docs(agent guides): align ecosystem names and review authority - #88
docs(agent guides): align ecosystem names and review authority#88seonghobae wants to merge 11 commits into
Conversation
keyverse (was cwl-idp) is the ecosystem's central passwordless IdP (OIDC/SCIM/ADFS/LDAP/FIDO2/OAuth2.1). feelanet-adfs is the employer ADFS SSO integration library that keyverse federates. Aligns AGENTS.md with .github/docs/CWL-MASTER-CONTEXT.md. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head06189318588b5350f44f9b93cef2ddb2727f5266. -
Head SHA:
06189318588b5350f44f9b93cef2ddb2727f5266 -
Workflow run: 30916934614
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file: AGENTS.md"]
R1 --> V1["required checks"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage evidence job did not run or did not publish coverage evidence. Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file: AGENTS.md"]
R1 --> V1["required checks"]
|
Summary
Align stale agent guidance with the repository and organization source of truth:
keyverse, not the employer-specificfeelanet-adfsintegration library;waf-ids-ai-socrepository name withwardnet;ModelClientreads provider secrets from the process environment with the implemented KV credential-registry contract;api_key_envis only a backward-compatible credential name and that unresolved credentials fail before provider egress;AGENTS.mdandCLAUDE.mdthat the centrally governed OpenCode review pipeline "stays on GitHub Models";ContextualWisdomLab/.github;NVIDIA_NIM_API_KEY, neverCOPILOT_GITHUB_TOKEN; andScope
AGENTS.md,CLAUDE.md, andtests/test_repository_security_metadata.py.githubcontrol plane or its review-agent identity/credential chainTest-first evidence
Ecosystem and credential authority
03a59c30f313a087526ebb88506b4f94d23e264fadded the first governance regression before theAGENTS.mdrepair; the inherited file still containedstays on **GitHub Models**and could not satisfy that contract.7b8ae5bace23a6530db09f637328cddb05d448c5repairedAGENTS.mdwhile keeping provider policy centrally owned.20bd54c4901dc8387286594bf72841611f83ab1fexpanded the regression to require the same authority and credential contract inCLAUDE.md; the inherited Claude guide still containedstays on GitHub Modelsand could not satisfy that contract.14dd82bbd98c2d9c80347984c35226bfc8ab2129repairedCLAUDE.mdto match the canonical guide.Repository writer lease and read-only dependencies
103180e55bfbacfce1c41bb45c4d60aa4451ef03requires both guides to state one writer per repository branch, exact PR-head/target-blob refetch, read-only dependency treatment, prohibition on dispatching write-capable agents outside this repository, and rejection of stale-head evidence.517dc91722804ffb914e77aa783042d9049adce2adds the canonical tool-neutral contract toAGENTS.md, including reconcile-once semantics and prohibition of one-shot/self-modifying repair workflows.a7f78f5674d9425be7f5f3bf355df431274d0944mirrors the contract in the Claude entry guide while keepingAGENTS.mdauthoritative.Exact integration identity
a7f78f5674d9425be7f5f3bf355df431274d0944fix/atheris-interpreter-lock(PR fix(security): pin provider egress and repair the Atheris lock #96)3703d0da9823b8258a0be94f1801aa5d61bfad9fecad520fc3bd3e2591fa79e473e0666223d6d427; it is not the live stacked-base tip.maintip observed during this evidence refresh:6841b71935e0b7cb98fb52bcb4709cc5100c8d87Current-head evidence
The following successful jobs explicitly checked out exact contributor head
a7f78f5674d9425be7f5f3bf355df431274d0944:31176988677, job92861040389: success31176988666, jobs92861039989and92861040052: success31176988668, jobs92861040663and92861040760: successThese are exact-contributor-head results against the then-triggered context; because the stacked base has since advanced, they are not current-base integration acceptance.
Still non-passing or absent:
CHANGES_REQUESTEDtargets predecessor head06189318588b5350f44f9b93cef2ddb2727f5266; its coverage-evidence concern remains relevant, but the review is neither current-head evidence nor an approvalAbsent, predecessor-head, stale-base, status-only, and synthetic-merge evidence is not exact-head success.
Integration order and dependency authority
This PR remains Draft and stacked on PR #96. PR #96 is still Draft at
3703d0da9823b8258a0be94f1801aa5d61bfad9f. Its Tests, Security, and Fuzz contributor-head jobs succeeded, while Security Scan/SAST evidence includes synthetic-merge or mixed-checkout execution and current-head automated-review plus independent-approval gates remain incomplete. Do not refresh this branch repeatedly while #96 remains mutable.The central
ContextualWisdomLab/.githubprotected-maintip observed during this refresh is6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. Historical central PR #759 is closed without merge; older open central repair proposals such as #812, #816, and #827 are unmerged and are not protected-main authority. No relevant central repair is treated as accepted until its exact commit is integrated into protectedmain. This repository does not write central branches, dispatch repair agents there, resolve their threads, or merge their PRs.After PR #96 reaches one accepted stable head or protected
main, reconcile this branch once against that exact base and regenerate every exact-head repository, security, coverage, and review surface. If that cannot be done safely, keep the PR Draft and rebuild only its unique changes on the latest protectedmain.Acceptance
Repository Tests, Fuzz, Security, Security Scan, SAST Semgrep, current-head central coverage/review evidence, zero valid unresolved findings, every live branch-protection and ruleset requirement, and qualifying independent non-author approval must pass on the same accepted head/base before merge. Pending, queued, skipped-required, cancelled, absent, failed, stale-head, predecessor-head, stale-base, status-only, infrastructure-only, or synthetic-merge evidence is not passing.
Supersession
Closed unmerged after exact diff and contract verification proved that canonical documentation PR #105 at
31cbf2549251e604ae86f53afe50c39d1a11a6d1preserves this PR's writer-lease, central review-authority, NVIDIA development-key, credential, and corrected ecosystem-name contracts. The exact regression file blob is identical (0d383af17487b9001435b4bd33a6e029a6eb4e74), and #105 adds the broader canonical documentation graph. #88's predecessor checks and review do not transfer; #105 must pass its own exact-head gates.