diff --git a/PR_GOVERNANCE_AUDIT.md b/PR_GOVERNANCE_AUDIT.md index daefb573a..f704cb499 100644 --- a/PR_GOVERNANCE_AUDIT.md +++ b/PR_GOVERNANCE_AUDIT.md @@ -131,7 +131,7 @@ governance contract. ## Live Repository Inventory -Live generated: 2026-06-26 KST via GitHub REST/GraphQL APIs. PR #28 post-merge refresh: 2026-06-23 16:05 KST. PR #37 post-merge refresh: 2026-06-23 21:50 KST. clearfolio PR #13 post-merge refresh: 2026-06-24 04:48 KST. Non-actionable Findings refresh: 2026-06-25 KST. PR #58, #65, #66, #68, #71, #79, and #80 post-merge refreshes: 2026-06-25 to 2026-06-26 KST. The 2026-07-02 13:21 KST refresh found 17 public non-fork repositories, adding `kaefa` and `waf-ids-ai-soc` to the prior public non-fork inventory. The public fork inventory still contains 6 repositories. `VibeSec` was not in that target set, and `appguardrail` was. +Live generated: 2026-06-26 KST via GitHub REST/GraphQL APIs. PR #28 post-merge refresh: 2026-06-23 16:05 KST. PR #37 post-merge refresh: 2026-06-23 21:50 KST. clearfolio PR #13 post-merge refresh: 2026-06-24 04:48 KST. Non-actionable Findings refresh: 2026-06-25 KST. PR #58, #65, #66, #68, #71, #79, and #80 post-merge refreshes: 2026-06-25 to 2026-06-26 KST. The 2026-07-02 18:15 KST refresh found 17 public non-fork repositories, adding `kaefa` and `waf-ids-ai-soc` to the prior public non-fork inventory. The public fork inventory still contains 6 repositories. `VibeSec` was not in that target set, and `appguardrail` was. Continuation snapshot: 2026-06-26 17:53 KST (`2026-06-26T08:53:00Z`). Every public non-fork target repository inherits org ruleset `18156473`, which requires @@ -152,7 +152,7 @@ onboarding exception before relying on autonomous PR queue draining. | Bucket | Repositories | Scheduler implication | |---|---|---| | Public target repos with central required Strix, OpenCode, and scheduler | `.github`, `ContextualWisdomLab.github.io`, `aFIPC`, `appguardrail`, `bandscope`, `clearfolio`, `codec-carver`, `contextual-orchestrator`, `fast-mlsirm`, `hyosung-itx-slogan-brief`, `kaefa`, `naruon`, `newsdom-api`, `pg-erd-cloud`, `scopeweave`, `semantic-data-portal`, `waf-ids-ai-soc` | Treat central required workflows as the rollout mechanism. Do not add repo-local copies only to satisfy governance. | -| Public target repos missing central required Strix, OpenCode, and scheduler ruleset inheritance | none observed on 2026-07-02 13:21 KST | Keep verifying inherited checks on current heads; do not reintroduce repo-local copies to compensate for stale PR evidence. `kaefa` is a runtime proof gap, not a missing-ruleset gap. | +| Public target repos missing central required Strix, OpenCode, and scheduler ruleset inheritance | none observed on 2026-07-02 18:15 KST | Keep verifying inherited checks on current heads; do not reintroduce repo-local copies to compensate for stale PR evidence. `kaefa` is a runtime proof gap, not a missing-ruleset gap. | | Public target repos with repo-local Strix/OpenCode/scheduler copies | `.github` only; this is the central source repository | Retire thick local copies outside `.github`; repository-owned product, release, and security workflows remain separate. | | Public target repos with partial or no local governance workflow footprint | all public non-fork targets outside `.github` | They are still centrally governed by ruleset `18156473`; local absence is not a required-workflow gap. | | Private target repos missing central required workflow onboarding | `xtrmLLMBatchPython` | Treat missing central Strix/OpenCode/scheduler checks as an organization ruleset onboarding gap. Do not bypass review or weaken repository approval rules to drain the queue. | @@ -160,23 +160,23 @@ onboarding exception before relying on autonomous PR queue draining. | Repo | Flow | Default | Auto | Central required workflows | Repo rules/protection | Repo required checks | Stale dismissal | Open PRs | Local workflow footprint | Recent merged actor | |---|---:|---:|---:|---|---|---|---:|---:|---|---| -| `ContextualWisdomLab/.github` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 32 | central source workflows | #267 `github-actions`; #265 `github-actions`; #263 `github-actions` | -| `ContextualWisdomLab/aFIPC` | GitHub Flow | `master` | off | Strix; OpenCode; scheduler proven on PR #78 | repo ruleset `PR` plus org central required workflows | `check`, `quality`, `secret-and-workflow-audit` | ruleset false | 21 | CodeQL; Dependency Review; R-CMD-check; quality/security audit | #78 `seonghobae`; #45 `seonghobae`; #43 `seonghobae` | +| `ContextualWisdomLab/.github` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 27 | central source workflows | #283 `github-actions`; #285 `github-actions`; #267 `github-actions` | +| `ContextualWisdomLab/aFIPC` | GitHub Flow | `master` | off | Strix; OpenCode; scheduler proven on PR #78 | repo ruleset `PR` plus org central required workflows | `check`, `quality`, `secret-and-workflow-audit` | ruleset false | 22 | CodeQL; Dependency Review; R-CMD-check; quality/security audit | #78 `seonghobae`; #45 `seonghobae`; #43 `seonghobae` | | `ContextualWisdomLab/ContextualWisdomLab.github.io` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 19 | none | #25 `seonghobae`; #15 `seonghobae`; #14 `seonghobae` | | `ContextualWisdomLab/appguardrail` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch`, `PR` | none | mixed: true/false by repo ruleset | 9 | release/security workflows | #133 `seonghobae`; #131 `seonghobae`; #115 `seonghobae` | -| `ContextualWisdomLab/bandscope` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch`; classic branch protection | `CodeQL`, `ci / build-and-test`, `dependency-review`, `gate / build / macos`, `gate / build / windows`, `release-preflight`, `sbom`, `security-audit`, `trivy-fs-scan` | ruleset true; classic false | 61 | app/security/release workflows | #451 `github-actions`; #459 `seonghobae`; #458 `seonghobae` | +| `ContextualWisdomLab/bandscope` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch`; classic branch protection | `CodeQL`, `ci / build-and-test`, `dependency-review`, `gate / build / macos`, `gate / build / windows`, `release-preflight`, `sbom`, `security-audit`, `trivy-fs-scan` | ruleset true; classic false | 36 | app/security/release workflows | #451 `github-actions`; #459 `seonghobae`; #458 `seonghobae` | | `ContextualWisdomLab/clearfolio` | GitHub Flow | `main` | off | Strix; OpenCode; scheduler | `PR` | none | ruleset false | 57 | none | #30 `seonghobae`; #29 `seonghobae`; #13 `seonghobae` | | `ContextualWisdomLab/codec-carver` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 42 | none | #103 `github-actions`; #98 `seonghobae`; #97 `opencode-agent` | | `ContextualWisdomLab/contextual-orchestrator` | GitHub Flow | `main` | off | Strix; OpenCode; scheduler | org central required workflows only | none | none | 2 | scorecard/security workflows | none | | `ContextualWisdomLab/fast-mlsirm` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 25 | CI | #46 `github-actions`; #45 `github-actions`; #44 `github-actions` | | `ContextualWisdomLab/hyosung-itx-slogan-brief` | GitHub Flow | `main` | off | Strix; OpenCode; scheduler | `Do not delete any branches` | none | none | 1 | validation workflow | #4 `seonghobae`; #3 `seonghobae`; #2 `seonghobae` | -| `ContextualWisdomLab/kaefa` | Git Flow | `develop` | on | ruleset inherited; current open PRs still need central required check proof | org central required workflows plus repo rulesets `Auto Review` and `PR` | R-CMD-check and dependency review workflows observed on PR #60 | repo ruleset present | 5 | R-CMD-check; dependency review | #51 `seonghobae`; #44 `seonghobae`; #42 `seonghobae` | +| `ContextualWisdomLab/kaefa` | Git Flow | `develop` | on | ruleset inherited; current open PRs still need central required check proof | org central required workflows plus repo rulesets `Auto Review` and `PR` | R-CMD-check and dependency review workflows observed on PR #60 | repo ruleset present | 6 | R-CMD-check; dependency review | #51 `seonghobae`; #44 `seonghobae`; #42 `seonghobae` | | `ContextualWisdomLab/naruon` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch`, `PR`; classic branch protection | central ruleset; repo-local application/security checks remain | ruleset true | 7 | application/governance/security workflows | #760 `seonghobae`; #758 `seonghobae`; #757 `seonghobae` | | `ContextualWisdomLab/newsdom-api` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch`, `mirror-classic-protection-main-develop` | `codeql (python, actions)`, `dependency-review`, `pytest`, `quality-gate`, `scorecard` | ruleset true | 3 | quality/security/release workflows | #203 `seonghobae`; #205 `seonghobae`; #206 `seonghobae` | | `ContextualWisdomLab/pg-erd-cloud` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 81 | app/security workflows | #247 `github-actions`; #246 `github-actions`; #239 `github-actions` | -| `ContextualWisdomLab/semantic-data-portal` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 2 | none | #3 `seonghobae`; #1 `seonghobae` | +| `ContextualWisdomLab/semantic-data-portal` | GitHub Flow | `main` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 3 | none | #3 `seonghobae`; #1 `seonghobae` | | `ContextualWisdomLab/scopeweave` | Git Flow | `develop` | on | Strix; OpenCode; scheduler | `Lock default branch` | none | ruleset true | 2 | security/pages workflows | #124 `seonghobae`; #118 `seonghobae`; #116 `seonghobae` | -| `ContextualWisdomLab/waf-ids-ai-soc` | GitHub Flow | `main` | off | Strix; OpenCode; scheduler present on PR #6 | org central required workflows only | `rust` local CI plus central required checks | none | 1 | CI; scorecard | #5 `seonghobae`; #4 `seonghobae`; #3 `seonghobae` | +| `ContextualWisdomLab/waf-ids-ai-soc` | GitHub Flow | `main` | off | Strix; OpenCode; scheduler proven on PR #6; PR #8 queued on current head | org central required workflows only | `rust` local CI plus central required checks | none | 1 | CI; scorecard | #7 `seonghobae`; #6 `github-actions`; #5 `seonghobae` | | `ContextualWisdomLab/xtrmLLMBatchPython` | Git Flow | `develop` | off | missing | `PR` | none | ruleset false | 1 | A2Z compliance; CodeQL; dependency/security checks; no OpenCode/Strix/scheduler | #49 `seonghobae`; #47 `seonghobae`; #45 `seonghobae` | ## Current Gaps By Repo @@ -187,15 +187,15 @@ onboarding exception before relying on autonomous PR queue draining. | `bandscope` | Required checks are repo-specific and broad; keep GitHub native auto-merge as the check interpreter. PR #459 merged the REST mergeability guard downstream. Scheduler run `28192186833` proved two current contracts: PR #450 emitted concrete conflict repair guidance instead of retrying `update-branch`, and PR #451/#446 requested `update-branch` with the workflow `GITHUB_TOKEN`, producing new heads authored by `github-actions[bot]`. That run also exposed a post-update `ACTION_REQUIRED` state with no jobs, so the scheduler must report workflow approval/policy wait rather than a source failure when it recurs. Follow-up PR #460 was closed because it copied the central scheduler into `bandscope` and would preserve exactly the repo-local drift this rollout should remove. | | `clearfolio` | PR #13 is merged at `4bc17c6` after same-head manual Strix run `28051319530`, same-head manual OpenCode run `28051665082`, unresolved review threads `0`, and guarded merge against head `5fe1791`. Auto-merge remains off, so direct guarded merge is the repo path. | | `codec-carver` | PR #98 replaced the legacy scheduler with the central GitHub Actions path. Keep #94 as the historical negative sample because it used `opencode-agent` as a merge actor. | -| `contextual-orchestrator` | Now inherits central required Strix, OpenCode, and scheduler workflows. The 2026-07-02 13:21 KST refresh found two open PRs, so those PRs are the next runtime fixtures for central evidence rather than another repo-local workflow copy. | +| `contextual-orchestrator` | Now inherits central required Strix, OpenCode, and scheduler workflows. The 2026-07-02 18:15 KST refresh found two open PRs, so those PRs are the next runtime fixtures for central evidence rather than another repo-local workflow copy. | | `aFIPC` | The old target-coverage gap is closed. PR #78 merged after central `coverage-evidence`, `opencode-review`, `strix`, and `scan-pr-queue` all passed on head `b1ddafced86302f461e95259699f1efde5ec87c9`; the current queue is now a normal per-PR review/mergeability problem, not a ruleset target gap. | | `hyosung-itx-slogan-brief` | Now inherits central required Strix, OpenCode, and scheduler workflows. Its default branch keeps only a repository validation workflow, auto-merge is off, and the only repository ruleset prevents branch deletion. It should either stay a lightweight GitHub Flow repo with explicit manual merge expectations or adopt the standard default-branch lock contract before autonomous merge is expected. | -| `kaefa` | Newly discovered public non-fork target at the 2026-07-02 13:21 KST refresh. It inherits org ruleset `18156473`, but current PR #60 status rollup showed only repo-local R-CMD-check, dependency-review, and CodeQL signals, with no central Strix/OpenCode/scheduler check runs. Treat it as an inherited-ruleset runtime proof gap until a new PR event or manual dispatch proves central checks on the current head. | +| `kaefa` | Newly discovered public non-fork target at the 2026-07-02 18:15 KST refresh. It inherits org ruleset `18156473`, but current PR #60 status rollup showed only repo-local R-CMD-check, dependency-review, and CodeQL signals, with no central Strix/OpenCode/scheduler check runs. Treat it as an inherited-ruleset runtime proof gap until a new PR event or manual dispatch proves central checks on the current head. | | `naruon` | Canonical strict check source. PR #756 synced the central scheduler into `naruon`; its first head proved that widening `GITHUB_TOKEN` permissions to solve DX creates Scorecard and governance failures, so the merged rollout keeps minimal token permissions and defaults risky review-dispatch/auto-merge paths off. PR #721 remains the useful historical fixture for `BEHIND` handling: central dry-run selected `update_branch`, while the older repo-local workflow treated it as `wait`. Current PR #760 is clean, approved, and green on head `57a2f8e4`, so it is a merge-readiness sample; current dry-run with auto-merge disabled reports `wait`, as expected for the low-privilege scheduler profile. | | `newsdom-api` | Ruleset-required checks must stay GitHub-interpreted. PR #207 has merged, so it is no longer an update-branch proof candidate. The remaining open PRs #187, #203, #205, and #206 currently block because the current head has no OpenCode approval. | | `pg-erd-cloud` | Good GitHub Actions merge samples; keep autofix workflows repo-local. | | `scopeweave` | PR #127 is the current representative trace. Dry-run `28147098767` selected `auto_merge`, but live run `28147157319` failed with `GraphQL: Resource not accessible by integration (mergePullRequest)` because merge through GitHub Actions requires a contents-write mutation surface. Commit `6601953` proved the tempting fix, but Scorecard immediately opened a Token-Permissions review thread against job-level `contents: write`; follow-up commit `c5c5530` restores `contents: read` and keeps update-branch on the lower-privilege PR-write path. Current head `c5c5530` is clean, approved, and green; it remains unmerged because Actions-based merge is an explicit repo policy exception, not the default rollout. | -| `appguardrail` | Public organization repo discovered in the 2026-06-26 refresh. It follows Git Flow on `develop`, inherits the central required workflow ruleset, has no default-branch local central-workflow copies, and has eight open PRs in the 2026-07-02 refresh, so it is now an active proof candidate rather than a zero-PR control repo. | +| `appguardrail` | Public organization repo discovered in the 2026-06-26 refresh. It follows Git Flow on `develop`, inherits the central required workflow ruleset, has no default-branch local central-workflow copies, and has nine open PRs in the 2026-07-02 18:15 KST refresh, so it is now an active proof candidate rather than a zero-PR control repo. | | `xtrmLLMBatchPython` | Private repository discovered during PR queue draining on 2026-06-29. PR #50 is blocked by the repository-local one-approval rule because the only visible direct collaborator is also the PR author, and no current-head central OpenCode or Strix check exists. Add the private repository to the central required-workflow ruleset before continuing autonomous merges; do not force-merge and do not reduce the approval count to zero as a workaround. | ## Representative Evidence @@ -207,7 +207,7 @@ onboarding exception before relying on autonomous PR queue draining. | `.github` | PR #28 head `811446d` reached current-head approval after manual Strix run `28007326148` published a successful `strix` status and manual OpenCode run `28008174977` approved the same head; it was merged by `seonghobae` with merge commit `a025be1`. PR #49 then merged the explicit ban on generic failed-check deflections, and PR #58 removes remaining fallback/pending/check-lookup paths that could turn review-tool states into PR review Findings. | Same-head manual evidence for self-modifying trusted workflow changes, current-head OpenCode approval, unresolved thread check, `--match-head-commit` guarded merge, and non-actionable Findings rejection. | Treating stale PR-target failure logs as merge blockers after newer same-head evidence exists, or posting an evidence-mapping failure as a user-facing Finding. | | `pg-erd-cloud` | Recent PRs #236, #237, #239 were merged by `app/github-actions`. | GitHub Actions as mechanical merge actor with head guard. | Human-only queue draining. | | `codec-carver` | Recent PR #94 was merged by `app/opencode-agent`, while later PR #103 was merged by `github-actions`. | Native auto-merge path for current-head approved PRs. | OpenCode app as merge actor. | -| `appguardrail` | Current public organization repo with default `develop`, inherited central required workflows, no default-branch local central copies, and eight open PRs at the 2026-07-02 refresh. | Use as an active policy-vs-source review fixture after central changes stabilize. | Treating inherited workflow presence alone as proof that the PR queue is drainable. | +| `appguardrail` | Current public organization repo with default `develop`, inherited central required workflows, no default-branch local central copies, and nine open PRs at the 2026-07-02 18:15 KST refresh. | Use as an active policy-vs-source review fixture after central changes stabilize. | Treating inherited workflow presence alone as proof that the PR queue is drainable. | ## DX/UX Transfer Decisions @@ -231,7 +231,7 @@ both separately; a change can improve one while harming the other. | `hyosung-itx-slogan-brief` | The repo now inherits the central required workflows and has local review/merge workflow names without heavier required checks, which makes it a lightweight GitHub Flow fixture. | It lacks the default-branch lock/stale-dismissal policy used by most organization repos. | Leave autonomous merge disabled unless that policy gap is intentional; otherwise add the standard default-branch lock before relying on autonomous merge. | | `contextual-orchestrator` | It now inherits central required workflows without carrying local governance workflow copies, which is the desired no-copy posture. | With two open PRs now present, inherited checks alone still do not prove useful runtime behavior until those current heads are inspected. | Use the current open PRs as proof fixtures; add a default-branch lock only if autonomous merge is desired. | | `aFIPC` | It has real PR pressure and a domain-specific requirement: fixed parameter item calibration changes must reproduce true parameters before estimates can be trusted. PR #78 now proves central required workflow coverage on `master`. | Several current PRs are still `DIRTY`, `BEHIND`, `BLOCKED`, or `CHANGES_REQUESTED`, so inherited workflow presence is not enough to drain the queue. | Keep central Strix/OpenCode/scheduler as the gate, then require current-head OpenCode approval, Strix, scheduler, and true-parameter FIPC tests before each merge. | -| `waf-ids-ai-soc` | Newly discovered public non-fork target with Rust CI and scorecard workflows. PR #6 already shows central `coverage-evidence`, `strix`, and `scan-pr-queue` check runs on head `43b62b5f347d1532c81b5ae38d8e41b4494fd486`, with OpenCode still in progress at the 2026-07-02 13:21 KST refresh. | It has no classic branch protection and auto-merge is off, so inherited required workflow presence is not enough to prove autonomous merge policy. | Keep as a GitHub Flow runtime proof fixture: require central OpenCode conclusion, Rust CI, Strix, scheduler, unresolved-thread check, and explicit merge actor evidence before treating it as migrated. | +| `waf-ids-ai-soc` | Newly discovered public non-fork target with Rust CI and scorecard workflows. PR #6 merged at `e1c0a85fd4a8e6dd67039be43eb7f659fec22abd` after central required workflow proof on head `43b62b5f347d1532c81b5ae38d8e41b4494fd486`; PR #8 is the current open proof candidate on head `48d8b56a0f995829fc95de4fed129d1c33aaadff` with central and local Rust checks queued at the 2026-07-02 18:15 KST refresh. | It has no classic branch protection and auto-merge is off, so inherited required workflow presence is not enough to prove autonomous merge policy. | Keep as a GitHub Flow runtime proof fixture: require central OpenCode conclusion, Rust CI, Strix, scheduler, unresolved-thread check, and explicit merge actor evidence before treating it as migrated. | ## Current Scheduler Contract @@ -354,7 +354,7 @@ PR #381: wait: OpenCode review is already in progress - `update-branch` `422/403` now has a safe fixture: unit tests simulate both permission-denied and stale `expected_head_sha` failures, assert they become `action_error`, and assert later PRs are still inspected. A real live `422/403` case is still useful as operational evidence, but it is no longer missing from the decision contract test surface. - `bandscope` PR #378 exposed a self-referential failed-check loop after manual retry run `28155083916`: the retry run succeeded and approved step execution, but the check rollup still contained the cancelled older `OpenCode Review/opencode-review` run `28152862698`, so OpenCode posted current-head `CHANGES_REQUESTED` review `4569063977` with the banned generic `No deterministic missing-string markers...` text. The collector now excludes OpenCode's own check by check name and by both actual (`OpenCode Review`) and legacy (`OpenCode PR Review`) workflow names before failed-check fallback evidence is built. - `aFIPC` PR #78 is now the closed target-coverage fixture: it merged only after central `coverage-evidence`, `opencode-review`, `strix`, and `scan-pr-queue` passed on head `b1ddafced86302f461e95259699f1efde5ec87c9`. The remaining aFIPC queue should be handled as per-PR review, conflict, stale-branch, and domain-test work, not as a missing-ruleset blocker. -- The 2026-07-02 13:21 KST live inventory added `kaefa` and `waf-ids-ai-soc` to the public non-fork target set. Both inherit org ruleset `18156473`; `waf-ids-ai-soc` PR #6 already exposes central required workflow runs, while `kaefa` PR #60 did not expose central OpenCode, Strix, or scheduler check runs in its status rollup and remains a runtime proof gap. +- The 2026-07-02 18:15 KST live inventory added `kaefa` and `waf-ids-ai-soc` to the public non-fork target set. Both inherit org ruleset `18156473`; `waf-ids-ai-soc` PR #6 merged after exposing central required workflow runs, PR #8 is the current queued runtime proof fixture, and `kaefa` PR #60 did not expose central OpenCode, Strix, or scheduler check runs in its status rollup and remains a runtime proof gap. - Public repo drift is real, not hypothetical: only `.github` matched the central scheduler/workflow byte-for-byte in the 2026-06-26 scan. Some drift is policy-specific and should not be overwritten blindly, but `bandscope` had behaviorally unsafe drift and now has PR #459 merged downstream. - The previous drift response still over-indexed on copying. `bandscope` PR #460 proved the correction: even when the copied scheduler produced the right diff --git a/docs/org-required-workflow-rollout.md b/docs/org-required-workflow-rollout.md index 1461608a7..1f1a48df9 100644 --- a/docs/org-required-workflow-rollout.md +++ b/docs/org-required-workflow-rollout.md @@ -1,6 +1,6 @@ # ContextualWisdomLab central required workflow rollout -Updated: 2026-07-02 13:21 KST +Updated: 2026-07-02 18:15 KST ## Decision @@ -17,10 +17,10 @@ Use an organization repository ruleset instead of copying workflow files into ea - `.github/workflows/opencode-review.yml` - `.github/workflows/pr-review-merge-scheduler.yml` - Required workflow ref: `refs/heads/main` -- Last verified workflow implementation base commit: `dbd33b3a0384de0129aa082a210383188d012415` (`#249`) +- Last verified workflow implementation base commit: `ef9950e6b55bf943c0295e1df3e34c94210d21cc` (`#283`) - Required workflow trigger support: `pull_request_target`, `push`, `workflow_run` -`.github` PRs through `#249` are now in `main`. The required-workflow +`.github` PRs through `#283` are now in `main`. The required-workflow ruleset points at `.github@main`; if live organization ruleset inspection reports another ref, treat that as operations drift and restore ruleset `18156473` to the current `main` head. @@ -66,7 +66,7 @@ Do not centralize the scheduler by running a `.github` scheduled job against oth ## Scope The active ruleset no longer maintains a repository-name allowlist. Live -ruleset inspection on 2026-07-02 13:21 KST reports +ruleset inspection on 2026-07-02 18:15 KST reports `repository_name.include=["~ALL"]`, so all current and future organization repositories inherit the three central required workflows on their default branch unless a later ruleset exclusion is added. The table below is the public @@ -74,11 +74,11 @@ non-fork inventory snapshot and rollout ledger, not the ruleset target list. | Repository | Visibility | Default branch | Flow | Open PRs | Local central-workflow copies on default branch | Rollout status | | --- | --- | --- | --- | ---: | --- | --- | -| `ContextualWisdomLab/.github` | public | `main` | GitHub Flow | 32 | central source; keep | single source of truth; central PRs through `#267` merged | -| `ContextualWisdomLab/aFIPC` | public | `master` | GitHub Flow | 21 | none | central checks proven on PR `#78`; active queue still needs per-PR review | +| `ContextualWisdomLab/.github` | public | `main` | GitHub Flow | 27 | central source; keep | single source of truth; central PRs through `#283` merged; PR `#286` current head queued after review-thread fixes | +| `ContextualWisdomLab/aFIPC` | public | `master` | GitHub Flow | 22 | none | central checks proven on PR `#78`; active queue still needs per-PR review | | `ContextualWisdomLab/pg-erd-cloud` | public | `main` | GitHub Flow | 81 | none | repo-local autofix worker removed by PR `#393`; default branch now keeps only repository-owned application and security workflows | | `ContextualWisdomLab/fast-mlsirm` | public | `main` | GitHub Flow | 25 | none | migrated; re-verify inherited checks on current open PRs | -| `ContextualWisdomLab/bandscope` | public | `develop` | Git Flow | 61 | none | no local central copies observed; verify inherited checks on active PRs | +| `ContextualWisdomLab/bandscope` | public | `develop` | Git Flow | 36 | none | no local central copies observed; verify inherited checks on active PRs | | `ContextualWisdomLab/contextual-orchestrator` | public | `main` | GitHub Flow | 2 | none | default branch has no local central copies; current open PRs are runtime proof fixtures | | `ContextualWisdomLab/naruon` | public | `develop` | Git Flow | 7 | none | default branch has no repo-local OpenCode, Strix, or scheduler copies; application/security workflows remain repository-owned | | `ContextualWisdomLab/newsdom-api` | public | `develop` | Git Flow | 3 | none | local workflows already gone; re-verify inherited checks on current open PRs | @@ -87,10 +87,10 @@ non-fork inventory snapshot and rollout ledger, not the ruleset target list. | `ContextualWisdomLab/ContextualWisdomLab.github.io` | public | `main` | GitHub Flow | 19 | none | migrated; re-verify inherited checks on current open PRs | | `ContextualWisdomLab/codec-carver` | public | `main` | GitHub Flow | 42 | none | local workflows already gone; quality uplift still needs 100% test/docstring evidence before closure | | `ContextualWisdomLab/clearfolio` | public | `main` | GitHub Flow | 57 | none | migrated; re-verify inherited checks before final closure | -| `ContextualWisdomLab/semantic-data-portal` | public | `main` | GitHub Flow | 2 | none | PR `#3` merged; default branch has no local central copies | +| `ContextualWisdomLab/semantic-data-portal` | public | `main` | GitHub Flow | 3 | none | PR `#3` merged; default branch has no local central copies | | `ContextualWisdomLab/hyosung-itx-slogan-brief` | public | `main` | GitHub Flow | 1 | none | migrated; re-verify inherited checks on current open PR | -| `ContextualWisdomLab/kaefa` | public | `develop` | Git Flow | 5 | none | newly discovered public non-fork target; ruleset inherited but current PR #60 lacked central check runs in status rollup | -| `ContextualWisdomLab/waf-ids-ai-soc` | public | `main` | GitHub Flow | 1 | none | newly discovered public non-fork target; PR #6 shows central required workflow runs on current head | +| `ContextualWisdomLab/kaefa` | public | `develop` | Git Flow | 6 | none | newly discovered public non-fork target; ruleset inherited but current PR #60 lacked central check runs in status rollup | +| `ContextualWisdomLab/waf-ids-ai-soc` | public | `main` | GitHub Flow | 1 | none | newly discovered public non-fork target; PR #6 merged after central workflow proof; PR #8 is now the open current-head runtime proof fixture | ## Current policy @@ -124,14 +124,15 @@ non-fork inventory snapshot and rollout ledger, not the ruleset target list. - `.github` PR `#247` was closed without merge because its reviewed-merge-update fallback would have approved a current head from previous-parent approval evidence after model exhaustion. That path conflicts with the current fail-closed policy: model timeout, model-pool exhaustion, or missing usable control output must lead to retry, alternate model execution, or a source-backed request for changes, not deterministic approval. - `.github` PR `#249` guarded the central PR Review Fix Scheduler so `CHANGES_REQUESTED` review states dispatch the central autofix worker only when the latest OpenCode review is on the current head, the merge state is `CLEAN` or `HAS_HOOKS`, and the review body does not indicate process-only blockers such as merge conflict, model-pool exhaustion, unresolved human review threads, failed checks, `coverage-evidence`, or failed Strix evidence. It merged at `dbd33b3a0384de0129aa082a210383188d012415` after current-head `coverage-evidence`, `strix`, `opencode-review`, `noema-review`, and `scan-pr-queue` all completed successfully. - `.github` PR `#255` removed the remaining deterministic low-risk approval fallback from the OpenCode approval gate and changed `coverage-evidence` blocker handling to publish a `REQUEST_CHANGES` review event, producing the PR review state `CHANGES_REQUESTED`, instead of leaving only a failed check/log. It merged at `e2beae72b87a8817cd57f9f51bab3947353baa61`; the first current-head OpenCode run reached an `APPROVE` gate result but hit the OpenCode GitHub App installation rate limit while publishing the review, then a rerun published approval and native auto-merge completed. +- `.github` PR `#283` refreshed the central OpenCode model configuration so every reasoning-capable review candidate sets `reasoning=true`, `options.reasoningEffort: high`, and `variants.high.reasoningEffort: high`; non-reasoning fallback candidates remain available without a false effort claim. It merged at `ef9950e6b55bf943c0295e1df3e34c94210d21cc`. - After PR `#255` merged, `ContextualWisdomLab/bandscope` PRs `#493`, `#494`, `#495`, and `#500` were rechecked for branch freshness. Merge simulation against `develop` found real conflicts rather than update-branch candidates: `#493` conflicts in `apps/desktop/src/App.tsx` plus the design-system docs, while `#494`, `#495`, and `#500` conflict in `docs/design-system/README.md`, `docs/design-system/component-contract.md`, and `docs/design-system/figma-to-code-workflow.md`. Each PR received a corrected conflict-resolution comment with the exact file list and merge/rebase repair commands. - `ContextualWisdomLab/aFIPC` PR `#78` is no longer a target-coverage gap. It merged after current-head central `coverage-evidence`, `opencode-review`, `strix`, and `scan-pr-queue` checks all passed on head `b1ddafced86302f461e95259699f1efde5ec87c9`; the OpenCode review approved the same head on 2026-06-30 06:02:55Z. - `ContextualWisdomLab/pg-erd-cloud` PR `#393` removed the repo-local `pr-review-autofix.yml` worker after the central autofix worker merged. The first OpenCode run on head `9d8eed5be47670b1b46f413295d9a6044d7327b2` exhausted the older model pool and requested changes. After `.github` PR `#246` merged, central OpenCode run `28485070313` approved the same head and the PR merged at `1e0d6a3dda5ea9afcd74dcd8380689672e1c8ef1` on 2026-07-01 00:33:50Z. Live default-branch content lookup returned 404 for `.github/workflows/pr-review-autofix.yml` after merge. -- Live non-fork inventory on 2026-07-02 13:21 KST found 17 public non-fork repositories, inherited ruleset `18156473` on `kaefa` and `waf-ids-ai-soc`, and no default-branch copies of `opencode-review.yml`, `strix.yml`, or `pr-review-merge-scheduler.yml` outside `.github`. -- `ContextualWisdomLab/waf-ids-ai-soc` PR `#6` current head `43b62b5f347d1532c81b5ae38d8e41b4494fd486` showed central `coverage-evidence`, `strix`, and `scan-pr-queue` check runs plus local Rust CI; `opencode-review` was still in progress at the 2026-07-02 13:21 KST refresh. +- Live non-fork inventory on 2026-07-02 18:15 KST found 17 public non-fork repositories, inherited ruleset `18156473` on `kaefa` and `waf-ids-ai-soc`, and no default-branch copies of `opencode-review.yml`, `strix.yml`, or `pr-review-merge-scheduler.yml` outside `.github`. +- `ContextualWisdomLab/waf-ids-ai-soc` PR `#6` merged at `e1c0a85fd4a8e6dd67039be43eb7f659fec22abd` after central required workflow proof on head `43b62b5f347d1532c81b5ae38d8e41b4494fd486`; PR `#8` current head `48d8b56a0f995829fc95de4fed129d1c33aaadff` is now the open runtime proof fixture with central and local Rust checks queued at the 2026-07-02 18:15 KST refresh. - `ContextualWisdomLab/kaefa` inherits ruleset `18156473`, but PR `#60` current head `13c9089855fcdd34391173560ccf6935bac1eebe` showed only repo-local R-CMD-check, dependency-review, and CodeQL signals in status rollup. Treat this as a runtime proof gap until a new PR event or manual dispatch proves central OpenCode, Strix, and scheduler checks on a kaefa current head. - `.github` scheduler default merge mode is now `direct_or_auto`: approved same-repository `CLEAN` PRs request immediate guarded merge, approved non-clean same-repository PRs can queue native auto-merge, and fork or external-head PRs are left for maintainer merge. - OpenCode approval runs the trusted central merge scheduler script directly with `pr_number` and `max_prs=1`, so the just-reviewed PR is inspected immediately even when organization required workflows are not repo-local `workflow_dispatch` targets. diff --git a/tests/test_pr_governance_audit_contract.py b/tests/test_pr_governance_audit_contract.py index eeecca8bf..fe4cbdec7 100644 --- a/tests/test_pr_governance_audit_contract.py +++ b/tests/test_pr_governance_audit_contract.py @@ -45,5 +45,7 @@ def test_new_public_nonfork_repos_are_classified_in_rollout_inventory(): assert "current PR #60 lacked central check runs" in rollout assert "runtime proof gap" in audit - assert "PR #6 shows central required workflow runs" in rollout + assert "PR #6 merged after central workflow proof" in rollout + assert "PR #8 is now the open current-head runtime proof fixture" in rollout assert "43b62b5f347d1532c81b5ae38d8e41b4494fd486" in audit + assert "48d8b56a0f995829fc95de4fed129d1c33aaadff" in audit