Skip to content

Pattern miner: [pattern-miner] Add VEX Statement Generator curated archetype - #318

Merged
pelikhan merged 1 commit into
mainfrom
mine-vex-statement-generator-archetype-e53a2a58abcce9f5
Oct 6, 2026
Merged

pelikhan merged 1 commit into
mainfrom
mine-vex-statement-generator-archetype-e53a2a58abcce9f5

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Caution

Protected files were modified in this change.
This pull request is in request_review mode and requires explicit human scrutiny before merge.

Protected files: .github/copilot-instructions.md

Summary

Mined githubnext/agentics and github/gh-aw for recurring patterns not yet in the wizard's pattern library, and added one new curated archetype: VEX Statement Generator.

Evidence

  • githubnext-agentics/files/workflows/vex-generator.md — a complete workflow that, on workflow_dispatch with typed inputs (alert number, GHSA/CVE id, package, ecosystem, severity, dismissal reason), maps the Dependabot dismissal reason to an OpenVEX status/justification, writes .vex/<ghsa-id>.json, and opens a pull request via create-pull-request.
  • github-gh-aw/files/.github/aw/dependabot.md, section "Dismissed Dependabot Alerts and VEX" — explicitly documents this as a recommended practice: "When a Dependabot security alert is dismissed with a substantive security reason ... consider generating a [VEX] statement ... Alerts dismissed as no_bandwidth do not represent a security decision and should not produce a VEX statement."

This satisfies the mining bar of one upstream workflow example plus explicit upstream documentation recommending the pattern.

Why the existing library did not cover it

I checked all 32 existing archetypes and the manifest's anti_patterns/trigger_combos for any mention of VEX, OpenVEX, vex-generator, or Dependabot-alert-dismissal workflows — none exist. The closest archetype, dependency-monitor, covers proactive dependency scanning/updating, not post-dismissal VEX documentation, which is a distinct typed-workflow_dispatch shape (not schedule-driven, not even discovery-driven — it runs with context already supplied as inputs).

I also confirmed workflow_dispatch was not yet a supported trigger type in patterns/workflow-generation.json's triggers map, even though several other upstream workflows (e.g. repo-assist.md, multi-device-docs-tester.md, agentic-wiki-writer.md) use it alongside other triggers — this archetype needed it added to render.

What changed in patterns/

  • Added patterns/archetypes/vex-statement-generator.json: new curated archetype (success_rate: null, count: 0) with workflow_dispatch trigger, create-pull-request safe output, and tips drawn directly from the upstream workflow and docs (dismissal-reason mapping, no_bandwidth skip, .vex/<ghsa-id>.json output path, purl from the repo's own manifest version, PR-not-direct-commit for review).
  • Updated patterns/manifest.json: appended vex-statement-generator to the archetypes id list.
  • Updated patterns/workflow-generation.json:
    • Added a workflow_dispatch entry to triggers (workflow_dispatch:\n inputs: {}), since no existing trigger definition covered it.
    • Added the vex-statement-generator entry under archetypes with icon, capabilities, permissions, instructions, and prompt body.

No other field (metadata, anti_patterns, trigger_combos, research_findings, degraded_workflows, success_rate, count, top_repos) was touched for this or any existing archetype.

Supporting changes

  • test/patterns.test.js: added vex-statement-generator to the curated-archetype smoke-test list (triggers/safe-outputs present).
  • test/workflow.test.js: added a test asserting buildTriggerYaml(['workflow_dispatch']) renders the new trigger's YAML.
  • .github/copilot-instructions.md: bumped the user-facing archetype count from 32 to 33 and added vex-statement-generator to the curated-archetypes list, to keep test/copilot-instructions.test.js passing (it asserts this doc matches the manifest).

Validation

  • npm test — all 329 tests pass (19 test files), including the new/updated tests above.
  • npm run build — production build succeeds; dist/patterns/archetypes/vex-statement-generator.json is emitted alongside the other archetype files.

Candidates deliberately left out

  • Discussion-to-issue task mining (discussion-task-miner.md): only one upstream workflow demonstrates this exact shape (discussions read -> filtered issue creation with cache-memory dedup); no second corroborating workflow or explicit "recommended pattern" doc section was found, so it doesn't clear the two-example bar.
  • Issue-parent/sub-issue auto-closing (sub-issue-closer.md): overlaps substantially with the existing issue-hierarchy-manager archetype's update-issue/link-sub-issue guidance; not a clearly distinct recurring shape.
  • MAX_OPEN_PRS pre-activation throttle (seen in 10 upstream workflows: adhoc-qa, ci-coach, doc-updater, efficiency-improver, glossary-maintainer, perf-improver, repo-assist, tech-content-editorial-board, test-improver, unbloat-docs): the underlying tip ("pre-activation step that skips scheduled runs once too many open PRs share your title prefix") is already present verbatim across 7 existing archetypes (code-improvement, daily-test-improver, documentation-updater, link-checker, linter-applier, performance-nut, repo-maintainer), so this is already covered.
  • assignees: copilot / assign-to-agent on scheduled findings (duplicate-code-detector.md, large-file-simplifier.md, issue-monster.md): already captured as a tip on the existing backlog-drip archetype.
  • min-integrity: none for maintainer-triggered read access (19 upstream workflows): already captured as tips on nitpick-reviewer, pr-fix-assistant, and repo-qa-assistant.

Generated by Pattern Miner · copilot · auto · 422 AIC · ⌖ 12 AIC · ⊞ 8.3K · ◷

Add a new curated archetype for generating OpenVEX statements when a
Dependabot alert is dismissed with a security justification, and add
workflow_dispatch trigger support needed to render it.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Protected files were modified in this pull request and require manual scrutiny before merge.

Please verify that each protected-file change is intentional, policy-compliant, and safe:

  • Protected files: .github/copilot-instructions.md

@pelikhan
pelikhan marked this pull request as ready for review October 6, 2026 21:42
@pelikhan
pelikhan merged commit 78b4ddd into main Oct 6, 2026
3 of 6 checks passed
@pelikhan
pelikhan deleted the mine-vex-statement-generator-archetype-e53a2a58abcce9f5 branch October 6, 2026 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant