Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
964 commits
Select commit Hold shift + click to select a range
45f0178
Merge branch 'trunk' into 12927-fix-repo-sync-worktree
sergiou87 Aug 11, 2026
27be4de
Move Git config isolation to git package
sergiou87 Aug 11, 2026
c0a1800
Remove unused test package imports
sergiou87 Aug 11, 2026
1d0cb0c
Add --search-type flag for semantic and hybrid issue search
michaeljacholke Jul 29, 2026
7035fd2
Address review feedback
michaeljacholke Aug 12, 2026
2e9fedd
Add worktree checkout to issue develop
sergiou87 Aug 12, 2026
3107015
Update AGENTS.md with cleanup comment guidance
babakks Aug 13, 2026
508510f
Reconcile feature detection cleanup comment rules in AGENTS.md
Copilot Aug 13, 2026
b892e92
Address review: drop cleanup markers, document search-type in skill
michaeljacholke Aug 13, 2026
a7059d5
Merge pull request #14006 from michaeljacholke/mj/semantic-search-issues
babakks Aug 13, 2026
10e8f3c
Use `require` instead of `assert`
sergiou87 Aug 13, 2026
3d7fb12
chore(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12
dependabot[bot] Aug 13, 2026
c613912
Merge pull request #14139 from cli/babakks/no-cleanup-comment-for-dot…
babakks Aug 13, 2026
b9f99e8
Merge pull request #14140 from cli/dependabot/go_modules/google.golan…
babakks Aug 13, 2026
53f541f
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Aug 13, 2026
ed5a99f
Upgrade gh-aw workflows to v0.85.4
tidy-dev Aug 13, 2026
fdca974
Merge pull request #14141 from cli/tidy-dev-upgrade-gh-aw-v0-85-4
tidy-dev Aug 13, 2026
6e04581
Bump Go to 1.26.6
web-flow Aug 14, 2026
62b87a7
Merge pull request #14143 from cli/bump-go-1.26.6
babakks Aug 14, 2026
b4c571a
Merge pull request #14119 from cli/dependabot/go_modules/github.com/g…
babakks Aug 14, 2026
ab3282d
chore(deps): bump github.com/klauspost/compress from 1.19.1 to 1.19.2
dependabot[bot] Aug 14, 2026
de84d01
Merge pull request #14120 from cli/dependabot/go_modules/github.com/k…
babakks Aug 14, 2026
fbfe833
chore(deps): bump the aw-actions group with 2 updates
dependabot[bot] Aug 14, 2026
0eeec0b
Merge pull request #14147 from cli/dependabot/github_actions/aw-actio…
babakks Aug 14, 2026
6e047e1
fix(skills): install Codex user skills to ~/.agents/skills
scarletkc Aug 15, 2026
d9b2a13
chore(deps): bump charm.land/lipgloss/v2 from 2.0.5 to 2.0.6
dependabot[bot] Aug 17, 2026
9419664
Adapt spinner output for invoking agents
niik Aug 18, 2026
61ff572
Strengthen agent spinner coverage
niik Aug 18, 2026
c0f9cf8
chore: sign APT repositories with both keys
babakks Apr 23, 2026
9d1ebcc
Merge pull request #13271 from cli/babakks/sign-apt-repo-with-both-keys
babakks Aug 18, 2026
95d3a1d
Accept pre-release tags in deployment validation (#14193)
BagToad Aug 18, 2026
c43d3af
Report what kind of token is active
BagToad Aug 18, 2026
8fb0321
Select a repository id and the viewer permission
BagToad Aug 18, 2026
8baae70
Describe and validate a file gh can attach
BagToad Aug 18, 2026
7a2542d
Rewrite markdown references to uploaded assets
BagToad Aug 18, 2026
2436703
Cover every supported markdown syntax with one document
BagToad Aug 18, 2026
7dddd61
Upload an asset to GitHub
BagToad Aug 18, 2026
171fce4
Read the files named by the attach flag
BagToad Aug 18, 2026
a3b137e
Upload attached files and put them in the markdown
BagToad Aug 18, 2026
7d1d9b7
Add --attach to gh pr comment and gh issue comment
BagToad Aug 18, 2026
9ba9e3f
Add --attach to gh pr create
BagToad Aug 18, 2026
0a631eb
Add --attach to gh pr edit
BagToad Aug 18, 2026
f479411
Add --attach to gh issue create
BagToad Aug 18, 2026
ccd55e6
Add --attach to gh issue edit
BagToad Aug 18, 2026
a1d715c
Refactor PR merge worktree cleanup
tidy-dev Aug 19, 2026
86058f8
Rename worktree branch field to ref
tidy-dev Aug 19, 2026
477d513
Merge remote-tracking branch 'origin/trunk' into tidy-dev-merge-workt…
tidy-dev Aug 19, 2026
d85ac93
Clarify worktree cleanup guidance
tidy-dev Aug 19, 2026
e3d0326
Consolidate token type constants
BagToad Aug 19, 2026
804304a
Move token inspection TODOs to call sites
BagToad Aug 19, 2026
697605b
Detach shared comment from struct field
BagToad Aug 19, 2026
06b86ae
Remove redundant decoding tests
BagToad Aug 19, 2026
bfffa55
Remove test reference from comment
BagToad Aug 19, 2026
89ca08a
Correct package documentation name
BagToad Aug 19, 2026
51b3aa2
Correct stale video test comment
BagToad Aug 19, 2026
7f5be71
Refactor validation types and update size limit message
BagToad Aug 19, 2026
167f684
ci: add temporary step to verify Linux repo signing keys
babakks Aug 20, 2026
450bb68
Merge pull request #14202 from cli/babakks/check-linux-repo-signature
babakks Aug 20, 2026
2a28fcd
Revert "ci: add temporary step to verify Linux repo signing keys"
babakks Aug 20, 2026
856ad9d
Merge pull request #14203 from cli/revert-14202-babakks/check-linux-r…
babakks Aug 20, 2026
4312999
chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1
dependabot[bot] Aug 20, 2026
9e6de9d
chore(deps): bump the codeql-actions group across 1 directory with 3 …
dependabot[bot] Aug 20, 2026
3963b73
chore: bump go to 1.26.7 (#14205)
babakks Aug 20, 2026
d5be33d
Share worktree checkout behavior
tidy-dev Aug 19, 2026
15cc350
Test worktree pull warning
tidy-dev Aug 20, 2026
a0a1392
Merge pull request #14204 from cli/dependabot/go_modules/github.com/s…
BagToad Aug 20, 2026
0d8b314
chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0
dependabot[bot] Aug 20, 2026
5c44f6c
Fix issue triage action compatibility
tidy-dev Aug 20, 2026
fc9c44c
Merge pull request #14169 from cli/dependabot/github_actions/codeql-a…
BagToad Aug 20, 2026
25470f2
Merge pull request #14207 from cli/tidy-dev-diagnose-issue-triage
tidy-dev Aug 20, 2026
af2ba94
Bump gh-aw-actions to v0.87.1 and recompile workflows
BagToad Aug 20, 2026
fba1667
Merge pull request #14164 from cli/dependabot/go_modules/golang.org/x…
BagToad Aug 20, 2026
b9336cf
Merge pull request #14166 from cli/dependabot/go_modules/charm.land/l…
BagToad Aug 20, 2026
fadd4ef
Merge pull request #14210 from cli/bagtoad/bump-gh-aw-actions-v0.87.1
BagToad Aug 20, 2026
c25dff1
Merge branch 'trunk' into 270-gh-issue-develop-worktree
tidy-dev Aug 20, 2026
b7c6866
Default Codespaces port forwarding to loopback
sergiou87 Aug 7, 2026
0817149
chore: fix extra whitespace
babakks Aug 20, 2026
a255baf
Merge commit from fork
BagToad Aug 20, 2026
1e04dab
Fix Copilot install warning newlines
BagToad Aug 20, 2026
046c222
Consolidate Copilot telemetry test
BagToad Aug 20, 2026
01823c0
Update cmd_test.go
niik Aug 21, 2026
7fff140
Merge pull request #14191 from cli/niik-agent-spinner-output
babakks Aug 21, 2026
3f2ae26
Print full help on command misuse for invoking agents
niik Aug 19, 2026
3a73af2
Resolve aliases to their target when rendering full help on error
niik Aug 21, 2026
1ad7a1d
Address worktree cleanup review feedback
tidy-dev Aug 21, 2026
d9cba2a
Merge pull request #14007 from cli/tidy-dev-merge-worktree-guards
babakks Aug 21, 2026
f5dce1a
Merge trunk into issue develop worktree branch
tidy-dev Aug 21, 2026
62e3e71
Merge pull request #14136 from cli/270-gh-issue-develop-worktree
babakks Aug 21, 2026
e4efbc4
Narrow Copilot newline fix scope
BagToad Aug 21, 2026
5d3c481
Merge pull request #14222 from cli/bagtoad/fix-copilot-newline
BagToad Aug 21, 2026
4f3d8fc
Reject non-empty worktree targets
tidy-dev Aug 24, 2026
f3dc831
Merge remote-tracking branch 'origin/trunk' into tidy-dev-pr-14060-re…
tidy-dev Aug 24, 2026
01fd267
chore(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1
dependabot[bot] Aug 24, 2026
4f5c8ac
chore(deps): bump charm.land/bubbletea/v2 from 2.0.8 to 2.0.9
dependabot[bot] Aug 24, 2026
28ecebf
Reuse shared worktree discovery for repo sync
tidy-dev Aug 24, 2026
f0b5f18
Validate image attachment markdown
BagToad Aug 24, 2026
bca0a67
Test populated worktree reuse
tidy-dev Aug 24, 2026
d038799
Remove duplicate test cases
BagToad Aug 24, 2026
27dd72f
Document unrewritable reference limitation
BagToad Aug 24, 2026
cf3bc43
Detect remote destinations by URL scheme
BagToad Aug 24, 2026
6d27fc9
Preserve whitespace in bracketed destinations
BagToad Aug 24, 2026
a04dcf4
Remove empty test placeholder
BagToad Aug 24, 2026
47b232e
Make test intent explicit
BagToad Aug 24, 2026
df67f15
Rename golden file regeneration flag
BagToad Aug 24, 2026
a075e86
Delete confusing test group headings
BagToad Aug 24, 2026
56f07af
Test mixed video reference orderings
BagToad Aug 24, 2026
43f3568
Fold redundant scenario into table
BagToad Aug 24, 2026
6b970a2
Assert upload host token normalization
BagToad Aug 24, 2026
319a0bd
Point upload TODO at DoRequest
BagToad Aug 24, 2026
91cdea2
Clarify attachment permission errors
BagToad Aug 24, 2026
81e3b32
Clarify upload request tests
BagToad Aug 24, 2026
4687c5d
Clarify upload error messages
BagToad Aug 24, 2026
1eaba3c
Stub upload file opening
BagToad Aug 24, 2026
6dda338
Cover multi-hash attachment arguments
BagToad Aug 25, 2026
ea0e187
Document partial upload behavior
BagToad Aug 25, 2026
52d5a3f
Clarify attachment alt text help
BagToad Aug 25, 2026
6c46619
Correct attachment conflict caller
BagToad Aug 25, 2026
fb6d377
Rename attachment argument slice
BagToad Aug 25, 2026
bb63c24
Preserve markdown for empty additions
BagToad Aug 25, 2026
886af95
Clarify comment attachment help
BagToad Aug 25, 2026
6abc068
Separate comment test case braces
BagToad Aug 25, 2026
49e92c2
Document permission-aware repository stub
BagToad Aug 25, 2026
ae5d443
Document partial PR attachment outcomes
BagToad Aug 25, 2026
912e411
Remove redundant prompt failure stubs
BagToad Aug 25, 2026
c81d081
Document partial issue attachment outcomes
BagToad Aug 25, 2026
eb9839e
Validate issue type before uploads
BagToad Aug 25, 2026
ac2222a
Test editor attachment rewriting
BagToad Aug 25, 2026
cd94f8c
Remove redundant issue prompt stub
BagToad Aug 25, 2026
c218854
Add attachment flag wrapper
BagToad Aug 25, 2026
9dc818d
Move attachment policy into commands
BagToad Aug 25, 2026
fe4c3cb
chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2
dependabot[bot] Aug 25, 2026
b9908d1
Support PI_CODING_AGENT_DIR for skills
tommaso-moro Aug 25, 2026
b061fc4
Document attachment support in gh skill
BagToad Aug 25, 2026
a18c1bc
Reject comments with JSON output
BagToad Aug 20, 2026
c2b23c8
Clarify rate limit retry units
BagToad Aug 25, 2026
22769b5
Document attachment path resolution
BagToad Aug 25, 2026
cc83172
Merge pull request #14262 from cli/bagtoad/sturdy-funicular
BagToad Aug 25, 2026
53c733c
test: cover non-empty worktree target rejection
babakks Aug 26, 2026
9e69e88
Merge pull request #14244 from cli/tidy-dev-worktree-checkout-feedback
babakks Aug 26, 2026
a99100c
test(repo sync): add single-worktree repo sync acceptance test
babakks Aug 26, 2026
c2c3572
test(repo sync): group non-current-branch sync tests into subtests
babakks Aug 26, 2026
e2fcbf7
fix(repo sync): surface worktree lookup error alongside update failure
babakks Aug 26, 2026
a2fd23c
Merge pull request #14060 from cli/12927-fix-repo-sync-worktree
babakks Aug 26, 2026
2ff7220
docs(gh-skill): document gh issue develop --checkout --worktree
babakks Aug 26, 2026
606cda4
Merge pull request #14265 from cli/babakks/add-issue-develop-worktree…
babakks Aug 26, 2026
3f5ef1f
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Aug 26, 2026
6e1904a
chore(deps): bump the codeql-actions group across 1 directory with 3 …
dependabot[bot] Aug 26, 2026
e954245
Replace interface{} with any
BagToad Aug 26, 2026
abdea37
Use fmt.Appendf for byte formatting
BagToad Aug 26, 2026
4f0eb3d
Use maps helpers for map loops
BagToad Aug 26, 2026
aee884d
Use min and max built-ins
BagToad Aug 26, 2026
3f7bb81
Use new expression syntax
BagToad Aug 26, 2026
8a63c38
Use omitzero JSON tags
BagToad Aug 26, 2026
e26caf1
Use integer range loops
BagToad Aug 26, 2026
83c1649
Use reflect.TypeFor
BagToad Aug 26, 2026
6f844ce
Use slices.Contains helpers
BagToad Aug 26, 2026
fdd5a07
Use standard library iterators
BagToad Aug 26, 2026
fc68dc4
Use strings.Builder for concatenation
BagToad Aug 26, 2026
d190d6a
Use strings.Cut
BagToad Aug 26, 2026
4cf0c4e
Use strings.CutPrefix
BagToad Aug 26, 2026
f0f3646
Use string sequence iterators
BagToad Aug 26, 2026
556199d
Use testing context helper
BagToad Aug 26, 2026
ecb8c5a
Use WaitGroup.Go
BagToad Aug 26, 2026
0b23d8d
Inline duration pointer helper
BagToad Aug 26, 2026
b3846d7
Apply remaining strings.Builder fix
BagToad Aug 26, 2026
981de3e
Run go fix in lint workflow
BagToad Aug 26, 2026
6ba9230
Remove inlined pointer helpers
BagToad Aug 26, 2026
e86515a
Remove obsolete reflection helper
BagToad Aug 26, 2026
7ca1a75
Merge pull request #14215 from cli/bagtoad/fix-issue-comments-json
BagToad Aug 27, 2026
09bf3ff
Merge pull request #14247 from cli/dependabot/go_modules/google.golan…
williammartin Aug 27, 2026
2e9fccb
Merge pull request #14248 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 27, 2026
19b17f9
Merge pull request #14250 from cli/dependabot/github_actions/codeql-a…
williammartin Aug 27, 2026
5388029
chore(deps): bump charm.land/bubbles/v2 from 2.1.1 to 2.2.0
dependabot[bot] Aug 27, 2026
3d63471
Merge pull request #14249 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 27, 2026
ee05802
Clarify PR testing guidance
williammartin Aug 27, 2026
e248b92
Merge pull request #14272 from cli/williammartin-truthful-pr-testing
williammartin Aug 27, 2026
3bc8eaa
Merge pull request #14271 from cli/williammartin-fix-spam-triage-labe…
williammartin Aug 27, 2026
19fe972
Bump agentic-workflows to 0.87.5
williammartin Aug 27, 2026
2c5ff72
Merge pull request #14273 from cli/wm-bump-aw
williammartin Aug 27, 2026
33edc00
Do not allow dependabot to bump aw
williammartin Aug 27, 2026
9610177
chore(deps): bump charm.land/bubbles/v2 from 2.2.0 to 2.2.1
dependabot[bot] Aug 27, 2026
d76da60
Merge pull request #14274 from cli/wm-aw-dependabot
williammartin Aug 27, 2026
07fb593
Use native Go diff checks
BagToad Aug 27, 2026
10f0ee3
Simplify skill processing limit
BagToad Aug 27, 2026
a0b4ede
Simplify auth host validation
BagToad Aug 27, 2026
4c32c17
Inline codespace slice checks
BagToad Aug 27, 2026
88684c2
Inline pull request slice checks
BagToad Aug 27, 2026
2ea4611
Merge pull request #14278 from cli/bagtoad/go-fix-cleanup
BagToad Aug 27, 2026
679018a
Merge pull request #14275 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 28, 2026
8d17165
Merge pull request #14258 from cli/dependabot/go_modules/github.com/s…
williammartin Aug 28, 2026
9b323de
Merge pull request #14267 from cli/dependabot/go_modules/github.com/g…
williammartin Aug 28, 2026
f2bf7c3
Limit attachment batches to 50 files
BagToad Aug 28, 2026
40b742f
Merge pull request #14289 from cli/bagtoad/limit-attachment-batches
BagToad Aug 28, 2026
367d30a
chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2
dependabot[bot] Aug 31, 2026
78aaae9
chore(deps): bump the codeql-actions group with 3 updates
dependabot[bot] Aug 31, 2026
5d0f7d7
chore(deps): bump azure/login from 3.0.1 to 3.0.2
dependabot[bot] Aug 31, 2026
0574bc5
Merge pull request #14299 from cli/dependabot/go_modules/google.golan…
sergiou87 Sep 1, 2026
35f596d
Merge pull request #14301 from cli/dependabot/github_actions/azure/lo…
sergiou87 Sep 1, 2026
a8460b5
Merge pull request #14300 from cli/dependabot/github_actions/codeql-a…
sergiou87 Sep 1, 2026
e909b95
Merge pull request #14154 from scarletkc/scarletkc/fix-codex-user-ski…
BagToad Sep 1, 2026
d528f20
Merge pull request #14260 from cli/tommaso-moro-support-pi-agent-dire…
BagToad Sep 1, 2026
71eac35
Merge pull request #14198 from cli/niik-agent-full-help-on-error
niik Sep 2, 2026
7be4c29
Fix discussion acceptance test flags
williammartin Sep 2, 2026
0da5ee8
Merge pull request #14321 from cli/williammartin-fix-discussion-accep…
williammartin Sep 2, 2026
c219743
Add acceptance coverage for gist
williammartin Aug 7, 2026
bceaa3b
Wait longer for the search index in the issues script
williammartin Aug 7, 2026
0f3ab22
Let GH_ACCEPTANCE_SCRIPT name several scripts
williammartin Aug 7, 2026
eae00d0
Add the api_host gateway harness
williammartin Aug 7, 2026
3189464
Send a host's token to its configured api_host
williammartin Aug 7, 2026
2d89b26
Make gh api honour api_host for relative paths
williammartin Aug 7, 2026
670b2a3
Send RenameRepo to a relative path
williammartin Aug 7, 2026
62a6e9e
Add a raw response request surface to api.Client
williammartin Aug 7, 2026
216199e
Let a caller name the scopes an endpoint needs
williammartin Aug 7, 2026
eae1deb
Let a caller stop a request following redirects
williammartin Aug 7, 2026
6fcf2ea
Let callers set headers on a shared client request
williammartin Aug 7, 2026
ffb187b
Send release asset uploads and downloads through api.Client
williammartin Aug 7, 2026
97fcb73
docs(api): clarify redirect method-rewriting in comments
babakks Aug 27, 2026
dbbaed8
fix(config): resolve api_host collisions deterministically
babakks Aug 27, 2026
fbda842
refactor(api): use errors.AsType for HTTP error checks
babakks Aug 27, 2026
d5ff05b
test(acceptance): cover selecting multiple scripts in one directory
babakks Aug 27, 2026
c67d0e6
test(api): assert DoRequest preserves an explicit ContentLength
babakks Aug 27, 2026
2266020
test(config): cover deterministic api_host collision resolution
babakks Aug 27, 2026
62f5a7c
test(config): add coverage for APIHostForHost
babakks Aug 27, 2026
061b2a1
fix(auth/shared): route GetScopes path through safeurl
babakks Aug 27, 2026
fcd05d9
chore(codeql): cover api.Client.Request in SafeURL path query
babakks Aug 27, 2026
4288f57
build(deps): bump go-gh to per-host api_host branch
babakks Aug 27, 2026
95107ff
test(acceptance): fix scriptfilter table field alignment
babakks Aug 27, 2026
48922ac
fix(api): compare request hostname without port when attaching auth t…
babakks Aug 28, 2026
ee5ed71
chore: tidy go.sum
babakks Aug 28, 2026
e7675c9
test(internal/attachments): add new method required by interface
babakks Aug 28, 2026
061e585
chore: apply go fix
babakks Aug 28, 2026
2f88d05
refactor(attachments): send uploads through api.Client.DoRequest
babakks Aug 28, 2026
6656e47
build(deps): bump go-gh to rebased per-host api_host branch
babakks Aug 28, 2026
fe76ff5
Rename tokenGetter to config
williammartin Sep 2, 2026
628e85c
Refactor AddAuthTokenHeader
williammartin Sep 2, 2026
714e5ea
Document when telemetry disabling is overzealous
williammartin Sep 2, 2026
8b3e2f1
Comment missing api-client-rollout todo
williammartin Sep 2, 2026
5ba76c6
Comment api command api_host usage
williammartin Sep 2, 2026
6e7b1fe
Remove redundant comment in gist create
williammartin Sep 2, 2026
0580da9
Remove unnecessary 204 on release edit
williammartin Sep 2, 2026
05a0a02
Remove redundant searcher comment
williammartin Sep 2, 2026
6865464
Bump go-gh to v2.15.0
williammartin Sep 2, 2026
905e868
Clarify supported GHES versions
williammartin Sep 2, 2026
09850d5
Use version-neutral GHES support link
williammartin Sep 2, 2026
b94691d
Refine GHES support wording
williammartin Sep 2, 2026
9d36fee
Merge pull request #14324 from cli/williammartin-github-mercy-preview
williammartin Sep 2, 2026
a82d1e9
Merge pull request #14318 from cli/issue-triage-improvements
sergiou87 Sep 2, 2026
adda317
Merge pull request #14104 from cli/williammartin-api-host-commit-split
williammartin Sep 2, 2026
ad5677b
chore: bump golang.org/x/crypto to 0.56.0
babakks Sep 3, 2026
8e55608
Merge pull request #14331 from cli/babakks/bump-crypto
williammartin Sep 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"image": "mcr.microsoft.com/devcontainers/go:1.25",
"image": "mcr.microsoft.com/devcontainers/go:1.26",
"features": {
"ghcr.io/devcontainers/features/sshd:1": {}
},
Expand Down
73 changes: 73 additions & 0 deletions .experiments/tech-debt-burndown/memory.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
# Tech debt burndown: agent memory

Standing corrections for the [`tech-debt-burndown` skill](../../.github/skills/tech-debt-burndown/SKILL.md).
This file is loaded at the start of every run and is binding.
Both humans and agent runs write here, and nothing distinguishes the two once
written. Assume any entry may be an unreviewed conclusion from a previous run.
Entries are binding on what to avoid; factual claims in them should be
re-verified before you lean on them, and corrected when stale. Date-stamp
anything you add.

**Budget: 150 lines of entries**, counted from the end of Current focus to the end
of the file. The header and Current focus do not count, and must never be trimmed
to get under budget: they are instructions, not findings. If an append would
exceed the budget, consolidate existing entries first, in the same pull request.

The budget exists so this file stays worth reading, not to save tokens - the
skill file is several times longer. A memory file that has become a run log is
one nobody reads carefully, including you.

## Current focus

**Human-owned. Agent runs must not edit this section.** Propose changes in the
pull request body instead.

Empty. With no focus set, runs fall back to the tier order in the skill.

<!-- Examples of what can go here:
- "Work on pkg/cmd/pr/edit until staticcheck is clean, then add the exclusion."
- "Prefer skipped tests and stale nolints over linter findings for now."
- "Leave staticcheck alone, it is all cosmetic. Focus on errcheck." -->

## Off limits

- Generated code and mocks. See the Never touch section of the skill.
- Removing a feature-detection gate (`// TODO <cleanupIdentifier>`). Whether a
gate can come out depends on the supported GHES version window, which is not
discoverable from the repo and cannot be resolved unattended.

## Known scale of the linter backlog

Counts measured by an agent run on 2026-08-06 against `trunk`, not verified by a
human, and stale as soon as anything lands. Use them to choose between linters,
not as a target count. Command: `--no-config --default=none
--max-issues-per-linter=0 --max-same-issues=0`, so this repo's exclusions are
*not* applied and these are upper bounds: errcheck 1245, staticcheck 221,
gosec 435.

`gosec` is the least tractable, because `.golangci.yml` already excludes G110,
G204, G301, G302, G304, G307, and G404, plus all `gosec` findings in `_test.go`
files, and a `--no-config` run reports all of those anyway. Always cross-check
`gosec` output against `.golangci.yml` before acting on it.

## Staticcheck shape

2026-08-06: repo-wide staticcheck has **no `SA` (correctness) findings**. It is
all style: QF1008 (70), QF1012 (50), ST1005 (29), QF1003 (24), ST1012 (16), rest
single digits. Staticcheck targets are mechanical and safe, but low value.

Most-affected packages: `pkg/cmd/pr/edit` (23), `pkg/cmd/issue/edit` (19),
`pkg/cmd/auth/status` (16), `pkg/cmd/extension` (11). `pkg/cmd/alias/imports` was
cleared 2026-08-06.

## Rejected targets

None yet.

## False positives

None yet.

## Failed attempts

None yet.
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,3 @@
.github/actions/*/lib/* linguist-generated

.github/workflows/*.lock.yml linguist-generated=true
20 changes: 11 additions & 9 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,15 +1,17 @@
* @cli/code-reviewers

pkg/cmd/codespace/ @cli/codespaces
internal/codespaces/ @cli/codespaces
pkg/cmd/codespace/ @cli/codespaces @cli/code-reviewers
internal/codespaces/ @cli/codespaces @cli/code-reviewers

# Limit Package Security team ownership to the attestation command package and related integration tests
pkg/cmd/attestation/ @cli/package-security
pkg/cmd/release/attestation/ @cli/package-security
pkg/cmd/release/verify/ @cli/package-security
pkg/cmd/release/verify-asset/ @cli/package-security
pkg/cmd/release/shared/ @cli/package-security
pkg/cmd/attestation/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify-asset/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/shared/ @cli/package-security @cli/code-reviewers

test/integration/attestation-cmd @cli/package-security
test/integration/attestation-cmd @cli/package-security @cli/code-reviewers

pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers
pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers @cli/code-reviewers

pkg/cmd/skills/ @cli/skills @cli/code-reviewers
internal/skills/ @cli/skills @cli/code-reviewers
76 changes: 74 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,76 @@
<!--
Thank you for contributing to GitHub CLI!
To reference an open issue, please write this in your description: `Fixes #NUMBER`
Thank you for contributing to GitHub CLI!

If you are proposing a fix for a security issue, STOP and follow .github/SECURITY.md instead.
-->

<!-- List related issues here. Use `fixes` or `closes` keywords to associate an issue number. -->

### Description

<!--
What's the problem? How are we addressing it?

Write for a reviewer who has not worked in this part of the codebase. Give them the
background they need before the problem makes sense, and avoid jargon.
-->

### How did you test this change?

<!--
Report only actions you actually performed and results you actually observed, using factual
first-person language (for example, "I ran..." and "I saw..."). Do not present planned,
hypothetical, inferred, or merely expected scenarios as testing.

Automated test results do not belong here. Passing unit tests, `go test ./...` output, and
coverage numbers tell a reviewer nothing they cannot see from CI, so do not paste them.

If you did not exercise the changed behavior, write `Not tested` and explain why.

Use one or more of these, whichever communicates best:

1. Screenshots or GIFs of the real command running. Preferred whenever the change is visible
in terminal output. If output changed, show it before and after.
2. Given/When/Then scenarios, but only when you actually executed the steps. For example:
Given I was in a repo with no open pull requests
When I ran `gh pr list`
Then I saw "no open pull requests in cli/cli"
3. A natural language walkthrough of what you did by hand, the states you covered, and what
you saw, including error and edge cases.

If you leave this empty, your pull request will very likely be closed.
-->

### Key points

<!--
Tradeoffs you accepted, alternatives you rejected, and anything a reviewer would otherwise have to guess at.
-->

### Notes for reviewers

<!--
Where should review start, and what should be read next? Call out anything you are unsure about.

Link related issues or prior discussion, with one sentence on why each matters.
-->

### Authorship and follow-up

<!--
REQUIRED - If you are an AI agent filling in this template, answer "Who wrote this" for yourself and answer honestly. For "Who answers review comments," use only a choice the human has explicitly made in the conversation. If no choice has already been established, pause and ask the human to choose one of the three options before creating or updating the pull request. Do not infer the choice from repository ownership, authorship, assignees, prior interactions, or the current operator. After the human answers, check exactly the option they chose; the last option is valid when the human explicitly chooses nobody.

Check exactly one box in each list.
-->

Who wrote this:

- [ ] A human wrote it.
- [ ] An agent wrote it under close human direction.
- [ ] An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

- [ ] @username will read and reply directly. Name the account.
- [ ] An agent will draft replies and @username will read them before they are posted.
- [ ] Nobody has explicitly committed to replying.
Loading