This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/.github/workflows
Adam Moussa b2684231b1 fix(ws3): keep agent-apply environment gate; drop fail-open Slack step
Reworked per GPT-4.1 cross-family review BLOCK. The original PR removed the
agent-apply GitHub Environment (the live required-reviewer human gate) and
replaced it with a Slack notice that FAILS OPEN when its webhook secret is
absent (which it is) plus an audit-log line. The cross-review correctly
flagged this as trading a preventive control for detective controls, one of
which silently no-ops.

This commit:
- Restores environment: agent-apply on gate-and-pr (the human approval pause).
- Drops the fail-open Slack notify step.
- Keeps the unconditional audit-log step as an additive detective control.
- Restores the MANDATORY-INVARIANT assertion (env must be present) and adds
  an assertion that the audit step is retained.

WS3's auto-dispatch (dispatch_invoker.py + graph/coordinator wiring) is
unchanged: it fires workflow_dispatch, which now pauses at the restored gate
for human approval — auto-dispatch up to the approval, then one click.
2026-06-23 12:17:19 -04:00
..
agent-team-apply-verify.yml fix(ws3): keep agent-apply environment gate; drop fail-open Slack step 2026-06-23 12:17:19 -04:00
ci.yaml ci: add workflow permissions from GHAS notes 2026-06-17 17:56:32 -04:00
dependency-review.yml ci: add workflow permissions from GHAS notes 2026-06-17 17:56:32 -04:00
labeler.yml Adopt org CI conventions: thin wrappers over reusable workflows + dependabot 2026-06-17 17:28:55 -04:00