Skip to content

feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression) - #1257

Merged
don-petry merged 5 commits into
mainfrom
dev-lead/issue-1253-20260715-0311
Jul 15, 2026
Merged

don-petry merged 5 commits into
mainfrom
dev-lead/issue-1253-20260715-0311

Conversation

@don-petry

@don-petry don-petry commented Jul 15, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #1253

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • New Features

    • Added automated validation for reusable workflow inputs.
    • Checks that forwarded inputs are declared and required inputs are provided.
    • Reports unresolved workflow references with warnings.
  • Documentation

    • Documented the reusable workflow input validation standards and behavior.
  • Tests

    • Added coverage for valid, invalid, missing-required, and unresolved workflow input scenarios.
  • Chores

    • Updated code-quality scanning exclusions for validation fixtures.

…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression)
@don-petry
don-petry requested a review from a team as a code owner July 15, 2026 03:27
Copilot AI review requested due to automatic review settings July 15, 2026 03:27
@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@donpetry-bot, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 32 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 97b43297-4c28-4344-94ac-88f54215ec6a

📥 Commits

Reviewing files that changed from the base of the PR and between 1606272 and 077c48b.

📒 Files selected for processing (2)
  • .github/workflows/lint.yml
  • scripts/validate-caller-inputs.sh
📝 Walkthrough

Walkthrough

Adds a Bash guard that validates reusable-workflow caller inputs against declarations at pinned refs, wires it into lint CI, documents the contract, and adds fixtures and Bats tests for valid, invalid, regression, CLI, and unresolved-reference cases.

Changes

Reusable caller-input validation

Layer / File(s) Summary
Input contract parsing
scripts/validate-caller-inputs.sh
Parses reusable workflow references, direct caller with: keys, and workflow_call.inputs declarations including required flags.
Contract validation and resolution
scripts/validate-caller-inputs.sh
Validates undeclared and missing required inputs, resolves reusable workflows at pinned refs, scans repository workflows, and reports unresolved refs as warnings.
CI integration and test coverage
.github/workflows/lint.yml, AGENTS.md, tests/dev-lead/fixtures/caller-inputs/*, tests/dev-lead/unit/test_validate_caller_inputs.bats, sonar-project.properties
Adds the lint job, documents the standard, supplies valid and failing fixtures, tests helper and end-to-end behavior, and excludes fixtures from Sonar analysis.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Lint
  participant Validator
  participant ReusableWorkflow
  participant Bats
  Lint->>Validator: run validate-caller-inputs.sh
  Validator->>ReusableWorkflow: resolve workflow at pinned ref
  ReusableWorkflow-->>Validator: return workflow_call inputs
  Validator-->>Lint: pass, fail, or warning
  Bats->>Validator: execute helper, pair, and scan tests
  Validator-->>Bats: validation results
Loading

Possibly related issues

  • #1052: This change implements the described caller-input validation guard, pinned-ref resolution, regression fixture, CI wiring, and tests.

Suggested labels: needs-human-review

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the core CI guard and regression coverage added by this PR.
Linked Issues check ✅ Passed The changes match #1253 by adding the guard script, lint job, tests, fixtures, and #1034 regression coverage.
Out of Scope Changes check ✅ Passed The extra docs, test fixtures, and Sonar exclusion are directly supporting the new guard and do not appear unrelated.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-1253-20260715-0311

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) July 15, 2026 03:28
@don-petry
don-petry disabled auto-merge July 15, 2026 03:29
@github-actions

Copy link
Copy Markdown
Contributor

CI Failure: SonarCloud Code Analysis

Step: Quality Gate — "C Security Rating on New Code" (required ≥ A)
Root cause: Lint/style

SonarCloud flagged 3 "Use full commit SHA hash for this dependency" security findings in the new test fixture workflows added by this PR: tests/dev-lead/fixtures/caller-inputs/missing-required/.github/workflows/caller.yml (line 13), tests/dev-lead/fixtures/caller-inputs/regression-1034/.github/workflows/caller.yml (line 15), and tests/dev-lead/fixtures/caller-inputs/good/.github/workflows/caller.yml (line 11). Each pins an actions/...@<ref> dependency to a tag/branch instead of a full 40-character commit SHA, which SonarCloud's GitHub Actions IaC ruleset treats as a supply-chain security issue on new code. There are also 3 related (non-blocking) warnings about only passing required secrets to reusable workflows in the same files.

Suggested fix: In the three fixture caller.yml files above, replace the tag-based uses: refs with the full pinned commit SHA (matching the actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 convention already used elsewhere in this PR, e.g. in lint.yml), then re-run the SonarCloud check.

View run logs

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead Fix CI — applied

PR: #1257 | SHA: 68b45685b2c889395cdf6f38167f964c3c691c40
Fix committed and pushed. Waiting for CI.

@don-petry
don-petry enabled auto-merge (squash) July 15, 2026 03:32
@don-petry
don-petry disabled auto-merge July 15, 2026 03:33
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) July 15, 2026 03:33
@don-petry
don-petry disabled auto-merge July 15, 2026 03:35
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: none
Skipped (informational): 0
Status: Quality Gate passed with 0 new issues — no actionable changes required.
```

@don-petry
don-petry enabled auto-merge (squash) July 15, 2026 03:35
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-07-15T04:36:12Z.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a new CI guard to prevent “channel-skew” breakages where a caller workflow forwards with: inputs that are not declared (or misses required inputs) in the reusable workflow at the pinned @ref (issue #1253 / regression class #1034). It does so by introducing a validation script, wiring it into lint.yml, and adding unit/fixture tests that reproduce the failure mode.

Changes:

  • Add scripts/validate-caller-inputs.sh to resolve pinned reusable refs and validate (a) forwarded ⊆ declared inputs and (b) required inputs forwarded.
  • Wire the new validation as a validate-caller-inputs job in .github/workflows/lint.yml.
  • Add Bats unit tests plus fixture caller/reusable trees (including a #1034 regression fixture) and document the guard in AGENTS.md.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
scripts/validate-caller-inputs.sh Implements the reusable-at-pinned-ref resolution + forwarded-input contract validation.
.github/workflows/lint.yml Adds the validate-caller-inputs CI job to run the new guard script.
tests/dev-lead/unit/test_validate_caller_inputs.bats Unit + fixture-driven tests covering parsing, validation logic, and the #1034 regression.
tests/dev-lead/fixtures/caller-inputs/reusable/dev-lead-reusable.yml Fixture reusable declaring optional + required inputs (and required secret) for validation tests.
tests/dev-lead/fixtures/caller-inputs/good/.github/workflows/caller.yml Passing fixture caller that forwards only declared inputs and includes required ones.
tests/dev-lead/fixtures/caller-inputs/regression-1034/.github/workflows/caller.yml Regression fixture that forwards an undeclared input and must fail.
tests/dev-lead/fixtures/caller-inputs/missing-required/.github/workflows/caller.yml Negative fixture omitting a required input and must fail.
AGENTS.md Documents the new guard/job and its rationale/behavior.

Comment thread scripts/validate-caller-inputs.sh Outdated
Comment thread scripts/validate-caller-inputs.sh Outdated
Comment thread scripts/validate-caller-inputs.sh Outdated
@donpetry-bot

donpetry-bot commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor
Superseded by automated re-review at 9f6b68801deeb13214cf89401dd937ec6899f3a5 — click to expand prior review.

Review — fix requested (cycle 1/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: MEDIUM
Reviewed commit: 65ad05f2b083e8d4b4c278599cc2e1948d6b775e
Review mode: triage-approved (single reviewer)

Summary

Adds a new CI guard (issue #1253, Part A of epic #1052): scripts/validate-caller-inputs.sh resolves every reusable-workflow caller's pinned @ref and asserts forwarded with: keys ⊆ declared workflow_call inputs and that required inputs are forwarded, wired as a validate-caller-inputs job in lint.yml, with bats tests, fixtures (including a #1034 regression fixture), AGENTS.md docs, and a Sonar exclusion for the fixtures. The implementation is well-structured and fully meets the issue's acceptance criteria, but the review cannot approve: three Copilot review threads on the new script are unresolved, and two of them are legitimate security-hardening findings that arrived after the last dev-lead fix-reviews pass and have not been addressed.

Linked issue analysis

Closes #1253 — substantively addressed. Deliverables all present: (1) scripts/validate-caller-inputs.sh with checks (a) forwarded ⊆ declared and (b) required forwarded, same-repo channel-tag resolution via git fetch, loud failure on resolved violations, soft-pass with ::warning:: only on unresolvable refs; (2) wired into lint.yml (SHA-pinned checkout, timeout-minutes, no new permissions or schedules); (3) bats unit + fixture tests including the #1034 regression (forwarded key absent at pinned ref → FAIL) and the missing-required case; shellcheck is green.

Findings

  1. [MEDIUM — unresolved Copilot thread] Argument/refspec injection into git fetch (scripts/validate-caller-inputs.sh, vci_resolve_reusable, review lines 261 and 270). Refs parsed from workflow uses: lines are passed to git fetch ... origin "$ref" and git fetch ... "https://github.com/${repo_slug}" "$ref" without an end-of-options --. Quoting does not stop option parsing, so a ref beginning with - is interpreted as a flag/refspec. Since this runs in PR-triggered CI over PR-modifiable workflow files, the input is not fully trusted. Fix is a one-liner in each fetch: add -- before "$ref" (or reject refs failing git check-ref-format --allow-onelevel).
  2. [LOW — unresolved Copilot thread] Top-level set -euo pipefail applies to sourcing callers (line 39/108). The script is deliberately source-able for the bats tests, but strict mode leaks into the caller shell as a side effect. Consider moving strict mode into the execute-directly branch.
  3. Secret scan: the run_secret_scanning MCP tool is not available in this environment; the gitleaks CI check passed and the diff introduces no secret-like content (fixtures use secrets: inherit placeholders only).

Blocking reason: approve gate "no unresolved review threads" fails (3 unresolved threads, 2 security-relevant on a CI-executed script). All prior advisory bots (Gemini/Codex/CodeRabbit) were rate-limited, so Copilot's review is the only substantive external feedback and it has not been actioned.

CI status

All checks green at 65ad05f2b083e8d4b4c278599cc2e1948d6b775e: Lint, shellcheck, bats/unit, validate-fixtures, validate-caller-inputs (the new job itself), CodeQL (actions + python), SonarCloud Quality Gate (passed after the fixture-exclusion fix), gitleaks secret scan, AgentShield, template-drift, and all org guards — SUCCESS; dependency-audit sub-jobs SKIPPED (no matching ecosystems). Branch is BEHIND main (auto-rebase applies after review).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

…mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.
@don-petry
don-petry disabled auto-merge July 15, 2026 05:47
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #1257
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-07-15T06:26:05Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-07-15T06:26:05Z

@don-petry
don-petry enabled auto-merge (squash) July 15, 2026 05:56

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/lint.yml:
- Around line 144-151: Document the intentional default credential persistence
on the actions/checkout step in the workflow, noting that
scripts/validate-caller-inputs.sh and vci_resolve_reusable require persisted
credentials for authenticated git fetch origin resolution of same-repository
channel tags; do not set persist-credentials to false, and optionally scope the
job permissions to the minimum read-only access required.

In `@scripts/validate-caller-inputs.sh`:
- Around line 63-73: Update the reusable-workflow reference matching in the
relevant validation function to recognize both .yml and .yaml paths, while
preserving the existing extraction of repo_slug, wf_path, and ref. Also update
the workflow scan around the existing .yml glob to process .yaml files, ensuring
references using either extension are validated and unresolved cases still emit
the existing warning.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 128a6000-2558-4015-8991-fd91d8be758c

📥 Commits

Reviewing files that changed from the base of the PR and between df3b7d4 and 1606272.

📒 Files selected for processing (9)
  • .github/workflows/lint.yml
  • AGENTS.md
  • scripts/validate-caller-inputs.sh
  • sonar-project.properties
  • tests/dev-lead/fixtures/caller-inputs/good/.github/workflows/caller.yml
  • tests/dev-lead/fixtures/caller-inputs/missing-required/.github/workflows/caller.yml
  • tests/dev-lead/fixtures/caller-inputs/regression-1034/.github/workflows/caller.yml
  • tests/dev-lead/fixtures/caller-inputs/reusable/dev-lead-reusable.yml
  • tests/dev-lead/unit/test_validate_caller_inputs.bats

Comment thread .github/workflows/lint.yml
Comment thread scripts/validate-caller-inputs.sh
@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry merged commit 1c35d04 into main Jul 15, 2026
42 checks passed
@don-petry
don-petry deleted the dev-lead/issue-1253-20260715-0311 branch July 15, 2026 06:09

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: 077c48b1683a8368246e648260a06070b3029352
Review mode: triage-approved (single reviewer)

Summary

Adds the #1052 Part A CI guard (issue #1253): a new validate-caller-inputs job in lint.yml backed by scripts/validate-caller-inputs.sh, which resolves every reusable-workflow caller's pinned @ref and asserts forwarded with: inputs are declared there and required inputs are forwarded. Includes bats unit + fixture tests (with a #1034 regression fixture), AGENTS.md documentation, and a Sonar exclusion for the new fixtures. Triage cleared this as low-risk; confirmation review agrees the implementation is sound — classified MEDIUM here only because it adds non-trivial CI logic.

Linked issue analysis

Closes #1253 ([#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref). All acceptance criteria are met: (1) guard FAILS on the #1034 pattern via the regression-1034 fixture and the new lint job passes on this branch; (2) shellcheck is green and all existing suites stay green; (3) the change is additive, the checkout action is SHA-pinned (actions/checkout v6.0.3), and review behaviour is unchanged. Unresolvable refs soft-pass with a logged ::warning:: as specified, never silently.

Findings

No blocking findings.

  • Security: git fetch uses '--' before refs (option-injection guard, addressing Copilot's earlier findings — threads resolved); cross-repo resolution is opt-in via VCI_RESOLVE_CROSS_REPO; fetched workflow content is parsed as text, never executed. persist-credentials is intentionally left true with a documented rationale (required for same-repo tag resolution; setting false would silently route every caller into the soft-pass path).
  • Review threads: all 5 threads (3 Copilot, 2 CodeRabbit) are resolved; CodeRabbit's changes-requested review was addressed and dismissed, and CodeRabbit subsequently approved.
  • Secret scan: run_secret_scanning MCP tool not available in this environment; gitleaks CI check is green and the diff introduces no credential-like content.
  • Since the prior review SHA (9f6b688), the only change is a merge of main into the branch — no new PR-specific code.

CI status

All required checks green: Lint (incl. the new validate-caller-inputs job), shellcheck, bats, unit tests, CodeQL (actions + python), Secret scan (gitleaks), SonarCloud quality gate, AgentShield, Agent Security Scan, holdout-guard, template-drift, and permission/structure guards. Skipped checks are conditional ecosystem audits (npm/pip/cargo/go audits, dependabot-automerge, ci-relay) — not applicable to this PR.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

don-petry added a commit that referenced this pull request Jul 16, 2026
Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).
don-petry added a commit that referenced this pull request Jul 16, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 18, 2026
…puts ⊆ declared inputs at the pinned @ref (+ #1034 regression) (#1257)

* feat: implement issue #1253 — [#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

* fix(ci): auto-fix for SonarCloud Code Analysis [skip ci-relay]

* fix(vci): harden git fetch against argument injection + scope strict mode to direct-exec

Addresses the pr-review/Copilot findings on #1257 (Part A of #1052):
- Add end-of-options `--` before "$ref" in both git fetch calls so a ref
  beginning with `-` (from a PR-modifiable, CI-executed workflow file) is
  treated as a refspec, not parsed as a flag/option (verified: without `--`
  git errors "unknown option"; with `--` it treats it as a ref).
- Move `set -euo pipefail` out of the top level into the execute-directly
  guard so sourcing the script (bats) no longer leaks strict mode into the
  caller's shell.

shellcheck clean; all 16 bats tests pass; sourced no longer sets errexit.

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: Don Petry Bot <donpetry+bot@gmail.com>
don-petry added a commit that referenced this pull request Aug 18, 2026
…the fleet-monitor workflow behind a human go/no-go (#1275)

* feat: implement issue #1152 — [Phase 4] Wire opt-in remediation into the fleet-monitor workflow behind a human go/no-go

* fix(reviews): address review comments [skip ci-relay]

* style(fleet-gate): scope strict mode to direct-exec (no source leak)

Human-review polish on #1275: move `set -euo pipefail` out of the top level into
the execute-directly guard, so sourcing fleet_remediate_gate.sh for the bats
tests doesn't leak strict mode into the caller's shell — matches the repo
standard codified in #1257/AGENTS.md. Pure/behaviour-preserving: shellcheck
clean, all 10 gate bats pass, sourcing leaves errexit off, and the gate still
fail-closes (schedule->dry-run, live dispatch w/ all preconditions->live,
missing token/pilot->dry-run).

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[#1052 A] CI guard: forwarded caller inputs ⊆ declared inputs at the pinned @ref (+ #1034 regression)

3 participants