跳转至

Docs PR Review Delivery

生成时间:2026-06-14T14:32:47.284416+00:00

本页把 Docs PR Review Bridge 后面的真实 GitHub 投递边界实体化为 dry-run delivery plan。它覆盖 PR comment、required reviewer、check-run 和 review comment polling 四类动作,但默认不调用 GitHub API,不保存 PR URL、Actions run URL、job URL、完整 SHA、raw diff、cookie 或临时 token。

汇总

  • delivery intent 数:20
  • PR comment intent 数:5
  • required reviewer intent 数:5
  • check-run intent 数:5
  • polling intent 数:5
  • GitHub 网络调用数:0
  • unsafe payload leak 数:0

Delivery Intents

Target Operation Delivery State Polling State Reviewers Gates
.github/workflows/ci.yml pull_request_comment planned_dry_run pending_external_apply engineering-maintainer ci_required_gates_present
.github/workflows/ci.yml required_reviewer planned_dry_run pending_external_apply engineering-maintainer ci_required_gates_present
.github/workflows/ci.yml check_run planned_dry_run pending_external_apply engineering-maintainer ci_required_gates_present
.github/workflows/ci.yml review_comment_polling pending_external_apply planned_dry_run engineering-maintainer ci_required_gates_present
docs/knowledge/docs-publish-review.md pull_request_comment planned_dry_run pending_external_apply automation-maintainer source_registry_or_generator_updated
docs/knowledge/docs-publish-review.md required_reviewer planned_dry_run pending_external_apply automation-maintainer source_registry_or_generator_updated
docs/knowledge/docs-publish-review.md check_run planned_dry_run pending_external_apply automation-maintainer source_registry_or_generator_updated
docs/knowledge/docs-publish-review.md review_comment_polling pending_external_apply planned_dry_run automation-maintainer source_registry_or_generator_updated
docs/knowledge/github-actions-run-ledger.md pull_request_comment planned_dry_run pending_external_apply automation-maintainer, security-reviewer source_registry_or_generator_updated, sanitized_fixture_only
docs/knowledge/github-actions-run-ledger.md required_reviewer planned_dry_run pending_external_apply automation-maintainer, security-reviewer source_registry_or_generator_updated, sanitized_fixture_only
docs/knowledge/github-actions-run-ledger.md check_run planned_dry_run pending_external_apply automation-maintainer, security-reviewer source_registry_or_generator_updated, sanitized_fixture_only
docs/knowledge/github-actions-run-ledger.md review_comment_polling pending_external_apply planned_dry_run automation-maintainer, security-reviewer source_registry_or_generator_updated, sanitized_fixture_only
mkdocs.yml pull_request_comment planned_dry_run pending_external_apply automation-maintainer mkdocs_strict_build_passed
mkdocs.yml required_reviewer planned_dry_run pending_external_apply automation-maintainer mkdocs_strict_build_passed
mkdocs.yml check_run planned_dry_run pending_external_apply automation-maintainer mkdocs_strict_build_passed
mkdocs.yml review_comment_polling pending_external_apply planned_dry_run automation-maintainer mkdocs_strict_build_passed
scripts/check.ps1 pull_request_comment planned_dry_run pending_external_apply engineering-maintainer local_check_matches_ci
scripts/check.ps1 required_reviewer planned_dry_run pending_external_apply engineering-maintainer local_check_matches_ci
scripts/check.ps1 check_run planned_dry_run pending_external_apply engineering-maintainer local_check_matches_ci
scripts/check.ps1 review_comment_polling pending_external_apply planned_dry_run engineering-maintainer local_check_matches_ci

Apply Boundary

当前输出是可审计投递计划,不是 live GitHub 写入。后续 live adapter 必须在命令行显式提供 repository、PR number、head SHA 和具备权限的 GitHub token / GitHub App token;这些运行时参数只能用于当次 API 调用,不写入 vault、docs、reports 或 Semantic Review event。

最小 live adapter 要保持同一语义:

  1. PR comment:只投递 safe_comment,不投递 raw diff。
  2. Required reviewer:只使用 reviewer registry 中的 reviewer id。
  3. Check-run:只写 gate 名称、状态和安全摘要。
  4. Polling:只记录投递是否被 GitHub 接收、是否仍等待人工 review,不保存 PR URL 或 run URL。

结论

当前 dry-run delivery plan 证明:Bridge 后面已经有稳定的 GitHub 投递 contract,可以作为真实 PR review comment / required reviewer / check-run / polling adapter 的输入;requires_review_comment_polling 仍保留为 live handoff,直到显式 apply 和 polling 结果进入安全事件流。