PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 1s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 3s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 3s
Rule 5 now treats internal http://192.168.68.116/v1 as non-canonical but working (authenticated via nginx), producing a WARNING instead of a FAILURE. The canonical internal path /litellm/v1 and the public host https://litellm.sysloggh.net/v1 both PASS. Everything else FAILS. Prose aligned: hermes-key-enforcement.prose.md now states the canonical internal form, notes that internal /v1 still works but is flagged as non-canonical (WARN not FAIL), and clarifies that the public host serves /v1 ONLY (404 on /litellm/v1). Corrected the 'unauthenticated path' wording at line 116, which was factually wrong. Tests updated: BASE template uses canonical internal path; new test cases prove canonical /litellm/v1 PASSES, wrong path FAILS, public host PASSES, and internal /v1 WARNS (not FAILS). Fixed backwards comment in test_old_rule5_check_would_fail_canonical.