Skip to content

fix: bump AGT to v3.4.0 for contributor check false-positive fix#1619

Closed
imran-siddique wants to merge 2 commits into
github:stagedfrom
imran-siddique:fix/bump-agt-3.4.0
Closed

fix: bump AGT to v3.4.0 for contributor check false-positive fix#1619
imran-siddique wants to merge 2 commits into
github:stagedfrom
imran-siddique:fix/bump-agt-3.4.0

Conversation

@imran-siddique
Copy link
Copy Markdown
Contributor

Bumps \AGT_REF\ from \�3.3.0\ to \�3.4.0\ in the contributor check workflow.

v3.4.0 includes dampening for established accounts (age > 1yr, 50+ followers, 20+ repos) to prevent false-positive HIGH risk flags on legitimate contributors like @aaronpowell.

AGT release: https://github.com/microsoft/agent-governance-toolkit/releases/tag/v3.4.0
Fix PR: microsoft/agent-governance-toolkit#1725

github-actions Bot and others added 2 commits May 5, 2026 02:03
Updates AGT_REF from v3.3.0 to v3.4.0 which includes dampening for
established accounts (age > 1yr, 50+ followers, 20+ repos) to prevent
false-positive HIGH risk flags on legitimate contributors.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings May 5, 2026 03:12
@github-actions github-actions Bot added targets-main PR targets main instead of staged workflow PR touches workflow automation labels May 5, 2026
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ This PR targets main, but PRs should target staged.

The main branch is auto-published from staged and should not receive direct PRs.
Please close this PR and re-open it against the staged branch.

You can change the base branch using the Edit button at the top of this PR,
or run: gh pr edit 1619 --base staged

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 5, 2026

🔴 Contributor Reputation Check: HIGH risk

Check Risk
Profile HIGH
Credential audit NONE

Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.

@github-actions github-actions Bot added the needs-review:HIGH Contributor reputation check flagged HIGH risk label May 5, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Bumps the Agent Governance Toolkit (AGT) reference used by the contributor reputation check workflow to reduce false-positive HIGH risk flags for established accounts.

Changes:

  • Update AGT_REF from v3.3.0 to v3.4.0 for the fetched contributor check scripts.

- name: Fetch AGT check scripts
env:
AGT_REF: v3.3.0
AGT_REF: v3.4.0
@aaronpowell aaronpowell changed the base branch from main to staged May 5, 2026 03:50
@aaronpowell aaronpowell requested a review from dvelton as a code owner May 5, 2026 03:50
@github-actions github-actions Bot added branched-main PR appears to include plugin files materialized from main and removed targets-main PR targets main instead of staged workflow PR touches workflow automation labels May 5, 2026
@aaronpowell aaronpowell mentioned this pull request May 5, 2026
@aaronpowell
Copy link
Copy Markdown
Contributor

Replaced by #1620 which branched from staged properly.

@aaronpowell aaronpowell closed this May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branched-main PR appears to include plugin files materialized from main needs-review:HIGH Contributor reputation check flagged HIGH risk

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants