/implement from a comment: three jobs, two credentials

/implement from a comment: three jobs, two credentials A sequence diagram generated by Archify. /implement on #59 run on the default branch in-lockstep gate: 0 or 3 MEMBER, OWNER or CODEOWNERS; bots refused provision, doctor changeset, scorecard, history bundle after run implement/from-ticket --approved-by ai-generated issue on failure download to $RUNNER_TEMP draft pull request ChangeGuard runs again; the branch is run-scoped history --from-bundle --push implement/report comments on the ticket Authorize the asker Model job Write job A person · comments /implement · Sequence participant A person comments /implement GitHub · issue_comment · Sequence participant GitHub issue_comment gate job · no credential · Sequence participant gate job no credential implement job · provider key, contents: read · Sequence participant implement job provider key, contents: read Artifact · changeset + bundle · Sequence participant Artifact changeset + bundle propose job · write token, no provider · Sequence participant propose job write token, no provider Legend request return async trace default message

The asker, not the text

  • • The gate is a Python function with tests, run by a job holding nothing
  • • The issue body stays untrusted whoever asked

Never co-resident

  • • The job that talks to a model cannot write
  • • The job that writes has no provider extra installed