Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
cd48d23
fix(opencode): keep product-file review when coverage gate fails
cursoragent Aug 16, 2026
31b1592
test(opencode): pin dispatch blob and close surface coverage gaps
cursoragent Aug 16, 2026
1841e18
fix(opencode): split status comment from review and keep model prose
cursoragent Aug 16, 2026
09bc3ad
fix(opencode): give NIM two hours and drop Copilot-class pool winners
cursoragent Aug 16, 2026
62f69f4
test(opencode): treat github-models as catalog-only, not pool winners
cursoragent Aug 16, 2026
6b9725a
fix(opencode): restore coverage-blocked status and honest class diagrams
cursoragent Aug 17, 2026
91f1447
test(opencode): retarget independent-reviewer dispatch blob pin
cursoragent Aug 17, 2026
8d4d7ed
test(opencode): retarget Strix mermaid assertions to the Python surfaces
cursoragent Aug 17, 2026
90eea34
fix(osv): stop 429 setup failures on the supplemental PR scan
cursoragent Aug 17, 2026
80bd590
fix(opencode): remove GitHub Models and fail closed on NIM
cursoragent Aug 17, 2026
f05924c
docs(opencode): reserve fail-closed orchestrator URL path
cursoragent Aug 17, 2026
6412387
fix(ci): satisfy main Strix smoke and wait out CodeQL 503s
cursoragent Aug 17, 2026
a0cf0ad
fix(ci): pass main Strix smoke and retry CodeQL init
cursoragent Aug 17, 2026
8c17723
fix(ci): drop materializer subprocess and retry Noema 503s
cursoragent Aug 17, 2026
26b72d6
fix(opencode): verify coverage identity, formal receipts, and Orgmetr…
cursoragent Aug 17, 2026
13a9fb0
test(opencode): retarget independent-reviewer dispatch blob pin
cursoragent Aug 17, 2026
2116038
test(opencode): close receipt, coverage-identity, and Noema branch gaps
cursoragent Aug 17, 2026
8c9ebf6
fix(opencode): address CodeRabbit findings on #1052 review-governance…
seonghobae Aug 18, 2026
fe3ed2a
fix(ci): correct assert_file_contains needle escaping for nvidia-nim …
seonghobae Aug 18, 2026
ff803b1
fix(opencode): treat nvidia-nim Strix windows as known report models
cursoragent Aug 18, 2026
d0b8c99
docs: add missing __init__ docstrings pulled in from main's merge
seonghobae Aug 19, 2026
453f900
fix(ci): keep retired fallback smoke lintable
seonghobae Aug 19, 2026
a4928c9
fix(opencode): remove unused GitHub Models permission
seonghobae Aug 20, 2026
e91db80
test(opencode): repin least-privilege review dispatch
seonghobae Aug 20, 2026
c97fa00
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 20, 2026
fe83dc0
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 20, 2026
529311f
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
1af53c4
fix(codeql): retry head initialization outage
seonghobae Aug 21, 2026
cd24023
fix(ci): remove unused materializer import
seonghobae Aug 21, 2026
d2ab979
fix(coverage): bind Rust materializer to base SHA (#1190)
seonghobae Aug 21, 2026
7b82aa4
fix(review): tolerate malformed Rust text
seonghobae Aug 21, 2026
ca7ab23
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
237df35
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
9b5dc3c
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
opencode-agent[bot] Aug 21, 2026
3fa76a2
test: align scheduler contract and audit runtime
seonghobae Aug 21, 2026
aa38b2d
chore(opencode): restore canonical pip lock ownership
seonghobae Aug 21, 2026
561a4f3
test(noema): reproduce private NIM visibility leak
seonghobae Aug 21, 2026
29ce7cd
fix(noema): keep private diffs off hosted NIM
seonghobae Aug 21, 2026
04604f1
fix(noema): admit governed private review endpoint
seonghobae Aug 21, 2026
98afe08
test(noema): cover private provider gate
seonghobae Aug 21, 2026
5299d32
Merge protected main into OpenCode review owner
seonghobae Aug 21, 2026
3c2b523
test(noema): cover invalid LLM hostname guard
seonghobae Aug 21, 2026
0bdc79b
Merge main into OpenCode review owner
seonghobae Aug 21, 2026
f16acaa
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
6d4915d
fix(strix): reconcile Luna-removal with main's own compat smoke-test …
seonghobae Aug 23, 2026
84b4cab
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
8f106a2
fix(coverage): install governed optional dependencies
seonghobae Aug 23, 2026
dfbf485
test(coverage): reject unsupported pnpm flag
seonghobae Aug 23, 2026
b10e20b
fix(review): slurp paginated coverage checks
seonghobae Aug 23, 2026
4aa738a
test(review): cover multi-page check receipts
seonghobae Aug 23, 2026
26c95bf
Merge remote-tracking branch 'origin/main' into cursor/opencode-revie…
seonghobae Aug 23, 2026
d01d68f
fix(opencode): preserve protected-main Strix contract
seonghobae Aug 23, 2026
d2629dc
test(ci): converge shared Strix and OpenCode quick-gate contracts
seonghobae Aug 23, 2026
4cb0e6e
test(opencode): preserve NIM-only replacement coverage
seonghobae Aug 23, 2026
fdfff41
fix(strix): recognize the hyphenated openai-direct fallback alias
seonghobae Aug 23, 2026
9147dcf
Merge remote-tracking branch 'origin/cursor/opencode-review-surfaces-…
seonghobae Aug 23, 2026
eed623e
fix(opencode): track live Strix default diagnostic
seonghobae Aug 23, 2026
766080a
test(opencode): cover live Strix default diagnostic
seonghobae Aug 23, 2026
cf065af
Merge branch 'main' into cursor/opencode-review-surfaces-1bda
seonghobae Aug 24, 2026
7403952
fix(review): classify root Rust tests as tests
seonghobae Aug 24, 2026
31e1b64
Merge protected main into OpenCode review surfaces
seonghobae Aug 24, 2026
8ea117c
fix(strix): remove shadowed direct OpenAI alias arm
seonghobae Aug 24, 2026
bf3c974
fix(opencode): hold predecessor Strix verdicts
seonghobae Aug 24, 2026
f3e43ef
fix(codeql): keep init single-shot
seonghobae Aug 24, 2026
2767946
Merge protected main into OpenCode review surfaces
cursoragent Aug 25, 2026
da8f30c
test(strix): retarget live default and fallback pins to gpt-5.4
cursoragent Aug 25, 2026
9783723
docs(strix): correct direct alias history
seonghobae Aug 25, 2026
abf47ce
Merge protected main into OpenCode review surfaces
cursoragent Aug 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .github/workflows/codeql-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,26 @@ jobs:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha }}

- name: Wait for GitHub API before CodeQL init
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
attempt=1
max_attempts=8
sleep_seconds=15
while [ "$attempt" -le "$max_attempts" ]; do
if gh api rate_limit --jq '.resources.core.limit' >/dev/null; then
echo "GitHub API is reachable on attempt ${attempt}."
exit 0
fi
echo "GitHub API was unavailable on attempt ${attempt}; retrying in ${sleep_seconds}s."
sleep "$sleep_seconds"
attempt=$((attempt + 1))
done
echo "::error::GitHub API stayed unavailable; CodeQL init cannot determine feature enablement."
exit 1
Comment thread
seonghobae marked this conversation as resolved.

Comment thread
seonghobae marked this conversation as resolved.
- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
Expand Down Expand Up @@ -196,6 +216,26 @@ jobs:
persist-credentials: false
ref: ${{ format('refs/pull/{0}/merge', github.event.pull_request.number) }}

- name: Wait for GitHub API before CodeQL init
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
attempt=1
max_attempts=8
sleep_seconds=15
while [ "$attempt" -le "$max_attempts" ]; do
if gh api rate_limit --jq '.resources.core.limit' >/dev/null; then
echo "GitHub API is reachable on attempt ${attempt}."
exit 0
fi
echo "GitHub API was unavailable on attempt ${attempt}; retrying in ${sleep_seconds}s."
sleep "$sleep_seconds"
attempt=$((attempt + 1))
done
echo "::error::GitHub API stayed unavailable; CodeQL init cannot determine feature enablement."
exit 1

- name: Initialize CodeQL
uses: github/codeql-action/init@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
with:
Expand Down
30 changes: 21 additions & 9 deletions .github/workflows/noema-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -287,15 +287,27 @@ jobs:
echo "::error::Noema reviewer credential selection succeeded but no token was minted; review cannot submit a verdict."
exit 1
fi
if [ "$TARGET_REPOSITORY_PRIVATE" = "false" ] && [ -n "${NVIDIA_NIM_API_KEY:-}" ] && [ -z "${NOEMA_LLM_API_URL:-}" ] && [ -z "${NOEMA_LLM_MODEL:-}" ]; then
export NOEMA_LLM_API_URL="https://integrate.api.nvidia.com/v1/chat/completions"
export NOEMA_LLM_MODEL="nvidia/nemotron-3-ultra-550b-a55b"
export NOEMA_LLM_API_KEY="${NVIDIA_NIM_API_KEY:-}"
fi
if [ -z "${NOEMA_LLM_API_URL:-}" ] || [ -z "${NOEMA_LLM_MODEL:-}" ] || [ -z "${NOEMA_LLM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: NOEMA_LLM_API_URL, NOEMA_LLM_MODEL, and NOEMA_LLM_API_KEY (or OPENAI_API_KEY) are required."
exit 1
fi
case "$TARGET_REPOSITORY_PRIVATE" in
false)
if [ -z "${NVIDIA_NIM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: NVIDIA_NIM_API_KEY is required so a green public-repository Noema check is a real NIM review."
exit 1
fi
export NOEMA_LLM_API_URL="https://integrate.api.nvidia.com/v1/chat/completions"
export NOEMA_LLM_MODEL="nvidia/nemotron-3-ultra-550b-a55b"
export NOEMA_LLM_API_KEY="${NVIDIA_NIM_API_KEY}"
;;
true)
if [ -z "${NOEMA_LLM_API_URL:-}" ] || [ -z "${NOEMA_LLM_MODEL:-}" ] || [ -z "${NOEMA_LLM_API_KEY:-}" ]; then
echo "::error::Noema LLM is unconfigured: a private repository requires an explicitly configured trusted NOEMA_LLM_API_URL, NOEMA_LLM_MODEL, and NOEMA_LLM_API_KEY. Private diff evidence is not sent to the hosted NVIDIA NIM endpoint."
exit 1
fi
;;
*)
echo "::error::Noema target repository visibility was missing or invalid; failing closed."
exit 1
;;
esac
python3 scripts/ci/noema_review_gate.py \
--repo "$TARGET_REPOSITORY" \
--pr-number "$PR_NUMBER"
756 changes: 378 additions & 378 deletions .github/workflows/opencode-review-dispatch.yml

Large diffs are not rendered by default.

48 changes: 45 additions & 3 deletions .github/workflows/opencode-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,49 @@ jobs:
name: opencode-review
needs: [coverage-evidence]
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
steps:
- run: >-
echo "Review approval remains a separate current-head PR review
requirement produced by the authenticated dispatch workflow."
- name: Verify current-head formal OpenCode review receipt
env:
GH_TOKEN: ${{ github.token }}
GH_PAGER: cat
TARGET_REPOSITORY: ${{ github.event.pull_request.base.repo.full_name || github.repository }}
PR_NUMBER: ${{ github.event.pull_request.number || '' }}
EXPECTED_HEAD: ${{ github.event.pull_request.head.sha || '' }}
IS_DRAFT: ${{ github.event.pull_request.draft }}
EVENT_ACTION: ${{ github.event.action }}
WORKFLOW_SHA: ${{ github.workflow_sha }}
run: |
set -euo pipefail
echo "Review approval remains a separate current-head PR review requirement produced by the authenticated dispatch workflow."
if [ "${EVENT_ACTION:-}" = "closed" ] || [ -z "${PR_NUMBER:-}" ]; then
echo "No open pull request receipt is required for this event."
exit 0
fi
if ! [[ "$TARGET_REPOSITORY" =~ ^ContextualWisdomLab/[A-Za-z0-9_.-]+$ ]] ||
! [[ "$PR_NUMBER" =~ ^[1-9][0-9]*$ ]] ||
! [[ "$EXPECTED_HEAD" =~ ^[0-9a-fA-F]{40}$ ]] ||
! [[ "$WORKFLOW_SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
echo "::error::Required OpenCode receipt gate rejected malformed live pull request or workflow identity."
exit 1
fi
trusted_archive="${RUNNER_TEMP:-/tmp}/trusted-opencode-source.tar.gz"
api_url="${GITHUB_API_URL:-https://api.github.com}"
curl -fsSL \
-H "Authorization: Bearer ${GH_TOKEN}" \
-H "Accept: application/vnd.github+json" \
-o "$trusted_archive" \
"${api_url}/repos/ContextualWisdomLab/.github/tarball/${WORKFLOW_SHA}"
tar -xzf "$trusted_archive" -C "${GITHUB_WORKSPACE:-.}" --strip-components=1
test -f scripts/ci/opencode_review_receipt_gate.py
draft_args=()
if [ "${IS_DRAFT:-false}" = "true" ]; then
draft_args=(--draft)
fi
python3 scripts/ci/opencode_review_receipt_gate.py \
--repo "$TARGET_REPOSITORY" \
--pr-number "$PR_NUMBER" \
--head-sha "$EXPECTED_HEAD" \
"${draft_args[@]}"
Comment thread
seonghobae marked this conversation as resolved.
Comment thread
seonghobae marked this conversation as resolved.
75 changes: 39 additions & 36 deletions .github/workflows/osv-scanner-pr.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Keeps the upstream OSV base/head diff check available on every PR. The
# central Security Scan workflow owns the blocking OSV result, finding logs,
# and SARIF upload so this supplemental check does not duplicate installation
# API calls or fail an otherwise clean PR when GitHub's upload quota is spent.
# Keeps a supplemental current-head OSV scan on every PR. The central Security
# Scan workflow owns the blocking OSV result, finding logs, and SARIF upload so
# this check does not duplicate installation API calls or fail an otherwise
# clean PR when GitHub rate-limits action downloads.
name: OSV-Scanner PR

on:
Expand All @@ -18,9 +18,7 @@ concurrency:

permissions:
# Scorecard Token-Permissions (alert #41): keep the workflow-level token
# read-only. SARIF upload needs security-events:write, but the osv-scan job
# below already grants it at job scope, so it is redundant (and over-broad)
# here.
# read-only. This supplemental job never uploads SARIF.
actions: read
contents: read

Expand All @@ -33,35 +31,40 @@ jobs:

osv-scan:
if: github.event.action != 'closed'
# ponytail: use upstream reusable PR workflow, don't hand-roll the diff scan
# Pinned to v2.3.8 + 1 commit (3a7550f) which gates the JSON job outputs
# behind the new `export-results` input (default false). v2.3.8 dumped the
# full old/new osv-scanner JSON into job outputs unconditionally, tripping
# GitHub's 1,048,576-byte job-outputs cap and failing the run. Same nested
# action pins as v2.3.8; only the Export step is now conditional.
uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@3a7550f43ba5b58905a821ce3a0ed24c4858b3f4 # v2.3.8 + export-results gate
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
# The pinned upstream reusable workflow declares this permission at its
# top level, so GitHub validates it even when upload-sarif is false.
security-events: write
with:
# Keep the PR code-scanning upload deterministic: direct manifest
# vulnerabilities are uploaded, but public registry rate limits cannot
# make the required upload check fail before SARIF reaches GitHub.
# The security-scan workflow still performs the full base/head OSV pass
# first and logs its --no-resolve fallback reason when registries are
# transiently unavailable.
scan-args: |-
--maven-registry=https://maven-central.storage-download.googleapis.com/maven2
--no-resolve
-r
./
# The required central security-scan.yml job uploads the comprehensive
# current-head OSV SARIF. Avoid a second upload through the reusable
# workflow because installation rate-limit failures are not findings.
upload-sarif: false
# Merge gating is done by central security-scan.yml with
# --fail-on-vuln=true after printing package, version, OSV ID and aliases.
fail-on-vuln: false
steps:
- name: Checkout current PR head
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

# Local scanner pin matches security-scan.yml. Do not call the upstream
# reusable PR workflow: it downloads the reporter action at job setup
# even when SARIF upload is disabled, and a GitHub 429 then fails this
# supplemental check before a non-blocking scan setting can apply.
- name: Scan current head with OSV
id: osv_head
continue-on-error: true
uses: google/osv-scanner-action/osv-scanner-action@a82132c0bd6c7261ffcb78e754c46c70ab57ad9a # v2.3.8
with:
# Keep the PR scan deterministic: public registry rate limits cannot
# make this supplemental check fail. The security-scan workflow still
# performs the full base/head OSV pass first and logs its --no-resolve
# fallback reason when registries are transiently unavailable.
scan-args: |-
--maven-registry=https://maven-central.storage-download.googleapis.com/maven2
--no-resolve
-r
./

- name: Defer merge gating to central Security Scan
run: |
set -euo pipefail
if [ "${{ steps.osv_head.outcome }}" = "failure" ]; then
echo "::warning::Supplemental OSV PR scan did not finish. Merge gating stays on security-scan.yml with --fail-on-vuln=true after printing package, version, OSV ID and aliases. Action-download or registry rate limits are not findings."
else
echo "Supplemental OSV PR scan finished. Merge gating stays on security-scan.yml."
fi
Comment thread
seonghobae marked this conversation as resolved.
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,11 @@ Semantic Versioning where the repository publishes a release.

## [Unreleased]

- Consolidate the already-supported `openai_direct/` and
`openai-direct/` fallback aliases into one normalization arm in
`child_model_for_api_base`. Both predecessor arms already emitted the same
`openai/<model>` child identifier; this is behavior-preserving cleanup that
keeps the two accepted spellings synchronized.
- Honor each trusted base project's exact, integrity-bearing pnpm
`packageManager` specification in OpenCode coverage images through the pinned
Node distribution's Corepack runtime, instead of admitting the specification
Expand Down Expand Up @@ -52,6 +57,8 @@ Semantic Versioning where the repository publishes a release.

### Changed

- Split central OpenCode publication into distinct surfaces: the formal pull-request review is a source-backed walkthrough of the actual diff, and the issue comment is gate/status only (head SHA, run id/attempt, coverage result, model-pool outcome, verdict, and a link to the formal review). Coverage-evidence failure no longer replaces the review or cites `.github/workflows/opencode-review.yml:1` on a product repository that did not change that file. The model pool still reviews the diff when coverage fails; REQUEST_CHANGES keeps model prose plus structured findings.
- Raise NVIDIA NIM and matching central-review run timeouts from 180s/5400s to 7200s (combined NIM budget also 7200s so one two-hour NIM attempt cannot stack seven times), raise the dynamic run-timeout cap to 7200s, and keep free-tier at 3600s. GitHub Models is removed from `opencode.jsonc` and the isolated OpenCode review catalog: no `github-models` review provider, no GPT-5 45s review path, and no review fallback when `NVIDIA_NIM_API_KEY` is unset. NIM-direct remains the OpenCode default; dispatch may attach one optional ContextualWisdomLab/contextual-orchestrator provider when `CONTEXTUAL_ORCHESTRATOR_URL` is set, without starting the sidecar or adding a GitHub Models review fallback. Strix retains protected main's independently governed, authenticated multi-provider fail-closed contract. PR-number concurrency and `cancel-in-progress: true` are unchanged.
- Emit completed repository pull-list requests as they finish in the five-minute
agent-mention sweep, while retaining the four-worker ceiling, rotation, and
exact-name dispatch ledger, so one slow repository cannot hide ready sibling
Expand Down
53 changes: 51 additions & 2 deletions ci-review-prompt.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,15 @@ green checks are not runtime-tool receipts. When no receipt exists, describe
only the source trace or explicit execution limitation; fabricating browser or
DevTools evidence invalidates the entire control block.

The formal review must name the actual changed files and what they do,
include file/line findings on the current-head diff or an explicit APPROVE
with a real walkthrough, and draw a useful sequence/class/state diagram of
the changed API rather than a generic `Changed file (N files)` inventory.
Coverage is a gate, not the review: cite coverage evidence in the status
surface and never replace the product-file walkthrough with a coverage
blocker. Never cite `.github/workflows/opencode-review.yml:1` unless that
file is in the current-head diff.

Review the diff first, then inspect surrounding code only when needed to
understand impact. Evaluate correctness, API compatibility, security/privacy,
data integrity, concurrency, error handling, observability, performance,
Expand Down Expand Up @@ -203,8 +212,48 @@ relevant source location, concrete evidence, impact, remediation, and suggested
verification. If no material issue exists, approve instead of manufacturing
comments.

Write the human-readable review first in this structure, then append the
sentinel and exactly one `opencode-review-control-v1` control block. Do not
include analysis, planning, tool-call narration, or placeholders that are not
part of this review structure.

```markdown
## Verdict

APPROVE | APPROVE_WITH_NITS | REQUEST_CHANGES | COMMENT | NEEDS_INFO

- **Confidence:** High | Medium | Low
- **Scope reviewed:** short summary of files/areas inspected
- **Commands run:** commands and brief results, or `None`
- **Risk profile:** Low | Medium | High, with one short reason

## Findings

No material issues found in the reviewed diff.
```

For each finding:

```markdown
### [P0/P1/P2/P3/Nit/FYI] Short title

- **Location:** `path/to/file.ext:line`
- **Evidence:** What in the code or command output supports this
- **Impact:** What can go wrong
- **Recommendation:** Concrete fix or direction
- **Suggested verification:** Test, command, or scenario confirming the fix
```

Then:

```markdown
## Test Gaps

No significant test gaps identified.
```

The final OpenCode output must still satisfy the existing
`opencode-review-control-v1` JSON contract required by the approval gate. Use
the reviewer rubric above for analysis and human-readable review quality, but
return the sentinel and control block exactly as requested by the workflow
the reviewer rubric above for analysis and human-readable review quality, then
append the sentinel and control block exactly as requested by the workflow
prompt, including the mandatory structured `adversarial_validation` evidence.
4 changes: 4 additions & 0 deletions code-reviewer-prompt.md
Original file line number Diff line number Diff line change
Expand Up @@ -240,3 +240,7 @@ No open questions.

Use Korean by default for human-facing prose. Keep code identifiers, file
paths, commands, error messages, and API names in their original language.

When this prompt is used from CI, write the Verdict / Findings / Test Gaps
review first, then append the workflow sentinel and `opencode-review-control-v1`
JSON. Do not omit the human review body in favor of control JSON alone.
38 changes: 38 additions & 0 deletions docs/doctoring/opencode-contextual-orchestrator-sidecar.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# OpenCode → contextual-orchestrator sidecar (next step)

검토 기준일: **2026-08-17**

## Decision

GitHub Models stays unused. The intended long-term OpenCode provider is
ContextualWisdomLab/contextual-orchestrator, an OpenAI-compatible
`/v1/chat/completions` hub. Until that sidecar exists, central review keeps
**NIM-direct** as the default (`NVIDIA_NIM_API_KEY` → `NVIDIA_API_KEY`).
`COPILOT_GITHUB_TOKEN` is not introduced.

This pull request does not start the sidecar and does not block OriginWeave
#47 quality fixes or the 7200s NIM timeout on it.

## Optional path already in dispatch

If `vars.CONTEXTUAL_ORCHESTRATOR_URL` is set,
`scripts/ci/attach_contextual_orchestrator_provider.py` attaches one
OpenAI-compatible `contextual-orchestrator` provider block to the isolated
catalog. The helper fails closed on GitHub Models hosts, embedded
credentials, non-http(s) URLs, and non-loopback `http`. Unset URL is a
no-op. Default `model` / `small_model` and `OPENCODE_MODEL_CANDIDATES`
stay NIM-direct.

## Next step (do not do it in this PR)

1. The review job starts a ContextualWisdomLab/contextual-orchestrator sidecar.
2. The sidecar registers these five organization secrets into its KV:
NIM, NIM_SUB, OpenAI, OpenRouter, and Bytez.
3. OpenCode talks only to that sidecar URL. It does not receive the five
upstream secrets and does not fall back to GitHub Models.

## References

ContextualWisdomLab/contextual-orchestrator is the org LLM routing hub
(LiteLLM-plus). See [`docs/CWL-MASTER-CONTEXT.md`](../CWL-MASTER-CONTEXT.md)
§3 and [`docs/nvidia-nim-opencode-hotfix.md`](../nvidia-nim-opencode-hotfix.md).
Loading
Loading