Skip to content

automation(review): admit mightyETL to the exact OpenCode dispatch target allowlist #818

Description

@seonghobae

Buyer-visible and merge-flow blocker

ContextualWisdomLab/mightyETL#121 is the sole dependency-eligible root of a seven-PR commercial ETL stack. Its exact head 2f374446b0e0dc180c53736787a2a7a9b331503f has successful repository CI, dependency review, CycloneDX SBOM, Semgrep, Security Scan, mergeability, and resolved review threads, but the central mention router repeatedly records:

Rejected @opencode-agent: repository is absent from OPENCODE_REPOSITORY_DISPATCH_TARGETS

No old review or author-only comment may substitute for the required exact-head independent verdict.

Required bounded change

Update the organization/repository Actions variable OPENCODE_REPOSITORY_DISPATCH_TARGETS by adding exactly:

ContextualWisdomLab/mightyETL

Preserve every existing exact entry and comma-delimited normalization rule. Do not use wildcards, organization-wide implicit admission, prefix matching, repository discovery, or model-controlled targets.

Security and credential invariants

  • Keep the existing OpenCode review identity, OIDC/App-token exchange, NVIDIA_NIM_API_KEY model path, and reviewer credential chain unchanged.
  • Do not introduce COPILOT_GITHUB_TOKEN.
  • Continue binding dispatch to live same-repository PR metadata, exact base/head refs and SHA values, configured scheduler actor/sender, and an exact target allowlist.
  • The review path remains review-only: no branch update, approval synthesis, merge, release, or branch-protection mutation.
  • No business payload or PII is added to the variable or dispatch receipt.

Acceptance evidence

  1. The stored variable contains ContextualWisdomLab/mightyETL exactly once and retains all prior exact entries.
  2. A fresh @opencode-agent review mention on unchanged mightyETL#121 receives a durable queued/accepted receipt rather than an allowlist rejection.
  3. The resulting repository-dispatch run validates the live PR number, base, and exact head 2f374446b0e0dc180c53736787a2a7a9b331503f before review.
  4. A non-allowlisted repository remains rejected in a deterministic contract or controlled negative verification.
  5. No credential, permission, provider, reviewer identity, or merge policy changes.

After the variable change, rerun the exact-head OpenCode/Noema review for mightyETL#121; do not reuse the earlier rejected receipts. This issue can close only after the accepted receipt and terminal review evidence are visible.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions