[M0-R][CI] Add mandatory scientific quality gates and protected PR workflow - #67
Open
andreazedda wants to merge 4 commits into
Open
[M0-R][CI] Add mandatory scientific quality gates and protected PR workflow#67andreazedda wants to merge 4 commits into
andreazedda wants to merge 4 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #13
References #23
References #26
Verified baseline and scope
bf097810b337dc6b766cda04497005670cd96513.4f6a0c8714609f02a4a55f693419c7178bfa46e2.E1_research_prototype; clinical decision support, patient-specific prediction validation, and causal-effect identification remain false.Workflow graph and required status
Stable required context:
M0-R CI / required. Every mandatory job has a timeout, the workflow usescontents: read, superseded PR/branch runs cancel, and the aggregator fails unless every dependency reportssuccess.Immutable action inventory
All repository workflow actions are pinned to verified full commit SHAs with release comments: checkout v4.2.2, setup-python v5.6.0, setup-uv v7.6.0, upload-pages-artifact v3.0.1, deploy-pages v4.0.5, setup-qemu v3.6.0, setup-buildx v3.11.1, docker login v3.4.0, metadata v5.8.0, build-push v6.18.0, gitleaks v2.3.9, and upload-artifact v4.6.2. The exact inventory is in
docs/operations/TESTING.md.Test evidence
requiredpass.uv==0.12.3;uv lock --checkand frozen chemistry sync pass.Baseline characterization found failures attributable to the chemistry extra not being installed, an import-time manual live-server script, and two stale assertions contradicted by already-merged behavior. The candidate installs the authoritative chemistry extra, makes the manual script import-safe, and updates only those stale assertions without changing product behavior.
Numerical-baseline comparison
Before and after both pass
dependency-lock-baseline-v1with no differences. The canonical seeded report remains 28,247 bytes with SHA-256708b828060bb06d5842f95850479c1f270c565e69c1fc8d2f40b0e97862ac957. No golden fixture, equation, coefficient, solver setting, model version, or numerical output changed.Privacy and safety evidence
local_private/was never traversed..dockerignoreexcludes private, environment, database, media, log, artifact, data, and output paths before Docker receives the build context..env.Dependency changes
sqlparseis updated from 0.5.4 to patched 0.6.0 inpyproject.tomlanduv.lockto remediate four high-severity advisories disclosed after the baseline. A newly disclosed moderate Django 4.2 GeoDjango advisory is narrowly triaged because the affected GIS surface is absent and no 4.2 patch exists; the documented Django 5.2 migration must remove that exception. No new CI dependency was added.Docker evidence
The hosted gate builds the locked image without pushing, verifies Git/source OCI labels, verifies no private/database/environment path entered the image, verifies empty media/log directories, and passes Django's synthetic-settings check inside the image. This is a current M0-R build/smoke result, not a claim of production readiness.
Branch protection and reviewer feasibility
masterprotection is active: pull requests and an up-to-date GitHub Actionsrequiredcheck are required; conversation resolution and admin enforcement are enabled; force pushes and branch deletion are disabled. The only verified collaborator is the PR author, so required approving reviews is honestly set to zero; there is no eligible second reviewer. Stale approvals will be dismissed if approvals are later enabled. Issue #13 and this PR remain open unless the owner explicitly documents a temporary solo-maintainer exception in an ADR or issue comment.The stale branch
andreazedda/issue7has zero unique commits relative tomaster, no open PR dependency, and all relevant commits are contained bymaster. It is retained until protection is safely audited.Rollback and residual risk
Rollback is a revert of the four focused commits. It creates no migration, database transformation, model-version transition, dataset invalidation, or numerical-fixture update. Reverting would restore the previous advisory exposure and remove the new mandatory gate, so protection should be updated before any such rollback. Residual risks are the documented Django/pytest audit exceptions, the absence of an eligible independent reviewer, and GitHub runner warnings that the pinned checkout/setup-python releases target deprecated Node 20 metadata while the runner currently forces Node 24.
Checklist