Skip to content

Compare changes

Choose two branches to see what one has that the other does not, then open a pull request for it.

Open a pull request

1 commit

1 file+71−40/1 viewed
+71−4
492492 Agents can also reach integrations directly: an agent definition lists MCP
493493 servers (Sentry, Linear and so on) it may use while working.
494494
495+## A repository that maintains itself
496+
497+> **2026-10-04:** the user asked for Dependabot, GitHub Advanced Security and
498+> Vercel-style deployments, "so you're not having to maintain shit and you're
499+> just pushing up agents that are delivering work consistently".
500+
501+GitHub reports problems and leaves the fix to you. In g1t, an agent opens an
502+issue for each problem, writes the fix, runs its checks, links a preview and
503+lands it through the queue. People only decide.
504+
505+### Upkeep agents
506+
507+- **Dependency updates.** A scheduled scan reads the lockfiles (npm, Cargo,
508+ Go, pip), finds outdated and vulnerable packages and opens one issue per
509+ update or group, assigned to g1t-agent. The agent upgrades the package,
510+ fixes what the upgrade broke and lands it through the queue. A repository
511+ sets how often it scans, which packages it groups and what lands without
512+ review (`.g1t/upkeep.yml`, shaped like `dependabot.yml`).
513+- **Secret scanning.** Pushes are scanned for known token formats. A push
514+ that adds a secret is refused with the file and line; one already in
515+ history opens an issue to rotate it and remove it.
516+- **Vulnerability alerts.** Dependencies are matched against the OSV
517+ database. Every alert links to the issue and pull request fixing it.
518+- **Code scanning.** A reviewer agent reads each pull request's diff for
519+ security problems and leaves findings as review comments with a
520+ suggested fix. Findings on `main` open issues.
521+- **A security page per repository** lists alerts, secrets and findings,
522+ with the agent work on each, like GitHub's Security tab.
523+
524+All of these are event sources for the existing issue → agent → checks →
525+queue pipeline; they need no new kind of work.
526+
527+### Deployments
528+
529+- **A preview for every pull request**, at
530+ `<pr>--<repo>--<owner>.g1t.page`, linked on the pull request and updated
531+ on each push. `main` deploys to `<repo>--<owner>.g1t.page`, and a
532+ repository can add its own domain.
533+- **On g1t.page, not g1t.sh,** so customer code never shares cookies or an
534+ origin with the site people sign in to.
535+- **Built on Workers for Platforms.** Each deployment is a user Worker in a
536+ dispatch namespace; one dispatch Worker on `*.g1t.page` routes to it. The
537+ build runs in the same runners as Actions. Static sites and Workers apps
538+ first; container apps and databases later.
539+- **Agents use the preview.** The reviewer agent opens the preview in a
540+ browser, takes screenshots of what changed and attaches them to its
541+ review, so an approver sees the result without reading the diff.
542+- **Environments.** Preview, production and their secrets; deploy history
543+ and one-click rollback.
544+- **Scale to zero.** An idle branch costs neither g1t nor the customer
545+ anything: a Worker runs, and is billed, only while it answers a request.
546+ A preview is deleted when its pull request closes or merges, and after
547+ a set number of idle days. Container apps, later, sleep when idle.
548+- **On by default, off in one click.** Deployments are recommended, not
549+ required: a repository can turn them off, keep only production, or
550+ deploy somewhere else from its own workflows. Apps built for Cloudflare
551+ (Workers, static assets, D1, KV, R2) deploy without configuration.
552+
553+Later, toward GitLab's DevOps breadth: environment protection rules,
554+package and container registries, releases, container hosting.
555+
495556 ## Agents and models
496557
497558 ### Defining an agent
736797 | --- | --- |
737798 | Repositories; a fork per pull request; data residency per workspace | Artifacts (forks, jurisdictions) |
738799 | Reacting to pushes | Artifacts event subscriptions on Queues |
739−| Preview URL per pull request; deploy on merge | Workers Builds and previews |
800+| Preview URL per pull request; deploy on merge | Workers for Platforms on `g1t.page` |
740801 | Site, API, MCP, git front end | Workers |
741802 | Per-repo coordination, live updates | Durable Objects |
742803 | Pull request lifecycles, automations | Workflows, Cron Triggers |
789850 page.~~ Done: questions and handoffs show as waiting, read, answered,
790851 taken on or declined; since 2026-10-03 an agent asked while it is not at
791852 work is woken to answer, where before the question waited forever.
792−2. **The large run.** Dozens of agents on a real repository, end to end, for
793− the video; g1t hosted on g1t.
794−3. **Polish for judges trying it in a minute:** a seeded demo workspace, the
853+2. **Upkeep agents** (above): dependency updates, secret scanning,
854+ vulnerability alerts, code scanning, the security page. No new
855+ infrastructure.
856+3. **Deployments on `g1t.page`** (above): previews per pull request,
857+ production on merge, the reviewer agent checking the preview.
858+4. **The large run, building 2 and 3.** About 20–30 issues on g1t itself,
859+ built by agents and landed through the queue, for the video: g1t built
860+ on g1t.
861+5. **Polish for judges trying it in a minute:** a seeded demo workspace, the
795862 empty states, and the first-run path from sign-up to an outcome landing.
796863
797864 Earlier items still open, after those: