-
Notifications
You must be signed in to change notification settings - Fork 0
feat(automation): run semantic-data-portal hourly NVIDIA NIM review repair #1082
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
ddc024f
379e6ec
9e8e93e
571bc1f
7b17d68
dbfdbbf
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| name: semantic-data-portal Hourly Review Repair | ||
|
|
||
| on: | ||
| schedule: | ||
| # Minute 59 avoids Clearfolio (23), DiskSage (37), fast-mlsirm (49), | ||
| # BandScope (53), naruon (11), Inkspan (47), orchestrator (17), | ||
| # Wardnet (7), codec-carver (5), pg-erd-cloud (13), Keyverse (29), | ||
| # noema (19), Scopeweave (31), Appguardrail (41), and newsdom-api (43). | ||
| - cron: "59 * * * *" | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||
|
|
||
| concurrency: | ||
| group: semantic-data-portal-hourly-review-repair | ||
| # A later heartbeat must not cancel in-flight catalog or governance RCA. | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| dispatch-review-repair: | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| uses: ./.github/workflows/pr-review-fix-scheduler.yml | ||
| with: | ||
| target_repository: ContextualWisdomLab/semantic-data-portal | ||
| base_branch: main | ||
| max_prs: "50" | ||
| max_dispatches: "1" | ||
| retry_hours: "2" | ||
| secrets: | ||
| PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }} | ||
| OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -38,6 +38,12 @@ only established scheduler credentials, and grants job-scoped | |
| 16. It names `ContextualWisdomLab/nonnest2` and protected `master`, maps | ||
| only established scheduler credentials, and grants job-scoped | ||
| `id-token: write`. The reusable engine stays product-neutral. | ||
| ## semantic-data-portal hourly caller | ||
|
Comment on lines
40
to
+41
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Missing blank line before new ARCHITECTURE.md heading The new Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| `semantic-data-portal-hourly-review-repair.yml` is a thin, read-only caller | ||
| at minute 59. It names `ContextualWisdomLab/semantic-data-portal` and | ||
| protected `main`, maps only established scheduler credentials, and grants | ||
| job-scoped `id-token: write`. The reusable engine stays product-neutral. | ||
|
|
||
| ## Hourly NVIDIA NIM repair gate | ||
|
|
||
|
|
@@ -66,9 +72,10 @@ The worker checks out helpers at `${{ github.sha }}` so a later default-branch | |
| push cannot replace privileged scripts after dispatch (CWE-367). Repair binds | ||
| `NVIDIA_NIM_API_KEY`, never `COPILOT_GITHUB_TOKEN`. | ||
|
|
||
| Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, and | ||
| fast-mlsirm at minute 49. Each caller is read-only, dispatches at most one | ||
| repair, and delegates all privileged logic to the same sealed scheduler. | ||
| Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, | ||
| fast-mlsirm at minute 49, and semantic-data-portal at minute 59. Each | ||
| caller is read-only, dispatches at most one repair, and delegates all | ||
| privileged logic to the same sealed scheduler. | ||
|
|
||
| ## Exact-artifact SBOM attestation | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,143 @@ | ||
| # semantic-data-portal hourly review-repair caller | ||
|
|
||
| 검토 기준일: **2026-08-17** | ||
|
|
||
| ## Decision | ||
|
|
||
| ContextualWisdomLab operates one protected hourly caller for | ||
| `ContextualWisdomLab/semantic-data-portal` (SDP — the higher ontology / | ||
| catalog / governance plane above naruon's document KG). The caller runs | ||
| at minute 59, delegates to the product-neutral central review-fix | ||
| scheduler, inspects at most 50 open pull requests targeting protected | ||
| `main`, and dispatches at most one bounded repair per heartbeat. | ||
|
|
||
| A paying buyer of the catalog plane would feel live semantic-data-portal | ||
| pull requests stalling while hourly NVIDIA NIM repair scanned only | ||
| Clearfolio, DiskSage, and fast-mlsirm. Live heads such as | ||
| ContextualWisdomLab/semantic-data-portal#61 (DiskSage catalog preview), | ||
| ContextualWisdomLab/semantic-data-portal#59 (DiskSage catalog ingestion), | ||
| ContextualWisdomLab/semantic-data-portal#58 (Keyverse claim aliases), | ||
| and ContextualWisdomLab/semantic-data-portal#35 (SQL source-table | ||
| allowlist) target `main` and never enter those other callers. | ||
|
|
||
| The caller does not implement review or mutation logic itself. | ||
| semantic-data-portal remains standalone; naruon owns the document KG and | ||
| imports SDP as a module without owning its catalog validators. | ||
| Privileged automation stays in `ContextualWisdomLab/.github`. | ||
|
|
||
| ## Root-cause analysis and remediation feasibility | ||
|
|
||
| The reusable worker performs exact-head root-cause analysis and tests | ||
| remediation feasibility before it edits. The reusable worker must: | ||
|
|
||
| 1. Refetch the exact live head, base, reviews, checks, changed paths, and | ||
| writer state. | ||
| 2. Establish the causal chain rather than repeat the terminal symptom. | ||
| 3. Enumerate materially distinct minimal remedies. | ||
| 4. Reject remedies that lack writer authority, cross sealed paths, require | ||
| unavailable credentials or protected-setting changes, violate stack | ||
| order, cannot be verified, or do not alter the diagnosed cause. | ||
| 5. Dispatch at most one feasible repair. Otherwise leave the tree | ||
| unchanged. | ||
|
|
||
| A queued or pending check remains a merge blocker but is not itself a | ||
| code finding. The independent non-author approval remains an external | ||
| authorization gate and is never synthesized by the repair worker. The | ||
| worker cannot approve, merge, release, resolve review findings by | ||
| inference, change protection, or manufacture passing checks. | ||
|
|
||
| ## Cadence and concurrency | ||
|
|
||
| The caller uses a single concurrency group and `cancel-in-progress: false`. | ||
| This preserves an in-flight bounded RCA instead of discarding catalog or | ||
| governance evidence when the next hourly heartbeat arrives. The reusable | ||
| scheduler cancels only its own superseded short queue scan. | ||
|
|
||
| The caller sets a **two-hour same-head retry floor**. Central OpenCode and | ||
| NVIDIA NIM work, plus catalog-ontology or SQL-gate analysis, can | ||
| legitimately approach two hours. An hourly redispatch of the same | ||
| unchanged head would create duplicate writer pressure rather than faster | ||
| remediation. | ||
|
|
||
| GitHub scheduled workflows can be delayed under load and execute only | ||
| from the default branch. The cron expression is a heartbeat, not a | ||
| real-time SLA. | ||
|
|
||
| ## Credential and model boundary | ||
|
|
||
| The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants | ||
| the reusable job `id-token: write` so the central scheduler can mint the | ||
| OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent | ||
| (GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and | ||
| `OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives | ||
| `NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250 | ||
| forbids executing the caller with write or model privileges it does not | ||
| need (MITRE, 2026). | ||
|
|
||
| Model execution remains inside the central worker. The model credential | ||
| is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or | ||
| forward it. | ||
|
|
||
| Before protected-main activation, the repository variable | ||
| `OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact | ||
| `ContextualWisdomLab/semantic-data-portal` target. Missing or mismatched | ||
| configuration fails before mutation credential materialization. | ||
|
|
||
| ## Security, standalone operation, and modularity | ||
|
|
||
| The caller adds no semantic-data-portal runtime dependency, database | ||
| object, network endpoint, tenant authority, or product credential. | ||
| semantic-data-portal continues to run as a standalone catalog and | ||
| governance plane. Naruon and other CWL services may consume its ontology | ||
| output, but they cannot weaken its exact-head, approval, or security | ||
| gates. | ||
|
|
||
| ## Verification and rollback | ||
|
|
||
| Machine-checkable contracts require the exact target/base, minute 59 | ||
| cadence, non-cancelling single-flight group, one dispatch, two-hour | ||
| retry floor, explicit secret mapping, read-only contents plus job-scoped | ||
| `id-token: write`, focused path-filter coverage, and absence of model or | ||
| Copilot credentials. Independent `pull_request`, `push`, and `compileall` | ||
| path blocks must each name the caller, doctoring, or contract they own. | ||
|
|
||
| After source integration, closure requires a scheduled or manual | ||
| protected-main consumer run proving the exact semantic-data-portal | ||
| repository and `main` base. Source checks alone are not | ||
| protected-main operational acceptance. Merge still requires zero | ||
| unresolved valid findings and a qualifying independent non-author | ||
| approval. | ||
|
|
||
| Rollback removes the semantic-data-portal caller, its focused test, | ||
| doctoring, and central path-filter/documentation entries. It must not | ||
| remove scheduler dispatch validation or affect independent product | ||
| callers. | ||
|
|
||
| ## APA 7th references | ||
|
|
||
| GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule | ||
|
|
||
| GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August | ||
| 17, 2026, from | ||
| https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows | ||
|
|
||
| GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token | ||
|
|
||
| MITRE. (2026). *CWE-250: Execution with unnecessary privileges*. | ||
| https://cwe.mitre.org/data/definitions/250.html | ||
|
|
||
| National Institute of Standards and Technology. (2022). *Secure software | ||
| development framework (SSDF) version 1.1: Recommendations for mitigating | ||
| the risk of software vulnerabilities* (NIST Special Publication 800-218). | ||
| https://doi.org/10.6028/NIST.SP.800-218 | ||
|
|
||
| NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.nvidia.com/nim/large-language-models/latest/ | ||
|
|
||
| OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, | ||
| from https://opencode.ai/docs/ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Cron collision comment is internally inconsistent
The
cron: "59 * * * *"comment at semantic-data-portal-hourly-review-repair.yml lists a set of minutes to avoid that omits several real callers in this repo (OriginWeave 10, nonnest2 16, quarantine-sandbox 14, github 21, accounting 27) and instead attributes minute 43 tonewsdom-apiwhen it is actually owned bygovernance-risk-compliance. This is only an explanatory comment and does not affect scheduling — minute 59 is genuinely free (confirmed against all existing caller crons and the reserved-slot comment inoriginweave-hourly-review-repair.yml). Worth tidying for accuracy but not a functional issue.Was this helpful? React with 👍 or 👎 to provide feedback.