Motivation
Link to the gh-aw PR: github/gh-aw#66039 — Fix strict mode rejecting GitHub App tokens configured with repositories: ["*"]
Proposed test
- Workflow file:
test-copilot-strict-github-app-token-wildcard.md
- Trigger:
workflow_dispatch
- Engine: copilot
- Safe output:
create-issue
- Variant: standard (uses
strict: true)
Minimal test prompt sketch
Configure strict: true with a GitHub tool or safe-output backed by a GitHub App token whose repositories config is an explicit wildcard (["*"]). Compilation should succeed (regression guard against the prior false rejection), and the agent should create an issue confirming the wildcard-scoped token was usable.
New fixtures or secrets needed
A GitHub App installation with wildcard repository access is likely required to exercise this live. If no such app/secret exists in this repo's fixtures, this would need a new secret (e.g. GH_AW_TEST_APP_ID / GH_AW_TEST_APP_PRIVATE_KEY) — flagging as an open question rather than assuming availability.
Notes
This is primarily a compile-time regression (strict mode no longer errors on this config). If a real wildcard-scoped App token fixture is unavailable, a reduced version of this test could assert successful compilation only (no live dispatch), but that may not map cleanly onto the existing workflow_dispatch + safe-output pass/fail harness pattern.
Generated by 🔍 Suggest New E2E Tests · copilot · auto · 89.7 AIC · ⌖ 6.55 AIC · ⊞ 8.6K · ◷
Motivation
Link to the gh-aw PR: github/gh-aw#66039 — Fix strict mode rejecting GitHub App tokens configured with
repositories: ["*"]Proposed test
test-copilot-strict-github-app-token-wildcard.mdworkflow_dispatchcreate-issuestrict: true)Minimal test prompt sketch
Configure
strict: truewith a GitHub tool or safe-output backed by a GitHub App token whoserepositoriesconfig is an explicit wildcard (["*"]). Compilation should succeed (regression guard against the prior false rejection), and the agent should create an issue confirming the wildcard-scoped token was usable.New fixtures or secrets needed
A GitHub App installation with wildcard repository access is likely required to exercise this live. If no such app/secret exists in this repo's fixtures, this would need a new secret (e.g.
GH_AW_TEST_APP_ID/GH_AW_TEST_APP_PRIVATE_KEY) — flagging as an open question rather than assuming availability.Notes
This is primarily a compile-time regression (strict mode no longer errors on this config). If a real wildcard-scoped App token fixture is unavailable, a reduced version of this test could assert successful compilation only (no live dispatch), but that may not map cleanly onto the existing
workflow_dispatch+ safe-output pass/fail harness pattern.