Skip to content

governance: establish and verify a qualifying independent PR approval path #1371

Description

@seonghobae

Control-plane gap

Naruon's effective live default-branch merge contract requires a qualifying non-author approval, and the repository writer still cannot prove a durable independent human review path from current observable repository state.

Fresh control-plane evidence on 2026-09-01 against protected develop@042b0c70531b229af3acbd0421a2f23098d848b3:

  • repository ruleset 17214772 (Lock default branch) requires 1 approving review, dismisses stale reviews on push, requires approval after the last push, requires review-thread resolution, and requires strict exact-head statuses opencode-review, trivy-fs, osv-scan, dependency-review, backend (Python 3.14), and frontend; it exposes no bypass actor;
  • repository ruleset 15586698 (PR) requires zero approvals by itself but still requires stale-review dismissal, review-thread resolution, and the same strict status set;
  • inherited organization ruleset 18156473 (CWL Central required workflows) requires 1 approving review and review-thread resolution and requires the current central workflow set. It currently has require_last_push_approval=false; the effective last-push approval requirement nevertheless remains because repository ruleset 17214772 requires it;
  • no active rule above currently requires CODEOWNER review;
  • protected current .github/CODEOWNERS is still * @seonghobae;
  • the GitHub integration available to this writer cannot enumerate the complete current collaborator/team inventory through its exposed repository tools, so the older 2026-08-17 collaborator observation must not be treated as fresh proof that no other eligible human exists;
  • model/bot comments, check/status conclusions, author actions, dismissed reviews, predecessor-head reviews, and self-approval are not qualifying independent approval evidence.

This is a governance-verifiability and availability defect, not authorization to weaken protection or use an administrative bypass.

Required governance action

Establish or expose a verifiable existing durable independent human approval route that GitHub can count under the live rules while preserving segregation of duties. Acceptable paths include:

  1. grant an appropriate human organization member/collaborator the minimum repository access required to submit counted PR reviews; or
  2. configure an existing human review team with repository access and expose enough repository/team metadata to the installed automation integration to verify eligibility rather than guess it.

If a qualifying human path already exists, no protection change is required: provide verifiable collaborator/team evidence and prove it on a bounded test PR.

Do not reduce required review counts, disable stale-review dismissal or last-push approval, grant a model/bot identity human-review authority merely to make it count, self-approve through another identity, invent a reviewer/team, or use an admin bypass. The inherited organization ruleset currently exposes an OrganizationAdmin bypass mode, but this Naruon writer is explicitly prohibited from relying on it; repository ruleset 17214772 also exposes no bypass route.

Acceptance evidence

  • Fresh collaborator/team inventory proves at least one eligible independent human reviewer in addition to the PR author, or an equivalent GitHub-verifiable review-team route.
  • A bounded test PR proves GitHub accepts a formal APPROVED review from that reviewer on the exact post-last-push head.
  • The approval is visible as a formal review submission, not a comment, status, check, reaction, model judgment, dismissed review, or author action.
  • Existing exact-head CI/security/coverage/package/provenance/thread-resolution/required-workflow gates remain unchanged and fail closed.
  • An otherwise gate-clean PR can merge through the normal protected path without admin bypass.

Why this remains open

The repository writer can verify the one-approval requirement and the current CODEOWNERS file, but it cannot currently enumerate enough live collaborator/team authority to prove that an eligible independent human route exists. Close only when the route is positively verified and exercised; do not close merely because a model reviewer comments or because administrative bypass is technically available.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions