Skip to content

Disable credential persistence on the agentic_commands router checkout - #60685

Merged
pelikhan merged 2 commits into
mainfrom
copilot/add-test-and-fix-agentic-commands
Sep 13, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/add-test-and-fix-agentic-commands

Conversation

Copilot AI commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

The generated central slash-command router workflow (.github/workflows/agentic_commands.yml) checked out the repo without persist-credentials: false, leaving GITHUB_TOKEN in the local git config for the lifetime of the routing job. The router only needs the tree (it loads actions/setup scripts and dispatches), so persisted credentials are pure blast radius.

Changes

  • pkg/workflow/central_slash_command_workflow.go — emit with: persist-credentials: false on the router's actions/checkout step.
  • pkg/workflow/central_slash_command_workflow_test.go — TestGenerateCentralSlashCommandWorkflow_CheckoutDoesNotPersistCredentials asserts the full checkout block (step name + pinned uses + with) and that persist-credentials: true never appears in the generated output.
  • .github/workflows/agentic_commands.yml — regenerated via make recompile.
  • Changeset added.

Generated output:

    steps:
      - name: Checkout repository
        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false

Note: the custom Go linter reports function-length and path-concatenation findings in central_slash_command_workflow.go. These reproduce on the unmodified baseline and are left untouched.

Copilot AI and others added 2 commits September 13, 2026 20:13
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title Ensure agentic_commands.yml router checkout sets persist-credentials: false Disable credential persistence on the agentic_commands router checkout Sep 13, 2026
Copilot AI requested a review from pelikhan September 13, 2026 20:18
@pelikhan
pelikhan marked this pull request as ready for review September 13, 2026 20:19
Copilot AI balanced review requested due to automatic review settings September 13, 2026 20:19
@pelikhan
pelikhan merged commit 3c53578 into main Sep 13, 2026
1 check passed
@pelikhan
pelikhan deleted the copilot/add-test-and-fix-agentic-commands branch September 13, 2026 20:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused change consistently updates generator output, regression coverage, generated workflow, and release metadata.

Pull request overview

Prevents the generated slash-command router from persisting checkout credentials, reducing credential exposure.

Changes:

  • Adds persist-credentials: false to the generated checkout step.
  • Adds focused regression coverage and regenerates the workflow.
  • Adds a patch changeset.
File summaries
File Description
pkg/workflow/central_slash_command_workflow.go Generates credential-free checkout configuration.
pkg/workflow/central_slash_command_workflow_test.go Verifies credentials are not persisted.
.github/workflows/agentic_commands.yml Applies the regenerated secure checkout block.
.changeset/central-commands-checkout-no-credentials.md Records the security hardening change.
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.12

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants