Repository navigation
docs(adr): propose ADR-0006 PR-comment delivery and App permission evolution - #414
Conversation
|
CHANGES REQUESTED for exact head The proposed ADR draws the right boundaries for this feature: it limits the ADR 0003 supersession to permissions/events/comment delivery, excludes Two document fixes are needed before this head lands:
The document cites earlier owner delegation as background, but that citation does not establish owner acceptance of this proposed ADR or the future live App permission update; the Activation section correctly keeps both as separate gates. A changed head needs another review. |
|
APPROVE this proposed ADR document at exact head The substantive scope from my prior review is unchanged: this document narrowly proposes superseding ADR 0003's permission set, event list and rare-comment clause for the PR-comment feature; it excludes |
What
ADR-0006, the explicit superseding decision reviewer-2 required on #406 before any activation of the PR-comment delivery path. Status Proposed — acceptance is owner-gated (Activation section).
It supersedes only the permission set, event list and "rare PR comments" clauses of ADR 0003 for this feature. Everything else in ADR 0003 stands; ADR 0004 is untouched; ADR 0005's rollout conditions are unchanged.
Decisions carried
contents: write,issues: write,issue_comment) as the opt-in change ADR 0003 anticipated. Noactions: write.contents: read+checks: write; webhook lookup narrowing; narrow dispatch token; comment editorissues: writeonly; no ambientcontext.octokiton untrusted-input paths).Also fixes the stale ADR index (0005 was never listed; both entries added in the second commit).
Refs: #406 (gated manifest delta), #411 (token narrowing hardening), #326 (credential split), reviewer-2 gate review on #406 (2026-09-26).