Reduce recurring runner-guard static-analysis noise - #53398
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.
Note
This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.
|
@copilot please take another pass on this PR. Please address these items, newest first:
Run: https://github.com/github/gh-aw/actions/runs/32043948991
|
…is-report-2026-08-17 Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed in |
|
🎉 This pull request is included in a new release. Release: |
The static-analysis report flagged reviewed runner-guard findings that were not being recognized as safe:
workflow_runactor allowlist gates for RGS-004, inlinerunner-guard:ignoresuppressions for RGS-012, and step-output interpolation in two workflows.workflow_runjobs gated byworkflow_dispatchplus an explicit actor allowlist as trusted activation gates.needs.Inline suppression handling
# runner-guard:ignore <RULE>comments near reported shell findings.Workflow interpolation hardening
run:blocks for:error-message-lint.ymlwindows-cli-integration.ymlCoverage