Roadmap item 5/10 · Workstream: Workflow Automation · Risk: High · Approval required: Yes · Target milestone: M2 — Governed intake
Objective
Turn GitHub issue events into validated Task records through a verified intake: HMAC over the raw body, delivery de-duplication, schema validation, and an explicit routing decision, replacing ad-hoc filtering in the Event Router.
Non-goals
- Processing pull-request or push events (separate issue)
- Running the DRC council on every task
- Storing raw webhook bodies
Acceptance criteria
Dependencies
Risk
High — this is the public ingress; verification bugs are security bugs, filtering bugs silently drop work.
Test evidence required
- Signed-fixture tests (valid, tampered body, wrong secret, missing header, replay)
- Read-only
ping delivery verified end to end with the HMAC recomputed locally
- Routing table tests for human vs
[bot] senders and the drc-review label
Definition of done
Objective
Turn GitHub issue events into validated Task records through a verified intake: HMAC over the raw body, delivery de-duplication, schema validation, and an explicit routing decision, replacing ad-hoc filtering in the Event Router.
Non-goals
Acceptance criteria
X-GitHub-Deliveryis a no-op (Implement correlation IDs, idempotency, and structured audit events #319)Dependencies
Risk
High — this is the public ingress; verification bugs are security bugs, filtering bugs silently drop work.
Test evidence required
pingdelivery verified end to end with the HMAC recomputed locally[bot]senders and thedrc-reviewlabelDefinition of done