Skip to content

Clarify Copilot authorization for GitHub publication - #134951

Merged
vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-automatic-issue-creation
Oct 5, 2026
Merged

vitek-karas merged 4 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-automatic-issue-creation

Conversation

@vitek-karas

@vitek-karas vitek-karas commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Motivation

The existing Agent Merge instructions tell Copilot to "open or update" a Known Build Error issue when a CI failure is unrelated to the PR. The create-kbe skill repeats that instruction without requiring publication approval, while the shared KBE guidance leaves confirmation to the caller.

This guidance was added to make Agent Merge useful by recording legitimate unrelated CI failures instead of repeatedly retriggering CI. Preserve that intentional automation, while making clear that an ordinary coding task does not grant permission to create additional issues or post comments.

Unexpected issue-filing behavior was reported in #134870. Assigning a PR or granting write access alone should not authorize additional publications, and an AI disclosure is not a substitute for authorization.

Changes

Define a consistent publication-authorization rule for repository instructions and the affected skills:

  • For incidental issue creation, issue updates, and comments, require explicit user authorization. Without it, prepare a local draft and ask before publishing; if asking is unavailable, leave the draft and report the pending decision.
  • Accept advance permission in an interactive prompt. Authorization to compose and publish a specified artifact is sufficient within its scope, without another confirmation or separate approval of generated text.
  • Preserve intentional publication by configured agentic workflows through their declared outputs and limits, and by explicitly requested or enabled specialized workflows through their documented publication contracts. Merely loading a skill or reading a workflow does not grant that authority. Draft-only, dry-run, and review-before-publication requests take precedence.
  • Define Agent Merge's publication scope in its existing repository-instruction section. Enabling it authorizes review replies on the current PR when review handling is authorized, and creation or updates of eligible Known Build Error issues in dotnet/runtime for unrelated failures on that PR when CI fixing is authorized. These operations do not require another approval prompt; unrelated publication remains unauthorized.

Make publication depend on scoped authorization, with local drafts when authorization is missing. Align the KBE, shared KBE, PR failure-scan, and mobile reporting instructions so they honor the caller's authorized outputs. Keep the Agent Merge no-rerun rule and KBE eligibility requirements intact. Clarify that a user-requested breaking-change documentation task includes its source-PR documentation comment, while creating the docs issue remains a separate publication decision.

These are Markdown guidance changes only. Runtime code, KBE eligibility rules, and configured workflow outputs and limits are unchanged.

Note

This PR and its description were prepared with GitHub Copilot assistance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the area-skills Agent Skills label Sep 30, 2026
@vitek-karas
vitek-karas marked this pull request as ready for review September 30, 2026 14:46
@vitek-karas
vitek-karas requested review from a team and jeffhandley as code owners September 30, 2026 14:46

@PureWeen PureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two authorization gaps where the new advance-permission wording removes a pause that previously caught uncertain content. Details are inline.

Note

This review was generated by GitHub Copilot.

Comment thread .github/skills/pr-failure-scan/SKILL.md Outdated
Comment thread .github/skills/breaking-change-doc/SKILL.md Outdated
vitek-karas and others added 2 commits September 30, 2026 21:58
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@vitek-karas
vitek-karas requested a review from PureWeen October 1, 2026 07:29
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@vitek-karas
vitek-karas merged commit cd6580f into dotnet:main Oct 5, 2026
25 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-automatic-issue-creation branch October 5, 2026 07:56
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skills Agent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants