Skip to content

Support dynamic checkout sets from GitHub Actions expressions - #63241

Open
pelikhan with Copilot wants to merge 34 commits into
mainfrom
copilot/dynamic-checkouts-github-action
Open

pelikhan with Copilot wants to merge 34 commits into
mainfrom
copilot/dynamic-checkouts-github-action

Conversation

Copilot AI commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

checkout: only accepted statically known objects or arrays, preventing workflows from selecting repositories at runtime. It now accepts an expression resolving to one checkout object or an array.

checkout: ${{ fromJSON(inputs.checkouts) }}

Changes

  • Compiler

    • Recognizes expression-valued checkout declarations, including imported workflows.
    • Emits runtime checkout steps in agent and safe-output jobs.
    • Preserves static default-checkout behavior.
  • Runtime

    • Validates repository names, fields, unique paths, and workspace containment.
    • Supports refs, tokens, fetch depth, sparse checkout, submodules, LFS, and wikis.
    • Uses ephemeral credentials for agent checkouts and preserves credentials only where safe outputs require them.
    • Rejects symlink-based workspace escapes.
  • Checkout metadata

    • Merges dynamic repositories into the checkout manifest.
    • Adds agent guidance for locating runtime-selected repositories.
  • Schema and documentation

    • Allows GitHub Actions expressions for checkout:.
    • Documents supported fields and static-only options.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 21.3 AIC · ⌖ 8.83 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/36058136776

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 30 AIC · ⌖ 8.77 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/36060789465

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 39.8 AIC · ⌖ 8.92 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Branch refresh requested by PR Sous Chef run https://github.com/github/gh-aw/actions/runs/36062966955

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 39.7 AIC · ⌖ 8.66 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 30.1 AIC · ⌖ 8.61 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 17.2 AIC · ⌖ 8.61 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 37.8 AIC · ⌖ 8.89 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again



✨ PR Review Safe Output Test - Run 36076891728

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 54.2 AIC · ⌖ 17.5 AIC · ⊞ 8K · ◷
Comment /smoke-claude to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 52.8 AIC · ⌖ 8.93 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 35.2 AIC · ⌖ 9 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/36092368943

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 27.3 AIC · ⌖ 8.64 AIC · ⊞ 9.3K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 42.9 AIC · ⌖ 8.69 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 30.6 AIC · ⌖ 8.74 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 20.4 AIC · ⌖ 8.92 AIC · ⊞ 9.2K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 13.9 AIC · ⌖ 8.47 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Branch refresh requested by PR Sous Chef run https://github.com/github/gh-aw/actions/runs/36175468658

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 18 AIC · ⌖ 8.61 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 30.8 AIC · ⌖ 8.67 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again


pr-sous-chef branch refresh requested from run https://github.com/github/gh-aw/actions/runs/36221620757

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 29.7 AIC · ⌖ 8.89 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 16 AIC · ⌖ 8.54 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 23.1 AIC · ⌖ 8.45 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 22.7 AIC · ⌖ 8.62 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 20.7 AIC · ⌖ 8.54 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


pr-sous-chef branch refresh requested by https://github.com/github/gh-aw/actions/runs/36255219324

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 19.1 AIC · ⌖ 8.58 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 26.1 AIC · ⌖ 8.97 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again


pr-sous-chef

Branch refresh requested by PR Sous Chef run: https://github.com/github/gh-aw/actions/runs/36260722205

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 19.5 AIC · ⌖ 9.41 AIC · ⊞ 9.3K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 15.7 AIC · ⌖ 11.6 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits September 24, 2026 19:13
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Comment thread actions/setup/js/dynamic_checkouts.cjs Outdated
Comment on lines +147 to +148
fetchArgs.push("origin", checkout.ref);
await runGit(fetchArgs);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in the current branch: dynamic checkout refs are rejected when they start with -, git fetch passes refs after --, sparse-checkout patterns are rejected when option-like, and sparse patterns are passed after --.

@pelikhan
pelikhan marked this pull request as ready for review September 24, 2026 19:48
Copilot AI balanced review requested due to automatic review settings September 24, 2026 19:48
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot checkouts should
declare an env section to store secrets that will be expanded in the JSON. In JSON mode, payload is not allowed to hold secrets. They should be declared and expanded so that they can be statically listed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Runtime credential cleanup, expression consistency, and Git option/LFS handling contain unresolved correctness and security issues.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity

Open (4)
What changed in this PR

Adds runtime-selected checkout sets to the compiler, agent jobs, safe-output jobs, metadata, schema, and documentation.

Changes:

  • Parses expression-valued checkout declarations.
  • Implements validated runtime Git checkouts and manifest merging.
  • Documents and tests dynamic checkout behavior.
File Description
pkg/​workflow/​workflow_data.go Stores dynamic expressions.
pkg/​workflow/​workflow_builder.go Collects local and imported expressions.
pkg/​workflow/​unified_prompt_step.go Adds dynamic checkout guidance.
pkg/​workflow/​frontmatter_types.go Extends parsed configuration.
pkg/​workflow/​frontmatter_parsing.go Parses expression-valued checkout.
pkg/​workflow/​dynamic_checkout.go Generates runtime checkout steps.
pkg/​workflow/​dynamic_checkout_test.go Tests parsing and generation.
pkg/​workflow/​compiler_yaml_checkout.go Emits agent checkout steps.
pkg/​workflow/​compiler_safe_outputs_steps.go Emits safe-output checkout steps.
pkg/​parser/​schemas/​main_workflow_schema.json Allows checkout expressions.
docs/​src/​content/​docs/​reference/​checkout.md Documents dynamic checkout sets.
actions/​setup/​js/​dynamic_checkouts.test.cjs Tests runtime behavior.
actions/​setup/​js/​dynamic_checkouts.cjs Implements runtime Git checkout.
actions/​setup/​js/​build_checkout_manifest.test.cjs Tests manifest preservation.
actions/​setup/​js/​build_checkout_manifest.cjs Merges existing manifest entries.

Comment thread actions/setup/js/dynamic_checkouts.cjs Outdated
.split(/\r?\n/)
.map(pattern => pattern.trim())
.filter(Boolean);
await runGit(["-C", checkoutTarget, "sparse-checkout", "set", "--no-cone", ...patterns]);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sparse-checkout patterns are now validated and passed after Git's option terminator. Addressed in 801b499.

Comment thread actions/setup/js/dynamic_checkouts.cjs Outdated
Comment on lines +140 to +141
core.info(`Checking out ${checkout.repository} into ${checkout.path}`);
await runGit(cloneArgs);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dynamic checkout clone, checkout, sparse checkout, and submodule operations now disable LFS smudging; only the explicit LFS branch pulls objects. Addressed in 801b499.

},
{
"type": "string",
"pattern": "^\\s*\\$\\{\\{[\\s\\S]+\\}\\}\\s*$",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Expression-valued dynamic checkouts are trimmed consistently during parsing and covered by a regression test. Addressed in 801b499.

Comment on lines +96 to +99
steps = append(steps, injectStepCondition(
c.generateDynamicCheckoutSteps(data.CheckoutExpressions, prCheckoutToken, true),
condition,
)...)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dynamic checkout expressions referencing steps.* now fail compilation, preventing agent-job values from being re-evaluated in safe_outputs. Addressed in 801b499.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot dynamic checkout should require a "allowed-repos" field that restricts the list of repo allowed to be checkout (gh action expression support too)

@github-actions

Copy link
Copy Markdown
Contributor

🔎 PR Code Quality Reviewer is reviewing code quality for this pull request...

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com
  • proxy.golang.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"
    - "proxy.golang.org"

See Network Configuration for more information.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #63241

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

Warning

Firewall blocked 5 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com
  • o205451.ingest.us.sentry.io
  • proxy.golang.org
  • storage.googleapis.com
  • sum.golang.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"
    - "o205451.ingest.us.sentry.io"
    - "proxy.golang.org"
    - "storage.googleapis.com"
    - "sum.golang.org"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

@copilot checkouts should
declare an env section to store secrets that will be expanded in the JSON. In JSON mode, payload is not allowed to hold secrets. They should be declared and expanded so that ...

Added compile-time validation: dynamic checkout: expressions that reference secrets.* directly (dot or bracket notation) now error in strict mode / warn otherwise, since the resolved expression is serialized into a single runtime JSON payload rather than a statically declared env var. Docs now show the recommended pattern of declaring the secret in the workflow's top-level env: section and referencing it via env.NAME inside the checkout expression (which stays visible to static analysis since workflow-level env: is available to every job/step). See 22e30b8's follow-up commit.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ponytail pass focused strictly on deletable complexity in changed lines.

net: -7 lines possible.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by ✂️ Ponytail Reviewer for #63241 · codex · gpt53codex · 6.46 AIC · ⌖ 2.15 AIC · ⊞ 12.5K
Comment /ponytail to run again

throw new Error(`failed to write dynamic checkout manifest: ${getErrorMessage(error)}`, { cause: error });
}
return manifestPath;
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

L215: yagni: tri-branch submodule mode check (true/"true"/"recursive") plus conditional flag push. const recursive = checkout.submodules === "recursive"; if (checkout.submodules !== false) run once with optional --recursive.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No change for this style-only simplification: the current explicit submodule handling keeps the accepted true, "true", and "recursive" modes easy to audit alongside the runtime validation.

}

function credentialArgs(serverURL, token, maskSecret = value => core.setSecret(value)) {
if (!token) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

L85: stdlib: manual key-validation loop with Set membership. Object.keys(entry).every(k => supportedFields.has(k)) with one failure branch, fewer control lines.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No change for this style-only simplification: the current explicit loop keeps the unsupported field name available for the precise validation error.

}
} else {
fs.mkdirSync(candidate);
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

L123: shrink: duplicated token alias handling (github-token and token) every normalize call. Resolve once (const token = entry["github-token"] ?? entry.token ?? "") and stringify once.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No change for this style-only simplification: the current normalization keeps the token aliases close to the returned checkout shape without changing behavior.

@github-actions

Copy link
Copy Markdown
Contributor
🏗️ ADR required — draft added for PR #63241

I added a draft ADR at docs/adr/63241-support-dynamic-checkout-sets-from-github-actions-expressions.md because this PR requires ADR enforcement and no existing ADR was found in the PR body or on the branch.

Evidence used

  • adr-prefetch-summary.json shows default_business_additions: 152, which exceeds the default 100-line threshold.
  • The PR body describes a new architectural capability: runtime-selected checkout sets for checkout: expressions.
  • The diff introduces new compiler/runtime paths (CheckoutExpressions, generateDynamicCheckoutSteps, dynamic_checkouts.cjs), runtime validation rules, manifest merging, and prompt/schema/documentation updates.

Inferred decision captured in the draft

  • Support GitHub Actions expression-valued checkout: declarations that resolve at runtime to one checkout object or an array.
  • Execute those dynamic checkouts in agent and safe-output jobs with runtime validation, workspace/path safety checks, and credential handling rules.

Next action

Please review and refine the draft ADR, especially the trade-offs and final wording, before merging this PR.

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com
  • proxy.golang.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"
    - "proxy.golang.org"

See Network Configuration for more information.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 23.8 AIC · ⌖ 7.85 AIC · ⊞ 10.1K · ◷
Comment /review to run again

Comment thread actions/setup/js/dynamic_checkouts.cjs Outdated
Comment on lines +142 to +157
if (checkout.ref) {
const fetchArgs = [...authArgs, "-C", checkoutTarget, "fetch", "--no-tags"];
if (checkout.fetchDepth > 0) {
fetchArgs.push("--depth", String(checkout.fetchDepth));
}
fetchArgs.push("origin", checkout.ref);
await runGit(fetchArgs);
await runGit(["-C", checkoutTarget, "checkout", "--force", "FETCH_HEAD"]);
}

if (checkout.sparseCheckout.trim()) {
const patterns = checkout.sparseCheckout
.split(/\r?\n/)
.map(pattern => pattern.trim())
.filter(Boolean);
await runGit(["-C", checkoutTarget, "sparse-checkout", "set", "--no-cone", ...patterns]);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in the current branch: dynamic checkout refs are validated against leading - and passed to git fetch after --; sparse-checkout patterns are also validated and passed after --.

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-09-24T20:21:08.415+00:00
review_event: REQUEST_CHANGES
top_themes:
  - dynamic checkout validation is incomplete across separate expression steps
  - safe_outputs re-evaluates checkout expressions in a different job context
  - runtime git argument hardening remains incomplete
files_reviewed:
  - actions/setup/js/build_checkout_manifest.cjs
  - actions/setup/js/build_checkout_manifest.test.cjs
  - actions/setup/js/dynamic_checkouts.cjs
  - actions/setup/js/dynamic_checkouts.test.cjs
  - docs/src/content/docs/reference/checkout.md
  - pkg/parser/schemas/main_workflow_schema.json
  - pkg/workflow/compiler_safe_outputs_steps.go
  - pkg/workflow/compiler_yaml_checkout.go
  - pkg/workflow/dynamic_checkout.go
  - pkg/workflow/dynamic_checkout_test.go
  - pkg/workflow/frontmatter_parsing.go
  - pkg/workflow/frontmatter_types.go
  - pkg/workflow/unified_prompt_step.go
  - pkg/workflow/workflow_builder.go
  - pkg/workflow/workflow_data.go
comment_count: 0

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 83.5 AIC · ⌖ 7.16 AIC · ⊞ 20.3K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking runtime gaps remain in dynamic checkout validation, safe_outputs re-evaluation, and git argument hardening.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 83.5 AIC · ⌖ 7.16 AIC · ⊞ 20.3K
Comment /review to run again

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot summarize the new syntax vs old syntax. Determine if it is confusing for an agent, update to make it more clear that some is static va dynamic

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

@copilot summarize the new syntax vs old syntax. Determine if it is confusing for an agent, update to make it more clear that some is static va dynamic

Updated in fd68ce6.

Syntax summary:

  • Static/existing checkout syntax stays as the direct object or array form under checkout:. These repositories are known at compile time, so the compiler emits normal actions/checkout steps and static-only options such as GitHub App auth, current, and additional fetch patterns remain available.
  • Dynamic checkout syntax is the wrapper object form:
checkout:
  repos: ${{ fromJSON(inputs.checkouts) }}
  allowed-repos:
    - owner/allowed-repo

checkout.repos is the runtime expression that resolves to one checkout object or an array of checkout objects. allowed-repos remains mandatory and is the trusted allowlist constraining those runtime results.

To reduce agent confusion, I updated the checkout reference, normative checkout spec, and schema description to explicitly say that top-level checkout: ${{ ... }} is not the dynamic syntax and checkout.dynamic should not be used. The docs now also call out that agents should treat static checkouts as workflow-source-known and dynamic checkouts as runtime-selected repositories discovered from the workspace/checkout manifest.

Validation: secret scan passed; make agent-report-progress passed; parallel validation reported no review comments and CodeQL was skipped as trivial.

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for the contribution, @Copilot 👋 — the dynamic checkout expression support (checkout: ${{ fromJSON(inputs.checkouts) }}) is a solid addition to the compiler/runtime, and it comes with schema updates, docs, and a good spread of unit tests (dynamic_checkout_test.go, dynamic_checkout_secrets_validation_test.go, etc.). This looks ready for maintainer review.

Nice work covering validation edge cases like symlink workspace escapes and credential handling for safe-output jobs.

Generated by ✅ Contribution Check · copilot · auto · 29.4 AIC · ⌖ 11.9 AIC · ⊞ 9.2K · ◷

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot There is still forward progress needed on this PR.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 29.7 AIC · ⌖ 8.89 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again

Copilot AI commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot There is still forward progress needed on this PR.
...

Verified current head 5fbbffb (already merged with latest main). All prior review threads already have replies with fix citations, and no new unaddressed feedback is linked here. Re-ran make fmt (clean), go build ./..., targeted checkout Go/JS tests, make test-unit, and make lint — all pass. make recompile fails only on a pre-existing, unrelated issue in workflow-skill-extractor.md (its engine: block predates this PR and isn't touched by the dynamic-checkout work), so I left it alone. Remaining cleanup (resolving stale review threads on GitHub, retriggering the in-progress Copilot check) is maintainer-side.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot There is still forward progress needed on this PR.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 22.7 AIC · ⌖ 8.62 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

Copilot AI commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot There is still forward progress needed on this PR.
...

No change since the last verification — head is still 5fbbffb. All prior review threads already have replies with fix citations, and no new unaddressed feedback is linked here.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot There is still forward progress needed on this PR.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 26.1 AIC · ⌖ 8.97 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again

Copilot AI commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

@copilot There is still forward progress needed on this PR.

  • Please address the remaining open review feedback, newest first:...

Reviewed all 20 listed threads. Each already has a substantive Copilot reply documenting the implemented fix or rationale; the current head contains those fixes, so no additional code change is needed. The branch is refreshed to main (b13bdf4 has current main as a merge parent). Thread resolution remains blocked here because gh has no authenticated host and no resolve-thread mutation tool is available. Local fmt, lint, test-unit, and test pass; the current GitHub Advanced Security check passed, while the current Copilot check is still running.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot There is still forward progress needed on this PR.

  • Please resolve the remaining mergeability/workflow issues and confirm the branch is ready for maintainer review.
  • The latest PR status still reports mergeable_state=dirty, so re-check the branch state and address anything still blocking merge.
  • After any needed fixes, run the pr-finisher skill.
  • A branch refresh was requested from sous-chef for this run: https://github.com/github/gh-aw/actions/runs/36260722205

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 19.5 AIC · ⌖ 9.41 AIC · ⊞ 9.3K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Comment thread docs/src/content/docs/specs/checkout-behavior-specification.md Outdated
Comment thread docs/src/content/docs/reference/checkout.md Outdated
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot There is still forward progress needed on this PR.
...

Merged current main and resolved the resulting checkout documentation conflicts in bfae6b19, retaining both activation-checkout and dynamic-checkout guidance and assigning unique compliance test IDs. make recompile and make agent-report-progress pass; the merge is clean locally. The GitHub mergeability/check status must refresh for the pushed head; the currently running Copilot check predates this push.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants