Parent program: #898
Canonical implementation: #948
Scope
- Make the EventRelay CI Investigator fail before activation when the dedicated
CODEX_API_KEY secret is absent.
- Preserve secret redaction and do not add, print, or mutate credential values.
- Keep the
.md source, generated .lock.yml, audit catalog, and governance regression synchronized.
Acceptance
Exact-head evidence
- Head:
5ab39e2e9d8567233bac388964080dff50edb300
- Pinned compile:
gh-aw v0.82.14, 1 workflow, 0 errors, 0 warnings.
- Focused governance tests: 9 passed.
- CI run 29950283485: passed.
- Coverage run 29950282778: passed, including test execution and artifact upload.
- gh-aw Validation 29950283640: passed.
- CodeQL 29950283484, Security Scan 29950283409, Secret Scan 29950282993, Dependency Review 29950283472: passed.
- Review threads: 0 unresolved after exact-head verification.
- E2E: skipped; this workflow-only change does not claim deployment proof.
Execution receipt
Original external execution:
Direct controller remediation:
Protected next action
A repository owner must configure/authorize the protected CODEX_API_KEY, then run the investigator at this exact head. Do not post the secret.
Parent program: #898
Canonical implementation: #948
Scope
CODEX_API_KEYsecret is absent..mdsource, generated.lock.yml, audit catalog, and governance regression synchronized.Acceptance
5ab39e2e9d8567233bac388964080dff50edb300.Exact-head evidence
5ab39e2e9d8567233bac388964080dff50edb300gh-aw v0.82.14, 1 workflow, 0 errors, 0 warnings.Execution receipt
Original external execution:
Copilotcopilot/fix-key-unset-codex/ fix(ci): require Codex credential before investigator activation #9482026-07-22T18:28:10Z2026-07-22T19:21:00Z5ab39e2e9d8567233bac388964080dff50edb300Direct controller remediation:
Protected next action
A repository owner must configure/authorize the protected
CODEX_API_KEY, then run the investigator at this exact head. Do not post the secret.