Repository navigation
Pattern miner: [pattern-miner] Add VEX Statement Generator curated archetype - #318
Merged
pelikhan merged 1 commit intoOct 6, 2026
Merged
Conversation
Add a new curated archetype for generating OpenVEX statements when a Dependabot alert is dismissed with a security justification, and add workflow_dispatch trigger support needed to render it. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
pelikhan
marked this pull request as ready for review
October 6, 2026 21:42
pelikhan
deleted the
mine-vex-statement-generator-archetype-e53a2a58abcce9f5
branch
October 6, 2026 21:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caution
Protected files were modified in this change.
This pull request is in
request_reviewmode and requires explicit human scrutiny before merge.Protected files:
.github/copilot-instructions.mdSummary
Mined
githubnext/agenticsandgithub/gh-awfor recurring patterns not yet in the wizard's pattern library, and added one new curated archetype: VEX Statement Generator.Evidence
githubnext-agentics/files/workflows/vex-generator.md— a complete workflow that, onworkflow_dispatchwith typed inputs (alert number, GHSA/CVE id, package, ecosystem, severity, dismissal reason), maps the Dependabot dismissal reason to an OpenVEX status/justification, writes.vex/<ghsa-id>.json, and opens a pull request viacreate-pull-request.github-gh-aw/files/.github/aw/dependabot.md, section "Dismissed Dependabot Alerts and VEX" — explicitly documents this as a recommended practice: "When a Dependabot security alert is dismissed with a substantive security reason ... consider generating a [VEX] statement ... Alerts dismissed asno_bandwidthdo not represent a security decision and should not produce a VEX statement."This satisfies the mining bar of one upstream workflow example plus explicit upstream documentation recommending the pattern.
Why the existing library did not cover it
I checked all 32 existing archetypes and the manifest's
anti_patterns/trigger_combosfor any mention of VEX, OpenVEX,vex-generator, or Dependabot-alert-dismissal workflows — none exist. The closest archetype,dependency-monitor, covers proactive dependency scanning/updating, not post-dismissal VEX documentation, which is a distinct typed-workflow_dispatchshape (not schedule-driven, not even discovery-driven — it runs with context already supplied as inputs).I also confirmed
workflow_dispatchwas not yet a supported trigger type inpatterns/workflow-generation.json'striggersmap, even though several other upstream workflows (e.g.repo-assist.md,multi-device-docs-tester.md,agentic-wiki-writer.md) use it alongside other triggers — this archetype needed it added to render.What changed in
patterns/patterns/archetypes/vex-statement-generator.json: new curated archetype (success_rate: null,count: 0) withworkflow_dispatchtrigger,create-pull-requestsafe output, and tips drawn directly from the upstream workflow and docs (dismissal-reason mapping,no_bandwidthskip,.vex/<ghsa-id>.jsonoutput path, purl from the repo's own manifest version, PR-not-direct-commit for review).patterns/manifest.json: appendedvex-statement-generatorto thearchetypesid list.patterns/workflow-generation.json:workflow_dispatchentry totriggers(workflow_dispatch:\n inputs: {}), since no existing trigger definition covered it.vex-statement-generatorentry underarchetypeswith icon, capabilities, permissions, instructions, and prompt body.No other field (
metadata,anti_patterns,trigger_combos,research_findings,degraded_workflows,success_rate,count,top_repos) was touched for this or any existing archetype.Supporting changes
test/patterns.test.js: addedvex-statement-generatorto the curated-archetype smoke-test list (triggers/safe-outputs present).test/workflow.test.js: added a test assertingbuildTriggerYaml(['workflow_dispatch'])renders the new trigger's YAML..github/copilot-instructions.md: bumped the user-facing archetype count from 32 to 33 and addedvex-statement-generatorto the curated-archetypes list, to keeptest/copilot-instructions.test.jspassing (it asserts this doc matches the manifest).Validation
npm test— all 329 tests pass (19 test files), including the new/updated tests above.npm run build— production build succeeds;dist/patterns/archetypes/vex-statement-generator.jsonis emitted alongside the other archetype files.Candidates deliberately left out
discussion-task-miner.md): only one upstream workflow demonstrates this exact shape (discussions read -> filtered issue creation with cache-memory dedup); no second corroborating workflow or explicit "recommended pattern" doc section was found, so it doesn't clear the two-example bar.sub-issue-closer.md): overlaps substantially with the existingissue-hierarchy-managerarchetype'supdate-issue/link-sub-issueguidance; not a clearly distinct recurring shape.adhoc-qa,ci-coach,doc-updater,efficiency-improver,glossary-maintainer,perf-improver,repo-assist,tech-content-editorial-board,test-improver,unbloat-docs): the underlying tip ("pre-activation step that skips scheduled runs once too many open PRs share your title prefix") is already present verbatim across 7 existing archetypes (code-improvement,daily-test-improver,documentation-updater,link-checker,linter-applier,performance-nut,repo-maintainer), so this is already covered.assignees: copilot/assign-to-agenton scheduled findings (duplicate-code-detector.md,large-file-simplifier.md,issue-monster.md): already captured as a tip on the existingbacklog-driparchetype.min-integrity: nonefor maintainer-triggered read access (19 upstream workflows): already captured as tips onnitpick-reviewer,pr-fix-assistant, andrepo-qa-assistant.