Skip to content

Require verified SHAs in issue-triage permalinks - #14343

Merged
sergiou87 merged 1 commit into
trunkfrom
issue-triage-permalinks
Sep 4, 2026
Merged

sergiou87 merged 1 commit into
trunkfrom
issue-triage-permalinks

Conversation

@sergiou87

Copy link
Copy Markdown
Contributor

Description

The issue-triage agent can produce invalid source-code permalinks by making up the commit SHA used in the URL. This change requires every permalink SHA to come directly from a GitHub tool response and prohibits inventing, inferring, abbreviating, or manually altering it.

Before posting a source link, the agent must fetch the cited file at that exact SHA and verify that the referenced code and line range exist in that revision. If the available tools cannot verify both the revision and cited lines, the agent must omit the source-code claim instead of emitting an invalid link.

The generated issue-triage workflow metadata is updated with gh-aw v0.87.5.

How did you test this change?

I compiled the issue-triage workflow with gh-aw v0.87.5 and saw one workflow validate successfully. I ran the repository whitespace check and saw no errors, and editor diagnostics reported no problems in the source or generated workflow. I did not exercise the changed behavior against a live issue because the workflow would post a triage comment.

The compiler continued to report the existing tools.github.min-integrity warning; this change does not alter tool permissions.

Key points

  • Tool-returned SHAs are the only permitted revisions in generated permalinks.
  • Re-fetching the file at the exact SHA verifies both revision provenance and cited lines.
  • Omitting an unverifiable code claim is safer than replacing the immutable link with a branch URL or guessed SHA.

Notes for reviewers

Start with .github/workflows/issue-triage.md. The only generated change in .github/workflows/issue-triage.lock.yml is the workflow body hash.

Authorship and follow-up

Who wrote this:

  • A human wrote it.
  • An agent wrote it under close human direction.
  • An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

  • @sergiou87 will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted.
  • Nobody has explicitly committed to replying.

Prevent issue-triage comments from constructing source links with fabricated or malformed revisions. Require the agent to obtain every permalink SHA directly from a GitHub tool response instead of inventing, inferring, abbreviating, or manually altering it.

Before citing source, require a second verification step that fetches the referenced file at the exact returned SHA and confirms the cited code and line range exist in that revision. If available tools cannot establish both the revision and cited lines, instruct the agent to omit the source-code claim rather than emit an invalid or unverifiable link.

Reinforce the same invariant in the final comment requirements and regenerate the compiled workflow metadata with gh-aw v0.87.5.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 4, 2026 08:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All reviewed changes are consistent and have no unresolved issues.

Review tier: Balanced
Findings: None

What changed in this PR

Strengthens issue-triage citations by requiring verified, immutable commit SHAs and line ranges.

Changes:

  • Requires SHAs from GitHub tool responses.
  • Omits unverifiable source-code claims.
  • Updates generated workflow metadata.
File Description
.github/​workflows/​issue-triage.md Adds permalink provenance and verification requirements.
.github/​workflows/​issue-triage.lock.yml Updates the generated workflow body hash.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sergiou87
sergiou87 marked this pull request as ready for review September 4, 2026 09:01
@sergiou87
sergiou87 requested a review from a team as a code owner September 4, 2026 09:01
@sergiou87
sergiou87 requested a review from tidy-dev September 4, 2026 09:01
@sergiou87
sergiou87 merged commit 400c084 into trunk Sep 4, 2026
20 checks passed
@sergiou87
sergiou87 deleted the issue-triage-permalinks branch September 4, 2026 09:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants