Skip to content

Recognize maintainer authorization - #14438

Merged
williammartin merged 3 commits into
trunkfrom
williammartin-maintainer-authorization
Sep 14, 2026
Merged

williammartin merged 3 commits into
trunkfrom
williammartin-maintainer-authorization

Conversation

@williammartin

@williammartin williammartin commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Description

The repository guidance currently says maintainer authorization must come from trusted context, but it does not identify authenticated repository permission as sufficient evidence. This clarifies that agents should check trusted context before applying the external-contributor gate and that an authenticated GitHub identity with at least write permission on cli/cli authorizes work requested by that user.

How did you test this change?

I ran git diff --check trunk...HEAD and saw no whitespace errors. I inspected git diff --name-status trunk...HEAD and saw that only AGENTS.md is modified, then reviewed the complete diff.

Key points

This treats authenticated permission of at least write as sufficient authorization because cli/cli grants that access to trusted maintainers, while retaining the existing trusted-context requirement for all other cases.

Notes for reviewers

Review the external contribution gate in AGENTS.md, especially the new permission-based authorization wording.

Authorship and follow-up

Who wrote this:

  • A human wrote it.
  • An agent wrote it under close human direction.
  • An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

  • @williammartin will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted.
  • Nobody has explicitly committed to replying.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 14, 2026 09:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Trusted maintainer authorization or eligible issue context has not been established.

Get a fresh assessment by requesting another Copilot review.

Review tier: Balanced (auto)
Findings: 1 Low severity

Note

Copilot is running an experiment and ran this review at Balanced.

Open findings (1)
What changed in this PR

Clarifies when maintainer permissions constitute trusted authorization.

Changes:

  • Recognizes authenticated maintain or admin permission.
  • Retains trusted-context requirements for other cases.
File Description
AGENTS.md Updates external-contribution authorization guidance.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread AGENTS.md
williammartin and others added 2 commits September 14, 2026 11:24
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@williammartin
williammartin marked this pull request as ready for review September 14, 2026 09:56
@williammartin
williammartin requested a review from a team as a code owner September 14, 2026 09:56
@williammartin
williammartin requested a review from niik September 14, 2026 09:56
@williammartin
williammartin merged commit 4595165 into trunk Sep 14, 2026
20 checks passed
@williammartin
williammartin deleted the williammartin-maintainer-authorization branch September 14, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants