Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
514 commits
Select commit Hold shift + click to select a range
8aacc70
chore: refresh org SBOM inventory
Sep 11, 2026
4aa845b
chore: preserve SBOM inventory publication lineage
Sep 11, 2026
06270ee
chore: refresh org SBOM inventory
Sep 11, 2026
7472570
chore: preserve SBOM inventory publication lineage
Sep 11, 2026
83f6208
chore: refresh org SBOM inventory
Sep 11, 2026
4db3c12
chore: preserve SBOM inventory publication lineage
Sep 11, 2026
30b5e33
chore: refresh org SBOM inventory
Sep 11, 2026
c6c5813
chore: preserve SBOM inventory publication lineage
Sep 11, 2026
3b47134
chore: refresh org SBOM inventory
Sep 12, 2026
5b715fa
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
9b4580c
test: require usable README scaffold and incomplete blocker semantics
seonghobae Sep 12, 2026
1a7120f
docs: add adaptable product README authoring scaffold
seonghobae Sep 12, 2026
0e7dc2e
docs: bind README template to execution evidence and protected delivery
seonghobae Sep 12, 2026
4a1519e
docs: retain README template decision and verification boundaries
seonghobae Sep 12, 2026
3153f2f
Merge protected main into README template lane
seonghobae Sep 12, 2026
0da57b1
chore: refresh org SBOM inventory
Sep 12, 2026
ead9bf8
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
691fb78
Merge pull request #1694 from ContextualWisdomLab/docs/repository-rea…
seonghobae Sep 12, 2026
952f95f
test(codeql): require versioned handler rollout bootstrap
seonghobae Sep 12, 2026
2351dc1
fix(codeql): stage versioned handler rollout bootstrap
seonghobae Sep 12, 2026
c5b8d00
docs(codeql): record handler-first rollout boundary
seonghobae Sep 12, 2026
a686a48
test(codeql): cap settlement below Actions rerun ceiling
seonghobae Sep 12, 2026
6308f7a
fix(codeql): stop settlement before rerun ceiling
seonghobae Sep 12, 2026
99bc9db
docs(codeql): record rerun exhaustion boundary
seonghobae Sep 12, 2026
a5ca9f1
merge: reconcile handler bootstrap with protected main
seonghobae Sep 12, 2026
1d3f510
fix(codeql): add versioned single-settlement handler
seonghobae Sep 12, 2026
b2ff9a9
test(codeql): enforce versioned settlement contract
seonghobae Sep 12, 2026
1d6b630
test(codeql): enforce versioned settlement contract
seonghobae Sep 12, 2026
c695a11
docs(codeql): define handler-first migration
seonghobae Sep 12, 2026
ce33538
docs(codeql): define handler-first migration
seonghobae Sep 12, 2026
0102377
docs(changelog): record versioned CodeQL bootstrap
seonghobae Sep 12, 2026
ae3d0a5
docs(codeql): record versioned handler bootstrap evidence
seonghobae Sep 12, 2026
b855e7d
Merge pull request #2095 from ContextualWisdomLab/docs/javascript-mat…
seonghobae Sep 12, 2026
fb17ef5
Merge pull request #2092 from ContextualWisdomLab/docs/org-queue-swee…
seonghobae Sep 12, 2026
fde889a
merge: reconcile handler bootstrap with protected main
seonghobae Sep 12, 2026
d7d9225
test(codeql): reproduce fallback stdout contamination
seonghobae Sep 12, 2026
6b476a8
fix(codeql): isolate failed credential response bodies
seonghobae Sep 12, 2026
9bf6a87
docs(codeql): record credential fallback RCA
seonghobae Sep 12, 2026
bedce13
docs(changelog): record settlement response isolation
seonghobae Sep 12, 2026
48c6304
chore(codeql): restack #2106 on protected main
seonghobae Sep 12, 2026
2c163e9
test(codeql): exercise consumed-field fallback contamination
seonghobae Sep 12, 2026
50adc03
fix(codeql): integrate versioned rerun exhaustion guards
seonghobae Sep 12, 2026
792d65b
style(codeql): align rerun-mode fixture mapping
seonghobae Sep 12, 2026
24bb659
docs(codeql): correct native rerun allowance
seonghobae Sep 12, 2026
40e4b21
chore: refresh org SBOM inventory
Sep 12, 2026
457b0b1
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
9521b67
test(scheduler): require read-only commit status evidence
seonghobae Sep 12, 2026
1c5c6b7
fix(scheduler): grant job-scoped commit status reads
seonghobae Sep 12, 2026
f823976
test(opencode): cover python-root VCS imports
seonghobae Sep 12, 2026
af04581
fix(opencode): admit immutable python source roots
seonghobae Sep 12, 2026
be75718
docs(opencode): record VCS source-root RCA
seonghobae Sep 12, 2026
ed82ddb
test(opencode): require python-root VCS imports
seonghobae Sep 12, 2026
145b6ca
merge: preserve corrected python-root RED contract
seonghobae Sep 12, 2026
ad59e5d
docs(opencode): bind corrected RED ancestry
seonghobae Sep 12, 2026
b1fe97c
test(opencode): require valid python-root VCS imports
seonghobae Sep 12, 2026
b92ddb1
merge: converge valid python-root RED contract
seonghobae Sep 12, 2026
5303e09
docs(opencode): bind valid RED contract
seonghobae Sep 12, 2026
683cb05
fix(opencode): advance trusted dispatch blob pin
seonghobae Sep 12, 2026
7e3b1a4
docs(opencode): record trusted blob RED and repair
seonghobae Sep 12, 2026
bdf2bf1
chore: refresh org SBOM inventory
Sep 12, 2026
50890f8
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
2a49f19
chore: refresh org SBOM inventory
Sep 12, 2026
9508ea0
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
6a3362a
chore: refresh org SBOM inventory
Sep 12, 2026
da9b27c
chore: preserve SBOM inventory publication lineage
Sep 12, 2026
6f588e3
chore: refresh org SBOM inventory
Sep 13, 2026
e3d8572
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
109b114
fix(security-scan): use current OSV output flags and bind SARIF uploa…
seonghobae Sep 13, 2026
8db9a1d
fix(sast-semgrep): fold the changed-scope gate into its single consum…
seonghobae Sep 13, 2026
81a2cc6
fix(pingora): admit bounded HWPX evidence documents without UTF-8 dec…
seonghobae Sep 13, 2026
4ba16a4
fix(codeql): grant private consumers pull-request and status reads
seonghobae Sep 13, 2026
0ad785d
Merge pull request #2121 from ContextualWisdomLab/fix/scheduler-statu…
seonghobae Sep 13, 2026
76f7335
test(pingora): keep the denied runtime form out of the HWPX fixture s…
seonghobae Sep 13, 2026
b72ab7f
fix(review-policy): key OpenRouter ZDR feed routes by model_id
seonghobae Sep 13, 2026
fb8138e
docs(sast-semgrep): describe the step-level guard in the job comment
seonghobae Sep 13, 2026
7c74dac
Merge pull request #2145 from ContextualWisdomLab/fix/codeql-pr-priva…
seonghobae Sep 13, 2026
c718d95
Merge remote-tracking branch 'origin/main' into fix/zdr-feed-model-id…
seonghobae Sep 13, 2026
feffdb3
Merge pull request #2146 from ContextualWisdomLab/fix/zdr-feed-model-…
seonghobae Sep 13, 2026
bae7e79
Merge remote-tracking branch 'origin/main' into fix/pingora-hwpx-evid…
seonghobae Sep 13, 2026
64f483d
Merge pull request #2144 from ContextualWisdomLab/fix/pingora-hwpx-ev…
seonghobae Sep 13, 2026
611ccd7
Merge 24bb6591ab7df23558cb793b4af60c567ff9da97 into 64f483db9d052322c…
seonghobae Sep 13, 2026
42a479d
chore: refresh org SBOM inventory
Sep 13, 2026
69212d9
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
a808114
Merge remote-tracking branch 'origin/main' into fix/osv-output-flags-…
seonghobae Sep 13, 2026
7e5b971
test(security-scan): assert each OSV step's output flag individually
seonghobae Sep 13, 2026
3452ed5
fix(codeql): resolve SARIF rules from the referenced tool component
seonghobae Sep 13, 2026
ab1ca3d
chore: refresh org SBOM inventory
Sep 13, 2026
97ba2b0
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
d6cf572
fix(scheduler): recheck cancellation races (#2153)
seonghobae Sep 13, 2026
509fa2a
chore(sidecar): advance contextual-orchestrator pin to 767e67fb (no i…
seonghobae Sep 13, 2026
78393ea
Merge pull request #2163 from ContextualWisdomLab/chore/bump-co-sidec…
seonghobae Sep 13, 2026
3253f59
Merge protected main d6cf5726 into canonical CodeQL handler owner
seonghobae Sep 13, 2026
db34e6b
Merge protected main 78393ea9 into canonical CodeQL handler owner
seonghobae Sep 13, 2026
19731ac
Merge remote-tracking branch 'origin/main' into fix/opencode-vcs-pyth…
seonghobae Sep 13, 2026
23fd192
chore: refresh org SBOM inventory
Sep 13, 2026
12207aa
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
04d0f65
fix(noema): extract office documents for review context (#2172)
seonghobae Sep 13, 2026
d33d76f
chore(restack): advance CodeQL handler onto protected main
seonghobae Sep 13, 2026
828eaae
fix(noema): close document reader review gaps (#2178)
seonghobae Sep 13, 2026
1ba96e4
chore(restack): advance CodeQL handler through Noema follow-up
seonghobae Sep 13, 2026
4c0f81b
chore(queue-health): reconcile protected main 2026-09-14
seonghobae Sep 13, 2026
7b4ea7c
Merge remote-tracking branch 'origin/main' into fix/opencode-vcs-pyth…
seonghobae Sep 13, 2026
9354280
Merge remote-tracking branch 'origin/main' into fix/codeql-sarif-gate…
seonghobae Sep 13, 2026
79546dc
Merge remote-tracking branch 'origin/main' into tmp-fix/osv-output-fl…
seonghobae Sep 13, 2026
aa52e2a
Merge remote-tracking branch 'origin/main' into tmp-fix/sast-semgrep-…
seonghobae Sep 13, 2026
5516b7f
chore: refresh org SBOM inventory
Sep 13, 2026
b9d894b
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
ebc69a4
Merge pull request #2123 from ContextualWisdomLab/fix/opencode-vcs-py…
seonghobae Sep 13, 2026
3a77ba0
chore: refresh org SBOM inventory
Sep 13, 2026
c420392
chore: preserve SBOM inventory publication lineage
Sep 13, 2026
4288590
Merge protected main into CodeQL bootstrap #2106
seonghobae Sep 14, 2026
d1d70e3
Merge pull request #2155 from ContextualWisdomLab/fix/codeql-sarif-ga…
seonghobae Sep 14, 2026
cf89070
Merge pull request #2143 from ContextualWisdomLab/fix/osv-output-flag…
seonghobae Sep 14, 2026
7f07029
Merge pull request #2147 from ContextualWisdomLab/fix/sast-semgrep-ga…
seonghobae Sep 14, 2026
44901e4
chore(codeql): reconcile bootstrap with protected main after #2147
seonghobae Sep 14, 2026
f68a738
chore: refresh org SBOM inventory
Sep 14, 2026
95a2c0f
chore: preserve SBOM inventory publication lineage
Sep 14, 2026
fbcf718
Merge protected main into queue-health owner #1150
seonghobae Sep 14, 2026
45da4c7
chore: refresh org SBOM inventory
Sep 14, 2026
8382ff6
chore: preserve SBOM inventory publication lineage
Sep 14, 2026
91be644
feat(pingora): admit declared research/data artifact paths (#2193) (#…
seonghobae Sep 14, 2026
9defd52
chore(codeql): reconcile protected main into #2106
seonghobae Sep 14, 2026
42bb922
Merge protected main into queue-health owner #1150
seonghobae Sep 14, 2026
4a0ce88
chore: refresh org SBOM inventory
Sep 14, 2026
50ffd9d
chore: preserve SBOM inventory publication lineage
Sep 14, 2026
bd6e5d8
chore: refresh org SBOM inventory
Sep 14, 2026
fd790b0
chore: preserve SBOM inventory publication lineage
Sep 14, 2026
5a81eec
chore: refresh org SBOM inventory
Sep 15, 2026
b1d2ce3
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
f75752c
chore: refresh org SBOM inventory
Sep 15, 2026
086def0
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
9137dd6
chore: refresh org SBOM inventory
Sep 15, 2026
4dbffaa
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
298e6c1
test(codeql): compare hardened-runner endpoints as exact lines
seonghobae Sep 15, 2026
0b110a4
chore: refresh org SBOM inventory
Sep 15, 2026
31986c3
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
6df7775
chore: refresh org SBOM inventory
Sep 15, 2026
8196ba3
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
e5ebeec
fix: 경로 탐색 취약점 완화를 위해 정규표현식 수정
seonghobae Sep 15, 2026
1833e75
chore: refresh org SBOM inventory
Sep 15, 2026
792dc3a
chore: preserve SBOM inventory publication lineage
Sep 15, 2026
0b5ab5f
chore: refresh org SBOM inventory
Sep 16, 2026
40fdd31
chore: preserve SBOM inventory publication lineage
Sep 16, 2026
b3f4fa4
chore: refresh org SBOM inventory
Sep 16, 2026
c8a9709
chore: preserve SBOM inventory publication lineage
Sep 16, 2026
e1d845f
fix: 경로 탐색 및 DoS 취약점 완화
seonghobae Sep 16, 2026
9b55fe5
chore: refresh org SBOM inventory
Sep 16, 2026
a7a1135
chore: preserve SBOM inventory publication lineage
Sep 16, 2026
8770316
test(traceability): require owner-qualified cross-repo evidence
seonghobae Sep 16, 2026
cf7fa86
revert(traceability): keep baseline repair with canonical document owner
seonghobae Sep 16, 2026
9bc00fc
docs: CI queue-stall baseline (24h, org-wide) + scoping ADR
seonghobae Sep 16, 2026
e0d022e
Merge pull request #2221 from ContextualWisdomLab/docs/ci-baseline-20…
seonghobae Sep 16, 2026
a462c87
fix(opencode-review): stop the coverage fallback from being unreceipt…
seonghobae Sep 16, 2026
38d9bfc
Merge pull request #2222 from ContextualWisdomLab/fix/1907-opencode-c…
seonghobae Sep 16, 2026
be80eb4
merge(main): reconcile CodeQL handler with protected main
seonghobae Sep 16, 2026
efc35f7
fix(opencode-review): vendor Cargo deps offline for the coverage sandbox
seonghobae Sep 16, 2026
346b46d
Merge pull request #2223 from ContextualWisdomLab/seonghobae/fix-1907…
seonghobae Sep 16, 2026
a5569a0
test(docs): require owner-qualified cross-repo evidence
seonghobae Sep 16, 2026
473371c
merge(main): reconcile CodeQL handler with Rust coverage materializer
seonghobae Sep 16, 2026
1336eae
chore: revert incomplete evidence-identity rehearsal
seonghobae Sep 16, 2026
8429787
test(docs): lock owner-qualified evidence identities
seonghobae Sep 16, 2026
1ebd10d
chore: refresh org SBOM inventory
Sep 16, 2026
0fa9a1a
chore: preserve SBOM inventory publication lineage
Sep 16, 2026
11a5630
fix(opencode-review): build PyO3/maturin extensions offline before co…
seonghobae Sep 16, 2026
89b225d
Merge pull request #2225 from ContextualWisdomLab/seonghobae/fix-1907…
seonghobae Sep 16, 2026
ff72f8b
merge(main): reconcile CodeQL bootstrap with current protected main
seonghobae Sep 16, 2026
5e4dfe4
docs: qualify cross-repository evidence identities
seonghobae Sep 16, 2026
fdab673
fix: restore exact baseline before repository identity repair
seonghobae Sep 16, 2026
8440b54
chore: refresh org SBOM inventory
Sep 16, 2026
498bec8
chore: preserve SBOM inventory publication lineage
Sep 16, 2026
a01dc86
docs(doctoring): root-cause the multi-hour review durations as inter-…
seonghobae Sep 17, 2026
45f612f
Merge pull request #2227 from ContextualWisdomLab/seonghobae/actions-…
seonghobae Sep 17, 2026
51dacbf
fix(opencode-review-dispatch): fold same-trust-level jobs to cut a qu…
seonghobae Sep 17, 2026
8ef0017
Merge pull request #2228 from ContextualWisdomLab/seonghobae/actions-…
seonghobae Sep 17, 2026
c1d347a
fix(opencode-review,noema-review): skip the AI review chain for docs/…
seonghobae Sep 17, 2026
3c38d38
Merge pull request #2229 from ContextualWisdomLab/seonghobae/actions-…
seonghobae Sep 17, 2026
c6a2a82
chore: refresh org SBOM inventory
Sep 17, 2026
288ff6f
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
fb74675
Merge protected main into CodeQL bootstrap branch
seonghobae Sep 17, 2026
ab31a05
fix(opencode-review): fold required-workflow-bootstrap + admit-curren…
seonghobae Sep 17, 2026
6513c7a
Merge pull request #2230 from ContextualWisdomLab/seonghobae/actions-…
seonghobae Sep 17, 2026
bff097e
Merge current protected main into CodeQL bootstrap branch
seonghobae Sep 17, 2026
f9863d9
feat(scheduler): add push-burst coalescing, inert by default (PR1/2)
seonghobae Sep 17, 2026
a9c6477
Merge pull request #2231 from ContextualWisdomLab/seonghobae/actions-…
seonghobae Sep 17, 2026
c81e39c
Merge current protected main into CodeQL bootstrap branch
seonghobae Sep 17, 2026
653466d
Fix CodeRabbit issues in PR #2106
coderabbitai[bot] Sep 17, 2026
d7099a9
fix(scheduler): fail-open coalesce when tick has not completed recently
seonghobae Sep 17, 2026
1b3f54a
fix(ci): step-scope coalesce tick gate so schedule produces run records
seonghobae Sep 17, 2026
6f79973
test(scheduler): cover coalesce tick fail-open and tick recency helpers
seonghobae Sep 17, 2026
e6a6c31
chore: refresh org SBOM inventory
Sep 17, 2026
4c7c5ed
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
6802910
Merge origin/main into sentinel-fix-path-traversal branch
seonghobae Sep 17, 2026
ec7102d
fix: dedupe sentinel learnings after main merge
seonghobae Sep 17, 2026
7d496d6
fix(codeql): stop SARIF false positive and wake-only verdict inversion
seonghobae Sep 17, 2026
2acb726
fix(tests): bound harden-runner endpoint parsing by indentation to ex…
coderabbitai[bot] Sep 17, 2026
b496417
fix(ci): step-scope coalesce tick gate so schedule produces run recor…
seonghobae Sep 17, 2026
d35788d
fix(scheduler): fail-open coalesce when tick has not completed recent…
seonghobae Sep 17, 2026
c73d1b4
chore: reconcile CodeQL bootstrap with protected main
seonghobae Sep 17, 2026
a44ad8f
fix: preserve protected coalesce tick regression
seonghobae Sep 17, 2026
8c77327
fix(codeql): SARIF FP allowlist parse + wake-step verdict read (#2234)
seonghobae Sep 17, 2026
47ccc21
chore: reconcile CodeQL bootstrap with latest protected main
seonghobae Sep 17, 2026
2fd736c
chore: refresh org SBOM inventory
Sep 17, 2026
bd99f68
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
6f9f2b4
chore(central-ci): reconcile queue-health owner with protected main
seonghobae Sep 17, 2026
41c1911
fix(security): reject path traversal in trusted path resolution (#2217)
seonghobae Sep 17, 2026
1e15046
fix(strix): bind PR findings and remediation claims to authenticated …
seonghobae Sep 17, 2026
2979045
fix(noema): re-dispatch on provider capacity after gateway failover
seonghobae Sep 17, 2026
4ba7960
chore: reconcile CodeQL bootstrap with protected queue hardening
seonghobae Sep 17, 2026
130ce42
fix(strix): bind PR findings and remediation claims to authenticated …
seonghobae Sep 17, 2026
65a71c5
chore: reconcile CodeQL bootstrap with Strix evidence hardening
seonghobae Sep 17, 2026
c423528
Merge origin/main into seonghobae/noema-transport-2165
seonghobae Sep 17, 2026
4fda7f5
fix(noema): bounded transport-capacity re-dispatch (#2165)
seonghobae Sep 17, 2026
e455561
chore: reconcile CodeQL bootstrap with Noema capacity repair
seonghobae Sep 17, 2026
86dd9ed
fix: preserve protected Noema executable modes
seonghobae Sep 17, 2026
dea8cc1
docs(doctoring): remeasure Actions queue after coalesce tick repairs
seonghobae Sep 17, 2026
7e1fb01
docs(doctoring): Actions queue 24h remeasurement after #2232–#2236 (#…
seonghobae Sep 17, 2026
fcaacfc
fix(opencode): extract coverage VCS import-root resolver for #2157
seonghobae Sep 17, 2026
4e56ff0
fix(opencode): extract coverage VCS import-root resolver (#2157)
seonghobae Sep 17, 2026
c9900f4
merge(main): resolve gap-baseline conflict for CodeQL bootstrap
seonghobae Sep 17, 2026
22652af
fix(codeql): prove GHAS base/head configuration identity before statu…
seonghobae Sep 17, 2026
6be76f6
fix(docs): keep owner-qualified identities after main merge
seonghobae Sep 17, 2026
0e9412f
fix(opencode): preserve protected coverage job contract
seonghobae Sep 17, 2026
8fc54eb
fix(codeql): bootstrap versioned dispatch handler (#2106)
seonghobae Sep 17, 2026
acedd9f
merge(main): reconcile #2239 GHAS identity fix with #2106 handler
seonghobae Sep 17, 2026
a1d0034
fix(codeql): prove GHAS base/head configuration identity (#2133)
seonghobae Sep 17, 2026
eba48c1
fix(python-security): stop reporting pip-audit transport failures as …
seonghobae Sep 17, 2026
c1f977f
chore(queue): reconcile #1150 queue-health owner onto current main
seonghobae Sep 17, 2026
74613cf
ops(queue): enroll DiskSage/LineageWeave/Noema/quarantine/OriginWeave
seonghobae Sep 17, 2026
31cce5f
fix(python-security): stop reporting pip-audit transport failures as …
seonghobae Sep 17, 2026
991b854
ops(queue): enroll DiskSage/LineageWeave/Noema/quarantine/OriginWeave…
seonghobae Sep 17, 2026
554a28b
fix(ci): skip inert coalesce ticks before runner admission
seonghobae Sep 17, 2026
3449d00
fix(ci): skip inert coalesce ticks before runner admission (#2242)
seonghobae Sep 17, 2026
14343c7
chore: refresh org SBOM inventory
Sep 17, 2026
924dd67
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
30a5e73
ops(queue): enroll mhtml-etl-gateway in queue-health evidence
seonghobae Sep 17, 2026
60c083e
Merge pull request #2243 from ContextualWisdomLab/seonghobae/queue-he…
seonghobae Sep 17, 2026
539ca3e
docs(doctoring): record post-#2242 coalesce tick live verify
seonghobae Sep 17, 2026
b969c77
Merge pull request #2244 from ContextualWisdomLab/seonghobae/coalesce…
seonghobae Sep 17, 2026
b5b1cfc
ops(queue): enroll pg-llm-batch
seonghobae Sep 17, 2026
eb99321
Merge pull request #2219 from ContextualWisdomLab/codex/pg-llm-batch-…
seonghobae Sep 17, 2026
6dffc0c
test(queue): capture terminal pre-execution failure
seonghobae Sep 15, 2026
e69709e
fix(queue): classify terminal pre-execution failures
seonghobae Sep 15, 2026
9a311dd
test(queue): preserve terminal aggregate accounting
seonghobae Sep 15, 2026
c85ba9c
test(queue): preserve queued job timing evidence
seonghobae Sep 17, 2026
4b2c426
fix(queue): fetch job evidence for queued current-head runs
seonghobae Sep 17, 2026
64aa08d
Merge pull request #2213 from ContextualWisdomLab/codex/queue-health-…
seonghobae Sep 17, 2026
3d89994
chore: refresh org SBOM inventory
Sep 17, 2026
7bb103e
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
b56f132
chore: refresh org SBOM inventory
Sep 17, 2026
00561dd
chore: preserve SBOM inventory publication lineage
Sep 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 53 additions & 10 deletions .github/actions/noema-review/two_phase.py
Original file line number Diff line number Diff line change
Expand Up @@ -167,16 +167,20 @@ def prepare_verdict(repo: str, number: int, expected_head: str, path: Path) -> i
changed_files = gate.fetch_changed_files(repo, number)
changed_paths = tuple(file_path for file_path, _status in changed_files)
review_context = gate.build_review_context(repo, number, pull_request, changed_files)
verdict = gate.call_llm(
repo,
number,
pull_request,
diff,
truncated,
expected,
review_context,
changed_paths,
)
try:
verdict = gate.call_llm(
repo,
number,
pull_request,
diff,
truncated,
expected,
review_context,
changed_paths,
)
except gate.NoemaTransportError as exc:
_emit_transport_capacity_outputs(exc, expected_head=expected)
raise

_write_envelope(
path,
Expand All @@ -196,6 +200,45 @@ def prepare_verdict(repo: str, number: int, expected_head: str, path: Path) -> i
return 0


def _emit_transport_capacity_outputs(
exc: gate.NoemaTransportError,
*,
expected_head: str,
) -> None:
"""Publish typed capacity evidence for the workflow's bounded re-dispatch step."""
retry_attempt = gate.current_transport_retry_attempt()
delay = gate.transport_redispatch_delay_seconds(
transport_retry_attempt=retry_attempt,
head_sha=expected_head,
retry_after_seconds=exc.retry_after_seconds,
)
eligible = bool(exc.capacity_unavailable and delay is not None)
outputs = {
"transport_capacity_unavailable": "true" if exc.capacity_unavailable else "false",
"transport_retry_eligible": "true" if eligible else "false",
"prepared": "false",
}
if type(exc.http_status) is int:
outputs["transport_http_status"] = str(exc.http_status)
if type(exc.provider_attempt_count) is int:
outputs["provider_attempt_count"] = str(exc.provider_attempt_count)
if delay is not None:
outputs["transport_retry_delay_seconds"] = str(delay)
outputs["transport_retry_next_attempt"] = str(retry_attempt + 1)
gate.append_github_output(outputs)
if eligible:
print(
"::notice::Noema provider capacity unavailable after gateway failover; "
f"bounded continuation re-dispatch is eligible in {delay}s "
f"(attempt {retry_attempt + 1}/{gate.MAX_TRANSPORT_REDISPATCH_ATTEMPTS})."
)
elif exc.capacity_unavailable:
print(
"::error::Noema provider capacity unavailable after gateway failover; "
"automatic re-dispatch budget is exhausted. Review remains required."
)


def publish_verdict(repo: str, number: int, expected_head: str, path: Path) -> int:
"""Publish a prepared verdict only with fresh exact-head/base reviewer authority."""
expected = _canonical_head(expected_head)
Expand Down
4 changes: 2 additions & 2 deletions .github/actions/orchestrator-free-sidecar/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@ inputs:
required: false
default: "false"
catalog_limit:
description: Maximum discovered route catalog size for the sidecar preflight.
description: Maximum discovered route catalog size for the sidecar preflight (a candidate list probed lazily to a readiness target, ADR-0029).
required: false
default: "12"
default: "24"
catalog_account_cap:
description: Maximum routes admitted from one credential account.
required: false
Expand Down
55 changes: 55 additions & 0 deletions .github/workflows/actions-queue-health.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: GitHub Actions queue health

on:
schedule:
- cron: "7 * * * *"

concurrency:
group: github-actions-queue-health
cancel-in-progress: false

permissions:
contents: read
actions: read

jobs:
collect:
name: Collect exact-head queue evidence
runs-on: ubuntu-24.04
timeout-minutes: 30
permissions:
contents: read
actions: read
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout trusted queue-health source
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Collect read-only repository and runner evidence
env:
GH_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN }}
run: |
if [ -z "${GH_TOKEN:-}" ]; then
echo "::error::PR_REVIEW_MERGE_TOKEN or OPENCODE_APPROVE_TOKEN is required for cross-repository queue reads."
exit 1
fi
echo "::add-mask::$GH_TOKEN"
python3 scripts/ci/actions_queue_health.py \
--allowlist config/actions_queue_health_repositories.json \
--output-json "$RUNNER_TEMP/actions-queue-health.json" \
--output-html "$RUNNER_TEMP/actions-queue-health.html"

- name: Upload queue-health evidence
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: github-actions-queue-health-${{ github.run_id }}
path: |
${{ runner.temp }}/actions-queue-health.json
${{ runner.temp }}/actions-queue-health.html
if-no-files-found: error
17 changes: 14 additions & 3 deletions .github/workflows/agent-mention-noema-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,26 @@ on:
repository_dispatch:
types: [agent-mention-noema]

concurrency:
# Workflow-level admission, for the same reason strix.yml, noema-review.yml,
# opencode-review.yml and opencode-review-dispatch.yml carry theirs at this level:
# a job-level group is never evaluated while the whole run waits behind the
# organization job ceiling, so a superseded mention keeps its queue slot until a
# runner frees up and only then cancels. At workflow level the older run is
# coalesced while both are still queued, which is where the slot is actually held.
# This workflow has a single job, so the group lives here and nowhere else --
# every workflow in this repository that carries a group at both levels
# (strix.yml, opencode-review-dispatch.yml) gives the two levels DIFFERENT names,
# because a job requesting the group its own run already holds would wait on itself.
group: agent-mention-noema-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
validate-and-forward:
if: github.repository == 'ContextualWisdomLab/.github'
concurrency:
group: agent-mention-noema-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
Expand Down
17 changes: 14 additions & 3 deletions .github/workflows/agent-mention-opencode-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,26 @@ on:
repository_dispatch:
types: [agent-mention-opencode]

concurrency:
# Workflow-level admission, for the same reason strix.yml, noema-review.yml,
# opencode-review.yml and opencode-review-dispatch.yml carry theirs at this level:
# a job-level group is never evaluated while the whole run waits behind the
# organization job ceiling, so a superseded mention keeps its queue slot until a
# runner frees up and only then cancels. At workflow level the older run is
# coalesced while both are still queued, which is where the slot is actually held.
# This workflow has a single job, so the group lives here and nowhere else --
# every workflow in this repository that carries a group at both levels
# (strix.yml, opencode-review-dispatch.yml) gives the two levels DIFFERENT names,
# because a job requesting the group its own run already holds would wait on itself.
group: agent-mention-opencode-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
validate-and-forward:
if: github.repository == 'ContextualWisdomLab/.github'
concurrency:
group: agent-mention-opencode-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
Expand Down
57 changes: 52 additions & 5 deletions .github/workflows/agent-review-runtime-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,21 +11,31 @@ on:
- "tests/test_noema_two_phase_handoff.py"
- "tests/test_noema_refreshed_app_identity.py"
- "tests/test_noema_token_lifetime_stale_run_contract.py"
- "scripts/ci/noema_review_document.py"
- "scripts/ci/noema_hwp_mcp_reader.mjs"
- "scripts/ci/noema-document-reader/package.json"
- "scripts/ci/noema-document-reader/package-lock.json"
- "tests/test_noema_document_review_context.py"
- "docs/doctoring/noema-review-token-lifetime.md"
- "docs/product-technical-gap-baseline.md"
- ".github/workflows/opencode-review-dispatch.yml"
- "scripts/ci/ensure_rust_llvm19.sh"
- "tests/test_opencode_rust_coverage_toolchain_contract.py"
- "scripts/ci/materialize_base_javascript_packages.py"
- "tests/test_javascript_materializer_docstrings.py"
- "tests/test_pr_review_autofix_nvidia_nim_contract.py"
- "docs/doctoring/opencode-rust-coverage-runtime-boundary.md"
- ".github/workflows/strix.yml"
- "docs/doctoring/strix-legal-git-paths.md"
- "docs/doctoring/strix-model-behavior-error.md"
- "docs/doctoring/strix-quality-timeout-fixtures.md"
- "docs/doctoring/strix-evidence-binding-2159-2168.md"
- "scripts/ci/strix_quick_gate.sh"
- "scripts/ci/strix_evidence_binding.py"
- "scripts/ci/test_strix_quick_gate.sh"
- "tests/test_docs_only_pr_runner_admission.py"
- "tests/test_strix_changed_path_policy.py"
- "tests/test_strix_evidence_binding.py"
- "tests/test_strix_model_behavior_error.py"
- "tests/test_strix_nvidia_nim_not_found_fallback.py"
- "tests/test_strix_workflow_dependency_hashes.py"
Expand Down Expand Up @@ -101,6 +111,8 @@ on:
- "docs/doctoring/exact-artifact-sbom-quality-runner-consolidation-20260903.md"
- "CHANGELOG.d/20260903-exact-artifact-quality-runner-consolidation.md"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-noema-document-ci.txt"
- "requirements-noema-document-ci-hashes.txt"

# PR validation only: a new head cancels only an older run of this workflow
# for the same repository and pull request.
Expand Down Expand Up @@ -136,7 +148,9 @@ jobs:
with:
python-version: "3.14"
cache: pip
cache-dependency-path: requirements-opencode-review-ci-hashes.txt
cache-dependency-path: |
requirements-opencode-review-ci-hashes.txt
requirements-noema-document-ci-hashes.txt

- name: Select affected contract suites
id: affected_suites
Expand Down Expand Up @@ -179,23 +193,33 @@ jobs:
tests/test_noema_two_phase_handoff.py|\
tests/test_noema_refreshed_app_identity.py|\
tests/test_noema_token_lifetime_stale_run_contract.py|\
scripts/ci/noema_review_document.py|\
scripts/ci/noema_hwp_mcp_reader.mjs|\
scripts/ci/noema-document-reader/package.json|\
scripts/ci/noema-document-reader/package-lock.json|\
tests/test_noema_document_review_context.py|\
docs/doctoring/noema-review-token-lifetime.md)
noema_suite=true
;;
.github/workflows/opencode-review-dispatch.yml|\
scripts/ci/ensure_rust_llvm19.sh|\
tests/test_opencode_rust_coverage_toolchain_contract.py|\
scripts/ci/materialize_base_javascript_packages.py|\
tests/test_javascript_materializer_docstrings.py|\
docs/doctoring/opencode-rust-coverage-runtime-boundary.md)
opencode_suite=true
;;
.github/workflows/strix.yml|\
docs/doctoring/strix-legal-git-paths.md|\
docs/doctoring/strix-model-behavior-error.md|\
docs/doctoring/strix-quality-timeout-fixtures.md|\
docs/doctoring/strix-evidence-binding-2159-2168.md|\
scripts/ci/strix_quick_gate.sh|\
scripts/ci/strix_evidence_binding.py|\
scripts/ci/test_strix_quick_gate.sh|\
tests/test_docs_only_pr_runner_admission.py|\
tests/test_strix_changed_path_policy.py|\
tests/test_strix_evidence_binding.py|\
tests/test_strix_model_behavior_error.py|\
tests/test_strix_nvidia_nim_not_found_fallback.py|\
tests/test_strix_workflow_dependency_hashes.py|\
Expand All @@ -206,6 +230,10 @@ jobs:
noema_suite=true
opencode_suite=true
;;
requirements-noema-document-ci.txt|\
requirements-noema-document-ci-hashes.txt)
noema_suite=true
;;
.github/workflows/pr-review-merge-scheduler.yml)
queue_suite=true
review_repair_suite=true
Expand Down Expand Up @@ -321,7 +349,13 @@ jobs:
if: steps.affected_suites.outputs.noema == 'true' || steps.affected_suites.outputs.opencode == 'true' || steps.affected_suites.outputs.review_repair == 'true' || steps.affected_suites.outputs.exact_artifact == 'true'
run: >-
python -m pip install --disable-pip-version-check --require-hashes
-r requirements-opencode-review-ci-hashes.txt
-r requirements-opencode-review-ci-hashes.txt -r requirements-noema-document-ci-hashes.txt

- name: Install exact Noema document dependencies
if: steps.affected_suites.outputs.noema == 'true'
run: >-
python -m pip install --disable-pip-version-check --require-hashes --no-deps
-r requirements-noema-document-ci-hashes.txt

- name: Verify Noema token-lifetime contracts
if: steps.affected_suites.outputs.noema == 'true'
Expand All @@ -331,13 +365,15 @@ jobs:
tests/test_noema_reviewer_token_lifetime.py \
tests/test_noema_two_phase_handoff.py \
tests/test_noema_refreshed_app_identity.py \
tests/test_noema_token_lifetime_stale_run_contract.py
tests/test_noema_token_lifetime_stale_run_contract.py \
tests/test_noema_document_review_context.py
python -m compileall -q \
.github/actions/noema-review/two_phase.py \
tests/test_noema_reviewer_token_lifetime.py \
tests/test_noema_two_phase_handoff.py \
tests/test_noema_refreshed_app_identity.py \
tests/test_noema_token_lifetime_stale_run_contract.py
tests/test_noema_token_lifetime_stale_run_contract.py \
tests/test_noema_document_review_context.py

- name: Verify OpenCode Rust coverage toolchain contract
if: steps.affected_suites.outputs.opencode == 'true'
Expand All @@ -346,6 +382,13 @@ jobs:
python -m pytest -q tests/test_opencode_rust_coverage_toolchain_contract.py
python -m compileall -q tests/test_opencode_rust_coverage_toolchain_contract.py

- name: Verify JavaScript materializer documentation contract
if: steps.affected_suites.outputs.opencode == 'true'
run: |
set -euo pipefail
python -m pytest -q tests/test_javascript_materializer_docstrings.py
python -m compileall -q scripts/ci/materialize_base_javascript_packages.py tests/test_javascript_materializer_docstrings.py

- name: Verify exact-head path policy and syntax
if: steps.affected_suites.outputs.strix == 'true'
env:
Expand All @@ -357,13 +400,16 @@ jobs:
python -m pytest -q \
tests/test_docs_only_pr_runner_admission.py \
tests/test_strix_changed_path_policy.py \
tests/test_strix_evidence_binding.py \
tests/test_strix_model_behavior_error.py \
tests/test_strix_nvidia_nim_not_found_fallback.py \
tests/test_strix_workflow_dependency_hashes.py \
tests/test_strix_quality_timeout_fixture_budget.py
bash scripts/ci/test_strix_quick_gate.sh
python -m compileall -q \
scripts/ci/strix_evidence_binding.py \
tests/test_strix_changed_path_policy.py \
tests/test_strix_evidence_binding.py \
tests/test_strix_model_behavior_error.py \
tests/test_strix_nvidia_nim_not_found_fallback.py \
tests/test_strix_workflow_dependency_hashes.py \
Expand Down Expand Up @@ -425,7 +471,8 @@ jobs:
run: |
python -m coverage run \
--branch \
-m pytest --import-mode=importlib tests/test_organization_commercial_readiness_loop*.py -q
-m pytest --import-mode=importlib \
tests/test_organization_commercial_readiness_loop*.py -q
python -m coverage report \
--include='scripts/ci/organization_commercial_readiness_loop.py' \
--show-missing \
Expand Down
Loading