Skip to content

feat(typesafe-triage): apply kind and needs_repro labels, add scheduled workflow - #24

Draft
glifocat wants to merge 1 commit into
feat/typesafe-triage-dry-runfrom
feat/typesafe-triage-action
Draft

glifocat wants to merge 1 commit into
feat/typesafe-triage-dry-runfrom
feat/typesafe-triage-action

Conversation

@glifocat

Copy link
Copy Markdown
Collaborator

Summary

Stacked on #22. Adds --apply to the TypeSafe triage script for the two questions that measured 100% agreement on the first live run (kind/* and triage/needs-repro), plus --since, --only-unlabeled, and a scheduled workflow that stays dry-run until the repository variable TYPESAFE_TRIAGE_APPLY is true.

Behavior

  • Labels are additive only. Never removes labels, never comments, never touches area, priority or pr_ready.
  • Requires secrets TYPESAFE_API_KEY and TRIAGE_GH_TOKEN.
  • Rollback: unset the repository variable.

Testing

  • python3 -m unittest tests.test_typesafe_triage: 87 tests, all offline with mocked transport and subprocess.
  • Codex adversarial review run to a clean pass; findings fixed include workflow shell injection and partial-failure label loss.

See docs/typesafe-triage.md for the apply rules.

@glifocat
glifocat force-pushed the feat/typesafe-triage-dry-run branch from aec9806 to bb7f172 Compare September 24, 2026 10:54
…ed workflow

Add --apply to typesafe-triage.py: writes only the two label questions that
measured 100% agreement on a live run. The ungated kind/* proposal is added
when the item has no existing kind/* label; on issues, triage/needs-repro is
added when needs_repro resolved yes and the label isn't already present, but
only when the kind proposal is itself ungated and bug/security (an apply-only
safety check on top of decide()'s dry-run gate, since a low-confidence or
missing kind answer shouldn't silently support writing needs_repro). Nothing
is ever removed and area/priority/pr_ready are never touched. Labels go
through gh issue edit/pr edit --add-label via a mockable subprocess helper,
with a live label recheck immediately before each write (closing the gap
between fetch and a run that can take a while, including withholding
needs_repro if a human has since reclassified the item's live kind). A failed
write, a malformed API response, or any other unexpected error mid-run
surfaces as PartialFailure, preserving completed items (and labels already
applied) instead of losing the whole run's output. --apply is refused
together with --fixture. The table gains an Applied column and the summary
an applied count; --json carries an applied list per item. A run that
matches zero items now exits 3 (not 1), distinct from a real error.

Add --since <ISO timestamp> and --only-unlabeled so an unattended run can
consider only new, unlabeled items.

Add .github/workflows/typesafe-triage.yml: workflow_dispatch (repo, apply
inputs) plus a schedule every 6 hours. The scheduled run passes a wider
fetch window, --only-unlabeled, and --apply only when the TYPESAFE_TRIAGE_APPLY
repository variable is "true"; every run's table is uploaded as a workflow
artifact. Untrusted inputs travel through env vars rather than shell
interpolation; the table/log are read back through a stop-commands guard
since issue/PR titles could otherwise be parsed as workflow commands.
Requires TYPESAFE_API_KEY and TRIAGE_GH_TOKEN secrets (the latter scoped to
the target repo), documented in docs/typesafe-triage.md along with the
rollback (unset the variable; applied labels are additive) and known
residual limitations (fetch-window coverage, a narrow write-ack race).

Extend tests/test_typesafe_triage.py with mocked-subprocess coverage: no gh
calls without --apply, exact add-label calls for an eligible item, no call
when a label already exists, no call for a gated proposal, --since/
--only-unlabeled filtering, the live-recheck and needs_repro cross-checks,
partial-failure preservation across several failure modes, and the new exit
code. All 89 tests pass offline (39 previous + 50 new); also verified
docs/skills-catalog.md's plugin-version/description contract test.

Update docs/typesafe-triage.md, SKILL.md, docs/skills-catalog.md and
CHANGELOG.md for the apply rules, the workflow, and the new exit code; bump
plugin.json 0.13.0 -> 0.13.1.

Reviewed with the adversarial-review skill (Codex) across sixteen rounds;
fixed everything real (shell injection, TOCTOU races, partial-failure data
loss, key redaction gaps, exit-code robustness, the needs_repro/kind
confidence gap) down to a clean final pass.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant