Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/mightyetl-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
Expand All @@ -29,6 +30,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_mightyetl_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -54,6 +56,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/mightyetl-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -66,6 +69,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/mightyetl-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
Expand All @@ -82,6 +86,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_mightyetl_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -107,6 +112,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/mightyetl-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -164,6 +170,7 @@ jobs:
tests/test_orgmetra_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_mightyetl_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/mightyetl-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: mightyETL Hourly Review Repair

on:
schedule:
# Minute 8 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4),
# codec-carver (5), life-os (6), Wardnet (7), naruon (11),
# pg-erd-cloud (13), orchestrator (17), noema (19), Clearfolio (23),
# Keyverse (29), Scopeweave (31), DiskSage (37), Appguardrail (41),
# newsdom-api (43), Inkspan (47), fast-mlsirm (49), BandScope (53),
# and semantic-data-portal (59).
Comment on lines +5 to +10

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Schedule-avoidance comment lists cross-repo minute allocations, not this repo's

The scheduling comment in mightyetl-hourly-review-repair.yml claims minute 8 avoids e.g. Wardnet (7), but within this repo minute 7 is actually taken by organization-commercial-readiness-loop.yml. This is an org-wide minute-allocation ledger comment, not a per-repo conflict list, so it does not affect correctness (minute 8 is genuinely unique among this repo's scheduled workflows). Noting for awareness only in case the org intends this comment to stay accurate.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +5 to +10

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Minute-8 avoidance comment omits neighbors already documented elsewhere

The cron comment in mightyetl-hourly-review-repair.yml lists minutes it avoids but omits psychometrics-commons (9) and OriginWeave (10), which sibling callers (e.g. nonnest2/originweave) do list. This is cosmetic only: minute 8 is verified unique across all scheduled workflows, so there is no actual collision. No contract test asserts the comment body, so this does not break CI. Noting for consistency, not as a defect.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

- cron: "8 * * * *"
Comment on lines +1 to +11

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: New caller not added to docs/automation/hourly-review-repair.md

This PR registers the new caller in the quality workflow path filters and CLAUDE.md, but does not add it to docs/automation/hourly-review-repair.md, which enumerates other callers (e.g. clearfolio at minute 23). I confirmed no contract test globs/enumerates all callers against that guide, so this is not a CI failure. Flagging only as a documentation-completeness follow-up for operator visibility.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Cron minute 8 does not collide with existing hourly callers

Verified all sibling hourly-review-repair workflows use distinct cron minutes (27, 53, 23, 37, 49, 21, 43, 16, 10, 14) and none use minute 8, so the new mightyetl caller's cron: "8 * * * *" avoids overlap. The OriginWeave caller's doctoring comment even already reserves minute 8 for mightyETL, so the scheduling is consistent.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


concurrency:
group: mightyetl-hourly-review-repair
# A later heartbeat must not cancel an in-flight CDC or ETL RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/mightyETL
base_branch: develop
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
Comment on lines +26 to +35

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Caller inputs match the reusable scheduler contract

All with: inputs (target_repository, base_branch, max_prs, max_dispatches, retry_hours) and both mapped secrets are declared in .github/workflows/pr-review-fix-scheduler.yml's workflow_call interface, and base_branch: develop matches the doctoring record. The caller stays thin and delegates all logic to the shared scheduler, consistent with sibling callers.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ repeatable compile command.
without running the test suite will break CI.
- **100% coverage and 100% docstrings on `scripts/ci/`** are hard gates, not aspirations. New helper
code needs matching tests and docstrings.
- **Product hourly callers** stay thin. Do not hard-code OriginWeave, naruon, or Keyverse
- **Product hourly callers** stay thin. Do not hard-code OriginWeave, mightyETL, naruon, or Keyverse
into `pr-review-fix-scheduler.yml`. The model credential remains `NVIDIA_NIM_API_KEY`
on the worker, never `COPILOT_GITHUB_TOKEN`.
- **`pull_request_target` trust boundary.** The required review workflows run the *base branch's*
Expand Down
140 changes: 140 additions & 0 deletions docs/doctoring/mightyetl-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
# mightyETL hourly review-repair caller

검토 기준일: **2026-08-17**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/mightyETL` (microservices CDC and bounded ETL
platform). The caller runs at minute 8, delegates to the product-neutral
central review-fix scheduler, inspects at most 50 open pull requests
targeting protected `develop`, and dispatches at most one bounded repair
per heartbeat.

A paying buyer of change-data-capture pipelines would feel live mightyETL
pull requests stalling while hourly NVIDIA NIM repair scanned only
Clearfolio, DiskSage, and fast-mlsirm. Live heads such as
ContextualWisdomLab/mightyETL#327 (blank Config Server authority),
ContextualWisdomLab/mightyETL#326 (hourly maintenance on develop),
ContextualWisdomLab/mightyETL#322 (explicit Config Server authority),
and ContextualWisdomLab/mightyETL#321 (confidential CDC probe
diagnostics) target `develop` and never enter those other callers.

The caller does not implement review or mutation logic itself. mightyETL
remains standalone; naruon and other CWL services consume transformed
records without owning the CDC runtime. Privileged automation stays in
`ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack
order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding CDC
evidence when the next hourly heartbeat arrives. The reusable scheduler
cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus Config Server or replication-probe analysis, can
legitimately approach two hours. An hourly redispatch of the same
unchanged head would create duplicate writer pressure rather than faster
remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can request
a GitHub OIDC JWT. The scheduler governs any subsequent credential exchange
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. The caller
applies least privilege to prevent CWE-250 by excluding write and model
privileges it does not need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or
forward it.

Before protected-develop activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/mightyETL` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no mightyETL runtime dependency, database object, network
endpoint, tenant authority, or product credential. mightyETL continues to
run as a standalone CDC/ETL platform. Naruon and other CWL services may
consume its output, but they cannot weaken its exact-head, approval, or
security gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 8
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and `compileall`
path blocks must each name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled protected-develop
consumer run proving the exact mightyETL repository and
`develop` base. Source checks alone are not protected-develop operational acceptance.
Merge still requires zero unresolved valid findings and a
qualifying independent non-author approval.

Rollback removes the mightyETL caller, its focused test, doctoring, and
central path-filter/documentation entries. It must not remove scheduler
dispatch validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
17, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *OpenID Connect reference*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/reference/security/oidc

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 17, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026,
from https://opencode.ai/docs/
6 changes: 3 additions & 3 deletions requirements-pip-audit-ci-hashes.txt
Original file line number Diff line number Diff line change
Expand Up @@ -213,9 +213,9 @@ packaging==26.2 \
# via
# pip-audit
# pip-requirements-parser
pip==26.1.2 \
--hash=sha256:382ff9f685ee3bc25864f820aa50505825f10f5458ffff07e30a6d96e5715cab \
--hash=sha256:f49cd134c61cf2fd75e0ce2676db03e4054504a5a4986d00f8299ae632dc4605
pip==26.2.1 \
--hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c42108c0384ed3e \
--hash=sha256:f6ad667e89a1fe78046c8f13232b247200f5258d7828f3f7883d660878e0813f
Comment on lines +216 to +218

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Unrelated pip bump in pip-audit hashes file

requirements-pip-audit-ci-hashes.txt bumps pip 26.1.2→26.2.1 with new hashes — the only dependency change in an otherwise config/docs PR. CLAUDE.md requires regenerating -hashes.txt files via uv pip compile, never hand-editing. Confirm this was regenerated with the recorded command and the hashes are correct, since a bad pin breaks the --require-hashes install.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

# via pip-api
pip-api==0.0.34 \
--hash=sha256:8b2d7d7c37f2447373aa2cf8b1f60a2f2b27a84e1e9e0294a3f6ef10eb3ba6bb \
Expand Down
Loading
Loading