Skip to content

chore(loop): attribute loop commits to github-actions[bot] - #57

Merged
Alex1990 merged 1 commit into
mainfrom
loop/56-git-identity
Sep 17, 2026
Merged

Alex1990 merged 1 commit into
mainfrom
loop/56-git-identity

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Closes #56

loop-task: #56

Why

agentEnv() injected tiny-oss loop <loop@users.noreply.github.com> as the commit identity under auto. That address belongs to the real, unrelated GitHub user @loop (id 1519971), so every loop commit was falsely attributed to a stranger — 8ec1b1e (PR #50, the instance the title cites) and 4d2735a/35c7312 (PR #55, the commit the body cites). Issue #52 reported the same defect but was routed to the human inbox before the norms made host changes loop work; #56 is the re-report.

What

  • scripts/loop/shared/agent.mjs — agentEnv() now sets GIT_AUTHOR_* / GIT_COMMITTER_* to GitHub Actions' own bot: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>. That is the same identity the host's PR is authored by (the job token opens it), and a bot noreply address is not a user account, so it cannot be squatted the way a bare login can.
  • scripts/loop/README.md — the git identity row in the "What the loop relies on" table documents the new identity and why the old one was wrong.

The commit itself was made with the corrected identity, so it already demonstrates the fix. Commit type is chore(loop) per AGENTS.md — host maintenance a consumer cannot observe, so it must not use fix/feat or enter CHANGELOG.md.

Only future commits change: 8ec1b1e and 4d2735a/35c7312 are already on main, and re-attributing history would need a force-push the Main branch ruleset forbids.

Verification

  • node probe of agentEnv(): auto yields the bot identity for author and committer, report sets neither, an explicit GIT_AUTHOR_EMAIL is still respected, and the R2 keys remain stripped.
  • gh api 'users/github-actions%5Bbot%5D' → {"id":41898282,"login":"github-actions[bot]","type":"Bot"}; gh api users/loop → real User id 1519971.
  • pnpm lint — 0 errors (39 pre-existing warnings).
  • pnpm fmt:check — all files formatted.
  • pnpm build — exit 0 (all entries + .d.ts).
  • pnpm check:types — exit 0.
  • pnpm test:azure-oracle — all checks passed.
  • pnpm exec vitest run --browser.headless with pnpm serve — 22 files passed, 231 passed / 26 skipped (integration specs skip without credentials).

Review

Two-lens review (correctness/regression and standards/safety) found no L1/L2 problems; the independent pr-review stage re-checks the diff.

agentEnv() injected 'tiny-oss loop <loop@users.noreply.github.com>' as the
git identity under auto. That address belongs to the real, unrelated GitHub
user @loop (id 1519971), so every loop commit - 8ec1b1e (PR #50) and
4d2735a/35c7312 (PR #55) - was falsely attributed to a stranger (#52, #56).

Use GitHub Actions' own bot instead, the same identity the host's PR is
authored by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>.
A bot noreply address is not a user account, so it cannot be squatted.

Only future commits change; the historical ones stay as they are.
@github-actions
github-actions Bot requested a review from Alex1990 as a code owner September 17, 2026 15:57
@github-actions

Copy link
Copy Markdown
Contributor Author

Coverage

Metric % Covered / Total
Lines 90.19% 1003/1112
Statements 89.06% 1083/1216
Functions 91.03% 193/212
Branches 76.43% 519/679

@github-actions

Copy link
Copy Markdown
Contributor Author

Loop pr-review — approve ✅

Independent check of the diff (scripts/loop/shared/agent.mjs, scripts/loop/README.md), separately from the feature (maker) run:

  • Correctness/regression — agentEnv('auto') now injects github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>. The defect is confirmed on both sides: gh api users/loop → real User id 1519971, and the cited commits 8ec1b1e/4d2735a/35c7312 all resolve to that account; gh api 'users/github-actions%5Bbot%5D' → Bot id 41898282, and this PR's own commit 66bf8fa is already attributed to it. A node probe confirms author and committer are set under auto, neither under report, an explicit GIT_AUTHOR_EMAIL is still respected, and the R2 keys stay stripped. The workflow/host never set GIT_AUTHOR_*, so the injected identity is what reaches git.
  • Standards/safety — chore(loop) is the right type per AGENTS.md (host maintenance a consumer cannot observe, so no fix/feat and no changelog). No src/, signer, dependency or workflow file is touched, so signatures and tree-shaking are unaffected. Host changes (scripts/loop/**) are explicitly loop-permitted and owner-reviewed; no secrets. require_extra_approval_for_unattributed_changes is documented as Copilot-scoped, and the PR author was already github-actions[bot], so this change adds no new merge gate.

Gates re-run from this checkout: pnpm lint 0 errors (39 pre-existing warnings), pnpm fmt:check clean, pnpm build + pnpm check:types exit 0, pnpm test:azure-oracle passed, browser suite 22 files / 231 passed / 26 skipped. CI Lint and Test are green on this head.

No L1/L2 problems. Awaiting the owner's approving review and merge.

@Alex1990
Alex1990 merged commit f7f6897 into main Sep 17, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The commit author of pr #50 is still loop

1 participant