Skip to content

feat: add CLI-first GitHub repository enhancement workflow - #118

Merged
CruxExperts merged 23 commits into
mainfrom
feat/github-repository-enhancement
Sep 27, 2026
Merged

CruxExperts merged 23 commits into
mainfrom
feat/github-repository-enhancement

Conversation

@CruxExperts

@CruxExperts CruxExperts commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Closes #109

Adds the CLI-first GitHub repository enhancement workflow and prepares LocalSetup 4.45.0. It audits registered controls, creates repository-bound plans, applies authorized operations with precondition checks, and verifies readback. The control registry is bounded; GitHub Enterprise Server compatibility and remote social-preview pixel identity remain unverified.

Publication now runs inexpensive checks before eight isolated test shards, then reuses successful validation for the exact candidate commit on main and during release preparation. The same procedure is recorded in the source skills, pre-publish workflow, repository guidance, release record, and generated provenance. File-size findings are advisory; signature, version, release-document, and artifact checks remain required.

Validation:

  • 55 focused tests passed for CI evidence, shard gating, architecture policy, runtime contracts, and signed-release safeguards.
  • Actual collection across all eight shards is disjoint and complete: 4,042 cases.
  • Framework audit: 0 errors, 1 warning. Catalog, architecture, and documentation alignment checks pass.
  • Final hosted suite on 700d0d90: 4,040 passed, 2 skipped across all eight shards; all prerequisite and aggregate checks passed. Longest shard: 28m50s.
  • Fixed two hosted fixture defects: restore copied Git mocks after each test and allow cold SDK imports in ordinary cases while preserving explicit deadline checks.
  • Source procedures and generated provenance are aligned with the accepted release source; no dirty-source receipt.
  • Version arithmetic remains one MINOR slice from 4.44.3 to 4.45.0 on the locked 4.x line.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T02:37:46.896482Z 700d0d9 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added area/docs Affected repository area area/release Affected repository area area/skills Skills, workflows, or packs status/needs-triage Triage status type/pr Issue or PR type labels Sep 27, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fac488fe5c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +67 to +69
return _native_interface(
["gh", "repo", "edit", "{plan.target.requested_full_name}", flag, str(value)],
[flag],

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Include the required visibility acknowledgment flag

When applying any isolated visibility plan, this generates gh repo edit OWNER/REPO --visibility VALUE without the mandatory acknowledgment flag, so the supported visibility operation is rejected before making the change. I checked the installed gh repo edit --help, which states: “When the --visibility flag is used, --accept-visibility-change-consequences flag is required.” Add that flag to the visibility argv and required-flags contract, or use the reviewed REST transport instead; the official CLI manual documents the same requirement.

Useful? React with 👍 / 👎.

Comment on lines +338 to +340
authorization.get("scope_visibility") != "reported"
or (isinstance(scopes, list) and "repo" in scopes)
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit public_repo tokens for public repository writes

When gh auth status reports a classic token scoped only with public_repo, this condition marks every operation on a public repository report-only even when the actor is an administrator. GitHub defines public_repo as limiting repository access to public repositories, whereas repo adds private-repository access, so requiring repo unnecessarily rejects a valid least-privilege credential for ordinary public-repository settings. Make this check visibility/operation-aware (and mirror it in the apply-time scope guard), while continuing to require appropriate access for private or visibility-changing operations.

Useful? React with 👍 / 👎.

CruxExperts added 11 commits September 26, 2026 20:32
Shard full validation after cheap checks, reuse exact-commit CI evidence, and align source skills, workflow procedures, and review policy. Keep signature and artifact gates.

Release-Type: none

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c514cd96eb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

}

def environments_summary(self) -> dict[str, Any]:
result = self._paginate_result("deployments/environments", operation="environments")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Query the repository environments endpoint

For every repository with environments, this requests GET /repos/{owner}/{repo}/deployments/environments, but GitHub's repository-environments API is GET /repos/{owner}/{repo}/environments and returns an object containing an environments collection. The current request therefore yields an unavailable observation—often a 404 that still permits the audit coverage receipt to be complete—instead of inventorying environment protection. Use the environments suffix with collection_key="environments", and update the corresponding inventory endpoint label and fixture.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 700d0d90bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

{
"schema_version": 1,
"version": "4.45.0",
"source_commit": "c4ba521eeb5a91cd12e306ddfdd1d47bc17db0e3",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind the release record to an ancestor source commit

The new 4.45.0 record names c4ba521eeb5a91cd12e306ddfdd1d47bc17db0e3, but git merge-base --is-ancestor confirms that commit is not an ancestor of the reviewed candidate. The repository's release-docs checker therefore emits source_not_ancestor, and both PR documentation validation and release preparation invoke that gate, blocking this candidate from publication. Regenerate or rebind the record to the actual source commit in this ancestry while preserving the source/generated-receipt split.

AGENTS.md reference: AGENTS.md:L171-L178

Useful? React with 👍 / 👎.

@CruxExperts
CruxExperts merged commit 700d0d9 into main Sep 27, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Affected repository area area/release Affected repository area area/skills Skills, workflows, or packs status/needs-triage Triage status type/pr Issue or PR type

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: add a CLI-first GitHub repository enhancement workflow

1 participant