Skip to content
Closed
Show file tree
Hide file tree
Changes from 62 commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
cd48d23
fix(opencode): keep product-file review when coverage gate fails
cursoragent Aug 16, 2026
31b1592
test(opencode): pin dispatch blob and close surface coverage gaps
cursoragent Aug 16, 2026
1841e18
fix(opencode): split status comment from review and keep model prose
cursoragent Aug 16, 2026
09bc3ad
fix(opencode): give NIM two hours and drop Copilot-class pool winners
cursoragent Aug 16, 2026
62f69f4
test(opencode): treat github-models as catalog-only, not pool winners
cursoragent Aug 16, 2026
6b9725a
fix(opencode): restore coverage-blocked status and honest class diagrams
cursoragent Aug 17, 2026
91f1447
test(opencode): retarget independent-reviewer dispatch blob pin
cursoragent Aug 17, 2026
8d4d7ed
test(opencode): retarget Strix mermaid assertions to the Python surfaces
cursoragent Aug 17, 2026
90eea34
fix(osv): stop 429 setup failures on the supplemental PR scan
cursoragent Aug 17, 2026
80bd590
fix(opencode): remove GitHub Models and fail closed on NIM
cursoragent Aug 17, 2026
f05924c
docs(opencode): reserve fail-closed orchestrator URL path
cursoragent Aug 17, 2026
6412387
fix(ci): satisfy main Strix smoke and wait out CodeQL 503s
cursoragent Aug 17, 2026
a0cf0ad
fix(ci): pass main Strix smoke and retry CodeQL init
cursoragent Aug 17, 2026
8c17723
fix(ci): drop materializer subprocess and retry Noema 503s
cursoragent Aug 17, 2026
26b72d6
fix(opencode): verify coverage identity, formal receipts, and Orgmetr…
cursoragent Aug 17, 2026
13a9fb0
test(opencode): retarget independent-reviewer dispatch blob pin
cursoragent Aug 17, 2026
2116038
test(opencode): close receipt, coverage-identity, and Noema branch gaps
cursoragent Aug 17, 2026
8c9ebf6
fix(opencode): address CodeRabbit findings on #1052 review-governance…
seonghobae Aug 18, 2026
fe3ed2a
fix(ci): correct assert_file_contains needle escaping for nvidia-nim …
seonghobae Aug 18, 2026
ff803b1
fix(opencode): treat nvidia-nim Strix windows as known report models
cursoragent Aug 18, 2026
d0b8c99
docs: add missing __init__ docstrings pulled in from main's merge
seonghobae Aug 19, 2026
453f900
fix(ci): keep retired fallback smoke lintable
seonghobae Aug 19, 2026
a4928c9
fix(opencode): remove unused GitHub Models permission
seonghobae Aug 20, 2026
e91db80
test(opencode): repin least-privilege review dispatch
seonghobae Aug 20, 2026
c97fa00
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 20, 2026
fe83dc0
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 20, 2026
529311f
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
1af53c4
fix(codeql): retry head initialization outage
seonghobae Aug 21, 2026
cd24023
fix(ci): remove unused materializer import
seonghobae Aug 21, 2026
d2ab979
fix(coverage): bind Rust materializer to base SHA (#1190)
seonghobae Aug 21, 2026
7b82aa4
fix(review): tolerate malformed Rust text
seonghobae Aug 21, 2026
ca7ab23
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
237df35
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
9b5dc3c
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
3fa76a2
test: align scheduler contract and audit runtime
seonghobae Aug 21, 2026
aa38b2d
chore(opencode): restore canonical pip lock ownership
seonghobae Aug 21, 2026
561a4f3
test(noema): reproduce private NIM visibility leak
seonghobae Aug 21, 2026
29ce7cd
fix(noema): keep private diffs off hosted NIM
seonghobae Aug 21, 2026
04604f1
fix(noema): admit governed private review endpoint
seonghobae Aug 21, 2026
98afe08
test(noema): cover private provider gate
seonghobae Aug 21, 2026
5299d32
Merge protected main into OpenCode review owner
seonghobae Aug 21, 2026
3c2b523
test(noema): cover invalid LLM hostname guard
seonghobae Aug 21, 2026
0bdc79b
Merge main into OpenCode review owner
seonghobae Aug 21, 2026
f16acaa
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
6d4915d
fix(strix): reconcile Luna-removal with main's own compat smoke-test …
seonghobae Aug 23, 2026
84b4cab
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
8f106a2
fix(coverage): install governed optional dependencies
seonghobae Aug 23, 2026
dfbf485
test(coverage): reject unsupported pnpm flag
seonghobae Aug 23, 2026
b10e20b
fix(review): slurp paginated coverage checks
seonghobae Aug 23, 2026
4aa738a
test(review): cover multi-page check receipts
seonghobae Aug 23, 2026
26c95bf
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
d01d68f
fix(opencode): preserve protected-main Strix contract
seonghobae Aug 23, 2026
d2629dc
test(ci): converge shared Strix and OpenCode quick-gate contracts
seonghobae Aug 23, 2026
4cb0e6e
test(opencode): preserve NIM-only replacement coverage
seonghobae Aug 23, 2026
fdfff41
fix(strix): recognize the hyphenated openai-direct fallback alias
seonghobae Aug 23, 2026
9147dcf
Merge remote-tracking branch 'origin/cursor/opencode-review-surfaces-…
seonghobae Aug 23, 2026
eed623e
fix(opencode): track live Strix default diagnostic
seonghobae Aug 23, 2026
766080a
test(opencode): cover live Strix default diagnostic
seonghobae Aug 23, 2026
cf065af
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
seonghobae Aug 24, 2026
7403952
fix(review): classify root Rust tests as tests
seonghobae Aug 24, 2026
31e1b64
Merge protected main into OpenCode review surfaces
seonghobae Aug 24, 2026
8ea117c
fix(strix): remove shadowed direct OpenAI alias arm
seonghobae Aug 24, 2026
bf3c974
fix(opencode): hold predecessor Strix verdicts
seonghobae Aug 24, 2026
f3e43ef
fix(codeql): keep init single-shot
seonghobae Aug 24, 2026
2767946
Merge protected main into OpenCode review surfaces
cursoragent Aug 25, 2026
da8f30c
test(strix): retarget live default and fallback pins to gpt-5.4
cursoragent Aug 25, 2026
9783723
docs(strix): correct direct alias history
seonghobae Aug 25, 2026
abf47ce
Merge protected main into OpenCode review surfaces
cursoragent Aug 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
74 changes: 74 additions & 0 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,44 @@ jobs:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha }}

- name: Wait for GitHub API before CodeQL init
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
attempt=1
max_attempts=8
sleep_seconds=15
while [ "$attempt" -le "$max_attempts" ]; do
if gh api rate_limit --jq '.resources.core.limit' >/dev/null; then
echo "GitHub API is reachable on attempt ${attempt}."
exit 0
fi
echo "GitHub API was unavailable on attempt ${attempt}; retrying in ${sleep_seconds}s."
sleep "$sleep_seconds"
attempt=$((attempt + 1))
done
echo "::error::GitHub API stayed unavailable; CodeQL init cannot determine feature enablement."
exit 1
Comment thread
seonghobae marked this conversation as resolved.

Comment thread
seonghobae marked this conversation as resolved.
- name: Initialize CodeQL
id: codeql_init
continue-on-error: true
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Wait after CodeQL feature-enablement outage
if: steps.codeql_init.outcome == 'failure'
run: |
set -euo pipefail
echo "CodeQL init failed; waiting before one retry for GitHub API outages."
rm -rf "$RUNNER_TEMP/codeql_databases" "$GITHUB_WORKSPACE/.codeql" || true
sleep 30

- name: Retry Initialize CodeQL
if: steps.codeql_init.outcome == 'failure'
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
languages: ${{ matrix.language }}
Comment thread
seonghobae marked this conversation as resolved.
Comment thread
github-actions[bot] marked this conversation as resolved.
Outdated
Expand Down Expand Up @@ -196,7 +233,44 @@ jobs:
persist-credentials: false
ref: ${{ format('refs/pull/{0}/merge', github.event.pull_request.number) }}

- name: Wait for GitHub API before CodeQL init
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
attempt=1
max_attempts=8
sleep_seconds=15
while [ "$attempt" -le "$max_attempts" ]; do
if gh api rate_limit --jq '.resources.core.limit' >/dev/null; then
echo "GitHub API is reachable on attempt ${attempt}."
exit 0
fi
echo "GitHub API was unavailable on attempt ${attempt}; retrying in ${sleep_seconds}s."
sleep "$sleep_seconds"
attempt=$((attempt + 1))
done
echo "::error::GitHub API stayed unavailable; CodeQL init cannot determine feature enablement."
exit 1

- name: Initialize CodeQL
id: codeql_init
continue-on-error: true
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Wait after CodeQL feature-enablement outage
if: steps.codeql_init.outcome == 'failure'
run: |
set -euo pipefail
echo "CodeQL init failed; waiting before one retry for GitHub API outages."
rm -rf "$RUNNER_TEMP/codeql_databases" "$GITHUB_WORKSPACE/.codeql" || true
sleep 30

- name: Retry Initialize CodeQL
if: steps.codeql_init.outcome == 'failure'
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
languages: ${{ matrix.language }}
Expand Down
30 changes: 21 additions & 9 deletions .github/workflows/noema-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -287,15 +287,27 @@ jobs:
echo "::error::Noema reviewer credential selection succeeded but no token was minted; review cannot submit a verdict."
exit 1
fi
if [ "$TARGET_REPOSITORY_PRIVATE" = "false" ] && [ -n "${NVIDIA_NIM_API_KEY:-}" ] && [ -z "${NOEMA_LLM_API_URL:-}" ] && [ -z "${NOEMA_LLM_MODEL:-}" ]; then
export NOEMA_LLM_API_URL="https://integrate.api.nvidia.com/v1/chat/completions"
export NOEMA_LLM_MODEL="nvidia/nemotron-3-ultra-550b-a55b"
export NOEMA_LLM_API_KEY="${NVIDIA_NIM_API_KEY:-}"
fi
if [ -z "${NOEMA_LLM_API_URL:-}" ] || [ -z "${NOEMA_LLM_MODEL:-}" ] || [ -z "${NOEMA_LLM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: NOEMA_LLM_API_URL, NOEMA_LLM_MODEL, and NOEMA_LLM_API_KEY (or OPENAI_API_KEY) are required."
exit 1
fi
case "$TARGET_REPOSITORY_PRIVATE" in
false)
if [ -z "${NVIDIA_NIM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: NVIDIA_NIM_API_KEY is required so a green public-repository Noema check is a real NIM review."
exit 1
fi
export NOEMA_LLM_API_URL="https://integrate.api.nvidia.com/v1/chat/completions"
export NOEMA_LLM_MODEL="nvidia/nemotron-3-ultra-550b-a55b"
export NOEMA_LLM_API_KEY="${NVIDIA_NIM_API_KEY}"
;;
true)
if [ -z "${NOEMA_LLM_API_URL:-}" ] || [ -z "${NOEMA_LLM_MODEL:-}" ] || [ -z "${NOEMA_LLM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: a private repository requires an explicitly configured trusted NOEMA_LLM_API_URL, NOEMA_LLM_MODEL, and NOEMA_LLM_API_KEY. Private diff evidence is not sent to the hosted NVIDIA NIM endpoint."
exit 1
fi
;;
*)
echo "::error::Noema target repository visibility was missing or invalid; failing closed."
exit 1
;;
esac
python3 scripts/ci/noema_review_gate.py \
--repo "$TARGET_REPOSITORY" \
--pr-number "$PR_NUMBER"
Loading
Loading