Skip to content

Adopt pinned central validation while preserving PowerShell CI - #2

Merged
DevOpsDerek merged 2 commits into
mainfrom
devopsderek-centralized-workflow-adoption
Oct 4, 2026
Merged

DevOpsDerek merged 2 commits into
mainfrom
devopsderek-centralized-workflow-adoption

Conversation

@DevOpsDerek

@DevOpsDerek DevOpsDerek commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Integrate DevOpsDerek/workflows/.github/workflows/validate-agentic-workflows.yml@dac4b81c298cb3ea6821ea312efa5375f42d5ccb into existing CI with gh-aw-version: v0.89.21, contents: read, and no inherited secrets or local action implementation.
  • Preserve Lint (PSScriptAnalyzer) and Test (Pester) identities, lint-before-test dependency, all original PowerShell commands, Pester >=5, and always-uploaded NUnit XML artifact pester-test-results. Pin checkout/upload actions; both checkouts use persist-credentials: false.
  • Defer manual course documentation upkeep. Removed its gh-aw source and generated lock in 3cd12ec because the compiler hardcodes credential persistence in the write-capable PR safe-output checkout with no supported override. No hand-edited lock or insecure workaround.
  • Document the unsupported PowerShell runner and security gate for future agent adoption. Validator-only: no agent/write job, new secret requirement, or automatic merge/release/deploy/publish capability.

Repository fit

The central checked-script runner does not support PowerShell and is intentionally not used. CI analyzer fails on any diagnostic, unlike local lint.ps1's error-only policy; delegating to that helper would weaken CI. Documentation consistency could fit the ten-lesson course but remains deferred until a central compiler supports non-persisted write-job credentials and regenerated output is verified. No lesson code/tests were changed.

Validation

  • Central published merge SHA has green hosted checks.
  • actionlint v1.7.12 on remaining ci.yml and git diff --check: pass.
  • Asserted only ci.yml remains in .github/workflows, permissions are read-only, both checkouts disable persistence, no write job remains, and original PowerShell command blocks/dependency/XML behavior are preserved.
  • Hosted run 37226624300 on 3cd12ec: central validator and PSScriptAnalyzer pass; Pester 50 passed/0 failed; non-expired pester-test-results artifact uploaded (2792 bytes). Validator correctly skips compilation because no gh-aw sources remain.
  • Credential-persistence review thread addressed and resolved by removing the unsafe capability.

Related to #1. Keep the adoption issue open/unassigned and project status unchanged pending human review. PR remains open and unmerged; do not merge automatically.

Preserve existing PSScriptAnalyzer and Pester CI contracts. Import a bounded manual documentation proposal workflow with human review.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 4, 2026 18:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The write-capable workflow must disable persisted checkout credentials before approval.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds pinned central workflow validation and bounded, manually triggered README upkeep while preserving existing PowerShell CI behavior.

Changes:

  • Pins validation and existing CI actions.
  • Adds restricted documentation-upkeep automation and generated lock.
  • Documents safeguards and regeneration.
  • Requires correction of a critical persisted-credentials issue in the generated workflow.
File Summary
README.md Documents CI and automation safeguards.
.github/​workflows/​course-docs-upkeep.md Defines bounded manual documentation upkeep.
.github/​workflows/​course-docs-upkeep.lock.yml Generated workflow implementation; contains the credential-persistence issue.
.github/​workflows/​ci.yml Adds validation and pins existing actions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/course-docs-upkeep.lock.yml Outdated
Remove the unsafe generated write job rather than hand-edit the compiler lock. Retain central validator-only adoption and document the security gate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 4, 2026 19:00
@DevOpsDerek DevOpsDerek changed the title Adopt pinned central validation and bounded course documentation upkeep Adopt pinned central validation while preserving PowerShell CI Oct 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified, and all approval assessments are favorable.

Review effort: Lite
Findings: None

Resolved since last review (1)

@DevOpsDerek
DevOpsDerek merged commit f05ce4d into main Oct 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants