From 92029a9e735475ab83b9daffeff500c92a9fe2ad Mon Sep 17 00:00:00 2001 From: Sergio Padrino Date: Fri, 4 Sep 2026 10:32:54 +0200 Subject: [PATCH] Require verified commit SHAs in issue-triage permalinks Prevent issue-triage comments from constructing source links with fabricated or malformed revisions. Require the agent to obtain every permalink SHA directly from a GitHub tool response instead of inventing, inferring, abbreviating, or manually altering it. Before citing source, require a second verification step that fetches the referenced file at the exact returned SHA and confirms the cited code and line range exist in that revision. If available tools cannot establish both the revision and cited lines, instruct the agent to omit the source-code claim rather than emit an invalid or unverifiable link. Reinforce the same invariant in the final comment requirements and regenerate the compiled workflow metadata with gh-aw v0.87.5. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/workflows/issue-triage.lock.yml | 2 +- .github/workflows/issue-triage.md | 13 +++++++++++-- 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/workflows/issue-triage.lock.yml b/.github/workflows/issue-triage.lock.yml index 5fbe3147362..92312b27966 100644 --- a/.github/workflows/issue-triage.lock.yml +++ b/.github/workflows/issue-triage.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2ab1afdb8171837ca6e1e8329feb3a5723168ab718ca41aa854e2da2e61c3b8f","body_hash":"197537e2f2d8e5927ab23cda2ecbb2dfccb500f425e837139d03f656b85a6511","compiler_version":"v0.87.5","agent_id":"copilot","engine_versions":{"copilot":"1.0.80"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2ab1afdb8171837ca6e1e8329feb3a5723168ab718ca41aa854e2da2e61c3b8f","body_hash":"190ddb4530ba768fe6d46714414872d0399b22ad6ffd5aa403d904e239f278c8","compiler_version":"v0.87.5","agent_id":"copilot","engine_versions":{"copilot":"1.0.80"}} # gh-aw-manifest: {"version":1,"secrets":["CLI_TRIAGE_APP_CLIENT_ID","CLI_TRIAGE_APP_PRIVATE_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/create-github-app-token","sha":"bcd2ba49218906704ab6c1aa796996da409d3eb1","version":"v3.2.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"2a78d04403fdc6907d0f05327cffac9dbad5312d","version":"v0.87.5"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.7","digest":"sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.7@sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.7","digest":"sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.7@sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.7","digest":"sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.7@sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.10","digest":"sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.10@sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e","pinned_image":"ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e"},{"image":"ghcr.io/github/github-mcp-server:v1.10.0","digest":"sha256:097512ddf58af80a620c177ae9cad93448f9a2a55c70ee8fde5cec6714522a8c","pinned_image":"ghcr.io/github/github-mcp-server:v1.10.0@sha256:097512ddf58af80a620c177ae9cad93448f9a2a55c70ee8fde5cec6714522a8c"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_discussion","get_discussion_comments","get_file_contents","get_latest_release","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_discussion_categories","list_discussions","list_issue_types","list_issues","list_releases","list_starred_repositories","list_tags","search_code","search_issues","search_repositories"]},{"name":"safeoutputs","tools":["add_comment","add_labels","apply_suspected_spam","missing_data","missing_tool","noop"]}]} # This file was automatically generated by gh-aw (v0.87.5). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/issue-triage.md b/.github/workflows/issue-triage.md index e7e7758a1c2..a1d018e4715 100644 --- a/.github/workflows/issue-triage.md +++ b/.github/workflows/issue-triage.md @@ -207,6 +207,13 @@ the comment. Trace the relevant behavior through the current `cli/cli` source an recent changes when useful. Form a concise hypothesis that explains how the reported symptom could arise, grounded in issue evidence and specific code. +When source evidence will appear in the comment, obtain the exact commit SHA from a +GitHub tool response. Never invent, infer, abbreviate, or manually alter a SHA. Before +constructing each permalink, fetch the cited file at that exact SHA and verify that the +referenced code and line range exist in that revision. If you cannot obtain and verify +the SHA and cited lines with the available tools, do not include that source-code claim +or permalink. + Include this hypothesis in the comment so the first responder has a concrete starting point. If available evidence cannot support a useful hypothesis, say what remains unknown and name the specific diagnostic evidence needed next; do not invent a cause. @@ -235,8 +242,10 @@ duplicate, name the likely original. If you are suggesting no label, say so and information would help a first responder finish triage. When referring to source code, link every file, symbol, or line claim to an immutable -GitHub permalink pinned to a full commit SHA and exact line range. Do not use branch -links, bare file paths, or unlinked code references. +GitHub permalink pinned to a verified full commit SHA and exact line range. Use only a +SHA returned by a GitHub tool and verify the cited file and lines at that SHA before +posting the link. Do not invent or guess a SHA, and do not use branch links, bare file +paths, or unlinked code references. When calling `add-comment`, explicitly set `item_number` to ${{ github.event.issue.number || inputs.issue_number }}.