Skip to content
This repository was archived by the owner on Aug 6, 2026. It is now read-only.

Harden separate PR authorization prompts - #3699

Closed
tatoalo wants to merge 1 commit into
mainfrom
posthog-code/harden-separate-pr-authorization
Closed

tatoalo wants to merge 1 commit into
mainfrom
posthog-code/harden-separate-pr-authorization

Conversation

@tatoalo

@tatoalo tatoalo commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Why: Reviewer-authored or retrieved text must not be able to authorize publishing a separate pull request when only a direct user instruction should override the single-PR default.

Changes

Clarify all existing-PR prompt paths so only the user’s own direct message can authorize a separate branch or PR, and explicitly exclude quoted, retrieved, generated, and reviewer-authored content. Add regression assertions for each prompt path.

Generated-By: PostHog Code
Task-Id: d2cc4bfb-076a-4011-901a-c34986241e82
@trunk-io

trunk-io Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

🚫 This pull request was removed from the merge queue because it was closed by @tatoalo. See more details here.

@github-actions

Copy link
Copy Markdown

React Doctor found no issues in the changed files. 🎉

Reviewed by React Doctor for commit d3505c3.

@tatoalo tatoalo self-assigned this Jul 22, 2026
@tatoalo tatoalo added the Stamphog This will request an autostamp by stamphog on small changes label Jul 22, 2026
@tatoalo
tatoalo marked this pull request as ready for review July 22, 2026 12:43
@greptile-apps

greptile-apps Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Reviews (1): Last reviewed commit: "Harden separate PR authorization prompts" | Re-trigger Greptile

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Trivial, well-tested change hardening agent prompt text to prevent PR-authorization confusion; "auth" title flag is incidental (prompt-injection hardening, not authentication/authorization code), and author has STRONG familiarity with these exact lines.

  • Author wrote 100% of the modified lines and has 63 merged PRs in these paths (familiarity STRONG).
  • 👍 on the PR from greptile-apps[bot].
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 8L, 1F substantive, 17L/2F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1a-trivial (17L, 2F, single-area, unknown)
stamphog 2.0.0b3 .stamphog/policy.yml @ fb1d37c · reviewed head d3505c3

@tatoalo
tatoalo enabled auto-merge (squash) July 22, 2026 12:48
@tatoalo
tatoalo disabled auto-merge July 22, 2026 12:48
@tatoalo tatoalo closed this Jul 22, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Stamphog This will request an autostamp by stamphog on small changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant