Skip to content

fix(ci): require the Codex credential before CI-investigator activation #949

Description

@groupthinking

Parent program: #898
Canonical implementation: #948

Scope

  • Make the EventRelay CI Investigator fail before activation when the dedicated CODEX_API_KEY secret is absent.
  • Preserve secret redaction and do not add, print, or mutate credential values.
  • Keep the .md source, generated .lock.yml, audit catalog, and governance regression synchronized.

Acceptance

  • The dedicated check executes before the compiled activation fallback validator.
  • Tests inspect compiled behavior, not source text alone.
  • gh-aw source and generated lock are synchronized.
  • Exact-head CI, Coverage, gh-aw Validation, CodeQL, Security Scan, Secret Scan, and Dependency Review pass.
  • All review findings proven fixed are resolved; zero threads remain unresolved.
  • A current-head independent reviewer attests to 5ab39e2e9d8567233bac388964080dff50edb300.
  • PR remains draft until the protected secret is configured and a real investigator run proves activation.

Exact-head evidence

  • Head: 5ab39e2e9d8567233bac388964080dff50edb300
  • Pinned compile: gh-aw v0.82.14, 1 workflow, 0 errors, 0 warnings.
  • Focused governance tests: 9 passed.
  • CI run 29950283485: passed.
  • Coverage run 29950282778: passed, including test execution and artifact upload.
  • gh-aw Validation 29950283640: passed.
  • CodeQL 29950283484, Security Scan 29950283409, Secret Scan 29950282993, Dependency Review 29950283472: passed.
  • Review threads: 0 unresolved after exact-head verification.
  • E2E: skipped; this workflow-only change does not claim deployment proof.

Execution receipt

Original external execution:

Direct controller remediation:

Protected next action

A repository owner must configure/authorize the protected CODEX_API_KEY, then run the investigator at this exact head. Do not post the secret.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions