Skip to content

feat(operations): restack runner-assignment audit on live main - #251

Closed
seonghobae wants to merge 1 commit into
mainfrom
feat/actions-runner-assignment-audit-current-main-v3
Closed

feat(operations): restack runner-assignment audit on live main#251
seonghobae wants to merge 1 commit into
mainfrom
feat/actions-runner-assignment-audit-current-main-v3

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Purpose

Restack the read-only GitHub Actions runner-assignment audit from stale/diverged Draft #240 onto the current protected main without rebasing or force-pushing historical work.

Exact identities

  • protected base immediately before successor creation: c01a663485dc25d2d11f35318aa0a677c07e0320
  • predecessor feat(operations): restack runner-assignment audit on current main #240 exact source head: 36688b353d716a2dbcb074114e99a19e526819c1
  • successor exact head: aeb567797ee9fd18c7e86fc03c36b91dd5e89223
  • ancestry: successor is 1 commit ahead / 0 behind protected base; merge base is exactly protected base
  • current-main delta: exactly 9 files, 1,146 additions, 0 deletions

Restack integrity

Eight source/test/operator blobs are preserved exactly from #240:

  • docs/doctoring/actions-runner-assignment-audit.md3920cc778152b366263e94f324c6e74a2b8becb8
  • scripts/actions-runner-assignment-audit.mjse09422a7a5effe883af6515b0255134dfe2effb3
  • scripts/lib/actions-runner-assignment-audit.mjsf7dba42424cd2c6c93ba95459e7a12eecf4135c4
  • scripts/lib/actions-runner-assignment-source.mjs0cad167a30e933d56f97d47e111be40ec280d2d3
  • test/actions-runner-assignment-audit.test.ts45ca88e2a9467afd6d132d0386a9bc0038a23b0f
  • test/actions-runner-assignment-cli.test.ts93e24358f70efd7844340c24d85d4f52e774e366
  • test/actions-runner-assignment-docs.test.ts83076fbf1f05234b1e5710348f48f6e5317b27ca
  • test/actions-runner-assignment-source.test.tse35adf11d2ff167f44014d1c8f9a9388249b8bc9

package.json is deliberately not copied from stale #240. The successor starts from current-main package blob 60080921304350d920e80e99a9c7b409034da587 and adds only operations:runner-assignment, preserving the newer operations:external-scheduler-evidence command and all other protected-main package metadata. Resulting package blob: 6f79d1385a803066a4c1cd0a0207c870ab8f6ab5.

Protected-main CHANGELOG.md is inherited unchanged; no stale predecessor changelog state is replayed.

Evidence boundary

The operator remains read-only and exact-source-head/workflow-run-ID bound. Paginated filter=all job evidence separates runner assignment from later workflow/test conclusions and dependency/environment waiting. Fresh unassigned queues remain non-passing; bounded-grace expiry fails closed; an assigned runner followed by workflow failure proves assignment only, not workflow success.

The gh subprocess receives bounded PATH, explicit read-only GH_TOKEN, pinned GH_HOST=github.com, and NO_COLOR=1; ambient write/model/App/proxy/home authority is not intentionally propagated. Reports carry no required-check, formal-review, merge, release, deployment, production, KPI, licensing, IP, or acquisition authority.

Predecessor CI/reviewer/scanner/model evidence does not transfer. This PR remains Draft until fresh exact-head application CI, reviewer CI, and protected-base-eligible central Security Scan execute against this exact head and the live protected base. Pending, queued, skipped, absent, neutral, failed, cancelled, stale, predecessor-head, status-only, model-only, and rate-limited evidence is non-passing.

Related: #27, #30, #77, #79, #88, #91, #94, #240

@coderabbitai

coderabbitai Bot commented Aug 13, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a8cb78e-897d-47ab-bfcd-47f0e8256425

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant