Skip to content

fix(semgrep): make the pinned image digest authoritative - #941

Merged
seonghobae merged 34 commits into
mainfrom
fix/semgrep-digest-single-source-20260812
Aug 28, 2026
Merged

fix(semgrep): make the pinned image digest authoritative#941
seonghobae merged 34 commits into
mainfrom
fix/semgrep-digest-single-source-20260812

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • keep the current Semgrep OSS 1.169.0 immutable image reference in one job-level SEMGREP_IMAGE variable;
  • validate that the value is a complete 64-hex SHA-256 manifest reference;
  • resolve that exact manifest before scanning and use the same value for docker run;
  • fail closed with an explicit error instead of allowing a partial local digest to surface as an ambiguous image-manifest failure.

The unchanged digest remains:

semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942

Scan scope, severities, SARIF handling, credentials, permissions, metrics-off behavior, and the existing fail-closed Semgrep gate remain unchanged.

Exact-current-head verification

  • protected base: main@d2c554dbbc04854db6215970fabb70cef1ceb690;
  • exact current head: 7b0edae3b2a8c59388d2df1e493daf97a20cb4b1;
  • changed surface: 8 owner files, including exact-head SAST checkout/attestation, SARIF identity, executable contracts, and immutable-image documentation;
  • this branch was synchronized with protected main by a non-force two-parent merge while preserving main's current Strix/OpenCode contracts;
  • hosted exact-head checks and independent review have been regenerated for this head; pending, queued, skipped, cancelled, predecessor, or absent evidence is non-passing.

Merge only after every required current-head check, zero valid unresolved findings, and the required qualifying independent approvals pass.

Summary by CodeRabbit

  • 보안 강화

    • Semgrep 실행에 고정된 이미지 다이제스트를 사용해 실행 환경의 일관성과 무결성을 강화했습니다.
    • 실행 전 다이제스트 형식과 이미지 매니페스트를 검증하며, 검증 실패 시 작업이 중단됩니다.
    • 스캔과 결과 업로드가 정확한 PR 커밋을 기준으로 수행되도록 검증을 강화했습니다.
  • 문서

    • Semgrep 이미지 다이제스트 단일 소스 정책과 관련 보안 지침을 문서화했습니다.
  • 테스트

    • 이미지 고정, 단일 참조, 매니페스트 검증 및 정확한 커밋 바인딩을 확인하는 테스트를 추가했습니다.

Open in Devin Review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f37a7b80-0075-48cd-aecd-92ad85d8714a

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 34d3b306-0212-4795-b3bc-7ab5f2024b53

📥 Commits

Reviewing files that changed from the base of the PR and between 3dfa07e and bdac48b.

📒 Files selected for processing (7)
  • .github/workflows/sast-semgrep.yml
  • AGENTS.md
  • ARCHITECTURE.md
  • CHANGELOG.md
  • CLAUDE.md
  • tests/test_central_required_workflow_ruleset_audit.py
  • tests/test_required_workflow_queue_contract.py
🚧 Files skipped from review as they are similar to previous changes (2)
  • AGENTS.md
  • CLAUDE.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Semgrep 워크플로가 고정 SHA256 digest를 검증하고 사용한다. PR head 리비전을 정확히 체크아웃하고 검증한다. SARIF 업로드를 PR head ref와 SHA에 연결한다. 문서와 테스트가 이 계약을 반영한다.

Changes

Semgrep 워크플로 무결성

Layer / File(s) Summary
이미지 digest 고정 및 실행 전 검증
.github/workflows/sast-semgrep.yml, tests/test_central_required_workflow_ruleset_audit.py, docs/doctoring/semgrep-image-digest-single-source.md
SEMGREP_IMAGE에 고정 digest를 설정한다. 실행 전에 64자리 SHA256 형식과 Docker 매니페스트를 검증한다. 로그와 Semgrep 실행에 동일한 환경 변수를 사용한다. 테스트는 이 계약을 확인한다.
정확한 제출 리비전 체크아웃 및 SARIF 연결
.github/workflows/sast-semgrep.yml, tests/test_required_workflow_queue_contract.py
PR head 저장소와 SHA를 명시적으로 체크아웃한다. 실제 HEAD가 예상 SHA와 다르면 작업을 중단한다. SARIF 업로드에 PR head ref와 SHA를 지정한다.
운영 계약 및 관련 문서 갱신
AGENTS.md, ARCHITECTURE.md, CLAUDE.md, CHANGELOG.md
동일한 job-level SEMGREP_IMAGE digest를 로그 증거, 매니페스트 검사, docker run에 사용한다는 계약을 기록한다. 관련 문서 링크와 변경 내역을 갱신한다.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Merge Risk: ⚪ Minimal · up to bdac4

The PR validates and reuses one immutable Semgrep image digest, failing closed before scanning if it is malformed or unavailable. No actionable merge-blocking risk remains after normal checks and review.

Sequence Diagram(s)

sequenceDiagram
  participant GitHub as GitHub event
  participant Workflow as Semgrep workflow
  participant Docker as Docker CLI
  participant Registry as Container registry
  participant Semgrep as Semgrep container
  participant SARIF as SARIF upload

  GitHub->>Workflow: Provide PR head repository and SHA
  Workflow->>Workflow: Checkout and verify exact HEAD SHA
  Workflow->>Docker: Inspect SEMGREP_IMAGE manifest
  Docker->>Registry: Request fixed digest manifest
  Registry-->>Docker: Return manifest result
  Workflow->>Semgrep: Run scan with validated SEMGREP_IMAGE
  Semgrep->>SARIF: Upload results with PR head ref and SHA
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (5 skipped: 5… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 고정된 Semgrep 이미지 digest를 단일 권위 참조로 사용하는 핵심 변경을 정확하고 간결하게 설명합니다.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (5 skipped: 5 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/semgrep-digest-single-source-20260812

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Current-head verification record (2026-08-12):

  • head: 432497975d8e74822f853e095764ec5bcbcf29c3;
  • base: main at 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;
  • changed surface: .github/workflows/sast-semgrep.yml only;
  • immutable Semgrep image reference is unchanged and now has one workflow source of truth.

At observation time, SAST Semgrep, Scorecard, Secret Scan, OSV-Scanner PR, Python Security, and SBOM Generation were running; Security Scan and CodeQL PR were queued; CodeRabbit was pending. No review or unresolved thread exists yet. Merge remains blocked until all exact-head required checks complete and qualifying independent approval is present.

Copy link
Copy Markdown
Contributor Author

Current-head verification record (2026-08-12 UTC):

  • head: 432497975d8e74822f853e095764ec5bcbcf29c3
  • base: 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba
  • central workflow now keeps the full immutable reference in one SEMGREP_IMAGE variable and uses it for both evidence and docker run;
  • image reference: semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942;
  • the exact Semgrep command completed successfully under the workflow's existing rules, severity, exclusions, SARIF, and metrics-off conditions;
  • all eight hosted checks for this exact head are terminal-success and there are no unresolved review threads.

The earlier local partial-digest manifest failure is therefore addressed at the central source of truth. Merge remains pending current independent review and repository policy approval; no stale or synthetic approval is being used.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 against independently resolved live main 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. Eight exact-head hosted workflows and the separate CodeRabbit status are terminal-success, with no unresolved review thread. Verify that one immutable Semgrep image reference is authoritative for both evidence and execution without weakening rules, severity, exclusions, SARIF, or metrics-off behavior. Automated judgment is not qualifying independent human approval or merge authorization.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 only. The exact-head security and supply-chain workflows are terminal-success. Validate that one job-level SEMGREP_IMAGE immutable digest is the sole source used by both evidence and docker run, with scan scope, severity, SARIF, permissions, credentials, and fail-closed behavior unchanged. Review only; do not mutate, merge, release, or alter protections.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

printf '%s\n' '== checked-out HEAD =='
git rev-parse HEAD
printf '%s\n' '== requested commits available =='
git cat-file -e "${head_expected}^{commit}"
git cat-file -e "${base_expected}^{commit}"

printf '%s\n' '== changed paths: requested base..head =='
git diff --name-status "$base_expected" "$head_expected"

printf '%s\n' '== workflow outline =='
ast-grep outline .github/workflows/sast-semgrep.yml --items all

printf '%s\n' '== exact workflow diff =='
git diff --no-ext-diff --unified=80 "$base_expected" "$head_expected" -- .github/workflows/sast-semgrep.yml

printf '%s\n' '== current workflow source, numbered =='
cat -n .github/workflows/sast-semgrep.yml

printf '%s\n' '== SEMGREP_IMAGE and image invocation references =='
rg -n -C 4 'SEMGREP_IMAGE|semgrep/semgrep|docker\s+run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off' \
  .github/workflows/sast-semgrep.yml

Length of output: 18513


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

printf '%s\n' '== PR refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head_sha: .head.sha, base_sha: .base.sha, state: .state, draft: .draft}'

printf '%s\n' '== check runs attached to the requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, details_url, app: .app.slug}'

printf '%s\n' '== commit statuses attached to the requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/status?per_page=100" \
  --jq '.statuses[] | {context, state, target_url, creator: .creator.login}'

printf '%s\n' '== PR reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

printf '%s\n' '== unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes { isResolved isOutdated comments(first: 1) { nodes { author { login } body } } }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 10858


@seonghobae No findings.

I reviewed only head 432497975d8e74822f853e095764ec5bcbcf29c3 against base 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 defines one job-level SEMGREP_IMAGE value with the required immutable digest.
  • Line 75 uses ${SEMGREP_IMAGE} for log evidence.
  • Line 81 uses ${SEMGREP_IMAGE} for docker run.
  • The scan configuration, severity filters, exclusions, SARIF handling, permissions, credential handling, and fail-closed gate logic are unchanged.
  • The exact-head Semgrep (multi-language SAST) check completed successfully.
  • GitHub reports no unresolved review threads.

I used the repository guidance that only results attached to the exact current head count as check evidence. Some attached checks are skipped or neutral; I did not treat them as successful evidence.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

Learnt from: CR
Repo: ContextualWisdomLab/.github PR: 0
File: CLAUDE.md:0-0
Timestamp: 2026-07-29T06:47:25.581Z
Learning: Applies to opencode.jsonc : All reviewer agents in `opencode.jsonc` must keep `"edit": "deny"`; reviewers must never implement changes.
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review
@coderabbitai review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 only. Validate the one-file central SAST change: the exact immutable Semgrep image reference is declared once in job-level SEMGREP_IMAGE and the identical value is used both for logged evidence and docker run; confirm the digest itself, scan scope, severities, SARIF handling, credentials, permissions, failure semantics, and merge authority are unchanged. All observed exact-head hosted checks are terminal-success and no review thread exists. Review only; do not mutate, merge, release, or bypass protection.

Copy link
Copy Markdown
Contributor Author

Exact-current-head review request for 432497975d8e74822f853e095764ec5bcbcf29c3 over protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

The bounded one-file repair keeps the Semgrep OSS 1.169.0 image digest unchanged and makes one job-level SEMGREP_IMAGE value authoritative for both evidence and execution. CodeQL PR, Python Security, Security Scan, OSV-Scanner PR, Secret Scan, Scorecard PR, SBOM Generation, and SAST Semgrep are terminal-success on this exact head; no review thread exists.

Review this unchanged head read-only. Do not update the branch, synthesize author approval, merge, release, or weaken protection.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
workflow='.github/workflows/sast-semgrep.yml'

printf '%s\n' '== local refs and changed paths =='
test "$(git rev-parse HEAD)" = "$head_expected"
git cat-file -e "${base_expected}^{commit}"
git diff --name-status "$base_expected" "$head_expected"
printf '%s\n' '== exact workflow diff =='
git diff --no-ext-diff --unified=100 "$base_expected" "$head_expected" -- "$workflow"
printf '%s\n' '== workflow outline =='
ast-grep outline "$workflow" --items all
printf '%s\n' '== image references and scan controls =='
rg -n -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker\s+run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|SEMGREP_APP_TOKEN' "$workflow"

printf '%s\n' '== pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head_sha: .head.sha, base_sha: .base.sha, state: .state, draft: .draft}'
printf '%s\n' '== check runs on requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'
printf '%s\n' '== commit statuses on requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'
printf '%s\n' '== reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'
printf '%s\n' '== unresolved threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes { isResolved isOutdated comments(first: 1) { nodes { author { login } body } } }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 16946


@seonghobae No findings.

I reviewed only head 432497975d8e74822f853e095764ec5bcbcf29c3 against base 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 declares SEMGREP_IMAGE once at the semgrep job level.
  • The value is the required immutable reference: semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942.
  • Line 75 logs ${SEMGREP_IMAGE}.
  • Line 81 passes the same ${SEMGREP_IMAGE} value to docker run.
  • The Semgrep configuration, severity filters, exclusions, SARIF processing, permissions, credential handling, and fail-closed gate logic are unchanged.
  • The exact-head Semgrep (multi-language SAST) check succeeded. The direct trivy-fs, scorecard, osv-scan, gitleaks (secret scan), and generate-sbom checks also succeeded.
  • I did not treat neutral or skipped checks as passing evidence, consistent with the repository guidance.
  • GitHub reports no unresolved review threads.

GitHub returned no submitted reviews. Therefore, no independent approval is present in the retrieved review data. This review does not grant merge authority.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

You are interacting with an AI system.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head='432497975d8e74822f853e095764ec5bcbcf29c3'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

echo '== Local commit and changed-path verification =='
printf 'checked_out_head='; git rev-parse HEAD
git cat-file -e "${head}^{commit}"
git cat-file -e "${base}^{commit}"
git diff --name-status "$base" "$head"

echo '== Workflow diff =='
git diff --no-ext-diff --unified=100 "$base" "$head" -- .github/workflows/sast-semgrep.yml

echo '== Relevant workflow lines at requested head =='
git show "${head}:.github/workflows/sast-semgrep.yml" |
  nl -ba |
  grep -E -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|contents:|security-events:|SEMGREP_APP_TOKEN'

echo '== Pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head: .head.sha, base: .base.sha, state, draft}'

echo '== Check runs for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'

echo '== Commit statuses for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'

echo '== Reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

echo '== Unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body } }
        }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 10166


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head='432497975d8e74822f853e095764ec5bcbcf29c3'

echo '== Relevant workflow lines at requested head =='
git show "${head}:.github/workflows/sast-semgrep.yml" |
  cat -n |
  grep -E -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|contents:|security-events:|SEMGREP_APP_TOKEN'

echo '== Pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head: .head.sha, base: .base.sha, state, draft}'

echo '== Check runs for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'

echo '== Commit statuses for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'

echo '== Reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

echo '== Unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body } }
        }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 9034


@seonghobae No findings.

I reviewed only 432497975d8e74822f853e095764ec5bcbcf29c3 against 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 defines the full immutable digest once in job-level SEMGREP_IMAGE.
  • Line 75 uses ${SEMGREP_IMAGE} for evidence logging.
  • Line 81 uses the identical ${SEMGREP_IMAGE} value for docker run.
  • The digest is semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942.
  • Scan scope, severity filters, exclusions, SARIF processing, permissions, credential persistence, and fail-closed behavior are unchanged.
  • The requested head and base still match PR #941.
  • The relevant exact-head checks are completed successfully.
  • I did not count skipped or neutral checks as successful evidence.
  • GitHub reports no unresolved review threads.

GitHub returned no pull-request reviews. Therefore, this review does not establish an independent approval or merge authorization.

I used the repository guidance that only successful checks on the exact current head count as merge evidence.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

You are interacting with an AI system.

@seonghobae
seonghobae enabled auto-merge (squash) August 12, 2026 10:45

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-current-head source review for 432497975d8e74822f853e095764ec5bcbcf29c3 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

The complete one-file diff moves the already-pinned immutable Semgrep manifest reference into one job-level SEMGREP_IMAGE value and uses that exact value for both log evidence and docker run. The digest, scanner version, configuration, severities, exclusions, SARIF handling, metrics policy, permissions, credentials, and fail-closed --error behavior are unchanged. All eight directly triggered exact-head security and supply-chain workflows, including the modified SAST Semgrep workflow itself, are terminal-success and no inline thread exists.

A qualifying independent reviewer must submit formal approval on this unchanged head. Do not update the branch, change the image digest, weaken scanner arguments, synthesize author approval, or bypass protection.

Copy link
Copy Markdown
Contributor Author

Exact-current-head automated review request for 432497975d8e74822f853e095764ec5bcbcf29c3. The bounded one-file refactor retains the identical immutable Semgrep digest and scan semantics; all eight directly triggered workflows are terminal-success and no thread exists. Review read-only without updating the branch or weakening SAST policy.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 26 minutes and 15 seconds before sending another message.

@opencode-agent
opencode-agent Bot disabled auto-merge August 12, 2026 12:12

Copy link
Copy Markdown
Contributor Author

Exact-current-head source review request for 5f51364418eb6e17300e771f9738d0580acad115 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

Check that the job-level immutable Semgrep reference is complete, the preflight resolves the exact manifest, and the scan uses that same reference without changing existing rules, severities, exclusions, SARIF, permissions, credentials, or fail-closed behavior. Review read-only; no digest/tag weakening or merge bypass.

@opencode-agent review
@cwl-noema-review review
@strix review

@seonghobae

Copy link
Copy Markdown
Contributor Author

Reviewed. Added single-digest contract, CHANGELOG, and APA 7th doctoring (NIST SP 800-190, SLSA 1.0). Local suite 977 passed x2, coverage 100%. Auto-merge armed.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 24ca6081e4704ca176ca02015cbbf27e07fbf832.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: bdac48bd483eadf665c15c30b54af17f0d979445
  • Workflow run: 33135347194
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for bdac48bd483eadf665c15c30b54af17f0d979445.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 13, 2026 08:53
@seonghobae
seonghobae enabled auto-merge (squash) August 13, 2026 15:38

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 8fabd327773eb5346f307ffdaa633b2e9f026c9a.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (2 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (2 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["CI script: materialize_base_python_requirements.py"]
  S4 --> I4["review and security gate shell path"]
  I4 --> R4["Review risk: CI script: materialize_base_python_requirements.py"]
  R4 --> V4["bash -n plus Strix self-test"]
  Evidence --> S5["Test (2 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test (2 files)"]
  R5 --> V5["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 14, 2026 01:29
@seonghobae
seonghobae marked this pull request as draft August 14, 2026 09:04

Copy link
Copy Markdown
Contributor Author

Returned to Draft because the exact current tree contradicts the body’s “Semgrep workflow only” scope.

The valid repair is bounded: one job-level immutable SEMGREP_IMAGE, exact full SHA-256 manifest validation/resolution, and reuse of that same value for the scan. Head 8fabd327773eb5346f307ffdaa633b2e9f026c9a additionally changes materialize_base_python_requirements.py, its tests, central ruleset tests, AGENTS, doctoring, and changelog.

Rebuild from protected main retaining only sast-semgrep.yml, the focused digest/ruleset regression, directly attributable doctoring/changelog evidence, and no materializer changes. Update the stale exact-head/check section, then reacquire exact-head Semgrep/CodeQL/security/SBOM and independent-review evidence.

@seonghobae
seonghobae marked this pull request as ready for review August 14, 2026 13:56

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review only exact current head 6015981514956977ebf18e74f3441b3bc560a679 against live protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. I removed the unrelated trusted-uv production delta by restoring the exact Semgrep immutable-manifest authority tree as a new descendant. The current diff is five files and preserves one job-level complete SHA-256 image reference, explicit manifest resolution before scan, the same immutable value for docker run, and fail-closed incomplete refs without changing scan scope, severities, permissions, credentials, metrics, or SARIF semantics. No review thread exists. Exact-head checks are regenerating; nonterminal evidence is not acceptance. Review read-only; do not mutate source, synthesize approval, weaken Semgrep/SLSA controls, or merge.

Copy link
Copy Markdown
Contributor Author

Inkspan consumer revalidation for the exact-source SAST owner path (no Inkspan-local substitute): ContextualWisdomLab/inkspan#201 is currently at exact submitted head 580ac1ad7453d5f6c443b1cea52493bef822844e. Its SAST Semgrep run 32893518440, job 97950685406, is GitHub-success, but the exposed execution sequence is Checkout -> Run Semgrep (SARIF) with no explicit pre-scan exact-repository/exact-submitted-head attestation step. Under Inkspan's exact-source evidence contract that success remains non-passing: a green scanner label without independently asserted source identity cannot prove the submitted head was the bytes scanned. After this owner repair reaches protected central main, rerun the unchanged/descendant Inkspan head and require the Semgrep job to attest the exact submitted repository/SHA before scanner execution and bind the resulting SARIF/gate evidence to that identity. Absent attestation, default/synthetic checkout, queued/skipped/predecessor evidence, or status-only success must not satisfy Inkspan merge/release acceptance.

Copy link
Copy Markdown
Contributor Author

Additional exact-source RED evidence from the existing public consumer path; no Inkspan-local scanner workaround is correct.

Affected consumer: ContextualWisdomLab/inkspan#176, exact contributor head e1345c45ba9bf8e75bdab8ad7f56c7d7437f1470.

Central SAST run 32871291271 is aggregate success, but Semgrep job 97878684332 did not scan that submitted source identity. Its checkout log fetched refs/pull/176/merge, checked out synthetic merge f2f49fc63fe535f1d9628dcae866eaa302b3f20e, and reports HEAD is now at f2f49fc Merge e1345c45... into fd75c835.... Current Inkspan protected main is later (128a239f8b71ca16add4b9e15e21752d1ad63ff0).

That aggregate green is therefore non-passing exact-source evidence under the consumer's release contract: the scan source is a stale synthetic merge, not contributor head e1345c45....

First causal boundary remains the central required Semgrep checkout/identity contract. Acceptance for this owner path is falsifiable: a consumer PR run must log and verify repository ContextualWisdomLab/inkspan, expected SHA e1345c45ba9bf8e75bdab8ad7f56c7d7437f1470, actual checkout SHA equal to that expected SHA, and bind SARIF identity to the same submitted source. Any mismatch must fail closed rather than produce a green SAST gate.

No duplicate scanner branch requested; this comment binds an additional exact affected SHA/run/job to the existing central #941 exact-source repair.

Copy link
Copy Markdown
Contributor Author

Fresh control-plane reconciliation found a revision-identity defect that must be repaired before #941 can authorize downstream exact-head evidence. GitHub currently reports protected main@60a34005e59efe2b622897e3c7b06882bdf63aee and actual PR contributor head 0f7cabaad874a9555b02ebb3a22db9aef3a478ce, while the PR body claims protected base d2c554dbbc04854db6215970fabb70cef1ceb690 and exact current head 7b0edae3b2a8c59388d2df1e493daf97a20cb4b1. The actual head has current terminal-success workflow runs (for example SAST 32947955344, Security 32947955408, CodeQL 32947955330, OSV 32947956073), but the formal review history contains no qualifying review anchored to 0f7caba...; the latest OpenCode REQUEST_CHANGES shown is on predecessor cffb40e.... Treat the body’s claimed SHA/review evidence as stale. Owner-path acceptance: refetch live main/head; reconcile the contributor branch without force/destructive history; update revision-sensitive body/evidence to the actual unchanged head; regenerate required current-head review/check evidence; and only then consider merge. This is also blocking ScopeWeave’s central reusable SAST/Security exact-head authority under #1222.

Copy link
Copy Markdown
Contributor Author

Inkspan downstream canary still proves this owner path is release-critical, and the owning PR has fresh base drift that must be reconciled before its evidence can count.

Exact affected consumer evidence:

  • ContextualWisdomLab/inkspan#389 submitted head: 80160413b87f462e811c7e48161e7ea0f01a230d
  • independently resolved protected Inkspan base: main@128a239f8b71ca16add4b9e15e21752d1ad63ff0
  • required SAST run: 32917948336; Semgrep job: 98025501935
  • checkout fetched refs/pull/389/merge at synthetic merge 5734fb699b62ba2c50217374a67d286cfe18e27d and logged Merge 80160413... into 128a239f...; therefore the successful scan is not exact-submitted-head evidence under the current fail-closed contract.

Fresh owner state:

  • protected .github/main has advanced to e00bd7964f332b69cf7b430b0cb5ad486eef8258.
  • PR fix(semgrep): make the pinned image digest authoritative #941 current head is 0f7cabaad874a9555b02ebb3a22db9aef3a478ce; GitHub currently reports it non-mergeable, while its recorded base SHA is the predecessor 60a34005e59efe2b622897e3c7b06882bdf63aee and its body still names older head/base values.
  • all currently listed inline review threads are resolved, but no qualifying counted APPROVED review is present.

RCA boundary remains central .github SAST ownership, not Inkspan source: the downstream consumer is invoking the organization-required SAST workflow as configured, and the incorrect checkout identity is materialized inside that required workflow. No correct Inkspan-local patch can make a central required workflow scan the submitted head.

Smallest safe owner action: reconcile this existing branch with the new protected main non-destructively, preserving the exact-head checkout/SARIF identity contract already implemented here; rerun all current-head required checks; verify the SAST job checkout SHA equals the PR submitted head rather than refs/pull/*/merge; then obtain the qualifying non-author approval required by live governance before normal integration. Do not transfer predecessor check/review evidence. After integration, rerun the Inkspan #389 canary and require the job log to prove checkout of 80160413b87f462e811c7e48161e7ea0f01a230d exactly.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 632a81e6b08daa2ca1875428f9a72cc683fac8a8.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found source-backed failed-check findings that must be addressed before merge.

  • Result: REQUEST_CHANGES
  • Reason: failed current-head checks were mapped to line-specific findings below for 632a81e6b08daa2ca1875428f9a72cc683fac8a8.
  • Head SHA: 632a81e6b08daa2ca1875428f9a72cc683fac8a8
  • Workflow run: 33000142791
  • Workflow attempt: 1
Failed checks

Findings

1. HIGH .github/workflows/strix.yml:554 - Strix unsupported-model errors must name the allowed providers

  • Problem: Strix failed because the trusted self-test log reported missing "STRIX_LLM must select NVIDIA NIM Nemotron, GitHub Models openai/gpt-5 or newer, direct OpenAI GPT-5.4 or newer, OpenRouter openrouter/free, or an approved organization Vertex AI model".

  • Root cause: The failed check is executing trusted-base workflow material, so this exact line must exist in the trusted workflow/test contract before the check can pass.

  • Fix: Keep or add the current-head line at ".github/workflows/strix.yml:554" so trusted-base Strix/OpenCode evidence contains "STRIX_LLM must select NVIDIA NIM Nemotron, GitHub Models openai/gpt-5 or newer, direct OpenAI GPT-5.4 or newer, OpenRouter openrouter/free, or an approved organization Vertex AI model".

  • Regression test: Keep scripts/ci/test_strix_quick_gate.sh assertions covering this exact string.

  • Suggested edit: ensure .github/workflows/strix.yml:554 contains the literal STRIX_LLM must select NVIDIA NIM Nemotron, GitHub Models openai/gpt-5 or newer, direct OpenAI GPT-5.4 or newer, OpenRouter openrouter/free, or an approved organization Vertex AI model; if the line was removed from trusted-base material, restore it exactly before approving.

2. HIGH .github/workflows/strix.yml:862 - Strix provider failure blocked current-head security evidence

  • Problem: Strix failed before producing vulnerability reports. The failed log reported LLM CONNECTION FAILED, RateLimitError or Too many requests for the primary model, provider/budget output for fallback models, and Configured model and fallback models were unavailable.
  • Root cause: The configured GitHub Models primary/fallback provider capacity or provider route failed for this run; no Strix Vulnerability Report window was produced, so there is no application source line to patch from this evidence.
  • Fix: Do not approve from this failed scan. Re-run Strix after GitHub Models capacity recovers or run an explicitly configured manual provider evidence scan with valid credentials; keep the configured fallback line at .github/workflows/strix.yml:862 aligned with the approved model list.
  • Suggested edit: keep .github/workflows/strix.yml:862 on the approved GitHub Models fallback list and rerun the current-head Strix check; there is no application source patch until Strix emits a vulnerability Code Location.
  • Regression test: Keep the failed-check evidence collector preserving RateLimitError, budget-limit, provider infrastructure, and unavailable-model lines so OpenCode reviews can distinguish external provider blockers from code vulnerabilities.
Failed check evidence for line-specific fixes

Failed GitHub Check Evidence

  • PR: #941
  • Head SHA: 632a81e6b08daa2ca1875428f9a72cc683fac8a8
  • Repository: ContextualWisdomLab/.github

Line-specific repair contract

  • Treat the check logs and annotations below as diagnostic evidence, not as a complete review.

  • For each actionable failed check, inspect the local source or diff and identify the exact file line that must change.

  • OpenCode REQUEST_CHANGES findings must include path, line, root_cause, fix_direction, regression_test_direction, and suggested_diff.

  • Do not request changes with only a GitHub Actions URL or a generic check name.

  • When Strix logs contain multiple Vulnerability Report or Model ... Vulnerabilities ... sections, include every model-reported vulnerability in the review evidence and findings, including model name, title, severity, endpoint, and Code Locations/path:line evidence when present.

  • Create one OpenCode finding per Strix model vulnerability report; do not satisfy two model reports with one combined finding, even when titles or locations match.

Failed check: Strix Security Scan/strix

Failed job steps

  • step 26: Run Strix (quick) (failure)

Check annotations

  • .github:456-456 [failure] Process completed with exit code 1.
  • .github:455-455 [failure] Strix could not complete authoritative vulnerability analysis because its provider/backend was unavailable (rate limit, token cap, connection, warm-up, or model-behavior failure). See the strix-reports artifact and run log.

Failed log signal summary

strix	UNKNOWN STEP	2026-08-26T17:48:39.1744793Z [command]/usr/bin/tar xz --warning=no-unknown-keyword --overwrite -C /home/runner/work/_temp/76509a28-e165-490b-b299-dfeba6696e4a -f /home/runner/work/_temp/477bfed3-ab33-4563-b3e0-1f2083499aa7
strix	UNKNOWN STEP	2026-08-26T17:48:42.9544909Z ^[[36;1m    print(f"::error::Could not parse GitHub workflow context JSON: {exc}", file=sys.stderr)^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:42.9553057Z ^[[36;1m    print("::error::Trusted workflow repository resolved to an invalid name.", file=sys.stderr)^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:42.9554505Z ^[[36;1m    print("::error::Trusted workflow ref resolved to an invalid value.", file=sys.stderr)^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:43.6089126Z hint: to use in all of your new repositories, which will suppress this warning,
strix	UNKNOWN STEP	2026-08-26T17:48:46.4738460Z ^[[36;1m  echo "::error::Strix target repository must belong to ContextualWisdomLab."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:46.4750425Z ^[[36;1m    echo "::error::Target repository event visibility was not public, private, or internal."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:46.4752341Z ^[[36;1m    echo "::error::Target repository visibility did not resolve to true or false after retries."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:48.5854036Z ^[[36;1m  echo "::error::PR number and head SHA are required for trusted PR-scope Strix evidence."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:48.5855934Z ^[[36;1m  echo "::error::PR head SHA must be a 40-character git SHA."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:48.5857249Z ^[[36;1m  echo "::error::PR base SHA must be a 40-character git SHA."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:48.5897075Z ^[[36;1mecho "::error::PR head ref did not resolve to expected commit $PR_HEAD_SHA after retries." >&2^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.3894550Z ^[[36;1m  echo "::error::PR head SHA must be a 40-character git SHA."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4084905Z ^[[36;1m    echo '::error::STRIX_LLM must not select mini or nano GPT-5 variants for security evidence.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4090658Z ^[[36;1m      echo '::error::STRIX_GITHUB_MODELS_TOKEN is required for GitHub Models Strix scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4095637Z ^[[36;1m      echo '::error::STRIX_OPENAI_API_KEY is required for Strix OpenAI Platform scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4100003Z ^[[36;1m      echo '::error::OPENROUTER_API_KEY is required for Strix OpenRouter scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4101908Z ^[[36;1m      echo '::error::NVIDIA NIM hosted trial scans are limited to public repositories.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4105489Z ^[[36;1m      echo '::error::NVIDIA_NIM_API_KEY is required for Strix NVIDIA NIM scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4109646Z ^[[36;1m      echo '::error::GCP_SA_KEY is required for Vertex AI Strix scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.4111968Z ^[[36;1m    echo '::error::STRIX_LLM must select NVIDIA NIM Nemotron, GitHub Models openai/gpt-5 or newer, direct OpenAI GPT-5.4 or newer, OpenRouter openrouter/free, or an approved organization Vertex AI model.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.5690354Z ^[[36;1m  echo "::error::Pinned Strix installation did not produce a trusted absolute executable path."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.5691989Z ^[[36;1m    echo "::error::Refusing a Strix executable from a workspace or runner-temp path."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.5694984Z ^[[36;1m  echo "::error::Pinned Strix installation did not produce a trusted absolute scripts root."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:52.5697153Z ^[[36;1m    echo "::error::Pinned Strix executable is outside the trusted scripts root."^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4121571Z ^[[36;1m  echo '::error::STRIX_GITHUB_MODELS_TOKEN is required for GitHub Models Strix scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4123012Z ^[[36;1m  echo '::error::STRIX_OPENAI_API_KEY is required for Strix OpenAI Platform scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4124407Z ^[[36;1m  echo '::error::OPENROUTER_API_KEY is required for Strix OpenRouter scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4126184Z ^[[36;1m  echo '::error::NVIDIA_NIM_API_KEY is required for Strix NVIDIA NIM scans.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4704128Z ^[[36;1m    echo '::error::STRIX_LLM must not select mini or nano GPT-5 variants for security evidence.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4714072Z ^[[36;1m    echo '::error::STRIX_LLM must select NVIDIA NIM Nemotron, GitHub Models openai/gpt-5 or newer, direct OpenAI GPT-5.4 or newer, OpenRouter openrouter/free, or an approved organization Vertex AI model.'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4940614Z ^[[36;1mbackend_unavailable_signal='RateLimitError|Too many requests\. For more on scraping GitHub|exceeded your current quota|insufficient_quota|billing details|"status"[[:space:]]*:[[:space:]]*"RESOURCE_EXHAUSTED"|tokens_limit_reached|Request body too large|Max size:[[:space:]]*[0-9]+[[:space:]]+tokens|Error code:[[:space:]]*413|LLM CONNECTION FAILED|Could not establish connection to the language model|LLM warm-up failed|Configured model and fallback models were unavailable|Configured Vertex model and fallback models were unavailable|emitted provider infrastructure or failure-signal output|before provider infrastructure failure|litellm(\.exceptions)?\.NotFoundError[^[:cntrl:]]*Nvidia_nimException[^[:cntrl:]]*Error code:[[:space:]]*404|Error during penetration test: loginAsGuest failed after [0-9]+ attempts: curl exit 7: curl: \(7\) Failed to connect to 127\.0\.0\.1 port 48080'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4948868Z ^[[36;1m# LLM-backend-unavailable outcomes (GitHub Models "Too many requests"^[[0m
strix	UNKNOWN STEP	2026-08-26T17:50:34.6027060Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:50:34.6029500Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:51:40.4371984Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:51:40.4374376Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:52:46.3094913Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:52:46.3099309Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:52:51.0317728Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:52:51.4407912Z Strix fallback model 'nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5' emitted provider infrastructure or failure-signal output; trying next configured fallback if available.
strix	UNKNOWN STEP	2026-08-26T17:52:57.4735576Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:54:03.7144381Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:55:09.8455785Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:55:10.1963844Z Configured model and fallback models were unavailable.
strix	UNKNOWN STEP	2026-08-26T17:55:10.2238699Z ##[error]Strix could not complete authoritative vulnerability analysis because its provider/backend was unavailable (rate limit, token cap, connection, warm-up, or model-behavior failure). See the strix-reports artifact and run log.
strix	UNKNOWN STEP	2026-08-26T17:55:10.2249029Z ##[error]Process completed with exit code 1.

Strix model attempt and finding summary

strix	UNKNOWN STEP	2026-08-26T17:49:24.4940614Z ^[[36;1mbackend_unavailable_signal='RateLimitError|Too many requests\. For more on scraping GitHub|exceeded your current quota|insufficient_quota|billing details|"status"[[:space:]]*:[[:space:]]*"RESOURCE_EXHAUSTED"|tokens_limit_reached|Request body too large|Max size:[[:space:]]*[0-9]+[[:space:]]+tokens|Error code:[[:space:]]*413|LLM CONNECTION FAILED|Could not establish connection to the language model|LLM warm-up failed|Configured model and fallback models were unavailable|Configured Vertex model and fallback models were unavailable|emitted provider infrastructure or failure-signal output|before provider infrastructure failure|litellm(\.exceptions)?\.NotFoundError[^[:cntrl:]]*Nvidia_nimException[^[:cntrl:]]*Error code:[[:space:]]*404|Error during penetration test: loginAsGuest failed after [0-9]+ attempts: curl exit 7: curl: \(7\) Failed to connect to 127\.0\.0\.1 port 48080'^[[0m
strix	UNKNOWN STEP	2026-08-26T17:49:24.4948868Z ^[[36;1m# LLM-backend-unavailable outcomes (GitHub Models "Too many requests"^[[0m
strix	UNKNOWN STEP	2026-08-26T17:50:34.6027060Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:50:34.6029500Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:50:34.6836057Z Strix run failed for model 'nvidia_nim/nvidia/nemotron-3-super-120b-a12b' after 68s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:51:40.4371984Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:51:40.4374376Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:51:40.5184122Z Strix run failed for model 'nvidia_nim/nvidia/nemotron-3-super-120b-a12b' after 6s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:52:46.3094913Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:52:46.3099309Z │  Error: litellm.RateLimitError: RateLimitError: Nvidia_nimException - Error  │
strix	UNKNOWN STEP	2026-08-26T17:52:46.3911169Z Strix run failed for model 'nvidia_nim/nvidia/nemotron-3-super-120b-a12b' after 6s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:52:46.6550112Z Primary model unavailable; retrying with fallback 'nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5'.
strix	UNKNOWN STEP	2026-08-26T17:52:51.0317728Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:52:51.1356447Z Strix run failed for model 'nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5' after 5s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:52:51.4407912Z Strix fallback model 'nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5' emitted provider infrastructure or failure-signal output; trying next configured fallback if available.
strix	UNKNOWN STEP	2026-08-26T17:52:51.4451492Z Primary model unavailable; retrying with fallback 'openai-direct/gpt-5.4'.
strix	UNKNOWN STEP	2026-08-26T17:52:57.4735576Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:52:57.5635502Z Strix run failed for model 'openai-direct/gpt-5.4' after 6s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:54:03.7144381Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:54:03.8051941Z Strix run failed for model 'openai-direct/gpt-5.4' after 6s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:55:09.8455785Z │  LLM CONNECTION FAILED                                                       │
strix	UNKNOWN STEP	2026-08-26T17:55:09.9359776Z Strix run failed for model 'openai-direct/gpt-5.4' after 6s (exit code 1).
strix	UNKNOWN STEP	2026-08-26T17:55:10.1963844Z Configured model and fallback models were unavailable.

No Strix vulnerability report windows were detected in the failed log.

Failed log excerpt

strix	UNKNOWN STEP	2026-08-26T17:48:36.6343485Z Current runner version: '2.336.0'
strix	UNKNOWN STEP	2026-08-26T17:48:36.6377523Z ##[group]Runner Image Provisioner
strix	UNKNOWN STEP	2026-08-26T17:48:36.6378947Z Hosted Compute Agent
strix	UNKNOWN STEP	2026-08-26T17:48:36.6380031Z Version: 20260729.566
strix	UNKNOWN STEP	2026-08-26T17:48:36.6381241Z Commit: cf7153fe6e25b664e8693c24944bf2b00355d109
strix	UNKNOWN STEP	2026-08-26T17:48:36.6382526Z Build Date: 2026-07-29T19:17:02Z
strix	UNKNOWN STEP	2026-08-26T17:48:36.6383639Z Worker ID: {620a229b-4d8f-494e-a70d-921d98e442a3}
strix	UNKNOWN STEP	2026-08-26T17:48:36.6385070Z Azure Region: eastus
strix	UNKNOWN STEP	2026-08-26T17:48:36.6386472Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:36.6389319Z ##[group]Operating System
strix	UNKNOWN STEP	2026-08-26T17:48:36.6390436Z Ubuntu
strix	UNKNOWN STEP	2026-08-26T17:48:36.6391463Z 24.04.4
strix	UNKNOWN STEP	2026-08-26T17:48:36.6392398Z LTS
strix	UNKNOWN STEP	2026-08-26T17:48:36.6393301Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:36.6394284Z ##[group]Runner Image
strix	UNKNOWN STEP	2026-08-26T17:48:36.6395690Z Image: ubuntu-24.04
strix	UNKNOWN STEP	2026-08-26T17:48:36.6396742Z Version: 20260816.277.1
strix	UNKNOWN STEP	2026-08-26T17:48:36.6398983Z Included Software: https://github.com/actions/runner-images/blob/ubuntu24/20260816.277/images/ubuntu/Ubuntu2404-Readme.md
strix	UNKNOWN STEP	2026-08-26T17:48:36.6401776Z Image Release: https://github.com/actions/runner-images/releases/tag/ubuntu24%2F20260816.277
strix	UNKNOWN STEP	2026-08-26T17:48:36.6403450Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:36.6406264Z ##[group]GITHUB_TOKEN Permissions
strix	UNKNOWN STEP	2026-08-26T17:48:36.6409700Z Actions: read
strix	UNKNOWN STEP	2026-08-26T17:48:36.6410673Z Contents: read
strix	UNKNOWN STEP	2026-08-26T17:48:36.6411593Z Metadata: read
strix	UNKNOWN STEP	2026-08-26T17:48:36.6412837Z Models: read
strix	UNKNOWN STEP	2026-08-26T17:48:36.6413795Z Statuses: write
strix	UNKNOWN STEP	2026-08-26T17:48:36.6414804Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:36.6417871Z Secret source: Actions
strix	UNKNOWN STEP	2026-08-26T17:48:36.6419640Z Prepare workflow directory
strix	UNKNOWN STEP	2026-08-26T17:48:36.6977589Z Prepare all required actions
strix	UNKNOWN STEP	2026-08-26T17:48:36.7048131Z Getting action download info
strix	UNKNOWN STEP	2026-08-26T17:48:36.9140473Z Download action repository 'step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40' (SHA:b09bb98e06d4d774595224525879c09bc6e98c40)
strix	UNKNOWN STEP	2026-08-26T17:48:37.2256804Z Download action repository 'actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97' (SHA:5fda3b95a4ea91299a34e894583c3862153e4b97)
strix	UNKNOWN STEP	2026-08-26T17:48:37.3380902Z Download action repository 'actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0' (SHA:9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)
strix	UNKNOWN STEP	2026-08-26T17:48:37.3932896Z Download action repository 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' (SHA:043fb46d1a93c77aae656e7c1c64a875d1fc6a0a)
strix	UNKNOWN STEP	2026-08-26T17:48:37.6013072Z Complete job name: strix
strix	UNKNOWN STEP	2026-08-26T17:48:37.7068396Z ##[group]Run step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40
strix	UNKNOWN STEP	2026-08-26T17:48:37.7069917Z with:
strix	UNKNOWN STEP	2026-08-26T17:48:37.7070405Z   egress-policy: audit
strix	UNKNOWN STEP	2026-08-26T17:48:37.7071011Z   disable-file-monitoring: true
strix	UNKNOWN STEP	2026-08-26T17:48:37.7079544Z   token: [REDACTED]
strix	UNKNOWN STEP	2026-08-26T17:48:37.7080063Z   disable-telemetry: false
strix	UNKNOWN STEP	2026-08-26T17:48:37.7080675Z   disable-sudo: false
strix	UNKNOWN STEP	2026-08-26T17:48:37.7081263Z   disable-sudo-and-containers: false
strix	UNKNOWN STEP	2026-08-26T17:48:37.7082007Z   use-policy-store: false
strix	UNKNOWN STEP	2026-08-26T17:48:37.7082644Z   deploy-on-self-hosted-vm: false
strix	UNKNOWN STEP	2026-08-26T17:48:37.7083579Z env:
strix	UNKNOWN STEP	2026-08-26T17:48:37.7084099Z   FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
strix	UNKNOWN STEP	2026-08-26T17:48:37.7084847Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:37.8378124Z [harden-runner] pre-step
strix	UNKNOWN STEP	2026-08-26T17:48:37.8378975Z [!] Current Configuration: 
strix	UNKNOWN STEP	2026-08-26T17:48:37.8385997Z {"repo":"ContextualWisdomLab/.github","run_id":"32995052110","correlation_id":"cfdb2508-4fb8-46bc-828e-4a2b32ee28e7","working_directory":"/home/runner/work/.github/.github","api_url":"https://[REDACTED].io/v1","telemetry_url":"https://[REDACTED].io/v1","allowed_endpoints":"","egress_policy":"audit","disable_telemetry":false,"disable_sudo":false,"disable_sudo_and_containers":false,"disable_file_monitoring":true,"private":false,"is_github_hosted":true,"is_debug":false,"one_time_key":"","api_key":[REDACTED],"use_policy_store":false,"deploy_on_self_hosted_vm":false}
strix	UNKNOWN STEP	2026-08-26T17:48:37.8392555Z 
strix	UNKNOWN STEP	2026-08-26T17:48:37.8393220Z ^[[32mView security insights and recommended policy at:^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:37.8394730Z https://app.stepsecurity.io/github/ContextualWisdomLab/.github/actions/runs/32995052110
strix	UNKNOWN STEP	2026-08-26T17:48:37.8396726Z RUNNER_NAME: GitHub Actions 1001362194
strix	UNKNOWN STEP	2026-08-26T17:48:38.6649990Z Runner IP Address: 52.188.198.96
strix	UNKNOWN STEP	2026-08-26T17:48:38.6651221Z Step Security Job Correlation ID: cfdb2508-4fb8-46bc-828e-4a2b32ee28e7
strix	UNKNOWN STEP	2026-08-26T17:48:38.6881104Z [!] Checking TLS_STATUS: ContextualWisdomLab
strix	UNKNOWN STEP	2026-08-26T17:48:38.9484763Z [!] TLS_NOT_ENABLED: ContextualWisdomLab
strix	UNKNOWN STEP	2026-08-26T17:48:39.1637630Z ✅ Checksum verification passed. checksum=4b14d8a3a5fbcef95af55e0c54d3bee6f44da802878c10289a4ca0b79b6d0237
strix	UNKNOWN STEP	2026-08-26T17:48:39.1744793Z [command]/usr/bin/tar xz --warning=no-unknown-keyword --overwrite -C /home/runner/work/_temp/76509a28-e165-490b-b299-dfeba6696e4a -f /home/runner/work/_temp/477bfed3-ab33-4563-b3e0-1f2083499aa7
strix	UNKNOWN STEP	2026-08-26T17:48:42.6796718Z Initialized
strix	UNKNOWN STEP	2026-08-26T17:48:42.7033775Z ##[group]Run step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40
strix	UNKNOWN STEP	2026-08-26T17:48:42.7034248Z with:
strix	UNKNOWN STEP	2026-08-26T17:48:42.7034481Z   egress-policy: audit
strix	UNKNOWN STEP	2026-08-26T17:48:42.7034749Z   disable-file-monitoring: true
strix	UNKNOWN STEP	2026-08-26T17:48:42.7037640Z   token: [REDACTED]
strix	UNKNOWN STEP	2026-08-26T17:48:42.7037886Z   disable-telemetry: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7038138Z   disable-sudo: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7038385Z   disable-sudo-and-containers: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7038678Z   use-policy-store: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7038935Z   deploy-on-self-hosted-vm: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7039184Z env:
strix	UNKNOWN STEP	2026-08-26T17:48:42.7039396Z   FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
strix	UNKNOWN STEP	2026-08-26T17:48:42.7039689Z   STATE_disableSudo: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7039947Z   STATE_disableSudoAndContainers: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7040255Z   STATE_monitorStatusCode: 200
strix	UNKNOWN STEP	2026-08-26T17:48:42.7040505Z   STATE_addSummary: true
strix	UNKNOWN STEP	2026-08-26T17:48:42.7040835Z   STATE_correlation_id: cfdb2508-4fb8-46bc-828e-4a2b32ee28e7
strix	UNKNOWN STEP	2026-08-26T17:48:42.7041166Z   STATE_isTLS: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7041378Z ##[endgroup]
strix	UNKNOWN STEP	2026-08-26T17:48:42.7772126Z [harden-runner] main-step
strix	UNKNOWN STEP	2026-08-26T17:48:42.7777772Z ^[[32mView security insights and recommended policy at:^[[0m
strix	UNKNOWN STEP	2026-08-26T17:48:42.7778791Z https://app.stepsecurity.io/github/ContextualWisdomLab/.github/actions/runs/32995052110
strix	UNKNOWN STEP	2026-08-26T17:48:42.7970488Z ##[group]Run actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
strix	UNKNOWN STEP	2026-08-26T17:48:42.7970927Z with:
strix	UNKNOWN STEP	2026-08-26T17:48:42.7971133Z   python-version: 3.13
strix	UNKNOWN STEP	2026-08-26T17:48:42.7971363Z   check-latest: false
strix	UNKNOWN STEP	2026-08-26T17:48:42.7974034Z   token: [REDACTED]

... truncated 2434 middle log lines ...

strix	UNKNOWN STEP	2026-08-26T17:55:12.2586305Z Wed, 26 Aug 2026 17:50:30 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 3455, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2587704Z Wed, 26 Aug 2026 17:50:32 GMT:domain resolved: [REDACTED].com., ip address: 75.2.113.119, TTL: 300
strix	UNKNOWN STEP	2026-08-26T17:55:12.2589093Z Wed, 26 Aug 2026 17:50:32 GMT:endpoint called ip address:port 75.2.113.119:443, domain: [REDACTED].com., pid: 3455, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2590730Z Wed, 26 Aug 2026 17:51:34 GMT:domain resolved: [REDACTED]., ip address: 140.82.114.23, TTL: 48
strix	UNKNOWN STEP	2026-08-26T17:55:12.2592238Z Wed, 26 Aug 2026 17:51:34 GMT:domain resolved: [REDACTED].io., ip address: 34.218.5.214, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2593648Z Wed, 26 Aug 2026 17:51:36 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 3725, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2595470Z Wed, 26 Aug 2026 17:51:38 GMT:endpoint called ip address:port 75.2.113.119:443, domain: [REDACTED].com., pid: 3725, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2596915Z Wed, 26 Aug 2026 17:52:30 GMT:endpoint called ip address:port 168.63.129.16:80, domain: , pid: 3782, process: python3.12
strix	UNKNOWN STEP	2026-08-26T17:55:12.2598258Z Wed, 26 Aug 2026 17:52:42 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 3840, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2599804Z Wed, 26 Aug 2026 17:52:44 GMT:endpoint called ip address:port 75.2.113.119:443, domain: [REDACTED].com., pid: 3840, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2601599Z Wed, 26 Aug 2026 17:52:48 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 3959, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2603164Z Wed, 26 Aug 2026 17:52:50 GMT:endpoint called ip address:port 75.2.113.119:443, domain: [REDACTED].com., pid: 3959, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2604742Z Wed, 26 Aug 2026 17:52:53 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 4116, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2606325Z Wed, 26 Aug 2026 17:52:55 GMT:domain resolved: [REDACTED]., ip address: 172.66.0.243, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2607588Z Wed, 26 Aug 2026 17:52:55 GMT:endpoint called ip address:port 172.66.0.243:443, domain: [REDACTED]., pid: 4116, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2609090Z Wed, 26 Aug 2026 17:53:00 GMT:domain resolved: [REDACTED]., ip address: 140.82.113.23, TTL: 52
strix	UNKNOWN STEP	2026-08-26T17:55:12.2610773Z Wed, 26 Aug 2026 17:53:04 GMT:domain resolved: [REDACTED]., ip address: 140.82.112.23, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2612441Z Wed, 26 Aug 2026 17:53:59 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 4214, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2613762Z Wed, 26 Aug 2026 17:54:01 GMT:domain resolved: [REDACTED]., ip address: [REDACTED].245, TTL: 31
strix	UNKNOWN STEP	2026-08-26T17:55:12.2615011Z Wed, 26 Aug 2026 17:54:01 GMT:endpoint called ip address:port [REDACTED].245:443, domain: [REDACTED]., pid: 4214, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2617088Z Wed, 26 Aug 2026 17:54:34 GMT:domain resolved: [REDACTED]., ip address: 140.82.114.24, TTL: 54
strix	UNKNOWN STEP	2026-08-26T17:55:12.2618837Z Wed, 26 Aug 2026 17:55:05 GMT:endpoint called ip address:port [REDACTED].133:443, domain: [REDACTED]., pid: 4317, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2620163Z Wed, 26 Aug 2026 17:55:07 GMT:domain resolved: [REDACTED]., ip address: 172.66.0.243, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2621410Z Wed, 26 Aug 2026 17:55:07 GMT:endpoint called ip address:port 172.66.0.243:443, domain: [REDACTED]., pid: 4317, process: python3.13
strix	UNKNOWN STEP	2026-08-26T17:55:12.2622899Z Wed, 26 Aug 2026 17:55:10 GMT:domain resolved: [REDACTED].com., ip address: 140.82.112.22, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2624392Z Wed, 26 Aug 2026 17:55:10 GMT:domain resolved: [REDACTED].windows.net., ip address: 57.150.27.1, TTL: 30
strix	UNKNOWN STEP	2026-08-26T17:55:12.2626353Z Wed, 26 Aug 2026 17:55:10 GMT:endpoint called ip address:port 140.82.112.22:443, domain: [REDACTED].com., pid: 2175, process: Runner.Worker
strix	UNKNOWN STEP	2026-08-26T17:55:12.2628345Z Wed, 26 Aug 2026 17:55:10 GMT:endpoint called ip address:port 57.150.27.1:443, domain: [REDACTED].windows.net., pid: 2175, process: Runner.Worker
strix	UNKNOWN STEP	2026-08-26T17:55:12.2630226Z Wed, 26 Aug 2026 17:55:10 GMT:endpoint called ip address:port 140.82.112.22:443, domain: [REDACTED].com., pid: 4418, process: node
strix	UNKNOWN STEP	2026-08-26T17:55:12.2632012Z Wed, 26 Aug 2026 17:55:10 GMT:endpoint called ip address:port 57.150.27.1:443, domain: [REDACTED].windows.net., pid: 4418, process: node
strix	UNKNOWN STEP	2026-08-26T17:55:12.2632981Z 
strix	UNKNOWN STEP	2026-08-26T17:55:12.2633194Z Wed, 26 Aug 2026 17:55:11 GMT:post_event called
strix	UNKNOWN STEP	2026-08-26T17:55:12.2633569Z 
strix	UNKNOWN STEP	2026-08-26T17:55:12.2633722Z status:
strix	UNKNOWN STEP	2026-08-26T17:55:12.2634071Z Initialized
strix	UNKNOWN STEP	2026-08-26T17:55:12.2720337Z agent.service log:
strix	UNKNOWN STEP	2026-08-26T17:55:12.2722018Z Aug 26 17:48:40 runnervm76f27 systemd[1]: /etc/systemd/system/agent.service:9: Standard output type syslog is obsolete, automatically updating to journal. Please update your unit file, and consider removing the setting altogether.
strix	UNKNOWN STEP	2026-08-26T17:55:12.2724491Z Aug 26 17:48:40 runnervm76f27 systemd[1]: /etc/systemd/system/agent.service:10: Standard output type syslog is obsolete, automatically updating to journal. Please update your unit file, and consider removing the setting altogether.
strix	UNKNOWN STEP	2026-08-26T17:55:12.2726896Z Aug 26 17:48:40 runnervm76f27 systemd[1]: Started agent.service - Agent.
strix	UNKNOWN STEP	2026-08-26T17:55:12.2728334Z Aug 26 17:48:40 runnervm76f27 sudo[2309]:     root : *** ; USER=root ; COMMAND=/usr/bin/systemctl stop systemd-resolved
strix	UNKNOWN STEP	2026-08-26T17:55:12.2729644Z Aug 26 17:48:40 runnervm76f27 sudo[2309]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2730910Z Aug 26 17:48:40 runnervm76f27 sudo[2309]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2732281Z Aug 26 17:48:41 runnervm76f27 sudo[2315]:     root : *** ; USER=root ; COMMAND=/usr/bin/systemctl restart systemd-resolved
strix	UNKNOWN STEP	2026-08-26T17:55:12.2733381Z Aug 26 17:48:41 runnervm76f27 sudo[2315]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2734629Z Aug 26 17:48:41 runnervm76f27 sudo[2315]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2736295Z Aug 26 17:48:41 runnervm76f27 sudo[2320]:     root : *** ; USER=root ; COMMAND=/usr/bin/resolvectl flush-caches
strix	UNKNOWN STEP	2026-08-26T17:55:12.2737602Z Aug 26 17:48:41 runnervm76f27 sudo[2320]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2738638Z Aug 26 17:48:41 runnervm76f27 sudo[2320]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2739876Z Aug 26 17:48:41 runnervm76f27 sudo[2323]:     root : *** ; USER=root ; COMMAND=/usr/bin/systemctl reload docker
strix	UNKNOWN STEP	2026-08-26T17:55:12.2741392Z Aug 26 17:48:41 runnervm76f27 sudo[2323]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2742634Z Aug 26 17:48:41 runnervm76f27 sudo[2323]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2743723Z Aug 26 17:48:41 runnervm76f27 sudo[2336]:     root : *** ; USER=root ; COMMAND=/usr/bin/systemctl daemon-reload
strix	UNKNOWN STEP	2026-08-26T17:55:12.2745076Z Aug 26 17:48:41 runnervm76f27 sudo[2336]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2747989Z Aug 26 17:48:41 runnervm76f27 systemd[1]: /etc/systemd/system/agent.service:9: Standard output type syslog is obsolete, automatically updating to journal. Please update your unit file, and consider removing the setting altogether.
strix	UNKNOWN STEP	2026-08-26T17:55:12.2750457Z Aug 26 17:48:41 runnervm76f27 systemd[1]: /etc/systemd/system/agent.service:10: Standard output type syslog is obsolete, automatically updating to journal. Please update your unit file, and consider removing the setting altogether.
strix	UNKNOWN STEP	2026-08-26T17:55:12.2752383Z Aug 26 17:48:41 runnervm76f27 sudo[2336]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2753498Z Aug 26 17:48:41 runnervm76f27 sudo[2400]:     root : *** ; USER=root ; COMMAND=/usr/bin/systemctl restart docker
strix	UNKNOWN STEP	2026-08-26T17:55:12.2754558Z Aug 26 17:48:41 runnervm76f27 sudo[2400]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
strix	UNKNOWN STEP	2026-08-26T17:55:12.2756121Z Aug 26 17:48:42 runnervm76f27 sudo[2400]: pam_unix(sudo:session): session closed for user root
strix	UNKNOWN STEP	2026-08-26T17:55:12.2757821Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Fetching custom detection rules module=armour api_url=https://[REDACTED].io/v1 repo=ContextualWisdomLab/.github
strix	UNKNOWN STEP	2026-08-26T17:55:12.2759405Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Custom detection rules evaluator initialized module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2761073Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Detection manager started module=detection-manager workers=4 buffer_size=1000
strix	UNKNOWN STEP	2026-08-26T17:55:12.2762718Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Selected Armour variant module=armour variant=fmod_ret
strix	UNKNOWN STEP	2026-08-26T17:55:12.2763929Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Config module=armour AGENT_PID=2295
strix	UNKNOWN STEP	2026-08-26T17:55:12.2766052Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Config module=armour ENFORCE_READ_BLOCK=false
strix	UNKNOWN STEP	2026-08-26T17:55:12.2767553Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Config module=armour ENFORCE_WRITE_BLOCK=false
strix	UNKNOWN STEP	2026-08-26T17:55:12.2768800Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Config module=armour ENFORCE_KILL_BLOCK=true
strix	UNKNOWN STEP	2026-08-26T17:55:12.2769742Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour protected_pids=1
strix	UNKNOWN STEP	2026-08-26T17:55:12.2771021Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour protected_pid_inodes=1
strix	UNKNOWN STEP	2026-08-26T17:55:12.2772344Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour protected_bpf_ids=9
strix	UNKNOWN STEP	2026-08-26T17:55:12.2773641Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour protected_fs_inodes=6
strix	UNKNOWN STEP	2026-08-26T17:55:12.2774675Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour protected_proc_fs_inodes=2
strix	UNKNOWN STEP	2026-08-26T17:55:12.2776418Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Map size module=armour events=16384
strix	UNKNOWN STEP	2026-08-26T17:55:12.2777747Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO ProtectedPids module=armour pids=map[2296:2295]
strix	UNKNOWN STEP	2026-08-26T17:55:12.2779017Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO ProtectedBPFIDs module=armour ids="[20 18 14 21 19]"
strix	UNKNOWN STEP	2026-08-26T17:55:12.2780376Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:24 Inode:11920}" path=/proc/2175/mem
strix	UNKNOWN STEP	2026-08-26T17:55:12.2782006Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:24 Inode:18785}" path=/proc/2154/mem
strix	UNKNOWN STEP	2026-08-26T17:55:12.2783901Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:2049 Inode:90853}" path=/etc/sudoers.d/runner
strix	UNKNOWN STEP	2026-08-26T17:55:12.2785738Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:28 Inode:922}" path=/etc/resolv.conf
strix	UNKNOWN STEP	2026-08-26T17:55:12.2787477Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:2049 Inode:508}" path=/etc/systemd/resolved.conf
strix	UNKNOWN STEP	2026-08-26T17:55:12.2789352Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO File Info module=armour inoKey="{Device:2049 Inode:325225}" path=/etc/docker/daemon.json
strix	UNKNOWN STEP	2026-08-26T17:55:12.2790878Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Protection maps populated module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2792113Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Protection maps are freezed module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2793354Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Linking completed module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2794513Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Armour engaged module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2795905Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO RingBuffer created module=armour size=16384
strix	UNKNOWN STEP	2026-08-26T17:55:12.2797125Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO Listening for events module=armour
strix	UNKNOWN STEP	2026-08-26T17:55:12.2798313Z Aug 26 17:48:42 runnervm76f27 agentservice[2295]: 2026/08/26 17:48:42 INFO [LOCKDOWN] Runner.Worker PID set module=armour pid=2175
strix	UNKNOWN STEP	2026-08-26T17:55:12.2799171Z 
strix	UNKNOWN STEP	2026-08-26T17:55:12.6019184Z Cleaning up orphan processes

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found source-backed failed-check findings that must be addressed before merge.

  • Result: REQUEST_CHANGES
  • Reason: failed current-head checks were mapped to line-specific findings below for a6d4632a5d5aa36d4f2a9cea55cc39b21755590d.
  • Head SHA: a6d4632a5d5aa36d4f2a9cea55cc39b21755590d
  • Workflow run: 33061777294
  • Workflow attempt: 1
Failed checks

Findings

1. HIGH .github/workflows/strix.yml:99 - Current-head Strix evidence is missing because the workflow run was cancelled before logs

  • Problem: Strix Security Scan reported a current-head workflow_run conclusion of cancelled, but GitHub emitted no failed job log and no Strix Vulnerability Report window.

  • Root cause: The security gate has no usable Strix evidence for this head SHA. This is a workflow execution/queue state, not an application vulnerability finding, so OpenCode must not invent a source-code fix.

  • Fix: Do not approve from this cancelled run. Re-run the current-head Strix Security Scan after stale runs complete or are cancelled, then review the resulting job log; keep the workflow concurrency line at .github/workflows/strix.yml:99 so stale runs do not silently replace current-head evidence.

  • Regression test: Keep failed-check evidence collection explicit for cancelled workflow runs with no job log so reviewers see that the blocker is missing scanner evidence.

  • Suggested edit: preserve .github/workflows/strix.yml:99 with event-separated Strix concurrency, so workflow_dispatch evidence cannot cancel the required pull_request_target context while same-event stale runs still collapse to current-head evidence; rerun current-head Strix until logs exist.

Failed check evidence for line-specific fixes

Failed GitHub Check Evidence

  • PR: #941
  • Head SHA: a6d4632a5d5aa36d4f2a9cea55cc39b21755590d
  • Repository: ContextualWisdomLab/.github

Line-specific repair contract

  • Treat the check logs and annotations below as diagnostic evidence, not as a complete review.

  • For each actionable failed check, inspect the local source or diff and identify the exact file line that must change.

  • OpenCode REQUEST_CHANGES findings must include path, line, root_cause, fix_direction, regression_test_direction, and suggested_diff.

  • Do not request changes with only a GitHub Actions URL or a generic check name.

  • When Strix logs contain multiple Vulnerability Report or Model ... Vulnerabilities ... sections, include every model-reported vulnerability in the review evidence and findings, including model name, title, severity, endpoint, and Code Locations/path:line evidence when present.

  • Create one OpenCode finding per Strix model vulnerability report; do not satisfy two model reports with one combined finding, even when titles or locations match.

Failed check: strix

No GitHub Actions job log is available for this status context.

Failed check: Strix Security Scan

No GitHub Actions job log is available for this failed workflow run.

The workflow run completed as cancelled before GitHub emitted a failed job log. Treat this as missing current-head security evidence, not as a source-code vulnerability report.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

@opencode-agent review exact head bdac48bd483eadf665c15c30b54af17f0d979445 against live protected main@17052a7ca3c16db90932a4d6036b43165ddee418 and submit the separate authenticated current-head verdict required by the central review contract. Do not promote the green opencode-review bootstrap check as a verdict. Explicitly classify the current-head GHAS comparative osv-scanner and Trivy neutral “configuration not found” results before any approval; synthetic-source predecessor evidence, predecessor reviews/checks, skipped evidence, and neutral evidence are non-passing. Preserve #941's exact-head SAST checkout/SARIF identity scope and do not mutate or merge from this review request.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for bdac48bd483eadf665c15c30b54af17f0d979445.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Devin Review

Comment thread .github/workflows/sast-semgrep.yml
Comment thread .github/workflows/sast-semgrep.yml

Copy link
Copy Markdown
Contributor Author

Fresh Inkspan exact-submitted-head canary for the SAST identity contract; this supersedes predecessor Inkspan reproductions but does not broaden #941 scope.

  • Consumer PR: ContextualWisdomLab/inkspan#391 exact submitted head 3edd7495a20f96b91eee97afa0f0dd62a8adc55c, protected base main@128a239f8b71ca16add4b9e15e21752d1ad63ff0.
  • Current synthetic PR merge ref resolves to refs/pull/391/merge@f34cf636258db9334eb399a9d92354c22a156acf.
  • Required SAST run 33146960743, Semgrep job 98770004226, is aggregate success; central protected workflow source is .github/main@f6c2a2702b7b7578b2d1fc5f2f9a5125a0390d33 and still uses unqualified actions/checkout in the pull-request job, with no explicit PR-head repository/SHA checkout or pre-scan HEAD == expected head attestation.

Therefore this current consumer success is still non-passing exact-source evidence: the workflow contract permits the pull-request synthetic merge ref to be the scanner workspace rather than submitted source 3edd749.... The current central source itself is the conflicting proposition; there is no correct Inkspan-local SAST workaround.

RED: current protected workflow lacks exact-head checkout/attestation while #391's submitted head and merge ref are distinct (3edd749... vs f34cf63...). Smallest causal remedy remains #941's explicit submitted repository/SHA checkout, fail-closed HEAD attestation, and SARIF binding. GREEN after integration: rerun a then-current Inkspan PR and require logged expected_sha == actual_sha == submitted head before Semgrep executes, with SARIF bound to the same head; synthetic/predecessor/status-only success remains non-passing.

Separate current blockers (Dependency Review false-green and Strix provider compatibility) remain on their own owner paths; do not mix them into this SAST source repair.

@seonghobae
seonghobae merged commit 7dd8a22 into main Aug 28, 2026
58 of 77 checks passed
@seonghobae
seonghobae deleted the fix/semgrep-digest-single-source-20260812 branch August 28, 2026 07:57
seonghobae pushed a commit that referenced this pull request Aug 31, 2026
… main

Merges main (which brought in the SSRF fix and sandboxed-web-e2e isolation
work) and extends this PR's own pin bump beyond its original target
(79c6841b, contextual-orchestrator PR #929) to contextual-orchestrator's
current main tip (0adca4703df67f8f31d3ea5b04a1e07ed775dd6c), which also
vendors:

- #941 (fix(discovery): keep credential accounts independent) + #945 (its
  matching test fix): removes the wrong assumption that nvidia_nim and
  nvidia_nim_sub share one model catalog/outage domain, which
  docs/planning/adrs/0015-durable-provider-catalog.md already contradicted.
  Without this, every hosted noema-review/opencode-review/strix run kept
  using the old collapsing logic regardless of what was merged upstream.
- a vision-input exclusion for the blind orchestrator/free pool (unrelated
  bugfix, additive only, no CLI-surface change).

Reviewed the incremental diff (79c6841b..0adca470) for sidecar dependency-
surface breakage per ADR-0003's own requirement: requirements.lock is
byte-for-byte unchanged, and every __main__.py CLI change is additive (new
--verbose flags, a new report field) -- register-credential and
--serve --agents ... --port ... --auth-token ... are untouched.

Updates the pin in all three places the contract lives (sidecar script
default, the contract test's ORCH_PIN_SHA, ADR-0003's "today" reference)
plus the product-technical-gap-baseline.md review record and CHANGELOG.

This is a prerequisite for the separate PROVIDER_FAMILIES fix in
scripts/ci/contextual_orchestrator_review_policy.py (this repo's own,
independent copy of the same nvidia_nim/nvidia_nim_sub collapsing bug) to
have any live effect on the free_family_diversity evidence PR #1437 reads.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Gs7KmNvH75nxz1sL8mKjw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: auth Authentication, authorization, identity, or tenant isolation area: ci-cd CI, GitHub Actions, checks, release, or supply chain priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: bug Defect or incorrect behavior

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant