Skip to content

governance: harden effective develop ruleset and remove routine admin bypass #89

Description

@seonghobae

Live Orgmetra governance defect — effective control plane

Fresh supported reads on 2026-09-05 confirm protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f is governed by inherited organization ruleset 18156473 — CWL Central required workflows, enforcement=active, scoped to ~DEFAULT_BRANCH. Classic branch-protection fields are not authoritative by themselves while this ruleset is active.

The live ruleset currently has:

  • required_approving_review_count = 1;
  • dismiss_stale_reviews_on_push = true;
  • require_last_push_approval = false;
  • require_code_owner_review = false;
  • required_review_thread_resolution = true;
  • require_extra_approval_for_unattributed_changes = true;
  • required_reviewers = [];
  • allowed merge methods merge and squash;
  • deletion and non-fast-forward protection;
  • OrganizationAdmin with bypass_mode = always; and
  • current_user_can_bypass = always.

The current required-workflow set is seven identities, not the nine previously recorded in this issue: opencode-review, pr-review-merge-scheduler, security-scan, strix, sast-semgrep, noema-review, and codeql-pr. The prior statement that CodeQL was absent is stale and remains superseded by the live payload. Required-workflow identity remains owned by ContextualWisdomLab/.github; Orgmetra must not clone, remove or weaken these gates locally.

Repository-local workflow state

Orgmetra PR #161 integrated normally on 2026-09-04 as protected commit eb9757f8649aaad026a9865508d9aad50c1a7a4f. It consolidated repository-local quality workflows and replaced moving ubuntu-latest selectors with explicit ubuntu-24.04 without weakening the domain/PostgreSQL/repository-quality contract.

The earlier statement that all current #63/#64/#65 jobs remained queued before checkout is now only partly true. #63 exact head 72070cb4b8d636825ce5b1a326df4c296596ed7e materially acquired a GitHub-hosted ubuntu-24.04 runner: Foundation CI 33936088421 / Repository quality 101224196516 completed GREEN after exact checkout, owned unit/service contracts, isolated PostgreSQL contracts, and read-only validation. PR Review Merge Scheduler 33936086820 is also GREEN. The six remaining required lanes visible on that exact head—Security Scan 33936088403, SAST Semgrep 33936088456, CodeQL PR 33936088409, OpenCode 33936086812, Strix 33936086809, and Noema 33936086817—remain non-terminal, and there is still no qualifying APPROVED review. #64/#65 remain separately blocked on their own exact-head acceptance. Selector correctness is therefore protected and materially proven for Foundation, while shared required-workflow admission/capacity is still incomplete. Do not recreate deleted leaf workflows, copy workflow bytes into feature branches, or generate no-op commits to simulate execution.

Canonical owner boundary

The policy decision and privileged live-ruleset mutation remain owned by ContextualWisdomLab/.github. Orgmetra’s responsibility is to keep this consumer/canary evidence current and fail closed. Before any settings mutation or claim that the organization policy has converged, re-fetch the central owner’s live protected head, active writer, exact-head checks/reviews, relevant ruleset payload/history and controlled-credential evidence in that owner lane. Historical .github PR numbers/heads in older comments are predecessor evidence only and are not promoted here without a fresh owner read.

For the current sole-maintainer operating model, Orgmetra must not manufacture independent-human evidence through bot/service-account approval, self-approval, broadened reviewer credentials or routine administrator bypass. Review-thread resolution, deterministic required workflows, deletion and non-fast-forward protection must remain enforced. Any change to approval count or bypass policy must be made and verified in the canonical central owner, then proven with an unchanged Orgmetra canary through the ordinary protected path.

Acceptance criteria

  • Effective scope remains the protected default branch without weakening normal PR enforcement.
  • Current central required-workflow identities remain exact and material; no leaf shim substitutes for them.
  • Required review conversations and deterministic security/review workflows materially execute on the exact candidate head.
  • Force-push/non-fast-forward and branch deletion remain prohibited.
  • Routine administrator bypass is not used to manufacture release/merge evidence; any break-glass path is separately governed and auditable.
  • Central source/audit policy and live ruleset payload/history converge before GOV-01 is declared repaired.
  • After central convergence, an unchanged eligible Orgmetra canary proves the ordinary protected path rather than bypass.
  • Every later central policy or workflow change invalidates stale consumer snapshots and requires fresh Orgmetra reads.

No release/version/tag is authorized until one exact integrated protected head satisfies the complete governance, product, security, recovery and release evidence set.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions