Skip to content

🧭 Idea Promotion Queue #763

Description

@github-actions

Legend: 🟒 Ripe β€” ready to promote now Β· 🟑 Soon β€” one gap to close Β· βšͺ Not yet / covered


🟒 Ripe to Promote

These are the pick-list for a human to bless. Add idea:approved to the Discussion to fire the BMAD Scrum Master initiative-planner.

Idea Why now Pre-drafted promotion note
#1842 Reusable Workflow Runtime Self-Identity for Live Drift Audit GitHub shipped job.workflow_ref/job.workflow_sha on Sep 3 2026 β€” three weeks ago. The thin-caller ADR-0001 architecture and fleet_stub_drift.sh can absorb this immediately with no new dependencies. Directly addresses the drift-bug class from #1034. Initiative: Extend fleet_stub_drift.sh and the reusable workflow template to emit a runtime identity assertion on each execution, comparing the resolved SHA against the expected channel tag. Drift caught live, not just in nightly lint, closes a detection gap that scheduled audits structurally cannot cover.
#1839 ARM64 Runner Migration for Fleet-Wide CI Cost Reduction GitHub ARM64 runners for private repos launched Jan 2026 with a verified 39% pricing reduction. This org's CI is 100% bash/jq/Python with zero x86 binary dependencies β€” zero porting risk. The feature has been GA for 8 months with no reported issues. Initiative: Migrate all scheduled utility workflows (fleet-monitor, compliance-audit, health-checks) to ubuntu-24.04-arm runners in a phased rollout starting with lowest-risk jobs, measuring actual minute savings against baseline before rolling to the PR-review cascade.
#1841 MCP Server Provenance Pinning with Hash Attestation for Review Tiers A real-world malicious MCP server was disclosed in 2026; OX Security confirmed 10+ CVEs in Anthropic MCP SDKs affecting ~200K servers. This repo uses REVIEW_MCP_CONFIG for the deep review tier today β€” there is live exposure. Initiative: Implement an MCP server allowlist (name + version + hash tuples in a committed file) with a pre-flight verification step in the MCP-enabled review invocation path, blocking any server update that has not been explicitly reviewed and promoted via a signed PR.
#1838 Non-Required Check Circuit Breaker for Merge Pipeline Resilience A silent deadlock class exists today: one persistently failing non-required check causes every PR to appear CI-failing, halting the review pipeline with no fleet alert. ci-status.sh is the right insertion point and the circuit-breaker pattern is well-understood. Initiative: Add a circuit-breaker detector to ci-status.sh that tracks N consecutive failures of a non-required check across M distinct PRs, degrades it from the CI-passing determination automatically, and fires a fleet-monitor alert β€” turning a silent deadlock into a noisy, self-healing degradation.
#1157 GitInject-Class PR Content Sanitization Layer for Review Pipeline Defense The GitInject arXiv paper (Jun 2026) names GitHub Actions + Claude Code pipelines as the primary attack surface. OWASP reports a 340% YoY surge in prompt injection in CI/CD. review-one-pr.sh passes PR descriptions and commit messages to the LLM with no sanitization today. Initiative: Add a pre-LLM sanitization stage to review-one-pr.sh that detects and neutralizes injection patterns (hidden instructions, role-override attempts, data-exfiltration commands) in PR descriptions, commit messages, and code comments before they reach any agentic tier.

🟑 Soon

Idea What's missing before it's ripe
#1840 Confidence-Scored Issue Triage for Intelligent Auto-Routing Needs a baseline measurement of the current triage false-positive rate (how many needs-human-review holds are actually auto-approvable). Without that number the confidence threshold is arbitrary and the initiative has no success criterion.
#1175 Agentic Persona Framework The Kiro gap-closure epic (#1142) and the ADR-0007 agent-ingress rollout (#1723) are both in-flight and change where persona definitions live. Formalizing the framework before those settle risks immediate rework.
#636 OWASP Agentic Top 10 Security Posture Scoring Strong direction, but #1157 (injection defense) and #1841 (MCP provenance) are higher-urgency remediations from the same threat model. Let those land first so the posture audit has real surface to score against.
#1041 Health-Check Issue Lifecycle Automation Concrete and low-risk, but needs verification of the actual open-issue accumulation rate before scoping the de-duplication logic. The 15+ open daily issues claim needs a current count to define scope.
#1348 Evaluate Additional AI Code-Review Services High urgency (CodeRabbit Free rate-limit is binding now), but this is an evaluation task, not a build initiative. Needs a defined benchmark harness and shortlist before promotion makes sense as an epic.
#1158 Canary Burn-Rate SLO with Post-Promotion Auto-Rollback Extends the Safe Release initiative (#495), which has Phase 2 (#1623) in-flight. Wait for Phase 2 to close before adding the burn-rate SLO layer to avoid scope collision.

βšͺ Not Yet / Covered


Already Approved (past triage)

These carry idea:approved and are active in the initiative pipeline β€” listed for reference, not re-ranked.


To promote an idea: open the linked Discussion and add the label idea:approved. The initiative-planner.yml workflow fires automatically and the BMAD Scrum Master (Bob) drafts the initiative plan as a new epic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    idea-triageMarks the Idea Promotion Queue tracking issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions