Skip to content

chore(metadata): record public-surface label taxonomy wave 3 - #1653

Draft
seonghobae wants to merge 146 commits into
mainfrom
chore/label-taxonomy-public-surface-wave-3
Draft

seonghobae wants to merge 146 commits into
mainfrom
chore/label-taxonomy-public-surface-wave-3

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Record evidence-backed repository issue/PR semantic types in the organization-owned label taxonomy so live classifications remain idempotent rather than one-off mutations.

The current branch doctoring record covers 175 active evidence-backed targets: a reconciled 47-target operating baseline plus 128 reviewed wave-3 targets. The central taxonomy owns the managed primary semantic labels (feature -> enhancement, bug -> bug, documentation -> documentation); richer repository-local priority, workflow-status, security, maintenance, architecture, component, and type: maintenance labels remain outside that managed semantic set.

Successor / stale-target reconciliation

The active inventory follows current canonical writers instead of retaining stale issue identities merely to keep counts stable. Existing branch history records successor carryover including codec-carver#514 → codec-carver#516, g7#2 → g7#3, merged psychometrics-commons#442 → current psychometrics-commons#434, superseded scopeweave#650 → scopeweave#651, and complete carryover for retired contextual-orchestrator#1003 and accounting-information-platform#45 into already-recorded canonical targets.

The current taxonomy blob is 2af5f823dea1e463edc38a4bf80295ace6831f2e. Current head additionally integrates the live-read assignments for pg-erd-cloud#1100, .github#2037/#2039, naruon#1603/#1604/#1605/#1606/#1607/#1608/#1609, appguardrail#1182/#1183, litellm-patched-proxy#5, 9drive#4, ConceptWeave#40, noema#560, and quarantine-sandbox-runtime#99/#100; tests intentionally pin exact inventory/blob identity, and the operator records must move atomically with any assignment change. Fresh traversal has added coordination on this PR for newly classified targets such as naruon#1541, learning-record-store#6, ContextualWisdomLab.github.io#204, pg-erd-cloud#1061, naruon#1500, html4tree#590, contextual-orchestrator#1028, naruon#1539, and pingora-gateway#17; those are live repository classifications but are not claimed as integrated taxonomy entries until this branch's config/test/doctoring set is updated together.

Exact authority — 2026-09-27

GitHub reports this PR open, Draft, and mechanically mergeable. Current exact head is 04f8d5135065498dce50b2150e4fa986e70ac60f.

The stale-base repair was performed without force-push. RED commit d8e7521de73035e81590f15db84636d2313da6f8 proves that repository names containing .. or ending in . were accepted. Two-parent merge 04f8d5135065498dce50b2150e4fa986e70ac60f preserves that test and current protected main@e6334e229581a918e2f22de18733b76fa65d7e71; its tree is 056d79a255439ec68aad299902b058e3111a0c6c. The main-side stricter repository-name validation and branch-side bounded ThreadPoolExecutor reconciliation are both present.

Fresh compare is ahead 63 / behind 0 with protected main as the merge base and exactly eight changed files. A detached checkout of the exact remote head passed all 19 label reconciliation/taxonomy tests, Python compilation, taxonomy --validate-only, and git diff --check.

Exact-head Repository Metadata Reconcile 36271689379, CodeQL PR 36271689369, SAST Semgrep 36271689346, Security Scan 36271689383, and Python Security 36271689343 are queued. The Reviews API still contains a CHANGES_REQUESTED verdict and has zero independent approvals; all inline threads are resolved. Draft status remains correct and this PR must not merge until current-head Checks and review admission settle.

The branch currently carries 63 commits and eight changed files. Continue preserving the single writer: live classification increments recorded in PR comments are not integrated until config, exact inventory tests/fixtures, and operator records move atomically on this branch.

Governance / concurrency

This branch is independent of Draft metadata desired-state PR #1639, which owns repository descriptions/topics/Pages intent. No branch protection, repository settings, Pages settings, secrets, review rules, or leaf repository source is changed here.

The recorded classifications do not make Draft work Ready, unblock blocked work, transfer merge authority, or waive exact-head checks/reviews. A source assignment is not live convergence evidence until repository labels are re-read after protected integration.

Summary by CodeRabbit

  • 새 기능

    • 저장소 라벨 분류 체계에 다양한 저장소·이슈 매핑을 추가하고 일부 기존 매핑을 최신화했습니다.
    • 라벨 분류 체계의 Wave 3 운영 문서를 추가했습니다.
    • 독립적인 라벨 대상 처리를 병렬화해 조정 작업을 빠르게 완료하도록 개선했습니다.
  • 문서

    • 라벨 대상 운영 기록과 후속 조정 기준을 최신 상태로 갱신했습니다.
  • 테스트

    • 병렬 처리, 라벨 분류 데이터 무결성, 워크플로 트리거 경로 검증을 추가·강화했습니다.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
📝 Walkthrough

Walkthrough

저장소 라벨 taxonomy와 운영 기록에 대상 매핑을 추가·수정했습니다. 라벨 reconciliation은 병렬 실행과 일괄 오류 출력을 사용합니다. 워크플로 트리거와 taxonomy 검증 테스트도 갱신했습니다.

Changes

저장소 라벨 reconciliation

Layer / File(s) Summary
Taxonomy 및 운영 기록 갱신
config/repository-label-taxonomy.json, docs/doctoring/repository-label-taxonomy-wave-3.md, docs/doctoring/repository-public-surface-reconciliation.md
저장소와 이슈의 라벨 유형 매핑을 추가·수정했습니다. wave-3 대상과 successor reconciliation 운영 기록을 갱신했습니다.
병렬 reconciliation 실행
scripts/ci/reconcile_repository_labels.py, tests/test_repository_label_reconciliation.py
assignment 처리를 최대 8개 worker로 병렬화했습니다. 실패를 수집한 뒤 한 번에 출력합니다. 동시 실행 테스트를 추가했습니다.
워크플로 트리거 및 taxonomy 검증
.github/workflows/repository-metadata-reconcile.yml, tests/test_repository_label_taxonomy.py, tests/test_repository_label_taxonomy_workflow_trigger.py
운영 기록과 워크플로 테스트 파일을 pull request 경로에 추가했습니다. taxonomy blob, 중복 assignment, 유형 유효성, 운영 기록 결합을 검증합니다.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: 🟡 Moderate · up to cc2cf

This change expands centrally reconciled labels and parallelizes their application, but it currently assigns an incorrect semantic label to disksage#315, records an inaccurate wave-3 inventory, and can cause nondeterministic test failures. Correct these issues before merging.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 4 files. (4 skipped: 4…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 PR의 주요 변경 사항인 public-surface label taxonomy wave 3 기록을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/label-taxonomy-public-surface-wave-3

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks labels Sep 1, 2026 — with ChatGPT Codex Connector
devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Fresh organization traversal found three additional evidence-backed semantic-type targets that are not in the current 61-target exact assignment set and should be folded into this same taxonomy lane (or its direct successor after re-reading the current head), rather than opened as a competing manifest writer:

  • ContextualWisdomLab/disksage#315 → documentation (product-first README / PRD / public Pages source; the PR is currently repo-locally status: blocked because four substantive irreversible-purge safety findings remain).
  • ContextualWisdomLab/macos_utility_packs#4 → documentation (public README/DeepWiki/docs landing surface; live repository description is already concise, while topics and Pages remain unset).
  • ContextualWisdomLab/wardnet#144 → bug as the semantic primary type (the Kubernetes manifest-path repair is causal; documentation remains a useful repository-local affected-surface label).

Also corrected repository-local workflow status where fresh evidence showed a real prerequisite/control-plane blocker rather than mere review wait: disksage#315, accounting-information-platform#37, learning-record-store#1, and learning-management-platform#1 now carry status: blocked with stale status: needs-review removed. These status/priority labels should remain outside this PR's centrally managed semantic-type set, consistent with its current boundary.

When extending the exact assignment list, update the exact-set test and operating-record count together; do not weaken exact matching or transfer queued/predecessor evidence.

devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Fresh organization-label reconciliation found three additional evidence-backed documentation targets that are not yet present in this branch's exact assignment inventory: ContextualWisdomLab/fast-mlsirm#1519, ContextualWisdomLab/governance-risk-compliance#60, and ContextualWisdomLab/naruon#1527. Their live PR labels have been normalized to type: docs in the current pass; GRC #60 also now carries priority: medium and status: draft because its PR body explicitly requires Draft-only handling. Please fold these three targets into config/repository-label-taxonomy.json, the exact-assignment test, and the wave-3 operating record on this existing writer rather than creating a competing taxonomy PR. Existing branch targets reconciled live in the same pass include CalendarWeave #1, RankWeave #40, EgressWeave #190, appguardrail #1077, life-os #211, Orgmetra #160, j-planner #2, learning-{management-platform,content-studio,record-store} #1, mhtml-etl-gateway #44/#56, saju-caldav #42, DiagramWeave #33, kaefa #81, wardnet #130, enterprise-architecture-core #18/#37, pg-erd-cloud #1040, scopeweave #625, and metering-billing-platform #157. Preserve each repository-local priority/status/security/component label; this central lane should continue to own only the primary semantic type mapping.

Copy link
Copy Markdown
Contributor Author

One desired-state correction from the same pass: ContextualWisdomLab/disksage#315 should be bug, not documentation, as its current branch contains substantive fail-closed containment for an unsafe irreversible cache-trash purge plus a release-verifier defect repair; the documentation/PRD work is secondary. I normalized the live primary semantic label to type: bug while preserving documentation, priority: medium, and status: blocked. Please change the #315 assignment in the existing exact taxonomy/test/operating-record writer rather than adding type: docs back.

Copy link
Copy Markdown
Contributor Author

A second primary-type correction: ContextualWisdomLab/fast-mlsirm#1717 should be bug, not documentation. Although it owns the README/Pages entry, its current exact branch also repairs repository runner selectors, executable acquisition-release orchestration/provenance contracts, and fail-closed source-tree sealing under a fix(ci) lane. I normalized the live primary semantic label to type: bug and preserved documentation, priority: high, and status: needs-review. Please update the exact taxonomy assignment/test/operating record accordingly.

Preserve the live security-owner and Gap-evidence lineage while merging the independently reviewed RED-to-GREEN repair that removes urlopen suppressions, accepts one credential-free HTTPS redirect only to the exact GitHub release-assets host, bounds reads, and closes every response/connection path.

Local exact-tree evidence: 16 focused tests passed; git diff --check passed. The same repair on the immediately preceding owner tree passed 5,178 tests, 8 skipped, and 40 subtests, and independent review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
Replace only the corrupted 120,060-byte binary payload with the last complete 3,678-line UTF-8 baseline from the immediate valid predecessor. Preserve the SAST transport repair and all other a5ddcfc changes. Fresh exact-head hosted evidence remains required.
Complete the Semgrep transport repair by constructing the urllib opener with ProxyHandler({}). This prevents environment-derived HTTPS proxy authorities and proxy credentials from entering the fixed GitHub-to-release-assets request path while preserving the reviewed one-hop redirect handler.

RED-to-GREEN: the bounded-download contract first required an explicit empty proxy map and failed when build_opener received only the redirect handler. Final focused verification: 16 passed; compileall and git diff --check passed. Independent offline replay with a credential-bearing https_proxy confirmed exclusion, and re-review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
Preserve the live exact-head SAST RCA documentation and the independently reviewed ProxyHandler({}) repair as ordinary parents. The merged tree retains the restored complete Gap baseline, fixed one-hop redirect handler, ambient proxy/auth exclusion, focused GREEN evidence, and all release HOLD language.

Focused exact-tree verification: 16 passed; git diff --check passed. Fresh hosted exact-head evidence and qualifying approval remain mandatory.
Preserve the existing combined #2530 successor as first parent and integrate current #2531 as canonical security owner. The conflict resolution retains every downstream #2530 Gap row while carrying the complete owner RCA, proxy-free bounded downloader, exact one-hop redirect policy, executable contracts, and SAST closure evidence.

Exact local verification: 31 focused tests passed; compileall, Ruff, and git diff --check passed.

Copy link
Copy Markdown
Contributor Author

2026-10-01 failed Checks RCA — canonical owner stack consumed

Previous exact head 04f8d5135065498dce50b2150e4fa986e70ac60f had two actionable source/config failures:

  • Python Security 36271689343, job 108547918952: requirements-strix-ci-hashes.txt selected AnyIO 4.14.0, and pip-audit reported CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349 (fixed in 4.14.2).
  • Repository Metadata Reconcile 36271689379, job 108486737936: the quality suite failed collection with ModuleNotFoundError: defusedxml from scripts/ci/noema_review_document.py.

Current head 5cd141ec2c33b631d164af936cd1c9de70e4c9a4 is an ordinary two-parent merge of complete #1653 and canonical stacked owner #2530@813f16fad7528b035d6ae4386cd176c9a67413c1 (whose ancestry includes security owner #2531@7900ba4c4d68c378023592252f2579646fad9aaa). The resulting tree is e8b2709d48be197cb730cb5d8fa1b62fdff75225: it preserves the label-taxonomy delta, pins AnyIO 4.14.2 in source/generated Strix locks, and supplies the hash-locked document-reader runtime dependency.

Fresh local focused verification on that exact merge tree: 32 tests passed across metadata live/workflow contracts plus Noema/Strix dependency contracts; git diff --check passed. Owner #2531's exact-head Python Security runs 36804208106 and 36803791283 are GREEN, and owner #2530's Repository Metadata Reconcile 36803907284 is GREEN.

New current-head runs are Repository Metadata 36811202649, Python Security 36811202694, Agent Mention Quality 36811202679, Agent Review Quality 36811202636, Trusted uv Quality 36811202519, Security 36811202524, SAST 36811202526, and CodeQL 36811202601. Keep Draft/HOLD until all are terminal and current-head approval exists. No force update, rebase, gate weakening, or unchanged rerun was used.

Reproduce the exact Trusted uv 99% branch-coverage failure from run 36811202519, job 110206427182. Exercise non-200 and opener-raised HTTPError closure, and replace the impossible nullable-response branch with one unconditional response-owned close scope. Preserve the exact host, redirect, byte, digest, timeout, and fail-closed boundaries.

Focused evidence: 17 passed; verify_release_maturin_tool_assets.py 107/107 statements and 34/34 branches; compileall and git diff --check GREEN. Full local collection reached 5,311 passed, 5 skipped, and 40 subtests; two unrelated native fixture cases failed because the ephemeral local environment lacked the maturin executable, so hosted exact-head full-suite evidence remains authoritative and required.
Bind the Maturin verifier source and focused regression test to both pull-request and protected-branch paths of the complete Trusted uv quality gate. The test-only trigger contract reproduces the omission before the workflow repair.

Focused evidence: 24 passed; verifier 107/107 statements and 34/34 branches; workflow YAML parse, compileall, and git diff --check GREEN.
Run the read-only complete Trusted uv quality gate for every pull-request base instead of only PRs targeting main. Preserve the protected-main push scope. A RED-to-GREEN workflow contract proves that canonical owner stacks cannot suppress exact-head evidence.

Focused evidence: 25 passed; verifier 107/107 statements and 34/34 branches; YAML parse and git diff --check GREEN.
Ordinary two-parent merge preserves the complete #1653 label-taxonomy delta and consumes canonical #2530 exact head dc54310. The owner head repairs Maturin response closure, restores 100% full-suite branch evidence, and admits stacked quality checks.

Owner hosted evidence: Trusted uv Materializer Quality CI run 36813245691 GREEN with 5,314 passed, 5 skipped, 40 subtests, 18,767/18,767 statements and 7,648/7,648 branches; Security, SAST, and Metadata GREEN. Local merge-tree evidence: 25 focused tests, verifier 107/107 statements and 34/34 branches, and git diff --check GREEN. Fresh consumer exact-head hosted checks remain required.

Copy link
Copy Markdown
Contributor Author

Consumed canonical coverage owner #2530 by ordinary two-parent merge at exact head b10b2d0c31e7762c30a5dcfa2a1452f4c674f622, tree 05836fc3b3aa23302ccc4e160af7cf04bd73f1e0. Parents are prior #1653 5cd141ec2c33b631d164af936cd1c9de70e4c9a4 and verified owner #2530 dc54310c8c5ee6637274e7e82f5ea53d64ad91e6; the label-taxonomy delta remains intact.

Owner exact-head Trusted uv Materializer Quality CI 36813245691 is terminal GREEN: 5,314 passed, 5 skipped, 40 subtests; production 18,767/18,767 statements and 7,648/7,648 branches. Owner Security, SAST, and Metadata are also GREEN. Local merge-tree evidence is 25 focused tests, verifier 107/107 statements and 34/34 branches, and clean git diff --check.

Fresh consumer exact-head hosted Checks are now required. The PR remains Draft / Proposed; Draft-skipped CodeQL is not acceptance, and no prior-head evidence is promoted. No force update, rebase, gate weakening, threshold change, self-approval, or predecessor closure was used.

Copy link
Copy Markdown
Contributor Author

Consumer exact-head revalidation update for b10b2d0c31e7762c30a5dcfa2a1452f4c674f622: Trusted uv Materializer Quality CI 36813668084, job 110213968910, is terminal GREEN. The complete central suite passed 5,316 tests, 5 optional skips, and 40 subtests; production coverage is 18,774/18,774 statements and 7,650/7,650 branches (100%). The repaired Maturin verifier is 107/107 statements and 34/34 branches.

At this same exact head, Security run 36813667987, Python Security 36813667948, SAST 36813668255, Repository Metadata 36813668166, and Agent Mention quality 36813667991 are terminal GREEN. Agent Review Runtime Quality 36813668125 remains in progress and Draft CodeQL 36813668008 is skipped; neither is represented as passing. The PR remains Draft / Proposed and unmerged.

Copy link
Copy Markdown
Contributor Author

Final exact-head check update: Agent Review Runtime Quality run 36813668125, job 110213969134, is now terminal GREEN. Thus every non-CodeQL hosted workflow generated for b10b2d0c31e7762c30a5dcfa2a1452f4c674f622 is terminal GREEN. CodeQL remains Draft-skipped, there is no current-head qualifying APPROVED review, and historical CHANGES_REQUESTED reviews are not silently treated as resolved approval. The PR remains Draft and unmerged.

seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

2026-10-01 21:14 UTC handoff continuation

The prior handoff comment reached GitHub's body limit; this comment continues the same evidence ledger.

  • New pg-erd-cloud#1249: restored generated .jules/bolt.md to the protected-base blob by ordinary commit; retained the Prisma source delta at exact head fea861ad4afa0a79e8bff2d54ec54770cda21fb1.
  • Normalized the title to refactor(prisma): index relation fields by composite key, set Proposed/Draft, and applied enhancement/medium/draft/maintenance classification.
  • The performance claim has no realistic ERD benchmark, allocation profile, output-parity regression, sanitized-key collision case, or same-source-field multi-edge fixture. Fresh exact-head Checks are required; predecessor/non-terminal results are not passing.
  • No merge, Force Push, destructive rebase, base retarget, manual rerun, or gate bypass was used.

Predecessor ledger: #1653 (comment)

  • Verification readback caught new concurrent writes: clearfolio#663 had reintroduced .jules/palette.md plus a POM-only Jackson copy at 97dc0210...; both were restored to base and the canonical Gap baseline retained at current cd8bb118.... newsdom-api#989 had reintroduced .jules/bolt.md plus an empty-vulnerability Trivy policy rewrite at 7f8efb84...; both were restored to base at current 130d3bb2.... Both remain Draft/open; no history rewrite or premature retirement occurred.
  • .github#2554 exact-head CodeQL 36926646328 is terminal RED: actions 110585680344 and Python 110585681209 both dispatch=success/verdict=pending; Security/Python Security/Semgrep are GREEN. The body now records this RCA and remains Draft without manual rerun.

2026-10-02 — seedream_evasepic#538 post-writer repair

  • Exact head dd25f3cf5507956f34b91d9716c471b15c2e87d4, Draft, base develop@06e3efc20d7d5ffa3f284188af0d181ce8403132.
  • Preserved the concurrent UTF-8/C1 regression and shared sanitizer comment; restored generated .jules/sentinel.md to the protected-base blob with an ordinary child commit.
  • Effective delta: terminal-output.sh plus test_terminal_output.sh.
  • Exact-head CLI UX 36948957961, Security 36948958005, and Semgrep 36948957997 are GREEN; CodeQL 36948957947 is skipped while Draft; approvals 0, unresolved threads 0. No merge/Ready/Close.

2026-10-02 — EmbedRelay#4 CodeQL RCA and review metadata

  • Exact head 4ccfe7b921e9e8eeae6a6c60da49e8d42b8ae0b1, Ready, mergeable, protected main@816dcacd4fc1903d91c5cae9b77e37e21811a78d.
  • Security 36946858964 and Semgrep 36946858995 are GREEN.
  • CodeQL 36946858996 Python 110650942123 and Actions 110650942137 are RED with DISPATCH_OUTCOME=success, VERDICT_STATE=pending; no source defect verdict exists.
  • All 26 threads resolved; independent approvals 0. Ready remains review admission; label normalized to status: needs-review. Merge remains held.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant