Enforce Java OpenSSF Gold quality gates and license evidence#14
Conversation
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Reviewed the Socket warnings across the locked runtime, Gradle, Dokka, Jazzer, JUnit, and test dependency graphs. The explicit repository license gate covers 100 resolved components with 0 unknown or disallowed licenses. OSV reports 0 known vulnerabilities, and 15 Maven artifacts reproduce byte-for-byte with license notices. Obfuscation alerts are heuristics on published JVM artifacts. I did not suppress alerts or change organization policy. Generated-inclusive coverage and independent human review remain explicit blockers. |
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
Too many files changed for review. ( |
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
Per-file licensing and coverage-classification verification added in f0e54de and evidence corrected in 897dedc. Local verification on 2026-07-24 with JDK 26.0.1 and JDK 25.0.4 for shrinker compatibility:
The SPDX headers moved the Stainless marker off line 1, so the narrow exact-marker classifier now inspects only the first 12 header lines. This restores the intended maintained-source gate without hiding the raw report. Simplification, maintainability, confidentiality, and security review found no additional findings. Socket policy warnings remain documented and unsuppressed. Generated-inclusive coverage applicability and a different human reviewer remain explicit blockers before a Gold claim. |
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
Maven Central release evidence is now live and consumer-verified. Version v0.5.2 publishes detached OpenPGP signatures for all 15 Maven files. The root JAR verifies against fingerprint |
|
Reviewed the generated service-test risk note against immutable head |
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
Discovery & Answer-Engine UpdateCommit Research and review rules are recorded in the organization discovery policy. The full repository-native local suite passed, including lint, tests, coverage, dependency/security checks, and reproducibility checks as applicable. Hosted checks are rerunning. A different human approval remains required before merge. |
furkanerday
left a comment
There was a problem hiding this comment.
Two audit requirements remain unresolved. OPENSSF.md:51 and build.gradle.kts:89 add the implementation provider name and provider-specific classification detail to this remediation; replace them with a repository-owned, provider-neutral generated-source classification while keeping raw generated-inclusive coverage visible. Also correct the PR description’s “1,346 tests” claim: the corrected repository evidence at OPENSSF.md:26 and the maintainer’s latest verification both say 1,342. The public evidence must be internally consistent.
Signed-off-by: kriptoburak <kriptoburak@users.noreply.github.com>
|
Addressed both evidence findings in signed commit
Re-requesting independent review. Hosted checks are rerunning. |
furkanerday
left a comment
There was a problem hiding this comment.
Re-reviewed the complete current diff and conversation after the coverage-classification fix. Generated-source detection now uses a provider-neutral repository marker while retaining the raw generated-inclusive report, the published test and coverage figures are consistent, every current commit has a valid author-matching DCO trailer, all checks are green, and no unresolved review threads remain.
Summary
Verification
./scripts/lint./scripts/buildGold Assessment
This PR closes the repository's currently actionable technical gaps.
It does not claim Gold status.
The raw report remains below Gold's coverage thresholds.
The project must confirm generated-code applicability or raise raw coverage.
The organization must also provide public human and continuity evidence.
A different human reviewer must approve this change before merge.