Skip to content

Allow Smoke Copilot dispatches to main - #51416

Merged
pelikhan merged 4 commits into
mainfrom
copilot/fix-safe-outputs-job
Aug 8, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/fix-safe-outputs-job

Conversation

Copilot AI commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Copilot’s safe_outputs job rejected its configured dispatch_workflow call because the requested default-branch ref was not allowlisted.

  • Safe-output policy

    • Allow haiku-printer dispatches only on refs/heads/main.
  • Generated workflow

    • Regenerate smoke-copilot.lock.yml with the ref-aware dispatch tool schema and handler configuration.
dispatch-workflow:
  workflows:
    - haiku-printer
  allowed-refs: [refs/heads/main]

Copilot AI linked an issue Aug 8, 2026 that may be closed by this pull request
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix failed safe_outputs job in Smoke Copilot workflow Allow Smoke Copilot dispatches to main Aug 8, 2026
Copilot AI requested a review from pelikhan August 8, 2026 16:25
@pelikhan

pelikhan commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

@copilot the default branch should be the implicit default for allowed-refs. Update spec and validation code.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot the default branch should be the implicit default for allowed-refs. Update spec and validation code.

Implemented in ada2751. allowed-refs now implicitly permits the repository default branch, with updated specification, coverage, and regenerated locks.

@pelikhan
pelikhan marked this pull request as ready for review August 8, 2026 16:59
Copilot AI balanced review requested due to automatic review settings August 8, 2026 16:59
@pelikhan

pelikhan commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

@copilot update the safe outputs specification

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.individual.githubcopilot.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.individual.githubcopilot.com"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check.

No ADR enforcement needed: PR #51416 does not have the 'implementation' label and has only 19 new lines of code in business logic directories (threshold: 100).

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates workflow dispatch ref allowlisting so Smoke Copilot can dispatch haiku-printer on the default branch.

Changes:

  • Adds an implicit default-branch ref allowlist.
  • Tests and documents the new behavior.
  • Regenerates four Smoke Copilot workflows.
Show a summary per file
File Description
pkg/workflow/dispatch_workflow.go Adds the implicit ref allowlist.
pkg/workflow/safe_outputs_cross_repo_config_test.go Tests default ref parsing.
docs/src/content/docs/reference/safe-outputs.md Documents implicit default-branch access.
.github/workflows/smoke-copilot.lock.yml Regenerates the standard smoke workflow.
.github/workflows/smoke-copilot-arm.lock.yml Regenerates the ARM smoke workflow.
.github/workflows/smoke-copilot-aoai-entra.lock.yml Regenerates the AOAI Entra workflow.
.github/workflows/smoke-copilot-aoai-apikey.lock.yml Regenerates the AOAI API-key workflow.

Review details

Tip

Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Suppressed comments (1)

pkg/workflow/dispatch_workflow.go:39

  • The stated policy change is scoped to Smoke Copilot's haiku-printer, but this assignment changes every dispatch-workflow configuration that omits allowed-refs from rejecting per-call message.ref overrides to accepting the default branch and exposing ref in the generated tool. Add the explicit allowed-refs entry shown in the PR description to the smoke workflow sources and regenerate their lock files, rather than changing the global omission semantics, unless this broader API change is intentionally part of the PR scope.
			dispatchWorkflowConfig.AllowedRefs = []string{defaultDispatchWorkflowAllowedRef}
  • Files reviewed: 7/7 changed files
  • Comments generated: 1
  • Review effort level: Balanced


var dispatchWorkflowLog = logger.New("workflow:dispatch_workflow")

const defaultDispatchWorkflowAllowedRef = "refs/heads/${{ github.event.repository.default_branch }}"

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /codebase-design — changes are clean and consistent.

📋 Summary

Positive Highlights

  • ✅ Both lock files updated consistently with the same allowed_refs pattern
  • ✅ Uses ${{ github.event.repository.default_branch }} instead of hard-coding main — correct and future-proof
  • ✅ ref parameter added to the tool input schema with clear description matching the policy
  • ✅ PR description accurately describes the fix

No blocking issues found.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 · 21.3 AIC · ⌖ 10.2 AIC · ⊞ 7.1K
Comment /matt to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes correctly add allowed_refs to the dispatch_workflow safe-output policy in both smoke-copilot-aoai-apikey.lock.yml and smoke-copilot-aoai-entra.lock.yml, restricting haiku-printer dispatches to refs/heads/${{ github.event.repository.default_branch }}. Using the dynamic default-branch expression rather than the hardcoded refs/heads/main mentioned in the PR description is the right approach. The optional ref parameter is also properly wired into the tool schema description. No issues found.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 · 25.1 AIC · ⌖ 6.49 AIC · ⊞ 5.5K

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

🧪 Test Quality Sentinel Report

✅ Test Quality Score: N/A — Maintenance Refactor

Analyzed 1 changed test file. No new func Test* functions were added; existing table-driven test expectations were updated to use the defaultDispatchWorkflowAllowedRef constant instead of a hardcoded string. This is a pure test maintenance change.

📊 Metrics (0 new tests)
Metric Value
Analyzed 0 new functions (Go: 0, JS: 0)
Modified test file pkg/workflow/safe_outputs_cross_repo_config_test.go (+13 / -2 lines)
Change type Expected-value refactor (constant vs. hardcoded string)
Build tag ✅ (go/redacted):build !integration present
Mock violations None
🚨 Violations 0

Verdict

✅ passed. No new behavioral tests to score; existing tests updated for correctness. No violations detected.

🧪 Test quality analysis by Test Quality Sentinel · sonnet46 · 41.4 AIC · ⌖ 6.59 AIC · ⊞ 7.7K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Test Quality Sentinel: N/A (maintenance refactor). 0% implementation tests. No violations.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot update the safe outputs specification

Updated in 939f5e3. The safe outputs specification now documents dispatch_workflow.allowed-refs, including implicit default-branch allowance when omitted, and requires runtime rejection for non-matching message.ref values.

@pelikhan
pelikhan merged commit 193bf85 into main Aug 8, 2026
28 checks passed
@pelikhan
pelikhan deleted the copilot/fix-safe-outputs-job branch August 8, 2026 17:28
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.86.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[aw] Failed jobs: Smoke Copilot

3 participants