You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[windows-integration] Replace direct gh issue create in Windows integration conclusion job with safe output compatible issue signaling #59882
The workflow .github/workflows/windows-cli-integration.yml is mostly aligned with the required behavior (daily schedule + manual trigger, multi-job orchestration, Linux build + artifact upload, Windows matrix/chaos integration checks, timeout/hang detection, and if: always() conclusion gating), but it has one critical mismatch for this environment and policy: it creates failure issues via direct gh issue create in the workflow.
Problem
The conclusion job currently runs:
gh issue create ...
In this execution model, GitHub writes must use safe-output tooling. Direct gh writes are not guaranteed/allowed for this class of automation. This can make failure reporting unreliable right where it is most needed.
Required update
Update the conclusion issue-creation step in .github/workflows/windows-cli-integration.yml to use the repository’s approved write path for issue creation (safe-output-compatible mechanism used by this project’s workflow system), while preserving existing behavior:
keep if: always() conclusion orchestration
preserve failed-jobs aggregation and explicit final pass/fail exit
preserve issue content quality (failed jobs + run URL + UTC timestamp)
keep minimal explicit permissions
Acceptance criteria
When build or integration is non-success, conclusion still fails the workflow.
A failure issue is created through the approved safe-output path, not direct gh issue create.
Issue body still includes failed jobs and run link for debugging.
No unrelated workflow behavior changes.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
ab.chatgpt.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
The workflow
.github/workflows/windows-cli-integration.ymlis mostly aligned with the required behavior (daily schedule + manual trigger, multi-job orchestration, Linux build + artifact upload, Windows matrix/chaos integration checks, timeout/hang detection, andif: always()conclusion gating), but it has one critical mismatch for this environment and policy: it creates failure issues via directgh issue createin the workflow.Problem
The
conclusionjob currently runs:gh issue create ...In this execution model, GitHub writes must use safe-output tooling. Direct
ghwrites are not guaranteed/allowed for this class of automation. This can make failure reporting unreliable right where it is most needed.Required update
Update the conclusion issue-creation step in
.github/workflows/windows-cli-integration.ymlto use the repository’s approved write path for issue creation (safe-output-compatible mechanism used by this project’s workflow system), while preserving existing behavior:if: always()conclusion orchestrationAcceptance criteria
buildorintegrationis non-success, conclusion still fails the workflow.gh issue create.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
ab.chatgpt.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.