fix(trust): roll forward audited central workflow source - #509
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough중앙 워크플로의 허용 커밋 SHA를 ChangesOIDC 신뢰 기준 갱신
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: 🟡 Moderate · up to This change rolls OIDC authorization forward to an audited central workflow commit without broadening the existing exact-source checks. The bounded risk is that the trust-anchor audit remains dependent on supplied external-source evidence, and required CI and security gates are still running; merge should wait for terminal-clean results and owner confirmation. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1 files. (2 skipped: 2 unsupported.) ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bind the Noema OIDC source authority to protected central 6ffd8f8 after re-auditing the exact noema-review workflow blob as byte-identical to the previously trusted generation. Preserve exact job_workflow_sha fail-closed semantics.
|
@coderabbitai review |
✅ Action performedReview finished.
|
Scope
Roll Noema's immutable GitHub Actions OIDC workflow-source authority forward to the current protected
ContextualWisdomLab/.githubsource without weakening exactjob_workflow_shaverification or mutating the foreign repository.Verified trust decision
Protected Noema
mainisad99b10f12bc0b42385f4d23fb7658480a12e83f. Read-only protected central.github/mainis1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5.The exact trusted
.github/workflows/noema-review.ymlblob remains unchanged across the accepted central movement, while the materialized central source tree changed in the review gate. Because the workflow executes code from the exactjob_workflow_sha, Noema continues to require exact commit equality rather than trusting ancestry or unchanged YAML bytes alone.Protected Noema
mainstill pinsALLOWED_WORKFLOW_SHA=3a7941aa92de00b8b39fd11cbe7bf3da2fbbeddc; this PR owns the accepted roll-forward to1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5. The separate central OIDC consumer mismatch remains central-owned and is not worked around in Noema.Test-first / production lineage
0bece50dc1ae4375fcbf67e8e097a142b410762d: stale production trust pin failed the focused regression while the rest of the suite passed.97dae86f3a075b2883c2a00b29f13cd322848f3a: later test-only stale-pin state; superseded before terminal hosted evidence.7f9085e9b3593477c2744d760cafc8560780a1e8: productionALLOWED_WORKFLOW_SHAmoves to central1cbb6a...without weakening exact source equality.a4108cef7aa210e2b7010d3e99e5705f5dd52295: architecture records the accepted central source decision.b220c192438576bb6649ecb8497bee2557c75623: another compatible writer non-destructively incorporated protectedmain@ad99b10...; verification shows current main is now the exact merge base and the effective delta remains only three trust-authority files.Current exact authority
Only unchanged evidence for exact head
b220c192438576bb6649ecb8497bee2557c75623is eligible.main@ad99b10f12bc0b42385f4d23fb7658480a12e83f;ARCHITECTURE.md,test/trusted-workflow-source-rollforward.test.ts,wrangler.tomlonly;33385497084: success;33385497149: success;33385497328: success;patch-validator-image33385497135: in progress / non-passing.Do not merge until the unchanged exact-head image/runtime/SBOM/vulnerability/provenance gate is terminal-success and live head/base/review/governance/central authority remain freshly unchanged.
Guardrails
ContextualWisdomLab/.github/.github/workflows/noema-review.yml@refs/heads/mainexact and preserve cryptographic source-SHA equality..github, naruon, contextual-orchestrator and other dedicated-writer repositories read-only from this Noema lane.