Skip to content

docs: add autonomous contribution policy with authorized bot registry#1680

Merged
imran-siddique merged 1 commit intomicrosoft:mainfrom
imran-siddique:docs/autonomous-contribution-policy
Apr 30, 2026
Merged

docs: add autonomous contribution policy with authorized bot registry#1680
imran-siddique merged 1 commit intomicrosoft:mainfrom
imran-siddique:docs/autonomous-contribution-policy

Conversation

@imran-siddique
Copy link
Copy Markdown
Member

Adds formal documentation of which bots are authorized and what autonomous behaviors are permitted. Gap #5 of 6 from the OpenSSF AI policy alignment.

New file: \docs/policies/autonomous-contributions.md\

  • Authorized bot registry: Dependabot, GitHub Actions bot, CLA bot, OpenSSF Scorecard, Copilot coding agent
  • Each entry documents: identity, permitted behaviors, scope, human oversight model
  • Prohibited autonomous behaviors list
  • Process for requesting/revoking bot authorization

Updated: CONTRIBUTING.md now links to the full policy.

Add docs/policies/autonomous-contributions.md documenting:
- Default policy: autonomous contributions not accepted
- Authorized bot registry: Dependabot, GitHub Actions, CLA bot,
  OpenSSF Scorecard, Copilot coding agent
- Each bot's permitted behaviors, scope, and oversight model
- Prohibited autonomous behaviors
- Process for requesting and revoking bot authorization
- Relationship to AGENTS.md

Link from CONTRIBUTING.md autonomous contributions section.

Gap #5 of the OpenSSF AI policy alignment.

Co-authored-by: Copilot <[email protected]>
@imran-siddique imran-siddique merged commit a0e7987 into microsoft:main Apr 30, 2026
20 of 21 checks passed
@imran-siddique imran-siddique deleted the docs/autonomous-contribution-policy branch April 30, 2026 23:01
@github-actions
Copy link
Copy Markdown

🤖 AI Agent: docs-sync-checker — Docs Sync

Docs Sync

Documentation is in sync.

@github-actions github-actions Bot added the size/M Medium PR (< 200 lines) label Apr 30, 2026
@github-actions
Copy link
Copy Markdown

🤖 AI Agent: breaking-change-detector — View details

No breaking changes detected.

@github-actions
Copy link
Copy Markdown

🤖 AI Agent: code-reviewer — View details

TL;DR: 0 blockers, 0 warnings. Documentation is clear and aligns with security best practices.

# Sev Issue Where

No action items required. Clean change.

@github-actions
Copy link
Copy Markdown

🤖 AI Agent: security-scanner — View details

No security issues found.

@github-actions
Copy link
Copy Markdown

🤖 AI Agent: test-generator — View details

Test coverage looks good. No gaps identified.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Apr 30, 2026
@github-actions
Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ❌ Failed Issues detected
🛡️ Security Scan ✅ Completed Analysis complete
🔄 Breaking Changes ⚠️ Warning See details
📝 Docs Sync ✅ Passed No issues found
🧪 Test Coverage ✅ Completed Analysis complete

Verdict: ❌ Changes needed

imran-siddique added a commit to imran-siddique/agent-governance-toolkit that referenced this pull request May 4, 2026
…microsoft#1680)

Add docs/policies/autonomous-contributions.md documenting:
- Default policy: autonomous contributions not accepted
- Authorized bot registry: Dependabot, GitHub Actions, CLA bot,
  OpenSSF Scorecard, Copilot coding agent
- Each bot's permitted behaviors, scope, and oversight model
- Prohibited autonomous behaviors
- Process for requesting and revoking bot authorization
- Relationship to AGENTS.md

Link from CONTRIBUTING.md autonomous contributions section.

Gap #5 of the OpenSSF AI policy alignment.

Co-authored-by: Copilot <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant