Require verified SHAs in issue-triage permalinks - #14343
Merged
Merged
Conversation
Prevent issue-triage comments from constructing source links with fabricated or malformed revisions. Require the agent to obtain every permalink SHA directly from a GitHub tool response instead of inventing, inferring, abbreviating, or manually altering it. Before citing source, require a second verification step that fetches the referenced file at the exact returned SHA and confirms the cited code and line range exist in that revision. If available tools cannot establish both the revision and cited lines, instruct the agent to omit the source-code claim rather than emit an invalid or unverifiable link. Reinforce the same invariant in the final comment requirements and regenerate the compiled workflow metadata with gh-aw v0.87.5. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
All reviewed changes are consistent and have no unresolved issues.
Review tier: Balanced
Findings: None
What changed in this PR
Strengthens issue-triage citations by requiring verified, immutable commit SHAs and line ranges.
Changes:
- Requires SHAs from GitHub tool responses.
- Omits unverifiable source-code claims.
- Updates generated workflow metadata.
| File | Description |
|---|---|
.github/workflows/issue-triage.md |
Adds permalink provenance and verification requirements. |
.github/workflows/issue-triage.lock.yml |
Updates the generated workflow body hash. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The issue-triage agent can produce invalid source-code permalinks by making up the commit SHA used in the URL. This change requires every permalink SHA to come directly from a GitHub tool response and prohibits inventing, inferring, abbreviating, or manually altering it.
Before posting a source link, the agent must fetch the cited file at that exact SHA and verify that the referenced code and line range exist in that revision. If the available tools cannot verify both the revision and cited lines, the agent must omit the source-code claim instead of emitting an invalid link.
The generated issue-triage workflow metadata is updated with gh-aw v0.87.5.
How did you test this change?
I compiled the issue-triage workflow with gh-aw v0.87.5 and saw one workflow validate successfully. I ran the repository whitespace check and saw no errors, and editor diagnostics reported no problems in the source or generated workflow. I did not exercise the changed behavior against a live issue because the workflow would post a triage comment.
The compiler continued to report the existing
tools.github.min-integritywarning; this change does not alter tool permissions.Key points
Notes for reviewers
Start with
.github/workflows/issue-triage.md. The only generated change in.github/workflows/issue-triage.lock.ymlis the workflow body hash.Authorship and follow-up
Who wrote this:
Who answers review comments: