feat(job-analysis): add governed qualification-rule review - #104
feat(job-analysis): add governed qualification-rule review#104seonghobae wants to merge 16 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-head correction: production implementation is now present at |
|
Current-head evidence update: |
|
@opencode-agent Please review the current unchanged head against protected |
…n-subclassable Strix OpenAI-direct scan of head d92ac4c surfaced one MEDIUM finding: a hostile in-process subclass could override _validated_payload to bypass all trust-bearing field validation. Repair: __init_subclass__ now raises TypeError for every subclass, so the trust boundary is non-overridable by construction. Regression coverage asserts subclass definition fails closed at class-definition time and base-class canonical evidence stays stable per issued instance. 55 tests, 100% owned statement/branch coverage.
|
Lifecycle correction: live protected |
Adopt protected develop without resurrecting the retired package-local quality workflow. Move the Job Qualification Rule Review exact CPython 3.14.7, SHA-256-bound installed-wheel, isolated toolchain, and 100% statement/branch coverage contract into canonical Foundation CI; add a regression that rejects leaf-workflow reintroduction; and reseal the exact Foundation manifest. No Job Analysis domain behavior, human-review authority, coverage threshold, protected history, or central gate is weakened.
Buyer-visible gap
Orgmetra needs governed evidence showing which Job Analysis evidence supports a proposed qualification rule before that rule can influence recruiting or selection. This lane remains a human-reviewed, PII-minimized qualification-rule review boundary; it does not evaluate candidates, reject applicants, mutate Job/Job Analysis, or write foreign CWL repositories.
Retained domain contract
The original RED/implementation chain remains intact:
d92ac4cb...hardened malformed Job references,79adb799...sealedJobQualificationRuleReviewPacketagainst subclass override, and14eab4eb...repaired the deterministic test-quality defects. Canonical evidence stays fixed tojob_qualification_rule_review, mandatory human review,reviewed_for_authoritative_resolution, andnot_authorized_for_candidate_or_employment_decision.Candidate/person PII, candidate qualification outcomes, assessment/cut scores, compensation, raw rule text, prompts and model output remain excluded. Before authoritative persistence/use, the host must re-resolve tenant/Job/Job Analysis, rule artifact, Task/KSAO/source provenance and reviewer authority at the business-effective coordinate and preserve immutable audit/outbox evidence.
Protected-parent reconciliation completed
Protected adoption authority remains
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. The branch first adopted it through ordinary non-force two-parent successor5bc1663afbd363dc75524afb0cebcf856595d421.The previously verified synthetic merge tree would have resurrected
.github/workflows/job-qualification-rule-review-quality.ymlwithruns-on: ubuntu-latest, undoing protected #161's repository-quality consolidation. That semantic adoption defect remains repaired:.github/workflows/foundation-ci.ymlpreserves exact CPython 3.14.7, SHA-256-bound installed-wheel, isolated test-toolchain, package-import provenance, and 100% statement/branch coverage contracts;packages/job-qualification-rule-review/tests/test_artifact_execution.pyrejects leaf-workflow reintroduction and requires the canonical installed-artifact path;manifest.jsonremains sealed to the final Foundation bytes from that repair: SHA-2562e7e89e7c1158b23e4cf5947ab2a6440c3a3dc47f4a6b23182ff5a15e53b5eaf, 10324 bytes, 169 lines.A follow-up docs-to-code sweep found
docs/traceability/job-qualification-rule-review.mdstill describing olddevelop@9e3e484...as protected truth and a retired dedicated quality workflow as the artifact gate. Ordinary successorfde420ae11680a8b54eada785683db1afecca6bdrepairs only that traceability authority: it recordseb9757f...as the protected-parent adoption snapshot, requires a fresh protected read before merge, and names canonical Foundation CI plus the leaf-reintroduction regression as the current artifact gate. The Foundation manifest does not inventory this traceability file, so no manifest reseal is implied by this docs-only successor.No Job Analysis production behavior, human-review authority, coverage threshold, protected history, central gate or dependency boundary was weakened.
Current acceptance state
GitHub reports this PR open · Draft at exact
fde420ae11680a8b54eada785683db1afecca6bdwith current protected baseeb9757f.... Foundation34017994517is now terminal SUCCESS on this exact head. Security34017994490, SAST34017994471, and CodeQL34017994488remain queued/non-terminal, so the lane is not review-ready and no predecessor result is being transferred.For predecessor
5bc1663a..., Foundation34013148564and SAST34013148551were terminal SUCCESS. Security34013148557failed only after exact checkout atCheck dependency review support, while sibling OSV/Scorecard paths succeeded; central.github#810remains the owner of that fail-closed Dependency Review availability incident. CodeQL34013148598failed only after both Actions/Python shards successfully requested current-head dispatch and then failedRelease runner or enforce current-head CodeQL verdict;.github#1927/#1929remain open around the dispatcher-identity authorization boundary. Those predecessor results are causal evidence, not GREEN forfde420ae....Submitted formal reviews remain COMMENTED-only; no qualifying independent
APPROVEDreview exists. All currently visible review threads are resolved.Stack order
#105 remains Draft at child exact
e9e4731b...on predecessor parent snapshotd92ac4cb...; it does not yet contain the current #104 trust-boundary/protected-parent/traceability repairs. Required order is: exact-head #104 acceptance → normal protected integration → #105 non-force adoption/retarget preserving its full persistence/search-path/PostgreSQL/provenance delta → retire/reconcile #105's own historical package-local workflow without resurrecting leaf CI → reseal final tracked bytes → fresh descendant acceptance.The active organization ruleset still requires one approval, stale-review dismissal on push, resolved threads, extra approval for unattributed changes, seven central required workflows, and deletion/non-fast-forward protection. Do not self-approve, use routine administrator bypass, weaken gates, transfer predecessor evidence, force-push/destructively rebase, or simply Close the valid delta.