chore(receipts): schema audit and canonicalization for SIEM-readiness - #562
Merged
Conversation
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: escoffier-labs/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Jul 26, 2026
solomonneas
marked this pull request as ready for review
July 26, 2026 22:03
solomonneas
force-pushed
the
chore/506-receipt-schema-audit
branch
from
July 26, 2026 22:19
7447be4 to
7b2be04
Compare
Co-Authored-By: Codex <codex@openai.com>
solomonneas
force-pushed
the
chore/506-receipt-schema-audit
branch
from
July 26, 2026 22:23
7b2be04 to
daae8de
Compare
This was referenced Jul 26, 2026
This was referenced Jul 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Audits verification receipts, Brigade run receipts and sidecars, and outcome records against four SIEM-readiness criteria:
New writes carry a documented
schema_version, legacy receipts without the field still load, and verify version 2 keeps its patch-identity tuple structurally stable. The schema reference permits additive optional fields within a version so concurrent receipt-field work can merge without changing the contract.Findings
compliantfixed-hereneeds-follow-up-issueThe committed audit report maps each receipt type and criterion to its tag. The schema reference lists fields, types, null and omission rules, and evolution policy.
Follow-up issues filed
receipts: replace mutable run.json snapshots with append-only lifecycle eventsreceipts: preserve worker and synthesis sidecars across resume and patch-ref updatesreceipts: archive verification evidence before retention pruningoutcome: make decision receipt filenames collision-safe and write-exclusiveoutcome: serialize digest-chain appends across concurrent capturesVerification
Full suite:
Determinism proof:
The two files were generated from the same payload through
aboyeur._write_json. A zero-exit byte comparison confirms identical serialization.Closes #506