Add inactive GitHub Actions CI normalizer payload - #219
Conversation
Deploying ystack with
|
| Latest commit: |
1b8580b
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://2ff034bd.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-default-github-actions.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 1b8580b BugsNo Important findings. Fresh review confirmed that a complete, completed run requires every visible child to be completed before success or any of the six terminal conclusion families is evaluated. Queued-child contradictions reject across failure, cancelled, timed out, action required, stale, and neutral. Incomplete snapshots stay fail-closed or inconclusive. Attempt, job/check identity, timeline, ordering, content-reference, and canonical-output boundaries remain exact. SecurityNo Important findings. Provider strings remain bounded untrusted data. Repository, workflow, suite, run, attempt, app, revision, evidence, config, instruction, and execution-boundary values are exact. The jq payload is offline, inactive, unqualified, authority-free, and effect-free; it exposes no credential, network, write, dispatch, rerun, cancellation, merge, activation, permission, tool, or capability surface. ComplianceNo Important findings. The reviewed diff is exactly the five permitted payload/test/docs/restore-manifest paths, with no manifest, constitution, forbidden, live, or process path. The restore manifest change is append-only. Required CI run 33665624320 attempt 2, check 100372133001, app 15368 succeeded on the exact reviewed head. Focused tests passed 76 assertions; relevant portable-core schema proof, bash syntax, diff checks, and final clean-worktree checks passed. Final review: clean, with zero unresolved Important findings. |
|
Construction receipt
|
Scope
Add the inactive, pure-jq GitHub Actions CI normalizer payload and its focused proof.
The payload validates caller-bound workflow, run, run-attempt, check-suite, job, check, app, head, base, time, instruction, config, and execution-boundary facts. It returns deterministic generic CI states while leaving provider names, text, and details as opaque data.
This is payload-first delivery. It intentionally has no adapter manifest or default-set wiring. Those wait for a later assembly PR that can reference the durable payload commit on
main.Changed paths:
README.mdRESTORE.mdadapters/github-actions-ci/v1/normalize.jqci/required-files.txtscripts/test/default-github-actions-ci-adapter.test.shSafety
The package is inactive, offline, and unqualified. It grants no authority or qualification, exposes no capability or permission surface, uses no credential, performs no network fetch, and cannot rerun, cancel, dispatch, comment, label, merge, or write provider state.
Exact tuple
0e10634657c127a6fb3185f1ab3f84c61fc8f7d01b8580b0c0818d8a725305404d6cdeeb78f4fd4b9bef02ec5b283fe5bb8516a2780d4a37ae9ed39aa53450355a6b88ea6a9c858d9979dd8f396d9144, then0e10634657c127a6fb3185f1ab3f84c61fc8f7d0Proof on the exact head
bash -n: passed.-x -S style: passed.Per the construction brief, the full suite, advisory, independent review, and merge were not run here.