1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
//! GitHub adapter for VGI git namespaces.
//!
//! Implements [`vgi_forge::Forge`] for github.com and GitHub Enterprise
//! Server, acting as **one community's own GitHub App** (§5.7 of the design:
//! no shared operator, one App and one bridge per community).
//!
//! - **Auth.** The App key signs a nine-minute RS256 JWT
//! ([`jwt::app_jwt`]) through an [`AppKeySigner`] — in-process
//! ([`InProcessKey`]) or an enclave. Every operation then mints its own
//! installation token, scoped to the one repository and the permissions
//! that operation needs, and drops it on return. Nothing long-lived is
//! cached.
//! - **Registration.** [`manifest`] builds the App manifest with the fixed,
//! reviewed permission set and exchanges GitHub's code for the App's
//! credentials ([`manifest::AppCredentials`], zeroized, never printed).
//! - **Binding.** [`vgi_forge::Forge::begin_bind`] sends the admin to the
//! App's install page with a `state` nonce; `complete_bind` checks it in
//! constant time and confirms the installation is this App's, on the
//! expected owner.
//! - **Accounts.** Members link through the OAuth device flow; the bridge
//! keeps the numeric id and login and discards the user token.
//! - **Repos.** Create (organisations only — a personal account reports
//! `bot_can_create_repos: false`, §8), inspect, archive, converge roles,
//! and the §5.3 bootstrap with a ruleset that has no bypass actors. So that
//! a pull request cannot satisfy its own check (§9), an organisation with
//! org rulesets runs verify-trust as a **required workflow** from the
//! bridge-managed `<org>/.vgi` at a pinned commit; elsewhere the workflow
//! is committed to the repository and, with two or more owners, guarded
//! by `CODEOWNERS` plus code-owner review; a solo repository gets the
//! check alone ([`plan::CheckGuard`]).
//! - **Webhooks.** `X-Hub-Signature-256` verified in constant time before
//! parsing; repository, member, membership, ruleset and installation
//! events become [`vgi_forge::ForgeEvent`]s.
//! - **Bridge-posted checks.** With [`GitHubConfig::bridge_checks`], a
//! namespace without an org required workflow gets no workflow at all:
//! the bridge runs verify-trust on each pull request and posts the check
//! as the App ([`checks`]), and the ruleset requires it from the App's own
//! integration id, which no workflow can post as (§9).
//! - **Pull-request gate.** `pull_request` `opened` / `reopened` become
//! [`vgi_forge::ForgeEventKind::PullRequestOpened`] (who and where, never
//! what), and the four [`vgi_forge::Forge`] pull-request calls read a pull
//! request, find the App's own comment, comment and close, for the
//! bridge's `closePullRequest` job (needs `pull_requests: write`).
//! - **Dependabot re-sign.** `push` deliveries (who moved which branch) and
//! a per-repository push token, for the bridge to re-sign Dependabot pull
//! requests with its own DID on signed provenance ([`resign`]).
//!
//! The HTTP layer is a thin reqwest client ([`api`]) rather than octocrab:
//! see the crate README for why.
pub use API_VERSION;
pub use ;
pub use ;
pub use ;
pub use ;
pub use PushEvent;
pub use Secret;