Repository navigation
Allow allow-listed GitHub Apps to check out same-repository PRs after comment triggers - #67247
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
Exact actor comparisons break the supported equivalence between App slugs and their [bot] identities.
1 open finding
What changed in this PR
Enables allowlisted GitHub Apps to check out same-repository PR branches after comment-triggered workflows.
Changes:
- Passes
on.botsinto the checkout step. - Adds guarded bot authorization and regression tests.
- Documents the checkout policy.
| File | Description |
|---|---|
actions/setup/js/checkout_pr_branch.cjs |
Adds allowlisted-bot checkout authorization. |
actions/setup/js/checkout_pr_branch.test.cjs |
Tests allowed and denied scenarios. |
pkg/workflow/pr.go |
Emits the bot allowlist environment variable. |
pkg/workflow/pr_test.go |
Tests allowlist emission. |
docs/src/content/docs/reference/triggers.md |
Documents the authorization boundary. |
🧠 Review effort: Balanced
| context.payload.sender?.login === actor && | ||
| context.payload.comment?.user?.login === actor && |
There was a problem hiding this comment.
Fixed in 7232560. Sender and comment-author logins must still match exactly; their identity is now compared canonically to the runtime actor using the existing slug/[bot] helper. Regression tests cover both forms for both comment events, mismatched actors, and differing sender/author login forms. All 243 checkout/permission tests pass.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 2b19291
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…ranch-bot-permission-fix Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged main with make merge-main (9a031a3) and pushed the identity fix plus all five CI failure fixes in 7232560. Local make lint, final progress gate, full workflow/workqueue Go tests, JS shard 4 (4,240 tests), queue compilation phases, and integration build pass. Replied to the listed review thread; marking it resolved requires manual action because no thread-resolution mutation is available here. Fallback code review found no significant issues; CodeQL timed out. CI on the new HEAD remains unverified; no CI was triggered. |
|
@copilot do a DevOps secops review, update compiler threat specs |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Updated the compiler threat spec/changelog and aligned RS-05a plus its unit-test/Z3 evidence. The security review found no vulnerabilities; focused tests, the final progress gate, and all modeled Z3 queries pass. Commit: |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: dab80d3
|
…ranch-bot-permission-fix # Conflicts: # pkg/workflow/agy_engine_test.go # pkg/workqueue/replay.go Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged latest |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 2de5633
|
…ranch-bot-permission-fix # Conflicts: # actions/setup/js/work_queue_issues_checks.cjs # pkg/workflow/agy_engine_test.go Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot resolve the merge conflicts in this pull request |
Merged the latest |
The merge conflicts are resolved in merge commit |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 26b04e7
|
…ranch-bot-permission-fix # Conflicts: # actions/setup/js/work_queue_compaction.test.cjs Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged latest |
|
@copilot add conformance tests, update TLA+ specs |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Added the comment-checkout conformance matrix for both event types and the TLA+ policy model with six guard-bypass negative controls. The baseline and all negative controls passed. Commit: |

A GitHub App listed in
on.botscan activate a comment-triggered workflow, but PR checkout rejects it because Apps are not repository collaborators.on.botsto the checkout step. Forissue_commentandpull_request_review_comment, bypass the collaborator check only when the allow-listed Bot authored the comment and the PR head and base repository IDs match the workflow repository.