This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/.github/workflows
Adam Moussa a705859ea3 Use the approved plan title as a conventional PR title
The apply pipeline's draft PRs were titled `agent-apply: <task_id>
(diff <hash>)` with a flat body — neither within Sea Haven PR
conventions. That format was deliberate injection-hardening (only
sanitized tokens, never model free-text; §4.6).

Thread the approved plan's title through dispatch as an optional
`pr_title` input, sanitized box-side (single line, no control chars,
70-char cap, capitalized) and RE-VALIDATED in the workflow as defense-
in-depth, with the hardened `agent-apply: <task_id>` title as the
fallback when empty/unsafe. Provenance (task id, diff hash, head) moves
to the PR body. gh consumes both as argv data, never shell-interpolated.
2026-06-25 13:43:30 -04:00
..
agent-team-apply-verify.yml Use the approved plan title as a conventional PR title 2026-06-25 13:43:30 -04:00
ci-web.yaml ci(agent-team): add web frontend CI via org reusable workflow 2026-06-24 18:42:34 -04:00
ci.yaml ci: add workflow permissions from GHAS notes 2026-06-17 17:56:32 -04:00
dependency-review.yml ci: add workflow permissions from GHAS notes 2026-06-17 17:56:32 -04:00
labeler.yml Adopt org CI conventions: thin wrappers over reusable workflows + dependabot 2026-06-17 17:28:55 -04:00