feat(automation): add hourly protected PR and OpenCode product loops - #271
feat(automation): add hourly protected PR and OpenCode product loops#271seonghobae wants to merge 37 commits into
Conversation
|
Warning Review limit reached
Next review available in: 13 seconds Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (6)
Comment |
|
@coderabbitai review @opencode-agent @cwl-noema-review Please independently review exact current head Treat both workflows as privileged supply-chain code. Verify immutable source/action pins, central review-agent secret inheritance without credential remapping, zero-open-PR backpressure across every paginated gate, non-cancelling single-flight behavior, OpenCode 1.18.13 archive checksum, NVIDIA-only model routing, blocked egress, disabled auto-update/plugins/model-fetch/LSP/project config, prompt-injection boundaries, exact key-disclosure scanning, file/diff/deletion/rename/symlink/mode protections, immutable patch/base/hash evidence, no repository-code execution in the credentialed model step, complete credential-free Maven and buyer-readiness verification, Maintainer App least-privilege publication only after revalidation, draft-only PR creation, and absence of self-approval, auto-merge, release, publish, or deploy behavior. Test-first evidence is RED |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== HEAD =='
git rev-parse HEAD
echo '== Changed files against first parent =='
git diff-tree --no-commit-id --name-status -r HEAD
echo '== Candidate files =='
fd -HI -t f -E .git '\.(ya?ml|md|py|sh)$' . | sort
echo '== Workflow structure =='
if [ -d .github/workflows ]; then
for f in .github/workflows/*; do
[ -f "$f" ] || continue
echo "--- $f"
sed -n '1,360p' "$f"
done
fi
echo '== Documentation and test references =='
rg -n -C 3 --glob '*.{md,py,yml,yaml,sh}' \
'OpenCode|NVIDIA_NIM_API_KEY|CLEARFOLIO_MAINTAINER|open PR|pull.?request|concurrency|mvn|pytest|publish|draft|auto-merge|workflow_call|secrets: inherit|74e54255|8d500b20|1\.18\.13' \
. || trueLength of output: 116049 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== PR merge-base and complete PR changed paths =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'merge_base=%s\n' "$base"
git diff --name-status "$base..HEAD"
echo '== Product workflow: verification and publication jobs =='
grep -n -E '^ (verify|publish):|^ - name:|^ (run|uses|if|permissions|env):|^[[:space:]]{8}(GH_TOKEN|EXPECTED_|NIM_|APP_|base_sha|patch_sha256|open_prs|current_sha|git |gh )' \
.github/workflows/hourly-product-development.yml
sed -n '300,620p' .github/workflows/hourly-product-development.yml
echo '== Product workflow: package boundary with line numbers =='
nl -ba .github/workflows/hourly-product-development.yml | sed -n '185,285p'
echo '== Complete scheduler contract tests =='
nl -ba scripts/test_hourly_opencode_scheduler_contract.py | sed -n '1,240p'
echo '== Static indicators for binary and pom semantic enforcement =='
rg -n -C 2 --glob '.github/workflows/hourly-product-development.yml' \
'numstat|binary|diff-filter|pom\.xml|dependency|version|xmllint|maven.*help|git diff.*pom' .Length of output: 10528
I found two blocking policy-enforcement gaps. I cannot approve this head.
The remaining reviewed controls match the stated design: immutable action and central workflow pins,
|
|
@coderabbitai review @opencode-agent @cwl-noema-review Please independently review exact current head A manual supply-chain review found that Verify the exact workflow permission map and last-match behavior, absence of automatic permission approval, NVIDIA-only routing, no repository-code execution in the credentialed step, immutable patch/base/hash evidence, credential-free acceptance, publication-only App identity, draft-only PR creation, and all existing branch-protection and independent-review gates. Current-head CI, Security Scan, and SAST are still running or queued and must not be treated as passing. Submit formal APPROVE only for this exact head after every required exact-head check succeeds; otherwise report actionable path-specific findings. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='2d63878b1490557725761984a8f62bc95fcb1d63'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
echo '== Commit and changed paths from merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"
echo '== Workflow files and structural outlines =='
fd -HI -t f -E .git 'hourly.*\.(yml|yaml)$|.*opencode.*\.(yml|yaml)$' .github/workflows 2>/dev/null | sort | while IFS= read -r f; do
echo "--- $f"
ast-grep outline "$f" --items all 2>/dev/null || sed -n '1,80p' "$f"
done
echo '== Relevant production workflow content =='
fd -HI -t f -E .git 'hourly-product-development\.(yml|yaml)$' .github/workflows 2>/dev/null | while IFS= read -r f; do
echo "--- $f"
nl -ba "$f" | sed -n '1,760p'
done
echo '== Changed documentation and contract-test references =='
rg -n -C 4 --glob '*.{yml,yaml,md,py}' \
'(opencode run|--auto|permission|NVIDIA_NIM_API_KEY|NVIDIA|model|provider|patch_sha256|base_sha|numstat|pom\.xml|binary|open PR|pull.?request|mvn -B|pytest|draft|auto-merge|secrets: inherit|concurrency)' \
.github docs scripts CHANGELOG.md 2>/dev/null || true
echo '== Exact-head pull request and check status =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,statusCheckRollup \
--jq '{number, headRefOid, mergeStateStatus, isDraft, reviewDecision, checks: [.statusCheckRollup[] | {name, status, conclusion}]}'Length of output: 2687 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== Product workflow, numbered =='
f='.github/workflows/hourly-product-development.yml'
awk '{printf "%6d\t%s\n", NR, $0}' "$f"
echo '== PR maintenance workflow, numbered =='
f='.github/workflows/hourly-pr-maintenance.yml'
awk '{printf "%6d\t%s\n", NR, $0}' "$f"
echo '== Operator guide and changelog excerpts =='
rg -n -C 5 --glob '*.{md,yml,yaml}' \
'(opencode run|--auto|permission|last.match|NVIDIA_NIM_API_KEY|NVIDIA|model|provider|patch_sha256|base_sha|numstat|pom\.xml|binary|open PR|pull.?request|mvn -B|pytest|draft|auto-merge|secrets: inherit|concurrency)' \
docs/operations/hourly-development.md CHANGELOG.md .github/workflows/hourly-product-development.yml .github/workflows/hourly-pr-maintenance.yml || true
echo '== Complete scheduler contract test =='
awk '{printf "%6d\t%s\n", NR, $0}' scripts/test_hourly_opencode_scheduler_contract.py
echo '== Exact-head PR and check status =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,statusCheckRollup \
--jq '{number, headRefOid, mergeStateStatus, isDraft, reviewDecision, checks: [.statusCheckRollup[] | {name, status, conclusion}]}'Length of output: 88258
The The remaining reviewed controls match the requested design. They include immutable action pins, NVIDIA-only model routing, disabled OpenCode expansion features, no repository-code execution in the credentialed step, paginated zero-open-PR gates, immutable base and patch checks, credential-free verification, a publication-only App token, and draft-only PR creation. Exact-head checks are not complete. You are interacting with an AI system. |
|
@coderabbitai review @opencode-agent @cwl-noema-review Independently review exact current head |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='ad68fd8b4528a4357896025fab02211901f6e911'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
echo '== Changed paths from merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"
echo '== Candidate workflow and contract files =='
fd -HI -t f -E .git \
'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_opencode_scheduler_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
. .github docs scripts 2>/dev/null | sort
echo '== Workflow structure =='
for f in .github/workflows/hourly-product-development.yml .github/workflows/hourly-pr-maintenance.yml; do
if [ -f "$f" ]; then
echo "--- $f"
ast-grep outline "$f" --items all 2>/dev/null || true
fi
done
echo '== Product workflow, numbered =='
if [ -f .github/workflows/hourly-product-development.yml ]; then
nl -ba .github/workflows/hourly-product-development.yml | sed -n '1,760p'
fi
echo '== PR maintenance workflow, numbered =='
if [ -f .github/workflows/hourly-pr-maintenance.yml ]; then
nl -ba .github/workflows/hourly-pr-maintenance.yml | sed -n '1,360p'
fi
echo '== Contract test and operator guide, numbered =='
if [ -f scripts/test_hourly_opencode_scheduler_contract.py ]; then
nl -ba scripts/test_hourly_opencode_scheduler_contract.py | sed -n '1,420p'
fi
if [ -f docs/operations/hourly-development.md ]; then
nl -ba docs/operations/hourly-development.md | sed -n '1,480p'
fi
echo '== Targeted workflow safeguards =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
'(ls-files --others|intent-to-add|numstat|diff --check|diff-filter|--diff-filter|core\.quotepath|NUL|\\-z|pom\.xml|symlink|chmod|100[0-7]{3}|git diff --binary|patch_sha256|base_sha|open PR|pull.?request|concurrency|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|NVIDIA_NIM_API_KEY|NVIDIA|auto-update|plugin|LSP|project.config|mvn -B|pytest|draft|auto-merge|actions/create-github-app-token)' \
.github/workflows scripts docs CHANGELOG.md 2>/dev/null || true
echo '== Exact-head PR and check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'Length of output: 3989 🏁 Script executed: #!/bin/bash
set -euo pipefail
numbered() {
file="$1"
echo "--- $file"
sed = "$file" | sed 'N;s/\n/\t/'
}
echo '== Product workflow =='
numbered .github/workflows/hourly-product-development.yml
echo '== PR maintenance workflow =='
numbered .github/workflows/hourly-pr-maintenance.yml
echo '== Contract test =='
numbered scripts/test_hourly_opencode_scheduler_contract.py
echo '== Operator guide =='
numbered docs/operations/hourly-development.md
echo '== Changelog =='
numbered CHANGELOG.md
echo '== Focused safeguard matches =='
rg -n -C 5 --glob '*.{yml,yaml,py,md}' \
'(ls-files --others|intent-to-add|numstat|diff --check|diff-filter|core\.quotepath|read -r -d|while IFS=|\\-z|pom\.xml|symlink|chmod|100[0-7]{3}|git diff --binary|patch_sha256|base_sha|open_prs|per_page=100|page=|concurrency|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|NVIDIA_NIM_API_KEY|NVIDIA|auto-update|plugin|LSP|project.config|mvn -B|python -m pytest|draft|auto-merge|create-github-app-token)' \
.github/workflows scripts docs CHANGELOG.md 2>/dev/null || true
echo '== Exact-head PR and check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'Length of output: 160818
The requested repair works for the new-file and binary cases:
Exact-head approval evidence is also incomplete. CodeQL
|
|
@opencode-agent @cwl-noema-review Independently review exact current head |
|
Security review on exact head |
|
@coderabbitai review @opencode-agent @cwl-noema-review Independently review exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='d565474dd516d7e612689374a51c990c8a3470c3'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
echo 'ERROR: checked-out repository is not the requested exact head.' >&2
exit 0
fi
echo '== Changed paths against PR merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"
echo '== Candidate files =='
fd -HI -t f -E .git \
'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_(opencode_scheduler|scheduler_egress)_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
.github scripts docs . 2>/dev/null | sort -u
for f in \
.github/workflows/hourly-product-development.yml \
.github/workflows/hourly-pr-maintenance.yml \
scripts/test_hourly_scheduler_egress_contract.py \
scripts/test_hourly_opencode_scheduler_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
do
if [ -f "$f" ]; then
echo "== NUMBERED: $f =="
nl -ba "$f"
fi
done
echo '== Focused control references =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
'(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|github-token|permissions:|contents: write|pull-requests: write|mvn|pytest|opencode run|--auto|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|draft:|auto-merge|merge|publish|release|deploy|per_page=100|page=|cancel-in-progress)' \
.github scripts docs CHANGELOG.md 2>/dev/null || true
echo '== Current PR state and exact-head check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
--jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'Length of output: 3670 🏁 Script executed: #!/bin/bash
set -euo pipefail
numbered_slice() {
file="$1"
start="$2"
end="$3"
if [ -f "$file" ]; then
echo "== $file, Lines $start-$end =="
awk -v start="$start" -v end="$end" 'NR >= start && NR <= end { printf "%5d %s\n", NR, $0 }' "$file"
fi
}
numbered_slice .github/workflows/hourly-product-development.yml 1 760
numbered_slice .github/workflows/hourly-pr-maintenance.yml 1 360
numbered_slice scripts/test_hourly_scheduler_egress_contract.py 1 360
numbered_slice scripts/test_hourly_opencode_scheduler_contract.py 1 420
numbered_slice docs/operations/hourly-development.md 1 460
numbered_slice CHANGELOG.md 1 260
echo '== Focused control references =='
rg -n -C 5 --glob '*.{yml,yaml,py,md}' \
'(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|github-token|permissions:|contents: write|pull-requests: write|mvn|pytest|opencode run|--auto|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|draft:|auto-merge|merge|publish|release|deploy|per_page=100|page=|cancel-in-progress)' \
.github scripts docs CHANGELOG.md 2>/dev/null || true
echo '== Current PR state and exact-head check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
--jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'Length of output: 202093 🏁 Script executed: #!/bin/bash
set -euo pipefail
workflow='.github/workflows/hourly-product-development.yml'
test_file='scripts/test_hourly_scheduler_egress_contract.py'
echo '== Product workflow: all job boundaries and hardening context =='
grep -n -E '^ (propose|verify|publish):|^ - name:|harden-runner|egress-policy|allowed-endpoints|NVIDIA_|CLEARFOLIO_|permissions:|permission-|github-token|opencode run|git (apply|diff|ls-files|add|push)|mvn |pip install|pytest|gh pr create|--draft|merge|release|publish|deploy' "$workflow" || true
echo '== Product workflow: verifier job =='
awk '
/^ verify:$/ { emit=1 }
/^ publish:$/ { emit=0 }
emit { printf "%5d %s\n", NR, $0 }
' "$workflow"
echo '== Product workflow: publisher job =='
awk '
/^ publish:$/ { emit=1 }
emit { printf "%5d %s\n", NR, $0 }
' "$workflow"
echo '== Egress regression test =='
awk '{ printf "%5d %s\n", NR, $0 }' "$test_file"
echo '== Product scheduler contract: verifier and publisher assertions =='
awk '
/^def test_uncredentialed_verifier_runs_complete_repository_acceptance/ { emit=1 }
/^def test_pr_scheduler_preserves_central_review_agent_credentials/ { emit=0 }
emit { printf "%5d %s\n", NR, $0 }
' scripts/test_hourly_opencode_scheduler_contract.py
echo '== Exact workflow diff for the egress repair =='
git diff a02bcde7bf60542f85297074fd21d2e697fbc72c..d565474dd516d7e612689374a51c990c8a3470c3 -- \
.github/workflows/hourly-product-development.yml \
scripts/test_hourly_scheduler_egress_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.mdLength of output: 30043
I found no new code-level blocker in the verifier-egress repair.
I cannot approve this head.
Complete the post-#270 reconciliation and run fresh exact-head checks. Then obtain the required formal reviews and independent approval before requesting approval. You are interacting with an AI system. |
|
@coderabbitai review @opencode-agent @cwl-noema-review Independently review exact current head Verify the test-first publisher-egress repair and the complete scheduler contract. RED evidence is Confirm that both code-executing verification and App credential-bearing publication use fail-closed Fuzz is not triggered by the authoritative path filter for this workflow/documentation/script-only diff. Parent #270 integration, post-parent reconciliation, formal exact-head reviews, and counted independent write-authorized approval remain mandatory blockers. Submit formal review evidence only for this exact head; otherwise report actionable path-specific findings. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
echo 'ERROR: The checkout does not match the requested exact head.' >&2
exit 0
fi
echo '== Changed paths from PR merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"
echo '== Relevant file map =='
fd -HI -t f -E .git \
'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_(opencode_scheduler|scheduler_egress)_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
.github scripts docs . 2>/dev/null | sort -u
for f in \
.github/workflows/hourly-product-development.yml \
.github/workflows/hourly-pr-maintenance.yml \
scripts/test_hourly_scheduler_egress_contract.py \
scripts/test_hourly_opencode_scheduler_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
do
if [ -f "$f" ]; then
echo "== NUMBERED: $f =="
nl -ba "$f"
fi
done
echo '== Focused workflow and contract controls =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
'(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|actions/create-github-app-token|permissions:|contents: write|pull-requests: write|github-token|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|per_page=100|page=|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|git apply|git push|gh pr create|draft:|auto-merge|merge|release|publish|deploy)' \
.github scripts docs CHANGELOG.md 2>/dev/null || true
echo '== Exact repair diff =='
git diff 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3..HEAD -- \
.github/workflows/hourly-product-development.yml \
scripts/test_hourly_scheduler_egress_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
echo '== PR `#271` and parent `#270` state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
--jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'Length of output: 3973 🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
test "$(git rev-parse HEAD)" = "$expected"
numbered() {
file="$1"
echo "== NUMBERED: $file =="
awk '{printf "%5d %s\n", NR, $0}' "$file"
}
numbered .github/workflows/hourly-product-development.yml
numbered .github/workflows/hourly-pr-maintenance.yml
numbered scripts/test_hourly_scheduler_egress_contract.py
numbered scripts/test_hourly_opencode_scheduler_contract.py
numbered docs/operations/hourly-development.md
numbered CHANGELOG.md
echo '== Exact publisher-egress repair diff =='
git diff 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3..HEAD -- \
.github/workflows/hourly-product-development.yml \
scripts/test_hourly_scheduler_egress_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
echo '== Focused control references =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
'(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|actions/create-github-app-token|contents: write|pull-requests: write|github-token|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|per_page=100|page=|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|git apply|git push|gh pr create|draft:|auto-merge|merge|release|publish|deploy)' \
.github scripts docs CHANGELOG.md 2>/dev/null || true
echo '== PR `#271` state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
--jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'Length of output: 202168
I found no new code-level blocker in the publisher-egress repair.
I cannot approve this head.
Complete these gates before requesting approval. You are interacting with an AI system. |
|
@coderabbitai review @opencode-agent @cwl-noema-review Please review exact current head Current-head CI |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
echo 'ERROR: checkout does not match the requested exact head.'
exit 0
fi
for f in \
.github/workflows/hourly-pr-maintenance.yml \
.github/workflows/hourly-product-development.yml \
scripts/test_hourly_opencode_scheduler_contract.py \
scripts/test_hourly_scheduler_egress_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
do
if [ -f "$f" ]; then
echo "== $f =="
nl -ba "$f"
fi
done
echo '== Focused control references =='
rg -n -C 3 --glob '*.{yml,yaml,py,md}' \
'(74e54255ec903e3ba5f920859b656fe2defcb057|8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937|secrets: inherit|cancel-in-progress|per_page=100|page=|open_prs|opencode run|--auto|NVIDIA_NIM_API_KEY|egress-policy|allowed-endpoints|intent-to-add|numstat|diff-filter|pom\.xml|patch_sha256|base_sha|create-github-app-token|contents: write|pull-requests: write|gh pr create|--draft|auto-merge|git merge|release|deploy)' \
.github scripts docs CHANGELOG.md || true
echo '== PR and parent state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json state,mergedAt,mergeCommit \
--jq '{state,mergedAt,mergeCommit:(.mergeCommit.oid // null)}'Length of output: 2205 🏁 Script executed: #!/bin/bash
set -euo pipefail
expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
test "$(git rev-parse HEAD)" = "$expected"
for f in \
.github/workflows/hourly-pr-maintenance.yml \
.github/workflows/hourly-product-development.yml \
scripts/test_hourly_opencode_scheduler_contract.py \
scripts/test_hourly_scheduler_egress_contract.py \
docs/operations/hourly-development.md \
CHANGELOG.md
do
if [ -f "$f" ]; then
printf '== %s ==\n' "$f"
awk '{printf "%5d %s\n", NR, $0}' "$f"
fi
done
echo '== Focused control references =='
rg -n -C 3 --glob '*.{yml,yaml,py,md}' \
'(74e54255ec903e3ba5f920859b656fe2defcb057|8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937|secrets: inherit|cancel-in-progress|per_page=100|page=|open_prs|opencode run|--auto|NVIDIA_NIM_API_KEY|egress-policy|allowed-endpoints|intent-to-add|numstat|diff-filter|pom\.xml|patch_sha256|base_sha|create-github-app-token|contents: write|pull-requests: write|gh pr create|--draft|auto-merge|git merge|release|deploy)' \
.github scripts docs CHANGELOG.md || true
echo '== PR and parent state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
--json headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
--jq '{headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
--json state,mergedAt,mergeCommit \
--jq '{state,mergedAt,mergeCommit:(.mergeCommit.oid // null)}'Length of output: 228913
I found no new code-level blocker in the reviewed workflows.
The reported exact-head CI, security, and SAST checks are complete and successful. The current GitHub state also shows successful Maven, buyer-readiness, CodeQL, Semgrep, OpenCode, Noema, and Strix checks. I cannot approve this PR.
|
Objective
Add two non-duplicative hourly loops:
NVIDIA_NIM_API_KEY, packages one bounded patch without executing repository code in the credentialed step, reverifies it separately, and uses a dedicated repository-scoped GitHub App only to open a draft PR.The product loop never uses
COPILOT_GITHUB_TOKEN, never approves or merges its own output, and never releases, publishes, or deploys.Trust and backpressure controls
74e54255ec903e3ba5f920859b656fe2defcb057;8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937;--auto, so unmatched permission requests fail closed;contents: writeandpull-requests: writefor branch and draft-PR publication;Test-first verifier-egress repair
The RED head
a02bcde7bf60542f85297074fd21d2e697fbc72caddedscripts/test_hourly_scheduler_egress_contract.pybefore production modification. CI run31026008612failed as intended because the credential-free verifier executed model-generated Java and Python tests under observation-only network policy.The verifier now uses fail-closed
egress-policy: block. Its allowlist is limited to GitHub API, checkout and Actions artifact transport, Maven Central, and the PyPI hosts required for hash-locked test dependencies.Test-first publisher-egress repair
The RED head
7a34049d5a4c7a5a41f21c71f96af403ffde0dc3added a regression contract before production modification. CI run31028342182failed as intended because the GitHub App credential-bearing publisher still used observation-onlyegress-policy: audit.Exact current head
cc533d982b38bd755cfa9c67e670ecc4bdcc64c6repairs that valid supply-chain finding without weakening the test:egress-policy: block;CHANGELOG.mdrecord the boundary and recovery contract.Relative to reviewed predecessor
d565474dd516d7e612689374a51c990c8a3470c3, the repair changes only the workflow egress stanza, its deterministic regression test, the authoritative operator guide, and the changelog.Exact-head evidence
For exact head
cc533d982b38bd755cfa9c67e670ecc4bdcc64c6:31028760873: success.92383820648: success.92383820672: success; 29 tests passed, including verifier and publisher egress contracts.31028760722: success.31028760655: success.Stack order
Keep this PR draft. Parent #270 must integrate first. This branch must then be reconciled onto protected
mainso the autonomous verifier also inherits #270's fail-closed Maven Surefire/Failsafe report-evidence gate, followed by fresh exact-head validation.Merge gate
Do not merge until #270 is integrated and this branch reconciled, every exact-head required check succeeds, formal CodeRabbit and OpenCode/Noema/Strix evidence exists, zero unresolved threads remains true, a repository-write-authorized independent reviewer submits a counted approval, and every branch-protection and repository-policy rule is satisfied. Do not bypass protections, infer formal approval from commit status, or publish a release.
After integration, administrators must configure
NVIDIA_NIM_API_KEY,CLEARFOLIO_MAINTAINER_APP_CLIENT_ID, andCLEARFOLIO_MAINTAINER_APP_PRIVATE_KEY; missing prerequisites fail closed without fallback identity or model.