Skip to content
Open
Show file tree
Hide file tree
Changes from 46 commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
aac99bb
fix(security): update pip audit lock past pysec-2026-3721
seonghobae Aug 21, 2026
84ee91b
feat: route autofix through contextual orchestrator
seonghobae Aug 21, 2026
d195ef4
chore(security): restore pip-audit lock owner scope
seonghobae Aug 21, 2026
b9cffcf
chore: schedule contextual-orchestrator hourly review repair (#1178)
seonghobae Aug 21, 2026
0e9d24c
Revert "chore: schedule contextual-orchestrator hourly review repair …
seonghobae Aug 21, 2026
08c92c4
Reapply "chore: schedule contextual-orchestrator hourly review repair…
seonghobae Aug 21, 2026
94a2804
fix(security): use osv scanner output-file flag
seonghobae Aug 21, 2026
859d3b7
fix(test): track osv scanner output-file option
seonghobae Aug 21, 2026
90ea841
fix(security): keep reporter output contract
seonghobae Aug 21, 2026
592deef
docs: complete fixture initializer docstring coverage
seonghobae Aug 21, 2026
4ed00ac
fix(codeql): bind merge analysis to merge commit SHA (#1206)
seonghobae Aug 21, 2026
94e2b28
fix(codeql): keep merge upload ref in documented form
seonghobae Aug 21, 2026
4d3d24a
fix(actions): deduplicate workflow-run scheduler scans (#1203)
seonghobae Aug 21, 2026
3016543
fix(review): fail closed when required check is not a verdict (#1002)
seonghobae Aug 21, 2026
4c659d2
Merge protected main into pip-audit scheduler root
seonghobae Aug 21, 2026
3b91220
fix(review): reject external heads in privileged paths
seonghobae Aug 21, 2026
dbb3c8a
fix(codeql): verify merge preview identity
seonghobae Aug 21, 2026
33cdcad
fix(codeql): authenticate merge preview fetch
seonghobae Aug 21, 2026
801c2f1
fix(codeql): bind analysis to exact current merge tree
seonghobae Aug 21, 2026
61ecd32
Merge protected main into exact merge-preview repair
seonghobae Aug 21, 2026
e5a7ac8
test: refresh review dispatch blob pin after restack
seonghobae Aug 21, 2026
1ff33c9
fix(codeql): fetch merge ancestry before preview
seonghobae Aug 23, 2026
997e4f1
Merge protected main into CodeQL review repair
seonghobae Aug 23, 2026
bee244e
merge(main): refresh CodeQL review owner
seonghobae Aug 24, 2026
069bfa6
merge(main): refresh CodeQL review owner
seonghobae Aug 24, 2026
dafcf87
fix(review): validate exact VCS dependency licenses
seonghobae Aug 24, 2026
88579ae
test(review): keep VCS license fixtures whitespace-clean
seonghobae Aug 24, 2026
863c343
test(review): prove VCS license gate coverage
seonghobae Aug 24, 2026
98af23e
fix(review): reject VCS license metadata redirects
seonghobae Aug 24, 2026
09c2489
Merge protected main into review verdict owner
seonghobae Aug 25, 2026
0b5dbd1
fix(review): reject dot-only VCS repository names
seonghobae Aug 25, 2026
59fdd8c
Merge protected main and clarify the MPL-2.0 policy exception
seonghobae Aug 25, 2026
234bbd6
Merge protected main into review-verdict owner
seonghobae Aug 25, 2026
b69d9c8
fix(ci): normalize merged scheduler files at EOF
seonghobae Aug 25, 2026
748e881
merge: converge review-verdict owner with protected main
seonghobae Aug 26, 2026
27a8bd5
fix(codeql): resolve fork heads through exact PR ref
seonghobae Aug 26, 2026
2d00301
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Aug 26, 2026
2e044cb
Merge main into fix/pip-audit-pip-2621, reconciling 8 conflicted files
claude Aug 30, 2026
105b1bf
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Aug 30, 2026
b2388fa
Merge remote-tracking branch 'origin/main' into fix/pip-audit-pip-2621
claude Aug 30, 2026
090b032
fix(scheduler): preserve draft dispatch budget when Strix is busy
seonghobae Aug 30, 2026
187f74b
Merge protected main into fix/pip-audit-pip-2621
seonghobae Aug 30, 2026
c4ec814
fix(scheduler): prioritize before applying queue cap
seonghobae Aug 30, 2026
b580a36
fix(scheduler): bound prioritized queue hydration
seonghobae Aug 30, 2026
b051f5d
fix(scheduler): preserve fallback priority authority
seonghobae Aug 30, 2026
207d94b
fix(review): fail closed before every Noema skip path
seonghobae Aug 31, 2026
e44650a
Merge protected main into Noema fail-closed review repair
seonghobae Aug 31, 2026
8bf311c
fix(review): paginate Noema approval evidence
seonghobae Aug 31, 2026
b8f4adb
Merge protected main into review-verdict repair
seonghobae Aug 31, 2026
6e32ebe
merge: main@f2f91b80 into #1198 (fix/pip-audit-pip-2621)
seonghobae Sep 5, 2026
0f5775e
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 6, 2026
c7c844e
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 6, 2026
26d72a5
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 11, 2026
6574924
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 12, 2026
a05f87b
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 13, 2026
81ecd66
Merge branch 'main' into fix/pip-audit-pip-2621
opencode-agent[bot] Sep 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 16 additions & 6 deletions scripts/ci/noema_review_gate.py
Original file line number Diff line number Diff line change
Expand Up @@ -647,24 +647,34 @@ def submit_review(repo: str, number: int, pr: dict[str, Any], actor: str, verdic


def inspect_and_review(repo: str, number: int) -> int:
"""Inspect PR state and submit Noema's LLM review when gates are clean."""
"""Inspect PR state and submit Noema's LLM review when gates are clean.

Missing current-head primary OpenCode approval fails closed before every
Noema skip path, so the required check cannot look reviewed without an
exact-head Reviews API verdict.
"""
pr = fetch_pr(repo, number)
actor = current_actor()
if not current_primary_approval(pr):
print(
"Current head does not have a primary OpenCode approval; "
"Noema cannot skip as success because that made the required "
"check look like a review."
)
return 1
Comment thread
seonghobae marked this conversation as resolved.
Outdated
if actor in PRIMARY_REVIEW_AUTHORS:
print(
f"Current token actor {actor!r} is already a primary review actor; "
"Noema review skipped so GitHub receives an independent reviewer."
"Noema review skipped after the current-head primary approval so "
"GitHub receives an independent reviewer."
)
return 0
if pr.get("isDraft"):
print("PR is draft; Noema review skipped.")
print("PR is draft; Noema review skipped after primary OpenCode approval.")
return 0
if existing_noema_review(pr, actor):
Comment thread
seonghobae marked this conversation as resolved.
Outdated
print("Current head already has a Noema review; nothing to do.")
return 0
if not current_primary_approval(pr):
print("Current head does not have a primary OpenCode approval; Noema review skipped.")
return 0
if has_current_changes_requested(pr):
print("Current head has requested changes; Noema review skipped.")
return 0
Comment thread
seonghobae marked this conversation as resolved.
Outdated
Expand Down
49 changes: 46 additions & 3 deletions tests/test_noema_review_gate.py
Original file line number Diff line number Diff line change
Expand Up @@ -527,9 +527,21 @@ def test_inspect_and_review_skip_paths(monkeypatch):
assert calls

cases = [
(make_pr(), "noema"),
(make_pr(isDraft=True), "noema"),
(make_pr(reviews={"nodes": [review(login="noema", body="<!-- noema-review-gate head_sha=head -->")]}), "noema"),
(make_pr(isDraft=True, reviews={"nodes": [review(body=marker_body)]}), "noema"),
(
make_pr(
reviews={
"nodes": [
review(body=marker_body),
review(
login="noema",
body="<!-- noema-review-gate head_sha=head -->",
),
]
}
),
"noema",
),
(make_pr(reviews={"nodes": [review("CHANGES_REQUESTED"), review(body=marker_body)]}), "noema"),
(make_pr(reviews={"nodes": [review(body=marker_body)]}, reviewThreads={"nodes": [{"isResolved": False, "isOutdated": False}]}), "noema"),
(make_pr(reviews={"nodes": [review(body=marker_body)]}, statusCheckRollup={"contexts": {"nodes": [{"__typename": "StatusContext", "context": "ci", "state": "FAILURE"}]}}), "noema"),
Expand All @@ -543,6 +555,37 @@ def test_inspect_and_review_skip_paths(monkeypatch):
assert calls == []


@pytest.mark.parametrize(
("pr", "actor"),
[
(make_pr(), "noema"),
(make_pr(isDraft=True), "noema"),
(
make_pr(
reviews={
"nodes": [
review(
login="noema",
body="<!-- noema-review-gate head_sha=head -->",
)
]
}
),
"noema",
),
(make_pr(), "opencode-agent"),
],
)
def test_noema_never_skips_success_without_current_head_primary_approval(
monkeypatch, pr, actor
):
"""Every Noema skip path remains non-passing until OpenCode approves this head."""
monkeypatch.setattr(noema, "fetch_pr", lambda repo, number: pr)
monkeypatch.setattr(noema, "current_actor", lambda: actor)

assert noema.inspect_and_review("owner/repo", 7) == 1


def test_parse_args_and_main(monkeypatch):
parsed = noema.parse_args(["--repo", "owner/repo", "--pr-number", "9"])
assert parsed.repo == "owner/repo"
Expand Down
Loading