Skip to content

fix(workflows): use copilot-requests auth for PR Quality Signal Review - #3722

Open
aaronpowell wants to merge 1 commit into
mainfrom
aaronpowell-fix-pr-quality-signal-review
Open

aaronpowell wants to merge 1 commit into
mainfrom
aaronpowell-fix-pr-quality-signal-review

Conversation

@aaronpowell

Copy link
Copy Markdown
Contributor

Fixes #3669

Root cause

The agent job in run 35807196722 exited before starting Copilot:

awf-reflect: models fetch returned 401 for http://api-proxy:10002/models
copilot model alias resolution failed: model-catalog retrieval prevented alias resolution for 'auto' ... refusing to start Copilot with an unresolved alias

pr-quality-signal.md didn't set copilot-requests: write, so the engine used the COPILOT_GITHUB_TOKEN secret, and that token got a 401. The repo's other agentic workflows (for example pr-duplicate-check, which passes) set this permission and authenticate with the workflow GITHUB_TOKEN.

Fix

  • Added copilot-requests: write to permissions in .github/workflows/pr-quality-signal.md.
  • Recompiled with the same gh-aw version as the existing lock (v0.88.8), so the lock diff only contains the auth change.

Validation

  • gh aw compile pr-quality-signal: compiled with no errors or warnings.

The agent failed to resolve the 'auto' model alias because the
COPILOT_GITHUB_TOKEN secret returned 401 on the models endpoint.
Grant copilot-requests: write so the engine authenticates with the
workflow GITHUB_TOKEN, matching the other agentic workflows.

Fixes #3669

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 24, 2026 02:02
@github-actions github-actions Bot added the workflow PR touches workflow automation label Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🟡 Contributor Reputation Check: MEDIUM risk

Check Risk
Profile MEDIUM
Credential audit NONE

Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.

@github-actions github-actions Bot added the needs-review:MEDIUM Contributor reputation check flagged MEDIUM risk label Sep 24, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused authentication fix has no unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes Copilot authentication for the PR Quality Signal Review workflow.

Changes:

  • Adds copilot-requests: write.
  • Regenerates the lock file to use github.token.
File Description
.github/​workflows/​pr-quality-signal.md Adds the required Copilot permission.
.github/​workflows/​pr-quality-signal.lock.yml Updates the generated authentication configuration.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: ⏳ Awaiting automation

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • .github/workflows/pr-quality-signal.lock.yml is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • .github/workflows/pr-quality-signal.md is a high-risk path (automation, scripts, MCP config, hooks, or review policy)

Automated checks

Check Status Details
Line endings 🔧 Infrastructure failure Waiting for a maintainer to approve workflow runs for this PR · logs
Spelling 🔧 Infrastructure failure Waiting for a maintainer to approve workflow runs for this PR · logs
Submission gate tests 🔧 Infrastructure failure Waiting for a maintainer to approve workflow runs for this PR · logs
Contributor reputation 🔧 Infrastructure failure Waiting for a maintainer to approve workflow runs for this PR · logs
Duplicate resource scan ⚠️ Failed (advisory, non-blocking) Waiting for a maintainer to approve workflow runs for this PR · logs
PR quality signal ⚠️ Failed (advisory, non-blocking) Waiting for a maintainer to approve workflow runs for this PR · logs

Action needed

  • 🔧 Line endings, Spelling, Submission gate tests, Contributor reputation hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.
  • ⚠️ Advisory checks did not complete (Duplicate resource scan, PR quality signal). This does not block the PR.

Review

  • Approvals: 0/2
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for 47a9de4 · gate run · This comment is maintained automatically — see submission gate docs.

This branch was successfully deployed

1 active deployment
github-pages — 47a9de4a Deployed Sep 24, 2026 by aaronpowell via deploy #499
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting-automation merge-risk:high needs-review:MEDIUM Contributor reputation check flagged MEDIUM risk workflow PR touches workflow automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[aw] PR Quality Signal Review failed

2 participants