github / github/gh-aw

Add SOC-2 compliance patterns doc page

Open
#41,746 1 comment 0 reactions 1 assignee Claimed by @pelikhan View on GitHub
documentation security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 48m
Merged PRs (30d)
773

Description

An issue arises for orgs working in compliance settings (e.g. SOC-2) which require, say, 2 human reviewers (creator + reviewer) on all code creations.

This can affect GH-AWs that use the `create-pull-request` safe output (with GITHUB_TOKEN or a GitHub App as the auth mechanism).

There are many, many AWs that do not use create-pull-request.  For example, it is an increasingly common pattern to

1. Use an AW to do deep research (e.g. about an incident)
2. Have AW file an issue using create-issue with a proposed, detailed course of action
3. A human assigns the issue to Copilot CCA and iterates on the PR from there.

Step (3) is where the human associates with the code-creating activity.

This pattern has added advantages too, e.g. it works if CCA is configured to run on Windows - the AW runs in the Ubuntu container sandbox doing research and issue-creation, while CCA or other agents run on Windows.

Options are
1. Use a PAT to identify the human overseer (e.g. repository maintainer or automation runner) as code-owner (equivalent and similar to co-creating with Copilot locally to create a PR)
2. Use a pattern like the above (`create-issue` not `create-pull-request`) where there is a manual step to assign the issue to CCA.

We should add a reference page about this and link it from other suitable Enterprise pages

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.