| ▲ | DougN7 6 hours ago | |||||||
Even then if the agent goes rogue and decides to do the merges you can’t stop it if it has any kind of access. This goes back to the OP’s point - agents can’t be 100% constrained. | ||||||||
| ▲ | parsimo2010 6 hours ago | parent | next [-] | |||||||
You can absolutely run an agent as a limited-privilege user that only has write privileges for specific files and only has execute privileges for certain files. If it is running as a limited-privilege user it can work on code in it's own copy of the repo and make commits and send pull requests, but it can't do the merge. The problem is that nobody wants to go through the effort to set up all these permissions and nobody wants to take the time to review everything and perform all the manual actions. | ||||||||
| ||||||||
| ▲ | la6479 6 hours ago | parent | prev [-] | |||||||
Neither can be humans. | ||||||||