Skip to content

feat(action): publish advisory application PR comparisons - #1015

Merged
pengfei-threemoonslab merged 2 commits into
mainfrom
codex/application-action-915
Oct 10, 2026
Merged

pengfei-threemoonslab merged 2 commits into
mainfrom
codex/application-action-915

Conversation

@pengfei-threemoonslab

@pengfei-threemoonslab pengfei-threemoonslab commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

A PR reviewer can now opt into a manifest-free application comparison directly in the Action. application: "true" uses the exact PR base/head SHAs, delegates merge-base and derived scope to diff --application, posts the CLI review under its own sticky marker, uploads the full JSON/text, and writes a job summary. Execution refusals have a visible fix; findings remain advisory unless application_fail_on explicitly selects comparison statuses.

Refs #915. Targets main after #1010 was squash-merged, following the owner-approved implementation order. The development-corpus runtime and full baseline/score measurements remain deferred by the owner to separate implementation. This PR does not auto-close those remaining acceptance items.

Behavior

  • Explicit base_ref/head_ref and application_scope are supported. Full history/objects must already be available; the Action never fetches.
  • Each run writes a fresh application directory. A refusal cannot reuse a prior comparison or verifier report.
  • Application and verifier comments/artifacts have distinct names. Fork publication denial writes the review to the summary.
  • Verifier options are refused in application mode; verifier decision/control outputs remain empty. The default verify/scan route keeps its behavior.
  • Quickstart includes one source-only YAML block and verified MIS_TALENT PR [codex] Harden scanner trust and report stability #7 refs. It explicitly does not claim this input is in v1.2.0.
  • Existing CI suites execute the shipped Action Bash and comment JavaScript on sample-application Git fixtures; no workflow token or grant changes.

Type and authorship

  • GitHub Action / distribution change
  • A coding agent wrote some or all of this change. Agent: Codex.
  • A person read the whole diff before opening this pull request.

Validation

  • Final Action/application/comment/metadata tests: 47 passed (19 application cases).

  • Route, host-only recipe, and shard-partition tests: 88 passed.

  • Related Action install and distribution-parity selection: 353 passed, 1 existing skip.

  • Additional verifier-attestation/CI compatibility selection: 159 passed.

  • Independent final targeted recheck: 22 passed.

  • Ruff and diff whitespace checks passed.

  • The new CI shard weight has measured JUnit provenance; no tests were excluded.

  • Committed-source verifier/control: complete, release decision passed, refreshed after commit.

  • CI found one legacy annotation-placement regression (test_action_yml_status_output_marked_legacy); corrected by restoring status as the first output. The original failure plus 38 related tests passed. The independent reviewer confirmed complete YAML semantic equality and unchanged routing/output values.

  • Original exact-head GitHub CI at 6b5209e493b9: all required checks passed; the release-tag-only check was skipped by its PR condition.

  • Sequential restack at 1d419595d284: range-diff confirmed Action changes unchanged; both test timing records were retained. Committed control is complete / passed; exact-head GitHub CI passed all 14 applicable checks, including six suite shards and aggregate coverage; the release-tag-only check was skipped.

  • Final six-increment combination at a4ea56e5987bf: 1,546 tests passed, 1 skipped; independent combination review passed 383 tests with no actionable P1/P2. Source remained unchanged during both selections. No corpus or baseline was scored.

Independent review and fixes

  1. Initial review found a P2: GitHub string comparisons ignore case while Bash rejects noncanonical application input. A rejected "FALSE" could reopen a legacy publication route. The fix makes every consumer use scan.outputs.execution_mode, written only by a validated execution branch. Invalid-case regression fixtures include an old verifier comment. GitHub expression semantics.
  2. Follow-up closed that P2 and identified an artifact-name collision when both application and verifier routes run in one workflow. Application now uploads agents-shipgate-application-review; legacy retains agents-shipgate-report. Metadata checks preserve the distinct names. Upload artifact semantics.
  3. Final independent review confirmed both P2 fixes, reran affected tests, and found no remaining actionable issues. Reviews were read-only; the coding agent implemented the fixes.

Baseline, holdout and released-build scoring were outside these reviews.

Ordered merge preparation

GitHub's effective repository policy rejected merge commits, so #1010 was squash-merged as cd1433be1b12. This branch replays only its two reviewed commits onto that main tree. New head 2ebca54fd63e has exactly the same file content as reviewed head 1d419595d284 (full-tree diff equality), and fresh committed control is complete / passed. Exact-head CI for the replay passed all 14 applicable checks; release-tag-only check skipped. #1010's post-merge main verification also passed all 13 CI jobs before this merge. Baseline work remains deferred.

Post-merge main verification

Squash-merged as a12175e7f1862cecba3a1a4bfbab95d8f3e88177. The main tree exactly matches the reviewed PR head. Post-merge targeted tests passed: 59 tests. Fresh committed verification on that main commit returned complete / passed. Main CI run completed successfully with all 13 jobs passed. Baseline, corpus, ledger, Q2 and released-build evaluation remain deferred.

@pengfei-threemoonslab
pengfei-threemoonslab marked this pull request as ready for review October 10, 2026 18:56
@pengfei-threemoonslab
pengfei-threemoonslab force-pushed the codex/application-action-915 branch from 6b5209e to 1d41959 Compare October 10, 2026 19:57
@pengfei-threemoonslab
pengfei-threemoonslab changed the base branch from main to codex/fix-1001-application-rows October 10, 2026 19:58
@pengfei-threemoonslab
pengfei-threemoonslab changed the base branch from codex/fix-1001-application-rows to main October 10, 2026 22:07
@pengfei-threemoonslab
pengfei-threemoonslab force-pushed the codex/application-action-915 branch from 1d41959 to 2ebca54 Compare October 10, 2026 22:07
@pengfei-threemoonslab
pengfei-threemoonslab merged commit a12175e into main Oct 10, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant