fix(ci): execute Server Tests on exact PR heads - #523
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (7)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughServer Tests, CodeQL Required, OSV 스캔이 exact-head 검증을 사용합니다. 서버·브라우저 커버리지와 API 경계 테스트가 확장되었습니다. E2E 테스트와 모달·토스트 UI 검증도 추가되었습니다. ChangesCI 무결성 및 커버리지
애플리케이션 계약
브라우저와 UI
Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: 🟡 Moderate · up to This PR improves exact-head CI execution and bounds browser-install time, but the supplied evidence still identifies unresolved validation risks, including a failing API timing test, potentially incomplete coverage enforcement, and flaky or overly permissive automated checks. Fix or explicitly accept these bounded risks before merging. Sequence Diagram(s)sequenceDiagram
participant PullRequest
participant ServerTests
participant CodeQLRequired
participant OSVScanner
participant GitCheckout
participant CoverageCollector
PullRequest->>ServerTests: contributor head SHA 전달
ServerTests->>GitCheckout: exact-head checkout
GitCheckout-->>ServerTests: actual HEAD 반환
ServerTests->>CoverageCollector: 서버·브라우저 테스트 실행
CoverageCollector-->>ServerTests: Istanbul 보고서와 진단 결과 반환
PullRequest->>CodeQLRequired: head SHA 전달
CodeQLRequired->>GitCheckout: exact-head checkout 및 SHA 검증
PullRequest->>OSVScanner: protected base와 contributor head 전달
OSVScanner->>GitCheckout: base·head 순차 checkout
OSVScanner-->>PullRequest: 비교 SARIF 업로드
Possibly related issues
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
@coderabbitai review |
|
|
@opencode-agent review Please submit a review-only formal verdict for exact current head |
|
@opencode-agent review Review only the exact current contributor head |
|
@opencode-agent review Please submit a review-only formal verdict for exact current contributor head |
|
@opencode-agent review Current-head re-dispatch request for |
|
@opencode-agent review Exact-head review-only request for Please submit a formal current-head |
|
@opencode-agent review Review only the exact current contributor head |
Buyer/control outcome
Refs #522.
ScopeWeave's repository-owned CI evidence is being made defensible at the revision boundary: deterministic pull-request execution binds repository-owned Server Tests to the immutable contributor head, base-sensitive comparisons independently resolve the live protected base, owned browser/server coverage fails closed at exact 100%, and dependency/security controls are tightened against stale or incomplete evidence.
Exact current identity
develop@2c328875e00e86537df3e965170be80532571cad;135117e0594939240e787a161574b6fb4e10f155;16f86b70539a410c20940a5e237af9b69c35479d;7f133dc301c9a2f86bd3a0f0c273ef676bf18e6a;fix/server-tests-exact-head-522;Any contributor-head or protected-base movement invalidates head/base-sensitive evidence until exact revisions, actual checkout attestations, reviews, checks, and live-base identity are freshly revalidated. This body is traceability, not merge authority.
Current exact-head evidence
Fresh evidence on
135117e0594939240e787a161574b6fb4e10f155includes repository-owned Server Tests, Fuzz, Dependency Review, CodeQL Required and OSV runs plus centrally owned security/review workflows. The current central SAST run33148083441, job98791495212, explicitly checked out the submitted contributor revision and passed a runtime exact-SHA verification before Semgrep; this is the working exact-head control pattern.Two required central lanes remain non-authoritative/non-passing on this unchanged head:
33148082474, job98775450437, failed closed because no current-head OpenCode verdict existed. A fresh@opencode-agent reviewrequest has been issued for this exact SHA; predecessor verdicts remain historical.33148082533was cancelled before any job/report materialized. A cancelled zero-job run supplies no exact-head scan receipt.The organization-owned Security Scan workflow still has head-oriented dependency-review/Trivy/Scorecard jobs whose central reusable workflow uses default checkout rather than explicit contributor-repository/ref checkout plus runtime SHA attestation. That owner defect is actively tracked in
ContextualWisdomLab/.github#1222; the Strix no-report recovery/evidence defect is actively tracked inContextualWisdomLab/.github#891. ScopeWeave does not create a competing writer in the central repository.GitHub Advanced Security also emits a neutral
osv-scannercomparison check because protecteddevelopcurrently has the reusable-workflow configuration.github/workflows/osvscanner.yml:osv-scan, while this PR intentionally changes repository OSV to a read-only, artifact-preserving exact-head differential job namedscanand keeps GitHub code-scanning publication CodeQL-only. The neutral comparison is not treated as passing evidence; repository OSV scan evidence is evaluated separately from the GHAS comparison surface.Review-driven repairs
Earlier realistic RED findings on this PR have been repaired test-first, including false file-picker authority, OSV/CodeQL contract contradiction, live-base resolver singular-result validation, deterministic browser/API coverage cases, dependency/coverage workflow evidence gaps, and exact-head browser invariant coverage. The current review-thread sweep returns no unresolved threads. Historical OpenCode
REQUEST_CHANGESevidence is anchored to predecessor head3ce9a8bbc483036bddc2fa1681f84e25f8493772, is dismissed/stale, and is not converted into a current verdict or approval. Current CodeRabbit, Devin, GitHub code-quality, and other model/informational submissions do not constitute the required independent approval.Merge boundary
Do not merge or enable auto-merge until the unchanged exact contributor head remains freshly reconciled to protected
develop, central required-workflow evidence is regenerated under corrected exact-head/evidence contracts, every applicable repository and organization CI/browser/coverage/docstring/CodeQL/SAST/security/dependency/supply-chain/package/provenance/required-workflow gate is substantively terminal-passing, valid unresolved findings are zero, and live review rules are satisfied. Active repository ruleset17214767requires one approving review, dismisses stale reviews on push, requires resolved review threads, and requires approval from someone other than the latest pusher; organization ruleset18156473also requires one approval and resolved threads.Pending, queued, skipped-required, cancelled, absent, neutral-required, failed, stale, predecessor, synthetic-only, status-only, author-only, model-only, rate-limited, or infrastructure-only evidence is non-passing. Do not self-approve, manufacture approval, dismiss a valid current review, weaken protection, or transfer predecessor evidence.
docs/doctoring/server-tests-exact-head.mdremains the detailed evidence-integrity record;CHANGELOG.mdrecords active Unreleased work rather than protected-shipped truth.