Repository navigation
Enrich dependency alerts with Copilot compatibility assessments #33
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
ac9b356
Enrich critical dependency alerts with Copilot assessments
harder 9498d8c
Guard gh skill install selectors against option injection
harder 68d7cee
Set supported Copilot CLI credit cap
harder 970fa38
Validate Copilot dependency assessments and secure pinned installs
harder 455acb7
Preserve failed Copilot output for diagnosis
harder 987be36
Handle Copilot review findings and assessment punctuation
harder f0bd6b1
Match gh upstream install flag and keep selectors behind separator
harder 7d2f890
Enforce Copilot assessment word limit
harder cc79920
Apply install version to skill selector or repository pin
harder 8acdba7
Retry unassessed dependency issues after partial monitor failures
harder 39570e6
Protect assessment ownership and versioned skill listings
harder 60814a9
Keep checkout credentials out of Copilot assessment workspace
harder b79c6fc
Retry malformed assessments and validate compatibility status
harder File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| # actionlint v1.7.12 predates GitHub's Copilot Requests token permission. | ||
| # Keep every other workflow check active, and remove this exception when | ||
| # actionlint adds the permission to its schema. | ||
| paths: | ||
| .github/workflows/critical-dependencies.yml: | ||
| ignore: | ||
| - '^unknown permission scope "copilot-requests"\.' |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,53 @@ | ||
| const fs = require('node:fs'); | ||
| const ASSESSMENT_MARKER = '<!-- skillview-copilot-assessment-v1 -->'; | ||
|
|
||
| function isOwnedAssessmentComment(comment) { | ||
| return comment?.user?.login === 'github-actions[bot]' && | ||
| comment.body?.includes(ASSESSMENT_MARKER) === true; | ||
| } | ||
|
|
||
| const headings = [ | ||
| '### What changed', | ||
| '### SkillView impact', | ||
| '### Compatibility assessment', | ||
| '### Focused follow-up', | ||
| ]; | ||
|
|
||
| function extractAssessment(raw) { | ||
| if (typeof raw !== 'string') return null; | ||
| // Copilot's silent text mode can include a planning message before its | ||
| // final answer. Publish only the requested, complete assessment. | ||
| const start = raw.lastIndexOf(headings[0]); | ||
| if (start < 0) return null; | ||
| const assessment = raw.slice(start).trim(); | ||
| if (assessment.length < 200 || assessment.length > 10000) return null; | ||
| if (assessment.split(/\s+/).length > 500) return null; | ||
| let previous = -1; | ||
| for (const heading of headings) { | ||
| const index = assessment.indexOf(heading); | ||
| if (index <= previous) return null; | ||
| previous = index; | ||
| } | ||
| const sections = headings.map((heading, index) => { | ||
| const from = assessment.indexOf(heading) + heading.length; | ||
| const to = index + 1 < headings.length | ||
| ? assessment.indexOf(headings[index + 1]) : assessment.length; | ||
| return assessment.slice(from, to).trim(); | ||
| }); | ||
| if (sections.some(section => section.length < 15)) return null; | ||
| const statuses = [...assessment.matchAll(/\*\*(Likely compatible|Potential break|Unknown)\.?\*\*/g)]; | ||
| if (statuses.length !== 1 || !/^\*\*(Likely compatible|Potential break|Unknown)\.?\*\*/.test(sections[2])) { | ||
| return null; | ||
| } | ||
| return assessment; | ||
| } | ||
|
|
||
| if (require.main === module) { | ||
| const [input, output] = process.argv.slice(2); | ||
| if (!input || !output) throw new Error('Expected input and output file paths'); | ||
| const assessment = extractAssessment(fs.readFileSync(input, 'utf8')); | ||
| if (!assessment) throw new Error('Copilot did not produce a complete assessment'); | ||
| fs.writeFileSync(output, `${assessment}\n`); | ||
| } | ||
|
|
||
| module.exports = { ASSESSMENT_MARKER, isOwnedAssessmentComment, extractAssessment }; |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.