Skip to content

feat(supply-chain): policies and review workflow - #111

Merged
balcsida merged 2 commits into
feat/supply-chain/m4-importsfrom
feat/supply-chain/m5-review
Sep 22, 2026
Merged

balcsida merged 2 commits into
feat/supply-chain/m4-importsfrom
feat/supply-chain/m5-review

Conversation

@balcsida

@balcsida balcsida commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Milestone 5. Depends on #110. Three record kinds stay separate and are never edited, only superseded.

  • Policy engine (internal/supplychain/policy) – walks the SPDX expression tree: AND takes the worst operand, OR the best (acceptable branches are reported; choosing one is a separate recorded decision), WITH pairs are their own terms and are never approved by their base license, unknown identifiers/references follow the policy's unknown handling and never become approved. Rules are validated against the pinned list and may not list a term in two classes. The shipped policy is a clearly labelled example fixture; unknown_handling must be review_required or prohibited.
  • Review service – queue of authorized occurrences whose verdict is not approved or whose decision went stale (expired exception / changed evidence, with the reason); human conclusions stored as immutable human evidence that override automated evidence without erasing it (disagreement stays visible); approve / reject / exception decisions recording policy version + verdict, reviewer, reason, usage context, expiry (≤ 1 year); optimistic concurrency – conclusions and decisions must echo the current assessment fingerprint (409 stale_basis); background re-evaluation retains historical results; repository-scoped review grants (admin-only; reviewers still need read access and cannot grant themselves); append-only audit trail (DB trigger).
  • Routes under /v1/supply-chain/review/* and /v1/supply-chain/policies, designed in OpenAPI. Migration 036.

Verification

Policy truth table (leaves, AND, OR with branch reporting, WITH, or-later handling, grouping differences, unknown handling never approves, rule validation). Integration test against PostgreSQL: install/activate example, invalid rules and unknown_handling=approved refused, evaluation counts and idempotency, queue scoping per principal, full permission matrix, stale-basis conflicts, exception expiry (queue + history), re-evaluation after a conclusion (prohibited → approved, history retained), human evidence coexisting with registry evidence, superseded decisions, append-only events.

Implications

  • Migration: 036 additive (policies, conclusions, policy results, decisions, review grants, review events with an append-only trigger).
  • Security: policy administration is admin-only; review capability is repository-scoped and separate from read access. No legal-obligation advice and no release-blocking gates.

Part of the Dependencies & Licenses stack (native GitHub stack #114, ten layers, main ← #104 ← #105 ← #106 ← #107 ← #108 ← #109 ← #110 ← #111 ← #112 ← #113). Design: ADR-0017; living plan with the full validation table: docs/execplans/supply-chain.md. All commits are SSH-signed. Nothing here calls a live GitHub Enterprise Server or a live package registry; GitHub and registry behavior is exercised against fixtures and fake servers only.

Stack created with GitHub Stacks CLI

@balcsida
balcsida added this pull request to stack #114 September 22, 2026 21:06
@balcsida balcsida changed the title feat/supply chain/m5 review feat(supply-chain): policies and review workflow Sep 22, 2026
@balcsida
balcsida force-pushed the feat/supply-chain/m5-review branch 2 times, most recently from 7b1cc75 to 9e8a76f Compare September 22, 2026 22:19
@balcsida
balcsida marked this pull request as ready for review September 22, 2026 22:20
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

balcsida and others added 2 commits September 23, 2026 00:30
…policies

Add a policy engine that walks the parsed expression tree: AND takes the
worst operand, OR the best (reporting which branches are acceptable
without recording a choice), WITH pairs are their own terms and are never
approved by their base license, unknown identifiers and references
follow the policy's unknown handling and never become approved. Rules
are validated against the pinned license list and may not list a term
in two classes. The shipped policy is a clearly labelled example
fixture. Migration 036 adds policies, conclusions, policy results,
scoped decisions, review grants, and an append-only review audit trail.

Co-Authored-By: Claude <noreply@anthropic.com>
…icy administration

Add the review service: a queue of authorized occurrences whose current
verdict is not approved or whose decision went stale (expired exception,
changed evidence); human license conclusions stored as immutable human
evidence that override automated evidence without erasing it; scoped
approve/reject/exception decisions that record the policy version,
verdict, reviewer, reason, usage context, and expiry, supersede earlier
decisions, and require the current evidence fingerprint (409 on a stale
basis); background policy evaluation that retains historical results;
administrator-only policy versions that refuse auto-approving unknowns;
repository-scoped review grants; and an append-only audit trail. REST
routes are designed in OpenAPI and the permission matrix, stale-basis
conflicts, expiry, re-evaluation, and immutability are proven against
PostgreSQL.

Co-Authored-By: Claude <noreply@anthropic.com>
@balcsida
balcsida force-pushed the feat/supply-chain/m5-review branch from 9e8a76f to 86592a4 Compare September 22, 2026 22:30
@balcsida
balcsida force-pushed the feat/supply-chain/m5-review branch 2 times, most recently from e2fbe60 to 86592a4 Compare September 22, 2026 23:51
@balcsida
balcsida merged commit 0def80c into main Sep 22, 2026
16 of 24 checks passed
@balcsida balcsida mentioned this pull request Sep 23, 2026
@balcsida
balcsida deleted the feat/supply-chain/m5-review branch September 23, 2026 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant