feat: add CLI-first GitHub repository enhancement workflow - #118
Conversation
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
…ion/release-4.45.0
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fac488fe5c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| return _native_interface( | ||
| ["gh", "repo", "edit", "{plan.target.requested_full_name}", flag, str(value)], | ||
| [flag], |
There was a problem hiding this comment.
Include the required visibility acknowledgment flag
When applying any isolated visibility plan, this generates gh repo edit OWNER/REPO --visibility VALUE without the mandatory acknowledgment flag, so the supported visibility operation is rejected before making the change. I checked the installed gh repo edit --help, which states: “When the --visibility flag is used, --accept-visibility-change-consequences flag is required.” Add that flag to the visibility argv and required-flags contract, or use the reviewed REST transport instead; the official CLI manual documents the same requirement.
Useful? React with 👍 / 👎.
| authorization.get("scope_visibility") != "reported" | ||
| or (isinstance(scopes, list) and "repo" in scopes) | ||
| ) |
There was a problem hiding this comment.
Permit public_repo tokens for public repository writes
When gh auth status reports a classic token scoped only with public_repo, this condition marks every operation on a public repository report-only even when the actor is an administrator. GitHub defines public_repo as limiting repository access to public repositories, whereas repo adds private-repository access, so requiring repo unnecessarily rejects a valid least-privilege credential for ordinary public-repository settings. Make this check visibility/operation-aware (and mirror it in the apply-time scope guard), while continuing to require appropriate access for private or visibility-changing operations.
Useful? React with 👍 / 👎.
Release-Type: none
Release-Type: none
Shard full validation after cheap checks, reuse exact-commit CI evidence, and align source skills, workflow procedures, and review policy. Keep signature and artifact gates. Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c514cd96eb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
|
|
||
| def environments_summary(self) -> dict[str, Any]: | ||
| result = self._paginate_result("deployments/environments", operation="environments") |
There was a problem hiding this comment.
Query the repository environments endpoint
For every repository with environments, this requests GET /repos/{owner}/{repo}/deployments/environments, but GitHub's repository-environments API is GET /repos/{owner}/{repo}/environments and returns an object containing an environments collection. The current request therefore yields an unavailable observation—often a 404 that still permits the audit coverage receipt to be complete—instead of inventorying environment protection. Use the environments suffix with collection_key="environments", and update the corresponding inventory endpoint label and fixture.
Useful? React with 👍 / 👎.
Release-Type: none
Release-Type: none
Release-Type: none
Release-Type: none
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 700d0d90bf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { | ||
| "schema_version": 1, | ||
| "version": "4.45.0", | ||
| "source_commit": "c4ba521eeb5a91cd12e306ddfdd1d47bc17db0e3", |
There was a problem hiding this comment.
Bind the release record to an ancestor source commit
The new 4.45.0 record names c4ba521eeb5a91cd12e306ddfdd1d47bc17db0e3, but git merge-base --is-ancestor confirms that commit is not an ancestor of the reviewed candidate. The repository's release-docs checker therefore emits source_not_ancestor, and both PR documentation validation and release preparation invoke that gate, blocking this candidate from publication. Regenerate or rebind the record to the actual source commit in this ancestry while preserving the source/generated-receipt split.
AGENTS.md reference: AGENTS.md:L171-L178
Useful? React with 👍 / 👎.
Closes #109
Adds the CLI-first GitHub repository enhancement workflow and prepares LocalSetup 4.45.0. It audits registered controls, creates repository-bound plans, applies authorized operations with precondition checks, and verifies readback. The control registry is bounded; GitHub Enterprise Server compatibility and remote social-preview pixel identity remain unverified.
Publication now runs inexpensive checks before eight isolated test shards, then reuses successful validation for the exact candidate commit on main and during release preparation. The same procedure is recorded in the source skills, pre-publish workflow, repository guidance, release record, and generated provenance. File-size findings are advisory; signature, version, release-document, and artifact checks remain required.
Validation:
700d0d90: 4,040 passed, 2 skipped across all eight shards; all prerequisite and aggregate checks passed. Longest shard: 28m50s.