Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/workflows/appguardrail-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: appguardrail Hourly Review Repair

on:
schedule:
# Minute 41 is the roster slot already reserved for Appguardrail across
# the hourly callers (see afipc/nonnest2/originweave cron comments). It
# avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4),
# codec-carver (5), life-os (6), Wardnet (7), mightyETL (8),
# psychometrics-commons (9), OriginWeave (10), naruon (11),
# DiagramWeave (12), pg-erd-cloud (13), mhtml-etl-gateway (14),
# html4tree (15), nonnest2 (16), orchestrator (17), noema (19),
# Clearfolio (23), Keyverse (29), Scopeweave (31), DiskSage (37),
# newsdom-api (43), macOS utility packs (44), Inkspan (47),
Comment thread
seonghobae marked this conversation as resolved.
# fast-mlsirm (49), BandScope (53), and semantic-data-portal (59).
- cron: "41 * * * *"

concurrency:
group: appguardrail-hourly-review-repair
# A later heartbeat must not cancel an in-flight scan RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/appguardrail
base_branch: develop

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 base_branch develop differs from sibling callers

Both new callers use base_branch: develop, whereas every existing caller uses master/main. The doctoring documents develop consistently, so this reads as intentional, but it depends on the target repos actually protecting develop and on OPENCODE_REPOSITORY_DISPATCH_TARGETS being updated out-of-band.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
14 changes: 14 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,8 @@ on:
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/afipc-hourly-review-repair.yml
- .github/workflows/appguardrail-hourly-review-repair.yml
- .github/workflows/macos_utility_packs-hourly-review-repair.yml
Comment thread
seonghobae marked this conversation as resolved.
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -33,6 +35,8 @@ on:
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_contextual_orchestrator_hourly_review_caller.py
- tests/test_afipc_hourly_review_caller.py
- tests/test_appguardrail_hourly_review_caller.py
- tests/test_macos_utility_packs_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand Down Expand Up @@ -60,6 +64,8 @@ on:
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/contextual-orchestrator-hourly-review-caller.md
- docs/doctoring/afipc-hourly-review-caller.md
- docs/doctoring/appguardrail-hourly-review-caller.md
- docs/doctoring/macos-utility-packs-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -78,6 +84,8 @@ on:
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/afipc-hourly-review-repair.yml
- .github/workflows/appguardrail-hourly-review-repair.yml
- .github/workflows/macos_utility_packs-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -92,6 +100,8 @@ on:
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_contextual_orchestrator_hourly_review_caller.py
- tests/test_afipc_hourly_review_caller.py
- tests/test_appguardrail_hourly_review_caller.py
- tests/test_macos_utility_packs_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand Down Expand Up @@ -119,6 +129,8 @@ on:
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/contextual-orchestrator-hourly-review-caller.md
- docs/doctoring/afipc-hourly-review-caller.md
- docs/doctoring/appguardrail-hourly-review-caller.md
- docs/doctoring/macos-utility-packs-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -178,6 +190,8 @@ jobs:
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_contextual_orchestrator_hourly_review_caller.py \
tests/test_afipc_hourly_review_caller.py \
tests/test_appguardrail_hourly_review_caller.py \
tests/test_macos_utility_packs_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
39 changes: 39 additions & 0 deletions .github/workflows/macos_utility_packs-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: macOS utility packs Hourly Review Repair

on:
schedule:
# Minute 44 is a fresh roster allocation for the macOS utility packs
# bootstrap. It avoids pg-llm-batch (1), aFIPC (2), kaefa (3),
# LineageWeave (4), codec-carver (5), life-os (6), Wardnet (7),
# mightyETL (8), psychometrics-commons (9), OriginWeave (10),
# naruon (11), DiagramWeave (12), pg-erd-cloud (13),
# mhtml-etl-gateway (14), html4tree (15), nonnest2 (16),
# orchestrator (17), noema (19), Clearfolio (23), Keyverse (29),
# Scopeweave (31), DiskSage (37), Appguardrail (41), newsdom-api (43),
# Inkspan (47), fast-mlsirm (49), BandScope (53), and
# semantic-data-portal (59).
- cron: "44 * * * *"

concurrency:
group: macos_utility_packs-hourly-review-repair
# A later heartbeat must not cancel an in-flight bootstrap RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/macos_utility_packs
base_branch: develop
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
150 changes: 150 additions & 0 deletions docs/doctoring/appguardrail-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,150 @@
# appguardrail hourly review-repair caller

검토 기준일: **2026-08-25**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/appguardrail`, the security-guardrail product that
scans vibe-coded applications, publishes findings/SARIF evidence, and
gates autonomous remediation. The caller runs at minute 41 — the roster
slot already reserved for Appguardrail across the hourly callers —
delegates to the product-neutral central review-fix scheduler, inspects
at most 50 open pull requests targeting protected `develop`, and
dispatches at most one bounded repair per heartbeat.

A buyer acquiring appguardrail for its assurance evidence would feel
open security work stalling while hourly NVIDIA NIM repair scanned only
Clearfolio, DiskSage, and fast-mlsirm. Live heads such as
ContextualWisdomLab/appguardrail#1031 (register malicious shared-skill
threats in the threat inventory), ContextualWisdomLab/appguardrail#927
(make Clean Scan an evidence-qualified assurance state),
ContextualWisdomLab/appguardrail#938 (ship a source-authoritative
detector vertical slice with independent efficacy evidence), and the
cross-repo collector feed behind
ContextualWisdomLab/appguardrail#850 target `develop` and never enter
those other callers.

The caller does not implement review or mutation logic itself.
appguardrail remains standalone; scanner rules, control-plane schema,
and report templates stay owned by the product repository. Privileged
automation stays in `ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths,
and writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths,
require unavailable credentials or protected-setting changes, violate
stack order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and
`cancel-in-progress: false`. This preserves an in-flight bounded RCA —
for example a SARIF drift or scan-path context diagnosis — instead of
discarding evidence when the next hourly heartbeat arrives. The reusable
scheduler cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode
and NVIDIA NIM work can legitimately approach two hours on detector
coverage analysis. An hourly redispatch of the same unchanged head would
create duplicate writer pressure rather than faster remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can mint the
OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250
Comment thread
coderabbitai[bot] marked this conversation as resolved.
forbids executing the caller with write or model privileges it does not
need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive
or forward it.

Before protected-develop activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/appguardrail` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no appguardrail runtime dependency, database object,
network endpoint, tenant authority, or product credential. appguardrail
continues to run standalone behind `appguardrail-scan` protection.
Org-security collectors and Strix consumers may read its findings, but
they cannot weaken its exact-head, approval, or security gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 41
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and
`compileall` path blocks must each name the caller, doctoring, or
contract they own.

After source integration, closure requires a scheduled or manual
protected-develop consumer run proving the exact appguardrail repository
and `develop` base. Source checks alone are not
protected-develop operational acceptance. Merge still requires zero unresolved valid
findings and a qualifying independent non-author approval.

Rollback removes the appguardrail caller, its focused test, doctoring,
and central path-filter/documentation entries. It must not remove
scheduler dispatch validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 25, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
25, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *OpenID Connect reference*. GitHub Docs. Retrieved
August 25, 2026, from
https://docs.github.com/en/actions/reference/security/oidc

GitHub, Inc. (n.d.-d). *Automatic token authentication*. GitHub Docs.
Retrieved August 25, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication
800-218). https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 25, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 25, 2026,
from https://opencode.ai/docs/
Loading
Loading