Skip to content

fix(ci): remove inherited duplicate model workflow - #1

Draft
seonghobae wants to merge 2 commits into
devfrom
guard-owner-gate
Draft

seonghobae wants to merge 2 commits into
devfrom
guard-owner-gate

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 27, 2026 •

Copy link
Copy Markdown

Issue for this PR

The repository has GitHub Issues disabled; creating the required issue returned HTTP 410, so no valid same-repository issue number can be linked. This PR records that repository-policy contradiction instead of inventing or closing an issue.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

The predecessor limited the inherited check-duplicates job to anomalyco/opencode, but retained direct-provider workflow source that installed OpenCode through a mutable URL and consumed OPENCODE_API_KEY.

This repair removes that unneeded job completely and preserves the non-model add-contributor-label behavior. It does not copy model selection, credential eligibility, fallback, or duplicate-scoring logic into the leaf repository. If duplicate assessment becomes a product requirement, ContextualWisdomLab/.github and released contextual-orchestrator orchestrator/free contracts remain the canonical owners.

It also adds:

  • an executable parsed-workflow contract covering the exact trigger and allowed job shape;
  • a Linux CI step that runs the contract from script/github;
  • docs/product-technical-gap-baseline.md with Proposed PRD/TRD/Context Map/UML/ERD applicability, gap, action, and status.

How did you verify your code works?

Exact published head: ebf719bd13366ea4dcd09a12b3cad732965ecb64
Exact tree: c0283f7aa174653318e21bd1fbdbf2df696dca35
Parent: 2aa4a9cf057096b27427dd406e136bcb37099780

  • RED: parsed workflow contract failed because actual jobs were check-duplicates plus add-contributor-label, while the allowed contract contained only contributor labeling.
  • GREEN: bun test pr-management-contract.test.mjs passed from script/github.
  • Mutation checks: an added run step and a trigger change from opened to edited each caused the contract to fail for the expected structural difference; both probes were removed and GREEN was reconfirmed.
  • Bun 1.3.14 install --frozen-lockfile --ignore-scripts: no lock changes.
  • Prettier check and git diff --check: passed.
  • Final local tree and GitHub-created tree matched byte-for-byte at c0283f7aa174653318e21bd1fbdbf2df696dca35.
  • Independent read-only review after all fixes: Critical/Important/Minor 0/0/0.

Hosted exact-head Checks and GitHub reviews are evaluated separately below; local validation is not represented as hosted GREEN evidence.

Screenshots / recordings

Not applicable; this change has no UI surface.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Current exact-head gate status

State remains Draft / Proposed. The predecessor exact-head Semgrep, Security Scan, and CodeQL failures are stale evidence after this head change. Current-head hosted Checks and qualifying independent GitHub approval must be observed before any Ready or merge decision. No Force Push, destructive rebase, bypass, auto-merge, release, or PR Close was used.

Keep the inherited direct-provider duplicate check on its canonical repository while preserving contributor labeling.

Signed-off-by: Seongho Bae <[email protected]>

Commit-Message-Assisted-by: Codex (Orca API)
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5dfbdb45-a821-47fa-a63d-9bb7e995632d

📥 Commits

Reviewing files that changed from the base of the PR and between b3f1a96 and 2aa4a9c.

📒 Files selected for processing (1)
  • .github/workflows/pr-management.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

check-duplicates 작업에 저장소 조건을 추가했습니다. 이 작업은 저장소가 anomalyco/opencode일 때만 실행됩니다.

Changes

워크플로 작업 범위

Layer / File(s) Summary
중복 검사 작업 조건
.github/workflows/pr-management.yml
check-duplicates 작업은 저장소가 anomalyco/opencode일 때 실행됩니다. 다른 저장소에서는 작업을 건너뜁니다.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 2aa4a

The duplicate check is limited to the canonical repository; no concrete merge-blocking risk remains.

Architecture Summary

Architecture risk: 🔵 Low · up to 2aa4a

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/pr-management.yml: check-duplicates now runs only when github.repository equals anomalyco/opencode; otherwise, the job is skipped.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed 제목은 inherited duplicate workflow와 관련되며 주요 변경 영역을 식별합니다. 그러나 실제 변경은 workflow를 제거하지 않고 anomalyco/opencode 저장소에서만 실행되도록 제한합니다.
Description check ✅ Passed 설명은 템플릿의 필수 섹션을 모두 포함합니다. 이슈 제약, 변경 내용, 검증 방법, 화면 변경 여부, 체크리스트를 구체적으로 기록했습니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Author

@coderabbitai approve

@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown
✅ Action performed

Comments resolved. Approval is disabled; enable reviews.request_changes_workflow to allow explicit top-level @coderabbitai resolve or @coderabbitai approve commands.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

This PR doesn't fully meet our contributing guidelines and PR template.

What needs to be fixed:

  • No issue referenced. Please add Closes #<number> linking to the relevant issue.

Please edit this PR description to address the above within 2 hours, or it will be automatically closed.

If you believe this was flagged incorrectly, please let a maintainer know.

@github-actions

Copy link
Copy Markdown

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

Copy link
Copy Markdown
Author

Exact-head admission correction — 2aa4a9cf057096b27427dd406e136bcb37099780

Ready is review admission only. Fresh audit against base b3f1a96c6dd7adeb28b36dd11add1998fc84d67b found:

  • latest terminal workflow blockers: SAST Semgrep 36358142807=failure, typecheck 36358142756=cancelled, test 36358142764=cancelled, nix-eval 36358142719=cancelled, Security Scan 36358142730=failure, CodeQL PR 36358142762=failure

This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed.

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 05:23

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for 2aa4a9cf057096b27427dd406e136bcb37099780.

The one-line delta adds a repository-identity guard to the inherited check-duplicates job and leaves the contributor-label job unchanged. That is the smallest change for the stated fork behavior, and I found no additional issue in this one-line diff itself.

This is a COMMENT, not an approval. Exact-head evidence is terminal non-GREEN: Semgrep run 36358142807 reports 302 inherited Medium+ findings; Security Scan 36358142730 reports 34 inherited Trivy findings; CodeQL PR 36358142762 records authenticated failure verdicts for both actions and javascript-typescript; typecheck, test, and nix-eval were cancelled. The underlying CodeQL SARIF and the protected-base scanner defects still require owner-level RCA and repair. Keep the PR Draft / Proposed and do not merge until current-head checks are GREEN and a qualifying independent approval exists.

@seonghobae seonghobae mentioned this pull request Sep 30, 2026
4 of 6 tasks
Remove the unneeded direct-provider duplicate-PR job instead of retaining it behind a repository condition. Preserve contributor labeling, add an executable parsed-workflow contract to CI, and record the Proposed product/technical gap boundary.
@seonghobae seonghobae changed the title fix(ci): restrict duplicate PR check to upstream fix(ci): remove inherited duplicate model workflow Oct 1, 2026

seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Author

Exact-head hosted-check RCA — ebf719bd13366ea4dcd09a12b3cad732965ecb64

Security Scan

Security Scan run 36942539958, job 110637183541, checked out the expected repository and exact head successfully. Trivy generated and uploaded SARIF, then the explicit gate failed on 35 inherited findings. None is located in this PR's four changed files.

The complete responsibility-preserving successor carryover is:

  • #2: OpenCode runtime Dockerfile — 4 findings.
  • #4: stats server Dockerfile — 1 finding.
  • #5: Tauri Linux Dockerfile — 1 finding.
  • #6: shared build-image Dockerfiles — 4 findings.
  • #8: github/bun.lock Action runtime dependencies — 10 findings.
  • #9: artifacts/glm52-rise-video/bun.lock — 15 findings.

Total: 4 + 1 + 1 + 4 + 10 + 15 = 35. The Draft successor stack preserves every scanner delta without suppressing the gate or mixing unrelated repairs into #1.

SAST Semgrep

SAST run 36942539868, job 110637133554, also verified and scanned the exact head. Semgrep completed successfully and the explicit Medium+ gate failed on 302 findings: 9 error and 293 warning. A machine comparison of every reported path against the four-file PR delta found 0 intersections.

The dominant inherited rule is path traversal audit (265 findings); the remaining report contains non-literal regex (22), prototype-pollution (3), shell-spawn (3), child-process (2), insecure transport (2), and five one-off workflow/container rules. This is repository-wide protected-base Gap work, not evidence that #1 introduced a source finding.

Current gate state

  • local contract: 1 pass, 0 fail;
  • Prettier: all four changed files pass;
  • git diff --check: pass;
  • local tree equals published tree c0283f7aa174653318e21bd1fbdbf2df696dca35;
  • Security Scan: failed on the 35 inherited findings above;
  • SAST Semgrep: failed on the 302 inherited findings above;
  • test, typecheck, nix-eval: queued;
  • CodeQL PR: skipped;
  • qualifying exact-head GitHub approvals: 0; the sole COMMENTED review targets predecessor 2aa4a9c….

Therefore #1 remains Draft / Proposed / merge HOLD. No Force Push, destructive rebase, gate bypass, rerun without a causal change, merge, auto-merge, release, or Close was used.

Stacked orchestration successor

#10 is the verified stacked successor for this PR's valid workflow delta. It targets #9's exact head and carries pr-management.yml byte-for-byte as contributor-label-only, then removes the remaining repository-owned direct provider/model workflows and the indirect release model path. Its exact head/tree are 0c01435161744b67ab109824f23adfda1e61295e / 18e40210c5cbb5250915ce8eacb56f83245a0840.

#1 is intentionally kept open and Draft until #10 integrates and complete carryover can be verified on the protected line.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant