fix(ci): skip Draft admission for heavy PR workflows - #2376
seonghobae wants to merge 6 commits into
Conversation
Co-authored-by: Seongho Bae <[email protected]>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (11)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough다섯 PR 워크플로가 ChangesPR Draft 수명주기 처리
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to This change keeps required security scans running on Draft PRs in ruleset-consuming repositories. Native runs in the .github repository still skip Draft PRs. No concrete merge-blocking risk was found. Confirm that the hosted checks pass on the current head before merging. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change preserves required scanning for consumer-repository Draft PRs while deferring native work until readiness. Existing permissions and execution paths remain unchanged. Current required-check enforcement and self-hosted runner isolation still need live confirmation. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 71.43% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. (8 skipped: 8 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: Seongho Bae <[email protected]>
Co-authored-by: Seongho Bae <[email protected]>
Co-authored-by: Seongho Bae <[email protected]>
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/agent-review-runtime-quality-ci.yml— GitHub Actions review job.github/workflows/codeql-pr.yml— GitHub Actions review job.github/workflows/python-security.yml— GitHub Actions review job.github/workflows/sast-semgrep.yml— GitHub Actions review job.github/workflows/security-scan.yml— GitHub Actions review jobCHANGELOG.d/20260925-heavy-pr-workflow-draft-admission.md— repository behaviordocs/doctoring/heavy-pr-workflow-draft-admission.md— operator or user guidancedocs/doctoring/required-workflow-path-filter-boundary.md— operator or user guidancetests/test_docs_only_pr_runner_admission.py— regression suitetests/test_required_workflow_queue_contract.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
R6 --> V6["required checks"]
Evidence --> S7["Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
S7 --> I7["operator or user guidance"]
I7 --> R7["Review risk: Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
R7 --> V7["docs review"]
Evidence --> S8["Test: test_docs_only_pr_runner_admission.py (2 files)"]
S8 --> I8["regression suite"]
I8 --> R8["Review risk: Test: test_docs_only_pr_runner_admission.py (2 files)"]
R8 --> V8["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
2633197d3ded3417c3acf97291a15a053d2b214b - Workflow run: 36199038763
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
R6 --> V6["required checks"]
Evidence --> S7["Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
S7 --> I7["operator or user guidance"]
I7 --> R7["Review risk: Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
R7 --> V7["docs review"]
Evidence --> S8["Test: test_docs_only_pr_runner_admission.py (2 files)"]
S8 --> I8["regression suite"]
I8 --> R8["Review risk: Test: test_docs_only_pr_runner_admission.py (2 files)"]
R8 --> V8["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
Admission correction — exact head
|
Non-destructively reconcile #2376 with protected main. Ruleset-injected required workflows do not re-enter on ready_for_review, so sibling consumers must not skip Draft scans. Preserve native .github Draft runner savings and current central runner routing. RED stale contract reproduced; GREEN 91 focused tests in normal and GITHUB_ACTIONS modes, plus 5,162 full tests.
|
Canonical-owner repair refreshed at exact head
No bypass or consumer workflow copy was used. |
Admission correction — exact head
|
Admission state authority — exact head
|
Exact-head admission repair — Draft restoredGitHub Draft was restored for current head Fresh evidence:
Admission remains HOLD. Do not promote this PR again until the dependency locks are repaired, the dispatched CodeQL jobs publish authenticated terminal success on this exact head, every required check is terminal successful, and a fresh independent current-head review is present. No bypass or stale evidence conversion is valid. |
Preserve the Draft-admission delta while stacking it on the exact canonical owner head that repairs urllib3 2.7.0 CVE-2026-97687/97688/97689. This is an ordinary two-parent integration; no force update and no source copy. Verified on the exact tree: - focused workflow/dependency contracts: 146 passed - full warnings-as-errors suite: 5,258 passed, 5 skipped, 40 subtests - git diff --check: passed
|
Exact-head owner-stack repair published.
This integrates the canonical Exact-tree verification:
The PR remains Draft/Proposed because the prerequisite is not terminally admitted and all hosted check/review evidence was invalidated by publication. No further same-head Ready/Draft wake transition is authorized. |
Current authority
Status: Proposed / Draft — stacked admission HOLD.
126e38992eba8d48f5cbcc14456e3414474a963e540fc71ed2b1a3551426b4b51b948576291d8eef.github#2536@6a37e4cdfbd8bf6f3a60645a0ad7c13e1b9c1ae3(seonghobae/coverage-incomplete-approval-20260930)f52ef22018dab716c5fd362bffcf0e5d0bcf8b52and the exact canonical prerequisite; branch advanced withforce=falseRoot cause and owner repair
Organization ruleset-launched required workflows do not re-enter on a consumer's
ready_for_reviewevent. A consumer first scanned while Draft can therefore remain without a fresh required scan after Ready.The owner repair keeps Draft runner savings only for native
ContextualWisdomLab/.githubruns. Ruleset consumers continue Security Scan, SAST Semgrep, and CodeQL while Draft:github.event.pull_request.draft == false || github.repository != 'ContextualWisdomLab/.github'Python Security and Agent Review Runtime Quality remain direct-run workflows with native Draft guards.
Security prerequisite integration
Ready-event Python Security run 36825244492 found
urllib3 2.7.0affected by CVE-2026-97687, CVE-2026-97688, and CVE-2026-97689. The causal owner repair already existed in #2536 withurllib3==2.8.0, source/lock parity coverage, strict exact-pin audit evidence, and ordinary history.This PR now stacks on that exact owner head. It does not copy or independently regenerate the owner lock.
RED → GREEN evidence
tests/test_control_workflows_skip_draft_prs.pyrejected the corrected ruleset boundary because its assertion was stale.GITHUB_ACTIONS=true.git diff --check: passed.Admission boundary
Do not create another empty wake commit, manual rerun, or repeated Draft↔Ready transition for this exact head. A newer exact-head authority must supersede this record before any state change.
Merge remains blocked until #2536 is terminally admitted, this exact head has fresh successful required Checks including a non-skipped authenticated CodeQL verdict, substantive review threads are resolved, and a qualifying independent exact-head approval exists. No bypass, merge, auto-merge, force update, synthetic status, or predecessor closure is authorized.
Changed boundary
Relative to the canonical prerequisite, this PR changes five owner workflows, doctoring/changelog evidence, and three executable contract suites. The live reproduction remains ContextualWisdomLab/naruon#1828.