ci: separate trusted policy from repository verification - #16
Conversation
Preserve required checks, protected paths and owner approval while removing product-layout coupling. Add central self-CI, repository-owned verification isolation, live settings inspection and regression coverage. Tracks openboa-ai/coffee-chat-bench#78.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a61d41c9fe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2b9e474102
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ae10f86e58
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 49f70374a4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f18eef7ae2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 00d7a0ee32
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8b48ca8e35
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 72b878212e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fc9efaf2ba
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please re-review unchanged head fc9efaf and reassess the normal-CI finding using the evidence in its inline reply. Repository normal CI already runs in the mandatory |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fc9efaf2ba
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Delivery status
Merged as 5b4d641 after the owner's explicit initial-landing approval. Codex completed reviewed head 23c840d without findings at 2026-09-08T23:30:28Z and posted a thumbs-up; all twelve review threads are resolved (eleven fixes and one source-backed no-change disposition).
Actual central main CI passed: https://github.com/openboa-ai/.github/actions/runs/34291035106 (job 102277398818). Logs verify the exact merge SHA, tested tree 6146355f63e2b436be685731f698b33ca5b0ddb2, all 28 regressions with zero skips/failures, successful workflow lint, and trusted Gitleaks scanning 38 history commits plus candidate files with no leaks. The named check reports completed/success from GitHub Actions. The review/fix/merge/main-CI monitor is stopped.
No target repository was published or migrated, and no GitHub ruleset, environment or required check was changed or bypassed. Those rollout decisions remain separate. The evidence and initial-rollout discussion below record the preparation and pre-landing gap; they do not mean all Coffee repositories are deployed.
Outcome
Separate shared security and approval policy from repository-owned quality verification across the four Coffee Chat repositories. This supersedes this PR's earlier directory-specific Bench admission patch; it does not create another PR.
Changes
Verified evidence
Candidate commit: 23c840d
Tested tree: 6146355f63e2b436be685731f698b33ca5b0ddb2
Review fixes
Rollout gate
The owner explicitly approved the exact remaining SECURITY.md correction and initial landing of this existing PR once latest-head Codex re-review has no additional actionable findings, followed by actual central main CI verification. This authorization does not permit changing settings, bypassing required checks, or publishing target repositories. New source code is not proof of live GitHub enforcement.
The candidate-owned supplementary pull_request workflow was removed after review identified that its author could replace host orchestration before any guard/container. Its earlier passing runs are historical candidate evidence, not current-head or trusted CI. The actual base f33da6b has no central CI entry point; latest-head GitHub CI is unavailable, not passing. Complete latest-head Codex review and retain exact-tree local regression/lint/secret-scan/isolation evidence for owner review of the initial landing. Do not fabricate success or bypass required checks. After owner-reviewed landing, observe trusted central main CI before selecting its final SHA for callers. Then align reviewer/ruleset settings and migrate exact target PRs without removing required checks, using only an explicitly approved, scoped and expiring exception where an old pin blocks its own transition. Existing quality/coverage rules remain untouched.
Target implementations are prepared in isolated local commits, not published as Ground Truth and not claimed merged. Product/Judge performance is outside this work.
Tracks openboa-ai/coffee-chat-bench#78.