Skip to content

docs(agents): tag protection + mutable-ref exception (#505) - #509

Merged
don-petry merged 2 commits into
mainfrom
feat/issue-505-tag-protection
Jun 9, 2026
Merged

don-petry merged 2 commits into
mainfrom
feat/issue-505-tag-protection

Conversation

@don-petry

@don-petry don-petry commented Jun 9, 2026 •

Copy link
Copy Markdown
Collaborator

What (Phase 1 · #505 · epic #495)

Makes the mutable channel-tag exception to the SHA-pin standard safe and explicit.

  • Configured the release-channel-tags repository ruleset (id 17432201, active):
    • target: tags pr-review/**, dev-lead/**
    • rules: restrict update + deletion
    • bypass: OrganizationAdmin + the automation Integration app
    • Net effect: the pr-review/dev-lead agents (running as GITHUB_TOKEN) cannot move or delete
      release tags; only an admin / the promotion automation can.
  • Documented the exception in AGENTS.md so compliance audits don't flag @pr-review/stable /
    @dev-lead/stable on first-party callers as "unpinned actions."

Why

Channel tags are deliberately mutable (that's how versions are selected without per-caller churn —
initiative §5.1). The SHA-pin standard targets third-party actions; these are first-party workflows
we own. The ruleset + immutable vX.Y.Z targets + cut-release.sh's overwrite-guard bound the risk.

When the health-gated promotion workflow (#501) lands, the ruleset bypass will be tightened to that
workflow's identity.

Closes #505. Blocked-by #496 in the DAG; the ruleset operates on the already-cut tags, and the doc
forward-references docs/release/versioning.md (lands with #508).

Summary by CodeRabbit

  • Documentation
    • Added comprehensive documentation explaining how release channel tags operate, including the distinction between immutable version tags and moving channel tags, repository ruleset constraints that govern tag management, and clarification on sanctioned first-party channel tag exceptions to standard pinning practices. Also documents controls for health-gated promotion workflows.

…505)

Records the release-channel-tags ruleset (restricts update/deletion of
pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation
Integration) and the scoped exception to the SHA-pin standard for first-party
channel tags. Tells compliance audits not to flag @pr-review/stable etc. as
unpinned actions. Ruleset id 17432201 created and active.

Closes #505

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@don-petry
don-petry requested a review from a team as a code owner June 9, 2026 03:38
Copilot AI review requested due to automatic review settings June 9, 2026 03:38
@don-petry don-petry added documentation Documentation changes security Security-related PRs and issues initiative Epic / initiative tracking issue labels Jun 9, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 667d8046-893e-455b-ad00-cd5a961efe46

📥 Commits

Reviewing files that changed from the base of the PR and between a250201 and 8938544.

📒 Files selected for processing (1)
  • AGENTS.md

📝 Walkthrough

Walkthrough

Added a new "Release channel tags & the mutable-ref exception" section to AGENTS.md that documents how first-party agent release channel tags (pr-review and dev-lead) use immutable version tags alongside mutable moving tags, clarifies the scoped exception to SHA-pinning rules, specifies ruleset constraints limiting tag movement to OrganizationAdmin and promotion automation, and provides guidance for compliance audits not to flag these sanctioned channel tags as unpinned.

Changes

Release channel tag governance documentation

Layer / File(s) Summary
Release channel tags & mutable-ref exception documentation
AGENTS.md
Section added defining immutable vX.Y.Z version tags versus moving stable/next/ring* channel tags, documenting the rationale and scope of the SHA-pinning exception for first-party workflows, specifying repository ruleset constraints that restrict tag movement/deletion to OrganizationAdmin and the promotion automation, and clarifying that compliance audits should not treat these sanctioned first-party channel tags as unpinned actions.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related PRs

  • petry-projects/.github-private#504: Both PRs document release channel and tag strategies for agentic workflows, covering immutable version tags and mutable channel pointers.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/issue-505-tag-protection

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates AGENTS.md to document the release channel tags and the mutable-ref exception for first-party agents. It explains the distinction between immutable releases and moving channel tags, and outlines the security boundaries that justify this exception. The feedback suggests formatting the reference to agentic-release-strategy.md as a clickable relative markdown link to improve navigability.

Comment thread AGENTS.md

Compliance audits must therefore **not** flag `@pr-review/stable` / `@dev-lead/stable` (or other channel
tags) on first-party callers as "unpinned actions" — they are the sanctioned version-selection mechanism
(see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

low

To improve navigability, consider formatting the reference to agentic-release-strategy.md as a clickable relative markdown link, similar to how other document references are handled in this file.

Suggested change
(see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`).
(see the initiative analysis §5.1: [docs/initiatives/agentic-release-strategy.md](./docs/initiatives/agentic-release-strategy.md)).

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
  (bot comment is a usage-limit notification, not a code review — no findings reported)
Files changed: none
Skipped (informational): 1 — "You have reached your Codex usage limits for code reviews"
```
**Tier 1 blocker check:** All completed CI checks passed (`success`/`skipped`). The only in-progress checks are `Analyze (python)`, `SonarCloud`, and `copilot-pull-request-reviewer` — none have a failing conclusion. The single review from `gemini-code-assist[bot]` is `COMMENTED` (not `CHANGES_REQUESTED`). Zero blockers; no code changes required.

@don-petry
don-petry enabled auto-merge (squash) June 9, 2026 03:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR documents a scoped, security-bounded exception to the org’s SHA-pin standard for first-party reusable workflows referenced via mutable per-agent channel tags (e.g., pr-review/stable, dev-lead/stable), aligned with the Phase 1 tag-protection work in #505.

Changes:

  • Adds an “Release channel tags & the mutable-ref exception” section to clarify immutable release tags vs. moving channel tags.
  • Explains why mutable channel tags are acceptable for first-party workflows and summarizes the bounding controls (ruleset + immutable release tags + guarded promotion path).

Comment thread AGENTS.md
Comment on lines +73 to +75
The agents (`pr-review`, `dev-lead`) are versioned via tags — see
[`docs/release/versioning.md`](./docs/release/versioning.md). Two kinds of tag exist per agent:

Comment thread AGENTS.md
Comment on lines +89 to +90
- Immutable `vX.Y.Z` tags are the real rollback targets; `scripts/cut-release.sh` refuses to overwrite
an existing release tag.
Comment thread AGENTS.md
Comment on lines +94 to +96
Compliance audits must therefore **not** flag `@pr-review/stable` / `@dev-lead/stable` (or other channel
tags) on first-party callers as "unpinned actions" — they are the sanctioned version-selection mechanism
(see the initiative analysis §5.1: `docs/initiatives/agentic-release-strategy.md`).
@don-petry
don-petry merged commit 3d38fe2 into main Jun 9, 2026
@don-petry
don-petry deleted the feat/issue-505-tag-protection branch June 9, 2026 16:12
@sonarqubecloud

sonarqubecloud Bot commented Jun 9, 2026

Copy link
Copy Markdown

don-petry added a commit that referenced this pull request Jun 12, 2026
…505) (#509)

Records the release-channel-tags ruleset (restricts update/deletion of
pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation
Integration) and the scoped exception to the SHA-pin standard for first-party
channel tags. Tells compliance audits not to flag @pr-review/stable etc. as
unpinned actions. Ruleset id 17432201 created and active.

Closes #505

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 14, 2026
…505) (#509)

Records the release-channel-tags ruleset (restricts update/deletion of
pr-review/** and dev-lead/** tags; bypass = OrganizationAdmin + automation
Integration) and the scoped exception to the SHA-pin standard for first-party
channel tags. Tells compliance audits not to flag @pr-review/stable etc. as
unpinned actions. Ruleset id 17432201 created and active.

Closes #505

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Documentation changes initiative Epic / initiative tracking issue security Security-related PRs and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Phase 1] Tag protection + document scoped mutable-ref exception to SHA-pin standard

2 participants