feat: OpenSpec planning for repo webhook tools #257
No reviewers
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/OpenSpec
Kind/Security
Kind/Testing
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
RFC - Request For Comments
Reviewed/Confirmed
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Status/Abandoned
Status/Blocked
Status/Need More Info
hermes-attempted
hermes-needs-clarification
hermes-ready
hermes-review
hermes-wip
human-required
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
agentic-forges/forgejo-mcp!257
Loading…
Reference in a new issue
No description provided.
Delete branch "refs/pull/257/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds the OpenSpec planning artifacts for repository webhook management (ref #136 — implementation tracked there, not closed by this PR).
forgejo://resource templates for repo hook CRUDoperation/hook/package, URI scheme (hook/hooks), explicit config-key allowlist for secret masking, two-path bounding (tool = unbounded, resource = cap 30)Battle-test outcome
All patches applied before this PR:
{?page,limit}+ singularhook/{id}unified across all artifactsSENTINELassertiontest_repo_hookoutbound traffic-32602pinned forhook/abcTest plan
battle-test.mdverdict is "Patch first" with all patches appliedopenspec validate --all --strictpasses (CI gate)op1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-vmfxt is running.
Starting Pipelinerun forgejo-mcp-openspec-validate-pr-vmfxt in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-openspec-validate-pr-vmfxt -fop1st Pipelines as Code/forgejo-mcp-code-scans-gf6vf is running.
Starting Pipelinerun forgejo-mcp-code-scans-gf6vf in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-gf6vf -fop1st Pipelines as Code/forgejo-mcp-on-pull-request-nrmpq is running.
Starting Pipelinerun forgejo-mcp-on-pull-request-nrmpq in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-on-pull-request-nrmpq -fop1st Pipelines as Code/forgejo-mcp-code-scans-gf6vf has failed.
Task Statuses:
fetch-source
gitleaks-version
Failure snippet:
task fetch-source has the status "Failed":{"level":"error","ts":1781680385.9825666,"caller":"git/git.go:53","msg":"Error running git [remote get-url origin]: exit status 2\nerror: No such remote 'origin'\n","stacktrace":"github.com/tektoncd-catalog/git-clone/git-init/git.run\n\tgithub.com/tektoncd-catalog/git-clone/git-init/git/git.go:53\ngithub.com/tektoncd-catalog/git-clone/git-init/git.Fetch\n\tgithub.com/tektoncd-catalog/git-clone/git-init/git/git.go:109\nmain.main\n\tgithub.com/tektoncd-catalog/git-clone/git-init/main.go:52\nruntime.main\n\truntime/proc.go:272"} {"level":"error","ts":1781680399.4610467,"caller":"git/git.go:53","msg":"Error running git [fetch --recurse-submodules=yes --depth=1 origin --update-head-ok --force 94f57273d51de3f73ce64e2fb627b068e6916489]: exit status 128\nfatal: unable to access 'https://codeberg.org/goern/forgejo-mcp/': gnutls_handshake() failed: The TLS connection was non-properly terminated.\n","stacktrace":"github.com/tektoncd-catalog/git-clone/git-init/git.run\n\tgithub.com/tektoncd-catalog/git-clone/git-init/git/git.go:53\ngithub.com/tektoncd-catalog/git-clone/git-init/git.Fetch\n\tgithub.com/tektoncd-catalog/git-clone/git-init/git/git.go:166\nmain.main\n\tgithub.com/tektoncd-catalog/git-clone/git-init/main.go:52\nruntime.main\n\truntime/proc.go:272"} {"level":"fatal","ts":1781680399.4611177,"caller":"git-init/main.go:53","msg":"Error fetching git repository: failed to fetch [94f57273d51de3f73ce64e2fb627b068e6916489]: exit status 128","stacktrace":"main.main\n\tgithub.com/tektoncd-catalog/git-clone/git-init/main.go:53\nruntime.main\n\truntime/proc.go:272"}op1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-vmfxt has successfully validated your commit.
Task Statuses:
fetch-source
validate
op1st Pipelines as Code/forgejo-mcp-openspec-validate-pr-vmfxt has successfully validated your commit.
Task Statuses:
fetch-source
validate
op1st Pipelines as Code/forgejo-mcp-on-pull-request-nrmpq has successfully validated your commit.
Task Statuses:
fetch-source
build-and-test
commit-title-check
/test forgejo-mcp-code-scans
op1st Pipelines as Code/forgejo-mcp-code-scans-x5srf is running.
Starting Pipelinerun forgejo-mcp-code-scans-x5srf in namespace op1st-pipelines
You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:
tkn pr logs -n op1st-pipelines forgejo-mcp-code-scans-x5srf -fop1st Pipelines as Code/forgejo-mcp-code-scans-x5srf has successfully validated your commit.
Task Statuses:
fetch-source
gitleaks-version
gitleaks