Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
153 commits
Select commit Hold shift + click to select a range
e3d7707
docs: design hourly OpenCode maintenance agent
seonghobae Aug 4, 2026
6e9219d
docs: plan hourly OpenCode maintenance agent
seonghobae Aug 4, 2026
ec45a1b
test(ci): define hourly OpenCode maintenance contract
seonghobae Aug 4, 2026
856667e
ci: schedule NVIDIA OpenCode maintenance agent
seonghobae Aug 4, 2026
995bfe3
fix(ci): make secret handling boundary explicit
seonghobae Aug 4, 2026
ff5065e
docs(ci): document OpenCode maintenance operations
seonghobae Aug 4, 2026
7e5e047
docs(ci): record NVIDIA OpenCode maintenance loop
seonghobae Aug 4, 2026
844642c
test(ci): require direct-token git bootstrap
seonghobae Aug 4, 2026
c7b168d
fix(ci): bootstrap OpenCode direct-token git access
seonghobae Aug 4, 2026
603a5ad
docs(ci): explain direct-token Git bootstrap
seonghobae Aug 4, 2026
b19d032
docs(ci): align plan with direct-token behavior
seonghobae Aug 4, 2026
a616fbe
docs(ci): harden direct-token credential lifecycle
seonghobae Aug 4, 2026
d23fefc
docs(changelog): record direct-token Git fix
seonghobae Aug 4, 2026
83b56c1
test(ci): require forced OpenCode termination
seonghobae Aug 4, 2026
613a753
fix(ci): force termination after OpenCode timeout
seonghobae Aug 4, 2026
b18c859
docs(ci): document forced OpenCode termination
seonghobae Aug 4, 2026
ba845b8
docs(ci): specify forced timeout escalation
seonghobae Aug 4, 2026
cc661d3
docs(ci): align plan with timeout escalation
seonghobae Aug 4, 2026
209ace0
docs(ci): cite GNU timeout behavior
seonghobae Aug 4, 2026
0f341d8
docs(ci): cite GNU timeout design basis
seonghobae Aug 4, 2026
9437c99
test(ci): require independent exact-head approval
seonghobae Aug 4, 2026
5c9f349
fix(ci): require independent exact-head approval
seonghobae Aug 4, 2026
671cf68
docs(ci): define exact-head approval gate
seonghobae Aug 4, 2026
87fe946
docs(changelog): record exact-head approval gate
seonghobae Aug 4, 2026
5ec2c22
test(ci): require checksum-pinned OpenCode install
seonghobae Aug 4, 2026
0ac43ab
test(ci): require local GitHub CLI credential helper
seonghobae Aug 4, 2026
5ac043e
fix(ci): close Scorecard supply-chain findings
seonghobae Aug 4, 2026
a9a9967
docs(ci): document checksum and permission boundaries
seonghobae Aug 4, 2026
1ce9a27
docs(ci): align OpenCode security design
seonghobae Aug 4, 2026
38a85be
docs(ci): update checksum-pinned implementation plan
seonghobae Aug 4, 2026
c1a8e79
docs(changelog): record OpenCode supply-chain hardening
seonghobae Aug 4, 2026
bdf9435
fix(test): normalize workflow line endings
seonghobae Aug 4, 2026
432f8ac
test(security): require patched Jackson BOM
seonghobae Aug 4, 2026
b1beef8
fix(security): align Jackson to patched BOM
seonghobae Aug 4, 2026
af707e9
docs(changelog): record Jackson advisory remediation
seonghobae Aug 4, 2026
751eedb
test(ci): require exact OpenCode archive membership
seonghobae Aug 5, 2026
13c3ab9
fix(ci): validate OpenCode archive members
seonghobae Aug 5, 2026
f4b2a1c
docs(ci): explain archive extraction boundary
seonghobae Aug 5, 2026
1ccc8c9
docs(ci): design fail-closed archive extraction
seonghobae Aug 5, 2026
368ceac
docs(ci): plan archive-member validation
seonghobae Aug 5, 2026
862bad4
docs(doctoring): record archive extraction evidence
seonghobae Aug 5, 2026
f3da591
docs(changelog): record archive extraction hardening
seonghobae Aug 5, 2026
7b82a40
test(ci): require regular OpenCode archive member
seonghobae Aug 5, 2026
31dc60e
fix(ci): reject non-regular archive entries
seonghobae Aug 5, 2026
7a36304
docs(doctoring): record regular-entry validation
seonghobae Aug 5, 2026
46fdace
docs(ci): document archive entry-type gate
seonghobae Aug 5, 2026
cc7766e
docs(ci): design regular-entry validation
seonghobae Aug 5, 2026
982a6bc
docs(ci): align archive entry-type plan
seonghobae Aug 5, 2026
42eb7d7
test(ci): require available free NVIDIA model
seonghobae Aug 5, 2026
90c1502
fix(ci): select available free NVIDIA model
seonghobae Aug 5, 2026
f0c0211
docs(doctoring): record NVIDIA model selection evidence
seonghobae Aug 5, 2026
5747bf8
docs(ci): select available NVIDIA coding model
seonghobae Aug 5, 2026
ca1dc7f
docs(ci): design current NVIDIA model selection
seonghobae Aug 5, 2026
57d15c6
docs(ci): plan current NVIDIA model integration
seonghobae Aug 5, 2026
a0ad9d0
docs(changelog): record current NVIDIA model
seonghobae Aug 5, 2026
d7596e4
test(etl): reject empty JaCoCo coverage scopes
seonghobae Aug 5, 2026
2517056
fix(etl): make JaCoCo coverage fail closed
seonghobae Aug 5, 2026
3b25dfd
test(etl): compare coverage includes deterministically
seonghobae Aug 5, 2026
bfd5114
test(etl): cover durable intake validation boundaries
seonghobae Aug 5, 2026
516bc57
test(etl): cover every durable intake branch
seonghobae Aug 5, 2026
d4d8a9e
refactor(etl): centralize durable SHA-256 identity
seonghobae Aug 5, 2026
1907a48
feat(etl): centralize SHA-256 digesting
seonghobae Aug 5, 2026
9b94b14
test(etl): verify SHA-256 digest utility
seonghobae Aug 5, 2026
b0a5d49
test(etl): include digest utility in complete coverage
seonghobae Aug 5, 2026
3106dc7
test(etl): bind digest utility to complete coverage
seonghobae Aug 5, 2026
b8fea3f
test(etl): cover empty durable batch validation
seonghobae Aug 5, 2026
cae178c
ci: expose exact JaCoCo branch diagnostics
seonghobae Aug 5, 2026
bd2f0d0
test(etl): cover parser end-of-input branch
seonghobae Aug 5, 2026
1feb650
test(ci): require default-branch-only maintenance source
seonghobae Aug 5, 2026
ed30200
test(ci): require diagnostics for all coverage targets
seonghobae Aug 5, 2026
82de9b3
test(security): verify effective Jackson BOM resolution
seonghobae Aug 5, 2026
7a682cf
fix(ci): bind maintenance workflow to default branch
seonghobae Aug 5, 2026
97b4449
fix(ci): diagnose every strict coverage target
seonghobae Aug 5, 2026
e081acd
fix(security): import patched Jackson BOM explicitly
seonghobae Aug 5, 2026
75eafeb
test(security): verify Jackson BOM precedence
seonghobae Aug 5, 2026
e9f3a03
docs: clarify OpenCode secret process scope
seonghobae Aug 5, 2026
3a46868
docs: align OpenCode extraction plan
seonghobae Aug 5, 2026
5f8fcdf
docs: align OpenCode extraction design
seonghobae Aug 5, 2026
91d86fa
test(ci): require exact-head checks after agent pushes
seonghobae Aug 5, 2026
1d35988
fix(ci): revalidate exact heads written by OpenCode
seonghobae Aug 5, 2026
9b63536
test(ci): harden exact-head run authorization
seonghobae Aug 5, 2026
b4ec3ba
fix(ci): fail closed on agent policy changes
seonghobae Aug 5, 2026
ee6c5eb
docs(ci): record exact-head check authorization evidence
seonghobae Aug 5, 2026
80dd0d0
docs(ci): document agent head revalidation
seonghobae Aug 5, 2026
9852841
docs(changelog): record exact-head check authorization
seonghobae Aug 5, 2026
a8d1f6a
test(ci): isolate Actions write from the agent
seonghobae Aug 5, 2026
1a56702
fix(ci): isolate check authorization from OpenCode
seonghobae Aug 5, 2026
cc4c9e9
docs(ci): isolate exact-head authorization authority
seonghobae Aug 5, 2026
6d23599
docs(ci): document split-job authorization
seonghobae Aug 5, 2026
41624f3
docs(ci): align design with split authority
seonghobae Aug 5, 2026
aa2ac97
docs(ci): align implementation plan with exact-head revalidation
seonghobae Aug 5, 2026
015511c
test(ci): require every exact-head workflow to materialize
seonghobae Aug 5, 2026
bd017ef
fix(ci): authorize the complete exact-head workflow set
seonghobae Aug 5, 2026
887a48a
docs(ci): require complete workflow-set materialization
seonghobae Aug 5, 2026
68e82f9
docs(ci): document complete exact-head workflow authorization
seonghobae Aug 5, 2026
df61d97
test(ci): require agent authority separation and PR-bound checks
seonghobae Aug 6, 2026
e689499
fix(ci): isolate agent PR authority and bind checks to PR
seonghobae Aug 6, 2026
c115a4a
docs(ci): record model and PR authority separation
seonghobae Aug 6, 2026
8d34b7c
docs(doctoring): prove PR authority and run association boundaries
seonghobae Aug 6, 2026
28b56bb
docs(design): separate model, publisher, and run authorizer
seonghobae Aug 6, 2026
f3d6861
docs(plan): complete authority-separated OpenCode workflow plan
seonghobae Aug 6, 2026
a5f0972
test(ci): assert semantic workflow authorization contract
seonghobae Aug 6, 2026
7974905
test(ci): guard jq branch candidate scope
seonghobae Aug 6, 2026
ed88fc8
fix(ci): capture branch name before jq array lookup
seonghobae Aug 6, 2026
75bdc19
test(ci): require existing PR policy-file guard
seonghobae Aug 6, 2026
91533ad
fix(ci): guard policy changes on updated PRs
seonghobae Aug 6, 2026
6b698be
docs(ci): document updated PR policy guard
seonghobae Aug 6, 2026
2f37444
docs(changelog): record existing PR policy guard
seonghobae Aug 6, 2026
9bbd20b
test(ci): expose synthetic merge workflow evidence
seonghobae Aug 7, 2026
4ce080a
fix(ci): execute quality gates on exact source head
seonghobae Aug 7, 2026
91f6dcb
fix(sbom): bind inventory generation to exact source head
seonghobae Aug 7, 2026
16ebda4
docs(ci): record exact-head source evidence boundary
seonghobae Aug 7, 2026
b24bed9
docs(changelog): record exact-head CI and SBOM evidence
seonghobae Aug 7, 2026
077340a
test(ci): require exact dependency review refs
seonghobae Aug 7, 2026
0b947a6
fix(ci): bind dependency review to exact PR refs
seonghobae Aug 7, 2026
3185f26
docs(ci): record exact dependency review evidence
seonghobae Aug 7, 2026
cd706f2
test(ci): reject ignored dependency review ref overrides
seonghobae Aug 7, 2026
4c30a17
docs(changelog): record exact dependency review binding
seonghobae Aug 7, 2026
3358b40
fix(ci): rely on pull-request dependency review refs
seonghobae Aug 7, 2026
6b6afb9
docs(ci): correct dependency review endpoint evidence
seonghobae Aug 7, 2026
d1cae11
docs(changelog): correct dependency review event semantics
seonghobae Aug 7, 2026
7efcca2
test: require read-only issue permission
seonghobae Aug 7, 2026
171e0a8
fix: restrict maintenance issue access
seonghobae Aug 7, 2026
c7ef4a8
docs: document read-only issue authority
seonghobae Aug 7, 2026
c2ecc34
docs: record least-privilege issue access
seonghobae Aug 7, 2026
727e7ca
test(ci): require isolated branch writer
seonghobae Aug 7, 2026
2079a01
fix(ci): isolate model from repository writes
seonghobae Aug 7, 2026
327d1e4
test(ci): bind policy guard to isolated publisher
seonghobae Aug 7, 2026
b6efb1f
test(security): require immutable container base images
seonghobae Aug 8, 2026
f8cdcf7
fix(security): pin container base image digests
seonghobae Aug 8, 2026
832061b
docs(security): record container image pinning evidence
seonghobae Aug 8, 2026
699d3f2
docs(changelog): record immutable base image pins
seonghobae Aug 8, 2026
7ae7dcc
test(ci): specify nonblocking maintenance progress contract
seonghobae Aug 8, 2026
8bac86c
docs(agents): keep scheduled maintenance productive during external w…
seonghobae Aug 8, 2026
6d5101c
docs(doctoring): record nonblocking scheduler progress contract
seonghobae Aug 8, 2026
3c22841
docs(changelog): record nonblocking scheduled progress
seonghobae Aug 8, 2026
29b373f
fix(changelog): preserve exact legacy config alias scope
seonghobae Aug 8, 2026
06f49cc
test(ci): compare scheduler policy independent of Markdown wrapping
seonghobae Aug 8, 2026
dba0af6
test(ci): require RCA feasibility loop in scheduler
seonghobae Aug 8, 2026
ab3d5b2
fix(ci): require RCA and feasible action selection
seonghobae Aug 8, 2026
36c8752
fix(ci): restore exact-head authorization dependency
seonghobae Aug 8, 2026
5efb68e
docs(agents): require RCA feasibility before action
seonghobae Aug 8, 2026
1b90dbc
docs(doctoring): record RCA feasibility contract
seonghobae Aug 8, 2026
427ce2b
docs(changelog): record RCA feasibility scheduler
seonghobae Aug 8, 2026
b1afefd
test(docs): require current OpenCode authority topology
seonghobae Aug 8, 2026
75265fa
docs(security): align OpenCode authority evidence
seonghobae Aug 8, 2026
2a4053c
Merge branch 'develop' into ci/hourly-opencode-nvidia-nim
opencode-agent[bot] Aug 10, 2026
d55e06d
test(automation): prove duplicate run approval red
seonghobae Aug 10, 2026
5d083a0
test(security): prove indented Docker FROM bypass red
seonghobae Aug 10, 2026
e67f912
test(automation): prove work-conserving prompt red
seonghobae Aug 10, 2026
3641d60
fix(security): include indented Docker FROM instructions
seonghobae Aug 10, 2026
69b39f5
fix(automation): complete work-conserving runtime contract
seonghobae Aug 11, 2026
d22e7d2
test(automation): pin current review contracts
seonghobae Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 99 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,17 @@ jobs:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout
- name: Checkout exact source revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false

- name: Verify exact source revision
shell: bash
run: |
set -euo pipefail
test "$(git rev-parse HEAD)" = "${{ github.event.pull_request.head.sha || github.sha }}"

- name: Set up Java
uses: actions/setup-java@1bcf9fb12cf4aa7d266a90ae39939e61372fe520 # v5.4.0
Expand All @@ -46,12 +55,100 @@ jobs:
if: runner.os == 'Windows'
run: .\\mvnw.cmd -B test

- name: Report uncovered JaCoCo branches
if: failure()
shell: bash
run: |
python_command="python3"
if ! command -v "${python_command}" >/dev/null 2>&1; then
python_command="python"
fi
"${python_command}" - <<'PY'
from pathlib import Path
import xml.etree.ElementTree as ElementTree

coverage_targets = {
"com/xtrmetl/etl/job/EtlJobService": "EtlJobService.java",
"com/xtrmetl/etl/controller/EtlJobController": "EtlJobController.java",
"com/xtrmetl/etl/service/Sha256Digest": "Sha256Digest.java",
}
reports = sorted(Path(".").glob("**/target/site/jacoco/jacoco.xml"))
if not reports:
raise SystemExit("No JaCoCo XML report was produced")

found_classes = {class_name: False for class_name in coverage_targets}
for report_path in reports:
report_root = ElementTree.parse(report_path).getroot()
for class_name, source_name in coverage_targets.items():
for class_element in report_root.findall(
f".//class[@name='{class_name}']"
):
found_classes[class_name] = True
print(f"JaCoCo branch diagnostics for {class_name} from {report_path}:")
for method_element in class_element.findall("method"):
for counter in method_element.findall("counter"):
if counter.get("type") != "BRANCH":
continue
missed = int(counter.get("missed", "0"))
if missed > 0:
print(
" method="
f"{method_element.get('name')}{method_element.get('desc')} "
f"first_line={method_element.get('line')} "
f"missed_branches={missed} "
f"covered_branches={counter.get('covered', '0')}"
)

for source_element in report_root.findall(
f".//sourcefile[@name='{source_name}']"
):
for line_element in source_element.findall("line"):
missed = int(line_element.get("mb", "0"))
if missed > 0:
print(
f" source={source_name} "
f"source_line={line_element.get('nr')} "
f"missed_branches={missed} "
f"covered_branches={line_element.get('cb', '0')}"
)

missing_classes = [
class_name
for class_name, was_found in found_classes.items()
if not was_found
]
if missing_classes:
raise SystemExit(
"Strict coverage targets absent from JaCoCo XML: "
+ ", ".join(missing_classes)
)
PY

test_self_hosted:
if: ${{ github.event_name == 'workflow_dispatch' && inputs.use_self_hosted == true }}
runs-on: self-hosted
steps:
- name: Checkout
- name: Checkout exact source revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false

- name: Verify exact source revision (Unix)
if: runner.os != 'Windows'
shell: bash
run: |
set -euo pipefail
test "$(git rev-parse HEAD)" = "${{ github.event.pull_request.head.sha || github.sha }}"

- name: Verify exact source revision (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
$actualHead = git rev-parse HEAD
if ($actualHead -ne "${{ github.event.pull_request.head.sha || github.sha }}") {
throw "Checked-out revision does not match the expected source SHA."
}

- name: Set up Java
uses: actions/setup-java@1bcf9fb12cf4aa7d266a90ae39939e61372fe520 # v5.4.0
Expand Down
Loading
Loading