Skip to content

docs: prefer GitHub connector in Codex Cloud - #1447

Merged
BigSimmo merged 9 commits into
mainfrom
codex/cloud-github-connector-policy
Jul 31, 2026
Merged

docs: prefer GitHub connector in Codex Cloud#1447
BigSimmo merged 9 commits into
mainfrom
codex/cloud-github-connector-policy

Conversation

@BigSimmo

@BigSimmo BigSimmo commented Jul 30, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a Cloud environment instruction to prefer the connected GitHub connector for supported GitHub tasks, including review-thread replies/resolution and GitHub Actions inspection.

Why

Cloud has an authenticated GitHub connector with administrator access to this repository. A missing shell gh CLI must not block work the connector can perform, and agents must not add a PAT as a workaround.

Validation

  • Confirmed the existing Cloud contract has one insertion point and preserved all other instructions.
  • GitHub Actions and required status checks will run through this PR.

Summary by CodeRabbit

  • Documentation
    • Expanded guidance for safely managing GitHub issues, pull requests, review threads, Actions runs, and repository changes.
    • Clarified connector-first workflows, verification requirements, and handling of unsupported repository or organization settings.
    • Updated the branch review ledger with recent review outcomes, checks, merge status, and documentation updates.
  • Chores
    • Added consistent GitHub workflow guidance across cloud development environments.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The change expands Cloud GitHub connector instructions and updates the append-only branch review ledger with additional review, verification, fix, and merge records.

Changes

GitHub connector guidance

Layer / File(s) Summary
Connector operation and verification policy
AGENTS.md, docs/codex-cloud.md
Cloud instructions now cover comments, review threads, Actions inspection and retries, exact target confirmation, result verification, and restrictions on credential workarounds.

Branch review ledger

Layer / File(s) Summary
Review record maintenance
docs/branch-review-ledger.md
The ledger adds and reorders records for review outcomes, verification checks, fixes, documentation reviews, and merge readiness.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: codex

Suggested reviewers: cursoragent

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the primary change: preferring the GitHub connector in Codex Cloud.
Description check ✅ Passed The description explains the change, motivation, and validation, but it does not use the template headings or include explicit risk and rollout details.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@BigSimmo

Copy link
Copy Markdown
Owner Author

Closing as superseded by merged PR #1449. Current main already establishes the authenticated GitHub connector as the default for explicitly authorised repository/PR/review-thread/Actions work, prohibits PAT workarounds, requires exact-target confirmation before writes, and documents the same contract in both AGENTS.md and docs/codex-cloud.md. The remaining one-line branch delta is redundant and less complete than the merged policy.

@BigSimmo BigSimmo closed this Jul 30, 2026
@BigSimmo

Copy link
Copy Markdown
Owner Author

@cursoragent this PR will be re-opened soon. Please resolve any failing CI, run bugbot and resolve any bugbot comments against current repo and fix any merge conflicts and also fix any errors and address and fix all comments or suggestions that are likely to improve the PR and Codebase. Please implement smallest required fix according to best code practices. Check your work. Leave this PR closed for now but still make all these changes and run the review. I want it ready to go for when I re-open it.

@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

PR #1447 is ready to reopen and left closed.

Done

  • Merged origin/main and fixed the real AGENTS.md conflict (git merge-tree clean).
  • Dropped the redundant docs: prefer GitHub connector in Codex Cloud #1447 one-liner in favor of docs(codex): route authorised GitHub tasks through connector #1449’s control-plane wording, then kept only additive gaps:
    • Actions artifact inspection, BigSimmo admin identity, shell fallback, write-result verification
    • Matching docs/codex-cloud.md updates
    • Cursor Cloud connector-first guidance (shell git push still allowed)
  • Bugbot: no cursor[bot] findings/threads
  • Review: no P0–P2; residual Cursor wording clarified
  • Checks: check:codex-cloud PASS; format:check PASS

Branch tip

codex/cloud-github-connector-policy @ e0121b87 — 5 commits ahead of main, merge-clean.

Notes for reopen

  • GitHub still shows the old closed head (3ac7e9a7) / CONFLICTING until reopen refreshes mergeability against the new tip.
  • Couldn’t update the closed PR body with this token; refresh the description on reopen to match the additive delta above.
Open in Web Open in Cursor 

cursoragent and others added 5 commits July 31, 2026 00:15
Resolve the AGENTS.md conflict against #1449 by keeping the merged
connector control-plane wording, then add the remaining #1447 gaps:
Actions artifact inspection, intended BigSimmo admin connection,
shell git/gh only for genuine connector gaps, write-result verification,
and matching Cursor Cloud + docs/codex-cloud guidance.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Local docs/policy review of codex/cloud-github-connector-policy at
fc42cf0 found no high-confidence P0-P2 issues; ledger append only.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Avoid over-reading the connector-first Cursor Cloud bullet as a ban on
ordinary authorised git branch publication; keep shell gh for genuine
connector gaps only.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
…nnector-policy

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
@BigSimmo BigSimmo reopened this Jul 31, 2026
@supabase

supabase Bot commented Jul 31, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@BigSimmo
BigSimmo marked this pull request as ready for review July 31, 2026 04:56
@BigSimmo

Copy link
Copy Markdown
Owner Author

@cursoragent Work this open PR (confirm number + GitHub head first). Start from
origin/ matching that head; preserve unrelated local WIP.
Do not merge, force-push, rebase, or arm auto-merge. No provider-backed
gates without approval. If you can’t push or resolve threads: diagnose +
comment only.

Goal: review + Bugbot the tip, fix actionable issues with smallest changes,
clear merge/required-CI/thread blockers, push fixes, post one PR summary.
Stay light — no full local verify:* / Playwright / broad suites unless
needed to prove one concrete fix. Don’t regenerate large assets unless required.

  1. Snapshot tip, behind/ahead, mergeable, merge-tree (real conflict vs
    behind-but-clean), required checks on that tip, unresolved actionable
    threads. Missing checks while dirty ≠ green. If the tip moves mid-work,
    re-snapshot.
    npm run ledger:lookup -- <branch> --scope "PR #<n> review+bugbot+fix".
    If already reviewed at this HEAD/scope and still clean with required checks
    green and no new actionable threads: summarize, comment, stop.

  2. Unblock once: real conflict → merge origin/main (for ledger/issues churn,
    prefer main’s queues, keep this PR’s notes); behind-but-clean → sync once
    (wait if required CI is in flight); else leave. No sync thrash.
    If auto-merge is already armed, push only for a real blocker.

  3. Review + Bugbot the delta vs base. High-confidence only (correctness,
    security, privacy, auth, data loss, migrations/RLS, clinical/RAG/source,
    prod reliability, user-facing). Separate PR-introduced defects from
    pre-existing re-emitted data. For generated assets, review generator/
    contracts/aliases/cache — not every generated line. If RAG/governance
    surfaces are touched, note/fix PR body only when policy text is wrong
    or missing. Ignore bot summary/rate-limit noise.

  4. Fix P0/P1 always; fix clear scoped P2; otherwise short disposition reply
    then resolve. Fix required-check failures on this tip only (ignore advisory).
    Prove with the smallest targeted check only. No broad refactors.

  5. Format + commit before push. Push only this PR’s fix commits. Append ledger
    for the final GitHub head + scope above (--supersede on a requested fresh
    same-HEAD pass). Never push a ledger-only tip.

  6. Post one concise top-level PR comment: tip SHA, sync, fixed vs dispositioned,
    required CI status, residual risks. Leave merge to me. Inline comments only
    for remaining open P0/P1 needing a human decision.

Stop when merge-tree clean, no actionable threads left, and required checks are
green or clearly in progress on the current tip.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

PR #1447 — tip 0213d15d (matches GitHub). Synced once; left merge to you.

Snapshot → unblock

Before After
13 behind, GitHub DIRTY/CONFLICTING, mergeability FAILURE merge-tree was clean (behind-but-clean)
Merged origin/main once → pushed 0213d15d
Now 0 behind, merge-tree clean, mergeable: MERGEABLE

Review + Bugbot

CI on tip 0213d15d

In progress / succeeding: PR Policy ✓ · PR mergeability ✓ · Gitleaks ✓ · Static PR + Safety + Semgrep running. Auto-merge not armed.

Other

  • Posted top-level PR summary comment
  • Ledger appended for 0213d15d / scope PR #1447 review+bugbot+fix locally — not pushed (ledger-only tip policy); local tip is 1 commit ahead of origin
  • Could not edit PR body (token 403); body still describes the old one-liner
Open in Web Open in Cursor 

cursoragent and others added 2 commits July 31, 2026 04:57
…nnector-policy

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Local ledger append for tip after main sync; not pushed alone
(ledger-only tip policy).

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

PR #1447 review+bugbot+fix

Tip: 0213d15d (matches GitHub head)
Sync: was 13 behind / merge-tree clean → merged origin/main once. Now 0 behind, merge-tree clean, GitHub mergeable: MERGEABLE (was stale DIRTY/CONFLICTING from behind-but-clean).

Threads / Bugbot: no unresolved Codex, Bugbot, Copilot, or human review threads. Ignored CodeRabbit rate-limit + Codex usage-limit noise.

Review (delta vs main): docs-only — AGENTS.md, docs/codex-cloud.md, prior reopen-prep ledger rows. No high-confidence P0–P2. Additive tightenings on #1449 base (artifact inspection, BigSimmo admin identity, shell gap fallback, write-result verify, Cursor Cloud connector-first). Fixed: none. Dispositioned: none actionable.

Required CI on tip 0213d15d: in progress — CI / SAST / Secret Scan / PR mergeability running; PR Policy SUCCESS. Prior tip ca97a3a0 mergeability failure was behind-but-clean staleness, not a content conflict.

Residual: PR body still describes the old one-liner (token cannot updatePullRequest); please refresh Summary on merge if desired. Ledger row for this scope recorded for 0213d15d locally (not pushed — ledger-only tip policy).

Leave merge to you.

@BigSimmo

Copy link
Copy Markdown
Owner Author

@cursoragent resolve merge conflict please

@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Merge conflict cleared on PR #1447.

  • Merged origin/main into codex/cloud-github-connector-policy (auto-merge, no content fights)
  • Pushed tip 7a4c2cdf
  • GitHub: mergeable: MERGEABLE (was dirty); merge-tree clean
  • PR delta unchanged: AGENTS.md, docs/codex-cloud.md, ledger rows

Required checks will re-run on the new tip.

Open in Web Open in Cursor 

…nnector-policy

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Resolved merge conflict by syncing origin/main.

  • Tip: 7a4c2cdf
  • git merge-tree clean; GitHub mergeable: MERGEABLE (was dirty)
  • PR delta unchanged: AGENTS.md, docs/codex-cloud.md, ledger rows
  • Required checks will re-run on the new tip; leave merge to you.

@BigSimmo
BigSimmo enabled auto-merge (squash) July 31, 2026 05:40
@BigSimmo
BigSimmo merged commit 8e158e7 into main Jul 31, 2026
26 checks passed
@BigSimmo
BigSimmo deleted the codex/cloud-github-connector-policy branch July 31, 2026 05:40

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@AGENTS.md`:
- Around line 886-887: Update the write-safety policy in AGENTS.md so
confirmations include the exact branch for branch mutations and exact file path
for file mutations, alongside repository, PR, thread, and job. Require
verification of the connector result for every allowed write; when using shell
git or gh due to a connector gap, verify the command result and perform a remote
read-back. Apply identical wording to docs/codex-cloud.md and the Cursor Cloud
block.

In `@docs/codex-cloud.md`:
- Around line 102-103: Update the Actions capability documentation near the
listed run/job operations to distinguish read-only inspection from retry
mutations. State that retrying a workflow run or job requires explicit
confirmation for the exact target and its expected side effects, including
potential deployments, while preserving inspection and approved mutation
permissions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0f8fcc8e-3cbe-4ec2-ba51-c56fdfc0e4c5

📥 Commits

Reviewing files that changed from the base of the PR and between 00753db and 7a4c2cd.

📒 Files selected for processing (3)
  • AGENTS.md
  • docs/branch-review-ledger.md
  • docs/codex-cloud.md

Comment thread AGENTS.md
Comment on lines +886 to +887
- Confirm the exact repository and PR/thread/job before a write, and verify the
connector result before treating the write as successful. If the connector lacks a

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Complete target and result verification for every allowed write.

This policy allows branch and file mutations, but the confirmation list names only the repository, PR, thread, and job. Confirm the exact branch and file path for branch and file writes. If the connector gap requires shell git or gh, verify that control plane’s result and perform a remote read-back; no connector result exists for that path.

Apply the same wording to docs/codex-cloud.md and the Cursor Cloud block.

Suggested wording
- Confirm the exact repository and PR/thread/job before a write, and verify the
- connector result before treating the write as successful.
+ Confirm the exact repository and operation-specific target (branch, file, PR,
+ thread, or job) before a write. Verify the result from the selected control
+ plane; for shell `git` or `gh`, perform a remote read-back.

Based on the PR objective, exact-target confirmation must cover every write target.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@AGENTS.md` around lines 886 - 887, Update the write-safety policy in
AGENTS.md so confirmations include the exact branch for branch mutations and
exact file path for file mutations, alongside repository, PR, thread, and job.
Require verification of the connector result for every allowed write; when using
shell git or gh due to a connector gap, verify the command result and perform a
remote read-back. Apply identical wording to docs/codex-cloud.md and the Cursor
Cloud block.

Comment thread docs/codex-cloud.md
Comment on lines +102 to +103
issue and PR comments, inline-review-thread replies/resolution, Actions
run/job/log/artifact inspection and retries, and approved branch, file, or PR mutations.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Require explicit confirmation before retrying Actions runs.

Actions inspection is read-only. Retrying a run is a hosted-CI mutation. It can trigger a deployment or another external side effect. Require confirmation for the exact workflow, run, or job and its expected side effects before retrying.

Suggested wording
- run/job/log/artifact inspection and retries, and approved branch, file, or PR mutations.
+ run/job/log/artifact inspection, and approved branch, file, or PR mutations.
+ Treat Actions retries as writes. Require explicit confirmation for the exact
+ workflow, run, or job and its expected side effects before retrying.

As per coding guidelines, hosted CI mutations require explicit user confirmation.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
issue and PR comments, inline-review-thread replies/resolution, Actions
run/job/log/artifact inspection and retries, and approved branch, file, or PR mutations.
issue and PR comments, inline-review-thread replies/resolution, Actions
run/job/log/artifact inspection, and approved branch, file, or PR mutations.
Treat Actions retries as writes. Require explicit confirmation for the exact
workflow, run, or job and its expected side effects before retrying.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/codex-cloud.md` around lines 102 - 103, Update the Actions capability
documentation near the listed run/job operations to distinguish read-only
inspection from retry mutations. State that retrying a workflow run or job
requires explicit confirmation for the exact target and its expected side
effects, including potential deployments, while preserving inspection and
approved mutation permissions.

Source: Coding guidelines

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants