Skip to content
Merged
Show file tree
Hide file tree
Changes from 119 commits
Commits
Show all changes
240 commits
Select commit Hold shift + click to select a range
280ff95
test(trust): require current audited central source
seonghobae Sep 1, 2026
f866fb7
fix(trust): roll forward audited central source
seonghobae Sep 1, 2026
1f7359e
docs(trust): record audited central source movement
seonghobae Sep 1, 2026
89f3176
test(trust): require latest audited central source
seonghobae Sep 1, 2026
61b741e
fix(trust): follow audited central head advance
seonghobae Sep 1, 2026
e053521
docs(trust): record latest audited central movement
seonghobae Sep 1, 2026
f4b6d84
test(trust): require latest protected central source
seonghobae Sep 1, 2026
62185eb
fix(trust): roll forward latest protected central source
seonghobae Sep 1, 2026
670faa9
docs(trust): record current protected central movement
seonghobae Sep 1, 2026
cac0152
merge(main): converge trusted workflow roll-forward
seonghobae Sep 1, 2026
e37fb47
test(trust): require latest audited central source
seonghobae Sep 1, 2026
183d6c9
fix(trust): roll forward audited central source
seonghobae Sep 1, 2026
f3a25f4
docs(trust): record latest audited central movement
seonghobae Sep 1, 2026
3ac3081
test(trust): require current central workflow source
seonghobae Sep 1, 2026
44786d8
fix(trust): roll forward current central workflow source
seonghobae Sep 1, 2026
8a3417e
docs(trust): align architecture with current central source
seonghobae Sep 1, 2026
e1d3055
test(trust): require current protected central source
seonghobae Sep 1, 2026
eb8aa40
fix(trust): roll forward current central source pin
seonghobae Sep 1, 2026
fb73a43
docs(trust): record latest protected central movement
seonghobae Sep 1, 2026
18ed507
test(trust): require current protected central source
seonghobae Sep 1, 2026
4677b0f
fix(trust): follow protected central source movement
seonghobae Sep 1, 2026
b507dac
docs(trust): audit latest protected central movement
seonghobae Sep 1, 2026
31c61bd
test(trust): preserve deployed durable object state
seonghobae Sep 1, 2026
e7e2c02
fix(trust): preserve deployed durable object configuration
seonghobae Sep 1, 2026
3c79947
test(trust): require latest protected central source
seonghobae Sep 1, 2026
c05a058
fix(trust): roll forward protected central source
seonghobae Sep 1, 2026
72b2639
chore(trust): converge protected acquisition base
seonghobae Sep 1, 2026
da6fb76
docs(trust): audit latest protected central source
seonghobae Sep 1, 2026
efef1ec
test(trust): require latest protected central source
seonghobae Sep 1, 2026
f7cd9ec
fix(trust): roll forward protected central source
seonghobae Sep 1, 2026
7a8b604
docs(trust): audit latest protected central source
seonghobae Sep 1, 2026
72b40ab
test(trust): require current central workflow source
seonghobae Sep 1, 2026
f472ced
fix(trust): roll forward current central workflow source
seonghobae Sep 1, 2026
ffd7663
docs(trust): record current central source audit
seonghobae Sep 1, 2026
2c25b3b
test(trust): require latest protected central source
seonghobae Sep 1, 2026
cf64989
fix(trust): follow latest protected central source
seonghobae Sep 1, 2026
0ade92f
docs(trust): record latest protected central audit
seonghobae Sep 1, 2026
9f2c790
test(trust): require current protected central source
seonghobae Sep 1, 2026
c13c483
fix(trust): roll forward audited central workflow source
seonghobae Sep 1, 2026
3a00c23
docs(trust): record audited central roll-forward
seonghobae Sep 1, 2026
f5f702d
test(trust): require latest audited central source
seonghobae Sep 1, 2026
c9373b7
fix(trust): pin audited central workflow source
seonghobae Sep 1, 2026
55a5911
docs(architecture): bind latest central trust source
seonghobae Sep 1, 2026
014092c
merge(main): converge current protected source
seonghobae Sep 1, 2026
3d5173b
test(trust): require current central source
seonghobae Sep 1, 2026
19c06a6
fix(trust): pin current central source
seonghobae Sep 1, 2026
71938a7
test(trust): follow protected central tip
seonghobae Sep 1, 2026
11a4485
fix(trust): follow protected central tip
seonghobae Sep 1, 2026
6847e70
test(trust): require current protected workflow source
seonghobae Sep 1, 2026
a794274
fix(trust): roll pin to audited central head
seonghobae Sep 1, 2026
d775c63
docs(trust): align audited central source authority
seonghobae Sep 1, 2026
c8eef63
test(trust): require current central workflow source
seonghobae Sep 1, 2026
e46df83
fix(trust): pin current audited central workflow source
seonghobae Sep 1, 2026
e44635c
docs(trust): record audited two-phase central source
seonghobae Sep 1, 2026
3051f7e
test(trust): require latest audited central source
seonghobae Sep 1, 2026
14fc2b5
fix(trust): roll forward audited central source
seonghobae Sep 1, 2026
549f29c
test(trust): require current central workflow source
seonghobae Sep 1, 2026
1a65843
fix(trust): roll forward audited central source identity
seonghobae Sep 1, 2026
6ba1323
docs(architecture): audit current central trust source
seonghobae Sep 1, 2026
161846b
test(trust): expose latest central source movement
seonghobae Sep 1, 2026
20ca19a
fix(trust): roll forward latest central workflow source
seonghobae Sep 1, 2026
4379229
docs(architecture): audit latest central trust source
seonghobae Sep 1, 2026
37f54ac
merge: converge trust roll-forward onto current main
seonghobae Sep 1, 2026
e0c1ba1
test(trust): require current protected central source
seonghobae Sep 1, 2026
297aca1
fix(trust): restore live protected workflow authority
seonghobae Sep 1, 2026
53cc7a5
docs(arch): bind trust audit to live protected central tip
seonghobae Sep 1, 2026
6b8f25c
test(trust): require current central review source
seonghobae Sep 1, 2026
9ecd494
fix(trust): roll forward central review workflow source
seonghobae Sep 1, 2026
3885639
docs(architecture): audit current central review source
seonghobae Sep 1, 2026
95b305a
test(trust): require current protected central source
seonghobae Sep 1, 2026
a0871b7
fix(trust): bind current protected central source
seonghobae Sep 1, 2026
8276961
test(trust): require latest protected central source
seonghobae Sep 1, 2026
c870401
fix(trust): bind latest protected central source
seonghobae Sep 1, 2026
6cd7b26
docs(architecture): make workflow trust authority code-current
seonghobae Sep 1, 2026
e76cfc4
test(trust): require current protected central source
seonghobae Sep 1, 2026
49f52f8
fix(trust): bind current protected central source
seonghobae Sep 1, 2026
a973511
docs(architecture): remove volatile trust-pin snapshot
seonghobae Sep 1, 2026
307e003
test(docs): stop duplicating volatile workflow trust pin
seonghobae Sep 1, 2026
80b1a8f
test(trust): require current audited central source
seonghobae Sep 1, 2026
9846687
fix(trust): rebind audited central workflow source
seonghobae Sep 1, 2026
03273e0
chore(trust): converge current protected main
seonghobae Sep 1, 2026
da1b426
fix(trust): restore protected-main README after convergence
seonghobae Sep 1, 2026
edfc54c
fix(trust): restore protected-main licensing policy after convergence
seonghobae Sep 1, 2026
f7d1522
fix(trust): restore protected-main product gap baseline after converg…
seonghobae Sep 1, 2026
9072062
fix(trust): restore protected-main tree after convergence
seonghobae Sep 1, 2026
504237e
test(trust): require current protected workflow source
seonghobae Sep 1, 2026
40e416d
fix(trust): bind current protected workflow source
seonghobae Sep 1, 2026
c58bab0
test(trust): require current protected central source
seonghobae Sep 1, 2026
68bfe2f
fix(trust): rebind to current protected central source
seonghobae Sep 1, 2026
dd50a76
test(trust): require latest audited central source
seonghobae Sep 1, 2026
a7a446f
fix(trust): bind latest audited central source
seonghobae Sep 1, 2026
d756eae
test(trust): require latest protected central source
seonghobae Sep 1, 2026
ceaabbd
fix(trust): bind latest protected central source
seonghobae Sep 1, 2026
becfe25
test(trust): require current protected workflow source
seonghobae Sep 2, 2026
fa31163
fix(trust): bind current protected workflow source
seonghobae Sep 2, 2026
ea17c4d
test(trust): require current protected workflow source
seonghobae Sep 2, 2026
c71204c
fix(trust): bind latest protected workflow source
seonghobae Sep 2, 2026
c2402d2
test(trust): require current protected central source
seonghobae Sep 2, 2026
46b0847
fix(trust): rebind protected central workflow source
seonghobae Sep 2, 2026
9045352
test(trust): require current protected central source
seonghobae Sep 2, 2026
b9dd4ae
fix(trust): rebind protected central workflow source
seonghobae Sep 2, 2026
f2d4298
docs: log the ALLOWED_WORKFLOW_SHA trust-pin advance in CHANGELOG
claude Sep 2, 2026
d60ceac
fix(trust): advance ALLOWED_WORKFLOW_SHA to current .github protected…
claude Sep 2, 2026
ea7e8f1
test(trust): expose stale central workflow pin
seonghobae Sep 2, 2026
6330860
fix(trust): rebind protected central workflow source
seonghobae Sep 2, 2026
dd92eeb
test(trust): expose latest central source movement
seonghobae Sep 2, 2026
b8fc05d
fix(trust): bind latest protected central source
seonghobae Sep 2, 2026
d8b8489
test(trust): require current central Noema review source
seonghobae Sep 2, 2026
d5d247a
fix(trust): bind current central Noema review source
seonghobae Sep 2, 2026
66850a4
test(trust): require current protected workflow source
seonghobae Sep 2, 2026
dc19a11
fix(trust): bind current protected workflow source
seonghobae Sep 2, 2026
4e88e1d
test(trust): require current protected workflow source
seonghobae Sep 2, 2026
f6f44c9
fix(trust): bind current protected Noema workflow source
seonghobae Sep 2, 2026
fef4064
Merge protected main into trusted workflow source repair
seonghobae Sep 2, 2026
7fb7207
test(trust): require current pin in release notes
seonghobae Sep 2, 2026
0ccf907
test(trust): require current central workflow source
seonghobae Sep 2, 2026
5188e25
fix(trust): rebind current protected workflow source
seonghobae Sep 2, 2026
af7da07
test(trust): keep mutable source pin single-sourced
seonghobae Sep 2, 2026
b66ed5f
docs(changelog): record current central trust roll-forward
seonghobae Sep 2, 2026
d3ad34c
test(trust): require latest audited central source
seonghobae Sep 2, 2026
26a36c0
fix(trust): rebind audited central source
seonghobae Sep 2, 2026
53e8c3e
test(trust): require current protected central source
seonghobae Sep 2, 2026
ef86293
fix(trust): bind current protected central source
seonghobae Sep 2, 2026
5feb977
test(trust): require current central workflow source
seonghobae Sep 2, 2026
6b506b5
fix(trust): rebind current central workflow source
seonghobae Sep 2, 2026
586ab35
fix(trust): restack audited workflow source on protected main
seonghobae Sep 3, 2026
f859fcc
test(trust): require current protected central source
seonghobae Sep 3, 2026
a996186
fix(trust): bind current protected central source
seonghobae Sep 3, 2026
cb01c71
test(trust): require current central workflow source
seonghobae Sep 3, 2026
77f82f4
fix(trust): bind current central workflow source
seonghobae Sep 3, 2026
bca05d7
test(trust): require current audited central source
seonghobae Sep 3, 2026
fe07b05
fix(trust): rebind audited central source tip
seonghobae Sep 3, 2026
d1aa46e
test(trust): require latest protected central source
seonghobae Sep 3, 2026
3622c1e
fix(trust): follow audited central protected source
seonghobae Sep 3, 2026
9f1d032
test(trust): require current central workflow source
seonghobae Sep 3, 2026
f63abfc
fix(trust): rebind current central workflow source
seonghobae Sep 3, 2026
06a6cd5
test(trust): require current protected workflow source
seonghobae Sep 3, 2026
46b41f5
fix(trust): rebind current protected workflow source
seonghobae Sep 3, 2026
ffda31a
test(trust): require current protected workflow source
seonghobae Sep 3, 2026
4e3cdab
fix(trust): rebind latest protected workflow source
seonghobae Sep 3, 2026
7879f6e
test(trust): require latest protected workflow source
seonghobae Sep 3, 2026
059cdcf
fix(trust): rebind current protected workflow source
seonghobae Sep 3, 2026
231da47
test(trust): require protected scheduler-source rollforward
seonghobae Sep 3, 2026
62ae569
fix(trust): bind protected scheduler-source revision
seonghobae Sep 3, 2026
da58d5f
test(trust): require current central workflow source
seonghobae Sep 3, 2026
9116fe5
fix(trust): rebind current central workflow source
seonghobae Sep 3, 2026
1fcbfa3
test(trust): require latest central workflow source
seonghobae Sep 3, 2026
a947958
fix(trust): bind latest protected central source
seonghobae Sep 3, 2026
da2166d
test(trust): require latest audited central workflow source
seonghobae Sep 3, 2026
02c9043
fix(trust): rebind audited central workflow source
seonghobae Sep 3, 2026
086e5ff
test(trust): require central workflow source 269e5bd
seonghobae Sep 3, 2026
e7fa7a2
fix(trust): roll central workflow source to 269e5bd
seonghobae Sep 3, 2026
0cdfab3
test(trust): require current protected workflow source
seonghobae Sep 3, 2026
b0bf566
fix(trust): bind current protected workflow source
seonghobae Sep 3, 2026
c4a0034
test(trust): require latest protected workflow source
seonghobae Sep 3, 2026
2f18733
fix(trust): bind latest protected workflow source
seonghobae Sep 3, 2026
8c7c545
test(trust): require latest protected workflow source
seonghobae Sep 3, 2026
58f6260
fix(trust): rebind protected workflow source
seonghobae Sep 3, 2026
e44917b
test(trust): require latest audited central workflow source
seonghobae Sep 3, 2026
386b66b
fix(trust): rebind audited central workflow source
seonghobae Sep 3, 2026
43edc77
test(trust): require current audited central workflow source
seonghobae Sep 4, 2026
534ad27
fix(trust): rebind audited central workflow source
seonghobae Sep 4, 2026
77ab71c
test(trust): correct OIDC contract description
seonghobae Sep 4, 2026
eba3265
test(trust): require current audited central workflow source
seonghobae Sep 4, 2026
047ede3
fix(trust): bind OIDC source to audited central head
seonghobae Sep 4, 2026
ead1a36
test(trust): require latest audited central workflow source
seonghobae Sep 4, 2026
51708e3
fix(trust): rebind OIDC source to latest audited head
seonghobae Sep 4, 2026
8b6d2b6
test(trust): require latest audited central workflow source
seonghobae Sep 4, 2026
b13f8b8
fix(trust): roll audited central workflow source forward
seonghobae Sep 4, 2026
605a105
test(trust): require current protected workflow source
seonghobae Sep 4, 2026
7d5107f
fix(trust): rebind current protected workflow source
seonghobae Sep 4, 2026
34789a4
Merge protected main into trusted workflow source repair
seonghobae Sep 4, 2026
40c91d7
test(trust): require latest protected workflow source
seonghobae Sep 4, 2026
6186b91
fix(trust): rebind latest protected workflow source
seonghobae Sep 4, 2026
bff4e34
test(trust): require latest audited central workflow source
seonghobae Sep 4, 2026
3e7e302
fix(trust): rebind audited central workflow source to f893b47
seonghobae Sep 4, 2026
4907120
test(trust): require current central workflow source
seonghobae Sep 4, 2026
8687a04
fix(trust): rebind current central source
seonghobae Sep 4, 2026
3568e8b
test(trust): require latest audited central source
seonghobae Sep 4, 2026
14256d8
fix(trust): rebind audited central workflow source
seonghobae Sep 4, 2026
69e1a4b
test(trust): require current central recovery source
seonghobae Sep 4, 2026
179613b
fix(trust): rebind current central recovery source
seonghobae Sep 4, 2026
f3bc68e
test(trust): require latest audited central workflow source
seonghobae Sep 4, 2026
9308ae9
fix(trust): rebind OIDC source to audited central head
seonghobae Sep 4, 2026
eb23a7a
test(trust): require current protected workflow source
seonghobae Sep 4, 2026
41d295a
fix(trust): bind current protected workflow source
seonghobae Sep 4, 2026
3c374ff
test(trust): require current audited central source
seonghobae Sep 4, 2026
7594b4a
fix(trust): rebind protected central workflow source
seonghobae Sep 4, 2026
247d00d
test(trust): require current protected workflow source
seonghobae Sep 4, 2026
17a19ee
fix(trust): rebind protected workflow source
seonghobae Sep 4, 2026
e9060ab
test(trust): require current protected central workflow source
seonghobae Sep 4, 2026
2e5a595
fix(trust): rebind audited central workflow source
seonghobae Sep 4, 2026
817483e
test(trust): require latest audited central source
seonghobae Sep 4, 2026
18449e5
fix(trust): rebind central workflow source
seonghobae Sep 4, 2026
28d2b6e
test(trust): require current central workflow source
seonghobae Sep 5, 2026
d03358c
fix(trust): rebind current central workflow source
seonghobae Sep 5, 2026
2eb8f38
test(trust): require current protected central source
seonghobae Sep 5, 2026
4165e94
fix(trust): rebind current protected central source
seonghobae Sep 5, 2026
73fc539
test(trust): require latest protected central source
seonghobae Sep 5, 2026
cd582ee
fix(trust): rebind protected central workflow source
seonghobae Sep 5, 2026
56d5379
test(trust): require restored central Noema source
seonghobae Sep 5, 2026
cfd8ae1
fix(trust): bind restored central Noema source
seonghobae Sep 5, 2026
21a3011
test(trust): require latest protected central source
seonghobae Sep 5, 2026
7f0f2b7
fix(trust): bind latest protected central source
seonghobae Sep 5, 2026
77e6020
test(trust): require restored central timeout policy source
seonghobae Sep 5, 2026
b0bb007
fix(trust): bind restored central timeout policy source
seonghobae Sep 5, 2026
11f3452
test(trust): require latest protected central workflow source
seonghobae Sep 5, 2026
ffd861c
fix(trust): rebind protected central workflow source
seonghobae Sep 5, 2026
8cf6be7
test(trust): require current protected central source
seonghobae Sep 5, 2026
6721cb5
fix(trust): rebind protected central source
seonghobae Sep 5, 2026
6e74611
test(trust): require latest protected workflow source
seonghobae Sep 5, 2026
d35993e
fix(trust): roll forward protected workflow source
seonghobae Sep 5, 2026
62a5f9b
test(trust): require current protected workflow source
seonghobae Sep 5, 2026
c01fa18
fix(trust): roll forward current protected workflow source
seonghobae Sep 5, 2026
014ce75
test(trust): require latest protected workflow source
seonghobae Sep 5, 2026
85d56f2
fix(trust): roll forward latest protected workflow source
seonghobae Sep 5, 2026
ac47194
test(trust): require current protected central source
seonghobae Sep 5, 2026
091c385
fix(trust): roll OIDC source pin to protected central head
seonghobae Sep 5, 2026
2120207
test(trust): require latest audited central workflow source
seonghobae Sep 5, 2026
51e6da8
fix(trust): rebind audited central workflow source
seonghobae Sep 5, 2026
5730327
test(trust): require current protected central source
seonghobae Sep 5, 2026
84cff17
fix(trust): advance protected central source pin
seonghobae Sep 5, 2026
b26ffa7
test(trust): require latest audited central source
seonghobae Sep 5, 2026
f7b8bde
fix(trust): rebind latest audited central workflow source
seonghobae Sep 5, 2026
44ffbde
test(trust): require current audited central workflow source
seonghobae Sep 5, 2026
d27262d
fix(trust): roll audited central workflow source forward
seonghobae Sep 5, 2026
b159085
test(trust): require latest audited central workflow source
seonghobae Sep 5, 2026
235ed71
fix(trust): roll audited workflow source to current central head
seonghobae Sep 5, 2026
30638a1
test(trust): require current central workflow source
seonghobae Sep 5, 2026
e2399da
fix(trust): rebind current central workflow source
seonghobae Sep 5, 2026
e48d7eb
merge: restack #527 on protected reviewer truth
seonghobae Sep 6, 2026
d751e31
merge(context-fabric): restack audited workflow trust on protected co…
seonghobae Sep 6, 2026
2e38afb
test(trust): require latest audited central source
seonghobae Sep 6, 2026
25eb862
fix(trust): rebind audited central source
seonghobae Sep 6, 2026
81dc9e1
test(trust): require latest audited central workflow source
seonghobae Sep 6, 2026
5e28f61
fix(trust): bind OIDC source to audited central head
seonghobae Sep 6, 2026
b50ebd0
chore(trust): restack audited source pin on protected main
seonghobae Sep 6, 2026
beb196b
test(trust): require current central workflow source
seonghobae Sep 6, 2026
ec5b105
fix(trust): rebind audited central workflow source
seonghobae Sep 6, 2026
d289bfc
merge: converge trusted workflow source onto protected #552 truth
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,9 @@ Routes have different meanings: `/health` is liveness, `/ready` is offline confi

This revision exposes both `ALLOWED_WORKFLOW_REF_PREFIX` and `ALLOWED_WORKFLOW_SHA`. Despite the legacy ref-binding name, `src/worker.ts` parses `ALLOWED_WORKFLOW_REF_PREFIX` as one **exact full workflow ref** and compares decoded `job_workflow_ref` or `workflow_ref` for exact equality. Wildcard, comma, whitespace, and prefix-sharing configuration forms are rejected. `src/runtime-entrypoint.ts` performs readiness dispatch and delegates `/exchange`; `src/entrypoint.ts` applies the distributed rate limiter before `src/worker.ts` performs its denial-only exact workflow-ref precheck. `src/index.ts` independently enforces the exact workflow ref/repository plus immutable `job_workflow_sha` or fallback `workflow_sha` after cryptographic verification. Missing, malformed, mismatched, or non-canonical configured source identity fails closed.

`wrangler.toml` pins `ALLOWED_WORKFLOW_SHA` to protected central `.github` commit `1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5`. The exact trusted `.github/workflows/noema-review.yml` blob at that protected commit remains Git blob `064c4e5aeedcbb188196bd4800a0b918abd6da27`. Movement from `c8cc68a34bd19a91e2544acf08f2ead142ba702b` to current `1cbb6a...` leaves the workflow bytes unchanged but modifies the materialized trusted source tree in `scripts/ci/noema_review_gate.py` and its focused tests, adding one bounded correction attempt when the trusted verdict validator rejects an invalid changed-line/adversarial verdict. Because `noema-review.yml` materializes the complete trusted central source tree at its immutable workflow SHA and then executes `python3 -m scripts.ci.noema_review_gate`, this source-tree change is trust-relevant even though the workflow blob is unchanged; Noema re-audited the exact protected one-commit delta before accepting the new repository commit identity. More generally, Noema re-audits both the exact workflow blob and every relevant protected central delta before each repository-commit movement; ancestry alone is insufficient because GitHub OIDC `job_workflow_sha` binds the caller to that exact repository commit identity. The central repository remains a read-only dependency from Noema. The protected central OIDC consumer still reads a top-level `.token` from the exchange response while Noema's stable success envelope exposes the credential under `data.token`; that consumer defect remains central-owned and is not repaired by weakening or reshaping Noema's stable envelope.
`wrangler.toml` is the canonical repository copy of the currently audited `ALLOWED_WORKFLOW_SHA`; this architecture document deliberately does not duplicate that mutable 40-character value. GitHub OIDC `job_workflow_sha` binds the caller to the exact protected central `.github` repository commit selected by `refs/heads/main`, not merely to the bytes of one workflow file. Therefore every protected central ref movement requires a fresh comparison before Noema may move the runtime trust pin, even when the intervening commit changes only unrelated files. The audit must compare the new protected source tip, the trusted `noema-review.yml` workflow, the review-gate implementation it invokes, central Security Scan authority, and the intervening source-tree delta. Audit-specific SHAs and file deltas belong in the active PR/review evidence rather than this canonical architecture document so later unrelated central commits cannot silently make architecture prose stale. The current central Noema workflow must continue to resolve its trusted source to an immutable workflow commit before materialization, reject stale pull-request heads before credential/model setup, and keep model evaluation separate from publication. Noema advances or rolls back its repository-commit trust pin only after those checks succeed.

The central repository remains a read-only dependency from Noema. A central OIDC consumer mismatch, reviewer-token lifecycle defect, or scanner-control defect remains central-owned: Noema does not weaken or reshape its producer envelope, reviewer boundary, or source-authentication semantics to compensate for a foreign consumer/control-plane defect.

The configured workflow ref and source SHA are operator authority bytes, not normalization input. The protected workflow-ref parser and authoritative verifier do not trim whitespace from these trust values before validation/comparison. A whitespace-bearing value therefore fails as unusable configuration rather than being normalized into a different trusted identity. On an active PR head this statement is candidate truth if the corresponding source delta is not yet on the live protected base.

Expand Down
5 changes: 4 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
# Changelog

## Unreleased
- 중앙 `.github` protected `main`이 `b4eec000d21084accb736d289eb64cfd78e7a91a`에서 `78271917b526469c559fa75cb5ee39426e5494d1`로 이동함에 따라 `ALLOWED_WORKFLOW_SHA` immutable OIDC 신뢰 pin을 재감사·갱신한다. 두 revision의 `.github/workflows/noema-review.yml` Git blob은 동일(`30c9e9a5173215aa685bc154db01e5988219aae5`)하고, 개재된 5개 protected commit은 dependency-review 통합, OpenCode superseded-poll 종료 처리, 완료된 source-fix workflow/script 정리만 변경한다. 워크플로 bytes가 같아도 GitHub OIDC `job_workflow_sha`는 정확한 repository commit identity에 결합되므로 runtime trust pin은 현재 protected source commit으로 이동한다.
- 중앙 `.github` protected `main`이 `a819919d8bd9bc4215fee1c65f39f0aef1df9234`에서 `6f70174e338013fec9a000311bc72312f5d4dbf9`로 다시 이동함에 따라 `ALLOWED_WORKFLOW_SHA` immutable OIDC 신뢰 pin을 재차 갱신한다. 두 커밋 사이에서 신뢰된 `noema-review.yml` 워크플로 blob은 동일(`2c941983f9d846415387816c0d5ce5326bfc10ef`)했고, 개재된 4개 커밋은 `pr-review-merge-scheduler.yml`과 `opencode-review.yml`만 변경했으며 noema-review.yml이 이들을 `uses:`로 참조하지도 않으므로 Noema의 OIDC 신뢰 경계에는 영향이 없음을 확인한 뒤 pin을 이동했다.
- 중앙 `.github` protected `main`이 `1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5`에서 `a819919d8bd9bc4215fee1c65f39f0aef1df9234`로 이동함에 따라 `ALLOWED_WORKFLOW_SHA` immutable OIDC 신뢰 pin을 갱신한다. 신뢰된 `noema-review.yml` 워크플로 blob 자체는 변경되지 않았지만 GitHub `job_workflow_sha`는 정확한 저장소 커밋에 결합되므로, 중앙 소스 트리 변경이 있을 때마다 이 pin도 재감사·이동해야 한다. `ARCHITECTURE.md`는 이 휘발성 40자 값을 문서에 중복 기재하지 않고 `wrangler.toml`을 canonical 저장소 사본으로 명시하도록 갱신했으며, 배포된 `NoemaRateLimiter`/`NoemaOidcReplayGuard` SQLite Durable Object 선언을 새 migration으로 재선언하지 않는 회귀 테스트를 추가했다.
- Noema의 필수 PR 워크플로 `ci`, `reviewer-ci`, `patch-validator-image`를 부동 `ubuntu-latest` 대신 명시적 `ubuntu-24.04` GitHub-hosted runner에 고정하고, 인용 여부와 무관하게 `ubuntu-latest` 회귀를 탐지하는 계약 테스트를 추가해 pre-checkout runner-assignment stall의 repository-owned selector 원인을 제거한다. 중앙 `Security Scan`의 runner/control-plane 권한은 별도 `.github` owner 경계에 유지한다.
- 비공개 취약점 보고 감사가 16 KiB 응답 상한, bounded stream 취소, canonical repository/source identity의 독립 검증, SHA-1/SHA-256 exact revision, symlink·retained-path 보호를 실패-폐쇄로 강제한다. 이 감사 결과는 live private reporting 활성화, notification staffing, 실제 advisory 대응 또는 release/deployment 완료 증거를 대신하지 않는다.
- External scheduler evidence audits now retain source authority through final report publication: reports are owner-only, no-follow, exclusive one-shot receipts, so a concurrent rename cannot move the accepted source inode onto the report pathname and have it replaced. Source/report path and inode alias checks, single-link retained-source validation, and Unicode control sanitization remain fail closed.
Expand Down Expand Up @@ -46,7 +49,7 @@
- credential-bearing GitHub App REST 요청의 egress를 exact `https://api.github.com` origin으로 고정. 새 Worker entrypoint가 `/exchange` 전에 `GITHUB_API_BASE`의 scheme·origin·userinfo·port·path·query·fragment를 검증하고, lookalike/malformed 설정은 rate-limit·OIDC parsing·private-key 사용·GitHub API 호출 전에 `503 ERR_GITHUB_API`로 실패-폐쇄하며 허용 값도 canonical origin으로 치환한다. `/health`는 설정 복구 중에도 유지하고 원본 설정값은 응답·로그에 노출하지 않는다.
- `src/**/*.ts` 전체에 statements·branches·functions·lines 100% coverage threshold를 강제하고, `/exchange` wrapper·OIDC replay guard·distributed limiter의 fail-closed 및 malformed-decision 경계를 회귀 테스트로 고정했다. 새 source branch가 coverage를 낮추면 CI가 즉시 실패한다.
- `/exchange` distributed rate-limit identity가 없는 요청을 shared `unknown` bucket으로 합치지 않고 `503`으로 실패-폐쇄하도록 강화. Cloudflare의 `CF-Connecting-IP`가 정확히 하나의 유효한 IPv4/IPv6가 아니면 Durable Object lookup과 bearer parsing 전에 중단하고, 유효한 IPv6는 canonical form으로 정규화하여 동일 주소의 표기 차이가 rate-limit bucket을 분할하지 않도록 한다.
- CI 검증 중 공개된 `undici` 취약점 묶음(GHSA-4cwx-7wf7-3272 포함)을 제거하기 위해 Wrangler→Miniflare 경유 transitive dependency를 patched `7.29.0`으로 override하고 lockfile을 재생성했다. `npm audit --audit-level=high` 0건으로 복구하고 release gate가 취약 버전에서 실패-폐쇄하도록 유지한다.
- CI 검증 중 공개된 `undici` 취약점 묶음(GHSA-4cwx-7wf7-3272 포함)을 제거하기 위해 Wrangler→Miniflare 경유 transitive dependency를 patched `7.29.0`으로 override하고 lockfile을 재생성했다. `npm audit --audit-level=high` 0건으로 복구되고 release gate가 취약 버전에서 실패-폐쇄되도록 유지한다.
- EOL 상태인 Node.js 20을 배포 계약에서 제거하고 `engines.node >=22` 및 배포 가이드의 지원 중 LTS 요구사항을 일치시켰다.
- SQLite-backed OIDC replay guard의 alarm cleanup을 current-claim-aware 방식으로 강화. Cloudflare alarm의 at-least-once·지연·재시도 실행이 만료 후 교체된 활성 `jti` claim을 삭제하지 않도록 저장된 현재 expiry를 transactionally 재검증하고, 활성 claim이면 해당 만료 시각과 grace period로 reschedule하며 expired/empty storage만 삭제한다.
- SQLite-backed `/exchange` rate limiter의 alarm cleanup을 current-window-aware 방식으로 강화. Cloudflare alarm의 지연·재시도 실행이 새 60초 window의 활성 bucket을 삭제해 요청 예산을 조기 재개하지 않도록 저장된 window deadline을 transactionally 재검증하고, 아직 활성인 경우 실제 reset 시각으로 reschedule하며 expired/empty storage만 삭제한다.
Expand Down
6 changes: 4 additions & 2 deletions test/architecture-documentation.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ describe("authoritative architecture documentation", () => {
}
});

it("binds the code-current architecture to Wrangler state classes and immutable workflow-source configuration", () => {
it("binds the code-current architecture to Wrangler state classes without duplicating the volatile workflow-source pin", () => {
const wrangler = readFileSync("wrangler.toml", "utf8");
const architecture = readFileSync("ARCHITECTURE.md", "utf8");

Expand All @@ -43,7 +43,9 @@ describe("authoritative architecture documentation", () => {
expect(workflowSha).toBeDefined();
expect(architecture).toContain("Code-current canonical architecture");
expect(architecture).toContain("`ALLOWED_WORKFLOW_SHA`");
expect(architecture).toContain(workflowSha!);
expect(architecture).toContain("`wrangler.toml` is the canonical repository copy");
expect(architecture).toContain("deliberately does not duplicate that mutable 40-character value");
expect(architecture).not.toContain(workflowSha!);
expect(architecture).not.toContain("Active PR #426");
expect(architecture).not.toContain("not deployed truth until the PR integrates");
});
Expand Down
12 changes: 12 additions & 0 deletions test/trusted-workflow-runtime-state-preservation.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
import { readFileSync } from "node:fs";
import { describe, expect, it } from "vitest";

describe("trusted workflow source roll-forward preserves deployed runtime state declarations", () => {
it("keeps the existing Durable Object exports instead of redeclaring deployed classes as new migrations", () => {
const wrangler = readFileSync(new URL("../wrangler.toml", import.meta.url), "utf8");

expect(wrangler).toContain('[exports.NoemaRateLimiter]\ntype = "durable-object"\nstorage = "sqlite"');
expect(wrangler).toContain('[exports.NoemaOidcReplayGuard]\ntype = "durable-object"\nstorage = "sqlite"');
expect(wrangler).not.toContain("new_sqlite_classes");
Comment thread
seonghobae marked this conversation as resolved.
});
});
13 changes: 11 additions & 2 deletions test/trusted-workflow-source-rollforward.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ import { readFileSync } from "node:fs";
import { describe, expect, it } from "vitest";

const auditedCentralWorkflowSourceSha =
"1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5";
"78271917b526469c559fa75cb5ee39426e5494d1";

describe("trusted central workflow source revision", () => {
it("binds the deployed OIDC trust configuration to the audited central source commit", () => {
Expand All @@ -12,4 +12,13 @@ describe("trusted central workflow source revision", () => {
`ALLOWED_WORKFLOW_SHA = "${auditedCentralWorkflowSourceSha}"`,
);
});
});

it("keeps the mutable exact source pin single-sourced in wrangler configuration", () => {
const architecture = readFileSync(new URL("../ARCHITECTURE.md", import.meta.url), "utf8");

expect(architecture).toContain(
"`wrangler.toml` is the canonical repository copy of the currently audited `ALLOWED_WORKFLOW_SHA`",
);
expect(architecture).not.toContain(auditedCentralWorkflowSourceSha);
});
});
2 changes: 1 addition & 1 deletion wrangler.toml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ ALLOWED_AUDIENCE = "cwl-noema-review"
ALLOWED_REPOSITORY_OWNER = "ContextualWisdomLab"
ALLOWED_WORKFLOW_REPOSITORY = "ContextualWisdomLab/.github"
ALLOWED_WORKFLOW_REF_PREFIX = "ContextualWisdomLab/.github/.github/workflows/noema-review.yml@refs/heads/main"
ALLOWED_WORKFLOW_SHA = "1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5"
ALLOWED_WORKFLOW_SHA = "78271917b526469c559fa75cb5ee39426e5494d1"
GITHUB_API_BASE = "https://api.github.com"
NOEMA_RATE_LIMIT_PER_MINUTE = "60"
NOEMA_OIDC_JWKS_CACHE_TTL_SECONDS = "300"
Expand Down
Loading