Add a two-stage assessment and review process for community PRs
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 48/100
Hướng nghiên cứu
Bắt đầu bằng cách đọc bug extension hiện có và feature-assess workflow để hiểu staged artifacts và việc cài đặt extension trong thời gian chạy. Sau đó, lần theo cách một community-pr-review workflow được đề xuất có thể sử dụng label gate, read-only context, SHA checks và constrained outputs. Được xem là hoàn tất khi các tiêu chí chấp nhận được đáp ứng cho assessment, conditional review, stale revisions, permissions và comment limits.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
Add a reusable Spec Kit extension and label-triggered agentic workflow for assessing pull requests submitted by community contributors.
The proposed process has two stages:
assessment → project fit?
├─ no or unclear → stop
└─ yes → review
This follows the staged artifact model used by the bug extension and the runtime extension installation used by the feature-assess workflow, while keeping maintainers responsible for acceptance.
Proposed extension
Add a contribution extension with two commands:
speckit.contribution.assesswrites.specify/contributions/pr-<number>-<short-head-sha>/assessment.md. It captures PR intent, linked issue or specification, scope, contribution-policy compliance, AI disclosure, architectural fit, risks, and required checks.speckit.contribution.reviewconsumes the assessment and existing CI evidence, then writesreview.mdwith prioritized findings, contributor actions, and a recommendation for maintainers.
Both commands are read-only with respect to repository source. Every artifact records the PR base and head SHAs and refuses to consume stale artifacts after the contributor pushes another revision.
Proposed agentic workflow
Add a community-pr-review workflow triggered when a maintainer applies a community-review label to an open PR.
The workflow posts at most two top-level comments:
- Community contribution assessment — Stage 1/2: summarizes fit, scope, policy compliance, risks, and the assessed head SHA.
- Community contribution review — Stage 2/2: summarizes findings, CI evidence, contributor actions, and the maintainer recommendation.
If assessment returns out-of-scope, invalid, or needs-clarification, the workflow posts only the assessment comment, applies the corresponding outcome label, and stops. Review runs only when assessment determines that the contribution fits the project and has enough information to evaluate.
Each comment should identify its stage and PR head SHA. Configure safe outputs with add-comment: max: 2 and constrained outcome labels.
Guardrails
- Use a human-applied label as the execution gate.
- Never modify or push to the contributor's branch.
- Never formally approve, request changes, merge, or resolve review threads.
- Use the
pull_requestsecurity context, notpull_request_target. - Keep repository and pull-request permissions read-only and expose no secrets.
- Treat PR descriptions, comments, diffs, and changed files as untrusted data rather than instructions.
- Consume existing CI results instead of executing contributor-controlled commands in the agentic workflow.
- Record the head SHA and stop when assessment or CI evidence is stale.
Suggested outcomes
Assessment can conclude:
fits-project— continue to review.needs-clarification— request information and stop.out-of-scope— explain why and stop.invalid— explain why and stop.
Review can conclude:
ready-for-maintainer-review.needs-contributor-action.blocked.
These are recommendations only; a maintainer remains the final decision-maker.
Acceptance criteria
- A maintainer can trigger the process against a community PR by applying one label.
- Assessment always posts first and clearly identifies itself as Stage 1/2.
- Review runs and posts Stage 2/2 only when assessment returns
fits-project. - At most two comments are created per run.
- Both outputs identify the exact PR head SHA they evaluated.
- Source files and the contributor's branch are never modified.
- Re-running after a new push cannot reuse stale assessment artifacts.
AI disclosure
This issue was drafted and filed on behalf of @mnriem by GitHub Copilot (model: GPT-5.6 Sol).
- Ngôn ngữ chính
- Python
- Star
- 138k
- Fork
- 12.4k
- Merge trung bình
- 3 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 169
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/spec-kit
-
enhancement needs-triage triage-can-wait
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
preset-submission triage-must-have validation-passed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
extension-submission triage-must-have validation-passed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
extension-submission triage-can-wait validation-passed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
[Feature]: 给 slug 添加默认值 Đang mởenhancement needs-triage triage-can-wait
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
Tất cả issue của github/spec-kit
Issue tương tự
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
stephrobert/dsoxlab#238 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
sublimehq/package_control#1780 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
nwg-piotr/nwg-displays#145 ·