Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
bc0ea0a
Add update-pull-request safe output
Copilot Sep 22, 2026
98559d5
add close pull request safe output core
Copilot Sep 22, 2026
772282e
Document and test update-pull-request safe output
Copilot Sep 22, 2026
89b6608
format and fix close pull request tests
Copilot Sep 22, 2026
860b6bf
address close pull request review feedback
Copilot Sep 22, 2026
2b08657
Address update-pull-request review feedback
Copilot Sep 22, 2026
44e3cdf
switch close pull request safe output to ado
Copilot Sep 22, 2026
9277c06
Correct update-pull-request for Azure DevOps
Copilot Sep 22, 2026
dbfc6a1
fix ado close pull request tests
Copilot Sep 22, 2026
fa84855
rename close pull request safe output to abandon
Copilot Sep 22, 2026
54a9faf
harden abandon pull request execution
Copilot Sep 22, 2026
949f477
merge: consolidate Azure DevOps PR safe outputs
jamesadevine Sep 24, 2026
444e773
merge: update consolidated safe outputs from main
jamesadevine Sep 24, 2026
ba005bd
feat(safe-outputs): add Azure DevOps PR mutations
jamesadevine Sep 24, 2026
cf9b51d
merge: integrate current PR reviewer and temporary-reference support
jamesadevine Sep 24, 2026
d6dba9c
feat(safe-outputs): split Azure DevOps PR tools with safe migration
jamesadevine Sep 24, 2026
bff5a88
refactor(safe-outputs): use canonical pull-request tool names
jamesadevine Sep 24, 2026
68f75d7
fix(safe-outputs): address PR identity and migration review findings
jamesadevine Sep 24, 2026
b3a7d3a
fix(tests): repair portable fixtures and PR label verification
jamesadevine Sep 24, 2026
e5fe6ee
test(safe-outputs): extend failure, Unicode and pipeline boundary cov…
jamesadevine Sep 24, 2026
d4f7f94
fix(safe-outputs): read authoritative PR labels and make test cleanup…
jamesadevine Sep 24, 2026
a351a42
fix(tests): recognize Azure Pipelines default job timeline identifiers
jamesadevine Sep 24, 2026
5111a66
test(safe-outputs): cover abandonment transport failures
jamesadevine Sep 24, 2026
e8ebf27
fix(smoke): tolerate bounded transient build polling failures
jamesadevine Sep 25, 2026
fa0cea7
fix(safe-outputs): reject unknown PR configuration and proposal fields
jamesadevine Sep 25, 2026
7957fa6
fix(smoke): recognize explicitly skipped unallocated ADO jobs
jamesadevine Sep 25, 2026
c8645de
test(safe-outputs): probe ADO PR lifecycle API contracts
jamesadevine Sep 25, 2026
7e7dd0a
feat(safe-outputs): unify PR targeting and migrate explicit scopes
jamesadevine Sep 25, 2026
34c307d
fix(safe-outputs): make comment reviews non-voting and report partial…
jamesadevine Sep 25, 2026
a9be3c3
feat(safe-outputs): govern PR labels and publish existing drafts
jamesadevine Sep 25, 2026
7830347
feat(safe-outputs): add owned comment lifecycle and explicit review b…
jamesadevine Sep 25, 2026
2726a75
fix(safe-outputs): respect immutable ADO thread properties and delete…
jamesadevine Sep 25, 2026
ef74722
feat(safe-outputs): add exact-head guarded PR branch pushes
jamesadevine Sep 28, 2026
9d291b6
docs(safe-outputs): clarify PR comment review and vote contracts
jamesadevine Sep 28, 2026
86e552b
fix(ci): prefetch complete diffs for large pull requests
jamesadevine Sep 28, 2026
c4aa050
fix(compile): invoke staged compiler for PR source preparation
jamesadevine Sep 28, 2026
549f2a7
fix(workflows): inherit runtime model selection for subagents
jamesadevine Sep 28, 2026
6b07d65
fix(tests): preflight every reviewer scope and reconcile completion r…
jamesadevine Sep 30, 2026
3172f1f
fix(compile): normalize enabled legacy PR comment shorthand
jamesadevine Sep 30, 2026
d890eb8
fix(tests): recover boundary resource groups with guarded cleanup
jamesadevine Sep 30, 2026
b915f39
fix(safe-outputs): bound PR transport and deduplicate inline reads
jamesadevine Sep 30, 2026
2f97a8a
test(safe-outputs): replace retired PR test-only implementations
jamesadevine Sep 30, 2026
4ba2a82
test(execute): expect explicit uncertain label delivery
jamesadevine Oct 1, 2026
c5dac7b
fix(safe-outputs): bound native PR patches and preserve exact blobs
jamesadevine Oct 1, 2026
c9f9881
fix(safe-outputs): reject filtered PR preimages before applying patches
jamesadevine Oct 1, 2026
873a05d
fix(safe-outputs): honor exact refs and emit one ADO change per path
jamesadevine Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .github/workflows/ado-script.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,22 @@ env:
CARGO_TERM_COLOR: always

jobs:
executor-harness-windows:
name: Executor harness (Windows)
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: scripts/ado-script/package-lock.json
- name: Install workspace dependencies
working-directory: scripts/ado-script
run: npm ci
- name: Exercise cross-platform process fixtures
working-directory: scripts/ado-script
run: npm test -- runner.test.ts execute-cli.test.ts ado-rest.test.ts
ado-script:
name: Build, Test & Drift-Check
runs-on: ubuntu-latest
Expand Down
40 changes: 34 additions & 6 deletions .github/workflows/pr-data-prefetch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,25 +55,53 @@ jobs:
set -euo pipefail
mkdir -p /tmp/gh-aw/agent

gh pr view "$PR_NUMBER" \
--repo "$TARGET_REPOSITORY" \
--json number,title,body,headRefName,headRefOid,baseRefOid,additions,deletions,changedFiles,files \
> /tmp/gh-aw/agent/pr-meta.json
HEAD_SHA=$(jq -er '.headRefOid' /tmp/gh-aw/agent/pr-meta.json)
BASE_SHA=$(jq -er '.baseRefOid' /tmp/gh-aw/agent/pr-meta.json)
if [ "$HEAD_SHA" != "$PR_HEAD_SHA" ]; then
echo "::error::PR head changed before prefetch; refusing to cache mismatched data."
exit 1
fi

# Exclusions must stay in sync with
# .github/workflows/shared/pr-diff-data-fetch.md — these are all
# generated artefacts, and line-commenting on them is pure noise.
gh pr diff "$PR_NUMBER" --repo "$TARGET_REPOSITORY" \
if ! gh pr diff "$PR_NUMBER" --repo "$TARGET_REPOSITORY" \
--exclude '**/*.lock.yml' \
--exclude 'scripts/ado-script/*.js' \
--exclude 'scripts/ado-script/test-bin/**' \
--exclude '**/*.gen.ts' \
--exclude '**/*.gen.json' \
--exclude '**/dist/**' \
--exclude 'Cargo.lock' \
> /tmp/gh-aw/agent/pr-diff.patch 2>/tmp/gh-aw/agent/pr-diff-error.txt; then
if ! grep -q 'diff exceeded the maximum number of lines' /tmp/gh-aw/agent/pr-diff-error.txt; then
cat /tmp/gh-aw/agent/pr-diff-error.txt >&2
exit 1
fi
[[ "$HEAD_SHA" =~ ^[a-fA-F0-9]{40}$ && "$BASE_SHA" =~ ^[a-fA-F0-9]{40}$ ]]
echo "::warning::PR exceeds GitHub's diff API limit; generating the full filtered diff from pinned Git objects."
OBJECTS=$(mktemp -d)
trap 'rm -rf -- "$OBJECTS"' EXIT
git init --bare --quiet "$OBJECTS"
AUTH=$(printf 'x-access-token:%s' "$GH_TOKEN" | base64 -w0)
GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0="http.${GITHUB_SERVER_URL}/.extraheader" \
GIT_CONFIG_VALUE_0="Authorization: Basic $AUTH" \
git --git-dir="$OBJECTS" -c credential.helper= -c http.followRedirects=false \
fetch --quiet --no-tags "${GITHUB_SERVER_URL}/${TARGET_REPOSITORY}.git" "$BASE_SHA" "$HEAD_SHA"
unset AUTH
git --git-dir="$OBJECTS" -c core.quotePath=false diff --no-ext-diff --no-textconv "$BASE_SHA...$HEAD_SHA" -- \
. ':(glob,exclude)**/*.lock.yml' ':(glob,exclude)scripts/ado-script/*.js' \
':(glob,exclude)scripts/ado-script/test-bin/**' ':(glob,exclude)**/*.gen.ts' \
':(glob,exclude)**/*.gen.json' ':(glob,exclude)**/dist/**' ':(exclude)Cargo.lock' \
> /tmp/gh-aw/agent/pr-diff.patch
fi
rm -f /tmp/gh-aw/agent/pr-diff-error.txt
LINES=$(wc -l < /tmp/gh-aw/agent/pr-diff.patch)

gh pr view "$PR_NUMBER" \
--repo "$TARGET_REPOSITORY" \
--json number,title,body,headRefName,headRefOid,additions,deletions,changedFiles,files \
> /tmp/gh-aw/agent/pr-meta.json

gh api "repos/$TARGET_REPOSITORY/pulls/$PR_NUMBER/comments" \
--paginate \
--jq '.[] | {id, path, line: (.line // .original_line), body: .body[:200], user: .user.login}' \
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-sous-chef.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 3 additions & 2 deletions .github/workflows/pr-sous-chef.md
Original file line number Diff line number Diff line change
Expand Up @@ -269,7 +269,9 @@ a manual invocation is an acknowledgement, not a licence to clean up reviews.
- the rest by most recent `updatedAt`.
Break ties by lower PR number, so reruns behave deterministically.
6. Use the `pr-processor` sub-agent for each PR, passing only the PR number and
its compact entry.
its compact entry. Do not specify a model or model alias when launching the
sub-agent. Omit the model parameter so it inherits the parent/runtime model
selection.
7. If `pr-processor` returns non-JSON or errors, record
`{pr_number: N, skip_reason: "sub_agent_error"}` in the report and move on.
Do not retry.
Expand Down Expand Up @@ -368,7 +370,6 @@ recommendations visible; wrap verbose detail in
## agent: `pr-processor`
---
description: Decides skip/nudge actions for a single pull request using a minimal number of API calls
model: small
---
You are given one PR number and its compact metadata. Decide what should happen
to it, using as few tool calls as possible.
Expand Down
Loading
Loading