mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 06:53:14 +00:00
|
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* feat(reviewer): explicit-request verdicts + shell verdict guard Mention-triggered reviews that explicitly ask for a verdict now submit a real APPROVE/REQUEST_CHANGES through publish_review; auto-reviews stay advisory (COMMENT). Authorization is enforced in code: publish_review honors a verdict only when the dispatching webhook set verdict_requested, which only the explicit-mention path does. - request_pr_review gains instructions (forwarded verbatim into an escaped requester_instructions data block) and request_verdict - self-review guard downgrades verdicts on Open SWE-authored PRs; stale APPROVEs are best-effort dismissed when later findings land - new PullRequestVerdictGuardMiddleware blocks gh pr review --approve/-a/--request-changes/-r, gh api, and curl verdict fallbacks on both the coding-agent and reviewer graphs - shared escape helper moved to agent/utils/prompt_data.py * fix(reviewer): harden verdict path against security-review findings Adversarial security review (detector fan-out + proof-or-kill verifier) of the verdict feature surfaced several verdict-integrity gaps; resolve the confirmed ones: - head-drift (high): a mid-run push moves the resolved head, so an APPROVE could anchor to an unreviewed commit. Downgrade any verdict to a comment when the resolved head differs from the reviewed head (verdict_ignored reason head_moved); the push's own re-review submits a fresh verdict. - self-review fail-open: downgrade to comment when the PR author cannot be confirmed (author_unknown), and compare bot logins case-insensitively. - verdict_submitted now reflects GitHub's returned review state, not just the event we asked for, so a coerced APPROVE isn't reported as submitted. - an authorized verdict whose findings all anchor outside the diff now posts as a bodied review with zero inline comments instead of failing. - add finding_reply to the shared data-block escape tag superset. |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| add_finding.py | ||
| confluence_comment.py | ||
| confluence_create_page.py | ||
| confluence_get_page.py | ||
| confluence_search.py | ||
| confluence_update_page.py | ||
| enter_plan_mode.py | ||
| fetch_url.py | ||
| http_request.py | ||
| jira_comment.py | ||
| jira_create_issue.py | ||
| jira_get_issue.py | ||
| jira_get_issue_comments.py | ||
| jira_list_projects.py | ||
| jira_update_issue.py | ||
| linear_comment.py | ||
| linear_create_issue.py | ||
| linear_delete_issue.py | ||
| linear_get_issue.py | ||
| linear_get_issue_comments.py | ||
| linear_list_teams.py | ||
| linear_search_issues.py | ||
| linear_update_issue.py | ||
| list_findings.py | ||
| list_review_findings.py | ||
| open_pull_request.py | ||
| publish_review.py | ||
| read_finding_outcomes.py | ||
| read_repo_file.py | ||
| reply_to_finding_thread.py | ||
| report_platform_issue.py | ||
| request_pr_review.py | ||
| resolve_finding_thread.py | ||
| save_plan.py | ||
| save_review_style.py | ||
| schedule_thread_wakeup.py | ||
| search_repo_code.py | ||
| slack_add_reaction.py | ||
| slack_read_thread_messages.py | ||
| slack_start_new_thread.py | ||
| slack_thread_reply.py | ||
| update_finding.py | ||
| web_search.py | ||