Skip to content

fix(ci): skip Draft admission for heavy PR workflows - #2376

Draft
seonghobae wants to merge 6 commits into
seonghobae/coverage-incomplete-approval-20260930from
cursor/draft-admission-follow-up-554c
Draft

seonghobae wants to merge 6 commits into
seonghobae/coverage-incomplete-approval-20260930from
cursor/draft-admission-follow-up-554c

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Current authority

Status: Proposed / Draft — stacked admission HOLD.

  • Exact head: 126e38992eba8d48f5cbcc14456e3414474a963e
  • Exact tree: 540fc71ed2b1a3551426b4b51b948576291d8eef
  • Canonical prerequisite/base: .github#2536@6a37e4cdfbd8bf6f3a60645a0ad7c13e1b9c1ae3 (seonghobae/coverage-incomplete-approval-20260930)
  • History: ordinary two-parent integration of prior head f52ef22018dab716c5fd362bffcf0e5d0bcf8b52 and the exact canonical prerequisite; branch advanced with force=false
  • State rationale: the prerequisite PR is still Draft/Proposed and this publication invalidates prior Checks/review. Draft is not an approval-before-Ready rule.

Root cause and owner repair

Organization ruleset-launched required workflows do not re-enter on a consumer's ready_for_review event. A consumer first scanned while Draft can therefore remain without a fresh required scan after Ready.

The owner repair keeps Draft runner savings only for native ContextualWisdomLab/.github runs. Ruleset consumers continue Security Scan, SAST Semgrep, and CodeQL while Draft:

github.event.pull_request.draft == false || github.repository != 'ContextualWisdomLab/.github'

Python Security and Agent Review Runtime Quality remain direct-run workflows with native Draft guards.

Security prerequisite integration

Ready-event Python Security run 36825244492 found urllib3 2.7.0 affected by CVE-2026-97687, CVE-2026-97688, and CVE-2026-97689. The causal owner repair already existed in #2536 with urllib3==2.8.0, source/lock parity coverage, strict exact-pin audit evidence, and ordinary history.

This PR now stacks on that exact owner head. It does not copy or independently regenerate the owner lock.

RED → GREEN evidence

  • Initial reconciled RED: tests/test_control_workflows_skip_draft_prs.py rejected the corrected ruleset boundary because its assertion was stale.
  • Pre-stack focused GREEN: 91 passed in normal mode and 91 passed with GITHUB_ACTIONS=true.
  • Integrated exact-tree focused workflow/dependency contracts: 146 passed.
  • Integrated exact-tree full warnings-as-errors suite: 5,258 passed, 5 optional skips, 40 subtests passed.
  • git diff --check: passed.
  • Both exact parents are ancestors of the published head.

Admission boundary

Do not create another empty wake commit, manual rerun, or repeated Draft↔Ready transition for this exact head. A newer exact-head authority must supersede this record before any state change.

Merge remains blocked until #2536 is terminally admitted, this exact head has fresh successful required Checks including a non-skipped authenticated CodeQL verdict, substantive review threads are resolved, and a qualifying independent exact-head approval exists. No bypass, merge, auto-merge, force update, synthetic status, or predecessor closure is authorized.

Changed boundary

Relative to the canonical prerequisite, this PR changes five owner workflows, doctoring/changelog evidence, and three executable contract suites. The live reproduction remains ContextualWisdomLab/naruon#1828.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 946b1ae4-b6f5-4b9d-9e25-0db44b29ac0e

📥 Commits

Reviewing files that changed from the base of the PR and between 37b1024 and f52ef22.

📒 Files selected for processing (11)
  • .github/workflows/agent-review-runtime-quality-ci.yml
  • .github/workflows/codeql-pr.yml
  • .github/workflows/python-security.yml
  • .github/workflows/sast-semgrep.yml
  • .github/workflows/security-scan.yml
  • CHANGELOG.d/20260925-heavy-pr-workflow-draft-admission.md
  • docs/doctoring/heavy-pr-workflow-draft-admission.md
  • docs/doctoring/required-workflow-path-filter-boundary.md
  • tests/test_control_workflows_skip_draft_prs.py
  • tests/test_docs_only_pr_runner_admission.py
  • tests/test_required_workflow_queue_contract.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

다섯 PR 워크플로가 converted_to_draft 이벤트를 구독합니다. 워크플로별 작업 조건은 닫힌 PR과 Draft PR을 처리하며, 일부 워크플로는 ContextualWisdomLab/.github 여부에 따라 Draft 처리 규칙을 달리합니다. 테스트와 문서도 해당 규칙에 맞게 변경했습니다.

Changes

PR Draft 수명주기 처리

Layer / File(s) Summary
PR 이벤트 및 작업 실행 조건
.github/workflows/agent-review-runtime-quality-ci.yml, .github/workflows/codeql-pr.yml, .github/workflows/python-security.yml, .github/workflows/sast-semgrep.yml, .github/workflows/security-scan.yml, tests/test_docs_only_pr_runner_admission.py, tests/test_required_workflow_queue_contract.py
다섯 워크플로가 converted_to_draft를 구독합니다. 작업 조건은 닫힌 PR 및 Draft 상태를 워크플로별로 처리합니다. 테스트는 이벤트, 작업 조건, 취소 설정 및 비-PR 이벤트 조건을 검사합니다.
저장소별 Draft 처리 계약
CHANGELOG.d/20260925-heavy-pr-workflow-draft-admission.md, docs/doctoring/heavy-pr-workflow-draft-admission.md, docs/doctoring/required-workflow-path-filter-boundary.md, tests/test_control_workflows_skip_draft_prs.py
테스트와 문서는 ruleset 대상 실행에서 Draft 검사를 유지하고 native .github 실행에서 Draft 작업을 건너뛰는 구분을 반영합니다. 변경 기록과 문서는 이벤트 재진입, 동시 실행 처리 및 검증 계약도 기술합니다.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to f52ef

This change keeps required security scans running on Draft PRs in ruleset-consuming repositories. Native runs in the .github repository still skip Draft PRs. No concrete merge-blocking risk was found. Confirm that the hosted checks pass on the current head before merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to f52ef

The change preserves required scanning for consumer-repository Draft PRs while deferring native work until readiness. Existing permissions and execution paths remain unchanged. Current required-check enforcement and self-hosted runner isolation still need live confirmation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected security boundary spans PR content in consumer repositories and central CodeQL execution. Draft admission changes when CodeQL work starts, but Ready PRs already reached the same authority and runner paths. The maximum consumer scope depends on the live organization ruleset, not the repository inequality guard alone.

Trust Boundaries and Controls

  • observed — Attacker-controlled PR content is checked out for scanning with persisted checkout credentials disabled. The repository guard is an admission exception, not an authorization grant. CodeQL's separate dispatch path retains live metadata validation and authenticated verdict checks before settling current-head results.

Resilience and Maintainability Implications

  • observed — Source-level controls preserve cancellation and fail-toward-scanning scope classification. Documentation also records pre-existing CodeQL startup failures with no check runs; that historical observation is not proof of a current failure or a regression introduced by this PR.

Hardening Proposals

  • proposed — Confirm the security admission guarantee with exact-head native and consumer runs across repeated Draft/Ready transitions, head changes and cancellation. Record required-check conclusions, injected workflow identity, and self-hosted runner isolation rather than relying solely on YAML assertions or historical observations.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 71.43% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. (8 skipped: 8… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 heavy PR workflow의 Draft admission 처리 변경을 정확히 요약합니다. 변경된 워크플로와 주요 목적에 직접 관련되며 간결하고 명확합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 71.43% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. (8 skipped: 8 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/agent-review-runtime-quality-ci.yml — GitHub Actions review job
  • .github/workflows/codeql-pr.yml — GitHub Actions review job
  • .github/workflows/python-security.yml — GitHub Actions review job
  • .github/workflows/sast-semgrep.yml — GitHub Actions review job
  • .github/workflows/security-scan.yml — GitHub Actions review job
  • CHANGELOG.d/20260925-heavy-pr-workflow-draft-admission.md — repository behavior
  • docs/doctoring/heavy-pr-workflow-draft-admission.md — operator or user guidance
  • docs/doctoring/required-workflow-path-filter-boundary.md — operator or user guidance
  • tests/test_docs_only_pr_runner_admission.py — regression suite
  • tests/test_required_workflow_queue_contract.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: codeql-pr.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Workflow: python-security.yml"]
  S3 --> I3["GitHub Actions review job"]
  I3 --> R3["Review risk: Workflow: python-security.yml"]
  R3 --> V3["actionlint plus required checks"]
  Evidence --> S4["Workflow: sast-semgrep.yml"]
  S4 --> I4["GitHub Actions review job"]
  I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
  R4 --> V4["actionlint plus required checks"]
  Evidence --> S5["Workflow: security-scan.yml"]
  S5 --> I5["GitHub Actions review job"]
  I5 --> R5["Review risk: Workflow: security-scan.yml"]
  R5 --> V5["actionlint plus required checks"]
  Evidence --> S6["Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
  R6 --> V6["required checks"]
  Evidence --> S7["Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
  S7 --> I7["operator or user guidance"]
  I7 --> R7["Review risk: Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
  R7 --> V7["docs review"]
  Evidence --> S8["Test: test_docs_only_pr_runner_admission.py (2 files)"]
  S8 --> I8["regression suite"]
  I8 --> R8["Review risk: Test: test_docs_only_pr_runner_admission.py (2 files)"]
  R8 --> V8["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 2633197d3ded3417c3acf97291a15a053d2b214b
  • Workflow run: 36199038763
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: codeql-pr.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Workflow: python-security.yml"]
  S3 --> I3["GitHub Actions review job"]
  I3 --> R3["Review risk: Workflow: python-security.yml"]
  R3 --> V3["actionlint plus required checks"]
  Evidence --> S4["Workflow: sast-semgrep.yml"]
  S4 --> I4["GitHub Actions review job"]
  I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
  R4 --> V4["actionlint plus required checks"]
  Evidence --> S5["Workflow: security-scan.yml"]
  S5 --> I5["GitHub Actions review job"]
  I5 --> R5["Review risk: Workflow: security-scan.yml"]
  R5 --> V5["actionlint plus required checks"]
  Evidence --> S6["Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: 20260925-heavy-pr-workflow-draft-admission.md"]
  R6 --> V6["required checks"]
  Evidence --> S7["Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
  S7 --> I7["operator or user guidance"]
  I7 --> R7["Review risk: Docs: heavy-pr-workflow-draft-admission.md (2 files)"]
  R7 --> V7["docs review"]
  Evidence --> S8["Test: test_docs_only_pr_runner_admission.py (2 files)"]
  S8 --> I8["regression suite"]
  I8 --> R8["Review risk: Test: test_docs_only_pr_runner_admission.py (2 files)"]
  R8 --> V8["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

Copy link
Copy Markdown
Contributor Author

Admission correction — exact head 2633197d3ded3417c3acf97291a15a053d2b214b

Current-head Runtime Quality 36162092418, CodeQL 36162092374, and Python Security 36162092395 are terminally failed; active opencode-agent CHANGES_REQUESTED remains. Canonical foundation successor .github#2385@950ab88553fe7415a73401c7ccc2e4749554395e carries the missing coverage lock, AnyIO audit repair, and CodeQL owner parents. This PR is returned to Draft/Proposed with its exact head preserved.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 09:06
Non-destructively reconcile #2376 with protected main. Ruleset-injected required workflows do not re-enter on ready_for_review, so sibling consumers must not skip Draft scans. Preserve native .github Draft runner savings and current central runner routing. RED stale contract reproduced; GREEN 91 focused tests in normal and GITHUB_ACTIONS modes, plus 5,162 full tests.

Copy link
Copy Markdown
Contributor Author

Canonical-owner repair refreshed at exact head f52ef22018dab716c5fd362bffcf0e5d0bcf8b52.

  • Non-destructive two-parent reconciliation: prior head 2633197d… + protected main@37b10243…; no Force Push.
  • Exact tree 0a3e9fd159c0f4b6b4dc85b5f1b025635924c51c matches the locally verified tree.
  • RED: current-main stale CodeQL Draft-guard contract failed on the reconciled tree.
  • GREEN: 91 focused tests; 91 with GITHUB_ACTIONS=true; full suite 5,162 passed / 8 skipped / 40 subtests; git diff --check passed.
  • GitHub now reports mergeable. PR remains Draft/Proposed because fresh exact-head hosted checks and review are outstanding.
  • Old CHANGES_REQUESTED is bound to 2633197d…, not the current head.
  • Live failure evidence remains fix(security): repair shared dependency scan failures naruon#1828: Ready transition did not create a fresh ruleset-required CodeQL run.

No bypass or consumer workflow copy was used.

@seonghobae
seonghobae marked this pull request as ready for review October 1, 2026 06:30
@seonghobae
seonghobae marked this pull request as draft October 1, 2026 06:30

Copy link
Copy Markdown
Contributor Author

Admission correction — exact head f52ef22018dab716c5fd362bffcf0e5d0bcf8b52

The PR was returned to Draft / Proposed after a fresh live-state check:

  • Security Scan 36825103802 was queued;
  • SAST 36825103890, Runtime Quality 36825103967, CodeQL PR 36825103746, and Python Security 36825103808 were in progress;
  • the only submitted review is an older-head CHANGES_REQUESTED on 2633197d…; current-head approvals are 0;
  • the PR body itself declares Draft/Proposed and fresh exact-head Checks/review outstanding.

This preserves the canonical ready-for-review re-entry repair without treating admission-triggered work as passing evidence. No rerun, bypass, merge, Force Push, rebase, close, or predecessor-result transfer was used.

@seonghobae
seonghobae marked this pull request as ready for review October 1, 2026 06:31

Copy link
Copy Markdown
Contributor Author

Admission state authority — exact head f52ef22018dab716c5fd362bffcf0e5d0bcf8b52

This PR is intentionally Ready for admission. Pending/queued checks and zero current-head approvals are reasons to withhold merge, not reasons to convert a mechanically mergeable, locally GREEN PR back to Draft.

A concurrent stale-state sweep converted the prior Ready generation back to Draft while its exact-head runs were active, which triggered converted_to_draft concurrency cancellation:

  • cancelled Ready runs: CodeQL 36825103746, SAST 36825103890, Python Security 36825103808, Runtime Quality 36825103967;
  • a new Draft generation then skipped those workflows.

The body now states Ready authority before this second Ready transition. Preserve Ready while current-head checks/review run. Do not interpret queued, pending, or in-progress admission as failure, and do not transfer the older-head CHANGES_REQUESTED verdict.

@seonghobae
seonghobae marked this pull request as draft October 1, 2026 06:34

Copy link
Copy Markdown
Contributor Author

Exact-head admission repair — Draft restored

GitHub Draft was restored for current head f52ef22018dab716c5fd362bffcf0e5d0bcf8b52. The same head had been promoted to Ready again before terminal evidence existed.

Fresh evidence:

  • CodeQL PR run 36825244482 is red because both compatibility shards (110249391921, 110249391927) have only a pending dispatch verdict. Their exact log says the dispatch workflow must publish the terminal verdict and rerun the exact failed job.
  • Python Security run 36825244492 is red at pip-audit job 110249387846. The pinned CI locks contain known-vulnerable dependencies, including urllib3==2.7.0 (CVE-2026-97687/97688/97689; fix 2.8.0), litellm==1.94.1 (CVE-2026-84377; fixed branches include 1.94.3), and PyJWT==2.13.0 findings. The full lock-level finding set must be remediated and regenerated; a rerun alone is not repair.
  • Security Scan 36825244575 is nonterminal and Agent Review Runtime Quality 36825244581 is in progress.
  • The only submitted review is CHANGES_REQUESTED on stale head 2633197d…; current-head approval is absent.

Admission remains HOLD. Do not promote this PR again until the dependency locks are repaired, the dispatched CodeQL jobs publish authenticated terminal success on this exact head, every required check is terminal successful, and a fresh independent current-head review is present. No bypass or stale evidence conversion is valid.

Preserve the Draft-admission delta while stacking it on the exact canonical owner head that repairs urllib3 2.7.0 CVE-2026-97687/97688/97689. This is an ordinary two-parent integration; no force update and no source copy.

Verified on the exact tree:
- focused workflow/dependency contracts: 146 passed
- full warnings-as-errors suite: 5,258 passed, 5 skipped, 40 subtests
- git diff --check: passed
@seonghobae
seonghobae changed the base branch from main to seonghobae/coverage-incomplete-approval-20260930 October 1, 2026 06:45

Copy link
Copy Markdown
Contributor Author

Exact-head owner-stack repair published.

This integrates the canonical urllib3==2.8.0 repair for CVE-2026-97687/97688/97689 without copying or regenerating the owner lock.

Exact-tree verification:

  • focused workflow/dependency contracts: 146 passed
  • full PYTHONWARNINGS=error suite: 5,258 passed, 5 optional skips, 40 subtests
  • git diff --check: passed
  • both exact parents are ancestors

The PR remains Draft/Proposed because the prerequisite is not terminally admitted and all hosted check/review evidence was invalidated by publication. No further same-head Ready/Draft wake transition is authorized.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants