Skip to content

Add security-audit-required job to security-audit.yml - #189

Merged
chrisdp merged 2 commits into
masterfrom
copilot/add-security-audit-required-job
May 20, 2026
Merged

Add security-audit-required job to security-audit.yml#189
chrisdp merged 2 commits into
masterfrom
copilot/add-security-audit-required-job

Conversation

Copilot AI commented May 20, 2026

Copy link
Copy Markdown
Contributor

Adds a required gate job to the security audit workflow so audit failures can be enforced selectively — blocking on scheduled runs and release branch PRs, but informational-only on feature branch PRs.

Changes

  • .github/workflows/security-audit.yml: Added security-audit-required job that:
    • Runs always() after the audit job
    • Exits non-zero (enforces failure) only when triggered by non-PR events or PRs from release/ branches
    • Sets permissions: {} to follow least-privilege principle
  security-audit-required:
    needs: audit
    if: always()
    runs-on: ubuntu-latest
    permissions: {}
    steps:
      - if: github.event_name != 'pull_request' || startsWith(github.head_ref, 'release/')
        run: if [ "${{ needs.audit.result }}" = "failure" ]; then exit 1; fi
Original prompt

Add the following security-audit-required job to the .github/workflows/security-audit.yml file after the existing audit job:

  security-audit-required:
    needs: audit
    if: always()
    runs-on: ubuntu-latest
    steps:
      - if: github.event_name != 'pull_request' || startsWith(github.head_ref, 'release/')
        run: if [ "${{ needs.audit.result }}" = "failure" ]; then exit 1; fi

This job should be added at the same indentation level as the audit job (under the jobs: section).

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: @copilot Accepted Confirmation: Confirm cloud agent session

Assistant: Roku-debug (6 of 11) is now starting.

data:
    - title: '[WIP] Add security-audit-required job to security-audit.yml'
      repository: rokucommunity/roku-debug
      url: https://github.com/copilot/tasks/pull/PR_kwDODnWL3c7dsCx4?session_id=26028825-5d9f-4b01-a31f-f61b3701d798
      state: queued

Waiting for approval for ropm (repository 7 of 11)...

User: again

Assistant: I'm waiting for your approval to start the PR for ropm (repository 7 of 11).

User: no button

Assistant: I'm waiting for your approval to start the PR for ropm (repository 7 of 11).

User: I have no button to click

Assistant: Let me try a different approach. I'll create the pull request for ropm now.

Assistant: Let me trigger the approval for ropm (repository 7 of 11) now.

User: @copilot Accepted Confirmation: Confirm cloud agent session

Assistant: Ropm (7 of 11) is now starting.

data:
    - title: '[WIP] Add security audit required job to workflows'
      repository: rokucommunity/ropm
      url: https://github.com/copilot/tasks/pull/PR_kwDOD6ArbM7dsEAR?session_id=8f593667-5a4a-49f1-b29f-e29fcdbb0fb1
      state: queued

Waiting for approval for bslint (repository 8 of 11)...

User: i have no button to click

Assistant: I'm waiting for your approval to start the PR for bslint (repository 8 of 11).

User: i have no button to click

Assistant: I understand the button isn't appearing. Let me try to trigger the approval request again for bslint (repository 8 of 11).

User: ok

Assistant: I'm waiting for your approval to start the PR for bslint (repository 8 of 11).

User: no approval requrst

Assistant: Let me try a different approach and directly initiate the PR request for bslint (repository 8 of 11).

Assistant: I'm waiting for your approval to start the PR for bslint (repository 8 of 11).

This pull request was created from Copilot chat.

Copilot AI changed the title [WIP] Add security audit required job to security-audit.yml Add security-audit-required job to security-audit.yml May 20, 2026
Copilot AI requested a review from chrisdp May 20, 2026 20:28
@chrisdp
chrisdp marked this pull request as ready for review May 20, 2026 20:39
@chrisdp
chrisdp enabled auto-merge May 20, 2026 20:39
@chrisdp
chrisdp merged commit 7b39de8 into master May 20, 2026
8 checks passed
@chrisdp
chrisdp deleted the copilot/add-security-audit-required-job branch May 20, 2026 20:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants