Skip to content

feat: add governed audit evidence review boundary - #102

Draft
seonghobae wants to merge 32 commits into
developfrom
feat/audit-evidence-review
Draft

feat: add governed audit evidence review boundary#102
seonghobae wants to merge 32 commits into
developfrom
feat/audit-evidence-review

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-06

Current exact head is 5344d77a9bd1058fee9fcecb7c6aaebc39ced995. Protected truth is develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; this branch still retains the older develop@9e3e4847510e1e612b48474ba42b177b8ed824df snapshot. Live state is open · Draft. The audit-evidence-review delta remains valid and is not a Close candidate.

The previous PR prose stopped at predecessor 67b84464dedc21c8414e1830826816144eda44df. Intervening ordinary successor 5344d77a9bd1058fee9fcecb7c6aaebc39ced995 is a real production+test trust-boundary repair. read_audit_evidence(...) now gives the authorization callback and store callback independent snapshots rather than the authoritative in-process query object. The added regressions prove a hostile authority callback cannot rewrite tenant/date/limit before the store read and a hostile reader callback cannot rewrite query reference/date/limit before returned-page checks. The authoritative query remains unchanged across both callbacks. This successor is adopted as current branch truth rather than treated as race/noise.

Exact-head historical evidence on 5344d77... is strong for the Orgmetra-owned surface: Audit Evidence Review Quality, Foundation, Recovery, SAST, Security Scan, coverage source/evidence, Dependency Review, PostgreSQL restore rehearsal, and applicable PostgreSQL integrity contracts completed successfully; the dedicated audit-evidence review contract reports 100% coverage. The same old-base exact head has terminal failures in OpenCode, Noema, and Strix, so it is not merge-passing and no successful local result is promoted over those required review gates.

Before Ready, non-force adopt current protected develop, preserve #161 repository-workflow consolidation and the complete audit-evidence callback-isolation delta, resolve semantic/provenance conflicts rather than selecting one tree wholesale, reseal deterministic artifacts from the final resolved bytes, then reacquire exact-head owned quality/100% coverage/PostgreSQL plus every then-current central security/review gate, resolved conversations, and a qualifying independent approval. Do not self-approve, use administrator bypass, force-push, create no-op retriggers, weaken gates, or copy foreign-owner source.

@coderabbitai

coderabbitai Bot commented Aug 23, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 53 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: fb9fa9bf-360f-4a80-9480-5cf7ce01fbb3

📥 Commits

Reviewing files that changed from the base of the PR and between 9e3e484 and 5344d77.

📒 Files selected for processing (15)
  • .github/workflows/audit-evidence-review-quality.yml
  • docs/adr/0102-governed-audit-evidence-review.md
  • docs/doctoring/audit-evidence-review-references.md
  • docs/traceability/audit-evidence-review.md
  • packages/audit-evidence-review/CHANGELOG.md
  • packages/audit-evidence-review/README.md
  • packages/audit-evidence-review/pyproject.toml
  • packages/audit-evidence-review/src/orgmetra_audit_evidence_review/__init__.py
  • packages/audit-evidence-review/src/orgmetra_audit_evidence_review/postgres.py
  • packages/audit-evidence-review/src/orgmetra_audit_evidence_review/review.py
  • packages/audit-evidence-review/tests/test_postgres_reader.py
  • packages/audit-evidence-review/tests/test_privacy_integrity.py
  • packages/audit-evidence-review/tests/test_review.py
  • packages/audit-evidence-review/tests/test_runtime_integrity.py
  • packages/audit-evidence-review/tests/test_validation.py
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/audit-evidence-review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae
seonghobae marked this pull request as draft August 23, 2026 20:06
devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae
seonghobae marked this pull request as ready for review August 23, 2026 20:59
@seonghobae
seonghobae marked this pull request as draft August 24, 2026 15:40
@seonghobae
seonghobae marked this pull request as ready for review August 24, 2026 15:40
@seonghobae seonghobae closed this Aug 24, 2026
@seonghobae seonghobae reopened this Aug 24, 2026
@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please review the current unchanged head against protected develop. Local exact-head verification: all owned package suites pass at 100% statement/branch coverage.

devin-ai-integration[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant