develop: add PAT permission guidance and verification - #400
Conversation
|
To preview the documentation for this pull request, visit the following URL:
|
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 185e2cd was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Final setup PAT permission audit runs after remote preflight —
src/cli/commands/setup.ts:152
Bugbot: review complete
|
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit b0977e7 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Unavailable repository Secret inventory is treated as empty —
src/data/repository/repository_variables_repository.ts:48
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit a8ac8f6 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Organization-only storage is blocked by unrelated repository inventory access —
src/application/policies/setup_configuration_storage_policy.ts:130
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit 021c842 was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- medium: Rate-limit responses are reported as missing permissions —
src/infrastructure/setup_token_permission_query_adapter.ts:57 - medium: Final setup-PAT permission report can be skipped —
src/cli/commands/setup.ts:158
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit fd095f2 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Unvalidated provider head SHA is interpolated into trusted prompt text —
src/application/policies/bugbot_diff_partition_policy.ts:149
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 5 potential problems when commit 4c7edc3 was analyzed. This snapshot is historical; use the status block above for current state. 5 findings are linked to changed code.
Findings
- high: Members-only authorization is bypassed for dynamic locale catalogs —
src/actions/github_action.ts:98 - medium: Organization member checks make valid workflow PATs unverifiable —
src/application/policies/setup_token_permission_policy.ts:183 - medium: Raw diff budget does not bound normalized prompt size —
src/application/policies/bugbot_diff_partition_policy.ts:85 - medium: Installed selected-branch health workflow is treated as unavailable —
src/data/repository/github/credential_health_workflow_visibility.ts:35 - low: Disabled assignment can still fail on a missing target number —
src/application/usecases/steps/issue/assign_members_workflow.ts:34
|
/copilot recheck |
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit b859c44 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Dynamic catalog incorrectly requires file-modification permission —
src/actions/github_action.ts:95
Request could not be completed
Action: Retry when the provider is available. Retained state: Existing persisted state and completed external effects were preserved. Error code: Retryable: Yes Reference: |
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 7 potential problems when commit 593b549 was analyzed. This snapshot is historical; use the status block above for current state. 7 findings are linked to changed code.
Findings
- medium: Organization Members operational evidence is contradicted by the canonical rule —
specs/setup-pat-permission-guidance-and-verification.md:409 - medium: Issue permission is required when issue automation is disabled —
src/application/policies/setup_token_permission_policy.ts:76 - medium: Do not dispatch a workflow that exists only on the selected ref —
src/infrastructure/setup_remote_credential_health_adapter.ts:102 - low: Definition of Done reports the wrong test count —
specs/setup-pat-permission-guidance-and-verification.md:896 - low: Definition of Done cites the wrong test-budget floor —
specs/bugbot-exhaustive-partitioned-analysis.md:697 - low: Fenced code text can satisfy the PAT prerequisite check —
scripts/documentation_pat_exception_policy.cjs:3 - low: Credential keep rule contradicts the mandatory workflow PAT re-entry —
specs/setup-configuration-credentials-and-doctor.md:144
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 3 potential problems when commit 2cced48 was analyzed. This snapshot is historical; use the status block above for current state. 3 findings are linked to changed code.
Findings
- medium: Temporary bootstrap can delete a workflow created by another actor —
specs/setup-pat-permission-guidance-and-verification.md:259 - medium: Validate remote inventory before copying setup files —
src/application/usecases/actions/initial_setup_workflow.ts:90 - low: Indented shell examples bypass PAT exception validation —
scripts/validate-documentation-contract.cjs:270
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 0ee8e03 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: README shell examples bypass the PAT exception check —
scripts/validate-documentation-contract.cjs:269
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit dc33c34 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Unverifiable write permissions can bypass required acknowledgement —
specs/setup-pat-permission-guidance-and-verification.md:727
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 2 potential problems when commit a5c1aba was analyzed. This snapshot is historical; use the status block above for current state. 2 findings are linked to changed code.
Findings
- medium: Any repository read can be marked operationally available —
src/application/policies/setup_token_permission_evidence_policy.ts:49 - medium: Organization targets can be masked by unseen repository resources —
src/application/usecases/actions/setup_resource_provisioning.ts:153
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit 6fa92ef was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- medium: Public members listing can falsely satisfy the Members read requirement —
specs/setup-pat-permission-guidance-and-verification.md:411
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit fb9a447 was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Partition test budget conflicts with companion specifications —
specs/bugbot-exhaustive-partitioned-analysis.md:564
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit e16e3db was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Definition of Done uses the wrong test budget —
specs/agent-runtime-provider-and-model-routing.md:358
There was a problem hiding this comment.
Current status: All findings originating in this review are resolved.
Last reconciled on7261967. See aggregate Bugbot status.
🤖 Bugbot review snapshot
Bugbot reported 1 potential problem when commit cca631a was analyzed. This snapshot is historical; use the status block above for current state. 1 finding is linked to changed code.
Findings
- low: Blockquoted shell examples bypass the PAT acknowledgement check —
scripts/documentation_pat_exception_policy.cjs:49
This change adds evidence-based PAT permission guidance and verification to setup, while strengthening Bugbot’s exhaustive review flow. It helps repository owners configure only the permissions needed by enabled workflows and makes review results more resilient to incomplete or malformed analysis.
What changed