-
Notifications
You must be signed in to change notification settings - Fork 0
fix(governance): automate ruleset owner-plane reconciliation #1644
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
seonghobae
wants to merge
234
commits into
main
Choose a base branch
from
fix/ruleset-owner-plane-reconciler
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
234 commits
Select commit
Hold shift + click to select a range
c11fb65
fix(governance): require central reviews for stacked prs
seonghobae ab65fcc
docs(governance): record restored approval contract
seonghobae bc2c93a
docs(governance): refresh stacked review rollout ledger
seonghobae 501fe54
fix(router): permit exact-head dispatch enqueue
seonghobae aa63517
fix(router): preserve every trusted mention with least privilege
seonghobae a7aeb56
fix(workflows): remove unsupported concurrency queue
seonghobae c18d8c0
Merge remote-tracking branch 'refs/remotes/origin/main' into fix/stac…
seonghobae 158f090
fix(governance): enforce exact central ref scope
seonghobae b873e71
fix(router): use reviewer token for sibling acknowledgements
seonghobae a56bf7f
fix(strix): classify caido sandbox startup failure
seonghobae 33b85a8
fix(strix): require trusted caido traceback marker
seonghobae 08f0f04
Merge main into stacked PR governance fix
seonghobae b628e88
fix(governance): preserve proposal branch create transition
seonghobae cf94d18
chore(governance): synchronize protected main
seonghobae f0bef61
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 8923bad
fix(ci): refresh audit lock and scheduler assertion
seonghobae d6be648
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] c6e1ba3
chore(governance): restore canonical pip lock ownership
seonghobae 6bf0447
fix(governance): avoid misleading multi-rule drift
seonghobae 5d64102
ci: refresh dependency and scheduler contracts
seonghobae 4eedfa4
Merge remote-tracking branch 'origin/main' into codex/pr1176-restack
seonghobae 5b2a216
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 49f6988
merge(main): retain only proposal-branch governance repair
seonghobae 2f16ea9
merge(main): refresh proposal-branch governance repair
seonghobae cc941b2
merge(main): refresh create-transition audit after Strix hotfix
seonghobae 55a6a79
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 27a686b
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae 366fe2f
merge: converge governance create-transition owner with protected main
seonghobae 437ea84
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] d6bb951
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 5486790
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 2701cf9
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 8664a7c
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 36d4fec
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae 6b09d65
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae 31e00c1
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae 940511d
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] f94292a
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 482d4c0
Merge protected main into proposal-branch governance repair
seonghobae 2a9d115
fix(governance): audit owner repository review ruleset
seonghobae 4ae3c61
fix(governance): reject hidden ruleset drift
seonghobae d222401
fix(governance): audit organization bypass actors
seonghobae 0b0a45b
fix(governance): fail closed on missing bypass evidence
seonghobae 63ca5e7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 8ea2ec5
Retrigger required checks against refreshed main (no new main commits…
claude 8dea465
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] ce108e7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 8a7c5b1
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] faf1dd6
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 36ade87
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 53f99d7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae dc8d7d9
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae 718ae19
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae c1b31b2
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 2bc22cc
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 73b5b28
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 135f16f
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 5acc547
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] a14822c
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 3407ca6
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] df92a2e
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] d33dd13
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] d435f88
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae 4d88d45
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 1141b31
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] ed314f6
test(governance): define solo-maintainer ruleset RED
seonghobae a815b54
ci(governance): run focused solo-maintainer contract
