Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy - #9588

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal
Jul 3, 2026
Merged

Document GH_AW_GITHUB_TOKEN removal and enterprise 8-day PAT policy#9588
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
dev/amauryleve/document-gh-aw-token-removal

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Why

The Grade Tests on PR agentic workflow (and every other gh-aw workflow here) was failing at the Checkout PR branch step, e.g. run 28666711551 on #9583:

GET /repos/microsoft/testfx/collaborators/Evangelink/permission - 403
GET /repos/microsoft/testfx/pulls/9583 - 403
The 'Microsoft Open Source' enterprise forbids access via a fine-grained
personal access token if the token's lifetime is greater than 8 days.

The enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days. The failing step resolves its token as GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN, so the over-lifetime GH_AW_GITHUB_TOKEN PAT it picked up got 403'd.

Fix

The actual remediation is an ops action, not a code change: delete the GH_AW_GITHUB_TOKEN secret so the compiler's token chain falls back to the built-in per-run GITHUB_TOKEN. This is safe repo-wide because:

  • No source .md workflow uses lockdown: true (removed repo-wide) or references the PAT secrets by hand.
  • All declare min-integrity: none, so nothing forces a custom PAT — they only prefer it when present.
  • All 30 compiled workflows share the identical fallback chain, so a single secret deletion fixes them all at once.

The only residual gap is write-backs on fork PRs (where GITHUB_TOKEN is read-only) — those should move to the org-owned GitHub App already documented in this README.

Change

Docs-only: updates .github/workflows/README.md to

  • reflect the concrete enterprise ≤8-day enforcement (previously worded as "~1 week" org policy),
  • note that GH_AW_GITHUB_TOKEN should be left unset so workflows degrade to GITHUB_TOKEN,
  • record the fast-unblock command and the fork-PR caveat.

No workflow behavior changes; .lock.yml files are untouched (no recompile needed).

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

The 'Microsoft Open Source' enterprise now hard-rejects fine-grained PATs whose lifetime exceeds 8 days, which 403s the agentic workflows' 'Checkout PR branch' step. Document the fast unblock (delete GH_AW_GITHUB_TOKEN so the token chain falls back to the built-in GITHUB_TOKEN) and clarify the enterprise policy in the workflows README.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings July 3, 2026 14:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documentation update to the agentic workflows README, clarifying the enterprise enforcement around fine-grained PAT lifetimes and the intended token fallback behavior so workflows don’t break when GH_AW_GITHUB_TOKEN is present but invalid.

Changes:

  • Updates the PAT policy wording to reflect the enterprise’s hard ≤8-day enforcement and the observed 403 failure mode.
  • Documents that GH_AW_GITHUB_TOKEN should be left unset so workflows fall back to the per-run GITHUB_TOKEN.
  • Adds a “fast unblock” remediation command and notes the fork-PR write-back caveat.
Show a summary per file
FileDescription
.github/workflows/README.mdUpdates secrets/auth documentation to reflect the 8-day PAT enforcement and the recommended fallback/remediation steps.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Low

Comment thread.github/workflows/README.md Outdated
Comment thread.github/workflows/README.md Outdated
@Evangelink
Amaury Levé (Evangelink) enabled auto-merge (squash) July 3, 2026 15:01
Split the token-chain code span so escaped pipes render as || instead of \\|\\|, and keep the gh secret delete command on a single line so the inline code span no longer spans a newline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

✅ 22/22 dimensions clean — no findings.

Applicable dimensions verified:

  • §17 Documentation Accuracy — The token fallback chain (GH_AW_GITHUB_MCP_SERVER_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN) matches what's compiled into .lock.yml files. The enterprise 8-day PAT enforcement policy, gh secret delete syntax, lockdown removal history, and the fork-PR GITHUB_TOKEN read-only caveat are all factually accurate and consistent with the existing README context.
  • §3 Security — The guidance to reduce secret surface area (delete the PAT, fall back to GITHUB_TOKEN) is sound. No credential exposure risk in the documented command.
  • §21 Scope & PR Discipline — Single-concern docs-only PR, well-motivated by actual workflow failures.

All other dimensions (1–2, 4–16, 18–20, 22) are N/A for this docs-only change.

@Evangelink
Amaury Levé (Evangelink) merged commit 0c3fc2b into mainJul 3, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dev/amauryleve/document-gh-aw-token-removal branch July 3, 2026 15:11
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink