Skip to content

fix(ci): Enforce CI workflows are run and CLI releases self-contained - #1442

Merged
Cedric Vidal (cedricvidal) merged 9 commits into
microsoft:mainfrom
cedricvidal:cedricvidal-portable-ci-gates
Sep 30, 2026
Merged

Cedric Vidal (cedricvidal) merged 9 commits into
microsoft:mainfrom
cedricvidal:cedricvidal-portable-ci-gates

Conversation

@cedricvidal

@cedricvidal Cedric Vidal (cedricvidal) commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Restore intended test execution in microsoft/scope, retaining repository-name
restrictions that prevent the gated jobs from running in fork repositories.
Make OSS build and release capabilities self-contained: scope-core is now a
separate repository, not a provider that OSS should depend on for images,
credentials, or CLI releases. No changes are made to that separate repository.
This PR is separate from #1441.

Preserve video collection/uploads and PR test reporting while fixing the
execution blockers exposed by enabling the OSS jobs:

Blocker Necessary correction
Integration job gates require the internal repository name Match microsoft/scope for worker and queue integration tests, while retaining fork-repository exclusions.
Changes to the workflow do not select integration checks Select the relevant checks for CI workflow changes without treating every application as changed.
Two matrix rows reference missing VS Code worker implementations, Dockerfiles, and tests Remove those nonfunctional rows; retain both current ACP workers and their tool checks.
Docker Hub login requires secrets unavailable to fork PRs Keep authenticated login when appropriate credentials exist; otherwise allow public-image pulls.
Video collection fails when tests produce no test-output directories Tolerate absent video directories while retaining collection and upload steps.

Upstream PRs from forks are distinct from workflows executing inside fork
repositories. Both current ACP tool-check jobs and queue recovery are selected
for CI changes in upstream. ACP fork-head jobs use read-only permissions and
explicitly empty credential values; live-auth tests retain their existing skip
behavior. Existing PR-reporting permissions and reporting steps are preserved.

Preserve capabilities without internal infrastructure

  • Remove both Azure/ACR image-publishing jobs from CI and the standalone Windows
    base/dependency image publisher. Replace the Windows build dependency with a
    hosted windows-2022 validation job that builds base, dependency, and worker
    images sequentially under local tags using the OSS Dockerfiles. No registry
    login or image publication is needed. Keep the Linux Docker builds used by ACP
    integration tests.
  • Remove the internal daily repository-status workflow source and generated
    workflow, plus its orphaned action pin. It was wired to internal repositories
    and deployment reporting.
  • Restore CLI publication as a manual, canonical-repository release flow using
    the OSS repository's own GitHub token and release assets. Remove FLUX App and
    scope-core/scope-doc dependencies, and build/test the release bundle before
    publication. Wire the installer and updater to the OSS releases as well.

Public website deployment, secret scanning, version checking, and applicable
OSS agent workflows are retained. Supporting documentation and focused
no-new-dependency regression coverage describe/enforce the repository boundary.
No package or lockfile changes remain.

Demos

No recording supplied. This change covers automation, Windows build validation,
and CLI release/install/update locations rather than a Portal interaction.
Installer and updater behavior is covered by fixture tests.

Before

The internal repository condition excludes integration jobs in microsoft/scope.
Correcting only that condition still leaves workflow edits untested by the
integration jobs and exposes the execution blockers listed above.

After

Public-upstream integration checks run for relevant CI edits, while execution
fixes preserve working reporting/video capabilities. A dedicated job builds
Windows images without publishing or internal Azure dependencies, and manual CLI
publication targets this repository. Internal status reporting is absent from
OSS rather than permanently disabled there. Credential-dependent live tests
still have external prerequisites; their absence must not be represented as
tested success.

Testing

  • Current revision: 8bffe1f24c30f39cb5247162ad93fe3edcba2a0c.
  • Website review correction: the public onboarding pages now use the canonical
    microsoft/scope installer without private-repository access; the website
    installer downloads that script completely before executing it, rather than
    duplicating release logic. Deployment/API authentication is preserved.
  • Current CI run 36617210397
    passed, including Windows Worker Build, both ACP integration jobs, queue
    recovery, application/unit/bundle checks and CI Summary.
  • Pages validation 36617210573
    passed its build; deployment was intentionally skipped for the PR.
  • Website follow-up validation: 33 focused installer/workflow tests, 7 website
    tests, and a 203-page public-base build passed. Both piped installer entry
    points were tested without GitHub credentials, including failure safety.

Earlier implementation validation at d326467941db5c5b4368e702444340949cb8a7f3:

  • CI run 36535215536
    completed successfully on that baseline: both ACP integration jobs,
    queue recovery, unit tests, application build, CLI bundle integration,
    Windows Worker Build, license headers, NOTICE, and CI Summary passed.
  • Windows job 109297648018
    built and tagged scope-windows-base:ci, scope-windows-deps:ci, and
    scope-copilot-windows:ci on the hosted runner, then passed the container
    smoke test (node --version returned v22.22.3). No registry publication or
    internal image artifact was used.
  • 45 focused checks passed for workflow boundaries, Windows command sequencing
    and failure propagation, release-version/bootstrap error cases, installer
    fixtures, and public updater/download behavior.
  • CLI build and typechecks passed; 15 bundled CLI integration tests passed.
  • Workflow YAML parsing, actionlint, license headers and whitespace checks
    passed. Local PowerShell command-fixture tests are complemented by the native
    Windows image-build proof linked above.
  • Credential-dependent live-model cases retain their existing skip behavior.
    Skipped cases and path-filtered jobs are not counted as executed coverage.
  • Existing lint limitation: the Lint Code job is green because its lint
    step is non-blocking, but that step reports eslint: not found in
    shared/github-auth/telemetry. The job and dependency lockfile are unchanged.
    This PR does not claim successful repository-wide ESLint execution;
    actionlint and the focused TypeScript checks did pass.

No live model calls, actual CLI releases, internal cloud publishing, or
Azure/OIDC/ACR setup changes were performed while developing this fix. OSS
validation requires no internal publishing credentials or infrastructure.
Existing live-model credentials and separate internal publishing infrastructure
remain outside this fix.

Documentation and compatibility

Repository identity remains an explicit integration-test gate; no opt-in
configuration replaces it. Documentation describes OSS test execution, local
Windows builds, same-repository CLI releases and public installation/update
locations. The public website's deployment workflow remains unchanged.
The CLI publishing workflow is manual and restricted to the upstream main
branch; no release is created by this PR's validation. Installation/update from
the new public location requires an actual CLI release asset to exist.

Checklist

  • If Portal features changed, keep CLI capabilities in sync. N/A
  • If Portal components changed, update their Storybook stories. N/A
  • If database changes require a migration, include up() / down() and keep it CosmosDB-compatible. N/A
  • If dependencies changed, update the lockfile and regenerate NOTICE / NOTICE-REVIEW.txt with pnpm notice as needed. N/A - no dependency changes.
  • Video showing the behavior before the suggested change. N/A
  • Video showing the behavior after the suggested change. N/A

Keep the canonical microsoft/scope execution gate while distinguishing upstream fork-head PRs from fork repository workflows. Run secret-free queue checks on upstream PRs and keep credentials and OIDC out of fork code.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restore all unrelated workflow, documentation, dependency, and test changes. The aggregate PR diff now only replaces the retired repository name with microsoft/scope in the four existing gates.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Select integration checks for workflow edits, keep ACP tool checks credential-free on upstream fork PRs, make Docker Hub login optional, and repair demonstrated video, shell, and Windows path failures. Remove only obsolete matrix rows with no worker implementation; retain PR reporting and artifact uploads.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cedricvidal Cedric Vidal (cedricvidal) changed the title fix(ci): restore upstream-only repository gates fix(ci): restore upstream workflow execution Sep 29, 2026
Remove the obsolete VS Code assignments rather than retaining dead case arms. Current ACP tag behavior is unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove internal ACR and cross-repository publication/status automation from OSS while preserving local ACP builds, CLI validation, videos, reporting, Pages and maintenance workflows. Document legacy CLI distribution separately from OSS release publishing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cedricvidal Cedric Vidal (cedricvidal) changed the title fix(ci): restore upstream workflow execution fix(ci): restore OSS checks and remove internal-only automation Sep 29, 2026
Validate the Windows base, pinned dependencies and worker on a hosted Windows runner using local images only. Propagate native Dockerfile failures and require Windows validation in CI Summary.

Restore manual main-only CLI releases to microsoft/scope with the repository token, serialized version selection, tested artifacts and a public installer/updater destination. Preserve Linux integration jobs and public automation without internal infrastructure.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cedricvidal Cedric Vidal (cedricvidal) changed the title fix(ci): restore OSS checks and remove internal-only automation fix(ci): make OSS checks and CLI releases self-contained Sep 29, 2026
@cedricvidal Cedric Vidal (cedricvidal) changed the title fix(ci): make OSS checks and CLI releases self-contained fix(ci): make OSS validation and CLI releases self-contained Sep 29, 2026
@cedricvidal
Cedric Vidal (cedricvidal) marked this pull request as ready for review September 29, 2026 07:29
Cedric Vidal (cedricvidal) added a commit to cedricvidal/scope that referenced this pull request Sep 29, 2026
Bring microsoft#1442 into microsoft#1441 without rewriting either branch. Merge the CI foundation PR first.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@duffney
Josh Duffney (duffney) requested a balanced review from Copilot September 29, 2026 18:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The published website installer and onboarding pages still direct users to the internal release repository.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Makes OSS CI, Windows validation, and CLI releases independent of internal repositories and credentials.

Changes:

  • Restores gated integration checks and adds local Windows image validation.
  • Publishes and installs CLI releases from microsoft/scope.
  • Removes internal image-publishing and repository-status automation.
File Description
scripts/​install-cli.test.ts Tests installer success and failure paths.
scripts/​ci-workflow.test.ts Verifies CI and release boundaries.
scripts/​build-windows-worker.test.ts Tests Windows build orchestration.
scripts/​build-windows-worker.ps1 Builds and smoke-tests Windows images locally.
install-cli.sh Adds the public CLI installer.
docs/​architecture/​cli-distribution.md Documents public CLI distribution.
CONTRIBUTING.md Documents OSS CI and release behavior.
apps/​workers/​coder-acp-copilot-windows/​Dockerfile.windows Propagates pnpm build failures.
apps/​workers/​coder-acp-copilot-windows/​Dockerfile.deps Propagates npm installation failures.
apps/​workers/​coder-acp-copilot-windows/​Dockerfile.base Validates native installer failures.
apps/​cli/​src/​utils/​update-check.ts Targets public Scope releases.
apps/​cli/​src/​utils/​update-check.test.ts Tests public release lookup.
apps/​cli/​src/​commands/​update.ts Downloads updates from microsoft/scope.
apps/​cli/​src/​commands/​update.test.ts Updates repository assertions.
apps/​cli/​README.md Documents public installation and updates.
apps/​cli/​package.json Updates repository metadata.
.github/​workflows/​publish-cli.yml Adds self-contained CLI publication.
.github/​workflows/​daily-repo-status.md Removes internal status automation source.
.github/​workflows/​daily-repo-status.lock.yml Removes generated status workflow.
.github/​workflows/​ci.yml Restores OSS checks and Windows validation.
.github/​workflows/​build-windows-base.yml Removes internal Windows image publishing.
.github/​aw/​actions-lock.json Removes the orphaned action pin.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apps/cli/README.md

```bash
gh api repos/growth-ecosystems/scope-doc/contents/install-cli.sh -H "Accept: application/vnd.github.raw" | bash
curl --fail --location https://raw.githubusercontent.com/microsoft/scope/main/install-cli.sh | bash
@cedricvidal Cedric Vidal (cedricvidal) changed the title fix(ci): make OSS validation and CLI releases self-contained fix(ci): Enforce CI workflows are run and CLI releases self-contained Sep 29, 2026
Use the canonical public installer throughout onboarding and delegate the website compatibility entry point to it. Preserve API access requirements and verify anonymous installs, failure safety, partial-download rejection and rendered public website links.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@duffney

Copy link
Copy Markdown
Collaborator

Non-blocking follow-ups:

  1. Release discovery only examines the first GitHub releases page (install-cli.sh uses the default REST page and gh release list defaults to 30). Once enough newer non-CLI releases exist, installation and update checks could stop finding the latest cli/v* release. Consider requesting sufficient pages/limits and selecting the highest valid stable CLI version semantically.

  2. The success case in scripts/build-windows-worker.test.ts inherits Vitest’s 5-second default timeout. It took 4.334 seconds in the successful PR CI run and timed out once locally while running alongside the focused suite. Consider giving this test/file an explicit timeout or reducing PowerShell process startup overhead.

Neither item should block this PR; the current checks, including the real Windows image build, pass.

@duffney Josh Duffney (duffney) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@manekinekko Wassim Chegham (manekinekko) added the area: cicd Build, test, release, and deployment pipelines. label Sep 29, 2026
Prevent shared server imports from leaking into the bundle and isolate bundle subprocess tests from workspace module resolution. Remove built-in and port-derived API destinations while keeping help, version, and updates usable without configuration.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve upstream shared ACP test-utils extraction and auto-labeling. Retain additive test-utils path selection alongside OSS validation filters, and build test-utils before Windows workers with native-command failure checks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cedricvidal
Cedric Vidal (cedricvidal) merged commit 115481e into microsoft:main Sep 30, 2026
19 checks passed
Cedric Vidal (cedricvidal) added a commit to cedricvidal/scope that referenced this pull request Sep 30, 2026
History-only synchronization after microsoft#1442 was squash-merged; evaluation files unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: cicd Build, test, release, and deployment pipelines.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants