fix(ci): Enforce CI workflows are run and CLI releases self-contained - #1442
Cedric Vidal (cedricvidal) merged 9 commits into
Conversation
Keep the canonical microsoft/scope execution gate while distinguishing upstream fork-head PRs from fork repository workflows. Run secret-free queue checks on upstream PRs and keep credentials and OIDC out of fork code. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restore all unrelated workflow, documentation, dependency, and test changes. The aggregate PR diff now only replaces the retired repository name with microsoft/scope in the four existing gates. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Select integration checks for workflow edits, keep ACP tool checks credential-free on upstream fork PRs, make Docker Hub login optional, and repair demonstrated video, shell, and Windows path failures. Remove only obsolete matrix rows with no worker implementation; retain PR reporting and artifact uploads. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the obsolete VS Code assignments rather than retaining dead case arms. Current ACP tag behavior is unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove internal ACR and cross-repository publication/status automation from OSS while preserving local ACP builds, CLI validation, videos, reporting, Pages and maintenance workflows. Document legacy CLI distribution separately from OSS release publishing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Validate the Windows base, pinned dependencies and worker on a hosted Windows runner using local images only. Propagate native Dockerfile failures and require Windows validation in CI Summary. Restore manual main-only CLI releases to microsoft/scope with the repository token, serialized version selection, tested artifacts and a public installer/updater destination. Preserve Linux integration jobs and public automation without internal infrastructure. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bring microsoft#1442 into microsoft#1441 without rewriting either branch. Merge the CI foundation PR first. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The published website installer and onboarding pages still direct users to the internal release repository.
Review effort: Balanced
Findings: 1
What changed in this PR
Makes OSS CI, Windows validation, and CLI releases independent of internal repositories and credentials.
Changes:
- Restores gated integration checks and adds local Windows image validation.
- Publishes and installs CLI releases from
microsoft/scope. - Removes internal image-publishing and repository-status automation.
| File | Description |
|---|---|
scripts/install-cli.test.ts |
Tests installer success and failure paths. |
scripts/ci-workflow.test.ts |
Verifies CI and release boundaries. |
scripts/build-windows-worker.test.ts |
Tests Windows build orchestration. |
scripts/build-windows-worker.ps1 |
Builds and smoke-tests Windows images locally. |
install-cli.sh |
Adds the public CLI installer. |
docs/architecture/cli-distribution.md |
Documents public CLI distribution. |
CONTRIBUTING.md |
Documents OSS CI and release behavior. |
apps/workers/coder-acp-copilot-windows/Dockerfile.windows |
Propagates pnpm build failures. |
apps/workers/coder-acp-copilot-windows/Dockerfile.deps |
Propagates npm installation failures. |
apps/workers/coder-acp-copilot-windows/Dockerfile.base |
Validates native installer failures. |
apps/cli/src/utils/update-check.ts |
Targets public Scope releases. |
apps/cli/src/utils/update-check.test.ts |
Tests public release lookup. |
apps/cli/src/commands/update.ts |
Downloads updates from microsoft/scope. |
apps/cli/src/commands/update.test.ts |
Updates repository assertions. |
apps/cli/README.md |
Documents public installation and updates. |
apps/cli/package.json |
Updates repository metadata. |
.github/workflows/publish-cli.yml |
Adds self-contained CLI publication. |
.github/workflows/daily-repo-status.md |
Removes internal status automation source. |
.github/workflows/daily-repo-status.lock.yml |
Removes generated status workflow. |
.github/workflows/ci.yml |
Restores OSS checks and Windows validation. |
.github/workflows/build-windows-base.yml |
Removes internal Windows image publishing. |
.github/aw/actions-lock.json |
Removes the orphaned action pin. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| ```bash | ||
| gh api repos/growth-ecosystems/scope-doc/contents/install-cli.sh -H "Accept: application/vnd.github.raw" | bash | ||
| curl --fail --location https://raw.githubusercontent.com/microsoft/scope/main/install-cli.sh | bash |
Use the canonical public installer throughout onboarding and delegate the website compatibility entry point to it. Preserve API access requirements and verify anonymous installs, failure safety, partial-download rejection and rendered public website links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Non-blocking follow-ups:
Neither item should block this PR; the current checks, including the real Windows image build, pass. |
Prevent shared server imports from leaking into the bundle and isolate bundle subprocess tests from workspace module resolution. Remove built-in and port-derived API destinations while keeping help, version, and updates usable without configuration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve upstream shared ACP test-utils extraction and auto-labeling. Retain additive test-utils path selection alongside OSS validation filters, and build test-utils before Windows workers with native-command failure checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
History-only synchronization after microsoft#1442 was squash-merged; evaluation files unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Summary
Restore intended test execution in
microsoft/scope, retaining repository-namerestrictions that prevent the gated jobs from running in fork repositories.
Make OSS build and release capabilities self-contained:
scope-coreis now aseparate repository, not a provider that OSS should depend on for images,
credentials, or CLI releases. No changes are made to that separate repository.
This PR is separate from #1441.
Preserve video collection/uploads and PR test reporting while fixing the
execution blockers exposed by enabling the OSS jobs:
microsoft/scopefor worker and queue integration tests, while retaining fork-repository exclusions.test-outputdirectoriesUpstream PRs from forks are distinct from workflows executing inside fork
repositories. Both current ACP tool-check jobs and queue recovery are selected
for CI changes in upstream. ACP fork-head jobs use read-only permissions and
explicitly empty credential values; live-auth tests retain their existing skip
behavior. Existing PR-reporting permissions and reporting steps are preserved.
Preserve capabilities without internal infrastructure
base/dependency image publisher. Replace the Windows build dependency with a
hosted
windows-2022validation job that builds base, dependency, and workerimages sequentially under local tags using the OSS Dockerfiles. No registry
login or image publication is needed. Keep the Linux Docker builds used by ACP
integration tests.
workflow, plus its orphaned action pin. It was wired to internal repositories
and deployment reporting.
the OSS repository's own GitHub token and release assets. Remove FLUX App and
scope-core/scope-docdependencies, and build/test the release bundle beforepublication. Wire the installer and updater to the OSS releases as well.
Public website deployment, secret scanning, version checking, and applicable
OSS agent workflows are retained. Supporting documentation and focused
no-new-dependency regression coverage describe/enforce the repository boundary.
No package or lockfile changes remain.
Demos
No recording supplied. This change covers automation, Windows build validation,
and CLI release/install/update locations rather than a Portal interaction.
Installer and updater behavior is covered by fixture tests.
Before
The internal repository condition excludes integration jobs in
microsoft/scope.Correcting only that condition still leaves workflow edits untested by the
integration jobs and exposes the execution blockers listed above.
After
Public-upstream integration checks run for relevant CI edits, while execution
fixes preserve working reporting/video capabilities. A dedicated job builds
Windows images without publishing or internal Azure dependencies, and manual CLI
publication targets this repository. Internal status reporting is absent from
OSS rather than permanently disabled there. Credential-dependent live tests
still have external prerequisites; their absence must not be represented as
tested success.
Testing
8bffe1f24c30f39cb5247162ad93fe3edcba2a0c.microsoft/scopeinstaller without private-repository access; the websiteinstaller downloads that script completely before executing it, rather than
duplicating release logic. Deployment/API authentication is preserved.
passed, including Windows Worker Build, both ACP integration jobs, queue
recovery, application/unit/bundle checks and CI Summary.
passed its build; deployment was intentionally skipped for the PR.
tests, and a 203-page public-base build passed. Both piped installer entry
points were tested without GitHub credentials, including failure safety.
Earlier implementation validation at
d326467941db5c5b4368e702444340949cb8a7f3:completed successfully on that baseline: both ACP integration jobs,
queue recovery, unit tests, application build, CLI bundle integration,
Windows Worker Build, license headers, NOTICE, and CI Summary passed.
built and tagged
scope-windows-base:ci,scope-windows-deps:ci, andscope-copilot-windows:cion the hosted runner, then passed the containersmoke test (
node --versionreturnedv22.22.3). No registry publication orinternal image artifact was used.
and failure propagation, release-version/bootstrap error cases, installer
fixtures, and public updater/download behavior.
passed. Local PowerShell command-fixture tests are complemented by the native
Windows image-build proof linked above.
Skipped cases and path-filtered jobs are not counted as executed coverage.
Lint Codejob is green because its lintstep is non-blocking, but that step reports
eslint: not foundinshared/github-auth/telemetry. The job and dependency lockfile are unchanged.
This PR does not claim successful repository-wide ESLint execution;
actionlint and the focused TypeScript checks did pass.
No live model calls, actual CLI releases, internal cloud publishing, or
Azure/OIDC/ACR setup changes were performed while developing this fix. OSS
validation requires no internal publishing credentials or infrastructure.
Existing live-model credentials and separate internal publishing infrastructure
remain outside this fix.
Documentation and compatibility
Repository identity remains an explicit integration-test gate; no opt-in
configuration replaces it. Documentation describes OSS test execution, local
Windows builds, same-repository CLI releases and public installation/update
locations. The public website's deployment workflow remains unchanged.
The CLI publishing workflow is manual and restricted to the upstream main
branch; no release is created by this PR's validation. Installation/update from
the new public location requires an actual CLI release asset to exist.
Checklist
up()/down()and keep it CosmosDB-compatible. N/ANOTICE/NOTICE-REVIEW.txtwithpnpm noticeas needed. N/A - no dependency changes.