Repository navigation
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Nested rationale length constraints remain unenforced, and retry guidance can suggest payloads rejected by the configured schema.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds workflow-defined narrowing for add_labels item schemas across compilation, MCP tooling, validation, and documentation.
Changes:
- Adds and validates
add-labels.item-schema. - Merges workflow constraints into generated MCP schemas.
- Improves validation guidance and documents structured label behavior.
| File | Description |
|---|---|
pkg/workflow/safe_outputs_handler_registry_issues.go |
Serializes item schemas into handler configuration. |
pkg/workflow/add_labels.go |
Adds the item-schema configuration field. |
pkg/workflow/add_labels_item_schema_test.go |
Tests configuration extraction and serialization. |
pkg/parser/schemas/main_workflow_schema.json |
Defines allowed narrowing syntax. |
pkg/parser/schema_add_labels_item_schema_test.go |
Tests accepted and rejected schemas. |
docs/src/content/docs/reference/safe-outputs.md |
Documents item schemas and removal behavior. |
actions/setup/js/mcp_server_core.cjs |
Passes effective schemas to error formatting. |
actions/setup/js/mcp_scripts_validation.test.cjs |
Tests workflow-specific required fields. |
actions/setup/js/mcp_scripts_validation.cjs |
Formats schema-aware validation errors. |
actions/setup/js/generate_safe_outputs_tools.test.cjs |
Tests schema merging. |
actions/setup/js/generate_safe_outputs_tools.cjs |
Applies narrowed schemas to MCP tools. |
| for (const [name, propertySchema] of Object.entries(configuredProperties)) { | ||
| properties[name] = { ...(properties[name] ?? {}), ...propertySchema }; |
| ` ${error.path} must be an object (string shorthand is not supported).`, | ||
| ' Expected: {"name":"bug","rationale":"Why this label applies","confidence":"HIGH"}', | ||
| " Required fields: name, rationale, confidence", | ||
| ` Required fields: ${Array.isArray(requiredFields) ? requiredFields.join(", ") : "name, rationale, confidence"}`, |
|
@copilot Please move this PR forward. Open review feedback remains from: copilot-pull-request-reviewer. Please refresh the branch if needed, address the outstanding review comments, and run the Outstanding themes to finish:
Warning Firewall blocked 4 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"
- "proxy.golang.org"
- "registry.npmjs.org"
- "storage.googleapis.com"See Network Configuration for more information.
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Both outstanding review themes are addressed in
Tests added for nested
Correction: the commit hash is |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
Great work on enhancing safe-output schema validation! This PR looks ready for review. You've included comprehensive test coverage (4 test files), updated documentation, and the changes are tightly focused on schema narrowing and enforcement. The implementation properly merges workflow constraints with built-in schemas and validates both MCP tool definitions and runtime calls. Well done! Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|

Safe-output tools exposed permissive built-in schemas even when workflows required stricter inputs. Invalid calls were therefore rejected only after agent execution, preventing retries and discarding otherwise valid output.
Schema configuration
safe-outputs.add-labels.item-schema.Runtime enforcement
Documentation
remove_labelsignoresrationale,confidence, andsuggest.add_labels) #62994Warning
Firewall blocked 4 domains
The following domains were blocked by the firewall during workflow execution:
github.comproxy.golang.orgregistry.npmjs.orgstorage.googleapis.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.