Skip to content

[windows-integration] Update windows-cli-integration workflow to use safeoutputs-compatible issue reporting and harden matrix coverage checks #59632

Description

@github-actions

The current .github/workflows/windows-cli-integration.yml is close to target, but it still needs focused updates to fully satisfy the required behavior and repository execution constraints.

Why change is needed

  • The conclusion job currently creates issues with gh issue create.
  • In this environment, GitHub writes must be declared via safe-output tooling, and gh write-path assumptions are not reliable in cloud-agent runs.
  • A few assertions should be made more explicit in step summaries to keep failures fast and debuggable for matrix scenarios.

Required updates

  • Replace the direct gh issue create call in conclusion with a repository-approved safe-output path for issue creation.
  • Keep the existing if: always() conclusion orchestration and final failure gate (exit 1) intact.
  • Preserve minimal explicit permissions and SHA-pinned actions.
  • Ensure matrix/chaos scenario failures keep clear, single-line diagnostics in step summary for:
    • shell variant
    • launch mode
    • env shape
    • path style
    • timeout/failure reason

Acceptance criteria

  • Workflow still triggers on daily schedule and workflow_dispatch.
  • Build job still runs on ubuntu-latest, cross-compiles gh-aw.exe, uploads artifact.
  • Integration job still runs on windows-latest, downloads artifact, executes systematic matrix across shell × launch mode × env shape × path style.
  • Timeout protection remains in place for integration invocations and ConPTY probes.
  • At least one intentional negative/chaos validation remains and fails fast with explicit error text.
  • Conclusion job always runs, aggregates prior job outcomes, and fails the workflow if required jobs fail.
  • Failure issue creation path is updated to an approved/compatible mechanism for this repo’s agentic constraints.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by 🪟 Daily Windows Terminal Integration Builder · codex · gpt53codex · 7.68 AIC · ⌖ 2.84 AIC · ⊞ 14.8K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions