diff --git a/.github/workflows/update-docs-agent.lock.yml b/.github/workflows/update-docs-agent.lock.yml index 0419aa3..90f02a8 100644 --- a/.github/workflows/update-docs-agent.lock.yml +++ b/.github/workflows/update-docs-agent.lock.yml @@ -25,7 +25,7 @@ # e2e/, Makefile, and .github/workflows, then updates matching documentation while # preserving the project's style and single-source-of-truth rules. # -# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"d7c22a35600664358894b276276c2e8248646c24ee6477dd61d4a4ebdf1b8d7c","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} +# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"eeebb8bf41f8a6f268d0ca98416de3b3ad165774b558b769505ce19a22847c1b","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} name: "Update ProcLens Docs" "on": @@ -54,8 +54,8 @@ jobs: activation: needs: pre_activation if: > - needs.pre_activation.outputs.activated == 'true' && ((github.actor != 'github-actions[bot]') && (github.event_name != 'pull_request' || - github.event.pull_request.head.repo.id == github.repository_id)) + needs.pre_activation.outputs.activated == 'true' && ((github.actor != 'github-actions[bot]' && github.actor != 'Copilot') && + (github.event_name != 'pull_request' || github.event.pull_request.head.repo.id == github.repository_id)) runs-on: ubuntu-slim permissions: contents: read @@ -159,19 +159,19 @@ jobs: run: | bash ${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh { - cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' + cat << 'GH_AW_PROMPT_3edf27c1b627f94a_EOF' - GH_AW_PROMPT_c1d3f941fb7ad28a_EOF + GH_AW_PROMPT_3edf27c1b627f94a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' + cat << 'GH_AW_PROMPT_3edf27c1b627f94a_EOF' Tools: create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_c1d3f941fb7ad28a_EOF + GH_AW_PROMPT_3edf27c1b627f94a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' + cat << 'GH_AW_PROMPT_3edf27c1b627f94a_EOF' The following GitHub context information is available for this workflow: @@ -201,12 +201,12 @@ jobs: {{/if}} - GH_AW_PROMPT_c1d3f941fb7ad28a_EOF + GH_AW_PROMPT_3edf27c1b627f94a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' + cat << 'GH_AW_PROMPT_3edf27c1b627f94a_EOF' {{#runtime-import .github/workflows/update-docs-agent.md}} - GH_AW_PROMPT_c1d3f941fb7ad28a_EOF + GH_AW_PROMPT_3edf27c1b627f94a_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 @@ -363,12 +363,12 @@ jobs: mkdir -p ${RUNNER_TEMP}/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_c5123daebf6c6de9_EOF' + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_11833459904221b6_EOF' {"create_pull_request":{"draft":false,"labels":["automation","documentation"],"max":1,"max_patch_size":1024,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS"],"protected_files_policy":"fallback-to-issue","protected_path_prefixes":[".github/",".agents/"]},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"}} - GH_AW_SAFE_OUTPUTS_CONFIG_c5123daebf6c6de9_EOF + GH_AW_SAFE_OUTPUTS_CONFIG_11833459904221b6_EOF - name: Write Safe Outputs Tools run: | - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_fcf08ae320930597_EOF' + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_43690b4187196bf1_EOF' { "description_suffixes": { "create_pull_request": " CONSTRAINTS: Maximum 1 pull request(s) can be created. Labels [\"automation\" \"documentation\"] will be automatically added." @@ -376,8 +376,8 @@ jobs: "repo_params": {}, "dynamic_tools": [] } - GH_AW_SAFE_OUTPUTS_TOOLS_META_fcf08ae320930597_EOF - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_bb4240b2c6fd8e45_EOF' + GH_AW_SAFE_OUTPUTS_TOOLS_META_43690b4187196bf1_EOF + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_4e3908e9ced5b60c_EOF' { "create_pull_request": { "defaultMax": 1, @@ -473,7 +473,7 @@ jobs: } } } - GH_AW_SAFE_OUTPUTS_VALIDATION_bb4240b2c6fd8e45_EOF + GH_AW_SAFE_OUTPUTS_VALIDATION_4e3908e9ced5b60c_EOF node ${RUNNER_TEMP}/gh-aw/actions/generate_safe_outputs_tools.cjs - name: Generate Safe Outputs MCP Server Config id: safe-outputs-config @@ -541,7 +541,7 @@ jobs: export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network host -v /var/run/docker.sock:/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e GH_AW_SAFE_OUTPUTS_PORT -e GH_AW_SAFE_OUTPUTS_API_KEY -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw ghcr.io/github/gh-aw-mcpg:v0.2.11' mkdir -p /home/runner/.copilot - cat << GH_AW_MCP_CONFIG_79fbfcb06dda8f41_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh + cat << GH_AW_MCP_CONFIG_43c379fc3592088f_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh { "mcpServers": { "github": { @@ -582,7 +582,7 @@ jobs: "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}" } } - GH_AW_MCP_CONFIG_79fbfcb06dda8f41_EOF + GH_AW_MCP_CONFIG_43c379fc3592088f_EOF - name: Download activation artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: @@ -1039,7 +1039,8 @@ jobs: pre_activation: if: > - (github.actor != 'github-actions[bot]') && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.id == github.repository_id) + (github.actor != 'github-actions[bot]' && github.actor != 'Copilot') && (github.event_name != 'pull_request' || + github.event.pull_request.head.repo.id == github.repository_id) runs-on: ubuntu-slim outputs: activated: ${{ steps.check_membership.outputs.is_team_member == 'true' }} diff --git a/.github/workflows/update-docs-agent.md b/.github/workflows/update-docs-agent.md index 0d85286..9f81dd3 100644 --- a/.github/workflows/update-docs-agent.md +++ b/.github/workflows/update-docs-agent.md @@ -11,7 +11,7 @@ on: types: [closed] workflow_dispatch: -if: github.actor != 'github-actions[bot]' +if: github.actor != 'github-actions[bot]' && github.actor != 'Copilot' permissions: read-all diff --git a/docs/AGENTIC_WORKFLOW.md b/docs/AGENTIC_WORKFLOW.md index ea886d2..cf97e28 100644 --- a/docs/AGENTIC_WORKFLOW.md +++ b/docs/AGENTIC_WORKFLOW.md @@ -8,7 +8,7 @@ The workflow: - Monitors repository changes when pull requests are closed into main - Maps code/process changes to the correct docs files - Opens a pull request with documentation updates when needed -- Skips self-trigger loops from github-actions bot +- Skips self-trigger loops from github-actions[bot] and Copilot actors This is intentionally high-level. Detailed behavior and policy live in the workflow source file: - `.github/workflows/update-docs-agent.md` @@ -67,7 +67,7 @@ git diff -- .github/workflows/update-docs-agent.md .github/workflows/update-docs Validate expected event behavior in Actions: - Automatic run on pull_request closed targeting main - No automatic run on push -- No run when actor is github-actions[bot] +- No run when actor is github-actions[bot] or Copilot A practical test sequence: 1. Open a test PR against main