fix(acquisition): restack deployment audit byte identity on latest main - #223
Conversation
|
Warning Review limit reached
Next review available in: 33 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Fresh protected-main successor for #213/#124 on exact base
db4f444c1b1849ec615364a233469870c23407e6. No predecessor checks, reviews, scanner/model output, deployment evidence, release evidence, or acquisition evidence transfer.Test-first proof
Exact RED head
6463d9ffaaba3cb29b4476a9beb529d6a66d6c2dadded onlytest/acquisition-deployment-evidence-input-integrity.test.ts. Applicationci31590227319, verify job94093234995, checked out that exact head and failed atrelease verify; the intended regressions proved protected source accepted all three unsafe cases:Each unsafe path returned status
0where the test required fail-closed status1. The same RED head's protected-base eligible centralSecurity Scancompleted successfully; reviewer evidence on RED is not application GREEN evidence.Current GREEN implementation
Exact current head
4c407b46eb91c9832ef2a9df6331172c5a319a34:O_RDONLY | O_NOFOLLOWcapability;Bufferused for semantics rather than decoded/re-encoded text;Stale duplicate #213 was closed only after proving the exact final blobs are preserved here:
scripts/acquisition-deployment-evidence-audit.mjsceb2b71c226c0e0c6d0116587a9c7c8f30fdf87aandtest/acquisition-deployment-evidence-input-integrity.test.tsdc5d587c66cd0735d8fa7603ef23149aceb93c46.Exact-head proof
For unchanged head
4c407b46eb91c9832ef2a9df6331172c5a319a34:ci31591248220, job94096480600: terminal success; exact checkout, package-manager identity, frozen install, andrelease verifysucceeded;reviewer-ci31591248252, job94096480772: terminal success; exact checkout, 100% reviewer line/branch coverage, 100% docstring gate, authenticated sandbox-image scan, and real no-network CodeGraph smoke succeeded;Security Scan31591248238: terminal success; dependency review, OSV, and Trivy hard-gate jobs succeeded, while Scorecard remains posture evidence;CodeRabbit reported
Review rate limitedafter Ready. That status/model evidence is not a source finding, formal approval, or live required gate. The current live ruleset requires the central Security Scan workflow and does not expose an approval rule.Authority boundary
This is retained-evidence integrity hardening only. It does not prove a real production deployment, cryptographically verify an attestation by itself, establish production environment governance, publish a release, choose owner/legal rights, establish revenue/transfer evidence, or make Noema acquisition-ready.