feat(automation): run Inkspan hourly NVIDIA NIM review repair - #796
feat(automation): run Inkspan hourly NVIDIA NIM review repair#796seonghobae wants to merge 11 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Exact-current-head read-only review request after one-time prerequisite reconciliation. Head: The focused Hourly NVIDIA NIM Review Repair workflow is successful on this exact head. The current base and head have the identical @coderabbitai review Review read-only. Do not update either branch, create repair automation, synthesize approval, mark Ready, or merge. Anchor findings only to the exact head above; queued, stale-head, or predecessor evidence is not success. |
|
I will anchor findings to head
|
|
/oc Refetch the live PR and stop without writing unless exact head is Reconcile the current prerequisite head into the existing Inkspan branch with an ordinary non-force merge and preserve every newer fail-closed scheduler, NVIDIA NIM, exact-scope, credential-isolation, explicit push-destination, test, and doctoring contract from #782. Resolve overlap by retaining the prerequisite implementation verbatim and preserving only the intended Inkspan product caller slice: After reconciliation, require the effective diff against the live stacked base to be product-only and explain any unavoidable ancestry-only file if GitHub still reports it. Run the focused Inkspan/hourly caller contracts, the complete hourly NVIDIA NIM quality suite, full repository tests, 100% production statement/branch coverage, 100% public docstrings, compileall, actionlint/shell syntax, and |
Purpose
Add the product-specific one-hour PR review → repair → revalidation caller for
ContextualWisdomLab/inkspanwhile reusing the bounded NVIDIA NIM scheduler from prerequisite PR #782.Exact current stacked head
a4af64e6866c591eecbaa63a0e22e4145c1a257eThe branch now contains a real merge parent for current prerequisite head
b921e26854f1b0fd367c76a32af6db966374bcef; GitHub reports the stacked PR mergeable with exactly five product files. No force-push, temporary workflow, encoded patch, or competing branch writer was used.Product and MSA behavior
.github/workflows/inkspan-hourly-review-repair.ymlat minute 37 of every hour, offset from Clearfolio.ContextualWisdomLab/inkspanand protected basemain.compose/ui.panelmodular integration.Credential, privacy, and compliance boundary
PR_REVIEW_MERGE_TOKENandOPENCODE_APPROVE_TOKEN; it never usessecrets: inherit.COPILOT_GITHUB_TOKEN, GitHub Models, and directNVIDIA_NIM_API_KEYbinding are absent from the caller.GITHUB_TOKENread-only and declare no job-level write elevation.github.tokenmutation fallback.Permanent five-file slice
.github/workflows/hourly-nvidia-nim-review-repair.yml.github/workflows/inkspan-hourly-review-repair.ymlCHANGELOG.mddocs/doctoring/inkspan-hourly-review-caller.mdtests/test_pr_review_fix_hourly_contract.pyThe focused workflow tracks both the caller and doctoring. The static contract validates the exact schedule/target, independent concurrency, one-dispatch and one-hour bounds, explicit secret mapping, read-only workflow-token boundary, no inherited or model secrets, and absence of product literals from the reusable engine.
Stacked activation boundary
This PR targets
fix/hourly-nvidia-nim-review-repair-main, the head branch of prerequisite #782. It must not merge before #782. The schedule is inactive until both the prerequisite and this caller reach protectedmain.After #782 merges:
main;Keep Draft. Pending, queued, cancelled, skipped-required, status-only, author-only, predecessor-head, or synthetic evidence is not acceptance.