Skip to content

Add GitHub self‑governance docs, CI, CODEOWNERS, role‑agent manifests, and Trust Authority tests - #13

Merged
blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-4vt514
Apr 17, 2026
Merged

blocksifrdev merged 2 commits into
mainfrom
codex/revise-ttp-integration-plan-for-agt-4vt514

Conversation

@blocksifrdev

Copy link
Copy Markdown
Collaborator

Motivation

  • Seed repository governance and release readiness for a public launch by adding CODEOWNERS, access/control docs, and a baseline CI job.
  • Introduce a reference design for applying TTP to GitHub workflows (self‑governance) so non‑human role‑agents can be runtime‑authorized and auditable.
  • Harden and extend the Trust Authority reference implementation with admin APIs and unit tests to validate aggregation semantics.

Description

  • Add global CODEOWNERS entries and a GitHub CI workflow (.github/workflows/ci.yml) to build/test the reference-implementations/trust-authority package on PRs and pushes.
  • Introduce a workflow skeleton ttp-governed-pr-action.yml that demonstrates calling a Runtime Authority Gate (POST /re/authorize) and enforcing decisions (PERMIT/CONSTRAIN/STEP_UP/ESCALATE/DENY).
  • Add a large suite of documentation and governance artifacts under docs/ (getting-started, operator-guide, public-readiness, repo-access-control, roadmap, ecosystem integrations, github-self-governance-reference-architecture, open-source-boundary, etc.), plus an RFC (rfcs/0001-github-self-governance-role-agents.md), policy (policy/github-self-governance-policy.yaml), API contract (runtime/api/re-authorize.contract.md), and execution receipt schema extension (spec/extensions/execution-receipt-v2.schema.json).
  • Add role agent manifests in agents/manifests/role-agents.yaml, examples (examples/github-app-self-governance.md), and mapping appendix (docs/scim-re-github-role-agent-mapping.md) to model AI role‑agents and protected actions.
  • Update project top-level docs and README to link new guides and split onboarding by audience.
  • Reference Trust Authority implementation changes: add jest.config.cjs, unit tests src/aggregation.test.ts, update package.json deps/devDeps, add tsconfig tweaks, and add helper files; implement GET /v1/admin/agents route and related store helpers (listAgents, getAgentReceiptsAcrossDomains) to support admin listing with optional metrics; and add small crypto compatibility fixes to use @noble/hashes sha512 usage (ed.etc.sha512Sync = (message) => sha512(message)).
  • Add policy and governance files (policy/github-self-governance-policy.yaml) and a reference execution-receipt schema to support auditable decisions.

Testing

  • Added unit tests for aggregation logic (reference-implementations/trust-authority/src/aggregation.test.ts) covering insufficient data, expected score bounds and contributing counts, and issuer weight cap behavior.
  • Configured CI to run npm install, npm run build, and npm test for the Trust Authority package via .github/workflows/ci.yml.
  • Ran the Trust Authority unit tests (npm test in reference-implementations/trust-authority) and the new aggregation tests completed successfully.

Codex Task

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5d9389c80

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +144 to +146
const prefix = `${agentId}:`
for (const [key, receipts] of this.receipts.entries()) {
if (key.startsWith(prefix)) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Match agent receipts by exact agent id

Using startsWith on the composite key can misattribute receipts when one agent ID is a prefix of another ID followed by : (for example, agent and agent:shadow). Since POST /v1/admin/agents does not restrict agent_id characters, GET /v1/admin/agents?include_metrics=true can return inflated counts/domains and leak another agent’s receipt metadata into the wrong entry. Parse the key or store receipts in a nested map keyed by agent_id to avoid prefix collisions.

Useful? React with 👍 / 👎.

@blocksifrdev
blocksifrdev merged commit 9e772c0 into main Apr 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant