mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
The head-tree fingerprint keeps the security win (approval binds to the exact workflow files and blob SHAs at the pushed head), but the guard was firing on every push because it no longer compared against a base. This change re-adds change detection using a base fetched from the authenticated remote at guard time: - Fetches the pushed branch from the remote; if it does not exist (new branch), fetches the remote's default branch via ls-remote and a fallback chain. - Compares the head workflow tree (ls-tree) against the freshly fetched base (FETCH_HEAD), not against any local refs/remotes/origin/* ref. - Returns None (no guard) when the workflow trees are identical, so code-only pushes to a branch that already contains workflow files are not blocked. - Updated test_non_workflow_push_runs_without_approval to use a non-empty-but unchanged workflow tree. Refs: 98 |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| check_message_queue.py | ||
| ensure_no_empty_msg.py | ||
| exclude_tools.py | ||
| model_fallback.py | ||
| notify_step_limit.py | ||
| plan_mode.py | ||
| refresh_github_proxy.py | ||
| refresh_slack_status.py | ||
| repair_orphaned_tool_calls.py | ||
| sandbox_circuit_breaker.py | ||
| sanitize_thinking_blocks.py | ||
| sanitize_tool_inputs.py | ||
| settle_review_check.py | ||
| tool_artifact.py | ||
| tool_error_handler.py | ||
| workflow_push_guard.py | ||