feat(operations): restack runner-assignment audit on deterministic toolchain - #94
Draft
seonghobae wants to merge 16 commits into
Draft
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
18 tasks
This was referenced Aug 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Clean stacked successor for superseded Draft #88 on the deterministic package-manager predecessor #91. This Draft starts from exact #91 head
ebde3720ee27292be0ce3315986e0438dd66af9fand preserves only the runner-assignment operational-evidence slice while retaining #91 package-manager/install-script/lockfile controls.Fresh exact source boundary
build/deterministic-npm-toolchain-on-main/ build(reproducibility): restack deterministic npm toolchain #91.ebde3720ee27292be0ce3315986e0438dd66af9f.f33930dcbd800ba1018a82de0151b7579d4d1b74.package.json, andCHANGELOG.md.package.jsonpreserves build(reproducibility): restack deterministic npm toolchain #91'spackageManager: npm@11.17.0, Node24.19.0, npm11.17.0, reviewedallowScriptspolicy and lockfile-control contract while adding onlyoperations:runner-assignment.CHANGELOG.mdpreserves the protected/build(reproducibility): restack deterministic npm toolchain #91 lineage and adds only the bounded runner-assignment entry.#88 was closed only after this replacement preserved its whole 10-path workstream and produced fresh application/reviewer evidence. Old #88 checks/reviews do not transfer.
Implemented evidence / credential boundary
The audit is read-only and exact-head/run-ID bound. Fully paginated
filter=alljob evidence distinguishes runner assignment from workflow/test conclusion and from dependency/environment-protection waiting:PENDING;runner_assignment_stalled;A fresh security review of the rebuilt operator found that
spawnSync("gh", …, { env: process.env })unnecessarily inherited every ambient secret/proxy/HOME setting. The test-first correction now exposes a fail-closedcreateGhSubprocessEnvironment()contract. Theghchild receives only:PATHfor executable resolution;GH_TOKEN;GH_HOST=github.com;NO_COLOR=1.Ambient
GITHUB_TOKEN,NVIDIA_NIM_API_KEY, Maintainer/Reviewer App private material, proxy variables,HOME, and unrelated process state do not cross into this diagnostic subprocess. The retained report is credential-free and explicitly has no required-check, formal-review, merge, release, or deployment authority.Fresh exact-head verification
For unchanged exact head
f33930dcbd800ba1018a82de0151b7579d4d1b74on live baseebde3720ee27292be0ce3315986e0438dd66af9f:cirun31378914501: terminal success;reviewer-cirun31378914523: terminal success;f33930dcbd800ba1018a82de0151b7579d4d1b74and live base before/after verification;24.19.0/ npm11.17.0; lockfile change control passed with zero changed package nodes;npm ci --legacy-peer-deps=false --install-links=false: 0 vulnerabilities;release:verify: 75 test files / 712 tests passed, configured statements/branches/functions/lines all 100%,npm audit --audit-level=high0 vulnerabilities;SKIPbecause no production 30-day log is present; this is not operational/acquisition PASS;Central
Security Scanremains absent because this PR targets a feature base. That absence is non-passingdefer_until_trigger, not scanner success and not automatically an infrastructure failure.Dependency / merge sequence
This PR remains Draft because its base is #91's feature branch. Safe integration order is:
mainunder actual live governance;Historical organization billing/runner-group/enterprise-policy cause remains unresolved unless authorized evidence proves it. No repair/self-modifying workflow, protection weakening, synthetic approval, force push, version bump or release is introduced.
Related: #27, #30, #77, #79, #88, #91