Repository navigation
Conversation
glifocat
force-pushed
the
feat/typesafe-triage-dry-run
branch
from
September 24, 2026 10:54
aec9806 to
bb7f172
Compare
…ed workflow Add --apply to typesafe-triage.py: writes only the two label questions that measured 100% agreement on a live run. The ungated kind/* proposal is added when the item has no existing kind/* label; on issues, triage/needs-repro is added when needs_repro resolved yes and the label isn't already present, but only when the kind proposal is itself ungated and bug/security (an apply-only safety check on top of decide()'s dry-run gate, since a low-confidence or missing kind answer shouldn't silently support writing needs_repro). Nothing is ever removed and area/priority/pr_ready are never touched. Labels go through gh issue edit/pr edit --add-label via a mockable subprocess helper, with a live label recheck immediately before each write (closing the gap between fetch and a run that can take a while, including withholding needs_repro if a human has since reclassified the item's live kind). A failed write, a malformed API response, or any other unexpected error mid-run surfaces as PartialFailure, preserving completed items (and labels already applied) instead of losing the whole run's output. --apply is refused together with --fixture. The table gains an Applied column and the summary an applied count; --json carries an applied list per item. A run that matches zero items now exits 3 (not 1), distinct from a real error. Add --since <ISO timestamp> and --only-unlabeled so an unattended run can consider only new, unlabeled items. Add .github/workflows/typesafe-triage.yml: workflow_dispatch (repo, apply inputs) plus a schedule every 6 hours. The scheduled run passes a wider fetch window, --only-unlabeled, and --apply only when the TYPESAFE_TRIAGE_APPLY repository variable is "true"; every run's table is uploaded as a workflow artifact. Untrusted inputs travel through env vars rather than shell interpolation; the table/log are read back through a stop-commands guard since issue/PR titles could otherwise be parsed as workflow commands. Requires TYPESAFE_API_KEY and TRIAGE_GH_TOKEN secrets (the latter scoped to the target repo), documented in docs/typesafe-triage.md along with the rollback (unset the variable; applied labels are additive) and known residual limitations (fetch-window coverage, a narrow write-ack race). Extend tests/test_typesafe_triage.py with mocked-subprocess coverage: no gh calls without --apply, exact add-label calls for an eligible item, no call when a label already exists, no call for a gated proposal, --since/ --only-unlabeled filtering, the live-recheck and needs_repro cross-checks, partial-failure preservation across several failure modes, and the new exit code. All 89 tests pass offline (39 previous + 50 new); also verified docs/skills-catalog.md's plugin-version/description contract test. Update docs/typesafe-triage.md, SKILL.md, docs/skills-catalog.md and CHANGELOG.md for the apply rules, the workflow, and the new exit code; bump plugin.json 0.13.0 -> 0.13.1. Reviewed with the adversarial-review skill (Codex) across sixteen rounds; fixed everything real (shell injection, TOCTOU races, partial-failure data loss, key redaction gaps, exit-code robustness, the needs_repro/kind confidence gap) down to a clean final pass.
glifocat
force-pushed
the
feat/typesafe-triage-action
branch
from
September 24, 2026 11:03
62afd00 to
cafc8f8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on #22. Adds
--applyto the TypeSafe triage script for the two questions that measured 100% agreement on the first live run (kind/*andtriage/needs-repro), plus--since,--only-unlabeled, and a scheduled workflow that stays dry-run until the repository variableTYPESAFE_TRIAGE_APPLYistrue.Behavior
TYPESAFE_API_KEYandTRIAGE_GH_TOKEN.Testing
python3 -m unittest tests.test_typesafe_triage: 87 tests, all offline with mocked transport and subprocess.See
docs/typesafe-triage.mdfor the apply rules.