Allow the winget-pkgs fork and upstream in gh-safe - #748
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe ChangesRepository allowlist
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The wrapper permits the intended fork and upstream operations while rejecting the inspected mismatched targets. No actionable merge-blocking issue remains after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The repository checks remain in place, but the newly allowed repositories receive broader command authorization than the two release actions described. Actual mutation authority depends on the configured GitHub account permissions, which were not established. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
scripts/gh-safe.shonly allowed writes tonesszer/Win-CodexBar, so the winget release step (a manifest branch on theFinesssee/winget-pkgsfork, then a PR onmicrosoft/winget-pkgs) could not go through the wrapper. This adds those two repos to the allowlist. Every other check is unchanged: read-back verification, the--repooverride block,repos/<repo>/scoping forgh api, and the upstreamsteipete/CodexBargate.gh-safe.tests.sh: the fakegh repo viewnow echoes the requested repo. New cases: winget PR create allowed, forkmerge-upstreamAPI allowed, an API path outside the bound fork rejected, and an unlistedother/winget-pkgsrejected.AGENTS.md: names the three allowlisted repos.Commands
bash -n scripts/gh-safe.sh: passes.scripts/gh-safe.tests.sh: passes locally ("GitHub write-safety shell tests passed."), run from a copy without the temp-dir cleanup trap, which this workstation's delete-policy hook blocks. The hosted-Slice cidoes not run this script; only the default developer slice oflocal-check.ps1does.