feat(python): implemented pull request vouching and gated review system

- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
This commit is contained in:
can1357
2026-06-19 03:14:43 +02:00
parent 71144825ec
commit aca5d5f48a
9 changed files with 491 additions and 18 deletions
+20
View File
@@ -110,6 +110,26 @@ ROBOMP_TASK_TIMEOUT_HARD_GRACE_SECONDS=60
ROBOMP_REQUEST_TIMEOUT_SECONDS=120
# =============================================================================
# --- PR review / vouch gate ---
# =============================================================================
# robomp reviews incoming contributor PRs. When PRs are gated by the vouch
# GitHub Action (.github/workflows/vouch-pr.yml), set the trigger to
# `vouched_label` so robomp reviews ONLY the PRs the gate let through (the
# workflow labels survivors with ROBOMP_VOUCH_REVIEW_LABEL) instead of racing
# the gate on PR open. Set ROBOMP_PR_REVIEW_ENABLED=false to disable robomp PR
# review entirely.
ROBOMP_PR_REVIEW_ENABLED=true
# open | vouched_label
ROBOMP_PR_REVIEW_TRIGGER=open
ROBOMP_VOUCH_REVIEW_LABEL=vouched
# In vouched_label mode only `labeled` events from this actor trigger review,
# so a manual triage/maintainer label cannot bypass the gate. Default matches
# the stock GITHUB_TOKEN actor; set to your App's bot login if the vouch
# workflow labels via a GitHub App token.
ROBOMP_VOUCH_REVIEW_LABELER=github-actions[bot]
# =============================================================================
# --- Per-submitter rate limiting ---
# =============================================================================