Skip to content

Remove cloud-hypervisor security review warning - #60304

Merged
pelikhan merged 3 commits into
mainfrom
copilot/remove-kvm-warning
Sep 11, 2026
Merged

pelikhan merged 3 commits into
mainfrom
copilot/remove-kvm-warning

Conversation

Copilot AI commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Removes the mandatory human security review warning for sandbox.agent.runtime: cloud-hypervisor while retaining its experimental preview status.

  • Compiler
    • Stop emitting the cloud-hypervisor security review warning.
    • Preserve runtime support and --cloud-hypervisor-preview behavior.
  • Tests
    • Verify cloud-hypervisor no longer emits or counts this warning.

Copilot AI and others added 2 commits September 11, 2026 16:40
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI requested a review from pelikhan September 11, 2026 16:46
@pelikhan
pelikhan marked this pull request as ready for review September 11, 2026 16:56
Copilot AI balanced review requested due to automatic review settings September 11, 2026 16:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The unrelated and untested cache-mode schema expansion should be removed or split into a separate change.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Removes the mandatory security-review warning for the experimental cloud-hypervisor runtime.

Changes:

  • Removes warning emission and counting.
  • Updates regression coverage.
  • Adds unrelated cache-mode schema support.
File summaries
File Description
pkg/workflow/compiler_validators.go Removes the warning logic.
pkg/workflow/compiler_validators_test.go Verifies no warning is emitted or counted.
pkg/workflow/schemas/github-workflow.json Adds unrelated cache-mode validation.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Comment on lines +16 to +20
"cacheMode": {
"$comment": "https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#cache-mode",
"description": "Controls the level of GitHub Actions cache access granted to a workflow or job.",
"type": "string",
"enum": ["read", "write", "write-only", "none"]
@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ PR Code Quality Reviewer failed during code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Design Decision Gate 🏗️. Review the logs for details.

No ADR enforcement needed: PR does not have the implementation label and has <=100 new lines of code in business logic directories (default_business_additions=20).

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #60304

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /codebase-design. The core change (removing the cloud-hypervisor security-review warning while preserving preview behavior) is small, correctly implemented, and its test is properly updated to assert the warning is gone with a zero warning count. No regression risk there.

📋 Key Themes & Highlights

Key Themes

  • Scope creep: pkg/workflow/schemas/github-workflow.json gains a new cacheMode/cache-mode definition unrelated to the PR's stated purpose. It isn't referenced by any Go code, docs, or tests in this repo, so it looks like unrelated schema drift bundled into this change (see inline comment). Recommend splitting into its own PR or dropping it here.

Positive Highlights

  • ✅ isCloudHypervisorRuntime and the --cloud-hypervisor-preview CLI flag path are untouched, so runtime support and preview status are correctly preserved as described in the PR body.
  • ✅ Test rename (...ReviewTrigger → ...DoesNotWarn) and updated assertions (NotContains + Zero warning count) accurately reflect the new behavior — no stale test expectations left behind.
  • ✅ Doc comment on emitSandboxRuntimeWarnings was updated to match the reduced scope of the function.

@copilot please address the review comments above.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 33.2 AIC · ⌖ 14.9 AIC · ⊞ 10.4K
Comment /matt to run again

"$ref": "#/definitions/globs",
"description": "When using the push and pull_request events, you can configure a workflow to run on specific branches or tags. If you only define only tags or only branches, the workflow won't run for events affecting the undefined Git ref.\nThe branches, branches-ignore, tags, and tags-ignore keywords accept glob patterns that use the * and ** wildcard characters to match more than one branch or tag name. For more information, see https://help.github.com/en/github/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#filter-pattern-cheat-sheet.\nThe patterns defined in branches and tags are evaluated against the Git ref's name. For example, defining the pattern mona/octocat in branches will match the refs/heads/mona/octocat Git ref. The pattern releases/** will match the refs/heads/releases/10 Git ref.\nYou can use two types of filters to prevent a workflow from running on pushes and pull requests to tags and branches:\n- branches or branches-ignore - You cannot use both the branches and branches-ignore filters for the same event in a workflow. Use the branches filter when you need to filter branches for positive matches and exclude branches. Use the branches-ignore filter when you only need to exclude branch names.\n- tags or tags-ignore - You cannot use both the tags and tags-ignore filters for the same event in a workflow. Use the tags filter when you need to filter tags for positive matches and exclude tags. Use the tags-ignore filter when you only need to exclude tag names.\nYou can exclude tags and branches using the ! character. The order that you define patterns matters.\n- A matching negative pattern (prefixed with !) after a positive match will exclude the Git ref.\n- A matching positive pattern after a negative match will include the Git ref again."
},
"cacheMode": {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/codebase-design] This cacheMode/cache-mode schema addition is unrelated to the stated purpose of this PR (removing the cloud-hypervisor security review warning) and isn't referenced anywhere else in the codebase (no Go code, docs, or tests use cache-mode).

💡 Why this matters

Bundling an unrelated schema change into a warning-removal PR makes the diff harder to review and muddies the change history — a reviewer approving "remove KVM warning" is also implicitly approving a new, unused validation surface for GitHub Actions' cache-mode field. If this addition is intentional (e.g. keeping the embedded schema in sync with upstream), it should be split into its own PR with a clear description and, ideally, a test exercising the new field. Otherwise, drop it from this PR.

@copilot please address this.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot run pr-finisher skill

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@pelikhan
pelikhan merged commit 5933ee9 into main Sep 11, 2026
1 check failed
@pelikhan
pelikhan deleted the copilot/remove-kvm-warning branch September 11, 2026 17:49
Copilot stopped work on behalf of pelikhan due to an error September 11, 2026 17:50
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants