feat(core): add governed Position reporting-change review - #95
feat(core): add governed Position reporting-change review#95seonghobae wants to merge 7 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (11)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes포지션 보고 변경 검토
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: 🟡 Moderate · up to The change adds a bounded pre-mutation review boundary without changing reporting-line data, and no user-facing or production defect is identified. The current head should not merge yet because the required independent non-author approval is still missing. Sequence Diagram(s)sequenceDiagram
participant Caller
participant build_position_reporting_change_review_packet
participant PositionReportingChangeReviewPacket
participant QualityWorkflow
Caller->>build_position_reporting_change_review_packet: reporting-change 입력 전달
build_position_reporting_change_review_packet->>PositionReportingChangeReviewPacket: 검증된 패킷 생성
PositionReportingChangeReviewPacket-->>Caller: canonical evidence와 SHA-256 digest 제공
QualityWorkflow->>PositionReportingChangeReviewPacket: 설치된 wheel 테스트 실행
QualityWorkflow-->>Caller: 커버리지와 checkout 검증 결과 반환
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…tively Preserve the complete governed reporting-change review delta while adopting protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f using GitHub's conflict-free exact merge tree. Keep #94 as an active read-only hierarchy dependency claim only; do not import mutable sibling source. No force-push, gate weakening, foreign-owner source copy, or release claim.
Repair the exact-head Foundation runner/inventory RED after protected-parent adoption. Retire the resurrected package-local workflow, preserve its exact CPython 3.14.7 installed-wheel and 100% statement/branch coverage contract inside canonical one-job Foundation CI, update the package regression and traceability, and reseal the Foundation manifest. No Position domain behavior, review authority boundary, coverage threshold, protected history, or central gate is weakened.
Buyer-visible scope
This Orgmetra-only PR adds a bounded, transport-neutral pre-mutation review boundary for solid-line Position-to-Position reporting reassignment. The packet keeps subordinate/current/proposed manager Position references distinct, rejects self-report/no-op proposals, separates business-effective from system-recorded time, binds reviewed scope with SHA-256 evidence, requires requester/reviewer separation, and remains
requires_human_review,requires_authoritative_resolution,not_authorized_to_apply, andhuman_review_only. It carries no Person PII, compensation, ratings, free-form personal reasons or employment-decision authority.Protected-parent adoption and causal repair
Current exact head is
9b50b4f3f42e1698c634a73e7f4580e9cfae4c8eon protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; the PR remains open · Draft.Ordinary non-force adoption
2317c367...preserved protected #161 and imported no mutable #94 source. Successorc0975db9...added protected-parent traceability, then hosted Foundation34005946944exposed the semantic adoption RED:.github/workflows/position-reporting-change-review-quality.ymlhad been resurrected withubuntu-latest, violating the protected exactubuntu-24.04runner/inventory contract.9b50b4f...is an ordinary fast-forward causal repair. It retires the leaf, preserves exact installed-wheel execution, hash-bound wheel installation, pinned CPython 3.14.7 and the unchanged 100% statement/branch threshold in canonical Foundation CI, rewrites the package repository contract to require the canonical path and retired leaf, updates traceability/changelog, and resealsmanifest.jsonagainst exact Foundation bytes (sha256=81ae584c9c3dd89d7e86011550d9afec439f17b46a1b21db2fc8104f9149aab3, 9199 bytes, 148 lines). No Position domain behavior, review authority, coverage threshold, protected history, mutable #94 source or central gate was weakened.Current acceptance
Foundation
34009658313and SAST Semgrep34009658300are terminal SUCCESS on exact9b50b4f.... Security Scan34009658302is terminal FAILURE only because dependency-review job101428767239checks out and verifies the exact head, then fails atCheck dependency review support; the authoritative Dependency Review action is skipped. OSV and Trivy complete successfully, but they do not replace that missing gate.CodeQL PR
34009658290is terminal FAILURE at the central verdict handoff rather than from a demonstrated Position source/SARIF finding. Language detection succeeds; Python job101428499016and Actions job101428499024successfully request current-head CodeQL dispatch and fail only atRelease runner or enforce current-head CodeQL verdict. Orgmetra does not synthesize a verdict, weaken the gate, or churn the head to retrigger central infrastructure.Historical predecessor GREEN and the failed
c0975db9...run do not transfer. The PR remains Draft while authoritative Dependency Review/CodeQL and the then-applicable independent review gates remain non-passing.Before authoritative mutation the host must still re-resolve tenant, subordinate/current/proposed manager Positions, business-effective coordinate, current recorded cutoff, solid-line relationship, Position validity/staffability, reviewer separation, cycle/cardinality constraints, and immutable audit/outbox evidence. This packet neither mutates HRIS truth nor grants employment-decision authority.
No self-approval, routine administrator bypass, gate weakening, predecessor-evidence transfer, no-op retrigger, force-push/destructive rebase, mutable sibling-source import, or release claim.