feat(python): implemented pull request vouching and gated review system

- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
This commit is contained in:
can1357
2026-06-19 03:14:43 +02:00
parent 71144825ec
commit aca5d5f48a
9 changed files with 491 additions and 18 deletions
+10
View File
@@ -44,6 +44,16 @@ services:
ROBOMP_MAINTAINER_LOGINS: ${ROBOMP_MAINTAINER_LOGINS:-}
ROBOMP_REVIEWER_BOTS: ${ROBOMP_REVIEWER_BOTS:-}
# --- PR review / vouch gate ---
# When PRs are gated by the vouch GitHub Action, set the trigger to
# `vouched_label` so robomp reviews ONLY PRs that survive the gate
# (the workflow labels survivors `ROBOMP_VOUCH_REVIEW_LABEL`), instead
# of racing the gate on PR open. `vouched_label` keeps review ENABLED.
ROBOMP_PR_REVIEW_ENABLED: ${ROBOMP_PR_REVIEW_ENABLED:-true}
ROBOMP_PR_REVIEW_TRIGGER: ${ROBOMP_PR_REVIEW_TRIGGER:-open}
ROBOMP_VOUCH_REVIEW_LABEL: ${ROBOMP_VOUCH_REVIEW_LABEL:-vouched}
ROBOMP_VOUCH_REVIEW_LABELER: ${ROBOMP_VOUCH_REVIEW_LABELER:-github-actions[bot]}
# --- model selection ---
ROBOMP_MODEL: ${ROBOMP_MODEL:-anthropic/claude-sonnet-4-6}
ROBOMP_PROVIDER: ${ROBOMP_PROVIDER:-}