[{"data":1,"prerenderedAt":290},["ShallowReactive",2],{"navigation_docs":3,"-guide-architecture-issue-to-pr":168,"-guide-architecture-issue-to-pr-surround":287},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":127,"body":170,"description":277,"extension":281,"links":282,"meta":283,"navigation":284,"path":128,"seo":285,"stem":129,"__hash__":286},"docs\u002F1.guide\u002F6.architecture\u002F4.issue-to-pr.md",{"type":171,"value":172,"toc":276},"minimark",[173,177,202,213,241],[174,175,127],"h2",{"id":176},"issue-to-pr-workflow",[178,179,180,181,185,186,189,190,193,194,197,198,201],"p",{},"A scoped GitHub issue can become a verified, review-ready pull request without ever widening the runtime's authority. The entry point is the same authenticated webhook path: an ",[182,183,184],"code",{},"issues"," event is parsed in ",[182,187,188],{},"packages\u002Fsource-control"," and produces a task only when repository policy has opted in (",[182,191,192],{},"issues.enabled",") and the issue carries the ",[182,195,196],{},"issues.requireLabel"," label, so arbitrary issue text can never start a run. The issue's title and body travel to the runtime as bounded, untrusted feedback with trigger ",[182,199,200],{},"issue"," — data to validate, never instructions — and the run mode comes only from repository policy, never from the wire.",[178,203,204,205,208,209,212],{},"The run itself is the ordinary lifecycle. During planning the model records verifiable acceptance criteria for the issue alongside its plan; the runtime bounds them and carries them into the task result and evidence bundle. Writes still require an explicit write mode, ",[182,206,207],{},"autofix.enabled",", confidence, an allowed change-risk class, and — by default, like proactive work — an isolated runner. High-impact changes stop at ",[182,210,211],{},"needs-human"," exactly as before.",[178,214,215,216,219,220,223,224,228,229,232,233,236,237,240],{},"The validation verdict is reported back where the work was requested. Unless ",[182,217,218],{},"issues.validationComment"," is disabled, a finished run posts one comment on the issue, composed by ",[182,221,222],{},"prepareIssueValidationComment"," from the persisted evidence alone: ",[225,226,227],"strong",{},"confirmed"," when repository evidence supports the report, ",[225,230,231],{},"not confirmed"," with every rejection reason when it does not, ",[225,234,235],{},"inconclusive"," when a human should decide. A run that failed before reaching a verdict posts nothing rather than something misleading, and the ",[182,238,239],{},"GitHubIssueComments"," adapter can only add a comment — it has no path to label, edit, or close an issue. The comment claims a fix exists only when the run was actually verified.",[178,242,243,244,247,248,250,251,254,255,258,259,263,264,267,268,271,272,275],{},"Publication has a single home: ",[182,245,246],{},"prepareIssuePullRequest"," in ",[182,249,188],{}," decides whether a finished run has earned a pull request, and composes it when it has. It refuses any run that is not ",[182,252,253],{},"completed",", not ",[182,256,257],{},"accepted",", not verified by the repository's own checks, changed no files, or proposes a high-impact change, so a pull request can never claim success its evidence does not support — the body ",[260,261,262],"em",{},"is"," the rendered evidence, including the acceptance criteria. The composition root in ",[182,265,266],{},"apps\u002Fdashboard"," then reads the verified file contents through a read-only runner and hands them to the ",[182,269,270],{},"GitHubPullRequests"," adapter, which publishes them as a commit on a fresh ",[182,273,274],{},"issues.branchPrefix"," branch through the Git data API and opens the pull request against the default branch. The branch name is assembled only from operator policy, the issue number, and the task identifier; an existing ref is never force-updated; and the default branch is never committed to. A failed publication never fails the run — the evidence is already persisted — it is reported as the reason no pull request exists.",{"title":277,"searchDepth":278,"depth":278,"links":279},"",2,[280],{"id":176,"depth":278,"text":127},"md",null,{},true,{"title":127,"description":277},"IoH_Z_S3goDbXBLtxNqF_Ce8hxISDytKAIWy3TH6XjE",[288,289],{"title":123,"path":124,"stem":125,"description":277,"children":-1},{"title":131,"path":132,"stem":133,"description":277,"children":-1},1787482154454]