Skip to content

Build GitHub issue-to-Task intake with webhook verification #322

Description

@labgadget015-dotcom

Roadmap item 5/10 · Workstream: Workflow Automation · Risk: High · Approval required: Yes · Target milestone: M2 — Governed intake

Objective

Turn GitHub issue events into validated Task records through a verified intake: HMAC over the raw body, delivery de-duplication, schema validation, and an explicit routing decision, replacing ad-hoc filtering in the Event Router.

Non-goals

  • Processing pull-request or push events (separate issue)
  • Running the DRC council on every task
  • Storing raw webhook bodies

Acceptance criteria

Dependencies

Risk

High — this is the public ingress; verification bugs are security bugs, filtering bugs silently drop work.

Test evidence required

  • Signed-fixture tests (valid, tampered body, wrong secret, missing header, replay)
  • Read-only ping delivery verified end to end with the HMAC recomputed locally
  • Routing table tests for human vs [bot] senders and the drc-review label

Definition of done

  • Intake live with verification on; one real issue produces one Task with a correlation ID
  • Rejections visible in audit events and alertable (see observability item)
  • Runbook for secret rotation (all three locations) referenced
  • Evidence URL and Correlation ID recorded on the project item

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions