Skip to content

Manage advisory GitHub App coverage through product onboarding #2161

Description

@shiny-code-bot

Objective

Make dedicated advisory GitHub App installation coverage an explicit,
fail-closed part of Launchplane product onboarding and governance readiness.

Finish Line

Launchplane can inventory and preflight whether the least-privilege advisory App
is installed for every active product repository before selecting a governance
canary or attempting a projection. Missing access produces a direct human action
link and blocks the rollout plan early, while App installation changes remain a
GitHub-human authorization boundary.

Current Status

State: Portfolio installation coverage is established; onboarding automation remains active as of August 17, 2026.

The shadow-era canary in #2159 used VeriReel PR #341, which merged on August 16, 2026 without an Owner acceptance event. That historical canary is superseded and must not be treated as evidence that Owner acceptance occurred. The current authoritative cutover is #2164 through Launchplane PR #2168, and the current truthful product candidate is draft VeriReel PR #343.

The advisory GitHub App still covers the nine active product repositories, including VeriReel. The current landing and canary sequence does not require new App installation authority.

Next action: implement typed onboarding/readiness inventory so future product repositories surface missing App access before canary selection. Preserve GitHub-human authorization for installation changes and never grant account-wide repository access by default.

Blocked by: none. This later onboarding work does not block the manual authoritative Owner endpoint for PR #343.

Acceptance Criteria

  • Product onboarding reports advisory App installation status for the exact immutable repository ID.
  • A missing installation fails readiness before projection and returns a direct GitHub human-action URL.
  • Launchplane never attempts to self-expand App repository access.
  • Selected-repository inventory is compared with active Launchplane product repository records.
  • Retired repositories are removed through an explicit reviewed human action.
  • App permissions remain only Metadata read and Checks write.
  • Projection readiness is separate from Owner policy, merge admission, and production authority.
  • The active nine-repository portfolio is verified without granting all-repository access.
  • Documentation and operator UI explain the human root-of-trust boundary.

Relationships

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:activeCurrent active plan

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions