-
Notifications
You must be signed in to change notification settings - Fork 0
feat(automation): run Scopeweave hourly NVIDIA NIM review repair #1078
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
6e66bcd
b20edee
820e2ab
b48509e
26b684b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| name: Scopeweave Hourly Review Repair | ||
|
|
||
| on: | ||
| schedule: | ||
| # Minute 31 avoids Clearfolio (23), DiskSage (37), fast-mlsirm (49), | ||
| # BandScope (53), naruon (11), Inkspan (47), orchestrator (17), | ||
| # Wardnet (7), codec-carver (5), pg-erd-cloud (13), Keyverse (29), | ||
| # and noema (19). | ||
| - cron: "31 * * * *" | ||
|
|
||
| concurrency: | ||
| group: scopeweave-hourly-review-repair | ||
| # A later heartbeat must not cancel an in-flight WBS or ITSM RCA. | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| dispatch-review-repair: | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| uses: ./.github/workflows/pr-review-fix-scheduler.yml | ||
| with: | ||
| target_repository: ContextualWisdomLab/scopeweave | ||
| base_branch: develop | ||
| max_prs: "50" | ||
| max_dispatches: "1" | ||
| retry_hours: "2" | ||
| secrets: | ||
| PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }} | ||
| OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }} | ||
|
Comment on lines
+1
to
+33
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: New Scopeweave caller matches sibling caller contract The new scopeweave-hourly-review-repair.yml mirrors the established sibling callers (e.g. Was this helpful? React with 👍 or 👎 to provide feedback.
Comment on lines
+24
to
+33
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Caller inputs match reusable scheduler contract The caller passes Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -867,16 +867,27 @@ jobs: | |
|
|
||
| # Recognized signals that the LLM backend was unavailable / starved. | ||
| backend_unavailable_signal='RateLimitError|Too many requests\. For more on scraping GitHub|exceeded your current quota|insufficient_quota|billing details|"status"[[:space:]]*:[[:space:]]*"RESOURCE_EXHAUSTED"|tokens_limit_reached|Request body too large|Max size:[[:space:]]*[0-9]+[[:space:]]+tokens|Error code:[[:space:]]*413|LLM CONNECTION FAILED|Could not establish connection to the language model|LLM warm-up failed|Configured model and fallback models were unavailable|Configured Vertex model and fallback models were unavailable|emitted provider infrastructure or failure-signal output|before provider infrastructure failure|litellm(\.exceptions)?\.NotFoundError[^[:cntrl:]]*Nvidia_nimException[^[:cntrl:]]*Error code:[[:space:]]*404' | ||
| # Any evidence that a vulnerability was actually reported. Its presence | ||
| # forces a hard failure so real findings are NEVER downgraded. Keep the | ||
| # severity branch anchored away from identifiers so environment lines | ||
| # such as STRIX_FAIL_ON_MIN_SEVERITY do not look like findings. | ||
| reported_vulnerability_signal='Vulnerabilities[[:space:]]+[1-9]|(^|[^A-Za-z0-9_])severity[[:space:]]*:' | ||
| # Only medium-or-higher findings are blocking evidence. Low and INFO | ||
| # reports are retained as artifacts but do not block merge progress; | ||
| # the configured Strix threshold is MEDIUM. Keep the severity branch | ||
| # anchored away from identifiers such as STRIX_FAIL_ON_MIN_SEVERITY. | ||
| reported_vulnerability_signal='(^|[^A-Za-z0-9_])severity[[:space:]]*:[[:space:]]*(critical|high|medium)([^A-Za-z0-9_]|$)' | ||
|
Comment on lines
+870
to
+874
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟨 Strix security gate no longer blocks on reported vulnerability counts during backend outages The Strix gate's Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| # Workflow-only callers can legitimately produce an informational | ||
| # "no assessable application code" report. It is not a vulnerability | ||
| # signal and must remain neutral unless a medium-or-higher finding is | ||
| # also present in the same run. | ||
| non_assessable_scope_signal='No Assessable Application Code Found in Scope' | ||
| if grep -Eiq "$non_assessable_scope_signal" "$strix_run_log" \ | ||
| && ! grep -Eiq "$reported_vulnerability_signal" "$strix_run_log"; then | ||
| echo "::warning title=Strix scope not assessable::Strix received workflow-only scope and produced no medium-or-higher vulnerability evidence; treating the informational scope result as neutral." | ||
| exit 0 | ||
| fi | ||
|
|
||
| # Neutral skip only when ALL hold: a backend-unavailability signal is | ||
| # present and no vulnerability was reported anywhere. This preserves | ||
| # real security gating while keeping uncontrollable provider outages | ||
| # from blocking current-head merge progress. | ||
| # present and no medium-or-higher vulnerability was reported. This | ||
| # preserves real security gating while keeping uncontrollable provider | ||
| # outages from blocking current-head merge progress. | ||
| if grep -Eiq "$backend_unavailable_signal" "$strix_run_log" \ | ||
| && ! grep -Eiq "$reported_vulnerability_signal" "$strix_run_log"; then | ||
| echo "::warning title=Strix backend unavailable::Strix could not complete because its LLM backend was unavailable (rate limit / token cap / connection or warm-up failure) before producing a vulnerability report. Treating as a neutral skip so an infrastructure outage does not block merges; genuine findings still fail the check. See the strix-reports artifact and the run log." | ||
|
Comment on lines
+870
to
893
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔍 Strix gate change is undocumented in CHANGELOG and outside the PR's stated scope This PR is described as adding the Scopeweave hourly caller, but it also materially changes the shared Strix security gate in strix.yml (medium-or-higher-only blocking plus a new non-assessable-scope neutral exit). This gate is shared across every sibling repo, so the behavioral change affects all repositories, not just Scopeweave. It is not recorded in CHANGELOG.md (only the Scopeweave caller entry was added at CHANGELOG.md). Reviewers should confirm the gate change is intended to ship in this PR and add a corresponding changelog entry. (Refers to this code) Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| Original file line number | Diff line number | Diff line change | ||||||
|---|---|---|---|---|---|---|---|---|
|
|
@@ -119,6 +119,7 @@ repeatable compile command. | |||||||
| - **100% coverage and 100% docstrings on `scripts/ci/`** are hard gates, not aspirations. New helper | ||||||||
| code needs matching tests and docstrings. | ||||||||
| - **Product hourly callers** stay thin. Do not hard-code OriginWeave, naruon, or Keyverse | ||||||||
| - **Product hourly callers** stay thin. Do not hard-code Scopeweave, naruon, or Keyverse | ||||||||
|
Comment on lines
121
to
+122
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 Guidance document left with a duplicated, incomplete instruction line A near-duplicate bullet was inserted ( Botched find-and-replace in the conventions listBefore the change the list had a single bullet: "Product hourly callers stay thin. Do not hard-code OriginWeave, naruon, or Keyverse into
Suggested change
Was this helpful? React with 👍 or 👎 to provide feedback. |
||||||||
| into `pr-review-fix-scheduler.yml`. The model credential remains `NVIDIA_NIM_API_KEY` | ||||||||
| on the worker, never `COPILOT_GITHUB_TOKEN`. | ||||||||
| - **`pull_request_target` trust boundary.** The required review workflows run the *base branch's* | ||||||||
|
|
||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,140 @@ | ||
| # Scopeweave hourly review-repair caller | ||
|
|
||
| 검토 기준일: **2026-08-17** | ||
|
|
||
| ## Decision | ||
|
|
||
| ContextualWisdomLab operates one protected hourly caller for | ||
| `ContextualWisdomLab/scopeweave` (issue and WBS management plus ITSM | ||
| Service Request: requester ticket ↔ team issues). The caller runs at | ||
| minute 31, delegates to the product-neutral central review-fix scheduler, | ||
| inspects at most 50 open pull requests targeting protected `develop`, and | ||
| dispatches at most one bounded repair per heartbeat. | ||
|
|
||
| A paying buyer of the work-item plane would feel live scopeweave pull | ||
| requests stalling while hourly NVIDIA NIM repair scanned only Clearfolio, | ||
| DiskSage, and fast-mlsirm. Live heads such as | ||
| ContextualWisdomLab/scopeweave#545 (70B NIM output cap), | ||
| ContextualWisdomLab/scopeweave#531 (SQLite backup rehearsal), | ||
| ContextualWisdomLab/scopeweave#529 (adaptive orchestration default), and | ||
| ContextualWisdomLab/scopeweave#523 (exact-head Server Tests) target | ||
| `develop` and never enter those other callers. | ||
|
|
||
| The caller does not implement review or mutation logic itself. | ||
| Scopeweave remains standalone; naruon extracts issues but does not own | ||
| the WBS runtime. Privileged automation stays in | ||
| `ContextualWisdomLab/.github`. | ||
|
|
||
| ## Root-cause analysis and remediation feasibility | ||
|
|
||
| The reusable worker performs exact-head root-cause analysis and tests | ||
| remediation feasibility before it edits. The reusable worker must: | ||
|
|
||
| 1. Refetch the exact live head, base, reviews, checks, changed paths, and | ||
| writer state. | ||
| 2. Establish the causal chain rather than repeat the terminal symptom. | ||
| 3. Enumerate materially distinct minimal remedies. | ||
| 4. Reject remedies that lack writer authority, cross sealed paths, require | ||
| unavailable credentials or protected-setting changes, violate stack | ||
| order, cannot be verified, or do not alter the diagnosed cause. | ||
| 5. Dispatch at most one feasible repair. Otherwise leave the tree | ||
| unchanged. | ||
|
|
||
| A queued or pending check remains a merge blocker but is not itself a | ||
| code finding. The independent non-author approval remains an external | ||
| authorization gate and is never synthesized by the repair worker. The | ||
| worker cannot approve, merge, release, resolve review findings by | ||
| inference, change protection, or manufacture passing checks. | ||
|
|
||
| ## Cadence and concurrency | ||
|
|
||
| The caller uses a single concurrency group and `cancel-in-progress: false`. | ||
| This preserves an in-flight bounded RCA instead of discarding WBS | ||
| evidence when the next hourly heartbeat arrives. The reusable scheduler | ||
| cancels only its own superseded short queue scan. | ||
|
|
||
| The caller sets a **two-hour same-head retry floor**. Central OpenCode and | ||
| NVIDIA NIM work, plus backup or planning-default analysis, can | ||
| legitimately approach two hours. An hourly redispatch of the same | ||
| unchanged head would create duplicate writer pressure rather than faster | ||
| remediation. | ||
|
|
||
| GitHub scheduled workflows can be delayed under load and execute only | ||
| from the default branch. The cron expression is a heartbeat, not a | ||
| real-time SLA. | ||
|
|
||
| ## Credential and model boundary | ||
|
|
||
| The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants | ||
| the reusable job `id-token: write` so the central scheduler can mint the | ||
| OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent | ||
| (GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and | ||
| `OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives | ||
| `NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250 | ||
| forbids executing the caller with write or model privileges it does not | ||
| need (MITRE, 2026). | ||
|
|
||
| Model execution remains inside the central worker. The model credential | ||
| is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or | ||
| forward it. | ||
|
|
||
| Before protected-develop activation, the repository variable | ||
| `OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact | ||
| `ContextualWisdomLab/scopeweave` target. Missing or mismatched | ||
| configuration fails before mutation credential materialization. | ||
|
|
||
| ## Security, standalone operation, and modularity | ||
|
|
||
| The caller adds no scopeweave runtime dependency, database object, | ||
| network endpoint, tenant authority, or product credential. Scopeweave | ||
| continues to run as a standalone work-item service. Naruon and other CWL | ||
| services may feed extracted issues into it, but they cannot weaken its | ||
| exact-head, approval, or security gates. | ||
|
|
||
| ## Verification and rollback | ||
|
|
||
| Machine-checkable contracts require the exact target/base, minute 31 | ||
| cadence, non-cancelling single-flight group, one dispatch, two-hour | ||
| retry floor, explicit secret mapping, read-only contents plus job-scoped | ||
| `id-token: write`, focused path-filter coverage, and absence of model or | ||
| Copilot credentials. Independent `pull_request`, `push`, and `compileall` | ||
| path blocks must each name the caller, doctoring, or contract they own. | ||
|
|
||
| After source integration, closure requires a scheduled or manual | ||
| protected-develop consumer run proving the exact scopeweave repository and | ||
| `develop` base. Source checks alone are not protected-develop operational acceptance. | ||
| Merge still requires zero unresolved valid findings and a | ||
| qualifying independent non-author approval. | ||
|
|
||
| Rollback removes the scopeweave caller, its focused test, doctoring, and | ||
| central path-filter/documentation entries. It must not remove scheduler | ||
| dispatch validation or affect independent product callers. | ||
|
|
||
| ## APA 7th references | ||
|
|
||
| GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule | ||
|
|
||
| GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August | ||
| 17, 2026, from | ||
| https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows | ||
|
|
||
| GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token | ||
|
|
||
| MITRE. (2026). *CWE-250: Execution with unnecessary privileges*. | ||
| https://cwe.mitre.org/data/definitions/250.html | ||
|
|
||
| National Institute of Standards and Technology. (2022). *Secure software | ||
| development framework (SSDF) version 1.1: Recommendations for mitigating | ||
| the risk of software vulnerabilities* (NIST Special Publication 800-218). | ||
| https://doi.org/10.6028/NIST.SP.800-218 | ||
|
|
||
| NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.nvidia.com/nim/large-language-models/latest/ | ||
|
|
||
| OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, | ||
| from https://opencode.ai/docs/ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Cron minute 31 does not collide with existing hourly callers
The new caller uses
cron: "31 * * * *"(scopeweave-hourly-review-repair.yml). I enumerated all cron schedules across.github/workflows/and confirmed minute 31 is not used by any other hourly review-repair caller (existing minutes: 5,7,10,11,13,14,16,17,19,21,23,27,29,37,43,47,49,53). The staggering comment omits several existing callers (OriginWeave 10, nonnest2 16, quarantine 14, github 21, governance 43, accounting 27) but the chosen slot is genuinely free, so this is not a bug.Was this helpful? React with 👍 or 👎 to provide feedback.