fix(context-fabric): require source-bound release attestation - #544
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughContext 계약 릴리스 admission이 보호된 소스 매니페스트와 attestation을 검증하도록 확장되었다. envelope 보존 capability와 보호된 소스 식별자가 릴리스 증거에 추가되었다. ADR과 관련 테스트도 갱신되었다. ChangesContext 계약 릴리스 admission
Estimated code review effort: 3 (Moderate) | ~20 minutes ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh protected-base repair supersedes the stale authority block above. Protected |
Scope
Strengthen Noema's Context Graph consumer ACL without copying
context-graph-contractssource or treating mutable producer PRs as authority. Noema requires exact release-source manifest + independently retained attestation digests, protected source ref and signer workflow, canonical Context Assertion/CloudEvent profile identities, and versionedcontext-assertion-envelope-preserving-admission-v1capability evidence. Cross-service SQL, mutable producer source, provider routing and foreign security authority remain out of scope.Retained TDD lineage
RED
1e2603bb...→ production20b8bead...bound exact protected-source manifest/attestation evidence; RED834b4ac8...→4f04a78a...added finite canonical capability metadata; REDe0f0dc0b...→c72ce1cb...added versioned envelope-preserving admission. Hosted fitness failures were repaired without weakening immutable-release semantics. The latest predecessor showed a Markdown-sensitive raw-substring fixture;d5ecf8331d78db1e5d1b5505e818a1f8aed01076strips backticks only for the semantic assertion while preserving the exactimmutable released context-graph-contractsrequirement.Current exact authority — 2026-09-06 KST
main@e1ac9d50f6c646f04be8c137c8acdc7200182fcd;d5ecf8331d78db1e5d1b5505e818a1f8aed01076;ci 33952078330, requiredSecurity Scan 33952078410,reviewer-ci 33952078464, andpatch-validator-image 33952078542are terminal success;95144d5bcf8f1cb4b9a7c552ede66737c23d6bca. The reviewer success above predates that repaired semantic-evidence contract reaching protected truth, so it is workflow-surface evidence rather than merge-authoritative semantic GREEN.Keep the source unchanged and Draft. After #546 reaches protected truth, regenerate semantic reviewer evidence for this exact head and re-read current governance. Do not promote mutable producer evidence, weaken the release attestation contract, source-churn for runners, self-approve, rewrite history, or absorb Context Graph/CO/security owner authority.
Summary by CodeRabbit
새 기능
문서
테스트