You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
replace prompt-only grep/edit trust with the immutable dotnet/skills Unskip Closed Tests package from 57e48d3619bf44b9307a3197239d398b0287b25c (dotnet/skills#1254)
bind every candidate to the exact commit, blob, source span, syntax-derived declaration/test identities, and canonical GitHub references; revalidate before editing and publishing
add a cross-platform PowerShell TestFX verification hook that bootstraps the pinned toolchain, packs acceptance projects when needed, maps source to one test project, runs every exact FQN, and writes each requested TRX
add PowerShell CI coverage for request validation, duplicate/fabricated identities, project mapping, portable target selection, exact command construction, stale revisions, missing TRX, acceptance packing, and replacement of the packaged fail-closed placeholder
The workflow now fails closed for open, not-planned, inaccessible, ambiguous, stale, malformed, skipped, zero-result, mismatched, or non-passing candidates. The read-only model can only select trusted manifest IDs; a deterministic safe-output job owns edits, verification, branch freshness, and creation/readback of at most one draft PR.
Validation
python agentic-workflows\unskip-closed-tests\tests\run_tests.py in dotnet/skills@57e48d3619bf44b9307a3197239d398b0287b25c — 22 passed
The default branch can advance after the check at line 239 but before PR creation. In that race, this readback verifies only the branch name, leaving a PR published against a newer base even though its edit and test evidence came from EXPECTED_COMMIT. Read back baseRefOid as well and close the PR/delete its branch when it differs from the verified commit.
This accepts a malformed URL such as issues/123abc as issue 123. If issue 123 is completed, unrelated text can make the candidate eligible and remove its Ignore; require a non-identifier boundary after the captured number.
This issue also appears in the following locations of the same file:
Run repository code in a bounded read-only verification job, package the verified edits by content hash, and apply them only in a fresh authenticated publisher checkout.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
dotnet/skillsUnskip Closed Tests package from57e48d3619bf44b9307a3197239d398b0287b25c(dotnet/skills#1254)The workflow now fails closed for open, not-planned, inaccessible, ambiguous, stale, malformed, skipped, zero-result, mismatched, or non-passing candidates. The read-only model can only select trusted manifest IDs; a deterministic safe-output job owns edits, verification, branch freshness, and creation/readback of at most one draft PR.
Validation
python agentic-workflows\unskip-closed-tests\tests\run_tests.pyindotnet/skills@57e48d3619bf44b9307a3197239d398b0287b25c— 22 passeddotnet restore UnskipClosedTests.Tool.csproj --locked-mode -bl:{}— passeddotnet build UnskipClosedTests.Tool.csproj --no-restore -bl:{}— passed, 0 warnings / 0 errorsgh-aw v0.89.21 compile unskip-closed-tests --strict— passedactionlint v1.7.12on the generated lock and helper workflow — passedpython .github/scripts/check_source_bom.py— passedpwsh -NoLogo -NoProfile -File .github/scripts/test_unskip_closed_tests_verify.ps1— 10 passedpython .github/scripts/check_action_pins.py— passed, 2545 references across 54 filesclosed/not_planned, Testing Platform overwriting/removing user console output #4425 toopen, and source stayed unchangedMSTest.Analyzers.Test.IgnoreShouldHaveJustificationAnalyzerTests.WhenTestMethodHasIgnoreWithMessage_NoDiagnosticThe package regression suite also covers repeated Ignore text at distinct sites, fabricated anchors/FQNs, false nesting, class-level ambiguity/inheritance/partial declarations, malformed GitHub evidence, inaccessible/not-planned/open references, revision changes, zero/all-skipped/mismatched execution, and post-verification eligibility changes.