v1.7.1
Agent runs in your repository, in a sandbox, under their own GitHub App
v1.7.1 is an agent-run release. There is no new surface to click on; the work is in how a run executes, who it acts as, and what it is allowed to touch.
Runs authenticate with GitHub's OIDC token
An agent run for owner/repo is now a workflow run in owner/repo. sigit.si dispatches the
agent workflow there and the job calls back with the OIDC token GitHub signs for it. The runner
API validates the OIDC token against the run before serving the request.
This replaces the shared secret, which could not be given to a consumer repository and which let
one job speak for any run. sigit.si no longer hands the job a repository credential either: the
job uses its own GITHUB_TOKEN. The pull request is still opened from sigit.si.
The agent runs in a sandbox
The job script now treats the agent, and the working copy it leaves behind, as untrusted. The
agent runs in an isolated sandbox, separated from the script's processes and environment,
the runner's files, and the GITHUB_TOKEN. The sandbox is terminated with the job, so cancel,
timeout and a lost runner leave nothing running.
The push used to run git in the agent's working copy with the credential in the environment, where a hook or a config entry the agent wrote would have run with it. The agent's commits now leave the sandbox as a bundle, are fetched into a repository the script created, and are pushed from there. A run is also capped at a maximum number of commits; past the cap the run is reported as failed and the push is skipped.
A dedicated GitHub App for agent runs
Runs now act through a second GitHub App, with its own credentials, webhook secret and installations, so nothing the agent does touches the review App. Webhooks pick the App from the delivery's installation target and verify with that App's secret, and the review App starts runs only while the agent App is not configured, so one mention still triggers once.
A GitHub App cannot be mentioned, so each App has a paired account of the same name that people write as the handle. The setup page after installing now asks you to add that account to the repository (Read is enough) so GitHub suggests and links it, and a Mention access page in Settings checks each private repository and links to the access settings for the ones still missing it. A recurring job signs in as each mention account and accepts its pending repository and organization invitations. There is a read-only admin page listing what is still pending.
The corresponding bot names are reserved on the forge.
Release masters: @setoelkahfi and @sigit.