You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Jul 23, 2026. It is now read-only.
Repository navigation
This repository was archived by the owner on Jul 23, 2026. It is now read-only.
Configurable push range base (stop hardcoding origin/main..HEAD for trust-root scan) #28
Parent
Part of Phase A in #25.
Problem
Trust-root push denylist enumerates the push range via something equivalent to:
Effects:
main, or whose upstream is notorigin/main, fail closed (or miss the intended range).Fail-closed on unresolvable range is correct for security hygiene; the bug is the base is not configurable.
Goals
Configurable range base with a clear precedence, e.g.:
AGENTIC_GIT_*+ legacy if needed)@{upstream}/ tracking)origin/mainfor back-compat or a documented fail-closed message that tells the user how to set the baseKeep fail-closed if the range cannot be computed after applying config.
Do not weaken basename trust-root matching (
.config-integrity-key,policy.toml,fleet.yaml,*.jsonl).Proposed surface (bikeshed in PR)
policy.toml: e.g.push_range_base = "origin/main"or"upstream"AGENTIC_GIT_PUSH_RANGE_BASEAcceptance
origin/master(or custom default) can pass trust-root scan when configuredorigin/mainupdated or given explicit fixture baseNon-goals