Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
174 commits
Select commit Hold shift + click to select a range
dcbd777
chore(ci): linearize validated control-plane integration
seonghobae Aug 5, 2026
e278811
ci(review): export read-only PR759 merge workspaces
seonghobae Aug 5, 2026
cb148ee
test(coverage): reproduce missing libclang in PR 759
seonghobae Aug 5, 2026
c6fbc03
ci(review): add exact merge base to PR759 export
seonghobae Aug 5, 2026
32a3e7a
chore(ci): remove write-capable one-shot repair workflow
seonghobae Aug 5, 2026
1357f78
chore(ci): remove transient merge-workspace export workflow
seonghobae Aug 5, 2026
2c9c9e2
ci(review): export PR759 immutable merge base
seonghobae Aug 5, 2026
90045ae
chore(ci): remove temporary PR 759 workspace export
seonghobae Aug 5, 2026
cfa512e
ci: trigger exact-head PR 759 libclang repair
seonghobae Aug 5, 2026
1a54886
ci: execute verified PR 759 libclang repair
seonghobae Aug 5, 2026
f5fee2a
ci: run exact-head libclang repair on branch push
seonghobae Aug 5, 2026
bdd2b30
ci: arm ready-for-review PR 759 libclang repair
seonghobae Aug 5, 2026
7dd61d6
chore: remove superseded PR 759 push repair
seonghobae Aug 5, 2026
845a895
ci(review): reconcile PR759 with protected main
seonghobae Aug 5, 2026
17c7947
chore(ci): remove write-capable PR 759 reconciliation workflow
seonghobae Aug 5, 2026
8f52741
chore(ci): remove PR-triggered write-capable repair workflow
seonghobae Aug 5, 2026
1fe1ee6
chore(ci): remove ready-event write-capable repair workflow
seonghobae Aug 5, 2026
a84e68e
ci: rearm PR 759 merge reconciliation
seonghobae Aug 5, 2026
27f7e3b
chore: remove superseded PR 759 reconciliation rearm
seonghobae Aug 5, 2026
8dfe71c
ci(review): export current PR759 three-way state
seonghobae Aug 5, 2026
23c4071
ci: reconcile PR 759 with protected main
seonghobae Aug 5, 2026
780cca4
ci: rewrite PR 759 merge trigger
seonghobae Aug 5, 2026
22d1482
chore: remove superseded PR 759 rewrite trigger
seonghobae Aug 5, 2026
9ec0402
chore: remove superseded PR 759 workspace export
seonghobae Aug 5, 2026
be895b1
chore(workflows): remove transient PR 759 branch writer
seonghobae Aug 5, 2026
ab652a5
ci: run exact PR 759 main reconciliation
seonghobae Aug 5, 2026
7e7ed4c
chore(ci): remove write-capable PR 759 merge workflow
seonghobae Aug 5, 2026
deb4bf6
ci: stage deterministic PR 759 reconciliation
seonghobae Aug 5, 2026
96aef94
docs: reconcile central changelog with protected main
seonghobae Aug 5, 2026
cb211f6
ci: execute deterministic PR 759 reconciliation
seonghobae Aug 5, 2026
610a606
ci: verify PR 759 resolved tree without repository writes
seonghobae Aug 5, 2026
0c3e44f
chore(workflows): remove write-capable PR repair workflow
seonghobae Aug 5, 2026
e2bb310
chore(workflows): remove branch-local PR evidence workflow
seonghobae Aug 5, 2026
67fff82
ci(coverage): make PR759 diagnostics permanently read-only
seonghobae Aug 5, 2026
8bdf6d8
chore(ci): remove temporary PR reconciliation helper
seonghobae Aug 5, 2026
87ca8d7
ci: generate verified coverage reconciliation artifact
seonghobae Aug 5, 2026
aa54722
chore(ci): remove branch-local coverage resolution workflow
seonghobae Aug 5, 2026
13356bf
ci: fix coverage reconciliation evidence contract
seonghobae Aug 5, 2026
f8fbf14
chore(ci): remove reintroduced branch-local reconciliation workflow
seonghobae Aug 5, 2026
97f4f58
test(coverage): reproduce missing libclang toolchain
seonghobae Aug 5, 2026
774340c
chore(ci): remove write-capable PR 759 finalizer
seonghobae Aug 5, 2026
db75f24
test(coverage): require version-aligned libclang
seonghobae Aug 5, 2026
17aadcc
ci: execute exact-head PR 759 libclang repair
seonghobae Aug 5, 2026
5a97946
merge(main): reconcile coverage diagnostics with trusted uv baseline
seonghobae Aug 5, 2026
ccad080
ci: finalize PR 759 libclang coverage prerequisite
seonghobae Aug 5, 2026
087b35b
ci: execute exact-head PR 759 libclang finalization
seonghobae Aug 5, 2026
ec42e67
chore: remove superseded libclang one-shot automation
seonghobae Aug 5, 2026
760b948
ci(review): stage deterministic PR759 libclang repair
seonghobae Aug 5, 2026
9e382ed
ci(review): run deterministic PR759 libclang repair
seonghobae Aug 5, 2026
841357a
ci: execute reviewed PR759 libclang repair
seonghobae Aug 5, 2026
ddae9f9
ci(review): stage PR759 final patch chunk 00
seonghobae Aug 5, 2026
01883a4
ci(review): fetch reviewed permanent diagnostics before repair
seonghobae Aug 5, 2026
9fba1db
ci(review): stage PR759 final patch chunk 01
seonghobae Aug 5, 2026
f05de13
ci(review): stage PR759 final patch chunk 02
seonghobae Aug 5, 2026
aa808d3
ci(review): use full history for deterministic PR759 repair
seonghobae Aug 5, 2026
c89adf6
ci(review): stage PR759 final patch chunk 03
seonghobae Aug 5, 2026
bf7b9fa
ci(review): embed reviewed permanent diagnostics source
seonghobae Aug 5, 2026
cfd8ce3
ci(review): finalize deterministic PR759 libclang repair
seonghobae Aug 5, 2026
01a850a
ci(review): stage PR759 final patch chunk 04
seonghobae Aug 5, 2026
f3029c4
ci(review): stage runtime-only PR759 libclang repair
seonghobae Aug 5, 2026
4c92481
ci(review): finalize runtime-only PR759 libclang repair
seonghobae Aug 5, 2026
30725d6
ci(review): publish verified PR759 exact merge head
seonghobae Aug 5, 2026
0d8639e
ci(pr759): retrigger fail-closed exact-head reconciliation
seonghobae Aug 5, 2026
1178d85
test(opencode): require permanent libclang and Python 3.10 locks
seonghobae Aug 5, 2026
57a4fc5
build(opencode): lock Python 3.10 TOML backport
seonghobae Aug 5, 2026
4c558a0
fix(opencode): make Python 3.10 diagnostics reproducible
seonghobae Aug 5, 2026
171abbf
test(opencode): require permanent toolchains and no branch writers
seonghobae Aug 5, 2026
48ca81d
test(opencode): run permanent LLVM contract in diagnostics
seonghobae Aug 5, 2026
f8c03d3
chore(opencode): remove superseded libclang contract
seonghobae Aug 5, 2026
4f9ae5f
chore(opencode): remove one-shot merge branch writer
seonghobae Aug 5, 2026
df05f3a
chore(opencode): remove one-shot libclang branch writer
seonghobae Aug 5, 2026
cd2fae4
chore(opencode): remove one-shot apply branch writer
seonghobae Aug 5, 2026
4501191
chore(opencode): remove one-shot libclang apply helper
seonghobae Aug 5, 2026
58f878c
chore(opencode): remove one-shot libclang runtime helper
seonghobae Aug 5, 2026
070815b
chore(opencode): remove transient encoded patch part 00
seonghobae Aug 5, 2026
307aa8b
chore(opencode): remove transient encoded patch part 01
seonghobae Aug 5, 2026
dc55df6
chore(opencode): remove transient encoded patch part 02
seonghobae Aug 5, 2026
40715bd
chore(opencode): remove transient encoded patch part 03
seonghobae Aug 5, 2026
8019f07
chore(opencode): remove transient encoded patch part 04
seonghobae Aug 5, 2026
505e91e
fix(opencode): keep Python 3.10 lock URL-free
seonghobae Aug 5, 2026
a3150c1
test(ci): isolate ambient Git configuration
seonghobae Aug 5, 2026
8593bf8
fix(ci): clear captured trusted uv caches
seonghobae Aug 5, 2026
5199c2f
fix(ci): preserve merged Git and NVIDIA fallback boundaries
seonghobae Aug 5, 2026
709ea37
ci(pr759): repair protected-main regressions
seonghobae Aug 5, 2026
33933ad
chore(ci): remove prohibited repair branch writer
seonghobae Aug 5, 2026
c96f499
test(ci): forbid transient branch writers
seonghobae Aug 5, 2026
4ba2183
ci(opencode): focus diagnostics on permanent contracts
seonghobae Aug 5, 2026
70d235a
test(opencode): remove deferred LLVM scope
seonghobae Aug 5, 2026
8523b77
docs(opencode): defer LLVM toolchain record
seonghobae Aug 5, 2026
c727e2a
docs(changelog): narrow permanent control-plane repairs
seonghobae Aug 5, 2026
78a7948
ci(pr759): repair LLVM coverage toolchain regression
seonghobae Aug 5, 2026
2f7b9d2
chore(ci): remove prohibited LLVM repair branch writer
seonghobae Aug 5, 2026
edd2185
test(strix): reject bracket glob metacharacters
seonghobae Aug 5, 2026
53d221f
fix(strix): reject bracket glob metacharacters
seonghobae Aug 5, 2026
a3547f4
test(strix): remove deferred mixed scanner scope
seonghobae Aug 5, 2026
d7aa999
test(strix): require permanent source-boundary diagnostics
seonghobae Aug 5, 2026
88e1b2b
ci(strix): bind source boundary to permanent diagnostics
seonghobae Aug 5, 2026
95f8f8b
test(strix): distinguish execution and compilation evidence
seonghobae Aug 5, 2026
c8bbf69
test(coverage): require compatible LLVM tools before Rust coverage
seonghobae Aug 6, 2026
3994d31
fix(coverage): restore compatible LLVM 19 tooling on current main
seonghobae Aug 6, 2026
748bc5d
test(coverage): require Git isolation in low-privilege wrappers
seonghobae Aug 6, 2026
ee471f5
ci(coverage): repair PR 794 Git isolation
seonghobae Aug 6, 2026
c8462fd
ci(coverage): trigger PR 794 Git-isolation repair
seonghobae Aug 6, 2026
8c6e1c3
chore(ci): remove inactive PR 794 repair workflow
seonghobae Aug 6, 2026
84a2d94
ci: stage exact-head PR 794 Git isolation repair
seonghobae Aug 6, 2026
214319c
ci: trigger exact-head PR 794 Git isolation repair
seonghobae Aug 6, 2026
8323b78
chore(ci): remove inactive PR 794 repair workflow
seonghobae Aug 6, 2026
79e372e
ci: activate bounded PR 794 Git isolation repair
seonghobae Aug 6, 2026
6494136
ci: trigger bounded PR 794 Git isolation repair
seonghobae Aug 6, 2026
278b10d
ci: remove inactive PR 794 repair trigger
seonghobae Aug 6, 2026
bce00fb
ci: repair OpenCode wrapper Git isolation
seonghobae Aug 6, 2026
5db416e
ci: retrigger bounded PR 794 Git isolation repair
seonghobae Aug 6, 2026
86685e3
chore(ci): trigger verified PR 794 repair
seonghobae Aug 6, 2026
aa1bf3c
ci: simplify PR 794 verified repair runner
seonghobae Aug 6, 2026
30265bb
fix(ci): use established workflow-capable repair token
seonghobae Aug 6, 2026
938846a
chore(ci): run PR 794 repair on synchronization
seonghobae Aug 6, 2026
d556f7b
fix(ci): materialize exact-parent repair commit via Git data API
seonghobae Aug 6, 2026
e23fcd9
fix(ci): use scoped job token for Git object creation
seonghobae Aug 6, 2026
752a976
fix(automation): complete exact-head one-shot repair
seonghobae Aug 6, 2026
d009992
fix(automation): publish exact-head repair artifact
seonghobae Aug 6, 2026
a887717
fix(automation): preserve hidden repair source and stable hashes
seonghobae Aug 6, 2026
5cf306e
fix(coverage): isolate low-privilege Git configuration
seonghobae Aug 6, 2026
fca5600
test(coverage): require exact-head toolchain quality workflow
seonghobae Aug 6, 2026
b2073df
ci(coverage): verify OpenCode toolchain at exact PR head
seonghobae Aug 6, 2026
1635420
test(coverage): require full exact-head repository quality gate
seonghobae Aug 6, 2026
7f12a15
ci(coverage): run complete exact-head repository quality gate
seonghobae Aug 6, 2026
6bd29cc
fix(coverage): make hash-locked install contract explicit
seonghobae Aug 6, 2026
7624bae
test(red): require all Authorization values to be redacted
seonghobae Aug 6, 2026
a6303cb
fix(security): redact every Authorization value
seonghobae Aug 6, 2026
25c178c
docs(security): define scheme-neutral Authorization redaction
seonghobae Aug 6, 2026
37f3ac8
docs(changelog): record scheme-neutral Authorization redaction
seonghobae Aug 6, 2026
bf75c32
test(security): preserve Authorization separators in expectations
seonghobae Aug 6, 2026
e151a10
test(security): align materializer redaction expectations
seonghobae Aug 6, 2026
fcd1695
test(coverage): reproduce omitted type-only TypeScript false failure
seonghobae Aug 6, 2026
3d4b82e
fix(coverage): exclude proven type-only TypeScript edits
seonghobae Aug 6, 2026
b39dfe5
test(coverage): cover interface-local documentation branch
seonghobae Aug 6, 2026
cb5df59
docs(coverage): record type-only declaration boundary
seonghobae Aug 6, 2026
2dc2253
docs(changelog): record type-only coverage correction
seonghobae Aug 6, 2026
caf4f31
test(coverage): reject mixed runtime type-only bypasses
seonghobae Aug 6, 2026
e6d6545
test(coverage): fail closed on lexical declaration edges
seonghobae Aug 6, 2026
57628ef
fix(coverage): reject mixed runtime declaration tails
seonghobae Aug 6, 2026
c878715
test(coverage): bound type alias erasure grammar
seonghobae Aug 6, 2026
9487f2d
test(coverage): reject semicolonless alias runtime capture
seonghobae Aug 6, 2026
f2481d5
fix(coverage): parse type aliases without runtime capture
seonghobae Aug 6, 2026
55ef51c
test(ci): bind focused diagnostics to JS gate
seonghobae Aug 6, 2026
002111d
ci(coverage): validate JS gate in focused workflow
seonghobae Aug 6, 2026
fa175f5
test(coverage): close JavaScript gate branches
seonghobae Aug 6, 2026
16b4e4b
test(opencode): require explicit LLVM 19 coverage tools
seonghobae Aug 6, 2026
926fdce
test(opencode): remove unrelated LLVM contract
seonghobae Aug 6, 2026
91dcd85
test(opencode-review): require verified LLVM 19 coverage tools
seonghobae Aug 6, 2026
9eb5043
docs(coverage): record LLVM 19 toolchain boundary
seonghobae Aug 6, 2026
894c659
fix(coverage): integrate image-owned LLVM 19 toolchain
seonghobae Aug 6, 2026
3768d41
test(coverage): preserve exact-head LLVM quality evidence
seonghobae Aug 6, 2026
88ece07
test(coverage): restore explicit LLVM runtime boundary
seonghobae Aug 6, 2026
01a1657
docs(coverage): restore explicit LLVM runtime contract
seonghobae Aug 6, 2026
eb79d1d
docs(changelog): keep LLVM runtime gap explicit
seonghobae Aug 6, 2026
1515ed9
test(coverage): remove duplicate LLVM runtime assertions
seonghobae Aug 6, 2026
38aaf9c
test(coverage): restore explicit LLVM runtime boundary
seonghobae Aug 6, 2026
b5d78ca
test(ci): track every LLVM quality surface
seonghobae Aug 6, 2026
959fa25
fix(ci): execute both LLVM contracts
seonghobae Aug 6, 2026
87dda3b
test(opencode): require explicit isolated LLVM coverage paths
seonghobae Aug 6, 2026
cc29073
chore(opencode): stage LLVM runtime-boundary repair
seonghobae Aug 7, 2026
f1520f7
test(opencode): harden staged LLVM runtime-boundary patch
seonghobae Aug 7, 2026
9c4b377
chore(opencode): remove staged LLVM patch artifact
seonghobae Aug 7, 2026
c3ccb78
chore(opencode): stage LLVM runtime boundary repair
seonghobae Aug 7, 2026
e0dd0e8
chore(opencode): remove staged LLVM patch artifact
seonghobae Aug 7, 2026
c738d7c
test(opencode): require NVIDIA NIM for autofix agent
seonghobae Aug 7, 2026
2c420e3
fix(opencode): bind autofix agent to NVIDIA NIM
seonghobae Aug 7, 2026
66025e3
docs(opencode): record NVIDIA NIM autofix boundary
seonghobae Aug 7, 2026
5d55916
docs(changelog): record NVIDIA NIM autofix boundary
seonghobae Aug 7, 2026
cabf02f
chore(opencode): restage LLVM runtime boundary repair
seonghobae Aug 7, 2026
98d28b0
chore(opencode): remove staged LLVM patch artifact
seonghobae Aug 7, 2026
34ae013
chore(opencode): restage LLVM runtime boundary implementation
seonghobae Aug 7, 2026
dcb87ea
chore(opencode): remove staged LLVM patch artifact
seonghobae Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -90,13 +90,13 @@ jobs:
ref: ${{ github.event.pull_request.head.sha }}

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
category: "/language:${{ matrix.language }}"
upload: false
Expand Down Expand Up @@ -197,13 +197,13 @@ jobs:
ref: ${{ format('refs/pull/{0}/merge', github.event.pull_request.number) }}

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
category: "/language:${{ matrix.language }}-merge"
upload: false
Expand Down
242 changes: 242 additions & 0 deletions .github/workflows/opencode-coverage-diagnostics-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,242 @@
name: OpenCode Coverage Diagnostics CI

on:
pull_request:
branches: [main]
paths:
- "scripts/ci/coverage_failure_summary.py"
- "scripts/ci/javascript_coverage_gate.py"
- "scripts/ci/materialize_base_javascript_packages.py"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/sanitize_github_output_summary.py"
- "scripts/ci/strix_model_utils.sh"
- "tests/test_javascript_coverage_gate.py"
- "tests/test_javascript_coverage_gate_type_only.py"
- "tests/test_materialize_base_javascript_packages.py"
- "tests/test_materialize_base_python_requirements.py"
- "tests/test_control_plane_branch_writer_absence.py"
- "tests/test_coverage_materializer_failure_diagnostics.py"
- "tests/test_coverage_native_fuzz_lock_boundary.py"
- "tests/conftest.py"
- "tests/test_materialize_uv_export_hash_contract.py"
- "tests/test_trusted_uv_download_contract.py"
- "tests/test_trusted_uv_materializer_quality_workflow_contract.py"
- "tests/test_trusted_uv_portability_and_streaming.py"
- "tests/test_uv_export_isolation_contract.py"
- "tests/test_uv_redirect_and_coverage_contract.py"
- "tests/test_uv_redirect_boundary.py"
- "tests/test_uv_workspace_fail_closed.py"
- "tests/test_sanitize_github_output_summary.py"
- "tests/test_strix_dependency_security_floor.py"
- "tests/test_strix_model_utils_source_dirs.py"
- "requirements-opencode-python310-ci-hashes.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-strix-ci.txt"
- "requirements-strix-ci-hashes.txt"
- "pyproject.toml"
- ".github/workflows/opencode-coverage-diagnostics-ci.yml"
push:
branches: [main]
paths:
- "scripts/ci/coverage_failure_summary.py"
- "scripts/ci/javascript_coverage_gate.py"
- "scripts/ci/materialize_base_javascript_packages.py"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/sanitize_github_output_summary.py"
- "scripts/ci/strix_model_utils.sh"
- "tests/test_javascript_coverage_gate.py"
- "tests/test_javascript_coverage_gate_type_only.py"
- "tests/test_materialize_base_javascript_packages.py"
- "tests/test_materialize_base_python_requirements.py"
- "tests/test_control_plane_branch_writer_absence.py"
- "tests/test_coverage_materializer_failure_diagnostics.py"
- "tests/test_coverage_native_fuzz_lock_boundary.py"
- "tests/conftest.py"
- "tests/test_materialize_uv_export_hash_contract.py"
- "tests/test_trusted_uv_download_contract.py"
- "tests/test_trusted_uv_materializer_quality_workflow_contract.py"
- "tests/test_trusted_uv_portability_and_streaming.py"
- "tests/test_uv_export_isolation_contract.py"
- "tests/test_uv_redirect_and_coverage_contract.py"
- "tests/test_uv_redirect_boundary.py"
- "tests/test_uv_workspace_fail_closed.py"
- "tests/test_sanitize_github_output_summary.py"
- "tests/test_strix_dependency_security_floor.py"
- "tests/test_strix_model_utils_source_dirs.py"
- "requirements-opencode-python310-ci-hashes.txt"
- "requirements-opencode-review-ci-hashes.txt"
- "requirements-strix-ci.txt"
- "requirements-strix-ci-hashes.txt"
- "pyproject.toml"
- ".github/workflows/opencode-coverage-diagnostics-ci.yml"
Comment thread
coderabbitai[bot] marked this conversation as resolved.

concurrency:
group: opencode-coverage-diagnostics-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
minimum-python-contract:
name: Python 3.10 runtime contract
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up minimum supported Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.10"

- name: Install hash-locked Python 3.10 compatibility dependency
run: >-
python -m pip install --disable-pip-version-check --require-hashes
--only-binary=:all:
-r requirements-opencode-python310-ci-hashes.txt

- name: Compile production modules on Python 3.10
run: |
python -m compileall -q \
scripts/ci/coverage_failure_summary.py \
scripts/ci/javascript_coverage_gate.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py

- name: Exercise exact failure evidence on Python 3.10
run: |
python - <<'PY'
import os
import pathlib
import tempfile

from scripts.ci import materialize_base_javascript_packages as javascript_materializer
from scripts.ci import materialize_base_python_requirements as python_materializer

with tempfile.TemporaryDirectory() as directory:
output = pathlib.Path(directory) / "github-output"
os.environ["GITHUB_OUTPUT"] = str(output)
exact_reason = (
"current-head npm lock package-lock.json package "
"apps/desktop/node_modules/@types/react-dom must pin a registry "
"tarball and SHA-512 integrity"
)
javascript_materializer._publish_coverage_failure_summary(
"Base JavaScript package lock materialization",
ValueError(exact_reason),
"Repair the lock and rerun coverage-evidence.",
)
python_materializer._publish_coverage_failure_summary(
"Base Python lock materialization",
OSError("fixture <unsafe>\nCWL_COVERAGE_SUMMARY_EOF"),
"Repair the trusted lock and rerun coverage-evidence.",
)
published = output.read_text(encoding="utf-8")
assert f"ValueError: {exact_reason}" in published
assert "OSError: fixture &lt;unsafe&gt; CWL_COVERAGE_SUMMARY_END" in published
assert published.count("coverage_summary<<CWL_COVERAGE_SUMMARY_EOF") == 2
PY

full-quality-gate:
name: Python 3.14 full quality gate
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up current stable Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.14"
cache: pip
cache-dependency-path: requirements-opencode-review-ci-hashes.txt

- name: Install hash-locked test tooling
run: >-
python -m pip install --disable-pip-version-check --require-hashes
-r requirements-opencode-review-ci-hashes.txt

- name: Run diagnostics and lock contracts with full branch coverage
run: |
python -m pytest \
tests/test_javascript_coverage_gate.py \
tests/test_javascript_coverage_gate_type_only.py \
tests/test_materialize_base_javascript_packages.py \
tests/test_materialize_base_python_requirements.py \
tests/test_control_plane_branch_writer_absence.py \
tests/test_coverage_materializer_failure_diagnostics.py \
tests/test_coverage_native_fuzz_lock_boundary.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_materializer_quality_workflow_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_redirect_and_coverage_contract.py \
tests/test_uv_redirect_boundary.py \
tests/test_uv_workspace_fail_closed.py \
tests/test_sanitize_github_output_summary.py \
tests/test_strix_dependency_security_floor.py \
tests/test_strix_model_utils_source_dirs.py \
--cov=scripts.ci.coverage_failure_summary \
--cov=scripts.ci.javascript_coverage_gate \
--cov=scripts.ci.materialize_base_javascript_packages \
--cov=scripts.ci.materialize_base_python_requirements \
--cov=scripts.ci.sanitize_github_output_summary \
--cov-branch \
--cov-fail-under=100 \
-q

- name: Enforce complete production docstrings
run: |
python -m interrogate \
--fail-under 100 \
scripts/ci/coverage_failure_summary.py \
scripts/ci/javascript_coverage_gate.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py

- name: Compile changed Python surfaces
run: |
python -m compileall -q \
scripts/ci/coverage_failure_summary.py \
scripts/ci/javascript_coverage_gate.py \
scripts/ci/materialize_base_javascript_packages.py \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/sanitize_github_output_summary.py \
tests/test_javascript_coverage_gate.py \
tests/test_javascript_coverage_gate_type_only.py \
tests/test_control_plane_branch_writer_absence.py \
tests/test_coverage_materializer_failure_diagnostics.py \
tests/test_coverage_native_fuzz_lock_boundary.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_materializer_quality_workflow_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_redirect_and_coverage_contract.py \
tests/test_uv_redirect_boundary.py \
tests/test_uv_workspace_fail_closed.py \
tests/test_sanitize_github_output_summary.py \
tests/test_strix_dependency_security_floor.py \
tests/test_strix_model_utils_source_dirs.py
Loading
Loading