Skip to content

fix(context-fabric): require source-bound release attestation - #544

Draft
seonghobae wants to merge 16 commits into
mainfrom
fix/context-release-source-attestation-admission
Draft

fix(context-fabric): require source-bound release attestation#544
seonghobae wants to merge 16 commits into
mainfrom
fix/context-release-source-attestation-admission

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Scope

Strengthen Noema's Context Graph consumer ACL without copying context-graph-contracts source or treating mutable producer PRs as authority. Noema requires exact release-source manifest + independently retained attestation digests, protected source ref and signer workflow, canonical Context Assertion/CloudEvent profile identities, and versioned context-assertion-envelope-preserving-admission-v1 capability evidence. Cross-service SQL, mutable producer source, provider routing and foreign security authority remain out of scope.

Retained TDD lineage

RED 1e2603bb... → production 20b8bead... bound exact protected-source manifest/attestation evidence; RED 834b4ac8...4f04a78a... added finite canonical capability metadata; RED e0f0dc0b...c72ce1cb... added versioned envelope-preserving admission. Hosted fitness failures were repaired without weakening immutable-release semantics. The latest predecessor showed a Markdown-sensitive raw-substring fixture; d5ecf8331d78db1e5d1b5505e818a1f8aed01076 strips backticks only for the semantic assertion while preserving the exact immutable released context-graph-contracts requirement.

Current exact authority — 2026-09-06 KST

  • protected Noema base: main@e1ac9d50f6c646f04be8c137c8acdc7200182fcd;
  • exact PR head: d5ecf8331d78db1e5d1b5505e818a1f8aed01076;
  • lifecycle: open / Draft;
  • exact-head application ci 33952078330, required Security Scan 33952078410, reviewer-ci 33952078464, and patch-validator-image 33952078542 are terminal success;
  • repository-wide semantic-review prerequisite is fix(reviewer): fail closed on empty CodeGraph semantics #546 exact 95144d5bcf8f1cb4b9a7c552ede66737c23d6bca. The reviewer success above predates that repaired semantic-evidence contract reaching protected truth, so it is workflow-surface evidence rather than merge-authoritative semantic GREEN.

Keep the source unchanged and Draft. After #546 reaches protected truth, regenerate semantic reviewer evidence for this exact head and re-read current governance. Do not promote mutable producer evidence, weaken the release attestation contract, source-churn for runners, self-approve, rewrite history, or absorb Context Graph/CO/security owner authority.

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Fresh protected-base repair supersedes the stale authority block above. Protected main is now e1ac9d50f6c646f04be8c137c8acdc7200182fcd. Ordinary two-parent non-force merge 9a064db4b38314728fd985249e3643c1f12ca435 preserves the complete #544 Context Graph release-attestation delta and inherits only the protected stateless GitHub installation-token regression. Current exact-head workflows are ci 33871855445, reviewer-ci 33871855476, required Security Scan 33871855442, and patch-validator-image 33871855421; all are queued/non-passing. Predecessor evidence does not transfer; keep Draft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant