Motivation
github/gh-aw#64976 — the compiler now requires explicit permission-* scope inputs on GitHub App token-minting steps in every compiled job (including imported/generated steps); missing scopes fail compilation in strict mode and warn otherwise.
Proposed test
- Workflow file:
test-copilot-github-app-token-missing-scope.md (or similar)
- Trigger:
workflow_dispatch
- Engine: copilot
- Safe output: n/a — this is a compile-time guard, not a safe-output behavior
- Variant: standard
Minimal test prompt sketch
A workflow source that mints a GitHub App token without any permission-* input, asserting gh aw compile fails (strict mode) or emits a warning (default mode) rather than silently producing a fully-scoped token.
New fixtures or secrets needed
Needs a GitHub App token-minting action/step configured in the test fixture. Unclear whether githubnext/gh-aw-test already has a reusable GitHub App credential for token minting, or whether this should instead be a gh aw compile unit-test-style check in gh-aw itself rather than an E2E workflow-dispatch test, since the failure mode is a compile error, not a runtime workflow outcome.
Notes
The e2e harness in this repo is designed around workflow_dispatch runtime assertions (e2e.sh), not compiler-only assertions. This may be better suited to gh-aw's own compiler test suite. Flagging here for triage to confirm whether an E2E regression test is wanted in this repo, and if so, how e2e.sh should assert a compile failure (currently COMPILE_FAILED_FILE marks compile failures as test failures, which is the opposite of what we'd want to assert here).
Generated by 🔍 Suggest New E2E Tests · copilot · auto · 101.8 AIC · ⌖ 8.13 AIC · ⊞ 8.5K · ◷
Motivation
github/gh-aw#64976 — the compiler now requires explicit
permission-*scope inputs on GitHub App token-minting steps in every compiled job (including imported/generated steps); missing scopes fail compilation in strict mode and warn otherwise.Proposed test
test-copilot-github-app-token-missing-scope.md(or similar)workflow_dispatchMinimal test prompt sketch
A workflow source that mints a GitHub App token without any
permission-*input, assertinggh aw compilefails (strict mode) or emits a warning (default mode) rather than silently producing a fully-scoped token.New fixtures or secrets needed
Needs a GitHub App token-minting action/step configured in the test fixture. Unclear whether
githubnext/gh-aw-testalready has a reusable GitHub App credential for token minting, or whether this should instead be agh aw compileunit-test-style check ingh-awitself rather than an E2E workflow-dispatch test, since the failure mode is a compile error, not a runtime workflow outcome.Notes
The e2e harness in this repo is designed around
workflow_dispatchruntime assertions (e2e.sh), not compiler-only assertions. This may be better suited to gh-aw's own compiler test suite. Flagging here for triage to confirm whether an E2E regression test is wanted in this repo, and if so, howe2e.shshould assert a compile failure (currentlyCOMPILE_FAILED_FILEmarks compile failures as test failures, which is the opposite of what we'd want to assert here).