mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-15 23:31:29 +00:00
The PR and issue Agent Shin workflows gated the destructive --close
flag with [ "${DISPATCH_CLOSE:-false}" != "false" ]. That pattern
treats anything other than the literal string "false" as enabling
closure — "True", "yes", "1", typos, accidental whitespace, etc.
The workflow_dispatch input UI is a 'true'/'false' choice dropdown so
the form is constrained, but the API (`gh workflow run -f close=...`)
accepts any string, and a CI cron / external invoker passing a
non-canonical truthy value would have silently enabled real
contributor PR closures.
Mirror the sibling Greptile closer's [ "${CLOSE_FLAG}" = "true" ]
pattern: only the EXACT string "true" enables --close; every other
value (including the unset/empty default) resolves to dry-run. This is
the fail-safe philosophy applied everywhere else in this PR.
Added tests/test_litellm/test_github_triage_workflows.py with two
parametrized invariants:
1. The destructive gate uses '= "true"' for its env-var
comparison (either bare '${ENV}' or '${ENV:-false}' form
accepted), and never the fail-open '!= "false"' pattern.
2. Every destructive gate is also gated on AGENT_SHIN_ENABLED being
"true" — either by entering the close branch on '=' or by
bailing out early on '!=' — so flipping the repo variable off is
a true kill switch regardless of per-run inputs.
Manually verified the test fails on the buggy '!= "false"' pattern and
passes on the fix, so it would have caught the regression at PR time.
Co-authored-by: Mateo Wang <mateo-berri@users.noreply.github.com>
|
||
|---|---|---|
| .. | ||
| _test-unit-base.yml | ||
| _test-unit-services-base.yml | ||
| auto_update_price_and_context_window.yml | ||
| auto_update_price_and_context_window_file.py | ||
| check-schema-sync.yml | ||
| check_duplicate_issues.yml | ||
| close_low_quality_prs.yml | ||
| codeql.yml | ||
| codspeed.yml | ||
| create-release-branch.yml | ||
| create-release.yml | ||
| create_daily_staging_branch.yml | ||
| guard-fork-dependencies.yml | ||
| guard-main-branch.yml | ||
| helm_unit_test.yml | ||
| issue-keyword-labeler.yml | ||
| label-component.yml | ||
| mutation-test.yml | ||
| run_llm_translation_tests.py | ||
| scorecard.yml | ||
| stale.yml | ||
| sync-schema.yml | ||
| test-code-quality.yml | ||
| test-linting.yml | ||
| test-litellm-ui-build.yml | ||
| test-mcp.yml | ||
| test-model-map.yaml | ||
| test-semgrep.yml | ||
| test-unit-core-utils.yml | ||
| test-unit-documentation.yml | ||
| test-unit-enterprise-routing.yml | ||
| test-unit-integrations.yml | ||
| test-unit-llm-providers.yml | ||
| test-unit-misc.yml | ||
| test-unit-proxy-auth.yml | ||
| test-unit-proxy-db.yml | ||
| test-unit-proxy-endpoints.yml | ||
| test-unit-proxy-infra.yml | ||
| test-unit-proxy-legacy.yml | ||
| test-unit-responses-caching-types.yml | ||
| test-unit-security.yml | ||
| test_server_root_path.yml | ||
| triage_issue_with_llm.yml | ||
| triage_pr_with_llm.yml | ||
| zizmor.yml | ||