Skip to content

feat: implement issue #1075 — Compliance audit — 2026-09-04 - #1098

Merged
don-petry merged 34 commits into
mainfrom
dev-lead/issue-1075-20260908-0437
Sep 30, 2026
Merged

don-petry merged 34 commits into
mainfrom
dev-lead/issue-1075-20260908-0437

Conversation

@don-petry

@don-petry don-petry commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #1075

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • Documentation
    • Clarified that new commits dismiss stale approvals, code owner approval is required, and substantive changes in the latest push need approval from another reviewer.
    • Clarified that automated dependency update rebases can merge through the designated bypass process without re-approval after branch updates.

CodeAnt-AI Description

Enforce independent reviews while streamlining Dependabot merges

What Changed

  • Regular pull requests now dismiss stale approvals after updates, require code-owner approval, and require approval from someone other than the latest contributor
  • Dependabot rebase updates can be merged directly by the authorized workflow without requiring redundant re-approval
  • Repository guidance now documents the updated review and merge requirements

Impact

✅ Fewer unreviewed changes can merge
✅ Code-owner approval is enforced
✅ Fewer blocked Dependabot merges

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@don-petry
don-petry requested a review from a team as a code owner September 8, 2026 04:44
@qodo-code-review

This comment has been minimized.

@codeant-ai

This comment has been minimized.

@codeant-ai

This comment has been minimized.

@chatgpt-codex-connector

This comment has been minimized.

@codeant-ai codeant-ai Bot added the size:XS This PR changes 0-9 lines, ignoring generated files label Sep 8, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #1098
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-09-08T05:16:01Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-09-08T05:16:01Z

@don-petry
don-petry enabled auto-merge (squash) September 8, 2026 04:46
@coderabbitai

This comment has been minimized.

@don-petry
don-petry disabled auto-merge September 8, 2026 04:46
Comment thread AGENTS.md Outdated
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: none
Skipped (in progress): CodeRabbit review pending completion
```
The PR is in good shape. Once CodeRabbit completes its review, it will post specific findings (if any) as a follow-up comment with actual file/line references. At that point, I can address any concrete defects reported.

@don-petry
don-petry enabled auto-merge (squash) September 8, 2026 04:47
@codeant-ai

This comment has been minimized.

@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the branch protection documentation in AGENTS.md to reflect new policies: dismissing stale reviews on push, requiring code owner reviews, and requiring last push approvals. The reviewer suggested enhancing the documentation by adding links to the CODEOWNERS standard and the Dependabot policy for better context.

Comment thread AGENTS.md Outdated
Comment thread AGENTS.md Outdated
@don-petry
don-petry disabled auto-merge September 8, 2026 04:47
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 8, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@donpetry-bot

donpetry-bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor
Superseded by automated re-review at 74c9012f0950fcc84da831cbff8a9580d4c7a9db — click to expand prior review.

Review — fix requested (cycle 1/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: MEDIUM
Reviewed commit: e7fac23c67a13698cc94796f9ec978d6c9a5381a
Review mode: triage-approved (single reviewer)

Summary

Docs-only change (3 lines in AGENTS.md) updating the branch-protection table to reflect the codified pr-quality ruleset. The three flipped values (dismiss stale reviews, code owner review, last push approval) correctly match standards/rulesets/pr-quality.json. However, the new 'Require last push approval' row contains a factual inaccuracy about the Dependabot rebase workflow, and 3 review threads are unresolved (thread resolution is a required merge gate). Escalating despite triage-approved clearance.

Linked issue analysis

Linked issue #1075 (Compliance audit — 2026-09-04) tracks 12 findings across 6 repos, remediated by running apply-rulesets.sh / apply-repo-settings.sh and per-repo workflow additions. This PR only syncs the AGENTS.md documentation with the codified ruleset — a legitimate part of the remediation, but 'Closes #1075' will close the umbrella issue while other findings (markets gitignore_baseline, .github-private non-stub-agent-shield.yml, and the actual ruleset drift on 5 repos) are remediated out-of-band via script runs, not this PR. A human should confirm those remediations were actually executed before the umbrella issue closes.

Findings

  1. [MEDIUM — blocking] Inaccurate description of Dependabot re-approval (AGENTS.md line 569). The new text claims 'the Dependabot rebase workflow re-approves after branch updates to keep approval valid.' The rebase workflow (dependabot-rebase-reusable.yml) contains no approval step — its own header states it 'merges directly via the APP_TOKEN bypass actor and does not rely on the automerge workflow's re-approval,' and notes the automerge re-approval may not even run after a branch update (latest commit is not from Dependabot, so fetch-metadata verification can fail). Approval is done by the automerge workflow ('gh pr review --approve'), not the rebase workflow. Since AGENTS.md is the org-wide source of truth that agents and humans act on, misdocumenting a security-relevant merge path should be fixed before merge. Suggested wording: last-push approval is satisfied for Dependabot updates because the rebase workflow merges via its bypass actor; the automerge workflow approves eligible Dependabot PRs.
  2. [LOW] 3 unresolved review threads — CodeAnt (Major: bypass actors exempt from stale-review dismissal — a fair caveat, could be addressed with a brief bypass-actor note) and 2 Gemini low-priority link suggestions. Required review thread resolution is enforced on this repo, so these block merge regardless.
  3. [INFO] Table values verified correct — all three settings are true in standards/rulesets/pr-quality.json; the direction of the docs change is right.
  4. [INFO] Secret scan — run_secret_scanning MCP tool not available in this run; gitleaks CI check passed. No secrets in the diff (markdown table only).

CI status

All substantive checks green: Lint, ShellCheck, CodeQL, SonarCloud (quality gate passed), agent-shield, Agent Security Scan, Secret scan (gitleaks), duplicate-decl-gate, CodeRabbit. Pending/cancelled entries are all dev-lead orchestration checks (dispatch/ci-relay/resume — the agent's own retry loop, not merge gates; Dev-Lead is intentionally not a required context per org standards).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

@don-petry
don-petry disabled auto-merge September 8, 2026 04:51
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: None
Skipped (informational): Quality Gate passed summary
```

@don-petry
don-petry enabled auto-merge (squash) September 8, 2026 04:51
@donpetry-bot

donpetry-bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor
Superseded by automated re-review at 74c9012f0950fcc84da831cbff8a9580d4c7a9db — click to expand prior review.

Review — fix requested (cycle 2/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: LOW
Reviewed commit: 74c9012f0950fcc84da831cbff8a9580d4c7a9db
Review mode: triage-approved (single reviewer)

Summary

Re-review after cycle-1 fix commit. The prior blocking finding (inaccurate claim that the Dependabot rebase workflow re-approves after branch updates) is fully resolved: AGENTS.md, standards/github-settings.md, and the dependabot-rebase.yml permissions comment now correctly state that the rebase workflow merges directly via its bypass actor (verified against dependabot-rebase-reusable.yml@dependabot-rebase/v2-stable). The CodeAnt bypass-actor caveat was also incorporated. However, 1 review thread (Gemini low-priority suggestion to link the CODEOWNERS standard in AGENTS.md) remains unresolved, and required review thread resolution is a merge gate on this repo — so approval cannot be granted yet. This is the only remaining blocker; resolving or addressing that single thread should clear the PR.

Linked issue analysis

Linked issue #1075 (Compliance audit — 2026-09-04) is an umbrella tracking 12 findings across 6 repos. This PR syncs org documentation (AGENTS.md branch-protection table) with the codified pr-quality ruleset — a legitimate part of the remediation. Carried forward from the prior review: 'Closes #1075' will close the umbrella issue while the ruleset drift on 5 repos, the markets gitignore_baseline finding, and the .github-private agent-shield.yml finding are remediated out-of-band via script runs. A human (or the dev-lead) should confirm those remediations executed before the umbrella issue auto-closes; this remains informational, not blocking.

Findings

  1. [RESOLVED] Inaccurate Dependabot re-approval description — the fix commit (74c9012) rewrote the wording in AGENTS.md line 569, standards/github-settings.md line 240, and the dependabot-rebase.yml comment to correctly describe the bypass-actor merge path. Verified accurate against the reusable workflow header.
  2. [RESOLVED] CodeAnt bypass-actor caveat — the dismiss-stale-reviews row now notes it does not apply to bypass actors or org admin overrides; the CodeAnt thread is marked resolved.
  3. [LOW — blocking] 1 unresolved review thread — Gemini low-priority suggestion on AGENTS.md (link to the CODEOWNERS standard for navigability). Not outdated, not resolved. Required review thread resolution is enforced on this repo, so this blocks merge regardless of approval. Fix: either apply the one-line link suggestion or resolve the thread with a brief rationale.
  4. [INFO] No new issues introduced — the delta since e7fac23 is docs wording plus a workflow comment; no functional changes.
  5. [INFO] Secret scan — run_secret_scanning MCP tool not available in this run; gitleaks CI check passed. No secret-like content in the diff.

CI status

All checks green on 74c9012: Lint, ShellCheck, CodeQL, SonarCloud (quality gate passed), agent-shield, Agent Security Scan, Secret scan (gitleaks), duplicate-decl-gate, bats, CodeRabbit, dependency-audit. Skipped entries are ecosystem-specific audits and dev-lead orchestration jobs (not merge gates).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Bot: `sonarqubecloud[bot]` (informational)  
**Issues addressed:** 0 (SonarCloud gate passed; CodeRabbit findings already resolved in prior commits)  
**Files changed:** None required  
**Skipped:** 1 informational (SonarCloud quality gate summary)
The PR is ready to merge.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
- **dependabot-rebase.yml lines 51-52**: ✓ Comments document `APP_TOKEN` for both update-branch and merge-PR operations, distinguish from `GITHUB_TOKEN` permission ceiling
### CI Status
- ✅ SonarCloud: Quality Gate Passed, 0 new issues
- ✅ All security, lint, and dependency checks passed
- ✅ Sharded checks (Lint, ShellCheck, Secret scan) all passed
- ⏳ Analyze (actions) still in progress but not a blocker
**Issues addressed:** 2  
**Files changed:** AGENTS.md, standards/workflows/dependabot-rebase.yml  
**Skipped:** 0 (SonarCloud comment is informational status only)
The PR is ready — all bot findings have been addressed and resolved by the harness.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #1098
No changes were committed, but the PR still can't be marked done: a reviewer requested changes. The retry cron will re-attempt automatically. Next attempt after: 2026-09-23T03:47:47Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but I can't mark it done yet: a reviewer requested changes. I'll re-check automatically.
Next attempt after: 2026-09-23T03:47:47Z

@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

don-petry and others added 2 commits September 22, 2026 23:52
- Revert CODEOWNERS Standard reference in AGENTS.md line 569 to link to standards/github-settings.md#codeowners-standard (the canonical reference used in github-settings.md)
- Clarify comments in dependabot-rebase.yml permissions block (lines 51-52) to better distinguish caller's GITHUB_TOKEN scope from APP_TOKEN bypass path used for actual operations

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
1. **AGENTS.md line 569** — CODEOWNERS Standard link ✓
   - Fixed: Changed reference from `standards/codeowners-standard.md` to `standards/github-settings.md#codeowners-standard` (the canonical reference used in github-settings.md)
   - CodeRabbit status: Marked "✅ Addressed in commits 52c8936 to d587a62"
2. **standards/workflows/dependabot-rebase.yml lines 51–52** — APP_TOKEN documentation ✓
   - Fixed: Clarified comments to distinguish caller's `GITHUB_TOKEN` scope from `APP_TOKEN` bypass path via `APP_ID`/`APP_PRIVATE_KEY`
   - CodeRabbit status: Marked "✅ Addressed in commits 52c8936 to d587a62"
**PR State:**
- All 13 CI checks passing
- CodeRabbit review threads resolved and outdated (CodeRabbit auto-detected the fixes)
- No further action required

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread standards/workflows/dependabot-rebase.yml
don-petry and others added 2 commits September 24, 2026 06:49
…ct APP_TOKEN usage

The live caller's permission comments were outdated — they claimed
update-branch and merge operations used GITHUB_TOKEN, but the reusable
workflow actually uses APP_TOKEN for both operations. Updated comments to
match the template in standards/workflows/dependabot-rebase.yml for consistency.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
## Summary
**Bot:** CodeRabbit (Tier 1 blocker)
**Issues addressed:** 2
- AGENTS.md CODEOWNERS link: Addressed and resolved/outdated — harness will auto-resolve
- dependabot-rebase.yml APP_TOKEN comments: Addressed and resolved/outdated — harness will auto-resolve
**Files with fixes in place:**
- `AGENTS.md` (line 569)
- `standards/workflows/dependabot-rebase.yml` (lines 51-52)
**SonarCloud:** Passed (informational, 0 findings)
All identified issues have been resolved. The outdated CodeRabbit threads will be auto-resolved by the harness.

@don-petry

Copy link
Copy Markdown
Contributor Author

Acknowledged — this is SonarCloud's Quality Gate Passed status notice (0 new issues, quality gate passed). It is a status notice, not an actionable code finding, so no action is needed on this PR.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: fix-reviews)

PR: #1098
No changes were committed, but the PR still can't be marked done: a reviewer requested changes. The retry cron will re-attempt automatically. Next attempt after: 2026-09-24T12:39:02Z

@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (no-changes)

Agent reasoning
Addressed 0 threads (open threads list was empty):
- Review threads: none open
- PR issue comments: all dispositioned already
    · bot findings (qodo, codeant×2, codex, coderabbit, sonarqubecloud): minimized/RESOLVED
    · maintainer disposition note IC_kwDORyesfc8AAAABUNDsHg: already answered (disposition=answered)
    · all other non-minimized comments are our own automation (skipped; never self-reply)
- Tier-1 blockers: none (all CI success/skipped; cancelled+in_progress dispatch are self-runs; no CHANGES_REQUESTED)
Test verification: no code changes made — working tree clean; existing CI is green
Files changed: none
```

@donpetry-bot

Copy link
Copy Markdown
Contributor

Review — fix requested (cycle 1/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: LOW
Reviewed commit: f6905e809521defa3c3cbd5457692f10c80f8c05
Cascade: triage → deep (triage: haiku 4.5 [sonnet 5] → deep: opus 4.8 [sonnet 5] + duck: o4-mini → audit: fable 5)

Summary

Documentation/comment-only change (8 lines) that correctly fixes stale docstrings — verified against petry-projects/.github dependabot-rebase-reusable.yml, the workflow does use APP_TOKEN and merges directly via the bypass actor without re-approving, so the new wording is accurate and the CodeAnt nitpick is already addressed. However the PR uses 'Closes #1075', which auto-closes a 12-finding compliance-audit umbrella whose remediations require actual ruleset/settings scripts, none of which are present in this docs-only diff. Also missing the required risk/test-plan/rollback description sections.

Findings

  • major: PR body says 'Closes Compliance audit — 2026-09-04 #1075', which auto-closes the compliance-audit umbrella tracking 12 findings across 6 repos (ruleset drift on google-app-scripts/TalkTerm/broodly/bmad-bgreat-suite, bypass-actor config on markets, push-protection/gitignore on markets, non-stub agent-shield.yml on .github-private). Their remediations are apply-rulesets.sh / apply-repo-settings.sh / per-repo workflow additions — none of which appear in this docs-only diff. Merging would prematurely close the umbrella and orphan the unremediated findings. If this PR is only the documentation slice, use 'Relates to Compliance audit — 2026-09-04 #1075' (not 'Closes') so sibling remediation PRs keep the issue open.
  • minor: PR description is missing 3 of 5 required sections (risk, test-plan, rollback), consistent with the deterministic SAFETY_CHECKS finding. The standards-sync/trusted-stub carve-out does not apply here (TRUSTED_STUB_SYNC=false, WORKFLOW_ONLY_CHANGE=false), so the terse-description gate stands.
  • info: Confirmed the corrected wording is accurate: fetched petry-projects/.github .github/workflows/dependabot-rebase-reusable.yml — it mints an APP_TOKEN via actions/create-github-app-token (APP_ID/APP_PRIVATE_KEY), calls update-branch with APP_TOKEN, and merges directly through the bypass actor (bypass_mode: always) without re-approving. The old docstrings ('re-approve PRs after branch update' / 'workflow re-approves after branch updates') were wrong; this PR fixes them and the AGENTS.md branch-protection table to match standards/github-settings.md. The 2026-09-08 CodeAnt nitpick at AGENTS.md:569 predates this fix and is already resolved.

Reviewed by the PR-review cascade (triage: haiku 4.5 [sonnet 5] → deep: opus 4.8 [sonnet 5] + duck: o4-mini → audit: fable 5). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compliance audit — 2026-09-04

2 participants