chore(governance): add CI/CD governance baseline#8
Conversation
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. 📒 Files selected for processing (7)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04c5294a0a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| jobs: | ||
| gates: | ||
| uses: ./.github/workflows/reusable-governance-gates.yml |
There was a problem hiding this comment.
Point governance gate to an existing reusable workflow
The gates job calls ./.github/workflows/reusable-governance-gates.yml, but that file is not present in this repo (verified via repo-wide file search), so every pull_request/push run of this workflow will fail before any checks execute. This breaks the new governance gate path and can block merges if the check is required.
Useful? React with 👍 / 👎.
| shell: bash | ||
| run: | | ||
| set -euo pipefail | ||
| bash scripts/check-chitty-onboarding.sh .chittyconnect.yml |
There was a problem hiding this comment.
Invoke an onboarding script that exists in the repository
This workflow executes scripts/check-chitty-onboarding.sh, but that script is not in the repository (repo-wide search finds no such path), so the onboarding job will fail with No such file or directory on every PR and push. If this gate is required, it will create a permanent CI blocker.
Useful? React with 👍 / 👎.
| run: | | ||
| set -euo pipefail | ||
| mkdir -p reports/secret-rotation | ||
| if bash scripts/onepassword-rotation-audit.sh .github/secret-catalog.json reports/secret-rotation; then |
There was a problem hiding this comment.
Call a rotation audit script that is actually present
The rotation step runs scripts/onepassword-rotation-audit.sh, but there is no script at that path in the repo, so the scheduled/manual audit job will always report failure due to a missing executable rather than real rotation status. This makes the new audit workflow non-functional and can generate noisy issue churn.
Useful? React with 👍 / 👎.
Automated governance baseline remediation from org control loop.