Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
5e0b6b1
fix(opencode): withhold approval on incomplete coverage evidence
seonghobae Sep 30, 2026
8cd0e18
test(ci): expose draft queue retirement gap
seonghobae Sep 30, 2026
fa7acfb
fix(ci): retire queued codeql-pr draft runs
seonghobae Sep 30, 2026
a7dff5c
fix(ci): retire queued sast-semgrep draft runs
seonghobae Sep 30, 2026
2ab271f
fix(ci): retire queued security-scan draft runs
seonghobae Sep 30, 2026
c091ee4
fix(ci): retire queued python-security draft runs
seonghobae Sep 30, 2026
c10f1c0
fix(ci): skip gitleaks entry on draft retirement
seonghobae Sep 30, 2026
3dbb0bc
test(ci): require live draft skip without event exemption
seonghobae Sep 30, 2026
415c2e7
docs(ci): record draft queue retirement
seonghobae Sep 30, 2026
f182312
docs(ci): explain draft queue retirement
seonghobae Sep 30, 2026
bf8acdc
ci: refresh checks on security prerequisite
seonghobae Sep 30, 2026
737fc6f
merge: carry central security and coverage owner into #2536
seonghobae Sep 30, 2026
3bc859c
fix(ci): fetch metadata evidence ancestry
seonghobae Sep 30, 2026
88143f9
docs(ci): record metadata ancestry RCA
seonghobae Sep 30, 2026
d76ab42
fix(security): refresh shared urllib3 locks
seonghobae Sep 30, 2026
be64c84
fix(security): pin patched PyJWT recursion release
seonghobae Sep 30, 2026
87ffafa
test(opencode): reject incomplete reused coverage evidence
seonghobae Sep 30, 2026
0bcded6
fix(opencode): bind reused approval to coverage decision
seonghobae Sep 30, 2026
43c78cc
test(opencode): refresh reviewed dispatch blob pin
seonghobae Sep 30, 2026
7771a2b
fix(opencode): fail closed on unmeasured approval reuse
seonghobae Sep 30, 2026
feb88e3
test(opencode): cover unmeasured approval CLI rejection
seonghobae Sep 30, 2026
18c886c
test(opencode): restore full coverage of approval rejection
seonghobae Sep 30, 2026
cf8fa36
chore(stack): integrate security owner into draft queue retirement
seonghobae Sep 30, 2026
76aa575
test(ci): align SAST draft admission contract
seonghobae Sep 30, 2026
ba55414
fix(opencode): honor latest exact-head review decision
seonghobae Sep 30, 2026
37ce2e4
fix(ci): restore queue-health credential fallback
seonghobae Sep 30, 2026
6a37e4c
fix(security): refresh review runtime locks
seonghobae Sep 30, 2026
0dacd79
merge: restack draft queue retirement on latest review authority
seonghobae Sep 30, 2026
8ea4750
fix(ci): skip merge scheduler runner on Draft conversion
seonghobae Sep 30, 2026
67c6892
fix(opencode): serialize exact-head dispatch admission
seonghobae Oct 1, 2026
8b4fdca
merge(ci): integrate current combined owner head
seonghobae Oct 1, 2026
bd05e83
merge(opencode): synchronize latest control-plane owner
seonghobae Oct 1, 2026
ba00ac0
fix(ci): diff agent quality against live base
seonghobae Oct 1, 2026
617212f
merge(ci): integrate shared security owner into live-base repair
seonghobae Oct 1, 2026
af088cc
fix(ci): refresh live base before diff gates
seonghobae Oct 1, 2026
5704440
fix(opencode): recheck receipt after receiver lease
seonghobae Oct 1, 2026
86ddef6
merge(opencode): synchronize current Maturin owner
seonghobae Oct 1, 2026
1a62357
fix(scheduler): prove stale-run retirement
seonghobae Oct 1, 2026
a44bbef
fix(scheduler): complete active-run inventory
seonghobae Oct 1, 2026
3a7d92e
fix(scheduler): retire review-event predecessors
seonghobae Oct 1, 2026
8951c2c
docs(evidence): bind final exact-suite count
seonghobae Oct 1, 2026
b66036e
fix(ci): stack live-base diff on canonical owner
seonghobae Oct 1, 2026
0bf08bb
fix(ci): admit stacked runtime quality owners
seonghobae Oct 1, 2026
ad79e58
fix(codeql): materialize draft consumer heads
seonghobae Oct 1, 2026
1fa31f5
fix(docs): restore complete product gap baseline
seonghobae Oct 1, 2026
8f6a870
merge: integrate shared security baseline prerequisite
seonghobae Oct 1, 2026
5deb2d7
fix(ci): stack live-base quality on queue owner
seonghobae Oct 1, 2026
db81de7
test(strix): align queue gate with lease admission
seonghobae Oct 1, 2026
5206633
merge: integrate #2546 Strix lease-contract gate repair
seonghobae Oct 1, 2026
f6dfbd8
merge(ci): reconcile CodeQL Draft event matrix
seonghobae Oct 1, 2026
59c9bcf
fix(sbom): preserve publication tree authority
seonghobae Oct 1, 2026
bd1a3d3
fix: admit exact-head Draft semantic reviews
seonghobae Oct 1, 2026
f79c8f2
fix(ci): retire stale central dispatch runs
seonghobae Oct 1, 2026
6eb1174
fix: preserve Draft-to-Ready review admission
seonghobae Oct 1, 2026
8b81426
fix: restore scheduler coverage guard
seonghobae Oct 1, 2026
a8bc588
merge: integrate current OpenCode admission owner
seonghobae Oct 1, 2026
3d2656b
docs(ci): correct stacked required-workflow scope
seonghobae Oct 1, 2026
0ba66af
merge: preserve runtime and SBOM publication owners
seonghobae Oct 1, 2026
1e2d753
fix(sbom): reject reverted owner history
seonghobae Oct 1, 2026
9143d6e
fix(codeql): preserve exact active dispatch
seonghobae Oct 1, 2026
c8d8e1f
merge: carry CodeQL admission repair into owner union
seonghobae Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 69 additions & 2 deletions .github/workflows/actions-queue-health.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ jobs:
permissions:
contents: read
actions: read
id-token: write
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
Expand All @@ -31,12 +32,78 @@ jobs:
with:
persist-credentials: false

- name: Exchange OpenCode app token for cross-repo reads
id: queue_read_app_token
env:
OIDC_AUDIENCE: opencode-github-action
OPENCODE_API_BASE_URL: https://api.opencode.ai
run: |
set -euo pipefail

mark_unavailable() {
echo "available=false" >>"$GITHUB_OUTPUT"
}

if [ -z "${ACTIONS_ID_TOKEN_REQUEST_TOKEN:-}" ] || [ -z "${ACTIONS_ID_TOKEN_REQUEST_URL:-}" ]; then
echo "OpenCode app token exchange unavailable: OIDC request environment is missing."
mark_unavailable
exit 0
fi

request_url="${ACTIONS_ID_TOKEN_REQUEST_URL}"
separator="&"
case "$request_url" in
*\?*) ;;
*) separator="?" ;;
esac

if ! oidc_response="$(
curl -fsS \
-H "Authorization: Bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${request_url}${separator}audience=${OIDC_AUDIENCE}"
)"; then
echo "OpenCode app token exchange unavailable: OIDC token request did not complete."
mark_unavailable
exit 0
fi

oidc_token="$(jq -r '.value // empty' <<<"$oidc_response")"
if [ -z "$oidc_token" ]; then
echo "OpenCode app token exchange unavailable: OIDC token response was empty."
mark_unavailable
exit 0
fi

if ! token_response="$(
curl -fsS \
-X POST \
-H "Authorization: Bearer ${oidc_token}" \
"${OPENCODE_API_BASE_URL}/exchange_github_app_token"
)"; then
echo "OpenCode app token exchange unavailable: app token request did not complete."
mark_unavailable
exit 0
fi

app_token="$(jq -r '.token // empty' <<<"$token_response")"
if [ -z "$app_token" ]; then
echo "OpenCode app token exchange unavailable: app token response was empty."
mark_unavailable
exit 0
fi

echo "::add-mask::$app_token"
{
echo "available=true"
echo "token=$app_token"
} >>"$GITHUB_OUTPUT"

- name: Collect read-only repository and runner evidence
env:
GH_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN }}
GH_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN || steps.queue_read_app_token.outputs.token }}
run: |
if [ -z "${GH_TOKEN:-}" ]; then
echo "::error::PR_REVIEW_MERGE_TOKEN or OPENCODE_APPROVE_TOKEN is required for cross-repository queue reads."
echo "::error::PR_REVIEW_MERGE_TOKEN, OPENCODE_APPROVE_TOKEN, or the exchanged OpenCode app token is required for cross-repository queue reads."
exit 1
fi
echo "::add-mask::$GH_TOKEN"
Expand Down
22 changes: 16 additions & 6 deletions .github/workflows/agent-review-runtime-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@ name: Agent Review Runtime Quality CI

on:
pull_request:
branches: [main]
paths:
- ".github/workflows/agent-review-runtime-quality-ci.yml"
- ".github/workflows/noema-review.yml"
Expand All @@ -22,6 +21,7 @@ on:
- "scripts/ci/ensure_rust_llvm19.sh"
- "tests/test_opencode_rust_coverage_toolchain_contract.py"
- "tests/test_rust_coverage_timeout_not_measured.py"
- "tests/test_coverage_incomplete_summary.py"
- "scripts/ci/resolve_base_rust_toolchain.py"
- "tests/test_resolve_base_rust_toolchain.py"
- "scripts/ci/place_maturin_extension.py"
Expand Down Expand Up @@ -166,10 +166,13 @@ jobs:
id: affected_suites
shell: bash --noprofile --norc -e -o pipefail {0}
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
BASE_REF: ${{ github.event.pull_request.base.ref }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
test "$(git rev-parse HEAD)" = "$HEAD_SHA"
git fetch --no-tags --prune origin "refs/heads/$BASE_REF:refs/remotes/origin/$BASE_REF"
change_base_sha="$(git merge-base "refs/remotes/origin/$BASE_REF" "$HEAD_SHA")"
test -n "$change_base_sha"
noema_suite=false
opencode_suite=false
strix_suite=false
Expand Down Expand Up @@ -215,6 +218,7 @@ jobs:
scripts/ci/ensure_rust_llvm19.sh|\
tests/test_opencode_rust_coverage_toolchain_contract.py|\
tests/test_rust_coverage_timeout_not_measured.py|\
tests/test_coverage_incomplete_summary.py|\
scripts/ci/resolve_base_rust_toolchain.py|\
tests/test_resolve_base_rust_toolchain.py|\
scripts/ci/place_maturin_extension.py|\
Expand Down Expand Up @@ -334,7 +338,7 @@ jobs:
exact_artifact_suite=true
;;
esac
done < <(git diff --name-only "$BASE_SHA...$HEAD_SHA")
done < <(git diff --name-only "$change_base_sha...$HEAD_SHA")

{
echo "noema=$noema_suite"
Expand Down Expand Up @@ -399,8 +403,8 @@ jobs:
if: steps.affected_suites.outputs.opencode == 'true'
run: |
set -euo pipefail
python -m pytest -q tests/test_opencode_rust_coverage_toolchain_contract.py tests/test_rust_coverage_timeout_not_measured.py tests/test_resolve_base_rust_toolchain.py tests/test_place_maturin_extension.py
python -m compileall -q tests/test_opencode_rust_coverage_toolchain_contract.py tests/test_resolve_base_rust_toolchain.py tests/test_place_maturin_extension.py
python -m pytest -q tests/test_opencode_rust_coverage_toolchain_contract.py tests/test_rust_coverage_timeout_not_measured.py tests/test_coverage_incomplete_summary.py tests/test_resolve_base_rust_toolchain.py tests/test_place_maturin_extension.py
python -m compileall -q tests/test_opencode_rust_coverage_toolchain_contract.py tests/test_coverage_incomplete_summary.py tests/test_resolve_base_rust_toolchain.py tests/test_place_maturin_extension.py

- name: Verify JavaScript materializer documentation contract
if: steps.affected_suites.outputs.opencode == 'true'
Expand Down Expand Up @@ -582,9 +586,15 @@ jobs:
tests/test_exact_artifact_quality_single_runner.py

- name: Verify consolidated workflow contract
env:
BASE_REF: ${{ github.event.pull_request.base.ref }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
python -m pytest -q tests/test_agent_review_runtime_quality_consolidation.py
python -m compileall -q tests/test_agent_review_runtime_quality_consolidation.py
git diff --check "${{ github.event.pull_request.base.sha }}...${{ github.event.pull_request.head.sha }}"
git fetch --no-tags --prune origin "refs/heads/$BASE_REF:refs/remotes/origin/$BASE_REF"
change_base_sha="$(git merge-base "refs/remotes/origin/$BASE_REF" "$HEAD_SHA")"
test -n "$change_base_sha"
git diff --check "$change_base_sha...$HEAD_SHA"
git diff --exit-code
64 changes: 58 additions & 6 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,16 +18,17 @@ name: CodeQL PR

on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review, closed]
types: [opened, synchronize, reopened, ready_for_review, converted_to_draft, closed]
# Do not restrict the base ref: the org required-workflow ruleset already
# scopes this to each repository's actual default branch via
# ref_name: ["~DEFAULT_BRANCH"], whatever it is named. A hardcoded
# [main, master, develop] list silently produced zero CodeQL checks for
# any repository with a different default branch name (confirmed live:
# a repository defaulting to gh-pages received every other required
# check but no CodeQL check at all) and would also block coverage for
# stacked PRs targeting a non-default feature branch, matching
# security-scan.yml's own "do not restrict the base ref" precedent.
# check but no CodeQL check at all). This does not widen ruleset 18156473:
# its default-ref scope must inject the required workflow first. A
# feature-base stacked PR gets this gate only where the workflow is run
# natively, or after retargeting to the repository default branch.

concurrency:
# NOT scoped by head SHA, unlike opencode-review.yml's group -- and that is
Expand Down Expand Up @@ -58,8 +59,11 @@ permissions:
jobs:
detect-languages:
name: Detect CodeQL languages
# Draft PRs get no runner; ready_for_review re-runs this on the same head.
if: (github.event.action != 'closed') && (github.event.pull_request.draft != true || github.event.action == 'converted_to_draft' || github.event.action == 'closed')
# Ruleset consumers do not receive unchanged-head Ready events, so their
# Draft heads materialize security evidence. The native owner saves its
# runner, while Draft conversion and close events only retire stale work
# through the per-PR concurrency group above.
if: github.event.action != 'closed' && github.event.action != 'converted_to_draft' && (github.event.pull_request.draft != true || github.event.pull_request.base.repo.full_name != 'ContextualWisdomLab/.github')
runs-on: ${{ fromJSON(github.workflow_ref == 'ContextualWisdomLab/.github/.github/workflows/codeql-pr.yml@refs/heads/main' && '{"group":"CWL central control","labels":["self-hosted","linux","x64"]}' || '"ubuntu-24.04"') }}
timeout-minutes: 5
permissions:
Expand Down Expand Up @@ -495,6 +499,54 @@ jobs:
exit 1
fi

# A later attempt of the same required run must preserve exact work
# already admitted by the protected central handler. Without this
# check, a missing terminal verdict makes every attempt redispatch;
# handler concurrency then replaces the durable queued run and sends
# the same work to the back of the scarce CodeQL queue.
expected_title="CodeQL Scan Dispatch ${TARGET_REPOSITORY}#${PR_NUMBER}@${live_head}/${live_base}/${REQUIRED_RUN_ID}/${live_merge}"
required_created_at="$(gh api "repos/${TARGET_REPOSITORY}/actions/runs/${REQUIRED_RUN_ID}" --jq .created_at)"
if ! [[ "$required_created_at" =~ ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}Z$ ]]; then
echo "::error::Could not validate required run creation time before CodeQL admission lookup."
exit 1
fi
dispatch_runs="$(
gh api --method GET --paginate \
-f per_page=100 \
-f event=repository_dispatch \
-f created=">=${required_created_at}" \
"repos/ContextualWisdomLab/.github/actions/workflows/codeql-scan-dispatch.yml/runs" |
jq -s .
)"
active_dispatch_id="$(printf '%s' "$dispatch_runs" | jq -r \
--arg title "$expected_title" \
--arg path ".github/workflows/codeql-scan-dispatch.yml" '
[
.[] | .workflow_runs[]?
| select(.path == $path)
| select(.event == "repository_dispatch")
| select(.display_title == $title or .name == $title)
| select(.status == "queued" or .status == "in_progress"
or .status == "waiting" or .status == "pending"
or .status == "requested")
| select(
(.actor.login // "" | ascii_downcase) as $actor
| $actor == "opencode-agent" or $actor == "opencode-agent[bot]"
)
| select(
(.triggering_actor.login // "" | ascii_downcase) as $trigger
| $trigger == "opencode-agent" or $trigger == "opencode-agent[bot]"
)
]
| first
| .id // empty
'
)"
if [[ "$active_dispatch_id" =~ ^[1-9][0-9]*$ ]]; then
echo "CodeQL admission deferred; preserving exact active dispatch ${active_dispatch_id}."
exit 0
fi

if [ -z "${ACTIONS_ID_TOKEN_REQUEST_TOKEN:-}" ] || [ -z "${ACTIONS_ID_TOKEN_REQUEST_URL:-}" ]; then
echo "::error::CodeQL scan dispatch requires GitHub OIDC."
exit 1
Expand Down
11 changes: 2 additions & 9 deletions .github/workflows/codeql-scan-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,21 +31,14 @@ on:
repository_dispatch:
types: [codeql-scan, codeql-scan-v2]

concurrency:
group: >-
codeql-scan-dispatch-${{
github.event.client_payload.target_repository || github.repository }}-${{
github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
validate-dispatch:
name: validate-dispatch
runs-on:
group: CWL central CodeQL
group: CWL central control
labels: [self-hosted, linux, x64]
timeout-minutes: 8
permissions:
Expand Down Expand Up @@ -866,7 +859,7 @@ jobs:
&& needs.scan.result != 'cancelled'
&& needs.scan.result != 'skipped'
runs-on:
group: CWL central CodeQL
group: CWL central control
labels: [self-hosted, linux, x64]
timeout-minutes: 8
permissions:
Expand Down
Loading
Loading