Skip to content

chore(release)(OMN-12245): backmerge onex_change_control v0.5.1 version bump to dev - #2230

Merged
jonahgabriel merged 2 commits into
devfrom
hotfix/omn-12245-release-onex_change_control-v0.5.1
Jun 6, 2026
Merged

jonahgabriel merged 2 commits into
devfrom
hotfix/omn-12245-release-onex_change_control-v0.5.1

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor

Evidence-Ticket: OMN-12245
Evidence-Source: OCC#2231

Backmerge companion for main release-version PR #2228 so dev retains the v0.5.1 release metadata after main release publication.

Summary by CodeRabbit

  • New Features

    • Added Main target guard workflow to enforce PR targeting rules for main branch.
    • Enhanced change control validation with new pre-commit hooks for freestanding checks.
  • Improvements

    • Upgraded GitHub Actions setup tools (Python v6, uv v7) for improved reliability.
    • Added retry logic with configurable timeouts for dependency installation and repository cloning.
    • Refined workflow permissions and HTTP protocol configuration for better resilience.
  • Updates

    • Updated contract evidence validation paths for consistency.
    • Expanded allowlists for additional handlers and components.

@coderabbitai

coderabbitai Bot commented Jun 6, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Actions and workflows add retry/backoff and new flags/permissions; a new main-target guard validates PR targeting rules. OCC rerun PRs retarget to dev. Pre-commit hooks and ignore rules adjust. Allowlist configs update. Contracts standardize evidence grep paths to drift/dod_receipts across many tickets.

Changes

CI guard hardening and contract receipt path normalization

Layer / File(s) Summary
Actions setup and dependency sync retries
.github/actions/validate-boundaries/action.yml, .github/actions/validate-contract/action.yml
Upgrades setup-python/uv and adds uv sync retry/backoff; hardens peer-repo cloning with retries and skips caller repo.
CI guards, inputs, permissions, and branch targeting
.github/workflows/*
Adds --scan-freestanding, uv-version input with sync retries, explicit permissions in preflight, main-target guard workflow, and rerun PRs targeting dev.
Repo hygiene: ignore and pre-commit hooks
.gitignore, .pre-commit-config.yaml
Ignores .onex_state/, excludes evidence/ from ruff, adds freestanding imperative-contracts hook, and updates a local hook path.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~75 minutes

Possibly related PRs

Poem

I hopped through YAML fields at night,
Nudged Actions to retry, hold on tight.
Main-branch gates now sternly stand,
Reruns drift to dev as planned.
In receipts I burrowed, paths made neat—
PASS prints shimmer, tap-tap feet. 🐇✨

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hotfix/omn-12245-release-onex_change_control-v0.5.1

@jonahgabriel
jonahgabriel force-pushed the hotfix/omn-12245-release-onex_change_control-v0.5.1 branch from d3aa9d9 to 8d4c211 Compare June 6, 2026 18:41
try: return json.loads(line)
except Exception: found={"raw":line[:2000]}
return found
open("/tmp/omn12294-cid.txt","w").write(CID)
break
time.sleep(6)
for name,_ in HOPS: print(f"HOP {name}: {'FOUND' if results[name]['found'] else 'MISSING'}",flush=True)
open("/tmp/omn12294-proof-result.json","w").write(json.dumps({"correlation_id":CID,"started_at":NOW,
without a live broker. This is the same injection seam the shipped tests use.
"""

async def start(self) -> None: ...
"""

async def start(self) -> None: ...
async def close(self) -> None: ...
async def close(self) -> None: ...
async def arm_response(
self, *, response_topic: str, correlation_id: str
) -> None: ...
) -> None: ...
async def publish(
self, topic: str, key: bytes | None, value: bytes, headers: object = None
) -> None: ...

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/ci.yml (1)

169-188: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Scope token permissions for imperative-contract-guard.

Line 169 defines a job that has no explicit permissions, so it inherits repository defaults. This guard only needs repository read access; default broader scopes increase blast radius unnecessarily.

Suggested fix
   imperative-contract-guard:
     name: Imperative Contract Guard
+    permissions:
+      contents: read
     runs-on: >-
       ${{
         (github.event_name == 'pull_request' &&
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 169 - 188, The
imperative-contract-guard job is missing explicit GitHub Actions permissions and
currently inherits broad repo defaults; add a minimal permissions block to the
imperative-contract-guard job (the job with name "Imperative Contract Guard") to
restrict it to repository read-only access (e.g., set permissions to contents:
read) placed at the job level above steps so the validate step ("Validate
imperative contract guard wiring") runs with least privilege.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/main-target-guard.yml:
- Around line 10-23: The workflow is missing an explicit permissions block, so
add a least-privilege permissions declaration at the top level of the workflow
(for the workflow that defines the on: pull_request and job main-target-guard)
by inserting a permissions: none stanza to ensure the run has no token scopes;
this targets the workflow containing the main-target-guard job and the
pull_request trigger so the job runs without GitHub token permissions.

In @.pre-commit-config.yaml:
- Around line 139-146: The hook "check-imperative-contracts-freestanding" can be
skipped because it has pass_filenames: false and is restricted by types:
[python]; update the hook config for id: check-imperative-contracts-freestanding
to ensure it always executes (e.g., add always_run: true) so freestanding
allowlist/contract-only commits still invoke the check even when no Python files
are staged; keep pass_filenames: false if desired but ensure always_run is
present to avoid the guard bypass.

In `@contracts/OMN-10487.yaml`:
- Around line 41-49: The grep checks use an absolute variable prefix in
contracts/OMN-10487.yaml (check id "dod-rerun-state-pr-target") but the new
entry "dod-004" in contracts/OMN-10485.yaml uses a relative path; update
OMN-10485.yaml so its command checks (the "dod-004" check_value and any
evidence_requirement command checks) prepend $CONTRACT_REPO_DIR to the
.github/workflows/... paths (matching the pattern used in
"dod-rerun-state-pr-target") to standardize path usage across contracts.

In `@contracts/OMN-11068.yaml`:
- Line 54: The check_value entries use a templated command ("gh pr view
${PR_NUMBER} --repo ${REPO} --json state,title") which allows any PR to pass;
replace the variable PR substitution with the specific PR IDs required by the
DoD descriptions: update the check_value that currently uses that template for
PR `#1765` to "gh pr view 1765 --repo ${REPO} --json state,title" and similarly
update the other check_value to "gh pr view 1715 --repo ${REPO} --json
state,title" so the checks are bound to the exact PRs; keep the ${REPO} token if
repo should remain variable.

---

Outside diff comments:
In @.github/workflows/ci.yml:
- Around line 169-188: The imperative-contract-guard job is missing explicit
GitHub Actions permissions and currently inherits broad repo defaults; add a
minimal permissions block to the imperative-contract-guard job (the job with
name "Imperative Contract Guard") to restrict it to repository read-only access
(e.g., set permissions to contents: read) placed at the job level above steps so
the validate step ("Validate imperative contract guard wiring") runs with least
privilege.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: ae3f70bc-b85f-4717-abf1-1515fb508a6e

📥 Commits

Reviewing files that changed from the base of the PR and between ccfa885 and 8d4c211.

📒 Files selected for processing (300)
  • .github/actions/validate-boundaries/action.yml
  • .github/actions/validate-contract/action.yml
  • .github/workflows/call-occ-preflight.yml
  • .github/workflows/ci.yml
  • .github/workflows/imperative-contract-guard.yml
  • .github/workflows/main-target-guard.yml
  • .github/workflows/occ-rerun-downstream.yml
  • .gitignore
  • .pre-commit-config.yaml
  • allowlists/omniintelligence.yaml
  • allowlists/omnimarket.yaml
  • allowlists/omnimemory.yaml
  • allowlists/onex_change_control.yaml
  • contracts/OMN-10143.yaml
  • contracts/OMN-10151.yaml
  • contracts/OMN-10207.yaml
  • contracts/OMN-10278.yaml
  • contracts/OMN-10316.yaml
  • contracts/OMN-10353.yaml
  • contracts/OMN-10377.yaml
  • contracts/OMN-10409.yaml
  • contracts/OMN-10424.yaml
  • contracts/OMN-10475.yaml
  • contracts/OMN-10483.yaml
  • contracts/OMN-10485.yaml
  • contracts/OMN-10487.yaml
  • contracts/OMN-10489.yaml
  • contracts/OMN-10490.yaml
  • contracts/OMN-10491.yaml
  • contracts/OMN-10500.yaml
  • contracts/OMN-10512.yaml
  • contracts/OMN-10518.yaml
  • contracts/OMN-10519.yaml
  • contracts/OMN-10520.yaml
  • contracts/OMN-10521.yaml
  • contracts/OMN-10535.yaml
  • contracts/OMN-10539.yaml
  • contracts/OMN-10540.yaml
  • contracts/OMN-10541.yaml
  • contracts/OMN-10542.yaml
  • contracts/OMN-10543.yaml
  • contracts/OMN-10544.yaml
  • contracts/OMN-10546.yaml
  • contracts/OMN-10547.yaml
  • contracts/OMN-10548.yaml
  • contracts/OMN-10552.yaml
  • contracts/OMN-10554.yaml
  • contracts/OMN-10561.yaml
  • contracts/OMN-10563.yaml
  • contracts/OMN-10564.yaml
  • contracts/OMN-10565.yaml
  • contracts/OMN-10566.yaml
  • contracts/OMN-10567.yaml
  • contracts/OMN-10569.yaml
  • contracts/OMN-10570.yaml
  • contracts/OMN-10572.yaml
  • contracts/OMN-10579.yaml
  • contracts/OMN-10580.yaml
  • contracts/OMN-10581.yaml
  • contracts/OMN-10584.yaml
  • contracts/OMN-10586.yaml
  • contracts/OMN-10587.yaml
  • contracts/OMN-10588.yaml
  • contracts/OMN-10589.yaml
  • contracts/OMN-10591.yaml
  • contracts/OMN-10592.yaml
  • contracts/OMN-10593.yaml
  • contracts/OMN-10602.yaml
  • contracts/OMN-10604.yaml
  • contracts/OMN-10605.yaml
  • contracts/OMN-10606.yaml
  • contracts/OMN-10607.yaml
  • contracts/OMN-10608.yaml
  • contracts/OMN-10609.yaml
  • contracts/OMN-10610.yaml
  • contracts/OMN-10611.yaml
  • contracts/OMN-10612.yaml
  • contracts/OMN-10613.yaml
  • contracts/OMN-10614.yaml
  • contracts/OMN-10615.yaml
  • contracts/OMN-10616.yaml
  • contracts/OMN-10617.yaml
  • contracts/OMN-10618.yaml
  • contracts/OMN-10619.yaml
  • contracts/OMN-10620.yaml
  • contracts/OMN-10621.yaml
  • contracts/OMN-10622.yaml
  • contracts/OMN-10626.yaml
  • contracts/OMN-10635.yaml
  • contracts/OMN-10636.yaml
  • contracts/OMN-10638.yaml
  • contracts/OMN-10640.yaml
  • contracts/OMN-10641.yaml
  • contracts/OMN-10644.yaml
  • contracts/OMN-10645.yaml
  • contracts/OMN-10648.yaml
  • contracts/OMN-10649.yaml
  • contracts/OMN-10650.yaml
  • contracts/OMN-10653.yaml
  • contracts/OMN-10655.yaml
  • contracts/OMN-10656.yaml
  • contracts/OMN-10657.yaml
  • contracts/OMN-10661.yaml
  • contracts/OMN-10665.yaml
  • contracts/OMN-10669.yaml
  • contracts/OMN-10670.yaml
  • contracts/OMN-10675.yaml
  • contracts/OMN-10676.yaml
  • contracts/OMN-10688.yaml
  • contracts/OMN-10689.yaml
  • contracts/OMN-10691.yaml
  • contracts/OMN-10692.yaml
  • contracts/OMN-10693.yaml
  • contracts/OMN-10694.yaml
  • contracts/OMN-10695.yaml
  • contracts/OMN-10696.yaml
  • contracts/OMN-10697.yaml
  • contracts/OMN-10698.yaml
  • contracts/OMN-10705.yaml
  • contracts/OMN-10715.yaml
  • contracts/OMN-10717.yaml
  • contracts/OMN-10718.yaml
  • contracts/OMN-10720.yaml
  • contracts/OMN-10721.yaml
  • contracts/OMN-10722.yaml
  • contracts/OMN-10723.yaml
  • contracts/OMN-10724.yaml
  • contracts/OMN-10725.yaml
  • contracts/OMN-10726.yaml
  • contracts/OMN-10727.yaml
  • contracts/OMN-10728.yaml
  • contracts/OMN-10729.yaml
  • contracts/OMN-10730.yaml
  • contracts/OMN-10731.yaml
  • contracts/OMN-10733.yaml
  • contracts/OMN-10734.yaml
  • contracts/OMN-10736.yaml
  • contracts/OMN-10737.yaml
  • contracts/OMN-10741.yaml
  • contracts/OMN-10742.yaml
  • contracts/OMN-10743.yaml
  • contracts/OMN-10744.yaml
  • contracts/OMN-10745.yaml
  • contracts/OMN-10748.yaml
  • contracts/OMN-10749.yaml
  • contracts/OMN-10750.yaml
  • contracts/OMN-10753.yaml
  • contracts/OMN-10754.yaml
  • contracts/OMN-10755.yaml
  • contracts/OMN-10768.yaml
  • contracts/OMN-10769.yaml
  • contracts/OMN-10771.yaml
  • contracts/OMN-10773.yaml
  • contracts/OMN-10778.yaml
  • contracts/OMN-10779.yaml
  • contracts/OMN-10780.yaml
  • contracts/OMN-10782.yaml
  • contracts/OMN-10783.yaml
  • contracts/OMN-10784.yaml
  • contracts/OMN-10786.yaml
  • contracts/OMN-10790.yaml
  • contracts/OMN-10791.yaml
  • contracts/OMN-10796.yaml
  • contracts/OMN-10799.yaml
  • contracts/OMN-10800.yaml
  • contracts/OMN-10810.yaml
  • contracts/OMN-10811.yaml
  • contracts/OMN-10813.yaml
  • contracts/OMN-10814.yaml
  • contracts/OMN-10815.yaml
  • contracts/OMN-10816.yaml
  • contracts/OMN-10817.yaml
  • contracts/OMN-10818.yaml
  • contracts/OMN-10819.yaml
  • contracts/OMN-10820.yaml
  • contracts/OMN-10822.yaml
  • contracts/OMN-10824.yaml
  • contracts/OMN-10835.yaml
  • contracts/OMN-10836.yaml
  • contracts/OMN-10837.yaml
  • contracts/OMN-10846.yaml
  • contracts/OMN-10847.yaml
  • contracts/OMN-10848.yaml
  • contracts/OMN-10859.yaml
  • contracts/OMN-10862.yaml
  • contracts/OMN-10866.yaml
  • contracts/OMN-10868.yaml
  • contracts/OMN-10870.yaml
  • contracts/OMN-10871.yaml
  • contracts/OMN-10872.yaml
  • contracts/OMN-10873.yaml
  • contracts/OMN-10874.yaml
  • contracts/OMN-10889.yaml
  • contracts/OMN-10895.yaml
  • contracts/OMN-10963.yaml
  • contracts/OMN-10964.yaml
  • contracts/OMN-10966.yaml
  • contracts/OMN-10972.yaml
  • contracts/OMN-10978.yaml
  • contracts/OMN-10983.yaml
  • contracts/OMN-11012.yaml
  • contracts/OMN-11065.yaml
  • contracts/OMN-11068.yaml
  • contracts/OMN-11070.yaml
  • contracts/OMN-11080.yaml
  • contracts/OMN-11083.yaml
  • contracts/OMN-11088.yaml
  • contracts/OMN-11104.yaml
  • contracts/OMN-11116.yaml
  • contracts/OMN-11130.yaml
  • contracts/OMN-11131.yaml
  • contracts/OMN-11137.yaml
  • contracts/OMN-11138.yaml
  • contracts/OMN-11139.yaml
  • contracts/OMN-11140.yaml
  • contracts/OMN-11141.yaml
  • contracts/OMN-11142.yaml
  • contracts/OMN-11143.yaml
  • contracts/OMN-11144.yaml
  • contracts/OMN-11149.yaml
  • contracts/OMN-11150.yaml
  • contracts/OMN-11151.yaml
  • contracts/OMN-11152.yaml
  • contracts/OMN-11153.yaml
  • contracts/OMN-11154.yaml
  • contracts/OMN-11155.yaml
  • contracts/OMN-11156.yaml
  • contracts/OMN-11157.yaml
  • contracts/OMN-11158.yaml
  • contracts/OMN-11159.yaml
  • contracts/OMN-11160.yaml
  • contracts/OMN-11166.yaml
  • contracts/OMN-11168.yaml
  • contracts/OMN-11169.yaml
  • contracts/OMN-11170.yaml
  • contracts/OMN-11171.yaml
  • contracts/OMN-11173.yaml
  • contracts/OMN-11174.yaml
  • contracts/OMN-11176.yaml
  • contracts/OMN-11177.yaml
  • contracts/OMN-11183.yaml
  • contracts/OMN-11184.yaml
  • contracts/OMN-11185.yaml
  • contracts/OMN-11189.yaml
  • contracts/OMN-11194.yaml
  • contracts/OMN-11202.yaml
  • contracts/OMN-11203.yaml
  • contracts/OMN-11206.yaml
  • contracts/OMN-11227.yaml
  • contracts/OMN-11228.yaml
  • contracts/OMN-11231.yaml
  • contracts/OMN-11234.yaml
  • contracts/OMN-11241.yaml
  • contracts/OMN-11243.yaml
  • contracts/OMN-11246.yaml
  • contracts/OMN-11247.yaml
  • contracts/OMN-11249.yaml
  • contracts/OMN-11261.yaml
  • contracts/OMN-11262.yaml
  • contracts/OMN-11266.yaml
  • contracts/OMN-11267.yaml
  • contracts/OMN-11268.yaml
  • contracts/OMN-11269.yaml
  • contracts/OMN-11270.yaml
  • contracts/OMN-11271.yaml
  • contracts/OMN-11272.yaml
  • contracts/OMN-11273.yaml
  • contracts/OMN-11274.yaml
  • contracts/OMN-11276.yaml
  • contracts/OMN-11277.yaml
  • contracts/OMN-11278.yaml
  • contracts/OMN-11279.yaml
  • contracts/OMN-11280.yaml
  • contracts/OMN-11282.yaml
  • contracts/OMN-11283.yaml
  • contracts/OMN-11284.yaml
  • contracts/OMN-11285.yaml
  • contracts/OMN-11292.yaml
  • contracts/OMN-11294.yaml
  • contracts/OMN-11297.yaml
  • contracts/OMN-11298.yaml
  • contracts/OMN-11299.yaml
  • contracts/OMN-11301.yaml
  • contracts/OMN-11330.yaml
  • contracts/OMN-11331.yaml
  • contracts/OMN-11346.yaml
  • contracts/OMN-11348.yaml
  • contracts/OMN-11350.yaml
  • contracts/OMN-11354.yaml
  • contracts/OMN-11379.yaml
  • contracts/OMN-11381.yaml
  • contracts/OMN-11382.yaml
  • contracts/OMN-11384.yaml
  • contracts/OMN-11385.yaml
  • contracts/OMN-11386.yaml
  • contracts/OMN-11413.yaml
  • contracts/OMN-11420.yaml
  • contracts/OMN-11421.yaml
  • contracts/OMN-11423.yaml
  • contracts/OMN-11424.yaml

Comment thread .github/workflows/main-target-guard.yml
Comment thread .pre-commit-config.yaml
Comment on lines +139 to +146
- id: check-imperative-contracts-freestanding
name: Imperative contract guard with freestanding reachability
language: system
entry: >-
uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding
pass_filenames: false
types: [python]
stages: [pre-commit]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Freestanding imperative-contract guard can be skipped on non-Python commits.

Line 145 restricts execution to Python-typed staged files; with pass_filenames: false and no always_run, this hook may not run on allowlist/contract-only commits, which creates a guard bypass.

Suggested fix
       - id: check-imperative-contracts-freestanding
         name: Imperative contract guard with freestanding reachability
         language: system
         entry: >-
           uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding
         pass_filenames: false
-        types: [python]
+        always_run: true
         stages: [pre-commit]
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- id: check-imperative-contracts-freestanding
name: Imperative contract guard with freestanding reachability
language: system
entry: >-
uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding
pass_filenames: false
types: [python]
stages: [pre-commit]
- id: check-imperative-contracts-freestanding
name: Imperative contract guard with freestanding reachability
language: system
entry: >-
uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding
pass_filenames: false
always_run: true
stages: [pre-commit]
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.pre-commit-config.yaml around lines 139 - 146, The hook
"check-imperative-contracts-freestanding" can be skipped because it has
pass_filenames: false and is restricted by types: [python]; update the hook
config for id: check-imperative-contracts-freestanding to ensure it always
executes (e.g., add always_run: true) so freestanding allowlist/contract-only
commits still invoke the check even when no Python files are staged; keep
pass_filenames: false if desired but ensure always_run is present to avoid the
guard bypass.

Comment thread contracts/OMN-10487.yaml
Comment on lines +41 to +49
- id: "dod-rerun-state-pr-target"
description: "OCC rerun-state automation opens dev-targeted PRs without suppressing CI."
source: "manual"
checks:
- check_type: "command"
check_value: >-
grep -q -- '--base dev' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml" && !
grep -q '\\[skip ci\\]' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml" && grep
-q 'Evidence-Ticket: OMN-10487' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Path prefix inconsistency with OMN-10485.yaml dod-004.

This entry uses $CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml (lines 47-49) while the newly added dod-004 in contracts/OMN-10485.yaml line 70 uses a relative path .github/workflows/call-occ-preflight.yml without the $CONTRACT_REPO_DIR prefix. Given that this PR is described as standardizing contract evidence grep paths, this inconsistency should be resolved.

🔧 Suggested fix for OMN-10485.yaml to match this pattern

In contracts/OMN-10485.yaml line 70, update to use the $CONTRACT_REPO_DIR prefix:

-          grep -q '^  pull-requests: read$' .github/workflows/call-occ-preflight.yml
+          grep -q '^  pull-requests: read$' "$CONTRACT_REPO_DIR/.github/workflows/call-occ-preflight.yml"

Similarly, if the evidence_requirement at line 23 of OMN-10485.yaml is intended to run as a command check (not just documentation), consider adding the prefix there as well.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@contracts/OMN-10487.yaml` around lines 41 - 49, The grep checks use an
absolute variable prefix in contracts/OMN-10487.yaml (check id
"dod-rerun-state-pr-target") but the new entry "dod-004" in
contracts/OMN-10485.yaml uses a relative path; update OMN-10485.yaml so its
command checks (the "dod-004" check_value and any evidence_requirement command
checks) prepend $CONTRACT_REPO_DIR to the .github/workflows/... paths (matching
the pattern used in "dod-rerun-state-pr-target") to standardize path usage
across contracts.

Comment thread contracts/OMN-11068.yaml
status: "verified"
checks:
- check_type: "command"
check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Pin the PR identity in the new DoD checks.

Line 54 and Line 62 currently succeed for whatever ${PR_NUMBER}/${REPO} are injected, but the descriptions require binding to specific PRs (#1765 and #1715). This weakens evidence integrity and can produce false-positive verification.

Suggested fix
-        check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title"
+        check_value: "gh pr view 1765 --repo OmniNode-ai/omnibase_infra --json number,state,title -q '.number == 1765'"
...
-        check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title"
+        check_value: "gh pr view 1715 --repo OmniNode-ai/onex_change_control --json number,state,title -q '.number == 1715'"

Also applies to: 62-62

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@contracts/OMN-11068.yaml` at line 54, The check_value entries use a templated
command ("gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title") which
allows any PR to pass; replace the variable PR substitution with the specific PR
IDs required by the DoD descriptions: update the check_value that currently uses
that template for PR `#1765` to "gh pr view 1765 --repo ${REPO} --json
state,title" and similarly update the other check_value to "gh pr view 1715
--repo ${REPO} --json state,title" so the checks are bound to the exact PRs;
keep the ${REPO} token if repo should remain variable.

@jonahgabriel
jonahgabriel force-pushed the hotfix/omn-12245-release-onex_change_control-v0.5.1 branch from 8d4c211 to 1ba80de Compare June 6, 2026 20:47
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 6, 2026
Merged via the queue into dev with commit 345a8cd Jun 6, 2026
56 checks passed
@jonahgabriel
jonahgabriel deleted the hotfix/omn-12245-release-onex_change_control-v0.5.1 branch June 6, 2026 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants