Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
4e4b99a
ci: stage fail-closed LLVM coverage repair
seonghobae Aug 4, 2026
c28a16f
ci: use bounded app token for workflow repair
seonghobae Aug 4, 2026
2cd3e13
ci(opencode-review): provision LLVM coverage tools
opencode-agent[bot] Aug 4, 2026
08e038d
chore: bootstrap coverage failure diagnostics repair
seonghobae Aug 4, 2026
657e8fe
chore: remove coverage diagnostics bootstrap workflow
seonghobae Aug 4, 2026
1c02958
fix(opencode-review): publish JavaScript lock failure evidence
seonghobae Aug 4, 2026
cb1ed50
fix(opencode-review): publish Python lock failure evidence
seonghobae Aug 4, 2026
b59d2bb
test(opencode-review): cover exact coverage setup diagnostics
seonghobae Aug 4, 2026
94bfa75
ci(opencode-review): verify coverage failure diagnostics
seonghobae Aug 4, 2026
2defa39
test(opencode-review): cover materializer branch contracts
seonghobae Aug 4, 2026
cad711b
ci(opencode-review): separate minimum-runtime and full-quality gates
seonghobae Aug 4, 2026
1fcb790
test(opencode-review): cover absent workspace manifest branch
seonghobae Aug 4, 2026
5bf0fdb
chore: bootstrap Strix security lock refresh
seonghobae Aug 4, 2026
16e438c
ci: run Strix lock refresh from same-repository PR
seonghobae Aug 4, 2026
9b273e0
fix(security): refresh vulnerable Strix dependencies
opencode-agent[bot] Aug 4, 2026
988e10f
ci: verify Strix security lock contract with diagnostics
seonghobae Aug 4, 2026
0165ed7
fix(strix): preserve complete support and Rust scopes (#753)
seonghobae Aug 5, 2026
575aa55
docs(doctoring): trace LLVM coverage toolchain decision
seonghobae Aug 5, 2026
3a31af0
fix(security): apply remediated Strix dependency floors
seonghobae Aug 5, 2026
6610317
ci: refresh PR 755 Strix lock from validated blob
seonghobae Aug 5, 2026
5495d08
fix(security): refresh remediated Strix hash lock
github-actions[bot] Aug 5, 2026
dc81bb8
ci(opencode-review): provision LLVM coverage tools (#755)
seonghobae Aug 5, 2026
c59dd43
fix(ci): align scheduled CodeQL action revision
seonghobae Aug 5, 2026
99ba682
ci: verify and repair early diagnostic redaction
seonghobae Aug 5, 2026
b1720b5
ci: repair early coverage diagnostic redaction
seonghobae Aug 5, 2026
30a40e3
ci: make PR759 redaction repair deterministic
seonghobae Aug 5, 2026
a2efb90
test(ci): reproduce mixed coverage credential leakage
seonghobae Aug 5, 2026
402743e
ci: run PR759 repair on inspectable exact-head event
seonghobae Aug 5, 2026
68f6ad0
test(ci): require mixed credential redaction in materializers
seonghobae Aug 5, 2026
ee42b1f
fix(ci): redact mixed credentials before key truncation
seonghobae Aug 5, 2026
8078137
ci: validate shared coverage sanitizer on exact heads
seonghobae Aug 5, 2026
79e109e
feat(ci): centralize redacted coverage failure envelopes
seonghobae Aug 5, 2026
badbb9a
chore(ci): remove completed PR 759 one-shot workflow
seonghobae Aug 5, 2026
3b61229
chore(ci): remove completed PR 759 repair workflow
seonghobae Aug 5, 2026
df5e5ea
ci: canonicalize PR 759 source repair
seonghobae Aug 5, 2026
8e4adcb
ci: verify shared redaction before diagnostic output
seonghobae Aug 5, 2026
f808953
chore(ci): remove completed PR 759 repair workflow
seonghobae Aug 5, 2026
2315fc0
chore(ci): remove obsolete PR 759 repair workflow
seonghobae Aug 5, 2026
67526be
ci: finalize PR 759 bounded diagnostics
seonghobae Aug 5, 2026
225c14e
test(opencode-review): repair shared diagnostics contract
seonghobae Aug 5, 2026
168b160
chore(ci): remove superseded PR 759 repair workflow
seonghobae Aug 5, 2026
6ae0932
chore(ci): remove obsolete PR 759 repair workflow
seonghobae Aug 5, 2026
66c1094
ci: run bounded PR 759 coverage summary repair
seonghobae Aug 5, 2026
c98fd59
ci: run canonical PR 759 repair
seonghobae Aug 5, 2026
6e4c2d4
fix(opencode-review): centralize redacted diagnostics
github-actions[bot] Aug 5, 2026
21420a9
chore(ci): remove completed PR 759 one-shot workflow
seonghobae Aug 5, 2026
206ab44
test(opencode-review): stage canonical diagnostics repair
seonghobae Aug 5, 2026
c60811f
chore(ci): remove completed PR 759 patch helper
seonghobae Aug 5, 2026
6120297
test(coverage): expose username-only URL userinfo leak
seonghobae Aug 5, 2026
b5a8597
fix(coverage): redact username-only URL userinfo
seonghobae Aug 5, 2026
e1d6e01
fix(strix): freeze source-directory scan boundary
seonghobae Aug 5, 2026
c9ecbe1
test(strix): reject source-directory traversal inputs
seonghobae Aug 5, 2026
c500762
docs(strix): record source-directory trust boundary
seonghobae Aug 5, 2026
76ac1cd
test(strix): reproduce standalone parent traversal
seonghobae Aug 5, 2026
4d076f6
fix(strix): reject standalone parent traversal
seonghobae Aug 5, 2026
71a695d
test(automation): require hourly NVIDIA NIM review repair
seonghobae Aug 5, 2026
71d1fc5
ci(automation): execute the hourly NIM repair contract
seonghobae Aug 5, 2026
1d70f78
fix(automation): run hourly review repair through NVIDIA NIM
seonghobae Aug 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -90,13 +90,13 @@ jobs:
ref: ${{ github.event.pull_request.head.sha }}

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
category: "/language:${{ matrix.language }}"
upload: false
Expand Down Expand Up @@ -197,13 +197,13 @@ jobs:
ref: ${{ format('refs/pull/{0}/merge', github.event.pull_request.number) }}

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
category: "/language:${{ matrix.language }}-merge"
upload: false
Expand Down
66 changes: 66 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
name: Hourly NVIDIA NIM Review Repair

on:
pull_request:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
- .github/workflows/pr-review-autofix.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- tests/test_pr_review_fix_hourly_contract.py
- tests/test_pr_review_fix_scheduler_source_pin.py
- tests/test_pr_review_autofix_nvidia_nim_contract.py
- docs/automation/hourly-review-repair.md
- docs/doctoring/hourly-nvidia-nim-autofix.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
- .github/workflows/pr-review-autofix.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- tests/test_pr_review_fix_hourly_contract.py
- tests/test_pr_review_fix_scheduler_source_pin.py
- tests/test_pr_review_autofix_nvidia_nim_contract.py
- docs/automation/hourly-review-repair.md
- docs/doctoring/hourly-nvidia-nim-autofix.md

permissions:
contents: read

concurrency:
group: hourly-nvidia-nim-review-repair-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
contract:
name: Hourly cadence, immutable source, and NIM credential boundary
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- name: Checkout exact source revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install hash-locked test tooling
run: >-
python -m pip install --disable-pip-version-check --require-hashes
-r requirements-opencode-review-ci-hashes.txt
- name: Verify hourly scheduler and NVIDIA NIM autofix contracts
run: |
set -euo pipefail
python -m pytest -q \
tests/test_pr_review_fix_hourly_contract.py \
tests/test_pr_review_fix_scheduler_source_pin.py \
tests/test_pr_review_autofix_nvidia_nim_contract.py
python -m compileall -q \
tests/test_pr_review_fix_hourly_contract.py \
tests/test_pr_review_fix_scheduler_source_pin.py \
tests/test_pr_review_autofix_nvidia_nim_contract.py
git diff --check
172 changes: 172 additions & 0 deletions .github/workflows/opencode-coverage-diagnostics-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,172 @@
name: OpenCode Coverage Diagnostics CI

on:
pull_request:
branches: [main]
paths:
- "scripts/ci/coverage_failure_summary.py"
- "scripts/ci/materialize_base_javascript_packages.py"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/sanitize_github_output_summary.py"
- "tests/test_materialize_base_javascript_packages.py"
- "tests/test_materialize_base_python_requirements.py"
- "tests/test_coverage_materializer_failure_diagnostics.py"
- "tests/test_sanitize_github_output_summary.py"
- "tests/test_strix_dependency_security_floor.py"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-strix-ci.txt"
- "requirements-strix-ci-hashes.txt"
- "pyproject.toml"
- ".github/workflows/opencode-coverage-diagnostics-ci.yml"
push:
branches: [main]
paths:
- "scripts/ci/coverage_failure_summary.py"
- "scripts/ci/materialize_base_javascript_packages.py"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/sanitize_github_output_summary.py"
- "tests/test_materialize_base_javascript_packages.py"
- "tests/test_materialize_base_python_requirements.py"
- "tests/test_coverage_materializer_failure_diagnostics.py"
- "tests/test_sanitize_github_output_summary.py"
- "tests/test_strix_dependency_security_floor.py"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-strix-ci.txt"
- "requirements-strix-ci-hashes.txt"
- "pyproject.toml"
- ".github/workflows/opencode-coverage-diagnostics-ci.yml"

concurrency:
group: opencode-coverage-diagnostics-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
minimum-python-contract:
name: Python 3.10 runtime contract
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up minimum supported Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.10"

- name: Compile production modules on Python 3.10
run: |
python -m compileall -q \
scripts/ci/coverage_failure_summary.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py

- name: Exercise exact failure evidence on Python 3.10
run: |
python - <<'PY'
import os
import pathlib
import tempfile

from scripts.ci import materialize_base_javascript_packages as javascript_materializer
from scripts.ci import materialize_base_python_requirements as python_materializer

with tempfile.TemporaryDirectory() as directory:
output = pathlib.Path(directory) / "github-output"
os.environ["GITHUB_OUTPUT"] = str(output)
exact_reason = (
"current-head npm lock package-lock.json package "
"apps/desktop/node_modules/@types/react-dom must pin a registry "
"tarball and SHA-512 integrity"
)
javascript_materializer._publish_coverage_failure_summary(
"Base JavaScript package lock materialization",
ValueError(exact_reason),
"Repair the lock and rerun coverage-evidence.",
)
python_materializer._publish_coverage_failure_summary(
"Base Python lock materialization",
OSError("fixture <unsafe>\nCWL_COVERAGE_SUMMARY_EOF"),
"Repair the trusted lock and rerun coverage-evidence.",
)
published = output.read_text(encoding="utf-8")
assert f"ValueError: {exact_reason}" in published
assert "OSError: fixture &lt;unsafe&gt; CWL_COVERAGE_SUMMARY_END" in published
assert published.count("coverage_summary<<CWL_COVERAGE_SUMMARY_EOF") == 2
PY

full-quality-gate:
name: Python 3.14 full quality gate
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up current stable Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.14"
cache: pip
cache-dependency-path: requirements-opencode-review-ci-hashes.txt

- name: Install hash-locked test tooling
run: >-
python -m pip install --disable-pip-version-check --require-hashes
-r requirements-opencode-review-ci-hashes.txt

- name: Run diagnostics and lock contracts with full branch coverage
run: |
python -m pytest \
tests/test_materialize_base_javascript_packages.py \
tests/test_materialize_base_python_requirements.py \
tests/test_coverage_materializer_failure_diagnostics.py \
tests/test_sanitize_github_output_summary.py \
tests/test_strix_dependency_security_floor.py \
--cov=scripts.ci.coverage_failure_summary \
--cov=scripts.ci.materialize_base_javascript_packages \
--cov=scripts.ci.materialize_base_python_requirements \
--cov=scripts.ci.sanitize_github_output_summary \
--cov-branch \
--cov-fail-under=100 \
-q

- name: Enforce complete production docstrings
run: |
python -m interrogate \
--fail-under 100 \
scripts/ci/coverage_failure_summary.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py

- name: Compile changed Python surfaces
run: |
python -m compileall -q \
scripts/ci/coverage_failure_summary.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py \
tests/test_coverage_materializer_failure_diagnostics.py \
tests/test_sanitize_github_output_summary.py \
tests/test_strix_dependency_security_floor.py
4 changes: 4 additions & 0 deletions .github/workflows/opencode-review-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -652,11 +652,15 @@ jobs:
r-base \
r-cran-covr \
r-cran-testthat \
llvm-19 \
rustc \
util-linux \
vulkan-tools \
xz-utils \
&& rm -rf /var/lib/apt/lists/*
ENV LLVM_COV=/usr/bin/llvm-cov-19
ENV LLVM_PROFDATA=/usr/bin/llvm-profdata-19
RUN test -x "$LLVM_COV" && test -x "$LLVM_PROFDATA"
RUN curl --proto '=https' --tlsv1.2 -fsSLo /tmp/node-linux-x64.tar.xz \
https://nodejs.org/dist/v24.18.0/node-v24.18.0-linux-x64.tar.xz \
&& echo '55aa7153f9d88f28d765fcdad5ae6945b5c0f98a36881703817e4c450fa76742 /tmp/node-linux-x64.tar.xz' | sha256sum -c - \
Expand Down
Loading
Loading