Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/copilot-cli-safeoutputs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ on:
pull_request:
paths:
- "src/**"
- "scripts/ado-script/**"
- "tests/**"
- "Cargo.toml"
- "Cargo.lock"
Expand Down Expand Up @@ -62,6 +63,12 @@ jobs:
mcpg:MCPG_VERSION:src/compile/common.rs
VERSIONS

- name: Build Copilot invoker bundle
run: |
set -euo pipefail
npm --prefix scripts/ado-script ci
npm --prefix scripts/ado-script run build:copilot-invoker

- name: Install compiler-pinned GitHub Copilot CLI
run: |
set -euo pipefail
Expand Down Expand Up @@ -111,6 +118,7 @@ jobs:
ADO_AW_BIN: ${{ github.workspace }}/target/debug/ado-aw
AWF_BIN: ${{ runner.temp }}/bin/awf
COPILOT_BIN: ${{ runner.temp }}/bin/copilot
COPILOT_INVOKER_BUNDLE: ${{ github.workspace }}/scripts/ado-script/copilot-invoker.js
AWF_VERSION: ${{ steps.versions.outputs.awf }}
MCPG_VERSION: ${{ steps.versions.outputs.mcpg }}
run: bash tests/awf-copilot-safeoutputs/run.sh
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-sous-chef.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/pr-sous-chef.md
Original file line number Diff line number Diff line change
Expand Up @@ -368,7 +368,6 @@ recommendations visible; wrap verbose detail in
## agent: `pr-processor`
---
description: Decides skip/nudge actions for a single pull request using a minimal number of API calls
model: small
---
You are given one PR number and its compact metadata. Decide what should happen
to it, using as few tool calls as possible.
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/review-rust.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/review-rust.md
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,6 @@ and the themes in a `<details>` block.
## agent: `rust-critic`
---
description: Hostile first-pass Rust reviewer that mines merge-blocking defects from changed lines
model: small
---
You are a hostile senior Rust reviewer performing a first-pass audit.

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/review-typescript.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/review-typescript.md
Original file line number Diff line number Diff line change
Expand Up @@ -171,7 +171,6 @@ wrong output; otherwise `COMMENT`.
## agent: `ts-critic`
---
description: Hostile first-pass TypeScript reviewer for bundled Azure DevOps runtime helpers
model: small
---
You are a hostile senior TypeScript reviewer performing a first-pass audit of
code that is bundled and executed on Azure DevOps build agents.
Expand Down
3 changes: 2 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -319,6 +319,7 @@ fail-closed and only pauses when the agent actually proposed a reviewed output.
│ ├── conclusion/ # Conclusion-job reporter source (bundled to conclusion.js)
│ ├── approval-summary/ # Safe-outputs summary renderer (bundled to approval-summary.js; end-of-Agent-job summary tab)
│ ├── github-app-token/ # GitHub App token minter (bundled to github-app-token.js; mints installation token in Agent + Detection when engine.github-app-token is set)
│ ├── copilot-invoker/ # Sandboxed Copilot process harness (bundled to copilot-invoker.js): strict versioned invocation/result documents, runtime model resolution, typed argv, signal forwarding, exact exit propagation
│ ├── executor-e2e/ # Stage 3 safe-output E2E test harness (not a bundle; runs deterministic scenarios against a real ADO project and files a GitHub issue on failure)
│ ├── compiler-smoke-e2e/ # Smoke E2E orchestrator (not a bundle): stages each case in `tests/smoke/cases.json` to the fixed `.smoke/pipeline.yml` path on its own per-case `ado-aw-mirror` ref, queues it against its credential *lane* definition, and asserts they go green. Two modes via `SMOKE_COMPILER_SOURCE`: `candidate` (compiler built from this commit, pinned pipeline-artifact) and `released` (latest release asset, release URLs required). Built to `test-bin/` by `build:compiler-smoke-e2e`, listed in `NON_BUNDLE_DIRS`.
│ ├── prepare-pr-base/ # create-pull-request preparer (bundled to prepare-pr-base.js): Agent mode uses ADO diff metadata + bounded fallback; SafeOutputs fetches the target tip; cross-org targets use isolated credentials + exact remote matching
Expand Down Expand Up @@ -463,7 +464,7 @@ index to jump to the right page.
(`gate.js`, `import.js`, the execution-context `exec-context-*.js`
bundles, `conclusion.js`, `approval-summary.js`,
`github-app-token.js`, `prepare-pr-base.js`, and
`azure-wif-refresh.js`), schemars-driven
`azure-wif-refresh.js`, `copilot-invoker.js`), schemars-driven
type codegen, the A2 design decision, the bundle env contract
modelled in `src/compile/ado_bundle.rs`, and the `trigger-e2e/`
gate-spec drift guard (kept in sync via `export-fact-catalog`).
Expand Down
Loading
Loading