Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
9ef8923
Merge pull request #63142 from github/repo-sync
docs-bot Sep 9, 2026
3816ce3
Move SDK quickstart to get started (#63036)
sunbrye Sep 9, 2026
6851593
Document the ability to delegate any PR comment to Copilot (#62901)
steveward Sep 9, 2026
b6941f1
Update pull request commenting instructions and screenshot (#45815)
ashis-baral Sep 9, 2026
59a4d1d
Merge pull request #45816 from github/repo-sync
docs-bot Sep 9, 2026
da56bc6
Merge pull request #63148 from github/repo-sync
docs-bot Sep 9, 2026
306e230
Fix translated/missing assign keyword breaking repository-roles-for-a…
docs-bot Sep 9, 2026
81f2df2
Bump the npm_and_yarn group across 1 directory with 4 updates (#63131)
dependabot[bot] Sep 9, 2026
9050d92
GitHub Code Quality: Agentic Autofix for Backlog Experiences [public …
mchammer01 Sep 9, 2026
4dd94cd
Update Copilot in Jetbrains capabilities (#63118)
SiaraMist Sep 9, 2026
441e8e7
Delete orphaned files (2026-09-07-16-29) (#63107)
docs-bot Sep 9, 2026
1c7e465
Delete orphaned features (2026-09-07-16-30) (#63108)
docs-bot Sep 9, 2026
df9bd94
FR: fixing broken links (#63150)
dihydroJenoxide Sep 9, 2026
3a6ec97
Merge pull request #45821 from github/repo-sync
docs-bot Sep 9, 2026
3031786
Merge pull request #63153 from github/repo-sync
docs-bot Sep 9, 2026
9df6656
Migrate the search results page to Primer Brand (#62942)
Ebonsignori Sep 9, 2026
a32a2ec
Migrate the docs footer to Primer Brand MinimalFooter (Docs 2026) (#6…
Ebonsignori Sep 9, 2026
f0ca6ae
Document read-only MCP requirement for code review (#62965)
ausdrew Sep 10, 2026
be60fe4
docs: document Actions cache-mode workflow option (#62301)
philip-gai Sep 10, 2026
1f077aa
Scope `push` to the default branch in copilot-setup-steps samples (#4…
brignano Sep 10, 2026
dda3921
Change "Blocked" to "Allowed" for the default of "Suggestions matchin…
pnsk Sep 10, 2026
608e68c
Fix typo (#63161)
subatoi Sep 10, 2026
3cdc359
Copilot CLI: Update integrations and remote control articles (#63159)
docs-bot Sep 10, 2026
c76a1f5
Clarify CNAME record value for private GitHub Pages sites (#63163)
galaxyeden Sep 10, 2026
dd75c5f
Merge pull request #45830 from github/repo-sync
docs-bot Sep 10, 2026
9ed50c3
Merge pull request #63169 from github/repo-sync
docs-bot Sep 10, 2026
fa961e0
Fix multi-line table cell rejoin and bare-if endif deletion (#63024)
heiskr Sep 10, 2026
ce1e164
Fix changelog agent by clearing the ai-inference model input (#63070)
heiskr Sep 10, 2026
845ef69
Change GraphQL warning icon (#63095)
heiskr Sep 10, 2026
5e088ce
Remove stale CLI docs auto-maintenance state (#63124)
heiskr Sep 10, 2026
f5390f3
Detect deletion-only pull requests as invalid (#63167)
Copilot Sep 10, 2026
144b53a
Add link to "Get started with managed settings" to AI governance jour…
isaacmbrown Sep 10, 2026
4cf7d32
Update OpenAPI Description (#63168)
docs-bot Sep 10, 2026
e087335
GraphQL schema update (#63171)
docs-bot Sep 10, 2026
ec1bf28
Update view a pull request review instructions and screenshot for cur…
ashis-baral Sep 10, 2026
de20b82
Merge pull request #45834 from github/repo-sync
docs-bot Sep 10, 2026
b4c8713
Merge pull request #63174 from github/repo-sync
docs-bot Sep 10, 2026
593c0f5
Copilot: Document Agent Plugins 1.0 support (#62640)
digitarald Sep 10, 2026
8fe6e5b
mai-code-1.0-flash deprecation (#63152)
dihydroJenoxide Sep 10, 2026
f3619f5
Merge pull request #45836 from github/repo-sync
docs-bot Sep 10, 2026
e467c2e
Merge pull request #63176 from github/repo-sync
docs-bot Sep 10, 2026
4179b5a
Skip lockfile churn check for Dependabot (#63066)
heiskr Sep 10, 2026
6cfb75b
Correct GHES deprecation issue labels, title, and dedupe (#63054)
heiskr Sep 10, 2026
3e89ef7
Version links inside GraphQL schema descriptions (#63026)
heiskr Sep 10, 2026
fca2765
Merge pull request #45837 from github/repo-sync
docs-bot Sep 10, 2026
5012ef7
Remove two dead workflows (#63122)
heiskr Sep 11, 2026
a9f2a10
automatic Dependabot access to GitHub-hosted registries docs (#63155)
JamieMagee Sep 11, 2026
4d21b1a
Use current CodeQL frontmatter keys (#62839)
mario-campos Sep 11, 2026
4a03824
[Content creation]: [Audit for Copilot IA project] Concepts: Usage an…
am-stead Sep 11, 2026
91315a6
[Content creation]: [Audit for Copilot IA project] Concepts: Models …
am-stead Sep 11, 2026
9e72f03
fix: moves COPILOT_HOOKS_DENY_DEMO guard to ensure deny() in scope (#…
ohainle Sep 11, 2026
2ae8802
Docs: deprecate the all-platforms CodeQL bundle in CLI download instr…
redsun82 Sep 11, 2026
f169461
Update OpenAPI Description (#63181)
docs-bot Sep 11, 2026
19a1102
Remove expired billing content (#63180)
sophietheking Sep 11, 2026
1315a41
Merge pull request #45842 from github/repo-sync
docs-bot Sep 11, 2026
76d4a88
Merge pull request #63184 from github/repo-sync
docs-bot Sep 11, 2026
03c86b4
docs: update copilot-cli content from source docs (#63016)
docs-bot Sep 11, 2026
798b61e
Update CodeQL CLI manual (#63141)
docs-bot Sep 11, 2026
43490d6
Document app-delegated SSO authorization (#63073)
cheshire137 Sep 11, 2026
ca58b18
Merge pull request #45847 from github/repo-sync
docs-bot Sep 11, 2026
843b53b
Merge pull request #63191 from github/repo-sync
docs-bot Sep 11, 2026
3ff0b32
Update audit log event data (#63185)
docs-bot Sep 11, 2026
c12b176
Fix unit tests in `tests/convert-markdown-for-docs.ts` (#63188)
mario-campos Sep 11, 2026
a2d810b
Fix link redirection for aka.ms URLs in documentation conversion (#63…
mario-campos Sep 11, 2026
078b583
Merge pull request #45848 from github/repo-sync
docs-bot Sep 11, 2026
7b8ac33
Signal that the copilot-setup-steps samples are illustrative
claude Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
13 changes: 7 additions & 6 deletions .github/workflows/changelog-agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -420,14 +420,15 @@ jobs:
uses: actions/ai-inference@2c43c91ae16266ca159d311430343c67a5ffa222 # v3
with:
provider: copilot
# No model is pinned: actions/ai-inference forwards --model to the
# Copilot CLI only when it differs from its GitHub Models default, so
# omitting it lets the CLI pick its own current default (latest Sonnet)
# and avoids breaking when a pinned slug (e.g. gpt-4.1) is retired.
# Must be an explicit empty string, not omitted. This action defaults
# `model` to "gpt-4.1" and always forwards it as --model, and that slug
# is retired, so omitting the input fails with:
# Error: Model "gpt-4.1" from --model flag is not available.
# An empty string makes the action skip --model entirely and lets the
# Copilot CLI pick its own current default. See actions/ai-inference#271.
model: ''
prompt-file: prompt.txt
system-prompt-file: system-prompt.txt
max-completion-tokens: 1000
temperature: 0.3
env:
COPILOT_GITHUB_TOKEN: ${{ secrets.DOCS_BOT_PAT_COPILOT }}

Expand Down
68 changes: 0 additions & 68 deletions .github/workflows/changelog-prompt.yml

This file was deleted.

49 changes: 34 additions & 15 deletions .github/workflows/check-for-spammy-prs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,14 +28,18 @@ jobs:
const repo = 'docs'
const pull_number = context.payload.pull_request.number

const { data: files } = await github.rest.pulls.listFiles({
owner: owner,
repo: repo,
pull_number: pull_number,
});
const files = await github.paginate(github.rest.pulls.listFiles, {
owner,
repo,
pull_number,
per_page: 100,
})

const onlyDeletes = files.length > 0 && files.every(f => f.status === 'removed')
const isEmptyCommit = !files.length
const onlyDeletesLines =
files.some(file => file.deletions > 0) &&
files.every(file => file.additions === 0)
const isEmptyCommit = !files.length
const touchesTooMany = files.length > 10
const isBlankLineEdit = files.length > 0 && files.every(file => {
const changedLines = (file.patch || '')
Expand All @@ -47,19 +51,34 @@ jobs:
const onlyRenames = files.length > 0 && files.every(f => f.status === 'renamed')

// Close the PR and add the invalid label
if (onlyDeletes || isEmptyCommit || touchesTooMany || isBlankLineEdit || onlyRenames) {
await github.rest.issues.update({
owner: owner,
repo: repo,
if (
onlyDeletesLines ||
onlyDeletes ||
isEmptyCommit ||
touchesTooMany ||
isBlankLineEdit ||
onlyRenames
) {
await github.rest.issues.addLabels({
owner,
repo,
issue_number: pull_number,
labels: ['invalid'],
});
})

// Comment on the PR
await github.rest.issues.createComment({
owner: owner,
repo: repo,
owner,
repo,
issue_number: pull_number,
body: `This pull request may have been opened accidentally. I'm going to close it now, but feel free to check out our [contribution guidelines](https://docs.github.com/en/contributing), or raise an issue.`,
});
body: onlyDeletesLines
? `This pull request only removes existing content. Before submitting a content-removal pull request, please [open an issue](https://github.com/github/docs/issues/new/choose) explaining the proposed removal and wait for approval from the GitHub Docs team. Once the change has been approved, you can open a new pull request and link it to the issue.`
: `This pull request may have been opened accidentally. I'm going to close it now, but feel free to check out our [contribution guidelines](https://docs.github.com/en/contributing), or raise an issue.`,
})

if (onlyDeletesLines) {
core.setFailed(
'This pull request only deletes lines. An approved issue is required first.',
)
}
}
80 changes: 0 additions & 80 deletions .github/workflows/move-existing-issues-to-the-correct-repo.yml

This file was deleted.

11 changes: 11 additions & 0 deletions .github/workflows/reviewers-docs-engineering.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,11 +54,22 @@ jobs:
# These are usually cross-platform `npm install` churn from contributors
# editing content. We comment with reset instructions instead of pulling in
# docs-engineering for review.
#
# Dependabot is exempt. Its security updates for transitive dependencies
# change only the lockfile, because the dependency is not in package.json.
# Those PRs are intentional, so the reset instructions are wrong and
# suppressing the review request leaves them with no reviewer at all.
- name: Detect lockfile-only churn
id: detect
env:
GH_TOKEN: ${{ secrets.DOCS_BOT_PAT_BASE }}
PR_AUTHOR: ${{ github.event.pull_request.user.login }}
run: |
if [ "$PR_AUTHOR" = "dependabot[bot]" ]; then
echo "Author is Dependabot; skipping lockfile churn detection."
echo "lockfile_only=false" >> "$GITHUB_OUTPUT"
exit 0
fi
changed=$(gh pr diff "$PR" --name-only)
echo "Changed files:"
echo "$changed"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/sync-graphql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ jobs:
with:
slack_token: ${{ secrets.SLACK_DOCS_BOT_TOKEN }}
message: |
⚠️ GraphQL Sync found ${{ needs.update_graphql_files.outputs.ignored-count }} ignored change types: ${{ needs.update_graphql_files.outputs.ignored-types }}
:graphql: GraphQL Sync found ${{ needs.update_graphql_files.outputs.ignored-count }} ignored change types: ${{ needs.update_graphql_files.outputs.ignored-types }}

These change types are not in CHANGES_TO_REPORT and were silently ignored. Consider reviewing if they should be added to the changelog.

Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/sync-sdk-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ on:
types: [opened, synchronize, reopened]
paths:
- '.github/workflows/sync-sdk-docs.yml'
- 'content/copilot/get-started/sdk-quickstart.md'
- 'src/workflows/sync-sdk-docs/**'

concurrency:
Expand Down Expand Up @@ -77,6 +78,10 @@ jobs:
- name: Copy SDK docs
run: |
mkdir -p "$SDK_DOCS_TARGET"
# Pages relocated out of this tree into hand-authored content are not
# excluded here — they are removed by the RELOCATED_PAGES map in
# src/workflows/sync-sdk-docs/normalize-sdk-docs.ts, which also
# repoints inbound links at their new URLs.
rsync -av --exclude='.validation/' --exclude='developer-docs/' "$SDK_TMP/docs/" "$SDK_DOCS_TARGET/"
echo "Copied $(find "$SDK_DOCS_TARGET" -name '*.md' | wc -l | tr -d ' ') markdown files"

Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file not shown.
Binary file removed assets/images/help/copilot/spark-data-access.png
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file modified assets/images/help/pull_requests/suggestion-block.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added assets/images/site/footer-divider.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added assets/images/site/footer-divider.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Original file line number Diff line number Diff line change
Expand Up @@ -31,9 +31,9 @@ For more information on workflow run artifacts, see [AUTOTITLE](/actions/tutoria

Caches are shared based on the branch or tag a workflow run uses, not on the identity of the workflow or job. See [AUTOTITLE](/actions/reference/workflows-and-actions/events-that-trigger-workflows) and the `GITHUB_REF` for the branch used for various workflow triggers. Any run that can read a cache restores its contents as-is, so you should treat restored files as untrusted input and never store secrets or other sensitive data in a cache.

Untrusted workflows can read sensitive cache contents, such as when a `pull_request` from a fork restores a cache. Poisoned caches can lead to code execution in trusted workflows. To limit the risk of cache poisoning, {% data variables.product.github %} gives workflows that run in response to low-trust triggers read-only access to caches in the default branch's scope.
Untrusted workflows can read sensitive cache contents, such as when a `pull_request` from a fork restores a cache. Poisoned caches can lead to code execution in trusted workflows. To limit the risk of cache poisoning, {% data variables.product.github %} gives workflows that run in response to low-trust triggers read-only access to caches in the default branch's scope.{% ifversion actions-cache-mode %} A workflow or job can override this read-only restriction by explicitly declaring a write-capable `cache-mode`, which reintroduces the cache-poisoning risk for that workflow.{% endif %}

For details on cache scope, access restrictions, and best practices for using caches securely, see [AUTOTITLE](/actions/reference/workflows-and-actions/dependency-caching#cache-access-for-low-trust-workflow-triggers).
For the trusted-versus-low-trust trigger breakdown and default cache behavior, see [AUTOTITLE](/actions/reference/workflows-and-actions/dependency-caching#cache-access-for-low-trust-workflow-triggers). For cache-specific security guidance, see [AUTOTITLE](/actions/reference/workflows-and-actions/dependency-caching#best-practices-for-using-caches-securely).

## Next steps

Expand Down
16 changes: 16 additions & 0 deletions content/actions/how-tos/reuse-automations/reuse-workflows.md
Original file line number Diff line number Diff line change
Expand Up @@ -303,6 +303,22 @@ jobs:

For more information on using job outputs, see [AUTOTITLE](/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idoutputs). If you want to share something other than a variable (e.g. a build artifact) between workflows, see [AUTOTITLE](/actions/tutorials/store-and-share-data).

{% ifversion actions-cache-mode %}

## Controlling cache access in reusable workflows

You can use the `cache-mode` key to grant a reusable workflow the least amount of {% data variables.product.prodname_actions %} cache access it needs. The value can be `read`, `write`, `write-only`, or `none`. If you omit `cache-mode`, a `read` or `write` default is used based on the trigger type. For the full syntax and the meaning of each value, see [AUTOTITLE](/actions/reference/workflows-and-actions/workflow-syntax#cache-mode). For trigger-dependent defaults, see [AUTOTITLE](/actions/reference/dependency-caching-reference#defaults).

When a caller workflow calls a reusable workflow, `cache-mode` propagates to the called workflow. An explicit `cache-mode` on the calling job, or inherited from the caller workflow, limits the cache access the called workflow can request.

If the calling job neither sets nor inherits an explicit `cache-mode`, the called workflow can explicitly request `write` even when the caller's low-trust trigger defaults to `read`. To cap a called workflow at read-only access, set `cache-mode: read` on the job that calls it.

If a called workflow declares a `cache-mode` that requests access beyond this explicit limit, the run does not start and {% data variables.product.github %} reports a validation error. For example, a caller that allows at most `read` cannot call a workflow that declares `write`. Because `read` grants restore access and `write-only` grants save access, the two are non-overlapping capabilities, so a mismatch between them is also an over-request. For example, a `write-only` caller cannot call a workflow that declares `read`.

For more information about cache access and the four modes, see [AUTOTITLE](/actions/reference/dependency-caching-reference#controlling-cache-access-with-cache-mode).

{% endif %}

## Monitoring which workflows are being used

{% ifversion fpt or ghes %}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ If you have confirmed you need `pull_request_target`, apply these controls to li

* **Restrict secrets.** Confirm that the permissions set on the `GITHUB_TOKEN` have the least privileges and that only the necessary repository and organization secrets are used for the workflow. For more information, see [AUTOTITLE](/actions/tutorials/authenticate-with-github_token#modifying-the-permissions-for-the-github_token).

* **Understand the impact to caching.** To reduce the risk of cache poisoning, workflows triggered by `pull_request_target` have read-only access to the cache in the default branch's scope. These workflows can restore existing cache entries but cannot create or overwrite them, so they cannot affect the execution of other, unrelated, workflows through the shared cache. If such a workflow attempts to save a cache, the save fails but the step and the job continue, and the failure is reported as a warning in the workflow log. If your workflow needs to populate the cache, save it from a workflow that runs on a trusted trigger such as `push`. For more information, see [AUTOTITLE](/actions/reference/workflows-and-actions/dependency-caching#cache-access-for-low-trust-workflow-triggers).
* **Understand the impact to caching.** To reduce the risk of cache poisoning, workflows triggered by `pull_request_target` have read-only access to the cache in the default branch's scope. These workflows can restore existing cache entries but cannot create or overwrite them, so they cannot affect the execution of other, unrelated, workflows through the shared cache. If such a workflow attempts to save a cache, the save fails but the step and the job continue, and the failure is reported as a warning in the workflow log. If your workflow needs to populate the cache, save it from a workflow that runs on a trusted trigger such as `push`.{% ifversion actions-cache-mode %} A workflow or job can opt out of this read-only restriction by explicitly declaring a write-capable `cache-mode`, but doing so on a `pull_request_target` workflow reintroduces the cache-poisoning risk this restriction is designed to prevent.{% endif %} For more information, see [AUTOTITLE](/actions/reference/workflows-and-actions/dependency-caching#cache-access-for-low-trust-workflow-triggers).

* **Ensure the underlying compute is isolated and ephemeral.** If self-hosted runners are used, you must confirm that the runner environment is properly restricted from internal resources and is not reused across {% data variables.product.prodname_actions %} runs. For more information, see [AUTOTITLE](/actions/reference/security/secure-use#hardening-for-self-hosted-runners).

Expand Down
Loading