Skip to content

chore(stack): sync #526 with protected main - #529

Closed
seonghobae wants to merge 1 commit into
fix/acquisition-source-document-authorityfrom
main
Closed

chore(stack): sync #526 with protected main#529
seonghobae wants to merge 1 commit into
fix/acquisition-source-document-authorityfrom
main

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Closed without merge: GitHub's live three-way merge reports conflicts for protected main@5aad3e410703faaf52882e2f33fadd25d217bcdd into canonical #526 head 2c5d6378f4842008e250f00b1a1aa8c79f76c811. No branch or source ref was changed. Canonical #526 remains the only delivery lane; convergence requires an explicit semantic merge of overlapping acquisition files.

* test(acquisition): refresh manifest after license inventory

* fix(acquisition): refresh manifest before integrity audit

* test(acquisition): reject stale pre-audit manifest artifact

* fix(acquisition): eliminate stale pre-audit manifest artifact

* test(acquisition): bind source revalidation to canonical audit

* test(acquisition): prevent duplicate manifest materialization

* fix(acquisition): share audit output authority

* fix(acquisition): unify conflicting output overrides

* fix(acquisition): make audit orchestration portable

* test(acquisition): require audit executable in buyer catalog

* test(acquisition): hash canonical audit executable

* test(acquisition): bind audit executable in composed catalog

* fix(acquisition): hash canonical audit executable

* test(acquisition): require one canonical hourly audit

* fix(acquisition): remove duplicate hourly manifest

* fix(acquisition): hash tracked blobs in process

* fix(acquisition): support SHA-256 exact heads

* fix(acquisition): carry SHA-256 commit identity

* fix(release): produce SHA-256 commit evidence

* fix(acquisition): pin stages to initial head

* fix(acquisition): canonicalize stage revision

* fix: support legacy Git tree inventory

* chore(acquisition): preserve protected-main changelog truth

* test(acquisition): reject source movement between audit stages

* fix(acquisition): fail closed on source movement between stages

* test(acquisition): reject tracked source drift during audit

* fix(acquisition): authenticate tracked source between audit stages

* fix(acquisition): authenticate inventory input bytes

* test(acquisition): bind dependency inventory to claimed commit

* test(acquisition): preserve source-binding diagnostic

* test(acquisition): revalidate source after failed stage

* fix(acquisition): revalidate source after stage failure

* fix(acquisition): revalidate failed stages

* docs(acquisition): document SHA-256 commit identities

* test(acquisition): match failed-stage preflight diagnostic

* test(acquisition): cover empty pinned file bytes
@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: a96ad997-2a98-41fb-bf22-07eec9e62537

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant