Repository navigation
Add GitHub self‑governance docs, CI, CODEOWNERS, role‑agent manifests, and Trust Authority tests - #13
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5d9389c80
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const prefix = `${agentId}:` | ||
| for (const [key, receipts] of this.receipts.entries()) { | ||
| if (key.startsWith(prefix)) { |
There was a problem hiding this comment.
Match agent receipts by exact agent id
Using startsWith on the composite key can misattribute receipts when one agent ID is a prefix of another ID followed by : (for example, agent and agent:shadow). Since POST /v1/admin/agents does not restrict agent_id characters, GET /v1/admin/agents?include_metrics=true can return inflated counts/domains and leak another agent’s receipt metadata into the wrong entry. Parse the key or store receipts in a nested map keyed by agent_id to avoid prefix collisions.
Useful? React with 👍 / 👎.
Motivation
Description
CODEOWNERSentries and a GitHub CI workflow (.github/workflows/ci.yml) to build/test thereference-implementations/trust-authoritypackage on PRs and pushes.ttp-governed-pr-action.ymlthat demonstrates calling a Runtime Authority Gate (POST /re/authorize) and enforcing decisions (PERMIT/CONSTRAIN/STEP_UP/ESCALATE/DENY).docs/(getting-started, operator-guide, public-readiness, repo-access-control, roadmap, ecosystem integrations, github-self-governance-reference-architecture, open-source-boundary, etc.), plus an RFC (rfcs/0001-github-self-governance-role-agents.md), policy (policy/github-self-governance-policy.yaml), API contract (runtime/api/re-authorize.contract.md), and execution receipt schema extension (spec/extensions/execution-receipt-v2.schema.json).agents/manifests/role-agents.yaml, examples (examples/github-app-self-governance.md), and mapping appendix (docs/scim-re-github-role-agent-mapping.md) to model AI role‑agents and protected actions.jest.config.cjs, unit testssrc/aggregation.test.ts, updatepackage.jsondeps/devDeps, addtsconfigtweaks, and add helper files; implementGET /v1/admin/agentsroute and related store helpers (listAgents,getAgentReceiptsAcrossDomains) to support admin listing with optional metrics; and add small crypto compatibility fixes to use@noble/hashessha512 usage (ed.etc.sha512Sync = (message) => sha512(message)).policy/github-self-governance-policy.yaml) and a reference execution-receipt schema to support auditable decisions.Testing
reference-implementations/trust-authority/src/aggregation.test.ts) covering insufficient data, expected score bounds and contributing counts, and issuer weight cap behavior.npm install,npm run build, andnpm testfor the Trust Authority package via.github/workflows/ci.yml.npm testinreference-implementations/trust-authority) and the new aggregation tests completed successfully.Codex Task