[Lopu] Complete single-entry listeners and all-target CodeQL - #404
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
✅ Develop S3 preview ready
The alias passed the develop bucket CORS preflight and a final live PR/SHA fence. Generic Vercel Preview deployments use the shared development runtime; this controller adds the stable exact-SHA alias and marker-scoped cleanup. |
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
|
🤝 Merged No AI resolution was needed by merge time; the branch was updated with a plain merge commit.
Please review the merge commit before relying on it. |
Structural `graphify update` completed (graphify 0.9.4); LLM semantic extraction failed, so the verified structural graph was preserved. Refreshed by the resolve-pr-conflicts workflow: https://github.com/lopugit/thingtime/actions/runs/32831578096
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
Lopu repository reviewLopu reviewed this PR against main as Thingtime's principal PR and repository manager. Backend: Claude Code default. Lopu found no justified local change to publish from this review pass. Lopu also opened a controller/workflow repair PR for the failed check root cause. Lopu review — PR #404 · [Lopu] Complete single-entry listeners and all-target CodeQLCompared: Authorized promotion PR. Head Checks: no red marks. The only non-pass is CodeQL: 0 open alerts on this head. Nothing to fix or disposition. VerdictNo changes needed. The consolidation is correct and — unusually — it is What I verifiedThe The CodeQL listener split is sound. The contract file earns its keep. Beyond the mapping assertions, it now The CI Control re-route is consistent.
Cross-PR finding — this PR and #395 fix the same symptom at different layers, and both are neededWhile reviewing #395 (which repairs
Push events run workflows from the pushed branch, so every open feature The practical consequence for sequencing:
They are complementary, not redundant, and #395 is worth landing first because Note on the diff sizeThe Changes made in the worktreeNone. The change is correct, atomic across the default-branch dispatch Validation
— Lopu |
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
🦉 Lopu — coherent on
|
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
|
🤖 Lopu — consolidation looks right; two cross-PR notes No changes requested. The The detail I checked hardest: the 1. This PR and #395 fix the same symptom at different layers — both are neededWhile reviewing #395 (which repairs
Push events run workflows from the pushed branch, so every open feature branch cut before this consolidation still carries a second push-triggered caller and keeps colliding with So: this PR is the durable fix (removes the duplicate caller going forward); #395 fixes the engine's concurrency group on 2.
|
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json
…arget CodeQL # Conflicts: # graphify-out/cache/semantic/1023dac098eb85a01dd9068b82500ff5621366ded6587be0ac29e7f3c8aa2611.json # graphify-out/cache/semantic/139ffa1a4fce7e8913d18ef419b09883f3065a993e4c91a1dd8b70a884bf59d3.json # graphify-out/cache/semantic/a506538ceab157e4094e237ac38fa5806d240da7147555859adc2ba81fe97d02.json # graphify-out/cache/semantic/e855b4869250114967bd729c9ee7020e2a4b2197d4bc3a244c7eb8178d0a7f33.json
Outcome
Completes the post-merge activation audit for #397.
pull_requestCodeQL checks associated with the PR while sending arbitrary-target metadata through the separate protected handoff.Dependency
Merge #403 into
github-actionsfirst. It publishes the new protected CodeQL handoff and fixes the durable Lopu queue. This PR then activates those references onmain; its main push will let the corrected controller synchronizemainintodevelop.Validation
node remix/scripts/workflow-caller-contract.mjs— 7 listenerscorepack pnpm --dir remix run test:ci-control— 20/20 passingDo not enable advanced CodeQL yet. After #403 and this PR merge, verify the listener runs, set
CODEQL_CENTRAL_PR_ENABLED=true, disable default setup, then setCODEQL_ADVANCED_ENABLED=true.