Skip to content

chore: refresh org SBOM inventory - #1678

Draft
opencode-agent[bot] wants to merge 191 commits into
mainfrom
automation/sbom-inventory
Draft

chore: refresh org SBOM inventory#1678
opencode-agent[bot] wants to merge 191 commits into
mainfrom
automation/sbom-inventory

Conversation

@opencode-agent

@opencode-agent opencode-agent Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Automated central SBOM inventory refresh for live non-fork repositories. Review reciprocal, restricted, and NOASSERTION license evidence in docs/sbom/inventory.md against the product's actual distribution and hosted-service model.


Devin Review

Current blocking state (2026-09-08)

  • Exact head: e6b292ce5e104212eaa032579afff1514b865019; live main comparison is ahead 70 / behind 0. The effective customer-evidence delta remains docs/sbom/inventory.json and docs/sbom/inventory.md.
  • required-workflow-bootstrap is deterministically RED before policy analysis because the Contents API does not inline the 1,148,611-byte JSON and protected main's policy caps that evidence path at 1 MiB. This is not an Nginx finding.
  • Canonical owner repair #1946 sits at exact head 1cb8cceb8719eb054979d84141cda9a95c0c6873, ahead 5 / behind 0, with bounded Git Blobs fallback plus malicious-content and malformed-evidence tests. Both original and Ready-event same-head Security, SAST, Python Security, and CodeQL PR runs are terminal GREEN. Noema and Strix were materialized but failed on central orchestrator/free availability (HTTP 429 / zero ready routes); OpenCode's derived CHANGES_REQUESTED contains no leaf-source finding. Keep this inventory PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protected main, this branch non-force integrates that release, and new exact-head checks plus independent review are valid.
  • Noema's orchestrator/free HTTP 429 is a separate review-transport blocker. Keep this PR Draft until fix(pingora): read Contents-API-oversized files through the Git Blobs API #1946 reaches protected main, this branch non-force integrates that release, and all new exact-head checks plus independent review are valid.

@opencode-agent
opencode-agent Bot requested a review from seonghobae as a code owner September 2, 2026 04:27

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 3 potential issues.

⚠️ 3 issues in files not directly in the diff

⚠️ Partial inventory appears complete

With 34 of 63 SBOM fetches returning 404, repo_count reports all 63 while component totals cover only 29. The inventory presents partial organization evidence as complete.


⚠️ Permitted licenses trigger violations

For MPL-2.0 components without another prohibited license, flagged reports at least 137 policy violations. Governance therefore escalates expressly permitted dependencies.


⚠️ Permissive alternatives trigger violations

When an SPDX expression offers a permissive alternative, flagged rejects it because another alternative is copyleft. Seven selectable permissive dependencies become policy violations.

Devin Review

@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep labels Sep 2, 2026 — with ChatGPT Codex Connector

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 0 new potential issues.

Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

⚠️ 1 issue in files not directly in the diff

⚠️ Restricted licenses escape policy review

Seven LicenseRef-NVIDIA-Proprietary components are marked unflagged. Unknown and non-standard licenses also disappear from the commercial-permissive policy review.

Devin Review

seonghobae and others added 30 commits September 10, 2026 08:21
…ialization

Companion infrastructure repair for contextual-orchestrator#1111, now merged at d0fe10b508b46b225627fd201ef49ba6b3712598. User-authorized chicken-and-egg recovery. Reviewed all three changed files: accept only a full immutable organization VCS commit plus a single lower bound satisfied by the fixed Python 3.14 coverage image; false and complex markers remain rejected. Exact-head Trusted uv Materializer Quality CI 34322532030, SAST 34322531949, Security Scan 34322531920, Python Security 34322531962, and CodeQL 34322531908 are successful; zero review threads. No formal approval is claimed. No rulesets, credentials, statuses, or source isolation boundaries were weakened. Fresh consumer execution is still required to establish restoration.
Explicit user-authorized bypass for contextual-orchestrator incident recovery. Full three-file diff reviewed at 3431353; zero inline review threads. Exact-head Python Security 34310169116, SAST 34310169148, CodeQL 34310169106 and Security Scan 34310169250 are success. Preserve legacy log forms and omit provider response bodies, credentials and free-form messages; validate typed provider status/request IDs and reject multiline/partial tokens. Prerequisite for #2053 and merged contextual-orchestrator#1105 producer compatibility. No independent-approval or complete live-runtime-recovery claim. No scanner, ruleset or status modifications.
…he central collector

Explicit user-authorized bypass for contextual-orchestrator infrastructure recovery. Prerequisite #1978 merged at 7b16449; retargeted this unchanged head to main without rewriting history. Full four-file diff reviewed; zero inline review threads. Exact-head CodeQL 34311014133, Security Scan 34311014127 and SAST 34311014150 are success; prior branch-based test claims are not fresh main/consumer evidence. Admit only 32-lowercase-hex server request IDs and contract-specific absence markers; retain legacy records and omit error text. Success summaries restricted to fixed review paths. No expanded auth, raw log publication, scanner suppression or synthetic statuses. Paired producer contextual-orchestrator#1105 is merged at 650bb67dd9cb9b0846a9026dd829c82f43b839e8. No independent approval or live incident-restoration claim.
User-authorized infrastructure-only incident merge, 2026-09-10. Full four-file queue-only delta reviewed. Source head28e10b5a Runtime Quality, Security, SAST, Python Security and CodeQL all succeeded; both authenticated dispatch language verdicts succeeded. OpenCode formal rejection cites peer infrastructure checks only, not a source finding. Original Noema34186939795/job101940505698 proves a CO414f2297 inference HTTP502 after73.4s prevented the model verdict. Existing inline/folded-comment parser findings are repaired in the current source; no unresolved inline threads. Ordinary expected-head merge, no review dismissal, synthetic status, permission/protection weakening, credential change or forced history. Push runs coalesce per branch; scheduled/PR evidence semantics preserved. Intermediate cancelled push reports are not guaranteed, as documented. Fresh merged-head CI and actual queue recovery remain unverified until observed. Evidence: issuecomment5613486794.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants