Skip to content

Repo automation

talas9 edited this page Oct 9, 2026 · 2 revisions

Repo automation

Note

Rules decide; a model only adds research, wording or an escalation to human review. Nothing here closes or deletes an issue, comment or account. Tunables live in .github/moderation/config.json, not in the workflows.

The jobs

Job Workflow Trigger What it does
Triage community.yml Issue, comment and discussion events Rules-first labels (type, area, priority, size) from the issue form and keywords, milestone, duplicate hint, a short brief and, for Q&A, an answer limited to allowed links
Moderation community.yml Same events Spam, abuse, off-topic and low-quality patterns; hides or labels (moderation:review) and escalates; never closes or deletes
PR check pr-check.yml PR opened or updated (pull_request_target, no checkout of PR code) Size, type and risk labels, a needs-issue check, one sticky checklist comment
Privacy scan privacy-scan.yml PRs, pushes to dev and main; also applied to new issue and comment text gitleaks plus rules for home paths, emails and session ids; private names come from a repository secret, never from a file
Roadmap manager roadmap.yml Board events, every 6 hours, weekly Syncs the project board, marks issues closed by PRs merged into dev as Done, flags stale items, opens one issue per code-scanning, Dependabot or secret-scanning alert, and posts a weekly digest with the automation mistake rate
Dependency updates dependabot-merge.yml Dependabot PRs into dev Patch and minor bumps merge once every other check is green; a major bump gets review:major-bump and one comment, never a merge
Stale stale.yml Daily Labels inactive items; exempts priority:P0 and P1; never closes

Model chain

Claude (primary token) → Claude (secondary token) → Copilot CLI → rules only

ai-model.yml is the reusable step. A slot is skipped when its secret is empty, and the chain moves on when a slot fails or hits a limit. If every slot is out, the caller applies its rules-only result. The job holds a read token only, tools are none or read-only, and the reply is schema-checked again before use.

Job Claude alias Copilot model
moderate, explain haiku haiku-class
brief, qa-answer, pr-summary, docs-inspector, digest sonnet sonnet-class
default opus opus-class

Tip

Models are chosen per job in model.models of the config file, by alias, never a pinned version. Change the file, not the workflow. The repository variables AI_PROVIDER (chain, none for rules only) and AI_DAILY_CAP (default 50) bound usage.

Rules that never bend

Warning

  • Automation may detect and report. It never deletes content or accounts, and never writes a flag that triggers a deletion elsewhere.
  • Alert kinds carry no per-subject identifier, so counts aggregate.
  • Untrusted text is fenced inside the prompt and the reply may only choose enum values; sanitized, capped text is the only free text used.

See also: Development workflow, Release runbook, docs/REPO-PIPELINES.md.

Home

🗺️ How it works

🛠️ How we work

📄 Templates

🔗 Elsewhere

Clone this wiki locally