Skip to content

docs(agent guides): align ecosystem names and review authority - #88

Closed
seonghobae wants to merge 11 commits into
fix/atheris-interpreter-lockfrom
docs/agents-keyverse
Closed

docs(agent guides): align ecosystem names and review authority#88
seonghobae wants to merge 11 commits into
fix/atheris-interpreter-lockfrom
docs/agents-keyverse

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Align stale agent guidance with the repository and organization source of truth:

  • assign the passwordless SSO role to keyverse, not the employer-specific feelanet-adfs integration library;
  • replace the former waf-ids-ai-soc repository name with wardnet;
  • replace the obsolete claim that ModelClient reads provider secrets from the process environment with the implemented KV credential-registry contract;
  • clarify that legacy api_key_env is only a backward-compatible credential name and that unresolved credentials fail before provider egress;
  • remove the stale assertion in both AGENTS.md and CLAUDE.md that the centrally governed OpenCode review pipeline "stays on GitHub Models";
  • preserve provider-pool, reviewer-identity, and credential-chain authority in ContextualWisdomLab/.github;
  • require repository-owned live model tests and autonomous development work to use NVIDIA_NIM_API_KEY, never COPILOT_GITHUB_TOKEN; and
  • establish one-writer branch leases, exact-head/blob refetch, read-only dependency authority, and stale-evidence rejection as executable repository guidance.

Scope

  • Changed files: AGENTS.md, CLAUDE.md, and tests/test_repository_security_metadata.py
  • No runtime, dependency, workflow, API, database, or permission changes
  • No mutation of the central .github control plane or its review-agent identity/credential chain

Test-first evidence

Ecosystem and credential authority

  • 03a59c30f313a087526ebb88506b4f94d23e264f added the first governance regression before the AGENTS.md repair; the inherited file still contained stays on **GitHub Models** and could not satisfy that contract.
  • 7b8ae5bace23a6530db09f637328cddb05d448c5 repaired AGENTS.md while keeping provider policy centrally owned.
  • 20bd54c4901dc8387286594bf72841611f83ab1f expanded the regression to require the same authority and credential contract in CLAUDE.md; the inherited Claude guide still contained stays on GitHub Models and could not satisfy that contract.
  • 14dd82bbd98c2d9c80347984c35226bfc8ab2129 repaired CLAUDE.md to match the canonical guide.

Repository writer lease and read-only dependencies

  • RED 103180e55bfbacfce1c41bb45c4d60aa4451ef03 requires both guides to state one writer per repository branch, exact PR-head/target-blob refetch, read-only dependency treatment, prohibition on dispatching write-capable agents outside this repository, and rejection of stale-head evidence.
  • GREEN 517dc91722804ffb914e77aa783042d9049adce2 adds the canonical tool-neutral contract to AGENTS.md, including reconcile-once semantics and prohibition of one-shot/self-modifying repair workflows.
  • GREEN a7f78f5674d9425be7f5f3bf355df431274d0944 mirrors the contract in the Claude entry guide while keeping AGENTS.md authoritative.
  • A networkless exact-token diagnostic reported all 10 required guide assertions passing. It is not a substitute for GitHub Checks.

Exact integration identity

  • Exact head: a7f78f5674d9425be7f5f3bf355df431274d0944
  • Stacked base branch: fix/atheris-interpreter-lock (PR fix(security): pin provider egress and repair the Atheris lock #96)
  • Exact live base-branch tip: 3703d0da9823b8258a0be94f1801aa5d61bfad9f
  • The connector's PR base snapshot still reports predecessor ecad520fc3bd3e2591fa79e473e0666223d6d427; it is not the live stacked-base tip.
  • Protected main tip observed during this evidence refresh: 6841b71935e0b7cb98fb52bcb4709cc5100c8d87
  • State: Draft
  • Mergeability snapshot: mergeable; this is not an acceptance or merge authorization.

Current-head evidence

The following successful jobs explicitly checked out exact contributor head a7f78f5674d9425be7f5f3bf355df431274d0944:

  • Tests run 31176988677, job 92861040389: success
  • Security run 31176988666, jobs 92861039989 and 92861040052: success
  • Fuzz run 31176988668, jobs 92861040663 and 92861040760: success

These are exact-contributor-head results against the then-triggered context; because the stacked base has since advanced, they are not current-base integration acceptance.

Still non-passing or absent:

  • Security Scan: absent
  • SAST Semgrep: absent
  • trusted central coverage/package evidence: absent
  • current-head Noema, Strix, and OpenCode verdicts: absent
  • qualifying independent non-author approval: absent
  • unresolved inline review threads: zero
  • requested reviewers: none
  • CodeRabbit commit status: success, but CodeRabbit explicitly skipped review because the PR is Draft; this is status-only, not a review verdict
  • recorded OpenCode CHANGES_REQUESTED targets predecessor head 06189318588b5350f44f9b93cef2ddb2727f5266; its coverage-evidence concern remains relevant, but the review is neither current-head evidence nor an approval

Absent, predecessor-head, stale-base, status-only, and synthetic-merge evidence is not exact-head success.

Integration order and dependency authority

This PR remains Draft and stacked on PR #96. PR #96 is still Draft at 3703d0da9823b8258a0be94f1801aa5d61bfad9f. Its Tests, Security, and Fuzz contributor-head jobs succeeded, while Security Scan/SAST evidence includes synthetic-merge or mixed-checkout execution and current-head automated-review plus independent-approval gates remain incomplete. Do not refresh this branch repeatedly while #96 remains mutable.

The central ContextualWisdomLab/.github protected-main tip observed during this refresh is 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. Historical central PR #759 is closed without merge; older open central repair proposals such as #812, #816, and #827 are unmerged and are not protected-main authority. No relevant central repair is treated as accepted until its exact commit is integrated into protected main. This repository does not write central branches, dispatch repair agents there, resolve their threads, or merge their PRs.

After PR #96 reaches one accepted stable head or protected main, reconcile this branch once against that exact base and regenerate every exact-head repository, security, coverage, and review surface. If that cannot be done safely, keep the PR Draft and rebuild only its unique changes on the latest protected main.

Acceptance

Repository Tests, Fuzz, Security, Security Scan, SAST Semgrep, current-head central coverage/review evidence, zero valid unresolved findings, every live branch-protection and ruleset requirement, and qualifying independent non-author approval must pass on the same accepted head/base before merge. Pending, queued, skipped-required, cancelled, absent, failed, stale-head, predecessor-head, stale-base, status-only, infrastructure-only, or synthetic-merge evidence is not passing.

Supersession

Closed unmerged after exact diff and contract verification proved that canonical documentation PR #105 at 31cbf2549251e604ae86f53afe50c39d1a11a6d1 preserves this PR's writer-lease, central review-authority, NVIDIA development-key, credential, and corrected ecosystem-name contracts. The exact regression file blob is identical (0d383af17487b9001435b4bd33a6e029a6eb4e74), and #105 adds the broader canonical documentation graph. #88's predecessor checks and review do not transfer; #105 must pass its own exact-head gates.

keyverse (was cwl-idp) is the ecosystem's central passwordless IdP
(OIDC/SCIM/ADFS/LDAP/FIDO2/OAuth2.1). feelanet-adfs is the employer ADFS
SSO integration library that keyverse federates. Aligns AGENTS.md with
.github/docs/CWL-MASTER-CONTEXT.md.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 88147918-29d6-4c8e-99e9-14ce3ceb5cbd

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@seonghobae
seonghobae enabled auto-merge (squash) August 4, 2026 05:47
@seonghobae seonghobae changed the title docs(AGENTS.md): passwordless SSO is keyverse, not feelanet-adfs docs(AGENTS.md): align ecosystem repository names Aug 4, 2026

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 06189318588b5350f44f9b93cef2ddb2727f5266.

  • Head SHA: 06189318588b5350f44f9b93cef2ddb2727f5266

  • Workflow run: 30916934614

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: AGENTS.md"]
  R1 --> V1["required checks"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 06189318588b5350f44f9b93cef2ddb2727f5266
  • Workflow run: 30916934614
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 06189318588b5350f44f9b93cef2ddb2727f5266.

  • Head SHA: 06189318588b5350f44f9b93cef2ddb2727f5266

  • Workflow run: 30916934614

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file: AGENTS.md"]
  R1 --> V1["required checks"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 4, 2026 16:22
@seonghobae
seonghobae changed the base branch from main to fix/atheris-interpreter-lock August 5, 2026 02:08
@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
@seonghobae
seonghobae marked this pull request as draft August 5, 2026 05:08
@seonghobae seonghobae changed the title docs(AGENTS.md): align ecosystem repository names docs(AGENTS.md): align ecosystem names and KV credential contract Aug 5, 2026
@seonghobae seonghobae changed the title docs(AGENTS.md): align ecosystem names and KV credential contract docs(AGENTS.md): align ecosystem names and review authority Aug 7, 2026
@seonghobae seonghobae changed the title docs(AGENTS.md): align ecosystem names and review authority docs(agent guides): align ecosystem names and review authority Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant