Skip to content

test(automation): verify hourly NVIDIA NIM repair boundary - #780

Closed
seonghobae wants to merge 58 commits into
mainfrom
fix/hourly-nvidia-nim-review-repair
Closed

test(automation): verify hourly NVIDIA NIM repair boundary#780
seonghobae wants to merge 58 commits into
mainfrom
fix/hourly-nvidia-nim-review-repair

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Temporary verification completed — do not merge

This Draft PR existed only to obtain pull-request-triggered exact-head red/green evidence for stacked product PR #779.

Contracts-only head 71d1fc599538715a71c5eb2423e97cc7d566f01f failed permanent run 30992189499 with 13 failed, 3 passed, proving the inherited two-hour/24-hour mutable-source GitHub-Models boundary.

Exact implementation head 1d70f782f81612a69dfacff9a39aa192c16c6b2f passed every direct current-head workflow:

  • Hourly NVIDIA NIM Review Repair 30992533806 and 30992534144;
  • OpenCode Coverage Diagnostics CI 30992533983;
  • Python Security 30992533939;
  • Security Scan 30992533890;
  • CodeQL 30992533873;
  • SAST Semgrep 30992533969;
  • OSV 30992534723;
  • Secret Scan 30992534003;
  • SBOM 30992533966;
  • Scorecard 30992533904.

The temporary PR is closed without merge. Product integration remains #759#779, with exact-head retargeting and independent approval after the prerequisite reaches main. The hourly scheduler is not active until that integration merges to the protected default branch.

seonghobae and others added 30 commits August 5, 2026 06:41
* test(strix): align setup-python pin contract

* fix(strix): isolate backend support-code scopes

* fix(strix): update vulnerable Python dependencies

* fix(strix): scan changed Rust security boundaries
Install and pin LLVM 19 coverage tools for Debian-packaged Rust, refresh the remediated Strix lock, and document the compatibility and fail-closed coverage contract.
seonghobae and others added 26 commits August 5, 2026 14:11
Add failing contracts for the one-hour scheduler cadence, immutable called-workflow source, NVIDIA_NIM_API_KEY-only OpenCode repair transport, write-credential stripping, fail-closed secret handling, and unchanged independent reviewer workflow.
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4b97b048-4f33-48c3-a4bd-e4dee58b9262

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Add a permanent read-only exact-head workflow that runs the hourly cadence, immutable scheduler source, NVIDIA_NIM_API_KEY, credential-stripping, fail-closed, and independent-review separation contracts. The current baseline is expected to fail before implementation.
Set the central scheduler to an hourly one-dispatch loop with a one-hour retry floor, bind reusable and dispatch worker source to immutable workflow SHAs, move write-capable OpenCode repair to NVIDIA_NIM_API_KEY only, strip GitHub/OIDC credentials from model subprocesses, and retain the independent reviewer workflow unchanged.
@seonghobae seonghobae closed this Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant