected_description="cwl1;h=${PR_HEAD_SHA};w=codeql-scan-dispatch;r=${REQUIRED_RUN_ID};s=${live_merge}"
verdict_state="$(printf '%s' "$statuses" | jq -r --arg ctx "$expected_context" --arg description "$expected_description" '
[
.[]
| select(.context == $ctx)
| select(.description == $description)
| select(
(.creator.login // "" | ascii_downcase) as $creator
| $creator == "opencode-agent" or $creator == "opencode-agent[bot]"
or $creator == "cwl-noema-review" or $creator == "cwl-noema-review[bot]"
)
]
| first // {} | .state // empty
Expand All @@ -235,9 +242,15 @@ jobs:
;;
esac

expected_title="CodeQL Scan Dispatch ${TARGET_REPOSITORY}#${PR_NUMBER}@${PR_HEAD_SHA}/${live_base}/${REQUIRED_RUN_ID}"
expected_title="CodeQL Scan Dispatch ${TARGET_REPOSITORY}#${PR_NUMBER}@${PR_HEAD_SHA}/${live_base}/${REQUIRED_RUN_ID}/${live_merge}"
expected_job="CodeQL dispatch scan (${LANGUAGE})"
runs_json="$(gh api --paginate --slurp "repos/ContextualWisdomLab/.github/actions/workflows/codeql-scan-dispatch.yml/runs")"
# A dispatch bound to this required run cannot predate its creation.
required_created_at="$(gh api "repos/${TARGET_REPOSITORY}/actions/runs/${REQUIRED_RUN_ID}" --jq .created_at)"
if ! [[ "$required_created_at" =~ ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}Z$ ]]; then
echo "::error::Could not validate required run creation time before CodeQL verdict lookup."
exit 1
fi
runs_json="$(gh api --method GET --paginate --slurp -f per_page=100 -f event=repository_dispatch -f created=">=${required_created_at}" "repos/ContextualWisdomLab/.github/actions/workflows/codeql-scan-dispatch.yml/runs")"
run_id="$(printf '%s' "$runs_json" | jq -r --arg title "$expected_title" --arg path ".github/workflows/codeql-scan-dispatch.yml" '
[
.[] | .workflow_runs[]
Expand All @@ -259,11 +272,20 @@ jobs:
gate_conclusion="$(printf '%s' "$dispatch_job" | jq -r '
(.steps[]? | select(.name == "Enforce CodeQL Medium+ SARIF gate") | .conclusion) // empty
')"
ghas_identity_conclusion="$(printf '%s' "$dispatch_job" | jq -r '
(.steps[]? | select(.name == "Verify GHAS base/head CodeQL configuration identity") | .conclusion) // empty
')"
sarif_upload_conclusion="$(printf '%s' "$dispatch_job" | jq -r '
(.steps[]? | select(.name == "Preserve CodeQL SARIF evidence") | .conclusion) // empty
')"
case "$gate_conclusion" in
success)
echo "verdict=success" >>"$GITHUB_OUTPUT"
echo "Found completed CodeQL dispatch scan gate for ${LANGUAGE}: success."
exit 0
if [ "$ghas_identity_conclusion" = "success" ] &&
[ "$sarif_upload_conclusion" = "success" ]; then
echo "verdict=success" >>"$GITHUB_OUTPUT"
echo "Found completed CodeQL dispatch proof for ${LANGUAGE}: gate, GHAS identity, and SARIF evidence succeeded."
exit 0
fi
;;
failure|cancelled|skipped)
echo "verdict=failure" >>"$GITHUB_OUTPUT"
Expand All @@ -283,7 +305,7 @@ jobs:
fi

if [ "$RUN_ATTEMPT" != "1" ]; then
echo "::error::Exact CodeQL job was rerun without an authenticated terminal verdict."
echo "::error::Exact CodeQL job was rerun without an authenticated terminal verdict; GHAS identity and preserved SARIF are required for authenticated terminal proof."
exit 1
fi
echo "verdict=pending" >>"$GITHUB_OUTPUT"
Expand Down Expand Up @@ -356,6 +378,7 @@ jobs:
live_pr="$(gh api "repos/${TARGET_REPOSITORY}/pulls/${PR_NUMBER}")"
live_head="$(printf '%s' "$live_pr" | jq -r '.head.sha // empty')"
live_base="$(printf '%s' "$live_pr" | jq -r '.base.sha // empty')"
live_merge="$(printf '%s' "$live_pr" | jq -r '.merge_commit_sha // empty')"
live_base_ref="$(printf '%s' "$live_pr" | jq -r '.base.ref // empty')"
live_head_ref="$(printf '%s' "$live_pr" | jq -r '.head.ref // empty')"
live_state="$(printf '%s' "$live_pr" | jq -r 'if (.state | type) == "string" then .state else empty end')"
Expand All @@ -375,8 +398,10 @@ jobs:
echo "::error::CodeQL dispatch requires a canonical current run id."
exit 1
fi
if ! [[ "$live_base" =~ ^[0-9a-fA-F]{40}$ ]] || [ -z "$live_base_ref" ] || [ -z "$live_head_ref" ]; then
echo "::error::Could not validate live pull request base identity before CodeQL dispatch."
if ! [[ "$live_base" =~ ^[0-9a-fA-F]{40}$ ]] ||
! [[ "$live_merge" =~ ^[0-9a-fA-F]{40}$ ]] ||
[ -z "$live_base_ref" ] || [ -z "$live_head_ref" ]; then
echo "::error::Could not validate live pull request base/source identity before CodeQL dispatch."
exit 1
fi

Expand Down Expand Up @@ -413,13 +438,17 @@ jobs:
pending_matrix='[]'
while IFS= read -r entry; do
language="$(printf '%s' "$entry" | jq -r '.language // empty')"
verdict_state="$(printf '%s' "$statuses" | jq -r --arg ctx "codeql-dispatch/${language}" '
expected_context="codeql-dispatch/${language}/${live_base}"
expected_description="cwl1;h=${PR_HEAD_SHA};w=codeql-scan-dispatch;r=${REQUIRED_RUN_ID};s=${live_merge}"
verdict_state="$(printf '%s' "$statuses" | jq -r --arg ctx "$expected_context" --arg description "$expected_description" '
[
.[]
| select(.context == $ctx)
| select(.description == $description)
| select(
(.creator.login // "" | ascii_downcase) as $creator
| $creator == "opencode-agent" or $creator == "opencode-agent[bot]"
or $creator == "cwl-noema-review" or $creator == "cwl-noema-review[bot]"
)
]
| first // {} | .state // empty
Expand Down Expand Up @@ -477,5 +506,6 @@ jobs:
--argjson matrix "$pending_matrix" \
--arg required_run_id "$REQUIRED_RUN_ID" \
--argjson required_jobs "$required_jobs" \
'{event_type:"codeql-scan",client_payload:{target_repository:$target_repository,pr_number:$pr_number,pr_base_ref:$pr_base_ref,pr_base_sha:$pr_base_sha,pr_head_ref:$pr_head_ref,pr_head_sha:$pr_head_sha,matrix:$matrix,required_run_id:$required_run_id,required_jobs:$required_jobs}}' |
--arg producer_source_sha "$live_merge" \
'{event_type:"codeql-scan-v2",client_payload:{target_repository:$target_repository,pr_number:$pr_number,pr_base_ref:$pr_base_ref,pr_base_sha:$pr_base_sha,pr_head:{schema:"1",ref:$pr_head_ref,sha:$pr_head_sha},producer_source_sha:$producer_source_sha,matrix:$matrix,required_run_id:$required_run_id,required_jobs:$required_jobs}}' |
GH_TOKEN="$app_token" gh api -X POST repos/ContextualWisdomLab/.github/dispatches --input -
75 changes: 72 additions & 3 deletions .github/workflows/codeql-scan-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -589,7 +589,7 @@ jobs:

- name: Detect optional Noema analysis-read credential
id: noema_analysis_config
if: steps.gate.outcome == 'success'
if: always() && steps.live_metadata.outcome == 'success'
env:
TARGET_REPOSITORY: ${{ needs.validate-dispatch.outputs.target_repository }}
NOEMA_APP_CLIENT_ID: ${{ vars.NOEMA_GITHUB_APP_CLIENT_ID || '' }}
Expand Down Expand Up @@ -701,10 +701,23 @@ jobs:
if-no-files-found: error
retention-days: 7

- name: Mint target-scoped Noema CodeQL status token
id: noema_status_token
if: always() && steps.noema_analysis_config.outputs.available == 'true'
continue-on-error: true
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ vars.NOEMA_GITHUB_APP_CLIENT_ID }}
private-key: ${{ secrets.NOEMA_GITHUB_APP_PRIVATE_KEY }}
owner: ContextualWisdomLab
repositories: ${{ steps.noema_analysis_config.outputs.repository }}
permission-statuses: write

- name: Publish CodeQL dispatch status
id: publish_status
if: always() && steps.live_metadata.outcome == 'success'
env:
NOEMA_STATUS_TOKEN: ${{ steps.noema_status_token.outputs.token || '' }}
TARGET_APP_STATUS_TOKEN: ${{ steps.target_app_token.outputs.token || '' }}
GITHUB_STATUS_READ_TOKEN: ${{ github.token }}
PR_REVIEW_MERGE_STATUS_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || '' }}
Expand Down Expand Up @@ -783,6 +796,11 @@ jobs:
actual_creator="$(jq -r '.creator.login // "" | ascii_downcase' "$status_response" 2>/dev/null || true)"
creator_trusted=false
case "$token_label" in
noema-status-token)
case "$actual_creator" in
cwl-noema-review|cwl-noema-review\[bot\]) creator_trusted=true ;;
esac
;;
target-app-token|pr-review-merge-token|opencode-approve-token)
case "$actual_creator" in
opencode-agent|opencode-agent\[bot\]) creator_trusted=true ;;
Expand Down Expand Up @@ -815,6 +833,9 @@ jobs:
return 1
}

if post_status "noema-status-token" "${NOEMA_STATUS_TOKEN:-}"; then
exit 0
fi
if post_status "target-app-token" "$TARGET_APP_STATUS_TOKEN"; then
exit 0
fi
Expand Down Expand Up @@ -920,8 +941,34 @@ jobs:
echo "token=$app_token"
} >>"$GITHUB_OUTPUT"

- name: Resolve Noema settlement token configuration
id: noema_settlement_config
env:
NOEMA_APP_CLIENT_ID: ${{ vars.NOEMA_GITHUB_APP_CLIENT_ID || '' }}
NOEMA_APP_PRIVATE_KEY: ${{ secrets.NOEMA_GITHUB_APP_PRIVATE_KEY || '' }}
TARGET_REPOSITORY: ${{ needs.validate-dispatch.outputs.target_repository }}
run: |
set -euo pipefail
if [ -n "$NOEMA_APP_CLIENT_ID" ] && [ -n "$NOEMA_APP_PRIVATE_KEY" ]; then
printf 'repository=%s\n' "${TARGET_REPOSITORY#*/}" >>"$GITHUB_OUTPUT"
echo "available=true" >>"$GITHUB_OUTPUT"
fi

- name: Mint target-scoped Noema CodeQL settlement token
id: noema_settlement_token
if: steps.noema_settlement_config.outputs.available == 'true'
continue-on-error: true
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ vars.NOEMA_GITHUB_APP_CLIENT_ID }}
private-key: ${{ secrets.NOEMA_GITHUB_APP_PRIVATE_KEY }}
owner: ContextualWisdomLab
repositories: ${{ steps.noema_settlement_config.outputs.repository }}
permission-actions: write

- name: Settle exact CodeQL required run
env:
NOEMA_WAKE_TOKEN: ${{ steps.noema_settlement_token.outputs.token || '' }}
TARGET_APP_WAKE_TOKEN: ${{ steps.target_app_token.outputs.token || '' }}
PR_REVIEW_MERGE_WAKE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || '' }}
OPENCODE_APPROVE_WAKE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN || '' }}
Expand Down Expand Up @@ -960,7 +1007,8 @@ jobs:
}

github_api() {
run_api "target-app-token" "$TARGET_APP_WAKE_TOKEN" "$@" ||
run_api "noema-settlement-token" "${NOEMA_WAKE_TOKEN:-}" "$@" ||
run_api "target-app-token" "$TARGET_APP_WAKE_TOKEN" "$@" ||
run_api "pr-review-merge-token" "$PR_REVIEW_MERGE_WAKE_TOKEN" "$@" ||
run_api "opencode-approve-token" "$OPENCODE_APPROVE_WAKE_TOKEN" "$@" ||
run_api "github-token" "$GITHUB_WAKE_TOKEN" "$@"
Expand Down Expand Up @@ -1074,6 +1122,26 @@ jobs:
echo "::error::CodeQL settlement rejected incomplete handler gate or SARIF evidence for ${language}."
exit 1
fi
clean_gate_count="$(printf '%s' "$handler_jobs" | jq --arg name "$expected_job_name" --argjson attempt "$GITHUB_RUN_ATTEMPT" '
[.[] | select(
.name == $name
and .status == "completed"
and .run_attempt == $attempt
and ([.steps[]? | select(.name == "Enforce CodeQL Medium+ SARIF gate" and .conclusion == "success")] | length) == 1
)] | length
')"
ghas_identity_count="$(printf '%s' "$handler_jobs" | jq --arg name "$expected_job_name" --argjson attempt "$GITHUB_RUN_ATTEMPT" '
[.[] | select(
.name == $name
and .status == "completed"
and .run_attempt == $attempt
and ([.steps[]? | select(.name == "Verify GHAS base/head CodeQL configuration identity" and .conclusion == "success")] | length) == 1
)] | length
')"
if [ "$clean_gate_count" -eq 1 ] && [ "$ghas_identity_count" -ne 1 ]; then
echo "::error::CodeQL settlement rejected missing GHAS configuration identity proof for ${language}."
exit 1
fi
done < <(printf '%s' "$REQUIRED_JOBS" | jq -c '.[]')

case "$RERUN_MODE" in
Expand All @@ -1099,7 +1167,8 @@ jobs:
return 1
}

if post_wake "target-app-token" "$TARGET_APP_WAKE_TOKEN" ||
if post_wake "noema-settlement-token" "${NOEMA_WAKE_TOKEN:-}" ||
post_wake "target-app-token" "$TARGET_APP_WAKE_TOKEN" ||
post_wake "pr-review-merge-token" "$PR_REVIEW_MERGE_WAKE_TOKEN" ||
post_wake "opencode-approve-token" "$OPENCODE_APPROVE_WAKE_TOKEN" ||
post_wake "github-token" "$GITHUB_WAKE_TOKEN"; then
Expand Down
Loading
Loading