Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
c464ebe
test(automation): add hourly NIM repair contract workflow
seonghobae Aug 5, 2026
2de9a0e
test(automation): require hourly bounded repair cadence
seonghobae Aug 5, 2026
8dbbe58
test(automation): require immutable scheduler source
seonghobae Aug 5, 2026
b02b4c9
test(automation): require NVIDIA NIM-only autofix boundary
seonghobae Aug 5, 2026
dcbe70f
fix(automation): enforce hourly NVIDIA NIM review repair
seonghobae Aug 5, 2026
2349543
docs(automation): record hourly NIM repair boundary
seonghobae Aug 5, 2026
63b5022
docs(changelog): record hourly NVIDIA NIM repair loop
seonghobae Aug 5, 2026
fa3b338
test(automation): require hourly clearfolio target by default
seonghobae Aug 5, 2026
41f2e2a
fix(automation): keep hourly scheduler target modular
seonghobae Aug 5, 2026
d10b57e
fix(automation): default hourly repair target to clearfolio
seonghobae Aug 5, 2026
f2eb154
test(automation): require modular clearfolio hourly caller
seonghobae Aug 5, 2026
f5836e4
refactor(automation): keep scheduler reusable behind product caller
seonghobae Aug 5, 2026
2daf2da
feat(automation): schedule clearfolio review repair hourly
seonghobae Aug 5, 2026
c8891d4
test(automation): cover active clearfolio scheduler caller
seonghobae Aug 5, 2026
112fd51
docs(automation): define modular clearfolio hourly caller
seonghobae Aug 5, 2026
c590e55
docs(changelog): record modular clearfolio heartbeat
seonghobae Aug 5, 2026
90074e6
test(automation): expose conflict autofix scope gap
seonghobae Aug 5, 2026
08ff6e0
docs(doctoring): record clearfolio scheduler caller boundary
seonghobae Aug 5, 2026
bc16ced
test(automation): track clearfolio caller doctoring
seonghobae Aug 5, 2026
94df8e3
test(automation): align hourly cadence with modular caller
seonghobae Aug 5, 2026
9512f8c
fix(automation): add conflict repair scope verifier
seonghobae Aug 5, 2026
0c3bf4c
test(automation): require job-scoped caller permissions
seonghobae Aug 5, 2026
c61083c
fix(automation): scope caller writes to scheduler job
seonghobae Aug 5, 2026
d441c36
test(automation): require conflict scope quality gate
seonghobae Aug 5, 2026
33e68f4
docs(automation): record job-scoped caller authority
seonghobae Aug 5, 2026
33fd551
docs(automation): define job-local scheduler permissions
seonghobae Aug 5, 2026
f2d58b7
ci(automation): repair conflict scope once
seonghobae Aug 5, 2026
f1b0ac4
refactor(automation): remove unreachable path bound branch
seonghobae Aug 5, 2026
c9dd236
test(automation): preserve conflict-scope red evidence
seonghobae Aug 5, 2026
8bb2e36
refactor(automation): remove unreachable JSON key branch
seonghobae Aug 5, 2026
ec40296
test(automation): complete conflict scope branch evidence
seonghobae Aug 5, 2026
0c40cbf
ci(automation): stage deterministic PR 782 repair helper
seonghobae Aug 5, 2026
4f036e4
ci(automation): repair PR 782 finalizer workflow
seonghobae Aug 5, 2026
f205cea
fix(automation): align one-shot conflict repair with final contract
seonghobae Aug 5, 2026
406d1f5
chore(ci): trigger bounded PR 782 repair
seonghobae Aug 5, 2026
65f7672
ci(automation): trigger verified PR 782 conflict-scope finalizer
seonghobae Aug 5, 2026
29d8bd5
ci: retrigger exact-head conflict-scope repair
seonghobae Aug 5, 2026
7316c5c
ci(automation): trigger exact-head conflict-scope repair
seonghobae Aug 5, 2026
a9a235a
ci(automation): finalize conflict scope repair exactly once
seonghobae Aug 5, 2026
aae2abf
ci(automation): retrigger bounded conflict-scope repair
seonghobae Aug 5, 2026
0c386d4
ci(automation): finalize PR 782 from branch push
seonghobae Aug 5, 2026
60f8cf4
ci(automation): finalize PR 782 on reopen
seonghobae Aug 5, 2026
31c2ed3
ci(automation): export exact PR 782 source
seonghobae Aug 5, 2026
548f382
ci(automation): harden conflict-scope finalizer
seonghobae Aug 5, 2026
25658c6
ci(automation): retrigger permanent conflict-scope repair
seonghobae Aug 5, 2026
ff9c94a
ci: finalize PR 782 conflict scope once
seonghobae Aug 5, 2026
5fd3ad0
test(automation): stage verified conflict-scope repair
seonghobae Aug 5, 2026
df61585
ci: apply verified conflict-scope repair
seonghobae Aug 5, 2026
0df85d2
ci(automation): apply verified PR 782 source artifact
seonghobae Aug 5, 2026
045d0e9
ci(automation): apply reviewed PR 782 conflict-scope repair
seonghobae Aug 5, 2026
5a919fb
ci(automation): retry reviewed PR 782 conflict-scope repair
seonghobae Aug 5, 2026
2977e0c
fix(automation): enforce conflict repair write scope
github-actions[bot] Aug 5, 2026
cd5d00c
chore(automation): remove completed PR 782 helpers
seonghobae Aug 5, 2026
a37e4a9
ci(review): publish PR 782 repair with workflow-capable token
seonghobae Aug 5, 2026
402caf2
chore(automation): remove verified PR 782 publisher
seonghobae Aug 5, 2026
b86cae4
ci: finalize PR 782 path canonicalization
seonghobae Aug 5, 2026
a1fe503
fix(automation): reject alternate conflict path spellings
github-actions[bot] Aug 5, 2026
4d69c58
ci: remove completed PR 782 repair workflow
seonghobae Aug 5, 2026
2f16cca
fix(automation): keep Clearfolio caller schedule-only
seonghobae Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .github/workflows/clearfolio-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Clearfolio Hourly Review Repair

on:
schedule:
# Offset the heartbeat from minute zero to reduce shared-runner congestion.
- cron: "23 * * * *"

concurrency:
group: clearfolio-hourly-review-repair
cancel-in-progress: true

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
actions: write
contents: read
issues: write
pull-requests: read
statuses: read
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/clearfolio
base_branch: main
max_prs: "50"
max_dispatches: "1"
retry_hours: "1"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
83 changes: 83 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
name: Hourly NVIDIA NIM Review Repair

on:
pull_request:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
- .github/workflows/pr-review-autofix.yml
- .github/workflows/clearfolio-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_fix_hourly_contract.py
- tests/test_pr_review_fix_scheduler_source_pin.py
- tests/test_pr_review_autofix_nvidia_nim_contract.py
- docs/automation/hourly-review-repair.md
- docs/doctoring/clearfolio-hourly-review-caller.md
- docs/doctoring/hourly-nvidia-nim-autofix.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
- .github/workflows/pr-review-autofix.yml
- .github/workflows/clearfolio-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_fix_hourly_contract.py
- tests/test_pr_review_fix_scheduler_source_pin.py
- tests/test_pr_review_autofix_nvidia_nim_contract.py
- docs/automation/hourly-review-repair.md
- docs/doctoring/clearfolio-hourly-review-caller.md
- docs/doctoring/hourly-nvidia-nim-autofix.md

permissions:
contents: read

concurrency:
group: hourly-nvidia-nim-review-repair-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
contract:
name: Hourly cadence, immutable source, NIM credential, and conflict scope
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit
- name: Checkout exact source revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install hash-locked test tooling
run: >-
python -m pip install --disable-pip-version-check --require-hashes
-r requirements-opencode-review-ci-hashes.txt
- name: Verify hourly scheduler and NVIDIA NIM autofix contracts
run: |
set -euo pipefail
python -m pytest -q \
tests/test_pr_review_conflict_scope.py \
tests/test_pr_review_fix_hourly_contract.py \
tests/test_pr_review_fix_scheduler_source_pin.py \
tests/test_pr_review_autofix_nvidia_nim_contract.py \
--cov=scripts.ci.pr_review_conflict_scope \
--cov-branch \
--cov-fail-under=100
python -m interrogate \
--fail-under 100 \
scripts/ci/pr_review_conflict_scope.py
python -m compileall -q \
scripts/ci/pr_review_conflict_scope.py \
tests/test_pr_review_conflict_scope.py \
tests/test_pr_review_fix_hourly_contract.py \
tests/test_pr_review_fix_scheduler_source_pin.py \
tests/test_pr_review_autofix_nvidia_nim_contract.py
git diff --check
84 changes: 50 additions & 34 deletions .github/workflows/pr-review-autofix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ jobs:
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
repository: ContextualWisdomLab/.github
ref: ${{ github.sha }}
fetch-depth: 1
persist-credentials: false
path: trusted-autofix-source
Expand Down Expand Up @@ -231,9 +232,9 @@ jobs:
EOF
jq -n --arg workspace "$TARGET_WORKSPACE" '{
"$schema": "https://opencode.ai/config.json",
"model": "github-models/openai/gpt-5",
"small_model": "github-models/deepseek/deepseek-v3-0324",
"enabled_providers": ["github-models"],
"model": "nvidia-nim/mistralai/mistral-nemotron",
"small_model": "nvidia-nim/nvidia/nemotron-3-nano-30b-a3b",
"enabled_providers": ["nvidia-nim"],
"permission": {
"edit": "allow",
"bash": "deny",
Expand All @@ -242,10 +243,13 @@ jobs:
"glob": "allow",
"list": "allow",
"task": "deny",
"skill": "deny",
"question": "deny",
"webfetch": "deny",
"websearch": "deny",
"lsp": "deny",
"external_directory": "deny"
"external_directory": "deny",
"doom_loop": "deny"
},
"agent": {
"ci-autofix": {
Expand All @@ -261,45 +265,40 @@ jobs:
"glob": "allow",
"list": "allow",
"task": "deny",
"skill": "deny",
"question": "deny",
"webfetch": "deny",
"websearch": "deny",
"lsp": "deny",
"external_directory": "deny"
"external_directory": "deny",
"doom_loop": "deny"
}
}
},
"provider": {
"github-models": {
"nvidia-nim": {
"npm": "@ai-sdk/openai-compatible",
"name": "GitHub Models",
"name": "NVIDIA NIM",
"options": {
"baseURL": "https://models.github.ai/inference",
"apiKey": "{env:STRIX_GITHUB_MODELS_TOKEN}"
"baseURL": "https://integrate.api.nvidia.com/v1",
"apiKey": "{env:NVIDIA_API_KEY}"
},
"models": {
"openai/gpt-5": {
"name": "OpenAI GPT-5",
"mistralai/mistral-nemotron": {
"name": "Mistral Nemotron",
"tool_call": true,
"reasoning": true,
"options": {
"reasoningEffort": "high"
},
"variants": {
"high": {
"reasoningEffort": "high"
}
},
"limit": {
"context": 200000,
"output": 100000
"context": 128000,
"output": 4096
}
},
"deepseek/deepseek-v3-0324": {
"name": "DeepSeek V3 0324",
"nvidia/nemotron-3-nano-30b-a3b": {
"name": "Nemotron 3 Nano 30B A3B",
"tool_call": true,
"reasoning": true,
"limit": {
"context": 128000,
"output": 4096
"output": 32768
}
}
}
Expand All @@ -310,16 +309,18 @@ jobs:
- name: Run OpenCode review autofix
if: env.RESOLVE_CONFLICT != 'true'
env:
STRIX_GITHUB_MODELS_TOKEN: ${{ secrets.STRIX_GITHUB_MODELS_TOKEN || github.token }}
GITHUB_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN || steps.target_app_token.outputs.token || github.token }}
MODEL: github-models/openai/gpt-5
USE_GITHUB_TOKEN: "true"
NVIDIA_API_KEY: ${{ secrets.NVIDIA_NIM_API_KEY }}
MODEL: nvidia-nim/mistralai/mistral-nemotron
SHARE: "false"
NPM_CONFIG_IGNORE_SCRIPTS: "true"
NO_COLOR: "1"
OPENCODE_AUTOFIX_WORKDIR: ${{ runner.temp }}/opencode-autofix-project
run: |
set -euo pipefail
if [ -z "${NVIDIA_API_KEY:-}" ]; then
echo "::error::NVIDIA_NIM_API_KEY is required for scheduled OpenCode autofix."
exit 1
fi
prompt_file="${RUNNER_TEMP}/opencode-autofix-prompt.md"
allowed_paths_context="$(
awk '
Expand Down Expand Up @@ -374,7 +375,8 @@ jobs:
}
trap restore_workspace_config EXIT
cd "$TARGET_WORKSPACE"
timeout 18000 opencode run "$(cat "$prompt_file")" \
env -u GITHUB_TOKEN -u GH_TOKEN -u ACTIONS_ID_TOKEN_REQUEST_TOKEN -u ACTIONS_ID_TOKEN_REQUEST_URL \
timeout 18000 opencode run "$(cat "$prompt_file")" \
--pure \
--agent ci-autofix \
--model "$MODEL" \
Expand Down Expand Up @@ -446,17 +448,20 @@ jobs:
- name: Merge base branch and resolve conflicts with OpenCode
if: env.RESOLVE_CONFLICT == 'true'
env:
STRIX_GITHUB_MODELS_TOKEN: ${{ secrets.STRIX_GITHUB_MODELS_TOKEN || github.token }}
NVIDIA_API_KEY: ${{ secrets.NVIDIA_NIM_API_KEY }}
GITHUB_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN || steps.target_app_token.outputs.token || github.token }}
GH_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN || steps.target_app_token.outputs.token || github.token }}
MODEL: github-models/openai/gpt-5
USE_GITHUB_TOKEN: "true"
MODEL: nvidia-nim/mistralai/mistral-nemotron
SHARE: "false"
NPM_CONFIG_IGNORE_SCRIPTS: "true"
NO_COLOR: "1"
OPENCODE_AUTOFIX_WORKDIR: ${{ runner.temp }}/opencode-autofix-project
run: |
set -euo pipefail
if [ -z "${NVIDIA_API_KEY:-}" ]; then
echo "::error::NVIDIA_NIM_API_KEY is required for scheduled OpenCode autofix."
exit 1
fi
cd "$TARGET_WORKSPACE"

# Merge the base branch into the detached head. A clean merge stays
Expand Down Expand Up @@ -486,6 +491,12 @@ jobs:
fi

if [ -n "$conflicted_files" ]; then
conflicted_paths_file="${RUNNER_TEMP}/opencode-conflicted-files.zlist"
conflict_scope_snapshot="${RUNNER_TEMP}/opencode-conflict-workspace-before.json"
git diff --name-only -z --diff-filter=U >"$conflicted_paths_file"
python3 "$GITHUB_WORKSPACE/trusted-autofix-source/scripts/ci/pr_review_conflict_scope.py" snapshot \
--root "$TARGET_WORKSPACE" \
--output "$conflict_scope_snapshot"
prompt_file="${RUNNER_TEMP}/opencode-conflict-prompt.md"
cat >"$prompt_file" <<EOF
Resolve the in-progress git merge conflict for PR #${PR_NUMBER} in ${TARGET_WORKSPACE}.
Expand Down Expand Up @@ -516,13 +527,18 @@ jobs:
fi
}
trap restore_workspace_config EXIT
timeout 18000 opencode run "$(cat "$prompt_file")" \
env -u GITHUB_TOKEN -u GH_TOKEN -u ACTIONS_ID_TOKEN_REQUEST_TOKEN -u ACTIONS_ID_TOKEN_REQUEST_URL \
timeout 18000 opencode run "$(cat "$prompt_file")" \
--pure \
--agent ci-autofix \
--model "$MODEL" \
--title "PR #${PR_NUMBER} merge conflict resolution"
restore_workspace_config
trap - EXIT
python3 "$GITHUB_WORKSPACE/trusted-autofix-source/scripts/ci/pr_review_conflict_scope.py" verify \
--root "$TARGET_WORKSPACE" \
--snapshot "$conflict_scope_snapshot" \
--allowed-paths "$conflicted_paths_file"
fi

# Fail closed: never push unresolved conflict markers.
Expand Down
Loading
Loading