Reworked per GPT-4.1 cross-family review BLOCK. The original PR removed the agent-apply GitHub Environment (the live required-reviewer human gate) and replaced it with a Slack notice that FAILS OPEN when its webhook secret is absent (which it is) plus an audit-log line. The cross-review correctly flagged this as trading a preventive control for detective controls, one of which silently no-ops. This commit: - Restores environment: agent-apply on gate-and-pr (the human approval pause). - Drops the fail-open Slack notify step. - Keeps the unconditional audit-log step as an additive detective control. - Restores the MANDATORY-INVARIANT assertion (env must be present) and adds an assertion that the audit step is retained. WS3's auto-dispatch (dispatch_invoker.py + graph/coordinator wiring) is unchanged: it fires workflow_dispatch, which now pauses at the restored gate for human approval — auto-dispatch up to the approval, then one click. |
||
|---|---|---|
| .. | ||
| sim | ||
| __init__.py | ||
| conftest.py | ||
| test_apply_verify_workflow_hardening.py | ||
| test_billing.py | ||
| test_build_verify_subgraph.py | ||
| test_builders.py | ||
| test_builders_llm.py | ||
| test_checker_intake.py | ||
| test_ci_fetcher.py | ||
| test_ci_gate.py | ||
| test_ci_gate_workflow.py | ||
| test_clarifier.py | ||
| test_clarifier_llm.py | ||
| test_claude_code_adapter.py | ||
| test_claude_code_live.py | ||
| test_coordinator.py | ||
| test_deadline_timer.py | ||
| test_dispatcher.py | ||
| test_fixer.py | ||
| test_github_adapter.py | ||
| test_github_intake.py | ||
| test_github_live.py | ||
| test_graph.py | ||
| test_invoker.py | ||
| test_ledger.py | ||
| test_operator_cli.py | ||
| test_planner.py | ||
| test_recovery.py | ||
| test_responder.py | ||
| test_resume_worker.py | ||
| test_review_loop.py | ||
| test_review_loop_llm.py | ||
| test_run_team.py | ||
| test_schema.py | ||
| test_slack_adapter.py | ||
| test_slack_listener.py | ||
| test_slack_live.py | ||
| test_state_store.py | ||
| test_task_model.py | ||
| test_transport_base.py | ||
| test_verifier.py | ||
| test_verifier_llm.py | ||
| test_ws3_dispatch_invoker.py | ||