Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Test codeguard pr#3

Open
m1el wants to merge 18 commits into
masterm1el/nemotron-asr.cpp:masterfrom
test_codeguard_prm1el/nemotron-asr.cpp:test_codeguard_prCopy head branch name to clipboard
Open

Test codeguard pr#3
m1el wants to merge 18 commits into
masterm1el/nemotron-asr.cpp:masterfrom
test_codeguard_prm1el/nemotron-asr.cpp:test_codeguard_prCopy head branch name to clipboard

Conversation

@m1el

@m1el m1el commented Feb 16, 2026

Copy link
Copy Markdown
Owner

No description provided.

m1el and others added 6 commits February 5, 2026 20:23
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds codeguard-action workflow that runs AI-powered risk classification
on PRs, plus local scripts for testing without GitHub context.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Configure codeguard-action with custom rubric
- Upload evidence bundle as artifact
@github-actions

github-actions Bot commented Feb 16, 2026

Copy link
Copy Markdown

[!!] GuardSpine: CONDITIONAL - Reviewer action needed

Policy: standard | Findings: 8

Risk tier: L3 | Human review: required

Reviewer Action Required (max 2)

  1. HIGH [config] (.github/scripts/test-action-docker.sh:96): Sensitive config code modified

    Review sensitive-config

  2. HIGH [None] (.codeguard/rubrics/clarity-mine.yaml:126): Complex boolean expressions are hard to reason about

    Review CLR-006

Advisory (6 items)
  • [low] FOOBAR should not be present in the codebase
  • [low] FOOBAR should not be present in the codebase
  • [high] Chains of negations are confusing
  • [high] AI concern: AI review failed: Error code: 400 - {'error': {'message': 'Provider returned error', 'code': 400, 'metadata': {'raw': '{"type":"error","error":{"type":"invalid_request_error","message":"output_config.format.schema: For 'number' type, properties maximum, minimum are not supported"},"request_id":"req_011CcWMtr9ns7XGXMJoQZTpY"}', 'provider_name': 'Amazon Bedrock', 'is_byok': False, 'previous_errors': [{'code': 400, 'message': 'Provider returned error', 'provider_name': 'Amazon Bedrock', 'raw': '{"message":"output_config.format.schema: For 'number' type, properties maximum, minimum are not supported"}'}, {'code': 400, 'message': 'Provider returned error', 'provider_name': 'Anthropic', 'raw': '{"type":"error","error":{"type":"invalid_request_error","message":"output_config.format.schema: For 'number' type, properties maximum, minimum are not supported"},"request_id":"req_011CcWMtprQJ4Jp1pzYrTz9S"}'}, {'code': 400, 'message': 'Provider returned error', 'provider_name': 'Anthropic', 'raw': '{"type":"error","error":{"type":"invalid_request_error","message":"output_config.format.schema: For 'number' type, properties maximum, minimum are not supported"},"request_id":"req_011CcWMtqQeKT6GkqhpFFFLH"}'}]}}, 'user_id': 'user_39GZ7EzPiAuzQZ6FIm5TTi6TbVP'}
  • [high] AI concern: Workflow now provides a new secret (OPENROUTER_API_KEY) to a third-party GitHub Action (DNYoussef/codeguard-action@v1); if the action is compromised or the tag moves, the secret can be exfiltrated (supply-chain risk). Pin the action to a commit SHA.
  • [high] AI concern: Enabling ai_review: "true" and configuring an external model (openrouter_model) likely sends diff/source content to a third-party service (OpenRouter/LLM). This is an information-disclosure risk for proprietary code and may violate data-handling policies unless explicitly approved and scoped.

GuardSpine Decision Engine | Removing reviewer decisions, not just effort

@m1el
m1el had a problem deploying to codeguard-check March 9, 2026 16:33 — with GitHub Actions Failure
@m1el
m1el had a problem deploying to codeguard-check March 9, 2026 16:36 — with GitHub Actions Failure
@m1el
m1el force-pushed the test_codeguard_pr branch from 877eb6b to f794c7c Compare March 9, 2026 18:33
@m1el
m1el temporarily deployed to codeguard-check March 9, 2026 20:19 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 9, 2026 20:50 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 9, 2026 20:53 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 10, 2026 00:22 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 10, 2026 00:39 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 10, 2026 00:56 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 10, 2026 01:24 — with GitHub Actions Inactive
@m1el
m1el temporarily deployed to codeguard-check March 10, 2026 02:07 — with GitHub Actions Inactive
@m1el
m1el deployed to codeguard-check June 28, 2026 21:23 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Morty Proxy This is a proxified and sanitized view of the page, visit original site.