Skip to content

Brokered gh lets a Team Workspace merge pull requests, although a named person always publishes from a Team Environment #20

Description

@immakermatty

Problem

On a hosted Team Environment, a named person always publishes and the agent never merges (root decision 0148, Team Environment addendum). The brokered gh adapter does not enforce this:

  • DENIED_COMMANDS in adapter/brokered-gh.mjs covers only auth, alias, config, extension and search;
  • gh pr merge is classified repository and runs with the write-tier token the broker mints for the Team's live grant.

Observed

In one Organization, the Team identity merged 13 pull requests in about a day (2026-10-04/05). They spanned the Organization root and several module and data repositories, and included pull requests authored by people. This happened before the Folder rule reached those Environments; none has been merged since.

The Organization's GitHub plan offers no branch protection for private repositories. Nothing else stopped the merges; two of them changed the Organization root repository, which every Environment of the Organization pulls.

Proposal

  • Deny gh pr merge, and the merge endpoints through gh api (PUT repos/{owner}/{repo}/pulls/{n}/merge, GraphQL mergePullRequest), in a Team Workspace. The message should name the hand-over: ask the Operator whom to ask, request that person's review, and assign the pull request to them.
  • State clearly that a direct git push to the default branch is still possible with a write-tier token; only branch rules on GitHub close that.

Source: v0.11.0 adapter/brokered-gh.mjs (classifyGhCommand).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions