Skip to content

Validate external safe-output secrets before activation - #60267

Merged
pelikhan merged 2 commits into
mainfrom
copilot/add-secrets-to-checks
Sep 11, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/add-secrets-to-checks

Conversation

Copilot AI commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Jira, Linear, and Azure DevOps safe outputs could fail after agent execution when required credentials were missing. This adds early activation checks with actionable configuration errors.

Changes

  • Secret requirements

    • Detect credentials required by enabled external safe-output handlers.
    • Validate Jira email/token, Linear API key, and Azure DevOps PAT.
    • Reuse the existing engine secret-validation mechanism.
  • Frontmatter overrides

    • Skip default checks when credentials are explicitly supplied through safe-outputs.env, linear-token, or a deployment environment.
  • Azure DevOps

    • Pass ${{ secrets.AZURE_DEVOPS_EXT_PAT }} to the safe-output processor by default.
    • Preserve explicit SYSTEM_ACCESSTOKEN and AZURE_DEVOPS_EXT_PAT overrides.
  • Failure reporting

    • Aggregate engine and safe-output validation failures into the activation result.
    • Clarify which component requires each missing secret.
    • Avoid exposing secret values.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI requested a review from pelikhan September 11, 2026 12:47
@pelikhan
pelikhan marked this pull request as ready for review September 11, 2026 12:49
Copilot AI balanced review requested due to automatic review settings September 11, 2026 12:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Staged handlers are incorrectly blocked, Linear overrides are mishandled, and failure guidance can be misleading.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds early credential validation for external safe-output providers and integrates failures into activation reporting.

Changes:

  • Validates Jira, Linear, and Azure DevOps credentials during activation.
  • Supports credential overrides and injects a default Azure DevOps PAT.
  • Updates validation messages, tests, and the smoke workflow lock file.
File summaries
File Description
pkg/workflow/safe_outputs_secret_validation.go Defines external credential requirements.
pkg/workflow/safe_outputs_secret_validation_test.go Tests requirement detection and step IDs.
pkg/workflow/safe_outputs_azure_devops.go Injects the default Azure DevOps PAT.
pkg/workflow/safe_outputs_azure_devops_test.go Tests PAT injection and overrides.
pkg/workflow/notify_comment_conclusion_helpers.go Includes safe-output validation in failure handling.
pkg/workflow/engine_helpers.go Supports caller-defined validation step IDs.
pkg/workflow/compiler_safe_outputs_job.go Applies Azure DevOps credential injection.
pkg/workflow/compiler_activation_steps.go Aggregates secret-validation outcomes.
pkg/workflow/compiler_activation_steps_test.go Tests generated external validation steps.
actions/setup/sh/validate_multi_secret.sh Generalizes validation error messages.
actions/setup/sh/validate_multi_secret_test.go Tests requirement messaging.
.github/workflows/smoke-issues.lock.yml Regenerates the smoke workflow with checks.
Review details
  • Files reviewed: 12/12 changed files
  • Comments generated: 4
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +37 to +39
if hasLinearSafeOutputs(config) &&
strings.TrimSpace(config.LinearToken) == "" &&
strings.TrimSpace(config.Env["GH_AW_LINEAR_TOKEN"]) == "" {
Comment on lines +235 to 241
if hasSecretValidationStep(engine, data) {
envVars = append(envVars, fmt.Sprintf(" GH_AW_SECRET_VERIFICATION_RESULT: ${{ needs.%s.outputs.secret_verification_result }}\n", constants.ActivationJobName))
if msg := engine.GetSecretFailureMessage(data); msg != "" {
envVars = append(envVars, fmt.Sprintf(" GH_AW_ENGINE_SECRET_FAILURE_MESSAGE: %q\n", msg))
if EngineHasValidateSecretStep(engine, data) {
if msg := engine.GetSecretFailureMessage(data); msg != "" {
envVars = append(envVars, fmt.Sprintf(" GH_AW_ENGINE_SECRET_FAILURE_MESSAGE: %q\n", msg))
}
}
Comment on lines +25 to +26
var requirements []safeOutputSecretRequirement
if hasAnyJiraSafeOutputEnabled(config) {
# Join secret names with " or "
secret_or_list=$(IFS=" or "; echo "${SECRET_NAMES[*]}")
requirement_msg="The $ENGINE_NAME engine requires either $secret_or_list secret to be configured."
requirement_msg="$secret_or_list is required by $ENGINE_NAME."
@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer failed during the skills-based review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ PR Code Quality Reviewer failed during code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Design Decision Gate 🏗️. Review the logs for details.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #60267

@github-actions

Copy link
Copy Markdown
Contributor
🏗️ ADR required — draft added for PR #60267

Result

A draft ADR has been added to this PR because ADR enforcement applies here and no existing ADR was found in the PR body or docs/adr/ on the branch.

Evidence used

  • adr-prefetch-summary.json: default_business_additions = 292, which is above the 100-line default threshold.
  • PR title/body: Validate external safe-output secrets before activation; describes early validation for Jira, Linear, and Azure DevOps credentials.
  • Diff files in pkg/workflow/ and actions/setup/sh/: add activation-time safe-output secret validation, Azure DevOps PAT injection, aggregated failure handling, and tests.
  • Most recent existing ADR on branch: docs/adr/60183-cache-audit-results-in-logs-jsonl.md, which does not cover this decision.

Draft ADR added

  • docs/adr/60267-validate-safe-output-secrets-before-activation.md

Inferred architectural decision

This PR makes the architectural decision to validate external safe-output credentials during activation, rather than waiting for safe-output processing after agent execution.

Next action

Please review and refine the draft ADR so it accurately reflects the intended long-term decision and trade-offs for activation-time safe-output secret validation.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 20 AIC · ⊞ 10.1K · ◷
Comment /review to run again

@pelikhan
pelikhan merged commit bc736c8 into main Sep 11, 2026
19 checks passed
@pelikhan
pelikhan deleted the copilot/add-secrets-to-checks branch September 11, 2026 13:09
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants