Skip to content

feat: add reusable Copilot review workflow - #11

Merged
cwillisf merged 2 commits into
mainfrom
feat/copilot-review-workflow
Sep 29, 2026
Merged

cwillisf merged 2 commits into
mainfrom
feat/copilot-review-workflow

Conversation

@cwillisf

Copy link
Copy Markdown
Contributor

Summary

Adds a reusable workflow that requests a Copilot code review when a PR is labeled copilot-review, then removes the label so it can be applied again later.

Manual Copilot review requests are billed to whoever makes them, so anyone on a personal Copilot plan is limited by that plan's allowance. Reviews requested by a bot are billed to the organization instead. Here the bot is github-actions[bot] via GITHUB_TOKEN. Applying a label requires triage access, which keeps outside contributors from triggering reviews on public PRs.

Repos opt in with a small caller workflow on pull_request_target: [labeled]. The header comment in the workflow shows the caller. The workflow never checks out PR code.

Resolves

N/A

Testing

actionlint passes. End-to-end testing needs a caller in another repo, so it will happen in scratch-blocks after this merges. That testing covers same-repo and fork PRs and checks that usage is billed to the org.

Requests a Copilot code review when a PR is labeled copilot-review. Reviews requested via GITHUB_TOKEN are billed to the organization instead of the person who applied the label, and only people with triage access can apply labels.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Pin the reusable workflow to an immutable commit SHA instead of the mutable main branch.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds a reusable GitHub Actions workflow that requests Copilot reviews for labeled pull requests and removes the label afterward.

Changes:

  • Adds the reusable Copilot review workflow.
  • Documents workflow adoption and repository YAML support.
File Description
AGENTS.md Documents the new workflow and repository contents.
.github/​workflows/​copilot-review.yml Requests Copilot reviews and removes the trigger label.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/copilot-review.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The label removal and review request are not atomic, allowing duplicate reviews and charges.

Review effort: Lite
Findings: None

Resolved since last review (1)

@cwillisf
cwillisf merged commit 8173373 into main Sep 29, 2026
2 checks passed
@cwillisf
cwillisf deleted the feat/copilot-review-workflow branch September 29, 2026 14:40
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants