Establish Forgejo compatibility and review-quality gates #26

Open
opened 2026-07-14 22:32:30 -04:00 by caleb-brown · 0 comments
Owner

What to build

Maintainers can prove that Temper supports its declared Forgejo envelope and produces acceptably grounded, actionable review feedback before a release is approved.

Acceptance criteria

  • A versioned Forgejo contract suite covers every relied-upon webhook, permission, pagination, diff, status, comment, review, inline-position, rate-limit, and token-scope behavior.
  • The supported Forgejo version envelope and rejection behavior are documented from the contract evidence.
  • A versioned representative PR corpus covers multiple languages, review profiles, no-findings cases, large changes, and adversarial content.
  • A human rubric scores correctness, actionability, novelty, severity, diff grounding, duplicate suppression, coverage, and harmful noise.
  • Security acceptance covers prompt injection, hostile rendering, fabricated locations, unauthorized forks, oversized input, and credential leakage.
  • Release thresholds and the process for reviewing corpus regressions are explicit and reproducible.
  • The gate fails clearly when compatibility, security, or quality evidence falls below the accepted bar.

Blocked by

  • #17 — Publish safe inline findings
  • #19 — Add manual, skip, and fork-review controls
  • #21 — Manage Review Policies and Reviewer Profiles safely
## What to build Maintainers can prove that Temper supports its declared Forgejo envelope and produces acceptably grounded, actionable review feedback before a release is approved. ## Acceptance criteria - [ ] A versioned Forgejo contract suite covers every relied-upon webhook, permission, pagination, diff, status, comment, review, inline-position, rate-limit, and token-scope behavior. - [ ] The supported Forgejo version envelope and rejection behavior are documented from the contract evidence. - [ ] A versioned representative PR corpus covers multiple languages, review profiles, no-findings cases, large changes, and adversarial content. - [ ] A human rubric scores correctness, actionability, novelty, severity, diff grounding, duplicate suppression, coverage, and harmful noise. - [ ] Security acceptance covers prompt injection, hostile rendering, fabricated locations, unauthorized forks, oversized input, and credential leakage. - [ ] Release thresholds and the process for reviewing corpus regressions are explicit and reproducible. - [ ] The gate fails clearly when compatibility, security, or quality evidence falls below the accepted bar. ## Blocked by - [#17](https://git.caleb-brown.dev/caleb-brown/temper/issues/17) — Publish safe inline findings - [#19](https://git.caleb-brown.dev/caleb-brown/temper/issues/19) — Add manual, skip, and fork-review controls - [#21](https://git.caleb-brown.dev/caleb-brown/temper/issues/21) — Manage Review Policies and Reviewer Profiles safely
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
caleb-brown/temper#26
No description provided.