PR and backlog triage for GitHub repositories, running as workflows on a stock Interchange hub. Interchange is the control plane (identity, grants, approvals, credentials, runs, audit).
apps/web: portal. After sign-in it converges everything over stock hub routes: tenant, GitHub App credentials, workflow source and deployments (onto the tenant's System One offerings). Prebuilt workflow bundles ship with it (scripts/build-workflows.ts)apps/hub: hub composition — stock@intx/hub-apiplus@corbits/webhooksat/api/hooks(replay table is the library's). Mounted on the same block:@corbits/artifacts,@corbits/cron. Custom routes: GitHub App ManifestGET/POST /api/integrations/github-manifest/{callback,start,cancel}(PEM never in the browser) and synchronous pull request writesPOST /api/integrations/github-actions/:tenantId(comment, review, merge, close). Temporary exception: HMAC intercept on/api/hooks*forX-Hub-Signature-256until@corbits/webhooksadds a GitHub verifier; it delivers to the tenant's live deployment as the system sender, like cronpackages/triage-workflows:pr-triage(PR event mail listener) andpr-triage-historical(open pull requests of a repository when triage is enabled for it, or on Triage again)packages/github-tool,packages/github-write-tool: read-only GitHub tools and the triage mirror writepackages/triage-contracts,packages/rule-packs: types and deterministic checksvendor/interchange: pin74c57b39plus deltas invendor/interchange/VENDORED.mdtooling/: dev runner, eval scriptsdocs/: DEV (local setup), DEPLOY, SELF_HOST
bun install
cp .env.example .env # four secrets + database
bun run devThen follow DEV.md step 5 in the portal. .env holds only Interchange settings; GitHub credentials live in the hub vault and deployments are found by workflow name.
Merge via the GitHub API needs GitHub App contents: write in addition to pull_requests: write; existing installs must accept the new permission on GitHub.
Eval scripts: bun run holdback | injection | report.
GPLv2 with the AI Exception; see LICENSE.md. Contributions require the CLA; see CONTRIBUTING.md. Report security issues per SECURITY.md.