Skip to content

Generate governed fleet policy upgrade pull requests #62

Description

@jmcte

Problem statement

Fleet reconciliation opens generic drift PRs but does not understand policy-version upgrade risk or first-of-class rollout gates.

Desired outcome

Dry-run fleet inventory and version-aware upgrade PRs with patch/minor/major governance.

Scope

  • Inventory public managed repositories, classifications, current pins, drift, and exceptions.
  • Patch auto-merge eligibility, minor independent review, major notification plus ADR.
  • Small-batch pilot recording.

Non-goals

  • Unbounded automatic migration or mass merge.

Acceptance criteria

  • Dry run is default and produces human/JSON inventory.
  • Upgrade PRs link policy diff, tests, exceptions, and provenance.
  • First representative repository per class must pass before further rollout.
  • Failed pilots stop their batch with remediation.

Test expectations

Begin with failing version classification, batching, exception, and first-of-class gate tests.

Security implications

Use least-privilege GitHub credentials and never expose private repository metadata publicly.

Documentation implications

Add fleet migration runbook and outcome record format.

Dependencies

Resolver, conformance, security, and provenance issues.

Human decision points

Major policy deviations, permanent exceptions, and ownership/visibility changes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions