Allow Smoke Copilot dispatches to main - #51416
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot the default branch should be the implicit default for allowed-refs. Update spec and validation code. |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot update the safe outputs specification |
|
✅ Test Quality Sentinel completed test quality analysis.
|
|
✅ PR Code Quality Reviewer completed the code quality review. Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.individual.githubcopilot.com"See Network Configuration for more information.
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. No ADR enforcement needed: PR #51416 does not have the 'implementation' label and has only 19 new lines of code in business logic directories (threshold: 100).
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅
|
There was a problem hiding this comment.
Pull request overview
Updates workflow dispatch ref allowlisting so Smoke Copilot can dispatch haiku-printer on the default branch.
Changes:
- Adds an implicit default-branch ref allowlist.
- Tests and documents the new behavior.
- Regenerates four Smoke Copilot workflows.
Show a summary per file
| File | Description |
|---|---|
pkg/workflow/dispatch_workflow.go |
Adds the implicit ref allowlist. |
pkg/workflow/safe_outputs_cross_repo_config_test.go |
Tests default ref parsing. |
docs/src/content/docs/reference/safe-outputs.md |
Documents implicit default-branch access. |
.github/workflows/smoke-copilot.lock.yml |
Regenerates the standard smoke workflow. |
.github/workflows/smoke-copilot-arm.lock.yml |
Regenerates the ARM smoke workflow. |
.github/workflows/smoke-copilot-aoai-entra.lock.yml |
Regenerates the AOAI Entra workflow. |
.github/workflows/smoke-copilot-aoai-apikey.lock.yml |
Regenerates the AOAI API-key workflow. |
Review details
Tip
Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Suppressed comments (1)
pkg/workflow/dispatch_workflow.go:39
- The stated policy change is scoped to Smoke Copilot's
haiku-printer, but this assignment changes everydispatch-workflowconfiguration that omitsallowed-refsfrom rejecting per-callmessage.refoverrides to accepting the default branch and exposingrefin the generated tool. Add the explicitallowed-refsentry shown in the PR description to the smoke workflow sources and regenerate their lock files, rather than changing the global omission semantics, unless this broader API change is intentionally part of the PR scope.
dispatchWorkflowConfig.AllowedRefs = []string{defaultDispatchWorkflowAllowedRef}
- Files reviewed: 7/7 changed files
- Comments generated: 1
- Review effort level: Balanced
|
|
||
| var dispatchWorkflowLog = logger.New("workflow:dispatch_workflow") | ||
|
|
||
| const defaultDispatchWorkflowAllowedRef = "refs/heads/${{ github.event.repository.default_branch }}" |
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /codebase-design — changes are clean and consistent.
📋 Summary
Positive Highlights
- ✅ Both lock files updated consistently with the same
allowed_refspattern - ✅ Uses
${{ github.event.repository.default_branch }}instead of hard-codingmain— correct and future-proof - ✅
refparameter added to the tool input schema with clear description matching the policy - ✅ PR description accurately describes the fix
No blocking issues found.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 · 21.3 AIC · ⌖ 10.2 AIC · ⊞ 7.1K
Comment /matt to run again
There was a problem hiding this comment.
The changes correctly add allowed_refs to the dispatch_workflow safe-output policy in both smoke-copilot-aoai-apikey.lock.yml and smoke-copilot-aoai-entra.lock.yml, restricting haiku-printer dispatches to refs/heads/${{ github.event.repository.default_branch }}. Using the dynamic default-branch expression rather than the hardcoded refs/heads/main mentioned in the PR description is the right approach. The optional ref parameter is also properly wired into the tool schema description. No issues found.
🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 · 25.1 AIC · ⌖ 6.49 AIC · ⊞ 5.5K
🧪 Test Quality Sentinel Report✅ Test Quality Score: N/A — Maintenance Refactor
📊 Metrics (0 new tests)
Verdict
|
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |
Smoke Copilot’s
safe_outputsjob rejected its configureddispatch_workflowcall because the requested default-branch ref was not allowlisted.Safe-output policy
haiku-printerdispatches only onrefs/heads/main.Generated workflow
smoke-copilot.lock.ymlwith the ref-aware dispatch tool schema and handler configuration.