ci(codeql): delegate PR CodeQL to central, keep local push-only (fixes duplicate check contexts) - #953
Conversation
User decision: central delegation. The org 'CWL Central required workflows' ruleset has a code_scanning rule (CodeQL, medium+), and the central ContextualWisdomLab/.github codeql-pr.yml already uploads PR-head AND merge-preview SARIF (upload: always) — so it fully satisfies the merge gate for this repo's languages (actions/js-ts/python). The local codeql.yml also ran on pull_request and uploaded the SAME /language:<lang> category, double-uploading SARIF and duplicating the 'CodeQL compatibility analysis'/'merge preview' check contexts, which stalled opencode auto-approve. - codeql.yml: drop the pull_request trigger + the analyze-merge (merge preview) job. It now scans only the default branch on push (there is no default-setup), and PR CodeQL + the code_scanning gate are owned by the central workflow. - test_release_governance: rewrite the codeql assertion to match push-only delegation (no PR trigger, no merge-preview, still uploads default-branch SARIF). Verified: the rewritten codeql governance test passes. (The 2 other governance failures — scorecard/trivy + dependency-review.yml — are the pre-existing develop-red that #935 fixes; inherited, not from this change.) Supersedes the stale #916 (based on the pre-#912 upload:always shape). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017RkKdtHRLG4wSLh6PVsp8J
# Conflicts: # .github/workflows/codeql.yml # backend/tests/test_release_governance.py
OpenCode Review Overview
Pull request overviewOpenCode reviewed the current-head bounded evidence and found no blocking issues. FindingsNo blocking findings. SummaryApproval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Backend: test_release_governance.py"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: test_release_governance.py"]
R2 --> V2["backend tests"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head bounded evidence and found no blocking issues.
Findings
No blocking findings.
Summary
Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including .github/workflows/codeql.yml, backend/tests/test_release_governance.py.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports supported repository test suites passed.
Docstring coverage: coverage execution evidence reports configured repository docstring gates passed or docstring coverage was advisory.
DAG: CodeGraph/source-backed behavior map connects .github/workflows/codeql.yml to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.
- Result: APPROVE
- Reason: PR changes are well-justified and verified
- Head SHA:
b8c6115c31b821998b817bb6f7851be5022033da - Workflow run: 29177075636
- Workflow attempt: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Backend: test_release_governance.py"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: test_release_governance.py"]
R2 --> V2["backend tests"]
Why (user decision: central delegation)
The org CWL Central required workflows ruleset has a
code_scanningrule (CodeQL, medium+). The centralContextualWisdomLab/.githubcodeql-pr.ymlalready uploads PR-head AND merge-preview SARIF (upload: always) → it fully satisfies the merge gate for this repo's languages (actions/js-ts/python). But the localcodeql.ymlalso ran onpull_requestand uploaded the same/language:<lang>category, double-uploading SARIF and duplicating theCodeQL compatibility analysis/merge previewcheck contexts — which stalled opencode auto-approve. This is the CodeQL merge-blocker.What
codeql.yml: drop thepull_requesttrigger + theanalyze-merge(merge-preview) job → scans only the default branch on push; PR CodeQL + thecode_scanninggate are delegated to the central workflow. Default-branch scanning is preserved (central is PR-only).test_release_governance: rewrite the codeql assertion to match push-only delegation.Verification
dependency-review.yml) are the pre-existing develop-red that fix(tests): develop is red — align governance tests with #926's central delegation #935 fixes — inherited, not from this change.Supersedes
Stale #916 (based on the pre-#912
upload: alwaysshape) — will close it.🤖 Generated with Claude Code