Repository navigation
feat(initiative): dependency-aware driver to deliver epics agentically - #507
Conversation
Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 40 minutes and 47 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (5)
📝 WalkthroughWalkthroughThis PR introduces a GitHub Actions-driven orchestration system for initiative epics. A new workflow triggers on issue closure, scheduled cron, or manual dispatch, executing a Bash driver script that labels sub-issues for automated processing only when their dependency blockers are resolved and safety gates are satisfied, up to a bounded concurrency limit. ChangesInitiative Driver Orchestration
Sequence DiagramssequenceDiagram
participant Trigger as Issue Closed / Cron / Manual
participant Workflow as Initiative Driver Workflow
participant Driver as initiative-driver.sh
Trigger->>Workflow: event.inputs.epic or env.CLOSED_ISSUE
Workflow->>Workflow: Validate GH_TOKEN present
Workflow->>Workflow: Set concurrency and permissions
Workflow->>Driver: Run with EPIC, CLOSED_ISSUE, DRY_RUN, MAX_IN_FLIGHT
flowchart
Init["Initialize env vars<br/>Set strict mode"] --> GateCheck["Check epic<br/>GATE_LABEL present?"]
GateCheck -->|No| Exit["Exit no-op"]
GateCheck -->|Yes| EnumSubs["Enumerate epic<br/>sub-issues"]
EnumSubs --> ClosedCheck["If CLOSED_ISSUE:<br/>verify in epic?"]
ClosedCheck -->|No| Exit
ClosedCheck -->|Yes| CountInflight["Count open sub-issues<br/>with DEV_LEAD_LABEL"]
CountInflight --> CalcCapacity["capacity = MAX_IN_FLIGHT<br/>- in_flight_count"]
CalcCapacity --> IterateOpen["For each open<br/>sub-issue"]
IterateOpen --> SkipCheck["Skip if:<br/>in-flight or<br/>hands-off or hold?"]
SkipCheck -->|Yes| IterateOpen
SkipCheck -->|No| CheckBlockers["Query blocked_by<br/>any open blockers?"]
CheckBlockers -->|Yes| IterateOpen
CheckBlockers -->|No| Label["Label with<br/>DEV_LEAD_LABEL<br/>or dry-run log"]
Label --> DecrementCap["capacity--"]
DecrementCap --> CapCheck{"capacity > 0?"}
CapCheck -->|Yes| IterateOpen
CapCheck -->|No| LogTotal["Log released count"]
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — fix-bot-comment (applied)Changes committed and pushed. |
There was a problem hiding this comment.
Pull request overview
Adds an initiative “driver” that orchestrates dev-lead pickups for an epic’s child issues by reading native GitHub dependency edges (“blocked by”) and applying the dev-lead label in dependency order, bounded by MAX_IN_FLIGHT, without changing dev-lead itself.
Changes:
- Introduces
scripts/initiative-driver.shto gate oninitiative:auto, compute in-flight capacity, and label newly-unblocked sub-issues. - Adds
.github/workflows/initiative-driver.ymlto run the driver onissues: closed, a safety-net cron, andworkflow_dispatch. - Documents the orchestration model and operator runbook in
docs/initiatives/agentic-release-strategy-orchestration.md.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
scripts/initiative-driver.sh |
New bash dispatcher that evaluates sub-issue readiness (blockers, hold/hands-off labels, in-flight cap) and applies dev-lead. |
.github/workflows/initiative-driver.yml |
New workflow to invoke the driver on issue-closure events, cron backstop, and manual runs. |
docs/initiatives/agentic-release-strategy-orchestration.md |
New doc describing the DAG/waves model, PAT requirement, and runbook for operating the driver. |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #507 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71d1cc353c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Code Review
This pull request introduces the agentic release strategy orchestration initiative, adding documentation and a Bash script (scripts/initiative-driver.sh) to automate dependency-aware label dispatching for initiative epics. The code review feedback highlights several critical robustness issues in the Bash script, particularly regarding silent failures under set -e when using process substitution with mapfile or executing subshells directly inside if conditions. Additionally, it suggests optimizing the has_label function using pure Bash pattern matching to avoid spawning unnecessary subprocesses.
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/initiative-driver.yml:
- Around line 43-52: The GH_PAT_WORKFLOWS token (GH_TOKEN) is currently set
under the global env and is exposed to every step (including actions/checkout);
remove GH_TOKEN from the top-level env and instead add GH_TOKEN: ${{
secrets.GH_PAT_WORKFLOWS }} to the env blocks of only the steps that invoke the
GitHub CLI or require the PAT (the guard step and the driver step referenced in
the workflow), and apply the same scoping fix for the second occurrence noted
around lines 59-72 so only those specific steps receive the token.
- Around line 36-37: The workflow currently grants only issues: write and
exposes GH_TOKEN at workflow level which breaks actions/checkout and
unnecessarily exposes the PAT; update the workflow permissions to include
contents: read (so actions/checkout succeeds) and remove or narrow issues: write
from the global permissions, and move the GH_TOKEN environment variable out of
the global env into the specific steps that need it (the PAT guard step and the
step that runs bash scripts/initiative-driver.sh which calls gh); ensure
actions/checkout step remains unprivileged by not inheriting the PAT and that
only the two gh-related steps have env: GH_TOKEN set.
In `@scripts/initiative-driver.sh`:
- Around line 42-50: Validate and normalize EPIC, CLOSED_ISSUE, MAX_IN_FLIGHT
and DRY_RUN early: require EPIC and CLOSED_ISSUE to match only digits and use
`${EPIC:?}` style with a clear error message to fail fast if empty/invalid;
ensure MAX_IN_FLIGHT is a positive integer (reject non-digits like "1+4" and
optionally clamp to a sensible max) before any arithmetic or use in API paths;
normalize DRY_RUN to a canonical "true" or "false" (accept common user values
like "true|false|1|0|yes|no" case-insensitively and convert to lowercase
"true"/"false") and use that normalized value for branching and before the first
`gh api` call; perform these checks and normalizations at the top of the script
(near the variable definitions for EPIC, CLOSED_ISSUE, MAX_IN_FLIGHT, DRY_RUN)
so invalid inputs fail with clear messages and never get passed to shell
commands or API endpoints.
- Around line 42-50: Make the top-level configuration variables (REPO, EPIC,
CLOSED_ISSUE, DEV_LEAD_LABEL, GATE_LABEL, HANDS_OFF_LABEL, HOLD_LABEL,
MAX_IN_FLIGHT, DRY_RUN) readonly by declaring them with readonly after their
default assignments, replace all single-bracket test expressions ([ ... ]) with
the safer double-bracket form ([[ ... ]]) wherever those variables are
evaluated, and convert any use of arithmetic conditional syntax from (( ... ))
to the POSIX-friendly $(( ... )) form in the arithmetic checks that reference
MAX_IN_FLIGHT or similar counters; locate these changes around the conditional
checks and arithmetic expressions that reference the above symbols and update
them consistently.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 8e78a357-0665-4903-9314-5841d03a4dd3
📒 Files selected for processing (3)
.github/workflows/initiative-driver.ymldocs/initiatives/agentic-release-strategy-orchestration.mdscripts/initiative-driver.sh
|
@coderabbitai resolve |
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
✅ Action performedComments resolved and changes approved. |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
|
Dev-Lead — fix-reviews (no-changes)Agent reasoning |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 4d969f91e9aede964a138a3a28380ae7e99c18b6
Review mode: triage-approved (single reviewer)
Summary
Adds a dependency-aware label dispatcher (scripts/initiative-driver.sh + .github/workflows/initiative-driver.yml) that releases an epic's sub-issues to the dev-lead agent in DAG order. Confirmation review of triage's low-risk assessment — all CI green, well-tested, properly hardened.
Linked issue analysis
No closing issue reference. PR body identifies this as a companion to #504 (analysis) and dependency edges for epic #495's children (#496–#506). Scope matches the description: orchestration layer that does not modify dev-lead itself.
Findings
Workflow hardening — .github/workflows/initiative-driver.yml is well-locked-down: contents: read only, persist-credentials: false, pinned actions/checkout SHA with version comment, 10-min timeout, concurrency group keyed by epic, fail-fast PAT-presence guard. The PAT requirement (GH_PAT_WORKFLOWS) is correctly motivated — a GITHUB_TOKEN-applied label would not retrigger dev-lead.yml.
Script safety — scripts/initiative-driver.sh uses set -euo pipefail, validates EPIC/MAX_IN_FLIGHT as integers, normalizes DRY_RUN, marks all config readonly after validation. has_label uses pure-bash exact-line matching (no regex injection risk). Gate label (initiative:auto on the epic) keeps Phase 1 human-driven by default. Per-issue dev-lead:hands-off / initiative:hold escape hatches honored. MAX_IN_FLIGHT cap bounds blast radius.
Tests — tests/test_initiative_driver.bats mocks gh to cover gate behavior, MAX_IN_FLIGHT cap, blocked_by evaluation, and label application. Note: the has_label micro-tests redefine the function locally with grep -qxF rather than invoking the script's pure-bash implementation, but the integration tests exercise the real script via bash $SCRIPT. Acceptable. lint.yml is updated to run the new bats file.
Docs — docs/initiatives/agentic-release-strategy-orchestration.md clearly explains the model, DAG/waves, gates, PAT requirement, and bootstrap order. Prior bot review threads (CodeRabbit, Codex, Gemini, Copilot) all resolved or dismissed; SonarCloud quality gate passed.
CI status
All required checks green: Lint, ShellCheck, bats, validate-agent-profiles, Agent Security Scan, Compile agentic workflows, CodeQL (actions + python), SonarCloud, AgentShield, Secret scan (gitleaks), unit-tests, gh-aw-compile, dependency-audit (no applicable ecosystems). review workflow runs from earlier cycles are CANCELLED/SKIPPED as expected.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4d969f91e9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| gh api "repos/$REPO/issues/$n/dependencies/blocked_by" \ | ||
| --jq '[.[] | select(.state=="open") | .number] | join(",")' |
There was a problem hiding this comment.
Paginate blocked-by dependencies before releasing
When a ready candidate has more than 30 blocked_by dependencies, this call only inspects the first page; I checked GitHub's REST docs for this endpoint, which list per_page with a default of 30 plus page pagination parameters. Because the sub-issues calls above use --paginate but this one does not, an open blocker on page 2+ is missed and the driver can apply dev-lead before all blockers are closed.
Useful? React with 👍 / 👎.
#507) * feat(initiative): dependency-aware driver to deliver epics agentically Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bot): address bot feedback [skip ci-relay] * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
#507) * feat(initiative): dependency-aware driver to deliver epics agentically Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bot): address bot feedback [skip ci-relay] * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
#507) * feat(initiative): dependency-aware driver to deliver epics agentically Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bot): address bot feedback [skip ci-relay] * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
#507) * feat(initiative): dependency-aware driver to deliver epics agentically Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bot): address bot feedback [skip ci-relay] * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
#507) * feat(initiative): dependency-aware driver to deliver epics agentically Adds an orchestration layer that turns the per-item dev-lead agent into ordered, dependency-gated delivery of a whole initiative — without changing the agent. - scripts/initiative-driver.sh: reads an epic's native 'blocked by' edges and applies the `dev-lead` label to each OPEN sub-issue whose blockers are all closed, bounded by MAX_IN_FLIGHT. Gated on `initiative:auto` (off by default, so Phase 1 stays human-driven); skips `dev-lead:hands-off`/`initiative:hold`. - .github/workflows/initiative-driver.yml: runs on issues:[closed] (merge -> close -> unblock -> label -> next pickup), a safety-net cron, and dispatch. Applies the label via GH_PAT_WORKFLOWS — a GITHUB_TOKEN-applied label does NOT trigger dev-lead (loop-prevention; same class as pr-review #463). - docs/initiatives/agentic-release-strategy-orchestration.md: model, DAG/waves, gates, the human->agent bootstrap order, and an operator runbook. Dependency edges for epic #495's children (#496-#506) are set as native GitHub 'blocked by' relationships. Validated: shellcheck clean; dry-run against the live DAG releases only #496 (no blockers) and correctly holds the rest; the default `initiative:auto` gate no-ops as intended. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bot): address bot feedback [skip ci-relay] * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>



What
Adds an orchestration layer that delivers an initiative epic's child issues through the existing
per-item dev-lead agent in dependency order — without modifying dev-lead itself.
scripts/initiative-driver.sh— reads an epic's native "blocked by" edges and applies thedev-leadlabel to each OPEN sub-issue whose blockers are all closed, bounded byMAX_IN_FLIGHT..github/workflows/initiative-driver.yml— runs onissues:[closed](merge → close → unblock →label → next pickup), a safety-net cron, and
workflow_dispatch.docs/initiatives/agentic-release-strategy-orchestration.md— model, DAG/waves, gates, thehuman→agent bootstrap order, and an operator runbook.
Companion to #504 (the analysis). Dependency edges for epic #495's children (#496–#506) are already
set as native GitHub "blocked by" relationships.
Why
Dev-lead is reactive and per-item (triggers only on the
dev-leadlabel). Coordinating a multi-issueinitiative = deciding when that label is applied to each ready issue. This driver makes that
decision from the dependency graph, so a merge automatically releases the now-unblocked successors.
Safety design
initiative:auto, soPhase 1 stays human-driven (you arm Phase 2 by adding that label once
@stableexists).dev-lead:hands-offandinitiative:holdissues (need a human).MAX_IN_FLIGHT(default 2) caps parallel token cost / blast radius.GH_PAT_WORKFLOWS— aGITHUB_TOKEN-applied label doesnot trigger dev-lead (GitHub loop-prevention; same class as PR Review Agent never reviews at green CI — skips on ci-pending with no CI-completion re-trigger (clean PRs stuck at REVIEW_REQUIRED) #463). Workflow fails fast if absent.
Validation
shellcheck scripts/initiative-driver.sh— clean.initiative:autogate: no-ops as intended (epic not yet armed).markdownlint-cli2— clean.Follow-ups (noted in the doc, not in this PR)
ghfor the gate/blocker/cap logic.EPIC=495default if a second initiative adopts the driver.Summary by CodeRabbit
New Features
Documentation