Update CONTRIBUTING.md to use a Fork Based workflow#5
Merged
danieljurek merged 2 commits intoAzure:mainfrom Jul 7, 2022
ellismg:ellismg/update-contributing
Merged
Update CONTRIBUTING.md to use a Fork Based workflow#5danieljurek merged 2 commits intoAzure:mainfrom ellismg:ellismg/update-contributing
danieljurek merged 2 commits intoAzure:mainfrom
ellismg:ellismg/update-contributing
Conversation
We no longer need to use topic branches and should be doing fork based workflows now.
This file is auto-generated from existing content based on all the packages we import. There is no reason to spell check this file.
Collaborator
VSCode Extension Installation Instructions
|
Collaborator
Azure Dev CLI Install InstructionsInstall scripts
MacOS/Linux
Windows Standalone Binary
Container |
danieljurek
approved these changes
Jul 7, 2022
jongio
added a commit
to jongio/azure-dev
that referenced
this pull request
Feb 27, 2026
- Use merged_at instead of merged for reliable merge detection (thread Azure#1) - Expand isDocOnlyPr to handle doc-adjacent assets (thread Azure#2) - Replace N+1 API calls with git.getTree for doc inventory (thread Azure#3) - Fix README trigger types to match actual workflow config (thread Azure#5) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
jongio
added a commit
to jongio/azure-dev
that referenced
this pull request
Feb 28, 2026
- Pin actions to commit SHAs (actions/checkout, azure/login) - Cap all_open/list mode to MAX_PRS_PER_RUN=20 - Cap AI output: MAX_REASON_LENGTH=200, MAX_SUMMARY_LENGTH=500 - Add MAX_IMPACTS=15 to limit AI-generated impact count - Add MAX_CONTENT_SIZE_BYTES=50KB per doc file - Sanitize doc manifest content (titles, topics, headings) - Reject unknown repos from AI output (not just warn) - Validate repo format with regex (owner/repo) - Block path traversal in AI-returned paths - Sanitize PR title in log output (strip control chars) - Strip HTML from existing PR body in closeCompanionPrs - Remove error messages from tracking comment (prevent data leak) - Upper-bound PR number input to 999999 - Rename TRUSTED_DOC_INVENTORY to DOC_INVENTORY tag Red team findings addressed: Azure#2, Azure#5, Azure#6, Azure#8, Azure#9, Azure#10, Azure#11 Admin items remaining: Azure#1 (env gating), Azure#3 (token scope), Azure#4 (OIDC vars) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We no longer need to use topic branches and should be doing fork based
workflows now.