Skip to content

BED-9900: Consolidate repository scope edges - #76

Closed
jaredcatkinson wants to merge 1 commit into
mainfrom
BED-9900-repository-scope-edge-consolidation
Closed

jaredcatkinson wants to merge 1 commit into
mainfrom
BED-9900-repository-scope-edge-consolidation

Conversation

@jaredcatkinson

Copy link
Copy Markdown
Contributor

Summary

  • Add GH_Scope nodes to represent repository selection for organization secrets, variables, runner groups, app installations, and personal access tokens.
  • Connect repositories and scoped resources through scope edges, replacing repeated repository to resource edges where selection can be modeled once.
  • Update schema, queries, descriptions, saved searches, and privilege zone rules for the new paths, with focused model and lookup tests.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 28af32b1-85f4-4f16-b57e-4e74da67878a

📥 Commits

Reviewing files that changed from the base of the PR and between 700f2db and e82471d.

📒 Files selected for processing (45)
  • descriptions/edges/GH_CanAccess.md
  • descriptions/edges/GH_CanReadSecret.md
  • descriptions/edges/GH_CanUseRunner.md
  • descriptions/edges/GH_Contains.md
  • descriptions/edges/GH_HasSecret.md
  • descriptions/edges/GH_HasVariable.md
  • descriptions/edges/GH_IsEligibleFor.md
  • descriptions/edges/GH_RequestsAccessTo.md
  • descriptions/edges/GH_ScopedTo.md
  • descriptions/nodes/GH_AppInstallation.md
  • descriptions/nodes/GH_Environment.md
  • descriptions/nodes/GH_OrgRole.md
  • descriptions/nodes/GH_OrgRunnerGroup.md
  • descriptions/nodes/GH_OrgSecret.md
  • descriptions/nodes/GH_OrgVariable.md
  • descriptions/nodes/GH_Organization.md
  • descriptions/nodes/GH_PersonalAccessToken.md
  • descriptions/nodes/GH_PersonalAccessTokenRequest.md
  • descriptions/nodes/GH_Repository.md
  • descriptions/nodes/GH_Scope.md
  • extension/privilege_zone_rules/t0-app-installations-all-repos.json
  • extension/privilege_zone_rules/t0-apps-all-repos.json
  • extension/privilege_zone_rules/t0-pats-all-repos.json
  • extension/saved_searches/repos-vulnerable-to-workflow-secret-exfil.json
  • extension/saved_searches/secrets-reachable-by-user.json
  • extension/schema.json
  • src/openhound_github/kinds/edges.py
  • src/openhound_github/kinds/nodes.py
  • src/openhound_github/lookup.py
  • src/openhound_github/models/__init__.py
  • src/openhound_github/models/app_installation.py
  • src/openhound_github/models/org_secret.py
  • src/openhound_github/models/org_variable.py
  • src/openhound_github/models/personal_access_token.py
  • src/openhound_github/models/personal_access_token_request.py
  • src/openhound_github/models/repository.py
  • src/openhound_github/models/runner.py
  • src/openhound_github/models/scope.py
  • src/openhound_github/resources/organization.py
  • tests/test_lookup.py
  • tests/test_org_secret_models.py
  • tests/test_repository_rulesets.py
  • tests/test_repository_scopes.py
  • tests/test_runner_models.py
  • tests/test_variable_models.py
 ______________________________________________________________________________________________________________________________________________________________________________________________________
< Debugging is twice as hard as writing the code in the first place. Therefore, if you write the code as cleverly as possible, you are, by definition, not smart enough to debug it. - Brian Kernighan >
 ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@jaredcatkinson jaredcatkinson changed the title BED-9900 consolidate repository scope edges BED-9900: Consolidate repository scope edges Sep 30, 2026
@jaredcatkinson
jaredcatkinson deleted the BED-9900-repository-scope-edge-consolidation branch September 30, 2026 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant