fix(ci): pin review sidecar to merged 429 recovery head - #2487
seonghobae wants to merge 1 commit into
Conversation
|
Warning Review limit reachedNext included review available in 15 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-head admission correction — Ready is review admission only. Fresh audit against base
This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed. |
Change
Pin the central review sidecar to contextual-orchestrator main
8e1f1a8bf3e96e56dc8fcc90ec777883a1d56ce6. That ancestry includes image request cooldown recovery (#1223), structured 429 recovery (#1251), and structured stage evidence (#1253). The previous pin was01bf92a3ec67a0e1f9b68978eb16b60301e985fd; itsrequirements.lockis byte-identical to the new pin's lock.This is an intermediate source-consumption step. The sidecar still clones source at runtime and still bootstraps provider keys. It does not satisfy the immutable released gateway and secrets-free consumer contract in #1759. Historical admin bypasses on the source PRs are not independent approval for this PR.
Verification
git diff --checkandbash -n scripts/ci/contextual_orchestrator_review_sidecar.shpassed.test_contextual_orchestrator_review_sidecar_contract.py,test_noema_orchestrator_workflow_contract.py,test_strix_contextual_orchestrator_contract.py).PYTHONPATH, the Python 3.12 launcher and gateway imports used by the sidecar succeeded (launcher-import-ok). The sidecar's embedded offline HTTP body-limit/forwarding probe also exited 0 against that exact CO source without provider egress. This does not prove live provider availability or hosted Noema behavior.Delivery gate
Require current-head security/quality checks and qualifying independent review. After protected merge, verify the central main pin and obtain hosted Noema or OpenCode exact-pin request evidence before calling this consumed. The release and remote gateway migration remain separate.