Skip to content

v3.8.89

Choose a tag to compare

@github-actions github-actions released this 21 Apr 16:27
· 9401 commits to main since this release
v3.8.89

Patch release: hardens GitHub signature-footer enforcement against hallucinated inline footers (t2685, #20307).

Changes

  • New: PATH shim (~/.aidevops/agents/scripts/gh) intercepts gh issue comment, gh issue create, gh pr comment, and gh pr create calls. Auto-injects the helper-generated signature via gh-signature-helper.sh footer whenever the body lacks the canonical <!-- aidevops:sig --> marker. Fast pass-through for all other subcommands. Bypass: AIDEVOPS_GH_SHIM_DISABLE=1.
  • Tightened OpenCode plugin gate in quality-hooks-signature.mjs::checkSignatureFooterGate. Marker-based detection replaces the prior cmd.includes('aidevops.sh') substring check. Transparent repair via output.args.command mutation; mentoring throw on unparseable bodies (heredoc-sourced etc.).
  • Reinforced prompts/build.txt §8 with the exact hallucinated prose as an anti-pattern example.

Why

On 2026-04-21 an interactive session composed a human-readable footer inline, bypassing runtime/version/model/token metadata enforcement. The canonical enforcement path (wrapper gh_create_issue/gh_issue_comment) only fires when agents call the wrappers — calling raw gh bypassed it. The PATH shim closes that hole by placing enforcement at the gh binary boundary.

Verification

  • 32/32 signature-footer gate tests pass
  • 12/12 PATH shim tests pass (10 cases)
  • 30/30 gh_wrapper auto-sig regression tests pass
  • 106/106 full plugin test suite pass
  • qlty smells: 23 total (below 25 threshold), 0 regression