Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
146 commits
Select commit Hold shift + click to select a range
b2425ae
chore(metadata): extend reviewed label assignments
seonghobae Sep 1, 2026
d22b261
test(metadata): pin public-surface type assignments
seonghobae Sep 1, 2026
444555c
docs(metadata): record label taxonomy wave 3
seonghobae Sep 1, 2026
978be08
test(metadata): cover taxonomy wave supplement
seonghobae Sep 1, 2026
0f5f051
style(metadata): preserve taxonomy layout
seonghobae Sep 1, 2026
8296aa7
style(metadata): preserve taxonomy test structure
seonghobae Sep 1, 2026
e5a2d4c
chore(metadata): extend public-surface label inventory
seonghobae Sep 2, 2026
bad7e0a
test(metadata): cover extended label inventory
seonghobae Sep 2, 2026
c7a5726
docs(metadata): record extended public-surface wave
seonghobae Sep 2, 2026
aa614d4
chore(metadata): record latest classification remediations
seonghobae Sep 2, 2026
0515224
test(metadata): pin latest classification inventory
seonghobae Sep 2, 2026
7a6fb18
docs(metadata): record latest classification wave
seonghobae Sep 2, 2026
1809a11
chore(metadata): record latest semantic label assignments
seonghobae Sep 2, 2026
cb19940
test(metadata): cover latest semantic label assignments
seonghobae Sep 2, 2026
88bafd6
docs(metadata): record latest taxonomy wave evidence
seonghobae Sep 2, 2026
be786fc
chore(metadata): record latest organization label wave
seonghobae Sep 2, 2026
23e9f86
test(metadata): cover latest organization label wave
seonghobae Sep 2, 2026
c546fb9
docs(metadata): record organization label wave evidence
seonghobae Sep 2, 2026
54f7274
chore(metadata): reconcile live semantic types
seonghobae Sep 2, 2026
3b4be20
test(metadata): pin reconciled semantic types
seonghobae Sep 2, 2026
f0c6f37
docs(metadata): record live taxonomy reconciliation
seonghobae Sep 2, 2026
92d03f8
chore(metadata): merge protected main into label taxonomy wave 3
seonghobae Sep 2, 2026
c214174
chore(metadata): reconcile fresh semantic classifications
seonghobae Sep 2, 2026
086e892
chore(metadata): refresh label taxonomy on current main
seonghobae Sep 2, 2026
ce424de
test(metadata): pin complete label taxonomy inventory
seonghobae Sep 2, 2026
89fbcad
docs(metadata): reconcile taxonomy operating inventory
seonghobae Sep 2, 2026
8809e44
merge(main): refresh label taxonomy writer without force push
seonghobae Sep 2, 2026
7b3f39b
merge(main): preserve current label taxonomy writer
seonghobae Sep 2, 2026
81b2dcf
chore(metadata): retarget codec-carver documentation authority
seonghobae Sep 2, 2026
f5588ea
test(metadata): pin canonical codec-carver writer
seonghobae Sep 2, 2026
a25a260
docs(metadata): record canonical codec-carver writer
seonghobae Sep 2, 2026
7f512d7
chore(metadata): reconcile taxonomy branch with protected main
seonghobae Sep 2, 2026
3255c0c
chore(metadata): retire superseded taxonomy targets
seonghobae Sep 2, 2026
1c526a3
test(metadata): pin active taxonomy inventory
seonghobae Sep 2, 2026
34e97d0
docs(metadata): retire superseded baseline targets
seonghobae Sep 2, 2026
ee41ac7
docs(metadata): reconcile active taxonomy count
seonghobae Sep 2, 2026
46f7ec8
chore(metadata): reconcile taxonomy branch with protected main
seonghobae Sep 2, 2026
bf3c07d
Merge current main into repository label taxonomy lane
seonghobae Sep 2, 2026
6cdc01b
chore(metadata): record naruon docs contract classification
seonghobae Sep 2, 2026
a815d49
chore(metadata): record reviewed documentation targets
seonghobae Sep 2, 2026
591646a
test(metadata): pin expanded label taxonomy
seonghobae Sep 2, 2026
4631b3f
docs(metadata): record reviewed documentation targets
seonghobae Sep 2, 2026
c53e16f
chore(metadata): reconcile taxonomy with protected main
seonghobae Sep 2, 2026
9929d34
test(metadata): require taxonomy supplement workflow trigger
seonghobae Sep 2, 2026
de97158
fix(metadata): trigger validation for taxonomy operating record
seonghobae Sep 2, 2026
fb2f77a
fix(metadata): trigger reconciliation for baseline record
seonghobae Sep 6, 2026
3588fec
test(metadata): cover baseline trigger path
seonghobae Sep 6, 2026
2ee4c15
docs(metadata): remove trailing whitespace
seonghobae Sep 6, 2026
7ad5617
test(metadata): require bounded parallel label reconciliation
seonghobae Sep 8, 2026
b78bc24
fix(metadata): bound parallel label reconciliation
seonghobae Sep 8, 2026
9b1679d
chore(metadata): persist latest live taxonomy drift
seonghobae Sep 8, 2026
c986278
chore(metadata): absorb concurrent naruon label drift
seonghobae Sep 8, 2026
01def05
chore(metadata): absorb appguardrail label drift
seonghobae Sep 8, 2026
844cd15
chore(metadata): absorb latest release-label drift
seonghobae Sep 8, 2026
120496f
chore(metadata): record concurrent label drift
seonghobae Sep 8, 2026
0a26f9a
chore(metadata): record dependency security drift
seonghobae Sep 8, 2026
05e754e
test(metadata): require latest Naruon label target
seonghobae Sep 8, 2026
3ab093c
chore(metadata): persist latest Naruon label assignment
seonghobae Sep 8, 2026
558d106
test(metadata): require latest semantic assignments
seonghobae Sep 8, 2026
cc2cfa8
chore(metadata): persist latest semantic assignments
seonghobae Sep 8, 2026
bca4040
test(metadata): make parallel failure assertion order-independent
seonghobae Sep 8, 2026
d8e7521
test(labels): reject ambiguous repository names
seonghobae Sep 26, 2026
04f8d51
merge(main): reconcile label taxonomy owner
seonghobae Sep 26, 2026
6d5caed
chore(ux): document ui absence and adjust test coverage
seonghobae Sep 29, 2026
416234f
chore(ux): document ui absence and trigger ci retry
seonghobae Sep 29, 2026
14eb9af
chore(ux): document ui absence and trigger ci retry again
seonghobae Sep 29, 2026
25c576c
chore(ux): document ui absence and trigger ci retry again
seonghobae Sep 30, 2026
41e95af
fix(ci): include suite parser dependencies in the quality lock
seonghobae Sep 30, 2026
cb4766f
chore(ux): trigger ci retry after returning from draft state
seonghobae Sep 30, 2026
019cf4c
docs(ci): record complete parser-lock suite and macOS environment RCA
seonghobae Sep 30, 2026
cd84d88
test(security): require patched Strix and Rust fixture locks
seonghobae Sep 30, 2026
1ca4b94
fix(security): refresh shared PyJWT and PyO3 locks
seonghobae Sep 30, 2026
02c70d5
test(security): reject duplicate vulnerable dependency locks
seonghobae Sep 30, 2026
f93f9f7
docs(ci): track full-suite parser-lock gap evidence
seonghobae Sep 30, 2026
189e6e3
docs(ci): distinguish source and live parser-lock heads
seonghobae Sep 30, 2026
19e3df3
test(coverage): reject unapproved production omissions
seonghobae Sep 30, 2026
706f352
fix(coverage): restore production modules to the gate
seonghobae Sep 30, 2026
25af103
fix(ci): close GitHub API HTTP error responses
seonghobae Sep 30, 2026
d1aa365
test(security): normalize requirement extras
seonghobae Sep 30, 2026
d3dadff
test(coverage): exercise fail-closed edge paths
seonghobae Sep 30, 2026
ae3ca14
fix(ci): bound CodeQL HTTP error diagnostics
seonghobae Sep 30, 2026
cf7326b
test(coverage): exercise Strix report scope
seonghobae Sep 30, 2026
6d3a989
merge(main): refresh coverage repair base
seonghobae Sep 30, 2026
a435def
test(coverage): close runtime helper edge gaps
seonghobae Sep 30, 2026
3dc4767
fix(ci): close remaining HTTP error responses
seonghobae Sep 30, 2026
9d3ec75
fix(ci): close responses after telemetry failures
seonghobae Sep 30, 2026
bc40de5
fix(ci): fetch lineage required by full quality gate
seonghobae Sep 30, 2026
3ef3ffa
chore(deps): add pyyaml and defusedxml to dev dependencies
seonghobae Sep 30, 2026
f62bb7e
chore(deps): consume canonical lock delta for ci dependencies
seonghobae Sep 30, 2026
ccb7bb7
merge: integrate shared security baseline prerequisite
seonghobae Sep 30, 2026
ef28f6b
merge: integrate GitHub API response lifecycle prerequisite
seonghobae Sep 30, 2026
2510618
docs: bind parser integration gap to exact head
seonghobae Sep 30, 2026
61fb469
test(coverage): integrate prerequisites and restore 100% gate
seonghobae Sep 30, 2026
2763134
chore(deps): retry transient ci failure after draft return
seonghobae Sep 30, 2026
2f7bde9
merge: carry current coverage owner into parser successor
seonghobae Sep 30, 2026
822bbdf
revert: restore validated coverage-owner tree
seonghobae Sep 30, 2026
5d4d2aa
test(ci): require metadata ancestry checkout
seonghobae Sep 30, 2026
176192a
fix(ci): fetch metadata validation ancestry
seonghobae Sep 30, 2026
ef014b9
merge: preserve corrected current coverage-owner head
seonghobae Sep 30, 2026
5e807bd
fix(security): pin patched urllib3 for pip audit
seonghobae Sep 30, 2026
bb3bcad
fix(security): pin patched urllib3 for Strix
seonghobae Sep 30, 2026
109b542
build(security): regenerate pip audit lock
seonghobae Sep 30, 2026
8dba299
build(security): regenerate Strix lock
seonghobae Sep 30, 2026
165b6fe
test(security): bind patched urllib3 locks
seonghobae Sep 30, 2026
0d5a2c3
docs(security): record urllib3 lock repair
seonghobae Sep 30, 2026
e65f595
docs(doctoring): trace urllib3 CVE repair
seonghobae Sep 30, 2026
dde3ea7
docs(gap): track shared urllib3 closure
seonghobae Sep 30, 2026
a2f73a4
merge: integrate canonical urllib3 security owner
seonghobae Sep 30, 2026
9b4258d
fix(security): advance PyJWT beyond parser DoS
seonghobae Sep 30, 2026
f6a8bf5
merge: integrate PyJWT security-owner head
seonghobae Sep 30, 2026
e5359ba
fix(security): advance shared PyJWT lock to 2.15.0
seonghobae Sep 30, 2026
516471f
merge: integrate concurrent PyJWT security repair
seonghobae Sep 30, 2026
5b3a76e
merge: integrate current PyJWT owner evidence
seonghobae Sep 30, 2026
135f611
test(review): reproduce transient trusted archive failure
seonghobae Sep 30, 2026
08d8506
fix(security): patch document reader transitives
seonghobae Sep 30, 2026
a997842
fix(review): retry transient trusted archive downloads
seonghobae Sep 30, 2026
29ebc1e
test(security): require Noema transitive source owner
seonghobae Sep 30, 2026
91f20d2
fix(security): own Noema transitive overrides
seonghobae Sep 30, 2026
298b443
test(security): reproduce Noema reader dependency findings
seonghobae Sep 30, 2026
0ebbd07
fix(security): update Noema reader transitive dependencies
seonghobae Sep 30, 2026
93433af
merge(security): integrate shared dependency prerequisite
seonghobae Sep 30, 2026
ee21e11
merge(security): integrate canonical Noema dependency owner
seonghobae Sep 30, 2026
9a4af5e
fix(security): narrow transitive floor and scan nested locks
seonghobae Sep 30, 2026
6a9bb74
merge(security): refresh canonical Noema dependency owner
seonghobae Sep 30, 2026
bd3cfe8
docs(test): align leaf evidence with patched dependency floor
seonghobae Sep 30, 2026
61a3f2e
docs(security): remove trailing blank-line regression
seonghobae Sep 30, 2026
8e3116e
test(docs): reject truncated gap baseline renderings
seonghobae Sep 30, 2026
5a91ce9
fix(docs): restore complete product gap baseline
seonghobae Sep 30, 2026
fe879f7
fix(security): patch shared Strix LiteLLM lock
seonghobae Oct 1, 2026
3a332c5
merge(security): integrate current shared owner repair
seonghobae Oct 1, 2026
eb05a35
fix(security): replace suppressed maturin URL opener
seonghobae Oct 1, 2026
94c48f9
docs(security): bind Gap baseline to exact-head evidence
seonghobae Oct 1, 2026
8f7a674
docs(security): record exact-head admission state
seonghobae Oct 1, 2026
e33d97d
merge(security): integrate bounded maturin downloader
seonghobae Oct 1, 2026
eede925
fix(security): replace audited HTTPSConnection downloader
seonghobae Oct 1, 2026
a5ddcfc
docs(security): bind Maturin SAST RCA to exact evidence
seonghobae Oct 1, 2026
f42da78
fix(docs): restore complete gap baseline after binary corruption
seonghobae Oct 1, 2026
c48981d
docs(security): record bounded Maturin SAST closure
seonghobae Oct 1, 2026
21467ef
fix(security): disable ambient release proxies
seonghobae Oct 1, 2026
7900ba4
merge(security): integrate proxy-free downloader with live evidence
seonghobae Oct 1, 2026
813f16f
merge(security): integrate current proxy-free Maturin owner repair
seonghobae Oct 1, 2026
5cd141e
merge: consume security and metadata owner stack
seonghobae Oct 1, 2026
2d439bb
test(ci): close maturin download responses
seonghobae Oct 1, 2026
8cf2ea5
fix(ci): trigger coverage for maturin verifier
seonghobae Oct 1, 2026
dc54310
fix(ci): admit stacked quality checks
seonghobae Oct 1, 2026
b10b2d0
merge(ci): consume current coverage owner #2530
seonghobae Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions .Jules/palette.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
## 2024-05-20 - Repository without UI Codebase
**Learning:** This repository is a GitHub organization profile consisting entirely of Markdown documentation and static assets, and does not contain an active UI or frontend application codebase.
**Action:** Since there is no UI, no UX enhancements can be applied. Aborting UX enhancements and PR creation as per instructions.
## 2026-09-29 - Product UI boundary confirmed

**Learning:** This repository owns the ContextualWisdomLab GitHub Actions control plane, including production CI scripts, tests, workflows, and documentation. It does not own an interactive product UI or frontend application.

**Action:** Do not invent product UI work in this repository. Improve the control-plane artifacts here and route reusable product UI work to its canonical product owner.
6 changes: 6 additions & 0 deletions .github/workflows/agent-mention-router-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,10 @@ on:
- "scripts/ci/agent_mention_sweep.py"
- "tests/test_agent_mention_*.py"
- "tests/test_pr_review_fix_scheduler_coverage.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "scripts/ci/compile_opencode_review_lock.sh"
push:
branches: [main]
paths:
Expand All @@ -26,7 +29,10 @@ on:
- "scripts/ci/agent_mention_sweep.py"
- "tests/test_agent_mention_*.py"
- "tests/test_pr_review_fix_scheduler_coverage.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "scripts/ci/compile_opencode_review_lock.sh"

concurrency:
group: agent-mention-router-quality-${{ github.repository }}-${{ github.event.pull_request.number || github.ref }}
Expand Down
17 changes: 15 additions & 2 deletions .github/workflows/agent-review-runtime-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,8 @@ on:
- "scripts/ci/contextual_orchestrator_review_sidecar.sh"
- "tests/test_zdr_policy.py"
- "tests/test_contextual_orchestrator_review_policy.py"
- "tests/test_contextual_orchestrator_review_launcher.py"
- "tests/test_review_preflight_concurrency.py"
- "tests/test_contextual_orchestrator_review_sidecar_contract.py"
- "tests/test_sidecar_disk_free_guard.py"
- "tests/test_hourly_review_repair_callers.py"
Expand Down Expand Up @@ -116,9 +118,11 @@ on:
- "docs/doctoring/exact-artifact-sbom-attestation.md"
- "docs/doctoring/exact-artifact-sbom-quality-runner-consolidation-20260903.md"
- "CHANGELOG.d/20260903-exact-artifact-quality-runner-consolidation.md"
- "requirements-opencode-review-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-noema-document-ci.txt"
- "requirements-noema-document-ci-hashes.txt"
- "scripts/ci/compile_opencode_review_lock.sh"

# PR validation only: a new head cancels only an older run of this workflow
# for the same repository and pull request.
Expand Down Expand Up @@ -237,11 +241,13 @@ jobs:
tests/test_strix_quality_timeout_fixture_budget.py)
strix_suite=true
;;
requirements-opencode-review-ci-hashes.txt)
requirements-opencode-review-ci.txt|\
requirements-opencode-review-ci-hashes.txt|\
requirements-noema-document-ci.txt|\
scripts/ci/compile_opencode_review_lock.sh)
noema_suite=true
opencode_suite=true
;;
requirements-noema-document-ci.txt|\
requirements-noema-document-ci-hashes.txt)
noema_suite=true
;;
Expand All @@ -267,6 +273,8 @@ jobs:
scripts/ci/contextual_orchestrator_review_sidecar.sh|\
tests/test_zdr_policy.py|\
tests/test_contextual_orchestrator_review_policy.py|\
tests/test_contextual_orchestrator_review_launcher.py|\
tests/test_review_preflight_concurrency.py|\
tests/test_contextual_orchestrator_review_sidecar_contract.py|\
tests/test_sidecar_disk_free_guard.py|\
tests/test_hourly_review_repair_callers.py|\
Expand Down Expand Up @@ -444,11 +452,14 @@ jobs:
--cov=scripts.ci.pr_review_autofix_context \
--cov=scripts.ci.zdr_policy \
--cov=scripts.ci.contextual_orchestrator_review_policy \
--cov=scripts.ci.contextual_orchestrator_review_launcher \
--cov-branch \
--cov-fail-under=100 \
tests/test_pr_review_conflict_scope.py \
tests/test_zdr_policy.py \
tests/test_contextual_orchestrator_review_policy.py \
tests/test_contextual_orchestrator_review_launcher.py \
tests/test_review_preflight_concurrency.py \
tests/test_contextual_orchestrator_review_sidecar_contract.py \
tests/test_sidecar_disk_free_guard.py \
tests/test_hourly_review_repair_callers.py \
Expand Down Expand Up @@ -488,6 +499,8 @@ jobs:
scripts/ci/contextual_orchestrator_review_launcher.py \
tests/test_zdr_policy.py \
tests/test_contextual_orchestrator_review_policy.py \
tests/test_contextual_orchestrator_review_launcher.py \
tests/test_review_preflight_concurrency.py \
tests/test_contextual_orchestrator_review_sidecar_contract.py \
tests/test_sidecar_disk_free_guard.py \
tests/test_hourly_review_repair_callers.py \
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/noema-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -493,6 +493,10 @@ jobs:
trusted_archive="${RUNNER_TEMP}/trusted-noema-source.tar.gz"
api_url="${GITHUB_API_URL:-https://api.github.com}"
curl -fsSL \
--retry 3 \
--retry-all-errors \
--retry-delay 1 \
--retry-max-time 30 \
-H "Authorization: Bearer ${GH_TOKEN}" \
-H "Accept: application/vnd.github+json" \
-o "$trusted_archive" \
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/opencode-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,10 @@ jobs:
api_url="${GITHUB_API_URL:-https://api.github.com}"
mkdir -p "$trusted_source_dir"
curl -fsSL \
--retry 3 \
--retry-all-errors \
--retry-delay 1 \
--retry-max-time 30 \
-H "Authorization: Bearer ${GH_TOKEN}" \
-H "Accept: application/vnd.github+json" \
-o "$trusted_archive" \
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/pr-review-merge-scheduler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -354,6 +354,10 @@ jobs:
trusted_archive="${RUNNER_TEMP}/trusted-scheduler-source.tar.gz"
api_url="${GITHUB_API_URL:-https://api.github.com}"
curl -fsSL \
--retry 3 \
--retry-all-errors \
--retry-delay 1 \
--retry-max-time 30 \
-H "Authorization: Bearer ${GH_TOKEN}" \
-H "Accept: application/vnd.github+json" \
-o "$trusted_archive" \
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/repository-metadata-reconcile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ on:
paths:
- "config/repository-metadata.json"
- "config/repository-label-taxonomy.json"
- "docs/doctoring/repository-label-taxonomy-wave-3.md"
- "docs/doctoring/repository-public-surface-reconciliation.md"
- "scripts/ci/reconcile_repository_metadata.py"
- "scripts/ci/reconcile_repository_labels.py"
- "tests/test_repository_metadata_reconciliation.py"
Expand All @@ -14,10 +16,15 @@ on:
- "tests/test_repository_metadata_workflow.py"
- "tests/test_repository_metadata_workflow_pages.py"
- "tests/test_repository_label_taxonomy.py"
- "tests/test_repository_label_taxonomy_workflow_trigger.py"
- "tests/test_repository_label_reconciliation.py"
- "tests/test_repository_label_convergence.py"
- "tests/test_repository_label_identity.py"
- "tests/test_repository_label_live_verification.py"
- "requirements-opencode-review-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-noema-document-ci.txt"
- "scripts/ci/compile_opencode_review_lock.sh"
- ".github/workflows/repository-metadata-reconcile.yml"
schedule:
- cron: "23 * * * *"
Expand All @@ -42,6 +49,7 @@ jobs:
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false
- name: Verify exact revision
shell: bash
Expand Down
12 changes: 11 additions & 1 deletion .github/workflows/trusted-uv-materializer-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,28 +2,37 @@ name: Trusted uv Materializer Quality CI

on:
pull_request:
branches: [main]
paths:
- ".github/workflows/trusted-uv-materializer-quality-ci.yml"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/verify_release_maturin_tool_assets.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
- "tests/test_verify_release_maturin_tool_assets.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "scripts/ci/compile_opencode_review_lock.sh"
- "pyproject.toml"
push:
branches: [main]
paths:
- ".github/workflows/trusted-uv-materializer-quality-ci.yml"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/verify_release_maturin_tool_assets.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
- "tests/test_verify_release_maturin_tool_assets.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "scripts/ci/compile_opencode_review_lock.sh"
- "pyproject.toml"

concurrency:
Expand Down Expand Up @@ -98,6 +107,7 @@ jobs:
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha }}
fetch-depth: 0

- name: Set up current stable Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
Expand Down
7 changes: 7 additions & 0 deletions CHANGELOG.d/20260930-github-api-http-error-close.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
## Fixed

- Close file-like `HTTPError` responses in the central CodeQL, Strix, Noema,
Pingora, review-preflight, Pages, and sandbox-readiness clients after bounded
status/telemetry extraction, preventing Python 3.14 resource leaks without
permitting redirects, suppressing warnings, or weakening bearer-token
authority checks; cap CodeQL diagnostic error-body reads at 400 bytes.
8 changes: 5 additions & 3 deletions CHANGELOG.d/20260930-semgrep-maturin-asset-urlopen.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

- `scripts/ci/verify_release_maturin_tool_assets.py` fetches from a fixed
`https://github.com/PyO3/maturin/releases/download/v1.15.0/` origin, and `verify_assets` admits only
five literal asset names, but `p/default`'s `dynamic-urllib-use-detected` flagged the call on
main and failed Semgrep on every PR. The call now carries the repository's standard reasoned
`nosemgrep`/`nosec B310` suppression.
five literal asset names. The downloader now uses a standard-library opener
that admits one credential-free HTTPS redirect only from the exact GitHub
release path to `release-assets.githubusercontent.com`, bounds the response,
and closes it on every path. It uses neither `urlopen` nor
`HTTPSConnection`, and carries no `nosemgrep` or `nosec` suppression.
5 changes: 5 additions & 0 deletions CHANGELOG.d/20261001-gap-baseline-source-restoration.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Fixed

- Restore the complete product and technical gap baseline after a connector
display truncation replaced the source artifact, and add a regression guard
that rejects future truncation banners.
5 changes: 5 additions & 0 deletions CHANGELOG.d/20261001-noema-document-reader-dependencies.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
### Noema document reader closes new transitive advisories

- The generated npm lock now selects `fast-uri` 3.1.8 and `ip-address` 10.7.1,
removing the three medium-severity findings published against the previous
transitive versions while leaving the direct runtime manifest unchanged.
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
### Noema document reader transitive security updates

- Updated the locked `fast-uri` dependency from 3.1.7 to 3.1.8 and
`ip-address` from 10.7.0 to 10.7.1. These are the first releases outside
the affected ranges for GHSA-hrr3-gc8f-f4qj, GHSA-j6r3-76f7-8jcv, and
GHSA-h3mg-xc3c-68pw. The direct dependency ranges are unchanged.
- Added a deterministic regression contract that rejects reintroduction of
vulnerable hoisted or nested copies of either transitive package.
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
### Shared Strix LiteLLM security floor

- Pinned LiteLLM 1.94.3 in the Strix source input and regenerated the complete
hash lock after exact-head `pip-audit` found CVE-2026-84377 in 1.94.1.
- Added a source/lock parity regression contract and preserved the stacked Noema
document-reader transitive security repair without copying its implementation.
6 changes: 6 additions & 0 deletions CHANGELOG.d/20261001-trusted-review-archive-retry.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
### Central review source survives transient GitHub archive failures

- Required Noema, Required OpenCode, and the PR review merge scheduler now use
bounded native `curl` retries when materializing the immutable trusted
`.github` source archive. Authentication, exact-SHA binding, extraction, and
fail-closed behavior are unchanged.
78 changes: 78 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,81 @@
### Maturin download failures close every transport response

- Refactor the bounded Maturin asset downloader so successful and rejected
responses share one unconditional close path while `HTTPError` keeps its own
explicit close path. A new regression exercises a non-200 response and an
opener-raised HTTP error. This removes an impossible optional-response branch
without changing hosts, redirects, byte limits, hashes, or fail-closed error
mapping; the focused suite is 17 passed with 100% statement and branch
coverage. The trusted full-suite workflow now also tracks the verifier source
and its focused test, so a future lifecycle change cannot omit the repository
coverage gate that detected this regression. The pull-request trigger admits
stacked canonical-owner bases as well as `main`; the protected-branch push
trigger remains restricted to `main`.

### Shared Strix lock advances beyond the PyJWT recursion DoS

- Advance the explicit Strix source pin and generated hash lock from PyJWT
`2.14.0` to `2.15.0`, closing GHSA-42vr-xj54-vc7v / CVE-2026-101918. Exact Security
Scan run `36741151937` found the advisory in dependent PR #2540; the
canonical owner repair stays in #2531. A source/lock contract, deterministic
lock regeneration, and pip-audit evidence keep the dependent branch free of a
leaf workaround and prevent a return to `2.14.0`. Exact-head hosted security
Checks, independent approval, ordinary protected integration, and immutable
consumer-pin advancement remain required before release admission.

### Shared urllib3 locks close proxy and streaming CVEs

- Pin urllib3 2.8.0 as an explicit source input in both the pip-audit and
Strix security-tooling closures, regenerate their hash locks without unrelated
version movement, and add a four-file parity contract. This closes
CVE-2026-97687 and CVE-2026-97689 found by exact-head Python Security while
preserving hash checking and the existing Strix cryptography override.

### Full-suite parser locks and honest branch coverage converge

- Consolidated the complete valid ancestry of `.github#2521` into `.github#2530`
with ordinary two-parent merges so the parser-lock and repository-coverage
gates no longer wait on one another. Behavior-level tests exercise the final
branches in the OpenCode queue, Strix dependency classifier, release runtime
prescreener, and release dependency gate without exclusions, pragmas,
threshold reductions, or sample shrinking. Direct consumers of the common
generated lock now also track both source requirements and the canonical
compiler. `.github#2532`'s warning-fatal HTTP response-lifecycle repair is
carried in the same successor so the complete suite can regenerate one
exact-head receipt. Protected hosted Checks and qualifying independent review
remain mandatory before ordinary merge; predecessors remain open until
merged-tree equivalence is proven. The combined Python 3.14 warnings-fatal
suite passes 5,291 tests with 5 optional skips and 40 subtests; all 18,729
production statements and 7,642 branches are covered, and production
Docstring coverage is 100%. The durable review-repair owner also triggers,
executes, compiles, and measures both launcher runtime suites at 100%.
Exact Git blobs, Cargo development locks, runtime receipts, final fanout caps,
and the Python 3.10 TOML fallback are covered as explicit trust boundaries;
one unreachable postcondition was removed only after prior fail-closed
validation made that state mechanically impossible.

### Full-suite quality environments install their collection parsers

- The common OpenCode quality input now owns the existing hash-pinned
`defusedxml` document parser and `PyYAML` workflow parser used during complete
repository test collection. Its Python 3.14/Linux lock was regenerated by
the repository compiler without manual hash edits. Local verification
reproduced the lock byte-for-byte, installed the common and Noema locks
together, imported both parsers, and passed 73 focused contracts with two
optional skips. Hosted exact-head Checks and qualifying independent review
remain required before protected merge.

### Shared security fixtures use patched PyJWT and PyO3 releases

- The Strix hash lock now takes PyJWT `2.14.0` as an explicit source input,
closing CVE-2026-102274 without hiding the dependency in the cryptography-only
override file. The offline Rust coverage fixture advances from PyO3 `0.22.6`
to `0.29.2`, beyond the `0.29.0` fixes for GHSA-36hh-v3qg-5jq4 and
GHSA-chgr-c6px-7xpp. Source/lock parity tests prevent either generated lock
from silently returning to the vulnerable versions. Protected integration,
immutable consumer-pin advancement, and fresh exact-head hosted security
Checks remain required before release admission.

### Intel macOS native archives are bound to x86_64 bytes

- The release prescreener now requires every native member in an Intel macOS
Expand Down
Loading
Loading