You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Enrich dependency alerts with Copilot compatibility assessments - #33
Enrich critical-dependency issues with upstream release highlights, skill-specific notes, explicit verification status, and focused follow-up checks. Retry missing or malformed Copilot assessments on existing issues.
Run pinned Copilot CLI with read-only tools for each new issue or manual reassessment. Validate required sections, compatibility status, and the 500-word limit before a separate least-privilege publisher updates its own marked comment.
Harden gh skill install calls: put selectors after --, pass --pin=<ref> safely, treat --upstream as a boolean flag, and place @VERSION on a skill selector rather than a repository. Update TUI and CLI call sites.
Add a live gh skill list --json contract check and update automation documentation.
Verification
Node monitor and assessment tests: 9 passed.
Real gh 2.102.0 contract tests: 7 passed; all 48 install-agent IDs match the catalog.
Focused install/parser tests: 44 passed. Release build: zero warnings or errors.
Sanitize upstream @mentions in generated issue highlights
.github/scripts/critical-dependencies.js:63
Unlike releaseOverview, this copies matching upstream text into an issue without neutralizing @mentions. Release notes commonly credit contributors, so a relevant paragraph can make the monitor notify unrelated upstream users or teams from the generated SkillView issue. Apply the same mention sanitization before storing the highlight.
Pass repository refs via --pin instead of positional parsing
gh skill install does not parse a ref from the repository positional; refs are accepted as SKILL@ref or via --pin. Consequently, a versioned listing passes owner/repo@ref to repository parsing and can fail instead of listing that ref. Since this path has no skill positional, pass --pin=<ref> before the separator and keep the repository unchanged.
This issue also appears on line 302 of the same file.
This checks for a verdict anywhere in the generated text, not specifically in ### Compatibility assessment, and does not enforce the requested single verdict. For example, a release-summary sentence containing **Likely compatible** lets an unsupported assessment such as “Probably fine” pass validation and be published. Validate exactly one allowed verdict and require it to occur in the compatibility section.
Marker matching accepts comments from non-workflow authors
.github/workflows/critical-dependencies.yml:133
The marker alone does not prove that the existing comment belongs to this workflow. Any issue participant can post or quote this public marker first, causing a rerun to target an unrelated user's comment (either overwriting it or failing authorization) instead of maintaining the workflow's own assessment. Restrict the match to the GitHub Actions bot author.
Versioned discovery passes ref as repository instead of --pin
Versioned discovery still puts @<ref> on the repository argument. In both supported gh 2.97.0 and 2.102.0, the first positional is parsed strictly as the repository, while a ref is selected via --pin <ref> (or via skill@version when a skill exists). Thus ListRepoSkillsAsync(..., "v1.2.0") asks gh for a repository literally named repo@v1.2.0 and fails instead of listing that ref. Pass the version as the trusted --pin value before the separator and keep the repository unchanged.
This issue also appears on line 301 of the same file.
The verdict regex scans the entire response, so malformed output is accepted when an allowed phrase appears in another section while ### Compatibility assessment contains no required verdict. Validate exactly one allowed verdict at the start of the extracted compatibility section before publishing.
Sanitize contributor mentions in copied release highlights
.github/scripts/critical-dependencies.js:68
Relevant excerpts are copied verbatim, so a normal generated release-note bullet such as ... by @contributor pings that upstream user when this workflow opens its issue. releaseOverview already neutralizes these mentions; apply equivalent sanitization here before embedding highlights.
The verdict regex scans the whole assessment rather than the compatibility section. For example, an **Unknown** quoted under “What changed” lets an assessment whose compatibility section has no verdict pass validation and be published. Require exactly one allowed verdict and require it at the start of sections[2].
Only edit bot-authored comments; otherwise create a new comment
.github/workflows/critical-dependencies.yml:133
The first marked comment may be user-authored. In that case the workflow tries to edit a comment it does not own, receives a permission error, and never publishes the assessment. Restrict replacement to the workflow bot's marked comment; otherwise create a new one.
Reject mutually exclusive flags before environment probing
src/SkillView.Core/Cli/CliDispatcher.cs:751
The boolean parser allows --from-local and --upstream together, and the updated parser test even constructs that combination. Every supported gh version rejects these flags as mutually exclusive, so the CLI performs environment/inventory work only to fail in the subprocess. Return invalid usage before probing, and keep this validation aligned with the TUI/service path.
Disable upstream mode when local mode is selected
src/SkillView.Core/Ui/InstallScreen.cs:313
This checkbox value is passed independently of FromLocal, so selecting both produces a command that gh rejects because --upstream and --from-local are mutually exclusive. Disable and clear the upstream checkbox while local mode is selected (and enforce the same invariant at the service/CLI boundary) instead of allowing an install that is guaranteed to fail.
The allowed-status regex scans the entire output, so **Unknown** in “What changed” lets an arbitrary value such as “Probably compatible” pass in the actual compatibility section. Validate that exactly one allowed status occurs and that it belongs to sections[2] before publishing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
gh skill installcalls: put selectors after--, pass--pin=<ref>safely, treat--upstreamas a boolean flag, and place@VERSIONon a skill selector rather than a repository. Update TUI and CLI call sites.gh skill list --jsoncontract check and update automation documentation.Verification
gh2.102.0 contract tests: 7 passed; all 48 install-agent IDs match the catalog.Related: #31