Skip to content

#1026 Name the side effects an approval ask authorizes - #1029

Merged
williamthorsen merged 2 commits into
mainfrom
1026
Jul 18, 2026
Merged

#1026 Name the side effects an approval ask authorizes#1029
williamthorsen merged 2 commits into
mainfrom
1026

Conversation

@williamthorsen

Copy link
Copy Markdown
Owner

What

Fixes an issue where merging a pull request that also deleted the remote branch required a separate approval just for that deletion. Agents are now instructed to include the branch deletion in the approval they request for a merge, so that a single approval covers both. More broadly, any request for approval must now name the consequential, hard-to-reverse side effects it authorizes, such as force-pushing or closing an issue.

Why

Merging a pull request with the default branch-deletion behavior forced a redundant second authorization every time: the approval request named only the merge, so the deletion that followed was never covered. Nothing in the guidance required an approval to name the side effects it authorizes, so the same gap could reappear in any future destructive gate.

Details

🎉 Features

  • The action-items doctrine now states that an approval ask must name the consequential, hard-to-reverse side effects it authorizes — deleting a branch, force-pushing, closing an issue — because consent, from a human or from a permission auto-classifier, extends only to what the ask text names. Future destructive approval gates inherit the requirement. The rule lands with the existing "name the concrete action" guidance in the on-demand doctrine, not in the render contract carried inline by every skill, so it adds no per-invocation cost.

🐛 Bug fixes

  • The merge-pr approval gate now renders its confirmation from the resolved deletion strategy, naming the branch it will delete: the specific remote branch for remote, the local and remote branch for both, and no deletion clause for none. The head branch name is captured alongside the other PR metadata so the ask can reference it. Previously the deletion appeared only in a Delete: metadata line, which the permission auto-classifier does not read — so it withheld authorization for the downstream deletion and forced a second approval on every merge.

Closes #1026

Fixes an issue where merging a pull request that deletes the remote branch required a second authorization: the approval ask named only the merge, while the deletion appeared only in a metadata line the permission auto-classifier does not read. The ask now names the branch deletion it authorizes, so a single merge approval also covers the deletion.
Asks that authorize a consequential, hard-to-reverse side effect — deleting a remote branch, force-pushing, closing an issue — must now name that side effect in the ask text, not only in metadata shown beside it. Consent extends only to what an ask names, for a human reader and equally for a permission auto-classifier that reads the ask text alone, so a side effect present only in adjacent metadata is left unauthorized.
@github-actions

Copy link
Copy Markdown

Dependency audit

Production dependency audit passed.

@williamthorsen williamthorsen self-assigned this Jul 18, 2026
@williamthorsen
williamthorsen marked this pull request as ready for review July 18, 2026 21:05
@williamthorsen
williamthorsen merged commit f3fc9c9 into main Jul 18, 2026
3 checks passed
@williamthorsen
williamthorsen deleted the 1026 branch July 18, 2026 21:13
williamthorsen added a commit that referenced this pull request Aug 4, 2026
…e-v0.2.2 codeassembly-v0.4.0 factory-v0.2.2 codeassembly-mcp-v0.2.2

codeassembly-v0.4.0
- #1153 feat: Make codeassembly and kb CLI tools publishable (#1164)
- #1091 fix: Anchor a project-deployed link where its target deploys (#1159)
- #1156 refactor: Rename packages to publishable names (#1157)
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- refactor: Refine typescript-preferences
- #1150 fix: State doc-description form and make comment mood opt-in (#1151)
- deps: Upgrade first-party linting deps to latest version
- #1137 feat: Establish personal rulebooks for code layout and TypeScript preferences (#1144)
- #1126 feat: Check a package's own guidance content before it ships (#1138)
- refactor: Fix lint
- tooling: Remove redundant lint rules
- #1133 fix: Reject an anchor link that names no heading (#1135)
- #1122 feat: Capture lede decisions as an accumulating corpus (#1132)
- #1125 feat: Honor invocation tokens in rulebook bodies (#1129)
- #1107 feat: Render rulebook links and path tokens per harness (#1124)
- #1115 feat: Sync guidance at build and install so an upgrade cannot leave it stale (#1123)
- #1114 feat: Adopt a dependency's guidance by naming the package (#1121)
- #1088 feat: Deliver project ambient rulebooks per harness (#1113)
- #1087 refactor: Rename the authoring rulebook and mark its enforced rules (#1092)
- #1095 tooling: Move compilation out of the install lifecycle into a bootstrap step (#1102)
- #1094 refactor: Remove the ambient ripgrep dependency from the test suite (#1097)
- deps: Upgrade all deps to latest version
- tooling: Upgrade all deps to latest version & modernize configs
- refactor: Fix lint
- #1077 feat: Show the proposed edit above post-review menu options (#1078)
- #1068 feat: Deliver ambient rulebooks mechanically, retiring GLOBAL.md (#1075)
- #1069 feat: Add a no-second-person rule to the lede-voice doctrine (#1070)
- #1050 feat: Add a redundancy rule to the lede-voice doctrine (#1058)
- #1035 internal: Add lifecycle workspace with the canonical envelope, vocabulary & lane fold (#1049)
- #1006 internal: Extend lifecycle-event instrumentation to five high-traffic skills (#1034)
- #1028 feat: Rule out absence-of-removed-code tests (#1032)
- #114 feat: Let reviewers emit gated insights into review artifacts (#1031)
- #1027 internal: Retire input.received and redundant skill.progress emits (#1030)
- #1026 fix: Name the side effects an approval ask authorizes (#1029)
- #1022 fix: Normalize action and question label identifiers across asks blocks (#1025)

factory-v0.2.2
- #1156 refactor: Rename packages to publishable names (#1157)
- deps: Upgrade all deps to latest version
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- tooling: Remove redundant lint rules
- deps: Upgrade deps to latest version
- deps: Upgrade all deps to latest version
- deps: Upgrade all deps to latest version
- tooling: Upgrade all deps to latest version & modernize configs
- refactor: Fix lint
- deps: Upgrade all deps to latest version

kb-v0.3.0
- #1153 feat: Make codeassembly and kb CLI tools publishable (#1164)
- #1156 refactor: Rename packages to publishable names (#1157)
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- tooling: Remove redundant lint rules
- #1095 tooling: Move compilation out of the install lifecycle into a bootstrap step (#1102)
- tooling: Upgrade all deps to latest version & modernize configs
- refactor: Fix lint

codeassembly-lifecycle-v0.2.0
- #1153 feat: Make codeassembly and kb CLI tools publishable (#1164)
- #1156 refactor: Rename packages to publishable names (#1157)
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- tooling: Remove redundant lint rules
- #1095 tooling: Move compilation out of the install lifecycle into a bootstrap step (#1102)
- tooling: Upgrade all deps to latest version & modernize configs
- #1038 feat: Add the read-only git adapter for worktree and base-branch ground truth (#1059)
- #1051 feat: Bound fold memory and rescan cost with a retention window (#1057)
- #1035 internal: Add lifecycle workspace with the canonical envelope, vocabulary & lane fold (#1049)

codeassembly-mcp-v0.2.2
- deps: Upgrade all deps to latest version
- #1156 refactor: Rename packages to publishable names (#1157)
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- #1095 tooling: Move compilation out of the install lifecycle into a bootstrap step (#1102)
- tooling: Upgrade all deps to latest version & modernize configs
- refactor: Fix lint

codeassembly-run-core-v0.2.2
- #1156 refactor: Rename packages to publishable names (#1157)
- #1152 tooling: Run every test in the default gate, classified by what it reaches (#1155)
- #1110 tooling: Migrate Vitest to nmr's centralized model (#1154)
- #1095 tooling: Move compilation out of the install lifecycle into a bootstrap step (#1102)
- tooling: Upgrade all deps to latest version & modernize configs
- refactor: Fix lint
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remote branch deletion is blocked by Claude's auto-classifier on merge

1 participant