Uh oh!
There was an error while loading. Please reload this page.
fix(governance): preserve proposal branch create transition - #1176
fix(governance): preserve proposal branch create transition#1176seonghobae wants to merge 34 commits into
Conversation
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📝 WalkthroughWalkthroughChanges에이전트 멘션 동시성
중앙 required-workflow 적용 범위
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk:🟡 Moderate · up to This PR expands central governance reviews to stacked branches, but its validation currently permits malformed branch-scope configurations that could allow required review coverage to be missed without detection. The audit contract and regression tests should be tightened before merging. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
commented
Aug 20, 2026
Current-head validation at
The full central suite had prior 100% evidence on the unchanged main source; this PR adds only the scoped audit/docs/ADR/test contract. Hosted current-head Checks and two qualifying independent approvals remain required; no bypass or self-approval. |
seonghobae
commented
Aug 20, 2026
Successor current-head validation at
The documentation-only successor preserves the implementation proof; stale predecessor-head review evidence does not count. A fresh exact-head independent review and current hosted Checks remain required before merge. |
seonghobae
commented
Aug 20, 2026
Exact current head is now |
seonghobae
commented
Aug 20, 2026
Current-head validation for bc2c93a: verified the live organization ruleset 18156473 is active with ref_name.include=[~ALL], and the PR aligns the audit code, regression fixture, ADR, and operator rollout ledger with stacked pull-request coverage. Passed: 16 central ruleset audit tests, Ruff, compileall, and git diff --check. Please review this exact head; merge remains gated on an independent non-author approval and terminal protected checks. |
seonghobae
commented
Aug 20, 2026
@opencode-agent Please review the current PR head bc2c93a. Verify the live ruleset alignment, stacked-PR scope audit, changed-file evidence, current mergeability, and required checks. Do not approve a stale head. |
seonghobae
commented
Aug 20, 2026
@opencode-agent review exact current HEAD bc2c93a. Inspect the complete diff, validate security and regression behavior, and publish only evidence bound to this SHA. Do not transfer predecessor approval, modify the branch, or merge. |
seonghobae
commented
Aug 20, 2026
@opencode-agent please review exact current HEAD |
seonghobae
commented
Aug 20, 2026
@cwl-noema-review please independently review exact current HEAD |
seonghobae
commented
Aug 20, 2026
Reproduced and fixed the central router Check failure at exact HEAD |
seonghobae
commented
Aug 20, 2026
@cwl-noema-review independently re-review exact current HEAD |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
seonghobae
commented
Aug 20, 2026
Exact-head causal repair evidence for
Hosted exact-head workflows and independent formal review remain separate non-passing gates until terminal evidence exists. |
seonghobae
commented
Aug 20, 2026
Current-head validation for |
seonghobae
commented
Aug 20, 2026
@opencode-agent review\nHead SHA: aa63517\nReview current HEAD only; check ruleset scope, stacked-PR required workflows, workflow permissions, and all changed tests/docs. Re-run after any push. |
seonghobae
commented
Aug 20, 2026
Current-head validation for |
seonghobae
commented
Aug 20, 2026
@opencode-agent review\nHead SHA: aa63517\nReview this exact head only, including least-privilege permissions, repository-dispatch authorization, and all changed queue/idempotency contracts. Re-run after any push. |
seonghobae
commented
Aug 20, 2026
Exact-head verification for the stacked central workflow governance change. Current pushed head: Root cause fixed: GitHub Actions rejects the unsupported Verified at this exact head:
@opencode-agent please perform the independent formal review for current head |
seonghobae
commented
Aug 20, 2026
Correction to the previous evidence comment: the exact pushed/current PR head is |
…ked-pr-central-required-workflows
seonghobae
commented
Aug 20, 2026
Queued @opencode-agent for PR #1176 at head |
seonghobae
commented
Aug 20, 2026
Queued @cwl-noema-review for PR #1176 at head |
Caution Review failedAn error occurred during the review process. Please try again later. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough중앙 required-workflow 규칙셋 감사가 기본 브랜치 전용 ref 범위와 비어 있는 제외 목록을 확인합니다. 워크플로 규칙의 Changes중앙 required-workflow 감사 검증
Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk:🟡 Moderate · up to The change is intended to restore proposal-branch creation without weakening protected-main governance, but it is not merge-ready because authoritative security results for the exact commit and required independent approvals are still missing. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
commented
Aug 22, 2026
Fresh ScopeWeave consumer-path refetch found the central owner repair itself needs stack reconciliation before it can unblock leaf writes. Exact current central state: protected |
seonghobae
commented
Aug 23, 2026
@opencode-agent please perform a fresh formal review of exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
49f6988795262194e4eda8b3ea7319b7b39c4e77. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32638743224/job/97192405871)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32638743224/job/97192405871)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["CI script: audit_central_required_workflows.py"]
S1 --> I1["review and security gate shell path"]
I1 --> R1["Review risk: CI script: audit_central_required_workflows.py"]
R1 --> V1["bash -n plus Strix self-test"]
Evidence --> S2["Test: test_central_required_workflow_ruleset_audit.py"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R2 --> V2["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage Decision
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["CI script: audit_central_required_workflows.py"]
S1 --> I1["review and security gate shell path"]
I1 --> R1["Review risk: CI script: audit_central_required_workflows.py"]
R1 --> V1["bash -n plus Strix self-test"]
Evidence --> S2["Test: test_central_required_workflow_ruleset_audit.py"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R2 --> V2["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
49f6988795262194e4eda8b3ea7319b7b39c4e77. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32638743224/job/97192405871)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32638743224/job/97192405871)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["CI script: audit_central_required_workflows.py"]
S1 --> I1["review and security gate shell path"]
I1 --> R1["Review risk: CI script: audit_central_required_workflows.py"]
R1 --> V1["bash -n plus Strix self-test"]
Evidence --> S2["Test: test_central_required_workflow_ruleset_audit.py"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R2 --> V2["targeted test run"]
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
seonghobae
commented
Aug 24, 2026
Exact-head check RCA: Strix run 32691651686 produced no vulnerability report artifact and failed after the configured fallback returned HTTP 404. The gate correctly treats this as provider/backend infrastructure, not a source finding. Revalidate after provider remediation; do not weaken the security gate. |
seonghobae
commented
Aug 24, 2026
@opencode-agent review Please submit a substantive formal Reviews API verdict for exact current head |
seonghobae
commented
Aug 24, 2026
@opencode-agent review Please publish an independent substantive formal Reviews API verdict for exact current head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
55a6a796d453ca4718859889fbbd4b416c20ebf1. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32720645174/job/97411134879)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32720645174/job/97411134879)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["CI script: audit_central_required_workflows.py"]
S1 --> I1["review and security gate shell path"]
I1 --> R1["Review risk: CI script: audit_central_required_workflows.py"]
R1 --> V1["bash -n plus Strix self-test"]
Evidence --> S2["Test: test_central_required_workflow_ruleset_audit.py"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R2 --> V2["targeted test run"]
seonghobae
commented
Aug 25, 2026
Owner-path refresh for the ScopeWeave #523 governance dependency: current PR head is |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head.Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence.Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.Result: REQUEST_CHANGES
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head27a686beeefc5fa8d8093021eb835664b78893c1.Head SHA:
27a686beeefc5fa8d8093021eb835664b78893c1Workflow run: 32825666061
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["CI script: audit_central_required_workflows.py"]
S1 --> I1["review and security gate shell path"]
I1 --> R1["Review risk: CI script: audit_central_required_workflows.py"]
R1 --> V1["bash -n plus Strix self-test"]
Evidence --> S2["Test: test_central_required_workflow_ruleset_audit.py"]
S2 --> I2["regression suite"]
I2 --> R2["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R2 --> V2["targeted test run"]
seonghobae
commented
Aug 25, 2026
Protected-main convergence and exact-tree verification (2026-08-26)
The new exact-head hosted workflows are queued; queued/skipped evidence is non-passing. The live organization-ruleset payload could not be freshly fetched through the available connector in this invocation, so prior live scope evidence is not promoted to a fresh acceptance claim. Acceptance still requires terminal exact-head evidence, independent current-head formal review, protected-main integration, and a no-bypass ScopeWeave proposal-branch create/update canary. No consumer source or refs were changed. |
Current protected-main synchronization (2026-08-25)
27a686beeefc5fa8d8093021eb835664b78893c1.main@8fd471a31399a914d9cb22a840f4a4c68e010ea6.f81b71594bdc7e3dc090669b14f719c99959a300exactly matched an independent localgit merge-tree --write-treeresult.scripts/ci/audit_central_required_workflows.pyandtests/test_central_required_workflow_ruleset_audit.py.git diff --checkpass.CHANGES_REQUESTEDreviews belong to predecessor heads.Decision:
WAIT_FOR_EXACT_HEAD_SECURITY_PROVENANCE_AND_INDEPENDENT_FORMAL_REVIEW.Buyer-visible gap
ScopeWeave and independent canaries reproduced proposal-branch creation/update failures while organization ruleset
18156473targeted~ALLand enforced required workflows during ref creation. That made the normal pull-request transition impossible before the proposal ref could exist.Refs #1200.
Change
ref_name.include=["~DEFAULT_BRANCH"],ref_name.exclude=[];~ALL, mixed scope, branch globs, string-shaped includes, and exclusions;workflows.parameters.do_not_enforce_on_create=true;No consumer source or protected branch was changed.
Test-first evidence
The source-relevant lineage remains:
~ALLand missing create-transition validation;Current hosted evidence
All nine commit-associated workflow runs are terminal GitHub-success: OSV, Secret Scan, SBOM, Scorecard, Security Scan, SAST Semgrep, Python Security, CodeQL, and the intentionally skipped repair workflow.
These labels are not promoted to complete exact-head security evidence:
32815655119/97703246596scanned synthetic merge9cb84a994d9a6ab6f50aa043487f2d0263bb7c5e, not submitted head27a686….32815655079/97703246321scanned the same synthetic merge.Live acceptance state
Ruleset
18156473is active with exact default-branch scope, no exclusions, anddo_not_enforce_on_create=true. After reviewed protected-main integration, acceptance still requires a fresh no-bypass ScopeWeave proposal-branch create/update canary and regenerated exact-head #523 evidence.Do not merge until #1222 supplies authoritative exact-head SAST/Trivy evidence for this unchanged head (or a descendant), all other required evidence remains terminal-passing, and live governance receives the required independent exact-head formal approvals.
Summary by CodeRabbit