Skip to content

feat(governance): trust exact-head Validator App reviews - #14

Merged
tom-sapletta-com merged 13 commits into
publish/validated-repair-031from
plan/ticket-018-validator-approval
Aug 4, 2026
Merged

feat(governance): trust exact-head Validator App reviews#14
tom-sapletta-com merged 13 commits into
publish/validated-repair-031from
plan/ticket-018-validator-approval

Conversation

@tom-sapletta-com

Copy link
Copy Markdown
Contributor

Summary

  • add an exact allowlist for the independent Validator GitHub App
  • accept human or allowlisted App approval only on the current head SHA
  • reject unknown bots, stale/dismissed reviews, self-review, and malformed policy
  • add deterministic approval fixtures to the governance gate

Validation

  • make governance
  • npm run verify
  • make smoke
  • make examples-check
  • make docker-smoke
  • gold v1/v2: 100%
  • full Docker E2E: 342/342 with JDK 17

Ticket: ticket-018, AC-30..AC-40. AC-40 intentionally remains open until this bootstrap policy is independently reviewed/merged and the real Validator App reviews PR #13.

@ifuri-validator-agent ifuri-validator-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deterministic Validator approval for exact head 17715cc6af4d983918462a23d0f37a810b910eec.

Ticket: ticket-018
Correlation ID: todo2code-pr-14-ticket-018-17715cc6
Model: openrouter/z-ai/glm-5.2
Advisory LLM verdict: APPROVE
Advisory summary: The visible diff consists of ticket-018 documentation updates (README, ai-codex logs, changelog) describing planning, implementation notes, and acceptance criteria for a Validator App allowlist and direct-PR strategy. The content is narrative/markdown only; no executable source, workflow, or governance logic changes are visible in the provided diff. Security-relevant claims (scoped App tokens, exact-head binding, fail-closed checks, no secrets in logs, advisory-only LLM verdicts) are consistent with defensive design, though they describe intended behavior rather than code in this diff.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Merge was not requested or performed.

@tom-sapletta-com
tom-sapletta-com merged commit 944feda into publish/validated-repair-031 Aug 4, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant