test(automation): verify hourly NVIDIA NIM repair boundary - #780
Closed
seonghobae wants to merge 58 commits into
Closed
test(automation): verify hourly NVIDIA NIM repair boundary#780seonghobae wants to merge 58 commits into
seonghobae wants to merge 58 commits into
Conversation
* test(strix): align setup-python pin contract * fix(strix): isolate backend support-code scopes * fix(strix): update vulnerable Python dependencies * fix(strix): scan changed Rust security boundaries
Install and pin LLVM 19 coverage tools for Debian-packaged Rust, refresh the remediated Strix lock, and document the compatibility and fail-closed coverage contract.
Add failing contracts for the one-hour scheduler cadence, immutable called-workflow source, NVIDIA_NIM_API_KEY-only OpenCode repair transport, write-credential stripping, fail-closed secret handling, and unchanged independent reviewer workflow.
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Add a permanent read-only exact-head workflow that runs the hourly cadence, immutable scheduler source, NVIDIA_NIM_API_KEY, credential-stripping, fail-closed, and independent-review separation contracts. The current baseline is expected to fail before implementation.
Set the central scheduler to an hourly one-dispatch loop with a one-hour retry floor, bind reusable and dispatch worker source to immutable workflow SHAs, move write-capable OpenCode repair to NVIDIA_NIM_API_KEY only, strip GitHub/OIDC credentials from model subprocesses, and retain the independent reviewer workflow unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Temporary verification completed — do not merge
This Draft PR existed only to obtain pull-request-triggered exact-head red/green evidence for stacked product PR #779.
Contracts-only head
71d1fc599538715a71c5eb2423e97cc7d566f01ffailed permanent run30992189499with 13 failed, 3 passed, proving the inherited two-hour/24-hour mutable-source GitHub-Models boundary.Exact implementation head
1d70f782f81612a69dfacff9a39aa192c16c6b2fpassed every direct current-head workflow:30992533806and30992534144;30992533983;30992533939;30992533890;30992533873;30992533969;30992534723;30992534003;30992533966;30992533904.The temporary PR is closed without merge. Product integration remains #759 → #779, with exact-head retargeting and independent approval after the prerequisite reaches
main. The hourly scheduler is not active until that integration merges to the protected default branch.