feat(job-analysis): add governed qualification-rule review - #104
feat(job-analysis): add governed qualification-rule review#104seonghobae wants to merge 16 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-head correction: production implementation is now present at |
|
Current-head evidence update: |
|
@opencode-agent Please review the current unchanged head against protected |
…n-subclassable Strix OpenAI-direct scan of head d92ac4c surfaced one MEDIUM finding: a hostile in-process subclass could override _validated_payload to bypass all trust-bearing field validation. Repair: __init_subclass__ now raises TypeError for every subclass, so the trust boundary is non-overridable by construction. Regression coverage asserts subclass definition fails closed at class-definition time and base-class canonical evidence stays stable per issued instance. 55 tests, 100% owned statement/branch coverage.
|
Lifecycle correction: live protected |
Adopt protected develop without resurrecting the retired package-local quality workflow. Move the Job Qualification Rule Review exact CPython 3.14.7, SHA-256-bound installed-wheel, isolated toolchain, and 100% statement/branch coverage contract into canonical Foundation CI; add a regression that rejects leaf-workflow reintroduction; and reseal the exact Foundation manifest. No Job Analysis domain behavior, human-review authority, coverage threshold, protected history, or central gate is weakened.
Buyer-visible gap
Orgmetra needs governed evidence showing which Job Analysis evidence supports a proposed qualification rule before that rule can influence recruiting or selection. This lane remains a human-reviewed, PII-minimized qualification-rule review boundary; it does not evaluate candidates, reject applicants, mutate Job/Job Analysis, or write foreign CWL repositories.
Retained domain contract
The original RED/implementation chain remains intact:
d92ac4cb...hardened malformed Job references,79adb799...sealedJobQualificationRuleReviewPacketagainst subclass override, and14eab4eb...repaired deterministic test-quality defects. Canonical evidence stays fixed tojob_qualification_rule_review, mandatory human review,reviewed_for_authoritative_resolution, andnot_authorized_for_candidate_or_employment_decision.Candidate/person PII, candidate qualification outcomes, assessment/cut scores, compensation, raw rule text, prompts and model output remain excluded. Before authoritative persistence/use, the host must re-resolve tenant/Job/Job Analysis, rule artifact, Task/KSAO/source provenance and reviewer authority at the business-effective coordinate and preserve immutable audit/outbox evidence.
Protected-parent reconciliation completed
Protected adoption authority is
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. The branch adopted it through ordinary non-force two-parent successor5bc1663afbd363dc75524afb0cebcf856595d421and then advanced docs-only to current exactfde420ae11680a8b54eada785683db1afecca6bd.The previously verified synthetic merge tree would have resurrected
.github/workflows/job-qualification-rule-review-quality.ymlwithruns-on: ubuntu-latest, undoing protected #161's repository-quality consolidation. That defect remains repaired: the package-local workflow stays retired; canonical Foundation preserves exact CPython 3.14.7, SHA-256-bound installed-wheel, isolated test-toolchain, package-import provenance and 100% statement/branch coverage;test_artifact_execution.pyrejects leaf-workflow reintroduction; andmanifest.jsonremains sealed to the final Foundation bytes from that repair.The follow-up traceability successor corrected stale
develop@9e3e484...and retired-workflow claims without changing production behavior or the Foundation manifest.Current exact-head acceptance — 2026-09-06
GitHub reports this PR open · Draft · mechanically mergeable at exact
fde420ae11680a8b54eada785683db1afecca6bdon protecteddevelop@eb9757f....34017994517: terminal SUCCESS.34017994471: terminal SUCCESS.34017994490: terminal FAILURE only independency-review. Exact head checkout succeeds;Check dependency review supportfails before the Dependency Review action runs. OSV, Scorecard and Trivy are terminal SUCCESS. This remains the central Dependency Review availability/control-plane class of failure, not an Orgmetra source finding.34017994488: terminal FAILURE only after both Python and Actions compatibility shards successfully request current-head dispatch; each then failsRelease runner or enforce current-head CodeQL verdict. No source/SARIF finding is established by this wrapper failure.Submitted formal reviews remain COMMENTED-only; no qualifying independent
APPROVEDreview exists. All currently visible review threads are resolved. Keep Draft; do not synthesize verdicts, no-op retrigger, self-approve, use routine administrator bypass, weaken gates, transfer predecessor evidence, force-push/destructively rebase, or simply Close the valid delta.Stack order
#105 remains Draft at child exact
e9e4731b...on predecessor parent snapshotd92ac4cb...; it does not yet contain the current #104 trust-boundary/protected-parent/traceability repairs. Required order is: restore current-head central gate availability/authorization and obtain qualifying review for #104 → normal protected integration → #105 non-force adoption/retarget preserving its full persistence/search-path/PostgreSQL/provenance delta → retire/reconcile #105's own historical package-local workflow without resurrecting leaf CI → reseal final tracked bytes → fresh descendant acceptance.