Skip to content

ops(required-workflows): enroll TEPP in OpenCode/Noema review and scheduler dispatch #795

Description

@seonghobae

Observed blocker

ContextualWisdomLab/TEPP is a new public organization repository covered by the documented ~ALL required-workflow policy, but its protected PR stack is not receiving the independent review identities needed to merge.

Current evidence:

Required investigation

  1. Verify the active organization ruleset targets TEPP's default branch and still references the current central required-workflow paths.
  2. Verify the OpenCode GitHub App and cwl-noema-review App are installed for TEPP with the intended repository-scoped permissions.
  3. Verify OPENCODE_REPOSITORY_DISPATCH_TARGETS contains the exact canonical repository name when targeted dispatch is used.
  4. Verify the organization sweep credential can read and mutate TEPP rather than classifying it as an unavailable repository.
  5. Trigger evidence-only current-head OpenCode and Noema review for TEPP Add Palette journal for profile repo #1 without branch update, auto-merge, direct merge, release, or protection bypass.
  6. Record the exact workflow run IDs, reviewer identities, head SHA binding, and concrete failure reason when any enrollment or credential prerequisite is absent.

Security constraints

  • Do not rename, duplicate, or repurpose existing reviewer credentials.
  • Do not use COPILOT_GITHUB_TOKEN.
  • Do not synthesize or self-submit approval.
  • Do not weaken the required independent non-author approval rule.
  • Keep model execution, reviewer identity, and repository mutation within the existing central trust boundaries.
  • Use NVIDIA_NIM_API_KEY only where the established review workflow already permits it.

Acceptance

TEPP #1 receives exact-current-head OpenCode and independent Noema verdicts through the protected central workflow, and the scheduler publishes a concrete merge decision without administrative bypass. The same enrollment must work for stacked #3 and #4 after their base order is satisfied.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions