Skip to content

ci: add the Copilot review gate - #2

Closed
mbkkong wants to merge 1 commit into
mainfrom
ci-copilot-review-gate
Closed

mbkkong wants to merge 1 commit into
mainfrom
ci-copilot-review-gate

Conversation

@mbkkong

@mbkkong mbkkong commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Adds the Copilot review gate check, which keeps a PR from merging until Copilot has reviewed it. Right now PRs usually merge within a minute, before the review is in.

The org rule that makes the check required goes on once every repo has this workflow. The logic is in mbunity/github-actions/copilot-review-gate.

CI change only.

Adds the required check that keeps a pull request from merging until Copilot has reviewed it. The
org ruleset that makes it required lands after every repo has the workflow, so no pull request
waits on a check that never reports.
Copilot AI lite review requested due to automatic review settings October 3, 2026 13:38
@mbkkong

mbkkong commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Closing: this repo is public, so it can't use the private gate action. It stays out of the Copilot review rule.

@mbkkong mbkkong closed this Oct 3, 2026
@mbkkong
mbkkong deleted the ci-copilot-review-gate branch October 3, 2026 13:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The required gate can be bypassed by modifying the workflow in the pull request.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds a required GitHub Actions gate that waits for Copilot review before allowing merges.

Changes:

  • Triggers on pull request updates and submitted reviews.
  • Uses concurrency cancellation and read-only permissions.
  • Invokes the shared Copilot review-gate action.

Critical finding: the gate runs from the pull request’s workflow, allowing authors to bypass the required check. It must run from a base-branch-controlled or protected workflow.

File Description
.github/​workflows/​copilot-review-gate.yml Defines the Copilot review gate workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +7 to +8
pull_request:
types: [opened, reopened, synchronize, ready_for_review]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants