feat(supply-chain): policies and review workflow - #111
Merged
balcsida merged 2 commits intoSep 22, 2026
Merged
Conversation
balcsida
added this pull request to stack #114
September 22, 2026 21:06
balcsida
force-pushed
the
feat/supply-chain/m5-review
branch
2 times, most recently
from
September 22, 2026 22:19
7b1cc75 to
9e8a76f
Compare
balcsida
marked this pull request as ready for review
September 22, 2026 22:20
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
…policies Add a policy engine that walks the parsed expression tree: AND takes the worst operand, OR the best (reporting which branches are acceptable without recording a choice), WITH pairs are their own terms and are never approved by their base license, unknown identifiers and references follow the policy's unknown handling and never become approved. Rules are validated against the pinned license list and may not list a term in two classes. The shipped policy is a clearly labelled example fixture. Migration 036 adds policies, conclusions, policy results, scoped decisions, review grants, and an append-only review audit trail. Co-Authored-By: Claude <noreply@anthropic.com>
…icy administration Add the review service: a queue of authorized occurrences whose current verdict is not approved or whose decision went stale (expired exception, changed evidence); human license conclusions stored as immutable human evidence that override automated evidence without erasing it; scoped approve/reject/exception decisions that record the policy version, verdict, reviewer, reason, usage context, and expiry, supersede earlier decisions, and require the current evidence fingerprint (409 on a stale basis); background policy evaluation that retains historical results; administrator-only policy versions that refuse auto-approving unknowns; repository-scoped review grants; and an append-only audit trail. REST routes are designed in OpenAPI and the permission matrix, stale-basis conflicts, expiry, re-evaluation, and immutability are proven against PostgreSQL. Co-Authored-By: Claude <noreply@anthropic.com>
balcsida
force-pushed
the
feat/supply-chain/m5-review
branch
from
September 22, 2026 22:30
9e8a76f to
86592a4
Compare
balcsida
force-pushed
the
feat/supply-chain/m5-review
branch
2 times, most recently
from
September 22, 2026 23:51
e2fbe60 to
86592a4
Compare
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Milestone 5. Depends on #110. Three record kinds stay separate and are never edited, only superseded.
internal/supplychain/policy) – walks the SPDX expression tree: AND takes the worst operand, OR the best (acceptable branches are reported; choosing one is a separate recorded decision),WITHpairs are their own terms and are never approved by their base license, unknown identifiers/references follow the policy's unknown handling and never become approved. Rules are validated against the pinned list and may not list a term in two classes. The shipped policy is a clearly labelled example fixture;unknown_handlingmust bereview_requiredorprohibited.humanevidence that override automated evidence without erasing it (disagreement stays visible); approve / reject / exception decisions recording policy version + verdict, reviewer, reason, usage context, expiry (≤ 1 year); optimistic concurrency – conclusions and decisions must echo the current assessment fingerprint (409 stale_basis); background re-evaluation retains historical results; repository-scoped review grants (admin-only; reviewers still need read access and cannot grant themselves); append-only audit trail (DB trigger)./v1/supply-chain/review/*and/v1/supply-chain/policies, designed in OpenAPI. Migration 036.Verification
Policy truth table (leaves, AND, OR with branch reporting, WITH, or-later handling, grouping differences, unknown handling never approves, rule validation). Integration test against PostgreSQL: install/activate example, invalid rules and
unknown_handling=approvedrefused, evaluation counts and idempotency, queue scoping per principal, full permission matrix, stale-basis conflicts, exception expiry (queue + history), re-evaluation after a conclusion (prohibited → approved, history retained), human evidence coexisting with registry evidence, superseded decisions, append-only events.Implications
Part of the Dependencies & Licenses stack (native GitHub stack #114, ten layers,
main ← #104 ← #105 ← #106 ← #107 ← #108 ← #109 ← #110 ← #111 ← #112 ← #113). Design: ADR-0017; living plan with the full validation table:docs/execplans/supply-chain.md. All commits are SSH-signed. Nothing here calls a live GitHub Enterprise Server or a live package registry; GitHub and registry behavior is exercised against fixtures and fake servers only.Stack created with GitHub Stacks CLI