build_verify_subgraph: BUILD->VERIFY nodes + route_after_verify. build_graph gains an opt-in build_verify param that repoints the review 'build' route at the subgraph (BUILD->VERIFY->{approved->END | loop->PLAN | parked->END}); default unchanged (P2). Coordinator build_verify_wiring composes it INERT (no ci_result -> ci_gate BLOCK -> PARKED; LLM is fix-proposer only, never declares green). NOT enabled in production: the live CI apply/verify + OIDC stays held for its /sh-security-review + GPT-4.1 cross-review gate. Also escapes untrusted intake text in logs (log-injection hygiene).
|
||
|---|---|---|
| .. | ||
| __init__.py | ||
| build_verify_subgraph.py | ||
| builders.py | ||
| builders_llm.py | ||
| clarifier.py | ||
| clarifier_llm.py | ||
| planner.py | ||
| review_loop.py | ||
| review_loop_llm.py | ||
| verifier.py | ||
| verifier_llm.py | ||