v3.2.0
rcl review … --attest(RCL-40): inside the organization's gate
workflow on GitHub Actions, rcl asks the runner for the job's OIDC token
(audience: the Harness origin fromHARNESS_API_URL), exchanges it at
POST /api/v1/reviews/attestfor a run-bound credential (rbc_…, thirty
minutes, one run id, valid while the Actions run is in progress) and records
the review under it — envelope, artifacts, model keys and model stats — so
Harness stores the run ascredential_kind: attested, the tier the enforced
gate reads. Fails loudly before any token is requested or any reviewer is
paid: outside Actions (ACTIONS_ID_TOKEN_REQUEST_URL/_TOKENunset),
withoutHARNESS_API_URL, off a pull request target, with a telemetry level
other thanfull(environment or project config), or when the exchange is
refused (the reason is printed). Never falls back toHARNESS_API_TOKENor
the stored login, implies--evidence-required, never spools (the
credential does not outlive the workflow run), and mints the credential
again for the same run id before delivery when a long review has used up
most of its thirty minutes.round_processedcarries the round's classification (RCL-47):
identities: [{identity_key, matched_identity, status, suppress_reason?}]
— each sighting's own report key, the identityconverge-reportmatched it
to by location, and whether it wasnew,repeat,suppressedor
regating. Harness applies a standing verdict to a key that moved with the
code only when it knows the matched identity (IO-12601); without it a
re-sighted fixed or dismissed finding reads as actionable and the gate says
unresolvedfor a loop rcl judged converged. One entry per key; text goes
through the usual scrubber.
npm: https://www.npmjs.com/package/review-council/v/3.2.0
Tarball SHA-256: 3d528d22253c37b230c31bcd308fbd57a6c047fa810e39ecbb0dd583b6fcc056