fix: bound GitHub pagination and credential forwarding - #192
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
api.github.comoriginReview-driven correction
The first independent review found that real GitHub pagination may canonicalize named repository paths to
/repositories/{id}/.... A live public API response reproduced that behavior. Focused failing regressions were added for file and commit pages plus a mismatched numeric repository ID, then the validator was corrected to accept only the numeric ID bound to verified pull-request metadata. The complete verification below was rerun on the repaired head.Verification
07633f74035559e085cdf18839a4b966cf7bbfffa466ebed15b9f1b15c496b01Evidence boundary
This is engineering evidence only. ScopeProof remains an evidence assistant, not a correctness oracle; it never executes target-repository code. Partial ingestion remains fail closed, persisted/exported objects remain Pydantic-validated, and the opt-in GitHub Action remains informational. No release, tag, package publication, outreach, participant contact, benchmark retuning, or product-stage advancement is included.
Product Stage 1 remains exactly:
Unsupported environments remain real screen-reader operation, Windows desktop workflow, Linux desktop workflow, non-Chromium browser behavior, and accessibility conformance.