seonghobae 3830a7d
fix(governance): align ruleset audit to solo maintainer
seonghobae f01d2cb
test(governance): rebaseline solo-maintainer ruleset policy
seonghobae 260705b
test(governance): reject synthetic required reviewers
seonghobae 1f0d0e8
ci(governance): exercise synthetic-reviewer RED
seonghobae 033d6ec
fix(governance): reject synthetic required reviewers
seonghobae 1c9c831
test(governance): require executable ruleset regressions
seonghobae 06e1ba2
fix(governance): execute full focused ruleset suite
seonghobae c3a0571
test(governance): detach temporary proof from permanent suite
seonghobae 2b381e1
fix(governance): pin focused contract Python
seonghobae 3ec4abf
ci(governance): move focused ruleset contract off saturated latest queue
seonghobae 81a7afb
ci(governance): retire proven focused ruleset contract lane
seonghobae 29f004d
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 66757ec
ci(governance): restore unproven focused contract lane
seonghobae c52470b
test(governance): cover complete ruleset drift evidence
seonghobae a9505c3
fix(governance): reject undeclared ruleset controls
seonghobae c3ec79a
fix(governance): report all fetched ruleset drift
seonghobae d1c0b7c
ci(governance): execute completeness regressions
seonghobae c2ab699
docs(governance): align rollout with solo-maintainer policy
seonghobae 49ebfae
test(governance): pin focused proof interpreter
seonghobae 1bd407d
fix(governance): restore Python 3.14 proof runtime
seonghobae 76516f4
fix(governance): run focused contract on explicit runner
seonghobae af04bac
docs(governance): preserve regression fixture history
seonghobae 63609f2
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 3156622
ci(governance): allow exact-head focused redispatch
seonghobae 74c0148
test(governance): reproduce malformed merge-method audit crash
seonghobae 9b5d822
test(governance): reject malformed merge methods
seonghobae b3c2f6d
ci(governance): repair malformed merge-method finding on exact head
seonghobae ce752a4
fix(governance): reject malformed merge-method payloads
seonghobae 7e82462
chore(governance): retire source-fix helper
seonghobae 2fb3a48
chore(governance): retire focused proof workflow
seonghobae a4b817b
chore(governance): integrate current main into ruleset writer
seonghobae 5d1e416
fix(governance): retire stale temporary-workflow regression
seonghobae ed3b562
chore(governance): integrate current main after queue repair
seonghobae 5c46858
chore(governance): integrate hourly queue-pressure repair
seonghobae 15ce91c
chore(governance): integrate required-review runner pin
seonghobae 214b0bd
fix(governance): preserve protected-main review runner repair
seonghobae a53b008
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 8977092
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 2bbdcaa
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 6455ecd
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] f77890e
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] 0852bc5
Merge current main into solo-maintainer governance writer
seonghobae a6d169d
Merge current main into solo-maintainer governance writer
seonghobae 9a33ecc
chore: preserve current label taxonomy
seonghobae 37f7f77
chore: preserve current repository metadata
seonghobae 8f66c9a
docs: preserve current public-surface reconciliation
seonghobae c69b254
test: preserve current label taxonomy contract
seonghobae a001ec2
test: preserve current repository metadata contract
seonghobae 48d9772
chore: restore exact protected-main metadata blobs
seonghobae 8339b9b
test: reject code-owner review in solo-maintainer rulesets
seonghobae 2887bb6
fix: reject code-owner approval deadlocks
seonghobae fbc90b3
Merge dedicated metadata credential into governance writer
seonghobae 0097f93
Merge current protected main into governance writer
seonghobae 9457e66
fix(governance): preserve current-main Pingora evidence
seonghobae 5c684d8
Merge current protected main into governance writer
seonghobae 65be10b
fix(governance): preserve current-main NIM retirement
seonghobae 12076f9
Merge protected main into solo-maintainer ruleset writer
seonghobae 74166cf
test(governance): define owner-plane reconciliation contract
seonghobae 946e15c
feat(governance): add fail-closed ruleset reconciler
seonghobae 1966b12
config(governance): bind exact ruleset targets
seonghobae fc95c34
ci(governance): gate ruleset reconciliation in owner plane
seonghobae 4e3f6ae
docs(governance): record owner-plane reconciliation evidence
seonghobae b77dd53
test(governance): reproduce stale-main and non-CAS review findings
seonghobae ca8a42c
fix(governance): bind reconciliation to current protected main
seonghobae de0e338
fix(governance): supersede stale owner-plane apply runs
seonghobae 10381a6
docs(governance): record ruleset PUT race boundary
seonghobae f7c5537
test(governance): cover protected-main reconciliation guard
seonghobae 019ff9f
test(governance): cover guarded multi-target forwarding
seonghobae 61e4587
test(governance): reproduce hidden ruleset history collision
seonghobae 8699add
fix(governance): recover hidden ruleset write collisions
seonghobae 2865291
test(governance): close history collision coverage
seonghobae 1811a7e
docs(governance): trace ruleset history collision recovery
seonghobae c4f1ec1
merge(governance): stack canonical solo-maintainer audit
seonghobae b1b3c14
fix(governance): serialize privileged ruleset writes
seonghobae 98ae2ed
test(governance): cover identity-edit recovery and critical section
seonghobae 744e1bb
chore(governance): stage exact PR1644 round-two repair
seonghobae 5b9609b
chore(governance): add one-shot PR1644 round-two repair
seonghobae 3042234
chore(governance): trigger PR1644 round-two repair
seonghobae b033af4
fix(governance): recover concurrent ruleset identity races
seonghobae e0a1548
test(governance): cover second collision-recovery race
seonghobae 570b5a7
ci(governance): validate collision recovery without idle hourly satur…
seonghobae 41b0c97
test(governance): make code-owner policy explicit in passing fixture
seonghobae 1469070
test(governance): align stacked audit fixture with canonical policy
seonghobae 2403654
test(governance): retire disabled hourly validation contract
seonghobae 6b07d32
docs(governance): record collision-chain and queue-safe owner-plane c…
seonghobae a62f5fc
chore(governance): remove completed round-two writer workflow
seonghobae 83dbf5a
chore(governance): remove completed round-two trigger
seonghobae 85c5832
chore(governance): remove completed round-two repair helper
seonghobae 437a782
merge(governance): integrate current protected main without losing ru…
seonghobae 0dea7d1
test(governance): pin unresolved owner-plane review regressions
seonghobae 8273fb5
fix(governance): close owner-plane review gaps
seonghobae 4beeb69
merge(governance): restack owner-plane reconciler on canonical audit
seonghobae bf1fe97
test(governance): keep main-guard mock aligned with recovery contract
seonghobae 44b4ea4
merge(governance): integrate current protected main without losing ru…
seonghobae f66d8d3
test(governance): cover ambiguous ruleset PUT timeouts
seonghobae b3b095e
fix(governance): reconcile ambiguous ruleset timeouts
seonghobae a0cda3c
test(governance): require guarded manual mutation
seonghobae 5e74e14
ci(governance): execute timeout regression suite
seonghobae 1400920
docs(governance): record timeout and manual guard contract
seonghobae 07df033
test(governance): cover timeout recovery edges
seonghobae ed0069c
merge: integrate current protected main into ruleset reconciler
seonghobae 24802de
merge: refresh canonical solo-maintainer audit stack
seonghobae 3aaa635
test(governance): cover ambiguous failures and runtime budget
seonghobae b70315e
test(governance): require ambiguous failure confirmation path
seonghobae 5d5562e
fix(governance): settle ambiguous writes fail-closed
seonghobae f1c190a
ci(governance): budget and observe owner-plane recovery
seonghobae ae7d98e
docs(governance): close third-round owner-plane findings
seonghobae 25fa97d
test(governance): include code-owner false in merge-method fixtures
seonghobae 92049ab
test(governance): repair Python 3.12 loader and workflow parsing
seonghobae efe18ae
test(governance): align history fixtures with editable PUT contract
seonghobae 0494f5a
test(governance): expect code-owner drift on malformed review settings
seonghobae e639e61
test(governance): project live state before recovery guard
seonghobae 71bdea2
test(governance): cover fail-closed owner-plane edges
seonghobae 7508c39
test(governance): cover empty settlement fail-closed path
seonghobae b6c64db
test(governance): make ambiguous live state genuinely drift
seonghobae d0ac1c9
merge(main): preserve current control-plane repairs in ruleset reconc…
seonghobae 40fe499
fix(governance): project required review safety controls
seonghobae c61d9de
test(governance): reproduce delayed recovery duplicate PUT
seonghobae 40a9ce7
test(governance): forbid blind recovery PUT retry
seonghobae e9260c1
fix(governance): enforce review controls and main guard
seonghobae b26e0ba
fix(governance): settle ambiguous recovery before retry
seonghobae c4b52e5
fix(governance): budget ambiguous recovery settlement
seonghobae eb74eef
fix(governance): budget full recovery settlement window
seonghobae 663ccfc
docs(governance): record bounded recovery settlement budget
seonghobae c49aae1
test(governance): cover bounded recovery and verify-only path
seonghobae 45990e9
test(governance): preserve provenance in collision harness
seonghobae 876697f
test(governance): reproduce intervening-version settlement race
seonghobae 1486443
chore(governance): run one-shot intervening-settlement repair
seonghobae 978c9f0
chore(governance): retire failed one-shot settlement repair
seonghobae de0b577
chore(governance): stage one-shot settlement source repair
seonghobae 131832d
chore(governance): execute one-shot settlement source repair
seonghobae d840bc9
chore(governance): retire unusable one-shot workflow
seonghobae e370c03
chore(governance): remove staged one-shot repair helper
seonghobae e833930
fix(governance): settle delayed writes across intervening versions
seonghobae 48b20bd
test(governance): regress ambiguous recovery runtime budget
seonghobae 63534b3
fix(governance): cover full recovery settlement runtime
seonghobae bfd8293
fix(governance): count recovery history reads in runtime budget
seonghobae 563691f
merge: preserve current protected main in governance writer
seonghobae 1924225
test(governance): require full hosted-job recovery headroom
seonghobae 2895cf9
fix(governance): reserve full hosted-runner recovery window
seonghobae 60bf2cb
docs(governance): align runtime record with hosted limit
seonghobae 7350611
fix(governance): preserve fail-closed settlement diagnostics
seonghobae fd8a315
test(governance): regress post-PUT stale-main cleanup
seonghobae f0abca0
test(governance): gate post-PUT cleanup regression
seonghobae bc8f758
fix(governance): finish post-PUT collision cleanup
seonghobae cf61c75
test(governance): cover successful post-PUT cleanup
seonghobae 1ca11b4
docs(governance): record post-PUT compensation boundary
seonghobae cd0a299
chore(governance): stage timeout-fixture source fix
seonghobae 9509748
test(governance): align ambiguous PUT settlement fixture
github-actions[bot] 6e92cf9
ci(governance): run one-shot review regression repair
seonghobae ff5fc4f
chore(governance): remove blocked one-shot repair workflow
seonghobae 061a239
test(governance): prove timeout settlement contract
seonghobae d5142b9
test(governance): align history settlement diagnostic
seonghobae ef634b3
test(governance): prove delayed recovery settlement interval
seonghobae cb27beb
test(governance): cover every permanent focused suite
seonghobae 0f3530c
test(governance): align current collision diagnostics
seonghobae 93a9b95
test(governance): distinguish newer recovery history
seonghobae 4b0b1e3
test(governance): cover post-settlement recovery race
seonghobae f43ea2a
merge(main): incorporate protected queue-hygiene changes into ruleset…
seonghobae 25ef945
merge(main): preserve completed registry-retirement cleanup
seonghobae 8539892
merge(main): preserve current OpenCode stale-dispatch repair
seonghobae 7698f40
merge(main): preserve current scheduler cadence on governance writer
seonghobae d0eecd6
merge(main): preserve current scheduler repairs on ruleset writer
seonghobae 8f95e06
merge(main): preserve current scheduler head guard on ruleset writer
seonghobae fac1e32
merge(main): preserve current control-plane repairs on ruleset writer
seonghobae 545f315
merge(main): preserve latest control-plane integrations on ruleset wr…
seonghobae 528139f
merge(main): preserve latest OpenCode control-plane repair on ruleset…
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,182 @@ | ||
| name: Ruleset Governance Reconcile | ||
|
|
||
| on: | ||
| pull_request: | ||
| paths: | ||
| - "config/ruleset-governance.json" | ||
| - "scripts/ci/audit_central_required_workflows.py" | ||
| - "scripts/ci/reconcile_ruleset_governance.py" | ||
| - "tests/test_ruleset_governance_reconciliation.py" | ||
| - "tests/test_ruleset_governance_review_regressions.py" | ||
| - "tests/test_ruleset_governance_review_round2.py" | ||
| - "tests/test_ruleset_governance_review_round3.py" | ||
| - "tests/test_ruleset_governance_timeout_regression.py" | ||
| - "tests/test_ruleset_governance_delayed_recovery_regression.py" | ||
| - "tests/test_ruleset_governance_runtime_budget_regression.py" | ||
| - "tests/test_ruleset_governance_post_put_cleanup_regression.py" | ||
| - "tests/test_central_required_workflow_ruleset_audit.py" | ||
| - "tests/test_ruleset_audit_completeness_regression.py" | ||
| - "tests/test_ruleset_merge_method_shape_regression.py" | ||
| - "tests/test_solo_maintainer_ruleset_policy.py" | ||
| - "docs/doctoring/ruleset-owner-plane-reconciliation.md" | ||
| - ".github/workflows/ruleset-governance-reconcile.yml" | ||
| push: | ||
| branches: | ||
| - main | ||
| paths: | ||
| - "config/ruleset-governance.json" | ||
| - "scripts/ci/audit_central_required_workflows.py" | ||
| - "scripts/ci/reconcile_ruleset_governance.py" | ||
| - "tests/test_ruleset_governance_reconciliation.py" | ||
| - "tests/test_ruleset_governance_review_regressions.py" | ||
| - "tests/test_ruleset_governance_review_round2.py" | ||
| - "tests/test_ruleset_governance_review_round3.py" | ||
| - "tests/test_ruleset_governance_timeout_regression.py" | ||
| - "tests/test_ruleset_governance_delayed_recovery_regression.py" | ||
| - "tests/test_ruleset_governance_runtime_budget_regression.py" | ||
| - "tests/test_ruleset_governance_post_put_cleanup_regression.py" | ||
| - "tests/test_central_required_workflow_ruleset_audit.py" | ||
| - "tests/test_ruleset_audit_completeness_regression.py" | ||
| - "tests/test_ruleset_merge_method_shape_regression.py" | ||
| - "tests/test_solo_maintainer_ruleset_policy.py" | ||
|
seonghobae marked this conversation as resolved.
|
||
| - "docs/doctoring/ruleset-owner-plane-reconciliation.md" | ||
| - ".github/workflows/ruleset-governance-reconcile.yml" | ||
|
seonghobae marked this conversation as resolved.
devin-ai-integration[bot] marked this conversation as resolved.
devin-ai-integration[bot] marked this conversation as resolved.
devin-ai-integration[bot] marked this conversation as resolved.
|
||
| workflow_dispatch: | ||
| schedule: | ||
| - cron: "31 * * * *" | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: ruleset-governance-reconcile-${{ github.event_name == 'pull_request' && github.event.pull_request.number || 'owner-plane' }} | ||
| # PR validation may safely supersede itself. Privileged owner-plane runs must | ||
| # finish their PUT + immutable-history verification/recovery critical section; | ||
| # cancelling them after PUT can strand an unverified overwrite. | ||
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | ||
|
seonghobae marked this conversation as resolved.
|
||
|
|
||
| jobs: | ||
| report-disabled: | ||
| if: >- | ||
| github.event_name == 'schedule' && | ||
| vars.CWL_RULESET_RECONCILE_ENABLED != 'true' | ||
| runs-on: ubuntu-slim | ||
| timeout-minutes: 2 | ||
| steps: | ||
| - name: Report disabled owner-plane state | ||
| shell: bash | ||
| run: >- | ||
| echo "Ruleset reconciliation is disabled; provision the protected owner-plane credential and enable variable before live mutation." >> "$GITHUB_STEP_SUMMARY" | ||
|
|
||
| validate: | ||
| # Source/regression drift is already validated on PR, push, and manual runs. | ||
| # A disabled schedule emits only the cheap report-disabled signal above. | ||
| if: >- | ||
| github.event_name != 'schedule' || | ||
| vars.CWL_RULESET_RECONCILE_ENABLED == 'true' | ||
|
devin-ai-integration[bot] marked this conversation as resolved.
|
||
| runs-on: ubuntu-slim | ||
| timeout-minutes: 20 | ||
| steps: | ||
| - name: Harden runner | ||
| uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | ||
| with: | ||
| egress-policy: audit | ||
| - name: Check out exact revision | ||
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| persist-credentials: false | ||
| - name: Verify exact revision | ||
| shell: bash | ||
| run: test "$(git rev-parse HEAD)" = "${{ github.event.pull_request.head.sha || github.sha }}" | ||
| - name: Set up Python | ||
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | ||
| with: | ||
| python-version: "3.12" | ||
| - name: Install hash-locked test tooling | ||
| run: >- | ||
| python -m pip install --disable-pip-version-check --require-hashes | ||
| --only-binary=:all: -r requirements-opencode-review-ci-hashes.txt | ||
| - name: Validate reviewed target manifest | ||
| run: >- | ||
| python scripts/ci/reconcile_ruleset_governance.py | ||
| --manifest config/ruleset-governance.json | ||
| --validate-only | ||
| - name: Prove reconciliation contract at repository quality gates | ||
| env: | ||
| COVERAGE_RCFILE: /dev/null | ||
| run: | | ||
| set -euo pipefail | ||
| python -m coverage run \ | ||
| --branch \ | ||
| --include=scripts/ci/reconcile_ruleset_governance.py \ | ||
| -m pytest -q \ | ||
| tests/test_ruleset_governance_reconciliation.py \ | ||
| tests/test_ruleset_governance_review_regressions.py \ | ||
| tests/test_ruleset_governance_review_round2.py \ | ||
| tests/test_ruleset_governance_review_round3.py \ | ||
| tests/test_ruleset_governance_timeout_regression.py \ | ||
| tests/test_ruleset_governance_delayed_recovery_regression.py \ | ||
| tests/test_ruleset_governance_runtime_budget_regression.py \ | ||
| tests/test_ruleset_governance_post_put_cleanup_regression.py \ | ||
| tests/test_central_required_workflow_ruleset_audit.py \ | ||
| tests/test_ruleset_audit_completeness_regression.py \ | ||
| tests/test_ruleset_merge_method_shape_regression.py \ | ||
| tests/test_solo_maintainer_ruleset_policy.py | ||
| python -m coverage report \ | ||
| --fail-under=100 \ | ||
| --show-missing \ | ||
| --include=scripts/ci/reconcile_ruleset_governance.py | ||
| python -m interrogate \ | ||
| --fail-under 100 \ | ||
| scripts/ci/reconcile_ruleset_governance.py | ||
| git diff --check | ||
|
|
||
| apply: | ||
| if: >- | ||
| github.event_name != 'pull_request' && | ||
| github.ref == 'refs/heads/main' && | ||
| vars.CWL_RULESET_RECONCILE_ENABLED == 'true' | ||
| needs: validate | ||
| runs-on: ubuntu-24.04 | ||
| # Use the full documented GitHub-hosted job execution limit so this workflow | ||
| # cannot impose an earlier timeout on the 128-minute mutation/recovery bound. | ||
| timeout-minutes: 360 | ||
| environment: ruleset-governance-maintenance | ||
| steps: | ||
| - name: Harden runner | ||
| uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 | ||
| with: | ||
| egress-policy: audit | ||
| - name: Check out trusted default branch | ||
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| ref: ${{ github.sha }} | ||
| persist-credentials: false | ||
|
seonghobae marked this conversation as resolved.
|
||
| - name: Verify exact trusted revision | ||
| shell: bash | ||
| run: test "$(git rev-parse HEAD)" = "${GITHUB_SHA}" | ||
| - name: Set up Python | ||
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | ||
| with: | ||
| python-version: "3.12" | ||
| - name: Require dedicated ruleset administration credential | ||
| env: | ||
| GH_TOKEN: ${{ secrets.CWL_RULESET_ADMIN_TOKEN }} | ||
| shell: bash | ||
| run: test -n "${GH_TOKEN}" | ||
| - name: Reconcile reviewed ruleset governance | ||
| env: | ||
| GH_TOKEN: ${{ secrets.CWL_RULESET_ADMIN_TOKEN }} | ||
| EXPECTED_MAIN_SHA: ${{ github.sha }} | ||
| run: >- | ||
|
seonghobae marked this conversation as resolved.
|
||
| python scripts/ci/reconcile_ruleset_governance.py | ||
| --manifest config/ruleset-governance.json | ||
| --expected-main-sha "$EXPECTED_MAIN_SHA" | ||
| - name: Verify post-change convergence from GitHub | ||
| env: | ||
| GH_TOKEN: ${{ secrets.CWL_RULESET_ADMIN_TOKEN }} | ||
| run: >- | ||
| python scripts/ci/reconcile_ruleset_governance.py | ||
| --manifest config/ruleset-governance.json | ||
| --verify-only | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| { | ||
| "schema_version": 1, | ||
| "organization": "ContextualWisdomLab", | ||
| "targets": [ | ||
| { | ||
| "scope": "repository", | ||
| "owner": "ContextualWisdomLab", | ||
| "repository": ".github", | ||
| "ruleset_id": 17921150, | ||
| "name": "Lock default branch" | ||
| }, | ||
| { | ||
| "scope": "organization", | ||
| "owner": "ContextualWisdomLab", | ||
| "repository": null, | ||
| "ruleset_id": 18156473, | ||
| "name": "CWL Central required workflows" | ||
| } | ||
| ] | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.