From 542bc7931b18797af30edd731874cf89f8f4b3da Mon Sep 17 00:00:00 2001 From: show <10173746+showxu@users.noreply.github.com> Date: Mon, 5 Oct 2026 15:54:21 +0800 Subject: [PATCH 1/2] Require automation proposals to be GitHub-signed commits Rulesets require signed commits, and a commit made with git commit in a workflow is unsigned, so automated pull requests could never merge. The tap and the website now have GitHub create proposal commits through the API with the workflow token; the maintenance guide records that rule. --- MAINTENANCE.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/MAINTENANCE.md b/MAINTENANCE.md index 6585eab..280292a 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -16,7 +16,9 @@ only what they share. that has no bypass: it blocks deletion and force pushes, requires signed commits, and accepts only squash-merged pull requests whose required checks pass. Automation proposes its changes as pull requests that merge - automatically once those checks pass. + automatically once those checks pass. It has GitHub create each proposal + commit through the API with the workflow token, which GitHub signs, because + a commit made with `git commit` in a workflow is unsigned and cannot merge. ## Versions From 5ed0288fa4e34ab8002a93dc997bf61512d67d8e Mon Sep 17 00:00:00 2001 From: show <10173746+showxu@users.noreply.github.com> Date: Mon, 5 Oct 2026 16:28:35 +0800 Subject: [PATCH 2/2] Route automation proposals through the automation App Pull requests opened with the workflow token now wait for manual approval before their checks run, so automation acts through the Computer MCP Automation App instead. --- MAINTENANCE.md | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/MAINTENANCE.md b/MAINTENANCE.md index 280292a..d9c4da9 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -16,9 +16,13 @@ only what they share. that has no bypass: it blocks deletion and force pushes, requires signed commits, and accepts only squash-merged pull requests whose required checks pass. Automation proposes its changes as pull requests that merge - automatically once those checks pass. It has GitHub create each proposal - commit through the API with the workflow token, which GitHub signs, because - a commit made with `git commit` in a workflow is unsigned and cannot merge. + automatically once those checks pass. It acts through the Computer MCP + Automation GitHub App, installed only where automation proposes changes: the + App's installation token has GitHub create each proposal commit through the + API, which GitHub signs, and opens the pull request, whose checks then run on + their own. A commit made with `git commit` in a workflow is unsigned, and a + pull request opened with the workflow token waits for manual approval before + its checks run. ## Versions