Repository navigation
ci: bootstrap trusted publisher before feature runner adoption - #5175
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: dashpay/platform/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Final review complete — no blockers (commit 7b63fc6) · triage: low |
thepastaclaw
left a comment
There was a problem hiding this comment.
Final validation — Phase 1 + Phase 2
Verified the exact head 7b63fc6 against the supplied base: the change adds only the 33-line trusted publisher caller, matching the locally available v4.2-dev caller except for the exact feature-branch filter. YAML parsing, structural assertions, and diff whitespace checks passed; no in-scope defects were identified. External controller isolation, live target installation, candidate publication, and downstream execution were not independently verified here and remain separate rollout validations.
Review provenance
Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); reviewer 2: glm-5.3-flash (agent: phase1-reviewer, role: architecture-layering); reviewer 3: glm-5.3-flash (agent: phase1-reviewer, role: security-auditor); reviewer 4: gpt-6-astra (agent: phase2-reviewer, role: general); reviewer 5: gpt-6-astra (agent: phase2-reviewer, role: architecture-layering); reviewer 6: gpt-6-astra (agent: phase2-reviewer, role: security-auditor); final verifier: gpt-6-astra (agent: astra-verifier, role: final-verifier)
- Triage:
lowbygpt-6-astra(effort low) — The diff adds a small, self-contained 33-line CI caller with pinned controller references and explicit event, branch, permission, and secret boundaries, making correctness straightforward to verify without changing application logic or a qualifying critical surface. - Phase 1 reviewers:
glm-5.3-flash— general (completed, effort high); agentphase1-reviewer,glm-5.3-flash— architecture-layering (completed, effort high); agentphase1-reviewer,glm-5.3-flash— security-auditor (completed, effort high); agentphase1-reviewer - Phase 1 model:
glm-5.3-flash— zai quota: 5h 86% left, weekly 90% left; passed overgemini-3.8-flash-high(antigravity below 15% reserve: weekly 13% left, 5h 100% left) - Fresh verifier:
gpt-6-astra— final-verifier; agentastra-verifier - Phase 2 reviewers:
gpt-6-astra— general (completed, effort medium); agentphase2-reviewer,gpt-6-astra— architecture-layering (completed, effort medium); agentphase2-reviewer,gpt-6-astra— security-auditor (completed, effort medium); agentphase2-reviewer
e2fd47d
into
dashpay:chore/bump-rust-dashcore-secp-033
Summary
Install only the vetted trusted image-publisher caller on the exact
chore/bump-rust-dashcore-secp-033target before enabling candidate-dependent consumers in #5167. This is infraclaw's CI infrastructure repair, not application-code propagation.Independent live inspection at base
49ad468a215fc4935eb43d74e4e8662a52b73f69confirms that both the requirements manifest andrunner-image-candidate.ymlare absent, and #5167 current head8251ef7a38469a2af00a0f04f19abf91f253e4b3has no candidate publisher run. The review's bootstrap finding is valid: a publisher added only in an unmerged consumer PR cannot be treated as installed trusted orchestration on its target branch.Scope and trust
.github/workflows/runner-image-candidate.yml, byte-for-byte the already reviewed caller in ci: align secp feature-base workflows with provisioned runner images #5167.7d901150bd3d0789d50c46f365b058f2f5f1f52d; adoption of the newly merged reuse controller is separate.pull_request_targetloads trusted base orchestration. No PR checkout, inline job shell, self-hosted runner, new runner registration, or credential in source.chore/*wildcard or expanded fork admission.Validation
12 focused structural checks pass: exact vetted caller content, trusted event/path, exact branch scope, both immutable controller pins, minimal permissions, explicit secrets, no untrusted checkout/shell, no consumer activation, draft/merge guards, and no new worker authority. YAML parsing and
git diff --checkpass. These checks do not claim actual candidate publication, compatible worker execution, or target adoption.Ordered rollout / merge hold
Checklist