Repository navigation
Give the QA voice's findings labels, so the loop can see them - #258
Merged
Merged
Conversation
SLOPSTER acts as an account with read access only, which is enough to open an Issue and deliberately not enough to label one: an account that could label could mark its own finding status:ready and put work into the AUTHOR's queue with nobody reading it. But every work-selection item in the AUTHOR runbook is expressed over labels, so an unlabelled Issue is not low priority — it is unreachable. Without this job the QA voice talks to nobody. qa_intake reads the three declaration lines the QA manifest requires and applies only labels the repository already has, plus `qa` and `status:needs-triage`. Never status:ready: promotion to work stays a judgement made by the AUTHOR at triage. Two refusals worth naming. An unknown value is dropped rather than created — the label set is the repository's vocabulary and several guards key on it, so losing an axis costs one triage while inventing a label costs the meaning of every axis. And `status:needs-triage` is added only when no status:* label stands, because an open Issue carrying two of them is #214, which happened twice in one day. A labelling failure warns rather than fails the job: an unlabelled finding is a triage cost, a red workflow on every QA Issue is a broken control plane. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
drevendev
force-pushed
the
policy/qa-intake
branch
from
September 7, 2026 17:58
50d8101 to
8708c0c
Compare
Contributor
There was a problem hiding this comment.
ACCEPT
Head revision: 8708c0c
Evidence:
-
Every required check is measured green at the head revision:
- build-and-test: SUCCESS
- typescript: SUCCESS
- policy-guard: SUCCESS
- mergeability: SUCCESS (CLEAN)
-
Every acceptance criterion is met:
- Well-formed findings receive three axes + qa + status:needs-triage ✓
- Unknown axis values are dropped, finding still arrives ✓
- status:ready is never applied ✓
- No duplicate status:* labels added ✓
- Issues from other accounts untouched ✓
- Labelling failures warn but keep job green ✓
-
Diff is confined to declared scope:
- .github/workflows/qa-intake.yml
- scripts/qa_intake.py
- scripts/tests/test_qa_intake.py
-
No invariants or tests weakened:
- Python test suite: 355/355 pass
- TypeScript test suite: 351/351 pass
- 15 new tests added for qa_intake logic
- All verification commands pass: npm typecheck, npm test, npm build
-
No secrets, credentials, or personal data present
-
Handoff record is complete with Issue linked, all sections present, and operator requirements documented
-
Dependency #257 (verdict ownership) is already merged
-
Policy change does not widen automated authority—adds control-plane QA labeling automation, not agent permissions
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #261
Goal
Let SLOPSTER's findings reach the loop. The QA account has read access only — enough
to open an Issue, not to label one — and an Issue with no labels is invisible to every
work-selection item in the AUTHOR runbook.
Depends on #257 (verdict ownership). Merging this first would put a second QA voice
into a queue that still reads any account's review as a verdict.
Scope — every changed path
scripts/qa_intake.py— new. ReadsType:/Area:/Priority:declarationlines, applies only labels that already exist, plus
qaandstatus:needs-triage.Acts only on Issues authored by
vars.ZENDEV_QA_LOGIN.scripts/tests/test_qa_intake.py— new. 15 tests..github/workflows/qa-intake.yml— new.issues: [opened, reopened], gated on theQA login, MACHINE identity, no model.
Non-goals
Does not grant
status:ready— promotion to work is a judgement the AUTHOR makes attriage. Does not create labels. Does not comment. Does not touch Issues from any other
account, including the researcher's and the operator's.
Acceptance criteria
qaandstatus:needs-triage.qa.status:readyis never applied, however the body is written.status:*label is added when one already stands (An open Issue can carry two status:* labels, and nothing removes the stale one #214).Verification
Live check after merge: open one Issue from the QA account by hand and confirm the
labels appear within a minute; open one from
drevendevand confirm it is untouched.Needs from the operator before this can work
zendev-machineapp → Issues: Read and write, and accept the new permission onthe
trade_simulationinstallation. Contents and Pull requests are not enough.ZENDEV_QA_LOGIN= the QA account's login. Unset, the jobnever runs.
qalabel. The script skips it if absent, so this is not blocking.🤖 Generated with Claude Code