Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
104 commits
Select commit Hold shift + click to select a range
e8b5386
chore: refresh org SBOM inventory
Sep 2, 2026
252fbe9
chore: refresh org SBOM inventory
Sep 2, 2026
3112343
chore: preserve SBOM inventory publication lineage
Sep 2, 2026
de8ed6e
chore: refresh org SBOM inventory
Sep 3, 2026
f221c87
chore: preserve SBOM inventory publication lineage
Sep 3, 2026
819ce60
chore: refresh org SBOM inventory
Sep 3, 2026
96c2159
chore: preserve SBOM inventory publication lineage
Sep 3, 2026
aeda71b
chore: refresh org SBOM inventory
Sep 4, 2026
c69893b
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
f300c14
chore: refresh org SBOM inventory
Sep 4, 2026
0b47e88
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
3a9fc3c
chore: refresh org SBOM inventory
Sep 4, 2026
a39c349
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
28437a3
Merge branch 'main' into automation/sbom-inventory
opencode-agent[bot] Sep 4, 2026
4d704ab
chore: refresh org SBOM inventory
Sep 4, 2026
35d7904
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
434ac80
Merge branch 'main' into automation/sbom-inventory
opencode-agent[bot] Sep 4, 2026
fd067fa
chore: refresh org SBOM inventory
Sep 4, 2026
4993226
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
8c6f95d
chore: refresh org SBOM inventory
Sep 4, 2026
f3b6515
chore: preserve SBOM inventory publication lineage
Sep 4, 2026
5b01c72
chore: refresh org SBOM inventory
Sep 5, 2026
4a1a98b
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
ca3c1cc
chore: refresh org SBOM inventory
Sep 5, 2026
1aaacb7
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
ec71e9e
Merge branch 'main' into automation/sbom-inventory
opencode-agent[bot] Sep 5, 2026
f430730
chore: refresh org SBOM inventory
Sep 5, 2026
ab9e2f4
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
6f8c51d
fix(dispatch): parse the trusted-dispatcher allowlist identically in …
seonghobae Sep 5, 2026
3f88e13
fix(codeql): serialise the dispatched scan matrix with toJSON (#1926)
seonghobae Sep 5, 2026
fd54ff6
chore: refresh org SBOM inventory
Sep 5, 2026
fe64665
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
7f4c5e3
fix(scheduler): hold pre-review branch updates while current-head che…
seonghobae Sep 5, 2026
2e8b13a
chore: refresh org SBOM inventory
Sep 5, 2026
f62edde
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
f2f91b8
fix(review): round-robin catalog fill across accounts within a tier (…
seonghobae Sep 5, 2026
de7b74e
chore: refresh org SBOM inventory
Sep 5, 2026
d6ffa3a
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
0149546
chore: refresh org SBOM inventory
Sep 5, 2026
9cf3a3d
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
d9eb9f7
fix(sidecar): record the orchestrator's per-attempt trace in the revi…
seonghobae Sep 5, 2026
972b74b
fix(sidecar): let the stream sanitizer pass orchestrator route and ci…
seonghobae Sep 5, 2026
fe827e1
fix(noema): upload the sidecar stderr and preflight report when the v…
seonghobae Sep 5, 2026
8709b25
chore: refresh org SBOM inventory
Sep 5, 2026
d78239c
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
eb74baa
chore: refresh org SBOM inventory
Sep 5, 2026
7af52ca
chore: preserve SBOM inventory publication lineage
Sep 5, 2026
0e42fbc
fix(sidecar): keep transient-rejected preflight routes as deferred fa…
seonghobae Sep 6, 2026
53c0a87
docs(sidecar): describe the deferral bound in passthrough terms
seonghobae Sep 6, 2026
37a1129
docs(sidecar): state the deferral bound in terms of the gateway retry…
seonghobae Sep 6, 2026
ce7dd4b
chore: refresh org SBOM inventory
Sep 6, 2026
a2dbb8e
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
6d897c9
fix(sidecar): fill the preflight served set lazily to a readiness target
seonghobae Sep 6, 2026
b270bde
fix(sidecar): cap every preflight stage's candidate list at the probe…
seonghobae Sep 6, 2026
a912575
fix(sidecar): keep the exception type and innermost frame per traceback
Sep 6, 2026
efb8926
fix(sidecar): bump vendored contextual-orchestrator pin to fix orches…
seonghobae Sep 6, 2026
e4c9c44
Merge remote-tracking branch 'origin/main' into fix/preflight-defer-t…
seonghobae Sep 6, 2026
384903d
Merge branch 'fix/preflight-defer-transient-routes' into fix/prefligh…
seonghobae Sep 6, 2026
71562e0
Merge branch 'main' into fix/sidecar-sanitizer-traceback-type-20260906
Sep 6, 2026
82ed98d
fix(sidecar): skip an account after two consecutive 429s at preflight
seonghobae Sep 6, 2026
3a1e10b
docs(adr-0029): state the probe cap's wall-time bound with the first …
seonghobae Sep 6, 2026
46f5761
Merge pull request #1947 from ContextualWisdomLab/fix/preflight-defer…
seonghobae Sep 6, 2026
1a49cc9
Merge remote-tracking branch 'origin/main' into fix/preflight-lazy-fill
seonghobae Sep 6, 2026
e18d846
Merge branch 'main' into fix/sidecar-sanitizer-traceback-type-20260906
Sep 6, 2026
ff9848a
Merge pull request #1950 from ContextualWisdomLab/fix/sidecar-sanitiz…
seonghobae Sep 6, 2026
27d478d
Merge remote-tracking branch 'origin/main' into fix/preflight-lazy-fill
seonghobae Sep 6, 2026
fb2ae81
Merge pull request #1949 from ContextualWisdomLab/fix/preflight-lazy-…
seonghobae Sep 6, 2026
fdc2b52
chore: refresh org SBOM inventory
Sep 6, 2026
b89a33a
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
4302463
fix(strix): name the sandbox bootstrap failure and give it a bounded …
seonghobae Sep 6, 2026
ccee8e2
chore: refresh org SBOM inventory
Sep 6, 2026
3c84cdf
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
5ea1cc4
ci(review): coalesce superseded OpenCode review dispatches before adm…
seonghobae Sep 6, 2026
0b0f104
fix(preflight): postpone a rate-limited account's candidates instead …
seonghobae Sep 6, 2026
c232ca0
fix(strix): sanitize strix-agent's recovered transient replay warning…
seonghobae Sep 6, 2026
dd0b96f
fix(review): name the Strix sandbox class in the failed-check finding…
seonghobae Sep 6, 2026
a1aa77c
chore: refresh org SBOM inventory
Sep 6, 2026
95b1d84
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
ee5567f
test(actions): pin concurrency group keys against comment leakage (#1…
seonghobae Sep 6, 2026
6e014c9
fix(actions): coalesce superseded agent mentions while they are queue…
seonghobae Sep 6, 2026
9aad23c
test(actions): parse the concurrency group instead of slicing the blo…
seonghobae Sep 6, 2026
ad0779b
fix(scheduler): skip review dispatch for a head whose merge tree cann…
seonghobae Sep 6, 2026
49eb9e7
test(actions): anchor cancel-in-progress contracts so a flipped flag …
seonghobae Sep 6, 2026
858aae1
chore: refresh org SBOM inventory
Sep 6, 2026
6e44c37
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
5c60b5d
test(concurrency): pin the cancel flag as a value for the PR-keyed sc…
seonghobae Sep 6, 2026
74224b2
fix(scheduler): match the run name GitHub actually sends for central …
seonghobae Sep 6, 2026
2396ddc
Revert "fix(scheduler): skip review dispatch for a head whose merge t…
seonghobae Sep 6, 2026
bf0bf0a
fix(audit): stop a ruleset drift from disabling the CodeQL coverage d…
seonghobae Sep 6, 2026
c9052e6
fix(audit): count the repositories examined, not the ones supplied (#…
seonghobae Sep 6, 2026
d568544
chore: refresh org SBOM inventory
Sep 6, 2026
994e356
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
db93a9e
chore: refresh org SBOM inventory
Sep 6, 2026
43fa180
chore: preserve SBOM inventory publication lineage
Sep 6, 2026
e67d786
chore: refresh org SBOM inventory
Sep 7, 2026
df02aad
chore: preserve SBOM inventory publication lineage
Sep 7, 2026
57b3493
chore: refresh org SBOM inventory
Sep 7, 2026
1e80114
chore: preserve SBOM inventory publication lineage
Sep 7, 2026
dd7ea81
fix(codeql): dispatch one current-head scan per pull request (#2008)
seonghobae Sep 7, 2026
78a4937
fix(codeql): accept queued pre-cutover scan-dispatch payloads (#2009)
seonghobae Sep 7, 2026
8befedc
chore: refresh org SBOM inventory
Sep 7, 2026
5f264b1
chore: preserve SBOM inventory publication lineage
Sep 7, 2026
4fb5293
chore: refresh org SBOM inventory
Sep 7, 2026
6c98f3c
chore: preserve SBOM inventory publication lineage
Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/actions/orchestrator-free-sidecar/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@ inputs:
required: false
default: "false"
catalog_limit:
description: Maximum discovered route catalog size for the sidecar preflight.
description: Maximum discovered route catalog size for the sidecar preflight (a candidate list probed lazily to a readiness target, ADR-0029).
required: false
default: "12"
default: "24"
catalog_account_cap:
description: Maximum routes admitted from one credential account.
required: false
Expand Down
17 changes: 14 additions & 3 deletions .github/workflows/agent-mention-noema-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,26 @@ on:
repository_dispatch:
types: [agent-mention-noema]

concurrency:
# Workflow-level admission, for the same reason strix.yml, noema-review.yml,
# opencode-review.yml and opencode-review-dispatch.yml carry theirs at this level:
# a job-level group is never evaluated while the whole run waits behind the
# organization job ceiling, so a superseded mention keeps its queue slot until a
# runner frees up and only then cancels. At workflow level the older run is
# coalesced while both are still queued, which is where the slot is actually held.
# This workflow has a single job, so the group lives here and nowhere else --
# every workflow in this repository that carries a group at both levels
# (strix.yml, opencode-review-dispatch.yml) gives the two levels DIFFERENT names,
# because a job requesting the group its own run already holds would wait on itself.
group: agent-mention-noema-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
validate-and-forward:
if: github.repository == 'ContextualWisdomLab/.github'
concurrency:
group: agent-mention-noema-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
Expand Down
17 changes: 14 additions & 3 deletions .github/workflows/agent-mention-opencode-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,26 @@ on:
repository_dispatch:
types: [agent-mention-opencode]

concurrency:
# Workflow-level admission, for the same reason strix.yml, noema-review.yml,
# opencode-review.yml and opencode-review-dispatch.yml carry theirs at this level:
# a job-level group is never evaluated while the whole run waits behind the
# organization job ceiling, so a superseded mention keeps its queue slot until a
# runner frees up and only then cancels. At workflow level the older run is
# coalesced while both are still queued, which is where the slot is actually held.
# This workflow has a single job, so the group lives here and nowhere else --
# every workflow in this repository that carries a group at both levels
# (strix.yml, opencode-review-dispatch.yml) gives the two levels DIFFERENT names,
# because a job requesting the group its own run already holds would wait on itself.
group: agent-mention-opencode-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true

permissions:
contents: read

jobs:
validate-and-forward:
if: github.repository == 'ContextualWisdomLab/.github'
concurrency:
group: agent-mention-opencode-${{ github.event.client_payload.target_repository }}-${{ github.event.client_payload.pr_number || github.run_id }}
cancel-in-progress: true
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
Expand Down
33 changes: 27 additions & 6 deletions .github/workflows/audit-central-ruleset.yml
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,18 @@ jobs:
python3 scripts/ci/audit_central_required_workflows.py --stacked "$stacked_ruleset_json"

- name: Audit organization CodeQL coverage
# Runs even when the ruleset step above failed. Those two audits share a
# job but not a subject: the ruleset step exits 1 on owner-configured
# governance drift, and on 2026-09-06 it did exactly that ("exactly two
# approving reviews are not required", "last-push approval protection is
# disabled"), which silently took this CodeQL coverage detector down with
# it -- every run since 2026-09-04 failed there and never reached this
# step. This step builds its own repository list into its own temp file
# and the step above exports nothing to GITHUB_ENV or GITHUB_OUTPUT, so
# it has no data dependency to lose. The job still fails overall; what
# changes is that a coverage gap is reported instead of hidden behind an
# unrelated failure.
if: always()
env:
ORG_LOGIN: ContextualWisdomLab
ORG_WIDE_CREDENTIAL_AVAILABLE: ${{ secrets.PR_REVIEW_MERGE_TOKEN != '' || secrets.OPENCODE_APPROVE_TOKEN != '' }}
Expand Down Expand Up @@ -165,13 +177,21 @@ jobs:
printf '[]\n' >"$coverage_json"
while IFS=$'\t' read -r repository archived; do
default_setup_state=null
# `state` alone is not coverage: a repository can report
# "configured" with an empty `languages` list, which scans nothing
# and produces no analyses (measured 2026-09-07 on life-os, aFIPC
# and inkspan). Collect both fields so the audit can tell those
# apart from a setup that actually covers a language.
default_setup_languages=null
if [ "$archived" != "true" ]; then
default_setup_state_json="$RUNNER_TEMP/codeql-default-setup-${repository//[^A-Za-z0-9_.-]/_}.json"
if gh api "repos/${ORG_LOGIN}/${repository}/code-scanning/default-setup" --jq .state \
>"$default_setup_state_json" 2>/dev/null; then
default_setup_state=$(jq -R '.' "$default_setup_state_json")
default_setup_json="$RUNNER_TEMP/codeql-default-setup-${repository//[^A-Za-z0-9_.-]/_}.json"
if gh api "repos/${ORG_LOGIN}/${repository}/code-scanning/default-setup" \
>"$default_setup_json" 2>/dev/null; then
default_setup_state=$(jq '.state // null' "$default_setup_json")
default_setup_languages=$(jq '.languages // []' "$default_setup_json")
else
default_setup_state=null
default_setup_languages=null
fi
fi

Expand All @@ -187,12 +207,13 @@ jobs:
fi
fi

echo "CODEQL_COVERAGE repository=${repository} archived=${archived} default_setup_state=${default_setup_state} latest_codeql_analysis=${latest_codeql_analysis}"
echo "CODEQL_COVERAGE repository=${repository} archived=${archived} default_setup_state=${default_setup_state} default_setup_languages=${default_setup_languages} latest_codeql_analysis=${latest_codeql_analysis}"
jq --arg name "$repository" \
--argjson archived "$archived" \
--argjson default_setup_state "$default_setup_state" \
--argjson default_setup_languages "$default_setup_languages" \
--argjson latest_codeql_analysis "$latest_codeql_analysis" \
'. + [{name: $name, archived: $archived, default_setup_state: $default_setup_state, latest_codeql_analysis: $latest_codeql_analysis}]' \
'. + [{name: $name, archived: $archived, default_setup_state: $default_setup_state, default_setup_languages: $default_setup_languages, latest_codeql_analysis: $latest_codeql_analysis}]' \
"$coverage_json" >"${coverage_json}.next"
mv "${coverage_json}.next" "$coverage_json"
done < <(jq -r '.[] | [.name, (.archived | tostring)] | @tsv' "$repositories_json")
Expand Down
Loading
Loading