fix(review): 특권 OpenCode PR 소스 격리#579
Conversation
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head61f4389f043921c566ed5394c844b9689a4537d1. -
Head SHA:
61f4389f043921c566ed5394c844b9689a4537d1 -
Workflow run: 29543971639
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: opencode-review.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: opencode-review.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (2 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (2 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (2 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (2 files)"]
R3 --> V3["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage Decision
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (14 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (14 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (12 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (12 files)"]
R3 --> V3["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head9548f668e725630a018d8369863fec791a20e848. -
Head SHA:
9548f668e725630a018d8369863fec791a20e848 -
Workflow run: 29545462958
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (2 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (2 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (7 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (7 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (7 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (7 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head461ddf25d49c680b99a72ffc4b8aaedc90057bf3. -
Head SHA:
461ddf25d49c680b99a72ffc4b8aaedc90057bf3 -
Workflow run: 29547114295
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (3 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (3 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (7 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (7 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head8702d861abf9564b5f46caa49231fbac992d26a6. -
Head SHA:
8702d861abf9564b5f46caa49231fbac992d26a6 -
Workflow run: 29548883079
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (3 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (3 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (7 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (7 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head448b42d0acfec98fc32095d85adff2f7d3332149. -
Head SHA:
448b42d0acfec98fc32095d85adff2f7d3332149 -
Workflow run: 29550081953
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (8 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (8 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head448b42d0acfec98fc32095d85adff2f7d3332149. -
Head SHA:
448b42d0acfec98fc32095d85adff2f7d3332149 -
Workflow run: 29550108517
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (8 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (8 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head0496b9c2e2018601b18eb6c7718ce7842194c244. -
Head SHA:
0496b9c2e2018601b18eb6c7718ce7842194c244 -
Workflow run: 29551817393
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 3
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (8 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (8 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current heade7e4ffdaae469e29dd82ad3774ca8e6afe76d3b4. -
Head SHA:
e7e4ffdaae469e29dd82ad3774ca8e6afe76d3b4 -
Workflow run: 29554291237
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (8 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (8 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (8 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (8 files)"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Noema PydanticAI review
Approval blocked: required coverage evidence not run or proven for this head. No dependency/SARIF issues, no workflow failures, no security findings, but test/docstring evidence is missing, so approval is not possible.
Findings
-
[high] .github/workflows/opencode-review.yml:1: Rerun the workflow ensuring 'coverage-evidence' is run and passes for the current head, or explain why coverage is not required for this repo. Approval cannot proceed without required test/docstring evidence. (coverage-evidence: skipped (present in current check conclusions), and all prior OpenCode review comments indicate 'coverage-evidence' job was not run or published for this head or prior heads (see OpenCode agent comments).)
-
Result: REQUEST_CHANGES
-
Verdict: request_changes
-
Confidence: high
-
Head SHA:
f538d6dd7c0f824a05f9ddc24893e5d490a896a1 -
Reviewer credential:
noema-github-app
이전 HEAD의 coverage 실패 판정이며 current HEAD 0acf47fb에서는 coverage-evidence가 성공하고 exact-head OpenCode가 재실행 중입니다. stale review만 정리하고 current-head 승인을 별도로 요구합니다.
이전 HEAD의 coverage 실패 판정이며 current HEAD 0acf47fb에서는 coverage-evidence가 성공하고 exact-head OpenCode가 재실행 중입니다. stale review만 정리하고 current-head 승인을 별도로 요구합니다.
current HEAD 검증 —
|
|
추가 current-head 실증입니다. 중앙 PR #590의 exact head 5686854 대상 review run 29734027190은 coverage와 모든 저장소 검사를 통과한 뒤 모델 풀에서만 실패했습니다. DeepSeek V3와 R1은 각각 5,400초 timeout, Luna는 quota, GPT-5 계열은 context-window, o3는 권한 오류였습니다. 특히 GPT-4.1은 26초 안에 리뷰 출력을 만들었지만 adversarial probe의 exact path/positive line 형식 한 항목 때문에 CONTROL_REJECTED 되었고 동일 모델 형식 재시도가 없었습니다. 최종 publish는 MODEL_OUTPUT_UNAVAILABLE로 fail-closed 했습니다. 이 실행은 본 PR의 모델별 짧은 상한, Luna 후순위 배치, DeepSeek fallback, 형식 전용 재시도 2회의 필요성을 직접 입증합니다. 실패 실행: https://github.com/ContextualWisdomLab/.github/actions/runs/29734027190 |
|
Current-HEAD governance repair pushed at This head closes the observed central review gaps:
Independent local verification on the committed files:
All new GitHub checks shown on the PR are for |
Current-head hosted evidence classificationAudited exact head
Merge/review decisions must exclude the false-green Strix and skipped Noema verdict until real current-head evidence exists. |
|
Current-head evidence for
The cross-repository status publication error still requires |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head1a826b7d3e218e999a60f28562728a0cdd5d90ae. -
Head SHA:
1a826b7d3e218e999a60f28562728a0cdd5d90ae -
Workflow run: 29799147016
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow (4 files)"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow (4 files)"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script (14 files)"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script (14 files)"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test (12 files)"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test (12 files)"]
R3 --> V3["targeted test run"]
배경
main의 CodeQL alerts #182-#185 (
actions/untrusted-checkout/critical)는 특권pull_request_targetOpenCode job이 신뢰된 workflow checkout 안으로 PR 객체를 fetch한 뒤 PR head를 실행 가능한 worktree로 materialize하는 경로를 지적합니다. 이후 current-head 감사에서 모델 풀 큐 독점, 불완전 Strix 증거, 교차 저장소 상태 게시, 정확하지 않은 coverage runner 및 Python 프로젝트 의존성 부재도 확인했습니다.변경
runner.temp의 격리된 bare Git 저장소로 fetch하고, 검증된 tree/blob만 inert source directory로 materialize합니다..git/.codegraph메타데이터, 경로 순회, 비 UTF-8 경로, 지원하지 않는 tree mode, 겹치는 출력 경로와 크기/파일 수 초과를 fail-closed로 거절합니다.v22.14.0과 pnpm11.5.3아카이브를 SHA-256으로 고정하고, mutable Corepack activation이나 npm fallback을 금지합니다.requirements-hashes.txt만 최대 8개/20 MiB로 추출하고, pinnedname==version+ SHA-256 형식만 허용합니다.--require-hashes --only-binary=:all:로 설치하고, networkless current-head 테스트에는 해당 프로젝트 환경만 제공합니다. 경로·형식·hash·wheel이 불명확하면 로그에 원인을 남기고 실패합니다./opt/base-python-envs의 root-owned read-only 경계가 아니면 거절합니다.검증
scripts/ci/test_strix_quick_gate.sh: passedgit diff --check: passed58d19ee90b34c9cf18c163c03f1f8f05bbce2dce:backend/requirements-hashes.txt와connector/requirements-hashes.txt를 exact base blob OID·크기·SHA-256과 함께 추출fastapi==0.139.0,pytest==9.1.1,pip check통과backend/tests/test_auth_real.py: 100 passed--network=default를 생성하지 못했습니다. 동일 해시 락 설치·테스트 경로는 위와 같이 로컬 Python 환경에서 재현했으며, hosted Ubuntu current-head run을 최종 권위 증거로 유지합니다.리뷰 계약
보안 workflow 변경이므로 exact current head에 대해 OpenCode와 Noema의 독립 리뷰가 모두 필요합니다. unresolved thread, current-head CodeQL/SARIF, Strix와 필수 체크가 모두 통과하기 전에는 병합하지 않습니다.