-
Notifications
You must be signed in to change notification settings - Fork 0
OpenCode: expose cross-repository review failure when App status publication is forbidden #691
Copy link
Copy link
Open
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestNew feature or requestpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behaviortype: featureNew or expanded product capabilityNew or expanded product capability
Description
Activity
Metadata
Metadata
Assignees
Labels
area: apiAPI, protocol, event, or external contractAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestNew feature or requestpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behaviortype: featureNew or expanded product capabilityNew or expanded product capability
Type
Projects
- StatusShow more project fieldsIn Progress
Problem
Central OpenCode repository_dispatch can fail closed without leaving any exact-head evidence on the target pull request when the exchanged OpenCode App token can write reviews but cannot write commit statuses.
Current-head evidence:
Governance classification
High-sensitivity review-governance observability and token-capability defect. It is not a source vulnerability and must not turn provider unavailability into a false clean review.
Acceptance criteria
Related