Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
8b37eeb
ci: add live canary regression lanes
serrrfirat Apr 12, 2026
d6f5ec5
test: tighten live zizmor canary prompt
serrrfirat Apr 12, 2026
78750c1
feat(auth): harden extension auth and unify canary lanes
ilblackdragon Apr 12, 2026
d25a4b3
merge: integrate upstream live canary lanes
ilblackdragon Apr 12, 2026
87b6e50
refactor(canary): unify auth live canary framework
ilblackdragon Apr 12, 2026
7b96690
fix(mcp): share stdio runtime state across user views
ilblackdragon Apr 12, 2026
442877a
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 12, 2026
793d021
fix(ci): mark root crate unpublished
ilblackdragon Apr 12, 2026
19da65c
merge: sync origin/staging
ilblackdragon Apr 12, 2026
d59426e
fix(auth): address oauth canary review findings
serrrfirat Apr 14, 2026
bb78a0e
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 17, 2026
f4015be
refactor: unify canary runners, restore post-merge user-isolation reg…
ilblackdragon Apr 17, 2026
65e78d9
Merge origin/codex/auth-oauth-canary-unification
ilblackdragon Apr 17, 2026
0f0aaec
fix: resolve unbound variable error in live-canary dispatcher
nickpismenkov Apr 14, 2026
86e8c0b
ci: enable live-canary workflow on PRs
nickpismenkov Apr 17, 2026
3e9aa07
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 18, 2026
1f4187f
Merge remote-tracking branch 'origin/codex/auth-oauth-canary-unificat…
ilblackdragon Apr 18, 2026
1982ee8
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 18, 2026
e8dbbcf
ci: enable live-canary on both main and staging PRs
nickpismenkov Apr 18, 2026
e8ca597
ci: enable all canary lanes to run on pull requests
nickpismenkov Apr 18, 2026
e8bc940
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 18, 2026
3e70291
fix: address PR #2367 Copilot review findings
ilblackdragon Apr 18, 2026
089b070
Merge remote-tracking branch 'origin/codex/auth-oauth-canary-unificat…
ilblackdragon Apr 18, 2026
0095afd
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
ilblackdragon Apr 18, 2026
5342489
fix(bridge): pass CredentialName as &str to setup instructions lookup
ilblackdragon Apr 18, 2026
ab17505
fix(e2e): unblock two auth-matrix canary tests
ilblackdragon Apr 18, 2026
d7b272c
fix(e2e): resolve remaining auth-matrix canary failures
ilblackdragon Apr 18, 2026
f9b1f0f
ci: keep only mock-backed canary lanes on PRs
ilblackdragon Apr 18, 2026
fe6ffeb
fix: deterministic replay
nickpismenkov Apr 19, 2026
468d8a6
Merge branch 'staging' into codex/auth-oauth-canary-unification
nickpismenkov Apr 19, 2026
7c21b70
ci: remove mission test from deterministic-replay lane
nickpismenkov Apr 19, 2026
162160e
ci: remove persona tests from deterministic-replay lane
nickpismenkov Apr 19, 2026
459f3bc
ci: temporarily enable public-smoke on PRs for testing
nickpismenkov Apr 19, 2026
d0a345f
ci: use existing ANTHROPIC_API_KEY secret for live canary
nickpismenkov Apr 19, 2026
0269008
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 19, 2026
68c6bba
fix: codestyle
nickpismenkov Apr 20, 2026
2410ad2
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 20, 2026
56d2e9e
style: apply cargo fmt
nickpismenkov Apr 20, 2026
d51c317
fix(e2e): update assertion to match new mock MCP response format
nickpismenkov Apr 20, 2026
b4688da
fix(e2e): accept response content as proof zizmor ran
nickpismenkov Apr 20, 2026
4da8331
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 20, 2026
d10822c
fix: update auth_manager path in chat test helper
nickpismenkov Apr 20, 2026
2679640
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 20, 2026
cff7c6a
ci: temporarily enable auth-live-seeded on PRs for testing
nickpismenkov Apr 20, 2026
016fa73
ci: use repo-level secrets for auth-live-seeded
nickpismenkov Apr 20, 2026
dcc670f
fix(e2e): print mock LLM port before modifying app state
nickpismenkov Apr 20, 2026
4430181
fix(e2e): fall back to default scopes when env var is empty
nickpismenkov Apr 20, 2026
7dbfcac
feat(e2e): auth-live-seeded uses real OAuth flow instead of DB seeding
nickpismenkov Apr 20, 2026
387a2c8
fix(e2e): complete OAuth flow for all Google extensions, not just Gmail
nickpismenkov Apr 20, 2026
c8bbd79
feat(e2e): support Notion MCP DCR credentials in auth-live-seeded
nickpismenkov Apr 20, 2026
dcc817d
Merge branch 'staging' into codex/auth-oauth-canary-unification
nickpismenkov Apr 20, 2026
53ad644
fix(e2e): preflight-refresh Google access token before auth-live-seeded
nickpismenkov Apr 20, 2026
dffb7bd
fix(e2e): case-insensitive expected_text matching in auth-live-seeded
nickpismenkov Apr 20, 2026
c83856f
fix(e2e): add Gmail canned response + move non-sensitive vars from se…
nickpismenkov Apr 20, 2026
8ae8cf3
ci: remove short-value secrets that corrupt CI logs
nickpismenkov Apr 20, 2026
c684d78
ci: add Notion DCR client secrets to auth-live-seeded workflow
nickpismenkov Apr 20, 2026
f6178ce
fix(e2e): add Notion preflight token refresh with proper User-Agent
nickpismenkov Apr 20, 2026
3b7c38e
fix(e2e): use tool name as expected_text instead of canned response s…
nickpismenkov Apr 20, 2026
cff7ee7
ci: temporarily enable all canary lanes on PRs for testing
nickpismenkov Apr 20, 2026
7baa2a5
ci: disable auth-browser-consent and private-oauth on PRs
nickpismenkov Apr 20, 2026
99686e2
fix(ci): read LIVE_OPENAI_COMPATIBLE_BASE_URL from vars not secrets
nickpismenkov Apr 20, 2026
de1fa2e
fix variable
nickpismenkov Apr 20, 2026
c3fc1be
feat(e2e): add lifecycle canary tests for Gmail, Calendar, and Notion
nickpismenkov Apr 20, 2026
8831659
fix(e2e): relax persona keyword checks + pre-install zizmor in CI
nickpismenkov Apr 20, 2026
5e9ebda
ci: remove temporary PR triggers from all live canary lanes
nickpismenkov Apr 20, 2026
aa67f42
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 20, 2026
974fe0e
fix(e2e): use tool_name_matches for negative recovery-loop assertions
nickpismenkov Apr 20, 2026
fe0dea0
Merge branch 'staging' into codex/auth-oauth-canary-unification
nickpismenkov Apr 20, 2026
b1443a1
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 20, 2026
39c3ac3
fix(e2e): correct bearer token prefix in multi-user MCP assertion
nickpismenkov Apr 20, 2026
d93243b
fix(mcp): resolve per-user client at tool-call time to stop cross-ten…
nickpismenkov Apr 20, 2026
ab6bb11
infra(runner): add Railway-hosted self-hosted runner for private-oaut…
nickpismenkov Apr 20, 2026
dca10fe
fix(mcp): partition Mcp-Session-Id by (user_id, server_name)
nickpismenkov Apr 21, 2026
edeed74
fix(mcp): close activate-vs-remove TOCTOU on shared MCP servers
nickpismenkov Apr 21, 2026
ec5c2a7
fix(canary): materialise sensitive auth secrets to files, out of job env
nickpismenkov Apr 21, 2026
e618848
fix(oauth): make token-body parser content-type-aware + validate token
nickpismenkov Apr 21, 2026
127f6ba
Merge branch 'staging' into codex/auth-oauth-canary-unification
nickpismenkov Apr 21, 2026
bf770c0
fix(runner): install libicu + kerberos + lttng deps for actions/runner
nickpismenkov Apr 21, 2026
09c738e
feat(runner): RUNNER_FORCE_REREGISTER env for re-registration recovery
nickpismenkov Apr 21, 2026
a49cbb9
feat(runner): IRONCLAW_DB_B64 env for one-shot libsql DB bootstrap
nickpismenkov Apr 21, 2026
d23983b
feat(runner): IRONCLAW_DB_URL fallback when base64 env exceeds plan l…
nickpismenkov Apr 21, 2026
32228d8
infra(runner): add seed-runner-db.sh for one-shot DB transfer
nickpismenkov Apr 21, 2026
5d50c1f
fix(runner): install python3 + python3-dev for pyo3 build
nickpismenkov Apr 21, 2026
f0d8b29
Merge remote-tracking branch 'origin/staging' into codex/auth-oauth-c…
nickpismenkov Apr 21, 2026
16fb498
fix(app): remove dead MCP_MAX_SESSIONS env-var parsing
nickpismenkov Apr 21, 2026
db36e3c
fix(extensions): clean up MCP client on tool-wrapper-construction fai…
nickpismenkov Apr 21, 2026
0aa54dd
style: apply cargo fmt
nickpismenkov Apr 21, 2026
f4834d2
fix(oauth): route all error-response body reads through a single trun…
nickpismenkov Apr 21, 2026
fb2f4fa
fix(canary): skip drive_auth_gate_roundtrip until WASM pre-flight gat…
nickpismenkov Apr 22, 2026
0df70e4
fix(canary,mcp,docs): address review findings + harden MCP registry i…
nickpismenkov Apr 22, 2026
96639e9
fix(e2e,docs): scope live-token override to Google + grammar typo
nickpismenkov Apr 22, 2026
e605627
docs(canary): document repo-scope secrets (no env isolation today)
nickpismenkov Apr 22, 2026
63b79fa
fix(runner): checkpoint WAL before copying DB in seed-runner-db.sh
nickpismenkov Apr 22, 2026
13b7638
fix(mcp): three review findings on MCP registry / process / startup p…
nickpismenkov Apr 22, 2026
23e0ac2
fix(mcp,canary): annotation-aware fingerprint + lock/await hygiene + …
nickpismenkov Apr 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
740 changes: 740 additions & 0 deletions .github/workflows/live-canary.yml

Large diffs are not rendered by default.

8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,10 @@ bench-results/
# Coverage reports (local runs, not committed)
/coverage/

# Canary / E2E run outputs (per-run logs, screenshots, trace artifacts —
# CI uploads these via actions/upload-artifact; never commit local copies)
artifacts/

# WASM build artifacts (loaded from disk, not bundled)
*.wasm

Expand All @@ -44,3 +48,7 @@ __pycache__/
engine_trace_*.json
tests/fixtures/llm_traces/live/github_dev_workflow_full_loop.json
tests/fixtures/llm_traces/live/github_dev_workflow_full_loop.log
# Per-test live-replay logs — generated when running `--ignored` live
# tests locally. Only the .json fixtures for each scenario are checked
# in; the .log files are local debugging artifacts.
tests/fixtures/llm_traces/live/*.log
1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ authors = ["NEAR AI <support@near.ai>"]
license = "MIT OR Apache-2.0"
homepage = "https://github.com/nearai/ironclaw"
repository = "https://github.com/nearai/ironclaw"
publish = false

[package.metadata.wix]
upgrade-guid = "D0156E61-BA37-451E-8AB9-1A2ECCCFA48F"
Expand Down
6 changes: 2 additions & 4 deletions deny.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,12 +7,10 @@ ignore = [
"RUSTSEC-2025-0068",
# tokio-tar PAX header parsing — sandbox containers only
"RUSTSEC-2025-0111",
# rustls-webpki CRL distributionPoint matching — 0.102.8 pinned by libsql transitive dep
# rustls-webpki advisories — 0.102.8 remains pinned by a libsql 0.6.0 transitive dep
# (via rustls 0.22 → hyper-rustls 0.25); keep ignored until that pin is gone.
"RUSTSEC-2026-0049",
# rustls-webpki URI name constraint bypass — 0.102.8 pinned by libsql transitive dep;
# patched in >=0.103.12 but libsql 0.6.0 requires rustls 0.22 which pins 0.102.x
"RUSTSEC-2026-0098",
# rustls-webpki wildcard name constraint bypass — same 0.102.8 pin from libsql
"RUSTSEC-2026-0099",
# rand unsoundness with custom logger calling rand::rng() during reseed — we don't use this pattern;
# revisit/remove by 2026-06-30, or when transitive deps (tower, nanoid, phf_generator) release rand ≥0.9.3 compat
Expand Down
55 changes: 35 additions & 20 deletions docs/extensions/github.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
---
title: "Github"
description: "Let your agent access Github"
title: "GitHub"
description: "Let your agent access GitHub"
---

The Github extension allows your agent to interact with Github repositories, issues, pull requests, and more, making it ideal for automating code-related tasks, managing projects, or gathering information from Github.
The GitHub extension allows your agent to interact with GitHub repositories, issues, pull requests, and more, making it ideal for automating code-related tasks, managing projects, or gathering information from GitHub.

---

Expand All @@ -12,32 +12,46 @@ The Github extension allows your agent to interact with Github repositories, iss

<Steps>

<Step title="Get an API Key">
To use the Github extension, you need to obtain an API key from Brave Search. You can get one by signing up at
<Step title="Install the GitHub Extension">

To install the GitHub extension, run:

```bash
ironclaw registry install github
```

</Step>

<Step title="Install the Web Search Extension">
<Step title="Configure Browser OAuth (Preferred)">

To install the Web Search extension, run the following command in your terminal:
Create a GitHub OAuth app at [github.com/settings/apps](https://github.com/settings/apps)
and set its callback URL to the IronClaw OAuth callback URL your gateway uses.

Then expose the app credentials to IronClaw:

```bash
ironclaw registry install github
export GITHUB_OAUTH_CLIENT_ID=...
export GITHUB_OAUTH_CLIENT_SECRET=...
```

Now authenticate:

```bash
ironclaw tool auth github
```

IronClaw will open the browser OAuth flow and store the resulting `github_token`.

</Step>

<Step title="Configure the API Key">
<Step title="Configure a PAT (Fallback)">

After installing the extension, you need to configure your Github API key in IronClaw. You can do this by running:
If you do not want to run a GitHub OAuth app, you can still use a Personal Access Token:

```bash
ironclaw tool auth github
ironclaw secret set github_token YOUR_TOKEN
```

Then follow the prompts to enter your API key.

<Warning>
Be sure to create a fine-grained personal access token with only the necessary permissions for your use case. When in doubt, choose the least permissive options, you can always create new tokens with different permissions later on
</Warning>
Expand All @@ -50,7 +64,7 @@ Be sure to create a fine-grained personal access token with only the necessary p

## Available Actions:

Here are some of the actions your agent can perform with the Github extension:
Here are some of the actions your agent can perform with the GitHub extension:

- `get_repo`: Retrieve repository information
- `list_issues`: List all issues in a repository
Expand Down Expand Up @@ -82,26 +96,27 @@ Lets configure our agent to have its own github account, which it can use to cre

<Steps>

<Step title="Create a new Github account">
<Step title="Create a new GitHub account">

Go to https://github.com and create a new account for your agent. If you are already logged in with your personal account you will need to briefly log out to create the new account, but you can log back in right after

</Step>

<Step title="Generate a Personal Access Token">

On the agent's Github account, go to [Settings -> Developer settings -> Personal access tokens -> Tokens (classic)](https://github.com/settings/tokens) and generate a new token (classic) with the following permissions: `repo` -> `public_repo`
On the agent's GitHub account, go to [Settings -> Developer settings -> Personal access tokens -> Tokens (classic)](https://github.com/settings/tokens) and generate a new token (classic) with the following permissions: `repo` -> `public_repo`

</Step>

<Step title="Authenticate the Github Extension">
Now that you have the token, you can authenticate the Github extension by running:
<Step title="Authenticate the GitHub Extension">
Now that you have either OAuth app credentials or a PAT, authenticate the GitHub extension:

```bash
ironclaw tool auth github
```

Then follow the prompts to enter the token you just generated.
If `GITHUB_OAUTH_CLIENT_ID` and `GITHUB_OAUTH_CLIENT_SECRET` are set, IronClaw
will use browser OAuth. Otherwise it falls back to prompting for a PAT.

</Step>

Expand All @@ -110,7 +125,7 @@ Then follow the prompts to enter the token you just generated.
Ask your agent to create a test issue in one of your public repositories, and check if the issue was created successfully.

<Tip>
Ask your agent to read the [Github Markdown Guidelines](https://github.com/adam-p/markdown-here/wiki/markdown-cheatsheet) and remember then when creating issues and comments, it can make the formatting much nicer!
Ask your agent to read the [GitHub Markdown Guidelines](https://github.com/adam-p/markdown-here/wiki/markdown-cheatsheet) and remember them when creating issues and comments, it can make the formatting much nicer!
</Tip>

</Step>
Expand Down
142 changes: 142 additions & 0 deletions docs/internal/live-canary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,142 @@
# Live Canary Regression Lanes

IronClaw now has two complementary regression systems:

- deterministic CI, which replays committed tests and traces without depending
on real third-party providers for the main blocking path;
- live canaries, which use real providers, real browser consent flows, or
selected real LLM lanes to catch provider drift, refresh failures, release
upgrade problems, and auth regressions that mocks will miss.

The implementation lives in:

- `.github/workflows/test.yml` for the normal blocking test lanes;
- `.github/workflows/live-canary.yml` for scheduled and manual live lanes;
- `scripts/live-canary/run.sh` for lane dispatch;
- `scripts/live-canary/scrub-artifacts.sh` for artifact scanning;
- `scripts/live-canary/upgrade-canary.sh` for previous-release upgrade checks.

The auth-specific executors used by the unified live-canary wrapper are:

- `scripts/auth_canary/run_canary.py`
- `scripts/auth_live_canary/run_live_canary.py` (both seeded and browser-consent
flows; selected with `--mode {seeded,browser}`)

Their shared auth-lane framework lives in:

- `scripts/live_canary/common.py`
- `scripts/live_canary/auth_registry.py`
- `scripts/live_canary/auth_runtime.py`

Future auth canaries should extend that shared framework and the canonical
account guide rather than introducing another bespoke runner layout.

## Lane Summary

| Lane | Scope | Runner | Trigger | Blocking |
| --- | --- | --- | --- | --- |
| `deterministic-replay` | Replays `tests/e2e_live*.rs` fixtures without live LLM calls | GitHub-hosted | PR/staging via `test.yml`; manual via `live-canary.yml` | Yes in `test.yml` |
| `public-smoke` | Real LLM plus public tools such as `zizmor_scan` and mission digest | GitHub-hosted | Daily and manual | Opens issue on scheduled failure |
| `persona-rotating` | Real LLM multi-turn persona workflow, one persona per day | GitHub-hosted | Daily and manual | Opens issue on scheduled failure |
| `private-oauth` | Google Drive auth gate and transparent refresh against a dedicated test account | Self-hosted `ironclaw-live` runner | Manual; scheduled only when enabled | Opens issue on scheduled failure |
| `provider-matrix` | Same live behavior against multiple provider adapters | GitHub-hosted | Weekly and manual | Opens issue on scheduled failure |
| `release-public-full` | Full public live suite for release candidates | GitHub-hosted | Manual | Release checklist gate |
| `upgrade-canary` | Previous release DB opened by current checkout | GitHub-hosted | Manual | Release checklist gate |
| `auth-smoke` | Fresh-machine mock-backed auth smoke: hosted OAuth, MCP OAuth, and multi-user MCP isolation | GitHub-hosted | Hourly and manual | No |
| `auth-full` | Larger mock-backed auth matrix including failure and refresh cases | GitHub-hosted | Manual | No |
| `auth-channels` | WASM channel auth diagnostic lane | GitHub-hosted | Manual | No |
| `auth-live-seeded` | Real-provider runtime checks using seeded tokens against a clean DB | GitHub-hosted | Hourly and manual | No |
| `auth-browser-consent` | Real browser-consent OAuth using Playwright against provider login UIs | GitHub-hosted | Nightly and manual | No |

## Required Repository Configuration

### Public live LLM lanes

Secrets:

- `LIVE_ANTHROPIC_API_KEY`
- `LIVE_OPENAI_COMPATIBLE_API_KEY`
- `LIVE_OPENAI_COMPATIBLE_BASE_URL`

Variables:

- `LIVE_ANTHROPIC_MODEL`
- `LIVE_OPENAI_COMPATIBLE_MODEL`
- `LIVE_CANARY_PRIVATE_OAUTH_ENABLED`

### Auth live-seeded lane

Secrets and dedicated account material are documented in
[scripts/live-canary/ACCOUNTS.md](../../scripts/live-canary/ACCOUNTS.md).

Current provider material includes:

- Google OAuth client credentials and seeded access/refresh tokens
- GitHub seeded token plus a stable issue fixture
- Notion seeded access token and a stable query fixture

### Auth browser-consent lane

Secrets and browser session material are documented in
[scripts/live-canary/ACCOUNTS.md](../../scripts/live-canary/ACCOUNTS.md).

Comment on lines +69 to +82

Copilot AI Apr 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These links use an absolute local path (/home/illia/ironclaw/...) so they'll be broken in GitHub-rendered docs. Use repo-relative links instead (e.g., /scripts/live-canary/ACCOUNTS.md).

Copilot uses AI. Check for mistakes.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 3e702910. Both occurrences in docs/internal/live-canary.md now use the repo-relative ../../scripts/live-canary/ACCOUNTS.md.

Current provider material includes:

- Google OAuth app credentials plus browser storage state
- GitHub OAuth app credentials plus browser storage state and issue fixture
- Notion browser storage state

## Commands

Run public live smoke locally:

```bash
IRONCLAW_LIVE_TEST=1 \
LLM_BACKEND=anthropic \
ANTHROPIC_API_KEY=... \
LANE=public-smoke \
scripts/live-canary/run.sh
```

Run a private OAuth lane on the dedicated runner:

```bash
LANE=private-oauth scripts/live-canary/run.sh
```

Run the auth smoke lane:

```bash
LANE=auth-smoke scripts/live-canary/run.sh
```

Run the seeded auth live lane:

```bash
LANE=auth-live-seeded scripts/live-canary/run.sh
```

Run the browser-consent auth lane:

```bash
LANE=auth-browser-consent scripts/live-canary/run.sh
```

Run selected auth provider cases only:

```bash
LANE=auth-live-seeded CASES=gmail,github scripts/live-canary/run.sh
LANE=auth-browser-consent CASES=google,github scripts/live-canary/run.sh
```

## Artifact Policy

Artifacts are written under `artifacts/live-canary/`.

Before upload, the workflow runs `scripts/live-canary/scrub-artifacts.sh`.
That script is a guardrail against uploading obvious token-shaped strings from
logs or result files.

Private OAuth lanes should continue to avoid uploading raw OAuth logs. The
auth-browser-consent and auth-live-seeded lanes may capture screenshots and JSON
results, but should not upload long-lived credential material.
28 changes: 14 additions & 14 deletions docs/zh/extensions/github.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
---
title: "Github"
description: "让智能体访问 Github"
title: "GitHub"
description: "让智能体访问 GitHub"
icon: github
---

Github 扩展允许智能体与 Github 仓库、议题、拉取请求等交互,非常适合自动化代码相关任务、管理项目或从 Github 收集信息。
GitHub 扩展允许智能体与 GitHub 仓库、议题、拉取请求等交互,非常适合自动化代码相关任务、管理项目或从 GitHub 收集信息。

---

Expand All @@ -14,14 +14,14 @@ Github 扩展允许智能体与 Github 仓库、议题、拉取请求等交互
<Steps>

<Step title="获取 API 密钥">
要使用 Github 扩展,您需要从 Github 获取个人访问令牌。
要使用 GitHub 扩展,您需要从 GitHub 获取个人访问令牌。


</Step>

<Step title="安装 Github 扩展">
<Step title="安装 GitHub 扩展">

在终端中运行以下命令安装 Github 扩展:
在终端中运行以下命令安装 GitHub 扩展:

```bash
ironclaw registry install github
Expand All @@ -31,7 +31,7 @@ ironclaw registry install github

<Step title="配置 API 密钥">

安装扩展后,需要在 IronClaw 中配置您的 Github API 密钥。运行:
安装扩展后,需要在 IronClaw 中配置您的 GitHub API 密钥。运行:

```bash
ironclaw tool auth github
Expand All @@ -51,7 +51,7 @@ ironclaw tool auth github

## 可用操作:

以下是智能体使用 Github 扩展可以执行的一些操作:
以下是智能体使用 GitHub 扩展可以执行的一些操作:

- `get_repo`:获取仓库信息
- `list_issues`:列出仓库中的所有议题
Expand All @@ -70,25 +70,25 @@ ironclaw tool auth github

## 在公共仓库上工作

让我们为智能体配置自己的 Github 账户,以便它可以在**公共仓库**中创建议题和评论拉取请求。
让我们为智能体配置自己的 GitHub 账户,以便它可以在**公共仓库**中创建议题和评论拉取请求。


<Steps>

<Step title="创建新的 Github 账户">
<Step title="创建新的 GitHub 账户">

前往 https://github.com 为智能体创建新账户。如果您已使用个人账户登录,需要暂时登出以创建新账户,之后可以立即重新登录。

</Step>

<Step title="生成个人访问令牌">

在智能体的 Github 账户上,前往 [Settings -> Developer settings -> Personal access tokens -> Tokens (classic)](https://github.com/settings/tokens) 并生成具有以下权限的新令牌(classic):`repo` -> `public_repo`
在智能体的 GitHub 账户上,前往 [Settings -> Developer settings -> Personal access tokens -> Tokens (classic)](https://github.com/settings/tokens) 并生成具有以下权限的新令牌(classic):`repo` -> `public_repo`

</Step>

<Step title="认证 Github 扩展">
获取令牌后,运行以下命令认证 Github 扩展:
<Step title="认证 GitHub 扩展">
获取令牌后,运行以下命令认证 GitHub 扩展:

```bash
ironclaw tool auth github
Expand All @@ -103,7 +103,7 @@ ironclaw tool auth github
让智能体在您的某个公共仓库中创建一个测试议题,检查议题是否创建成功。

<Tip>
让智能体阅读 [Github Markdown 指南](https://github.com/adam-p/markdown-here/wiki/markdown-cheatsheet) 并在创建议题和评论时记住这些格式规范,可以让格式更加美观!
让智能体阅读 [GitHub Markdown 指南](https://github.com/adam-p/markdown-here/wiki/markdown-cheatsheet) 并在创建议题和评论时记住这些格式规范,可以让格式更加美观!
</Tip>

</Step>
Expand Down
Loading
Loading