Skip to content

fix(semgrep): make the pinned image digest authoritative - #941

Open
seonghobae wants to merge 16 commits into
mainfrom
fix/semgrep-digest-single-source-20260812
Open

fix(semgrep): make the pinned image digest authoritative#941
seonghobae wants to merge 16 commits into
mainfrom
fix/semgrep-digest-single-source-20260812

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • keep the current Semgrep OSS 1.169.0 immutable image reference in one job-level SEMGREP_IMAGE variable;
  • validate that the value is a complete 64-hex SHA-256 manifest reference;
  • resolve that exact manifest before scanning and use the same value for docker run;
  • fail closed with an explicit error instead of allowing a partial local digest to surface as an ambiguous image-manifest failure.

The unchanged digest remains:

semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942

Scan scope, severities, SARIF handling, credentials, permissions, metrics-off behavior, and the existing fail-closed Semgrep gate remain unchanged.

Exact-current-head verification

  • protected base: main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;
  • exact current head: 5f51364418eb6e17300e771f9738d0580acad115;
  • changed surface: .github/workflows/sast-semgrep.yml only;
  • SAST Semgrep run 31598619582, job 94120163405: terminal success;
  • the new Verify pinned Semgrep manifest step completed successfully before the scan;
  • OSV-Scanner PR, Security Scan, Python Security, SBOM Generation, Secret Scan, and Scorecard are terminal-success for this head; CodeQL remains queued;
  • no stale predecessor-head check or skipped check will be treated as acceptance.

Merge only after every required current-head check, zero valid unresolved findings, and the required qualifying independent approvals pass.

Summary by CodeRabbit

  • 보안 강화

    • Semgrep 실행에 고정된 이미지 다이제스트를 사용해 실행 환경의 일관성과 무결성을 강화했습니다.
    • 실행 전 다이제스트 형식과 이미지 매니페스트를 검증하며, 검증 실패 시 작업이 중단됩니다.
  • 문서

    • Semgrep 이미지 다이제스트 단일 소스 정책과 관련 보안 지침을 문서화했습니다.
  • 테스트

    • 이미지 고정, 단일 참조 및 매니페스트 검증이 정상적으로 적용되는지 확인하는 테스트를 추가했습니다.

Open in Devin Review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e162593e-565f-46b4-a676-df445dfabee4

📝 Walkthrough

Walkthrough

Semgrep 워크플로가 이미지 참조를 고정 SHA256 digest로 관리한다. 실행 전에 digest 형식과 Docker 매니페스트 존재 여부를 검증한다. 검증된 이미지 참조를 Semgrep 실행 단계에서 사용한다. 운영 문서와 테스트도 이 계약을 반영한다.

Changes

Semgrep 이미지 검증

Layer / File(s) Summary
이미지 digest 고정 및 실행 전 검증
.github/workflows/sast-semgrep.yml, tests/test_central_required_workflow_ruleset_audit.py
SEMGREP_IMAGE에 고정 digest를 설정한다. 실행 전에 digest 형식과 Docker 매니페스트를 검증한다. 검증된 환경 변수로 Semgrep을 실행한다. 테스트는 digest 선언, 단일 사용, 변수 참조와 매니페스트 검증 단계를 확인한다.
운영 계약 및 관련 문서 갱신
AGENTS.md, ARCHITECTURE.md, CLAUDE.md, CHANGELOG.md, docs/doctoring/semgrep-image-digest-single-source.md
로그 증거, 매니페스트 검사와 docker run이 동일한 job-level SEMGREP_IMAGE digest를 사용하도록 문서화한다. 단일 소스 정책과 변경 내역을 기록한다.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: 🟡 Moderate · up to 3dfa0

The workflow now validates and scans a pinned Semgrep image, but the current tests do not prove that manifest inspection and execution use the same job-level image reference. A regression could therefore pass CI undetected, so the assertions should be strengthened or the risk explicitly accepted before merge.

Sequence Diagram(s)

sequenceDiagram
  participant Workflow as Semgrep workflow
  participant Docker as Docker CLI
  participant Registry as Container registry
  participant Semgrep as Semgrep container
  Workflow->>Workflow: Validate SEMGREP_IMAGE digest format
  Workflow->>Docker: Inspect SEMGREP_IMAGE manifest
  Docker->>Registry: Request fixed digest manifest
  Registry-->>Docker: Return manifest result
  Docker-->>Workflow: Return validation result
  Workflow->>Semgrep: Run scan with validated SEMGREP_IMAGE
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 고정된 Semgrep 이미지 digest를 단일 권위 소스로 만드는 주요 변경을 정확하고 간결하게 설명합니다.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/semgrep-digest-single-source-20260812

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Current-head verification record (2026-08-12):

  • head: 432497975d8e74822f853e095764ec5bcbcf29c3;
  • base: main at 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;
  • changed surface: .github/workflows/sast-semgrep.yml only;
  • immutable Semgrep image reference is unchanged and now has one workflow source of truth.

At observation time, SAST Semgrep, Scorecard, Secret Scan, OSV-Scanner PR, Python Security, and SBOM Generation were running; Security Scan and CodeQL PR were queued; CodeRabbit was pending. No review or unresolved thread exists yet. Merge remains blocked until all exact-head required checks complete and qualifying independent approval is present.

Copy link
Copy Markdown
Contributor Author

Current-head verification record (2026-08-12 UTC):

  • head: 432497975d8e74822f853e095764ec5bcbcf29c3
  • base: 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba
  • central workflow now keeps the full immutable reference in one SEMGREP_IMAGE variable and uses it for both evidence and docker run;
  • image reference: semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942;
  • the exact Semgrep command completed successfully under the workflow's existing rules, severity, exclusions, SARIF, and metrics-off conditions;
  • all eight hosted checks for this exact head are terminal-success and there are no unresolved review threads.

The earlier local partial-digest manifest failure is therefore addressed at the central source of truth. Merge remains pending current independent review and repository policy approval; no stale or synthetic approval is being used.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 against independently resolved live main 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. Eight exact-head hosted workflows and the separate CodeRabbit status are terminal-success, with no unresolved review thread. Verify that one immutable Semgrep image reference is authoritative for both evidence and execution without weakening rules, severity, exclusions, SARIF, or metrics-off behavior. Automated judgment is not qualifying independent human approval or merge authorization.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 only. The exact-head security and supply-chain workflows are terminal-success. Validate that one job-level SEMGREP_IMAGE immutable digest is the sole source used by both evidence and docker run, with scan scope, severity, SARIF, permissions, credentials, and fail-closed behavior unchanged. Review only; do not mutate, merge, release, or alter protections.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

printf '%s\n' '== checked-out HEAD =='
git rev-parse HEAD
printf '%s\n' '== requested commits available =='
git cat-file -e "${head_expected}^{commit}"
git cat-file -e "${base_expected}^{commit}"

printf '%s\n' '== changed paths: requested base..head =='
git diff --name-status "$base_expected" "$head_expected"

printf '%s\n' '== workflow outline =='
ast-grep outline .github/workflows/sast-semgrep.yml --items all

printf '%s\n' '== exact workflow diff =='
git diff --no-ext-diff --unified=80 "$base_expected" "$head_expected" -- .github/workflows/sast-semgrep.yml

printf '%s\n' '== current workflow source, numbered =='
cat -n .github/workflows/sast-semgrep.yml

printf '%s\n' '== SEMGREP_IMAGE and image invocation references =='
rg -n -C 4 'SEMGREP_IMAGE|semgrep/semgrep|docker\s+run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off' \
  .github/workflows/sast-semgrep.yml

Length of output: 18513


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

printf '%s\n' '== PR refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head_sha: .head.sha, base_sha: .base.sha, state: .state, draft: .draft}'

printf '%s\n' '== check runs attached to the requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, details_url, app: .app.slug}'

printf '%s\n' '== commit statuses attached to the requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/status?per_page=100" \
  --jq '.statuses[] | {context, state, target_url, creator: .creator.login}'

printf '%s\n' '== PR reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

printf '%s\n' '== unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes { isResolved isOutdated comments(first: 1) { nodes { author { login } body } } }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 10858


@seonghobae No findings.

I reviewed only head 432497975d8e74822f853e095764ec5bcbcf29c3 against base 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 defines one job-level SEMGREP_IMAGE value with the required immutable digest.
  • Line 75 uses ${SEMGREP_IMAGE} for log evidence.
  • Line 81 uses ${SEMGREP_IMAGE} for docker run.
  • The scan configuration, severity filters, exclusions, SARIF handling, permissions, credential handling, and fail-closed gate logic are unchanged.
  • The exact-head Semgrep (multi-language SAST) check completed successfully.
  • GitHub reports no unresolved review threads.

I used the repository guidance that only results attached to the exact current head count as check evidence. Some attached checks are skipped or neutral; I did not treat them as successful evidence.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

Learnt from: CR
Repo: ContextualWisdomLab/.github PR: 0
File: CLAUDE.md:0-0
Timestamp: 2026-07-29T06:47:25.581Z
Learning: Applies to opencode.jsonc : All reviewer agents in `opencode.jsonc` must keep `"edit": "deny"`; reviewers must never implement changes.
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review
@coderabbitai review

Review exact current head 432497975d8e74822f853e095764ec5bcbcf29c3 only. Validate the one-file central SAST change: the exact immutable Semgrep image reference is declared once in job-level SEMGREP_IMAGE and the identical value is used both for logged evidence and docker run; confirm the digest itself, scan scope, severities, SARIF handling, credentials, permissions, failure semantics, and merge authority are unchanged. All observed exact-head hosted checks are terminal-success and no review thread exists. Review only; do not mutate, merge, release, or bypass protection.

Copy link
Copy Markdown
Contributor Author

Exact-current-head review request for 432497975d8e74822f853e095764ec5bcbcf29c3 over protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

The bounded one-file repair keeps the Semgrep OSS 1.169.0 image digest unchanged and makes one job-level SEMGREP_IMAGE value authoritative for both evidence and execution. CodeQL PR, Python Security, Security Scan, OSV-Scanner PR, Secret Scan, Scorecard PR, SBOM Generation, and SAST Semgrep are terminal-success on this exact head; no review thread exists.

Review this unchanged head read-only. Do not update the branch, synthesize author approval, merge, release, or weaken protection.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head_expected='432497975d8e74822f853e095764ec5bcbcf29c3'
base_expected='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
workflow='.github/workflows/sast-semgrep.yml'

printf '%s\n' '== local refs and changed paths =='
test "$(git rev-parse HEAD)" = "$head_expected"
git cat-file -e "${base_expected}^{commit}"
git diff --name-status "$base_expected" "$head_expected"
printf '%s\n' '== exact workflow diff =='
git diff --no-ext-diff --unified=100 "$base_expected" "$head_expected" -- "$workflow"
printf '%s\n' '== workflow outline =='
ast-grep outline "$workflow" --items all
printf '%s\n' '== image references and scan controls =='
rg -n -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker\s+run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|SEMGREP_APP_TOKEN' "$workflow"

printf '%s\n' '== pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head_sha: .head.sha, base_sha: .base.sha, state: .state, draft: .draft}'
printf '%s\n' '== check runs on requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'
printf '%s\n' '== commit statuses on requested head =='
gh api --paginate "repos/${repo}/commits/${head_expected}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'
printf '%s\n' '== reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'
printf '%s\n' '== unresolved threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes { isResolved isOutdated comments(first: 1) { nodes { author { login } body } } }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 16946


@seonghobae No findings.

I reviewed only head 432497975d8e74822f853e095764ec5bcbcf29c3 against base 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 declares SEMGREP_IMAGE once at the semgrep job level.
  • The value is the required immutable reference: semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942.
  • Line 75 logs ${SEMGREP_IMAGE}.
  • Line 81 passes the same ${SEMGREP_IMAGE} value to docker run.
  • The Semgrep configuration, severity filters, exclusions, SARIF processing, permissions, credential handling, and fail-closed gate logic are unchanged.
  • The exact-head Semgrep (multi-language SAST) check succeeded. The direct trivy-fs, scorecard, osv-scan, gitleaks (secret scan), and generate-sbom checks also succeeded.
  • I did not treat neutral or skipped checks as passing evidence, consistent with the repository guidance.
  • GitHub reports no unresolved review threads.

GitHub returned no submitted reviews. Therefore, no independent approval is present in the retrieved review data. This review does not grant merge authority.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

You are interacting with an AI system.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head='432497975d8e74822f853e095764ec5bcbcf29c3'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

echo '== Local commit and changed-path verification =='
printf 'checked_out_head='; git rev-parse HEAD
git cat-file -e "${head}^{commit}"
git cat-file -e "${base}^{commit}"
git diff --name-status "$base" "$head"

echo '== Workflow diff =='
git diff --no-ext-diff --unified=100 "$base" "$head" -- .github/workflows/sast-semgrep.yml

echo '== Relevant workflow lines at requested head =='
git show "${head}:.github/workflows/sast-semgrep.yml" |
  nl -ba |
  grep -E -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|contents:|security-events:|SEMGREP_APP_TOKEN'

echo '== Pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head: .head.sha, base: .base.sha, state, draft}'

echo '== Check runs for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'

echo '== Commit statuses for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'

echo '== Reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

echo '== Unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body } }
        }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 10166


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr_number='941'
head='432497975d8e74822f853e095764ec5bcbcf29c3'

echo '== Relevant workflow lines at requested head =='
git show "${head}:.github/workflows/sast-semgrep.yml" |
  cat -n |
  grep -E -C 5 'SEMGREP_IMAGE|semgrep/semgrep|docker run|--config=|--severity=|--exclude=|--sarif|--error|--metrics=off|permissions:|contents:|security-events:|SEMGREP_APP_TOKEN'

echo '== Pull request refs =='
gh api "repos/${repo}/pulls/${pr_number}" \
  --jq '{head: .head.sha, base: .base.sha, state, draft}'

echo '== Check runs for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/check-runs?per_page=100" \
  --jq '.check_runs[] | {name, status, conclusion, app: .app.slug}'

echo '== Commit statuses for requested head =='
gh api --paginate "repos/${repo}/commits/${head}/status?per_page=100" \
  --jq '.statuses[] | {context, state, creator: .creator.login}'

echo '== Reviews =='
gh api --paginate "repos/${repo}/pulls/${pr_number}/reviews?per_page=100" \
  --jq '.[] | {user: .user.login, state, commit_id, submitted_at}'

echo '== Unresolved review threads =='
gh api graphql \
  -F owner='ContextualWisdomLab' \
  -F name='.github' \
  -F number="$pr_number" \
  -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body } }
        }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 9034


@seonghobae No findings.

I reviewed only 432497975d8e74822f853e095764ec5bcbcf29c3 against 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

  • The diff changes only .github/workflows/sast-semgrep.yml.
  • Line 61 defines the full immutable digest once in job-level SEMGREP_IMAGE.
  • Line 75 uses ${SEMGREP_IMAGE} for evidence logging.
  • Line 81 uses the identical ${SEMGREP_IMAGE} value for docker run.
  • The digest is semgrep/semgrep@sha256:2b33f46ba66cf8cc2ad59ccfa7d22951fd00c632c38f1339e84ec8e6e641a942.
  • Scan scope, severity filters, exclusions, SARIF processing, permissions, credential persistence, and fail-closed behavior are unchanged.
  • The requested head and base still match PR #941.
  • The relevant exact-head checks are completed successfully.
  • I did not count skipped or neutral checks as successful evidence.
  • GitHub reports no unresolved review threads.

GitHub returned no pull-request reviews. Therefore, this review does not establish an independent approval or merge authorization.

I used the repository guidance that only successful checks on the exact current head count as merge evidence.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

You are interacting with an AI system.

@seonghobae
seonghobae enabled auto-merge (squash) August 12, 2026 10:45

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-current-head source review for 432497975d8e74822f853e095764ec5bcbcf29c3 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

The complete one-file diff moves the already-pinned immutable Semgrep manifest reference into one job-level SEMGREP_IMAGE value and uses that exact value for both log evidence and docker run. The digest, scanner version, configuration, severities, exclusions, SARIF handling, metrics policy, permissions, credentials, and fail-closed --error behavior are unchanged. All eight directly triggered exact-head security and supply-chain workflows, including the modified SAST Semgrep workflow itself, are terminal-success and no inline thread exists.

A qualifying independent reviewer must submit formal approval on this unchanged head. Do not update the branch, change the image digest, weaken scanner arguments, synthesize author approval, or bypass protection.

Copy link
Copy Markdown
Contributor Author

Exact-current-head automated review request for 432497975d8e74822f853e095764ec5bcbcf29c3. The bounded one-file refactor retains the identical immutable Semgrep digest and scan semantics; all eight directly triggered workflows are terminal-success and no thread exists. Review read-only without updating the branch or weakening SAST policy.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 26 minutes and 15 seconds before sending another message.

@opencode-agent
opencode-agent Bot disabled auto-merge August 12, 2026 12:12

Copy link
Copy Markdown
Contributor Author

Exact-current-head source review request for 5f51364418eb6e17300e771f9738d0580acad115 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

Check that the job-level immutable Semgrep reference is complete, the preflight resolves the exact manifest, and the scan uses that same reference without changing existing rules, severities, exclusions, SARIF, permissions, credentials, or fail-closed behavior. Review read-only; no digest/tag weakening or merge bypass.

@opencode-agent review
@cwl-noema-review review
@strix review

@seonghobae

Copy link
Copy Markdown
Contributor Author

Reviewed. Added single-digest contract, CHANGELOG, and APA 7th doctoring (NIST SP 800-190, SLSA 1.0). Local suite 977 passed x2, coverage 100%. Auto-merge armed.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 24ca6081e4704ca176ca02015cbbf27e07fbf832.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: ca926fde25943c44ae53588d0af1b6988de4ec55
  • Workflow run: 32810839307
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head ca926fde25943c44ae53588d0af1b6988de4ec55.

  • Head SHA: ca926fde25943c44ae53588d0af1b6988de4ec55

  • Workflow run: 32810839307

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 13, 2026 08:53
@seonghobae
seonghobae enabled auto-merge (squash) August 13, 2026 15:38

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 8fabd327773eb5346f307ffdaa633b2e9f026c9a.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (2 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (2 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["CI script: materialize_base_python_requirements.py"]
  S4 --> I4["review and security gate shell path"]
  I4 --> R4["Review risk: CI script: materialize_base_python_requirements.py"]
  R4 --> V4["bash -n plus Strix self-test"]
  Evidence --> S5["Test (2 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test (2 files)"]
  R5 --> V5["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 14, 2026 01:29
@seonghobae
seonghobae marked this pull request as draft August 14, 2026 09:04

Copy link
Copy Markdown
Contributor Author

Returned to Draft because the exact current tree contradicts the body’s “Semgrep workflow only” scope.

The valid repair is bounded: one job-level immutable SEMGREP_IMAGE, exact full SHA-256 manifest validation/resolution, and reuse of that same value for the scan. Head 8fabd327773eb5346f307ffdaa633b2e9f026c9a additionally changes materialize_base_python_requirements.py, its tests, central ruleset tests, AGENTS, doctoring, and changelog.

Rebuild from protected main retaining only sast-semgrep.yml, the focused digest/ruleset regression, directly attributable doctoring/changelog evidence, and no materializer changes. Update the stale exact-head/check section, then reacquire exact-head Semgrep/CodeQL/security/SBOM and independent-review evidence.

@seonghobae
seonghobae marked this pull request as ready for review August 14, 2026 13:56

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review only exact current head 6015981514956977ebf18e74f3441b3bc560a679 against live protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. I removed the unrelated trusted-uv production delta by restoring the exact Semgrep immutable-manifest authority tree as a new descendant. The current diff is five files and preserves one job-level complete SHA-256 image reference, explicit manifest resolution before scan, the same immutable value for docker run, and fail-closed incomplete refs without changing scan scope, severities, permissions, credentials, metrics, or SARIF semantics. No review thread exists. Exact-head checks are regenerating; nonterminal evidence is not acceptance. Review read-only; do not mutate source, synthesize approval, weaken Semgrep/SLSA controls, or merge.

Copy link
Copy Markdown
Contributor Author

Fresh exact-head review handoff for 5b07547a01137989ae1324cd472bb15229d5e0d2 on current main@885f2cd251999f21cf562cab3e2d9cc3cc3ec737.

This current head preserves #1222's SAST identity contract: checkout is bound to pull_request.head.repo.full_name / pull_request.head.sha, git rev-parse HEAD is attested against the expected SHA before Semgrep, and SARIF is attributed to that exact submitted head. All 12 substantive hosted workflows are successful, the unrelated repair workflow is skipped, and unresolved threads are zero. No exact-current-head formal Reviews API verdict exists.

@opencode-agent review

Review-only request: submit a substantive formal verdict for this exact current head after verifying the head-oriented SAST binding and fail-closed identity mismatch path.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 5b07547a01137989ae1324cd472bb15229d5e0d2.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Fresh downstream consumer reproduction for the exact-submitted-revision portion of this owner lane; not a request to broaden Semgrep scan policy.

ContextualWisdomLab/inkspan#299 remains at source head 1efbd632719b0e54c5a33e3a95224a4bd2f869d3 against protected base 3b38ead2d00f44eb578d0689087b9293b3dabe1e, but central required-workflow evidence is still bound to the synthetic merge checkout 12668622e38473c14dbb7d22bb9e3e0c05f1ea8a:

The Inkspan branch does not own these central workflow checkouts; its local workflow delta is only repository CI. The smallest correct remedy is therefore this central exact-submitted-revision contract (and the corresponding central Security lane under #1222), not a leaf checkout workaround.

Downstream acceptance for Inkspan: after the central repair reaches protected .github/main, rerun unchanged or descendant Inkspan #299 and require the central SAST/Security jobs to attest the exact source head/repository identity before repository-code consumption/scanning. Synthetic refs/pull/*/merge checkout evidence remains predecessor/non-passing even when the aggregate job is green.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for ed123d06d2681947177568dd0c8e3d1f14c159c6.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Exact-current-head formal review requested for 2d9c7c13c878f118749e8909245e9831e5c37451 against protected main@93b9cbb145bfe03453c9421dcf7e0668da0f8050. All 13 substantive exact-head workflows are successful and unresolved threads are 0. Existing CHANGES_REQUESTED reviews are predecessor-head failed-Strix deflections and are non-passing for this head. Please submit a substantive Reviews API verdict on this exact head.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for 2d9c7c13c878f118749e8909245e9831e5c37451.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Merge protected main 0c6b9a6 while retaining the bounded SAST exact-head owner delta. Full suite: 1,398 passed, 1 skipped, 16 subtests; full Strix quick-gate: PASS.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Please submit a substantive formal Reviews API verdict for exact current head 8af67397915e94d246cd7c9792b2ccb92c436e6f against protected main@0c6b9a6459c9dbdf5e23fb01df7a32a8a14964b3. All substantive commit-associated workflows are terminal success, unresolved review threads are 0, and no qualifying exact-head formal verdict exists. Review the current SAST exact-head checkout/attestation and immutable Semgrep digest binding contract only; predecessor reviews and status/check success are non-passing substitutes. Review-only: do not mutate or merge the branch.

@seonghobae
seonghobae enabled auto-merge (squash) August 24, 2026 06:44

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Please publish an independent substantive formal Reviews API verdict for exact current head f5d3224404a9dcd04a1b4e1650c51bc256876586 against protected main@613a33e0cb1c6db9790fae99f6253445712ac37a. All 12 substantive exact-head workflows are terminal-success and unresolved review threads are 0. Older CHANGES_REQUESTED, COMMENTED, check/status, and predecessor-head evidence is historical. Inspect the complete current diff and bind APPROVED or CHANGES_REQUESTED only to this SHA; do not reuse an older verdict.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for f5d3224404a9dcd04a1b4e1650c51bc256876586.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Current-head downstream revalidation of the required Strix failure for this Semgrep owner path:

  • PR fix(semgrep): make the pinned image digest authoritative #941 exact head: f5d3224404a9dcd04a1b4e1650c51bc256876586
  • live protected base / trusted Strix source: main@613a33e0cb1c6db9790fae99f6253445712ac37a
  • required Strix run/job: 32718660538 / 97405203031
  • all substantive commit-bound exact-head workflows are terminal-success on this head, including SAST Semgrep, CodeQL, OSV, Python Security, Security Scan, SBOM, Secret Scan, Scorecard, exact-artifact/SBOM and changed-path quality; all current review threads are resolved.

The required Strix log proves the remaining CHANGES_REQUESTED is not a new #941 Semgrep-source contradiction. The pull_request_target run executes TRUSTED_STRIX_GATE from protected main@613a33e…, while scanning #941 head f5d3224…. NVIDIA primary exhausts with 429s; fallback nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5 then reaches Penetration test completed and Vulnerabilities 0 (No exploitable vulnerabilities detected), but the protected-main predecessor gate still emits Strix run emitted provider infrastructure or failure-signal output; failing closed. Direct OpenAI fallback then returns 404 page not found.

Canonical causal owner is .github#1263 (absorbing #1291), whose current head repairs the false-positive failure-signal classification while preserving #891 fail-closed semantics. Because this required run executes the protected-main gate, neither an unchanged rerun nor a #941-local Semgrep edit can validate that repair. Smallest safe path is: integrate #1263 under live governance, obtain a fresh required Strix run whose trusted source SHA contains the repaired gate, then revalidate this unchanged #941 exact head before treating its security gate as passing. Downstream Inkspan #299 must likewise be revalidated from its own exact head; no predecessor or branch-only evidence should transfer.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for f5d3224404a9dcd04a1b4e1650c51bc256876586.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head ca926fde25943c44ae53588d0af1b6988de4ec55.

  • Head SHA: ca926fde25943c44ae53588d0af1b6988de4ec55

  • Workflow run: 32807991400

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head ca926fde25943c44ae53588d0af1b6988de4ec55.

  • Head SHA: ca926fde25943c44ae53588d0af1b6988de4ec55

  • Workflow run: 32810839307

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: sast-semgrep.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: sast-semgrep.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (4 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (4 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: semgrep-image-digest-single-source.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: semgrep-image-digest-single-source.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: auth Authentication, authorization, identity, or tenant isolation area: ci-cd CI, GitHub Actions, checks, release, or supply chain priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: bug Defect or incorrect behavior

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant