-
Notifications
You must be signed in to change notification settings - Fork 46
Add safe-inputs gh CLI testing to smoke workflows #11299
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot remove api.github.com in network.allowed in gh.md Keep smoke workflows strict |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot remove api.github.com in network.allowed in gh.md Keep smoke workflows strict |
|
🌑 The shadows whisper... Smoke Codex was cancelled. The oracle requires further meditation... |
|
💫 TO BE CONTINUED... Smoke Claude failed! Our hero faces unexpected challenges... |
|
📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing... |
|
🎉 Yo ho ho! Changeset Generator found the treasure and completed successfully! ⚓💰 |
|
💫 TO BE CONTINUED... Smoke Claude was cancelled! Our hero faces unexpected challenges... |
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation... |
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 |
|
📰 DEVELOPING STORY: Smoke Copilot reports was cancelled. Our correspondents are investigating the incident... |
|
🎉 Yo ho ho! Changeset Generator found the treasure and completed successfully! ⚓💰 |
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
|
GitHub MCP (merged PRs): ✅ Add --push flag to upgrade and init commands with reusable git helpers; Fix authentication failure in reaction step
|
|
Smoke Test: Copilot - 21252861988 PRs Reviewed:
Results: Overall Status: PASS (5/6 tests passed) cc: @pelikhan
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
Smoke Test ResultsPRs reviewed:
Tests:
Status: PARTIAL PASS (gh CLI tool missing)
|
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
|
📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing... |
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 |
|
🎉 Yo ho ho! Changeset Generator found the treasure and completed successfully! ⚓💰 |
|
GitHub MCP (last 2 merged PR titles): ✅ Allow id-token: write permission in strict mode; Update action pin SHAs for anchore/sbom-action and actions/ai-inference
|
Smoke Test ResultsResults:
Status: PASS
|
Smoke Test ResultsPRs Tested:
Test Results:
Overall Status: PASS cc @pelikhan
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
Adds safe-inputs validation to all smoke test workflows by testing GitHub CLI tool integration via the
safeinputs-ghtool.Changes
safeinputs-ghtool withgh pr list --repo ${{ github.repository }} --limit 2 --json number,title,authornetwork.allowedsection containingapi.github.comto eliminate network firewall requirementsshared/gh.mdand maintainstrict: truemodeGITHUB_TOKENImplementation Note
The
shared/gh.mdfile provides thesafeinputs-ghtool configuration without network restrictions, allowing it to work with all engine types including custom engines in strict mode.Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.
Changeset
shared/gh.mdto remove thenetwork.allowedrestriction and validate GitHub CLI access usingGITHUB_TOKEN.Changeset
shared/gh.mdto remove thenetwork.allowedrestriction and validate GitHub CLI access usingGITHUB_TOKEN.