Repository navigation
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
Attempt-dependent local prefixes cause partial reruns to request artifacts that successful upstream jobs never uploaded.
1 open finding
What changed in this PR
This PR makes compiled reusable workflows more resilient to GHES secret masking of cross-job outputs, addressing #38345.
Changes:
- Compute artifact prefixes locally in downstream jobs.
- Resolve target repositories locally with activation and GitHub-context fallbacks.
- Restore development-mode setup actions after workspace replacement and update regression tests.
| File | Description |
|---|---|
| pkg/workflow/threat_detection_job_test.go | Expect local detection artifact prefixes. |
| pkg/workflow/safe_outputs_jobs.go | Use repository-name fallbacks for App tokens. |
| pkg/workflow/safe_outputs_config_runtime.go | Add dispatch repository fallbacks. |
| pkg/workflow/safe_output_helpers_test.go | Expect local agent artifact prefixes. |
| pkg/workflow/safe_jobs.go | Add local setup and development-mode restoration. |
| pkg/workflow/safe_jobs_test.go | Check prefix computation before downloads. |
| pkg/workflow/publish_code_coverage.go | Initialize local coverage artifact prefixes. |
| pkg/workflow/publish_code_coverage_test.go | Check coverage setup ordering. |
| pkg/workflow/notify_comment_work_queue_test.go | Update work-queue artifact expectations. |
| pkg/workflow/notify_comment_test.go | Update conclusion artifact expectations. |
| pkg/workflow/notify_comment_conclusion_helpers.go | Add conclusion App repository fallbacks. |
| pkg/workflow/github_app_owner_derivation.go | Use resilient repository expressions. |
| pkg/workflow/github_app_owner_derivation_test.go | Update repository fallback assertions. |
| pkg/workflow/create_code_scanning_alert.go | Add local setup and action restoration. |
| pkg/workflow/compiler_yaml_step_generation.go | Generate downstream prefix and repository steps. |
| pkg/workflow/compiler_yaml_checkout.go | Use repository fallbacks for checkout. |
| pkg/workflow/compiler_workflow_call.go | Centralize local prefix and repository expressions. |
| pkg/workflow/compiler_workflow_call_test.go | Test downstream setup generation. |
| pkg/workflow/compiler_safe_outputs_steps.go | Add mention-token repository fallbacks. |
| pkg/workflow/compiler_safe_outputs_job.go | Update downloads, token fallbacks, and setup ordering. |
| pkg/workflow/compiler_safe_outputs_job_test.go | Check local resolution and restoration ordering. |
| pkg/workflow/compiler_main_job_helpers.go | Expose the agent’s locally computed prefix. |
| pkg/workflow/compiler_experiments_test.go | Expect local experiment artifact prefixes. |
| pkg/workflow/agentic_output_test.go | Update mention-token fallback expectations. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| func (c *Compiler) generateSetupStepForJob(jobName string, data *WorkflowData, setupActionRef string, destination string, enableArtifactClient bool, traceID string, parentSpanID string, artifactClientCondition string) []string { | ||
| steps := c.generateSetupStepWithArtifactClientCondition(data, setupActionRef, destination, enableArtifactClient, traceID, parentSpanID, artifactClientCondition) | ||
| if data != nil && hasWorkflowCallTrigger(data.On) && jobName != "activation" && jobName != "pre_activation" { | ||
| steps = append(steps, generateArtifactPrefixStep()...) |
There was a problem hiding this comment.
The GHES path now uses retry-stable prefixes, while non-GHES jobs continue to consume the producer’s prefix output. I added a regression test for attempts 1 and 2. Fixed in d024eb1.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: d2cf978
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…put-masking Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot enable this mode when ghes: true |
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…put-masking Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

GHES can blank activation outputs whose values match registered secrets. Downstream jobs then request unprefixed artifacts or receive an empty target repository, even when the activation outputs are declared.
${{ steps.artifact-prefix.outputs.prefix }}agentrather than a cross-job prefix output.