docs(agents): tag protection + mutable-ref exception (#505) - #509
Conversation
…505) Records the release-channel-tags ruleset (restricts update/deletion of pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation Integration) and the scoped exception to the SHA-pin standard for first-party channel tags. Tells compliance audits not to flag @pr-review/stable etc. as unpinned actions. Ruleset id 17432201 created and active. Closes #505 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdded a new "Release channel tags & the mutable-ref exception" section to ChangesRelease channel tag governance documentation
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request updates AGENTS.md to document the release channel tags and the mutable-ref exception for first-party agents. It explains the distinction between immutable releases and moving channel tags, and outlines the security boundaries that justify this exception. The feedback suggests formatting the reference to agentic-release-strategy.md as a clickable relative markdown link to improve navigability.
|
|
||
| Compliance audits must therefore **not** flag `@pr-review/stable` / `@dev-lead/stable` (or other channel | ||
| tags) on first-party callers as "unpinned actions" — they are the sanctioned version-selection mechanism | ||
| (see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`). |
There was a problem hiding this comment.
To improve navigability, consider formatting the reference to agentic-release-strategy.md as a clickable relative markdown link, similar to how other document references are handled in this file.
| (see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`). | |
| (see the initiative analysis §5.1: [docs/initiatives/agentic-release-strategy.md](./docs/initiatives/agentic-release-strategy.md)). |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
There was a problem hiding this comment.
Pull request overview
This PR documents a scoped, security-bounded exception to the org’s SHA-pin standard for first-party reusable workflows referenced via mutable per-agent channel tags (e.g., pr-review/stable, dev-lead/stable), aligned with the Phase 1 tag-protection work in #505.
Changes:
- Adds an “Release channel tags & the mutable-ref exception” section to clarify immutable release tags vs. moving channel tags.
- Explains why mutable channel tags are acceptable for first-party workflows and summarizes the bounding controls (ruleset + immutable release tags + guarded promotion path).
| The agents (`pr-review`, `dev-lead`) are versioned via tags — see | ||
| [`docs/release/versioning.md`](./docs/release/versioning.md). Two kinds of tag exist per agent: | ||
|
|
| - Immutable `vX.Y.Z` tags are the real rollback targets; `scripts/cut-release.sh` refuses to overwrite | ||
| an existing release tag. |
| Compliance audits must therefore **not** flag `@pr-review/stable` / `@dev-lead/stable` (or other channel | ||
| tags) on first-party callers as "unpinned actions" — they are the sanctioned version-selection mechanism | ||
| (see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`). |
|
…505) (#509) Records the release-channel-tags ruleset (restricts update/deletion of pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation Integration) and the scoped exception to the SHA-pin standard for first-party channel tags. Tells compliance audits not to flag @pr-review/stable etc. as unpinned actions. Ruleset id 17432201 created and active. Closes #505 Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…505) (#509) Records the release-channel-tags ruleset (restricts update/deletion of pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation Integration) and the scoped exception to the SHA-pin standard for first-party channel tags. Tells compliance audits not to flag @pr-review/stable etc. as unpinned actions. Ruleset id 17432201 created and active. Closes #505 Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>



What (Phase 1 · #505 · epic #495)
Makes the mutable channel-tag exception to the SHA-pin standard safe and explicit.
release-channel-tagsrepository ruleset (id17432201, active):pr-review/**,dev-lead/**update+deletionGITHUB_TOKEN) cannot move or deleterelease tags; only an admin / the promotion automation can.
AGENTS.mdso compliance audits don't flag@pr-review/stable/@dev-lead/stableon first-party callers as "unpinned actions."Why
Channel tags are deliberately mutable (that's how versions are selected without per-caller churn —
initiative §5.1). The SHA-pin standard targets third-party actions; these are first-party workflows
we own. The ruleset + immutable
vX.Y.Ztargets +cut-release.sh's overwrite-guard bound the risk.When the health-gated promotion workflow (#501) lands, the ruleset bypass will be tightened to that
workflow's identity.
Closes #505. Blocked-by #496 in the DAG; the ruleset operates on the already-cut tags, and the doc
forward-references
docs/release/versioning.md(lands with #508).Summary by CodeRabbit