feat(labels): add gated apply-mode pilot#425
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR extends the existing label audit tooling by adding a tightly gated --apply / --confirm-apply pilot mode to create/update canonical labels only, while keeping default behavior read-only and documenting the operational guardrails.
Changes:
- Add gated apply-preview and confirmed-apply modes to
scripts/labels-dry-run.rb, including pilot allowlist enforcement and JSON/Markdown mode metadata. - Add a shell smoke-test harness to validate refusal paths and
apply-previewJSON output. - Update the labels runbook to document the apply-mode pilot constraints and example commands.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
scripts/test-labels-dry-run.sh |
Adds a smoke-test script covering refusal paths and apply-preview JSON mode. |
scripts/labels-dry-run.rb |
Introduces apply-preview/confirmed apply support with pilot guardrails and planned operations output. |
runbooks/labels.md |
Documents apply-mode pilot guardrails and provides preview/confirmed command examples. |
6b77dc4 to
8f0de09
Compare
Contributor
|
Just as a heads up, I was blocked by some firewall rules while working on your feedback. Expand below for details. Warning Firewall rules blocked me from connecting to one or more addresses (expand for details)I tried to connect to the following addresses, but was blocked by firewall rules:
If you need me to access, download, or install something from one of these locations, you can either:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
--apply/--confirm-applymode for canonical label create/update operationsSafety model
Default behavior remains read-only.
Confirmed apply is intentionally constrained:
--repovalues--all-repos --apply--confirm-apply--allow-non-pilot-repois explicitly passed after maintainer approvalTest Plan
ruby -c scripts/labels-dry-run.rbscripts/test-labels-dry-run.shscripts/labels-dry-run.rb --repo z-shell/.github --include-cleanscripts/labels-dry-run.rb --repo z-shell/.github --json | ruby -rjson -e 'data=JSON.parse($stdin.read); abort unless data["mode"]=="dry-run"; abort unless data["repos_scanned"]==1'scripts/labels-dry-run.rb --repo z-shell/.github --apply --include-cleanscripts/labels-dry-run.rb --repo z-shell/.github --apply --json | ruby -rjson -e 'data=JSON.parse($stdin.read); abort unless data["mode"]=="apply-preview"; abort if data["confirmed"]'scripts/labels-dry-run.rb --repo z-shell/zi --apply --json--all-repos --apply--all-repos --apply --confirm-apply--repo z-shell/zi --apply --confirm-apply--repo z-shell/.github --confirm-applyRefs #411.