feat: add reusable Copilot review workflow - #11
Merged
Merged
Conversation
Requests a Copilot code review when a PR is labeled copilot-review. Reviews requested via GITHUB_TOKEN are billed to the organization instead of the person who applied the label, and only people with triage access can apply labels.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Pin the reusable workflow to an immutable commit SHA instead of the mutable main branch.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds a reusable GitHub Actions workflow that requests Copilot reviews for labeled pull requests and removes the label afterward.
Changes:
- Adds the reusable Copilot review workflow.
- Documents workflow adoption and repository YAML support.
| File | Description |
|---|---|
AGENTS.md |
Documents the new workflow and repository contents. |
.github/workflows/copilot-review.yml |
Requests Copilot reviews and removes the trigger label. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Adds a reusable workflow that requests a Copilot code review when a PR is labeled
copilot-review, then removes the label so it can be applied again later.Manual Copilot review requests are billed to whoever makes them, so anyone on a personal Copilot plan is limited by that plan's allowance. Reviews requested by a bot are billed to the organization instead. Here the bot is
github-actions[bot]viaGITHUB_TOKEN. Applying a label requires triage access, which keeps outside contributors from triggering reviews on public PRs.Repos opt in with a small caller workflow on
pull_request_target: [labeled]. The header comment in the workflow shows the caller. The workflow never checks out PR code.Resolves
N/A
Testing
actionlintpasses. End-to-end testing needs a caller in another repo, so it will happen in scratch-blocks after this merges. That testing covers same-repo and fork PRs and checks that usage is billed to the org.