Skip to content

Document CodeQL canary proof requirements - #30

Draft
Shepdesign with Copilot wants to merge 2 commits into
mainfrom
copilot/prove-canary-non-negotiable-5-gate
Draft

Shepdesign with Copilot wants to merge 2 commits into
mainfrom
copilot/prove-canary-non-negotiable-5-gate

Conversation

Copilot AI commented Sep 30, 2026 •

Copy link
Copy Markdown

The gate’s unit tests verify SARIF handling, but real Swift analysis has not yet completed, leaving both query coverage and clean-run SARIF attestation unverified. The CodeQL workflow documentation now records what must be observed before the gate can be considered proven.

  • Verification sequence: Require multiple successful analyses of a non-empty Swift database and confirm the SARIF declares the gate rule; then run and remove an unmarked URLSession canary, verifying the gate fails at its source location and subsequently returns green.
  • Merge protection: Note that Analyze (swift) must be configured as a required check in repository settings to block merges.
  • Current status: The canary remains unproven; the latest main-branch run failed before analyze.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

Co-authored-by: Shepdesign <97276735+Shepdesign@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:52
Copilot AI changed the title [WIP] Add test to prove canary for non-negotiable-5 gate Document CodeQL canary proof requirements Sep 30, 2026
Copilot AI requested a review from Shepdesign September 30, 2026 18:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fixes #27 would close the issue while its required verification remains incomplete.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)

# Nothing here needs changing when it is fixed upstream: the job simply starts
# passing. PR #22 has the investigation's history; where it and this comment
# disagree, this comment is the later measurement and wins.
# Do not call the gate proven yet. It has never analyzed real Swift successfully:

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prove the canary: the non-negotiable-5 gate is tested, not proven

3 participants