Repository navigation
Adopt pinned central validation while preserving PowerShell CI - #2
Merged
Merged
Conversation
Preserve existing PSScriptAnalyzer and Pester CI contracts. Import a bounded manual documentation proposal workflow with human review. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The write-capable workflow must disable persisted checkout credentials before approval.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds pinned central workflow validation and bounded, manually triggered README upkeep while preserving existing PowerShell CI behavior.
Changes:
- Pins validation and existing CI actions.
- Adds restricted documentation-upkeep automation and generated lock.
- Documents safeguards and regeneration.
- Requires correction of a critical persisted-credentials issue in the generated workflow.
| File | Summary |
|---|---|
README.md |
Documents CI and automation safeguards. |
.github/workflows/course-docs-upkeep.md |
Defines bounded manual documentation upkeep. |
.github/workflows/course-docs-upkeep.lock.yml |
Generated workflow implementation; contains the credential-persistence issue. |
.github/workflows/ci.yml |
Adds validation and pins existing actions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Remove the unsafe generated write job rather than hand-edit the compiler lock. Retain central validator-only adoption and document the security gate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
DevOpsDerek/workflows/.github/workflows/validate-agentic-workflows.yml@dac4b81c298cb3ea6821ea312efa5375f42d5ccbinto existing CI withgh-aw-version: v0.89.21,contents: read, and no inherited secrets or local action implementation.Lint (PSScriptAnalyzer)andTest (Pester)identities, lint-before-test dependency, all original PowerShell commands, Pester >=5, and always-uploaded NUnit XML artifactpester-test-results. Pin checkout/upload actions; both checkouts usepersist-credentials: false.Repository fit
The central checked-script runner does not support PowerShell and is intentionally not used. CI analyzer fails on any diagnostic, unlike local lint.ps1's error-only policy; delegating to that helper would weaken CI. Documentation consistency could fit the ten-lesson course but remains deferred until a central compiler supports non-persisted write-job credentials and regenerated output is verified. No lesson code/tests were changed.
Validation
actionlint v1.7.12on remaining ci.yml andgit diff --check: pass.pester-test-resultsartifact uploaded (2792 bytes). Validator correctly skips compilation because no gh-aw sources remain.Related to #1. Keep the adoption issue open/unassigned and project status unchanged pending human review. PR remains open and unmerged; do not merge automatically.