Skip to content

Add guard coverage for gh gist rename - #14745

Merged
lpcox merged 3 commits into
mainfrom
copilot/guard-coverage-fix
Oct 11, 2026
Merged

lpcox merged 3 commits into
mainfrom
copilot/guard-coverage-fix

Conversation

Copilot AI commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

gh gist rename mutates a gist through POST /gists/{gist_id} but lacked a guard write classification and DIFC rule.

  • Classification: Add canonical rename_gist to the CLI-only write inventory.
  • DIFC: Apply user-private secrecy and user-scoped writer integrity, matching other gist writes.
  • Coverage: Extend classification and labeling tests for the new operation.
tool_names::DELETE_GIST | tool_names::RENAME_GIST => {
    secrecy = private_user_label();
    baseline_scope = Cow::Borrowed(scope_names::USER);
    integrity = writer_integrity(scope_names::USER, ctx);
}

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix guard coverage gap for GitHub CLI operation Add guard coverage for gh gist rename Oct 11, 2026
Copilot AI requested a review from lpcox October 11, 2026 15:57
@lpcox
lpcox marked this pull request as ready for review October 11, 2026 16:12
Copilot AI balanced review requested due to automatic review settings October 11, 2026 16:12
@lpcox

lpcox commented Oct 11, 2026

Copy link
Copy Markdown
Collaborator

@copilot merge main and resolve conflicts

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The classification, DIFC policy, and tests consistently cover the new operation.

0 open findings

What changed in this PR

Adds guard coverage for the CLI-only gh gist rename mutation.

Changes:

  • Classifies rename_gist as a CLI write.
  • Applies user-private secrecy and writer integrity labels.
  • Adds classification and labeling tests.
File Description
tools.rs Registers and tests the CLI write operation.
tool_rules.rs Adds DIFC labels and coverage.
constants.rs Defines and tests the canonical tool name.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

…e-fix

# Conflicts:
#	guards/github-guard/rust-guard/src/labels/tool_rules.rs
#	guards/github-guard/rust-guard/src/tools.rs

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Oct 11, 2026

Copy link
Copy Markdown
Contributor Author

@copilot merge main and resolve conflicts

Merged main and resolved both conflicts, preserving the gist rename classification and labels. Merge commit: 67ad844.

@lpcox
lpcox merged commit 9027836 into main Oct 11, 2026
30 checks passed
@lpcox
lpcox deleted the copilot/guard-coverage-fix branch October 11, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[guard-coverage] Guard coverage gap: 1 operation from github-mcp-server / GitHub CLI not fully covered

3 participants