feat(job-analysis): add governed semantic ontology evidence - #83
feat(job-analysis): add governed semantic ontology evidence#83seonghobae wants to merge 43 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (16)
🚧 Files skipped from review as they are similar to previous changes (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughSemantic Job Evidence Adapter의 공개 API와 봉투 무결성 검증을 정비했습니다. 검증된 스냅샷을 canonical 출력에 재사용합니다. Python 3.12–3.14 wheel 품질 검증, 테스트 fixture, 추적성 문서를 추가했습니다. ChangesSemantic Job Evidence 구현
Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: 🟡 Moderate · up to This PR adds a metadata-only, human-review-required evidence envelope that records tenant scope, actor references, provenance, and integrity digests without carrying raw ontology or employment-decision content. Production consumers must still bind actor references to authenticated tenant principals and persist the canonical payload and digest together; otherwise evidence accountability could be weakened. The exact head is not merge-ready because dependency review has failed, required checks are incomplete, and qualifying approval is still missing. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Please review the current unchanged head against protected |
Buyer-visible gap
Orgmetra needs a governed boundary that can bind one ontology-resolution result to exact tenant/Job Analysis scope, source revision, evidence digests, accountable actors, and mandatory human review without copying raw ontology query/response content into HR governance evidence. This lane writes Orgmetra only;
ContextualWisdomLab/semantic-data-portalremains a read-only dedicated-writer dependency and no cross-service application-table SQL is introduced.Governed source-evidence boundary
SemanticJobEvidenceEnvelopebinds tenant and Orgmetra-owned Job Analysis/request references, distinct opaqueactor:UUIDv4 requester/reviewer correlations, the closed non-decision usejob_analysis_source_evidence, query/response/catalog SHA-256 evidence digests, foreign contract identity, evidence version and exact UTC system-recorded time.Canonical evidence remains
external_source_evidence,requires_human_review, andnot_authorized_for_job_or_employment_decision. It carries no raw query term, ontology response, Person/candidate PII, credential, score, employment decision, or autonomous Job-analysis approval. The current source repairc340e7599f147b25fab4c94cd2042a96d6128235also rejects human-readable actor handles by reusing the canonical opaque UUIDv4 reference validator.Fresh release-contract prerequisite
The current branch records a reviewed Semantic Data Portal revision, but Orgmetra's integration rule is stricter: production/dependency acceptance consumes an immutable released contract, not a mutable branch or bare source revision. A fresh owner-repository release query on 2026-09-06 returns zero published releases for
ContextualWisdomLab/semantic-data-portal.Therefore this PR remains dependency-first and Draft. The pinned source revision is review evidence only; it is not an admissible production dependency. Do not integrate or relabel it as released until the canonical owner publishes an immutable versioned contract/API/schema and Orgmetra updates its ACL/adapter binding to that release with exact compatibility evidence.
Protected-parent semantic adoption finding
Current protected authority is
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; current feature head remainsc340e7599f147b25fab4c94cd2042a96d6128235. GitHub reports the PR mechanically mergeable, but the current synthetic merge1811ed75a8cb9d560ad59337d7520389296764efis not semantically acceptable as-is: its exact workflow inventory resurrects.github/workflows/semantic-job-evidence-adapter-quality.ymlalongside canonical Foundation/Recovery. The resurrected leaf still usesubuntu-latest, while protected #161 consolidated repository-owned quality workflows and pins the canonical runner contract.This is the same class of semantic adoption defect already proven on other old-feature lanes. A future Orgmetra reconciliation must retire the leaf and preserve its useful contracts—Python 3.12/3.13/3.14 compatibility, SHA-256-bound installed-wheel execution, isolated toolchain/import provenance, compile and exact 100% statement/branch coverage—inside the canonical Foundation path, add executable non-resurrection coverage, and reseal provenance from final bytes before a non-force protected-parent adoption is pushed.
Current acceptance discipline
Historical local/hosted GREEN on
c340e759...remains predecessor/old-base evidence only. No protected-parent successor has been pushed in this repair because doing so with the currently computed tree would knowingly restore retired CI and because the required foreign released contract does not yet exist.The PR remains open · Draft. Do not self-approve, use routine administrator bypass, weaken gates, treat a bare foreign commit as a released dependency, copy Semantic Data Portal source, push the known-bad synthetic merge tree, no-op retrigger, force-push/destructively rebase, or Close this valid Job Analysis evidence delta.