Skip to content

Fix safe_outputs checkout failure for pull_request_review events - #18552

Merged
pelikhan merged 2 commits into
mainfrom
copilot/fix-safe-outputs-checkout
Feb 26, 2026
Merged

Fix safe_outputs checkout failure for pull_request_review events#18552
pelikhan merged 2 commits into
mainfrom
copilot/fix-safe-outputs-checkout

Conversation

Copilot AI commented Feb 26, 2026

Copy link
Copy Markdown
Contributor

For pull_request_review events, github.base_ref is empty (only populated for pull_request/pull_request_target), causing the fallback to github.ref_name which resolves to N/merge — an invalid git ref.

Changes

  • 5 expression sites updated with an additional github.event.pull_request.base.ref middle fallback:
# Before
${{ github.base_ref || github.ref_name }}

# After
${{ github.base_ref || github.event.pull_request.base.ref || github.ref_name }}

Affected locations:

  • compiler_safe_outputs_steps.go — checkout ref:

  • compiler_safe_outputs_config.go (×2) — base_branch in create_pull_request and push_to_pull_request_branch handler configs

  • create_pull_request.goGH_AW_BASE_BRANCH env var

  • create_agent_session.goGITHUB_AW_AGENT_SESSION_BASE env var

  • Tests updated across 4 test files to match the new expression

  • 160 lock files recompiled

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/graphql
    • Triggering command: /usr/bin/gh /usr/bin/gh api graphql -f query=query($owner: String!, $name: String!) { repository(owner: $owner, name: $name) { hasDiscussionsEnabled } } -f owner=github -f name=gh-aw GO111MODULE 64/bin/go /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet t-25�� k/gh-aw/gh-aw/.github/workflows/bot-detection.md -buildtags /usr/bin/git -errorsas -ifaceassert -nilfunc git (http block)
    • Triggering command: /usr/bin/gh /usr/bin/gh api graphql -f query=query($owner: String!, $name: String!) { repository(owner: $owner, name: $name) { hasDiscussionsEnabled } } -f owner=github -f name=gh-aw go /usr/bin/git go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh /usr/bin/gh api graphql -f query=query($owner: String!, $name: String!) { repository(owner: $owner, name: $name) { hasDiscussionsEnabled } } -f owner=github -f name=gh-aw 0XVD7GS/mRL0tEU7-c /usr/bin/git go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/ai-inference/git/ref/tags/v1
    • Triggering command: /usr/bin/gh gh api /repos/actions/ai-inference/git/ref/tags/v1 --jq .object.sha iK_VzgSGT GO111MODULE /opt/hostedtoolcache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go tcfg�� -json main.go /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linu--limit GOINSECURE GOMOD GOMODCACHE /opt/hostedtoolcache/go/1.25.0/x64/pkg/tool/linux_amd64/vet (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/11bd71901bbe5b1630ceea73d27597364c9af683
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/11bd71901bbe5b1630ceea73d27597364c9af683 --jq .object.sha -json GO111MODULE ode_modules/.bin/sh GOINSECURE GOMOD GOMODCACHE go env json' --ignore-path ../../../.pr**/*.json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v3
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v3 --jq .object.sha -json GO111MODULE ache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env 1012-28691/test-2642407247/.github/workflows GO111MODULE fg GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v4 --jq .object.sha /ref/tags/v8 GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet env runs/20260226-191012-28691/test-3482350079/.github/workflows fg /opt/hostedtoolcache/go/1.25.0/x64/bin/go l GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v4 --jq .object.sha -json GO111MODULE /opt/hostedtoolcache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env runs/20260226-191012-28691/test-1494119249/.github/workflows GO111MODULE 94183/b349/vet.cfg GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v4 --jq .object.sha /tmp/TestHashStability_SameInputSameOutput2755177644/001/stability-test.md 2554470/b396/imp-test.v=true /usr/bin/git k/gh-aw/gh-aw/pkgit k/gh-aw/gh-aw/pkrev-parse nch,headSha,disp--show-toplevel git rev-�� --git-dir /opt/hostedtoolcache/go/1.25.0/xGO111MODULE /usr/bin/git b/workflows -trimpath 64/bin/go git (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v5
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/pkg/tool/linux_amd64/compile GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linuREDACTED (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha -bool -buildtags ache/node/24.13.1/x64/bin/node -errorsas -ifaceassert -nilfunc git t-13�� bility_SameInputSameOutput2755177644/001/stability-test.md rev-parse 94183/b424/vet.cfg ck 'scripts/**/*git GO111MODULE 64/bin/go git (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v5 --jq .object.sha user.email test@example.com /usr/bin/git -mod=readonly -f 64/bin/go git rev-�� --show-toplevel go /usr/bin/git -json GO111MODULE 64/bin/go git (http block)
  • https://api.github.com/repos/actions/checkout/git/ref/tags/v6
    • Triggering command: /usr/bin/gh gh api /repos/actions/checkout/git/ref/tags/v6 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/github-script/git/ref/tags/v7
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v7 --jq .object.sha "prettier" --wriGOSUMDB git 64/bin/go --show-toplevel go /usr/bin/git go env h ../../../.pret.prettierignore GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v7 --jq .object.sha --write ../../../**/*.js**/*.json 64/bin/go --ignore-path ../../../.pretti/home/REDACTED/.npm/_npx/b388654678d519d9/node_modules/.bin/prettier /usr/bin/git go env h ../../../.pret.prettierignore GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v7 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE x_amd64/asm GOINSECURE GOMOD GOMODCACHE x_amd64/asm (http block)
  • https://api.github.com/repos/actions/github-script/git/ref/tags/v8
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha GOSUMDB GOWORK 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha go1.25.0 -c=4 -nolocalimports -importcfg /tmp/go-build24194183/b393/importcfg -pack /tmp/go-build24194183/b393/_testmain.go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE sh (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/github-script/git/ref/tags/v8 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE node (http block)
  • https://api.github.com/repos/actions/setup-go/git/ref/tags/4dc6199c7b1a012772edbd06daecab0f50c9053c
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/4dc6199c7b1a012772edbd06daecab0f50c9053c --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE r: $owner, name: $name) { hasDiscussionsEnabled } } GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/setup-go/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/v4 --jq .object.sha -json GO111MODULE 64/pkg/tool/linux_amd64/vet GOINSECURE GOMOD GOMODCACHE 64/pkg/tool/linux_amd64/vet env -json fg 94183/b298/vet.cfg GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/setup-go/git/ref/tags/v5
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/v5 --jq .object.sha re GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE odules/npm/node_c4ade70765ddb00c9db8737be9f090128bc84e56 GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-go/git/ref/tags/v5 --jq .object.sha re GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD tCreatePullReque/home/REDACTED/work/gh-aw/gh-aw/.github/workflows go (http block)
  • https://api.github.com/repos/actions/setup-node/git/ref/tags/v4
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v4 --jq .object.sha vaScript1730807880/001/test-frontmatter-with-env--detach GO111MODULE /opt/hostedtoolcache/go/1.25.0/x64/bin/go GOINSECURE GOMOD GOMODCACHE go env runs/20260226-191012-28691/test-3482350079/.github/workflows GO111MODULE 94183/b273/vet.cfg l GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/actions/setup-node/git/ref/tags/v6
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v6 --jq .object.sha prettier --write 64/bin/go !../../../pkg/wonode --ignore-path ../../../.prettiprettier go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v6 --jq .object.sha echo "��� JSON fGOSUMDB git 64/bin/go --ignore-path ..tail go /usr/bin/git go /pre�� -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/actions/setup-node/git/ref/tags/v6 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ules�� -json GO111MODULE (http block)
  • https://api.github.com/repos/astral-sh/setup-uv/git/ref/tags/eac588ad8def6316056a12d4907a9d4d84ff7a3b
    • Triggering command: /usr/bin/gh gh api /repos/astral-sh/setup-uv/git/ref/tags/eac588ad8def6316056a12d4907a9d4d84ff7a3b --jq .object.sha h ../../../.prettierignore GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/docker/build-push-action/git/ref/tags/v6
    • Triggering command: /usr/bin/gh gh api /repos/docker/build-push-action/git/ref/tags/v6 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/docker/build-push-action/git/ref/tags/v6 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE r: $owner, name: $name) { hasDiscussionsEnabled } } GOINSECURE GOMOD GOMODCACHE x_amd64/link (http block)
  • https://api.github.com/repos/docker/login-action/git/ref/tags/v3
    • Triggering command: /usr/bin/gh gh api /repos/docker/login-action/git/ref/tags/v3 --jq .object.sha -json GO111MODULE ode_modules/.bin/node GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE r: $owner, name: $name) { hasDiscussionsEnabled } } GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/docker/login-action/git/ref/tags/v3 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE r: $owner, name: $name) { hasDiscussionsEnabled } } GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/docker/metadata-action/git/ref/tags/v5
    • Triggering command: /usr/bin/gh gh api /repos/docker/metadata-action/git/ref/tags/v5 --jq .object.sha -json GO111MODULE es/.bin/node GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/docker/metadata-action/git/ref/tags/v5 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/docker/setup-buildx-action/git/ref/tags/v3
    • Triggering command: /usr/bin/gh gh api /repos/docker/setup-buildx-action/git/ref/tags/v3 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE r: $owner, name: $name) { hasDiscussionsEnabled } } GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh api /repos/docker/setup-buildx-action/git/ref/tags/v3 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go ode_�� -json GO111MODULE x_amd64/link GOINSECURE GOMOD GOMODCACHE x_amd64/link (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/1/artifacts
    • Triggering command: /usr/bin/gh gh run download 1 --dir test-logs/run-1 GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env hub/workflows GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/12345/artifacts
    • Triggering command: /usr/bin/gh gh run download 12345 --dir test-logs/run-12345 GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/12346/artifacts
    • Triggering command: /usr/bin/gh gh run download 12346 --dir test-logs/run-12346 GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/2/artifacts
    • Triggering command: /usr/bin/gh gh run download 2 --dir test-logs/run-2 GO111MODULE x_amd64/link GOINSECURE GOMOD GOMODCACHE x_amd64/link env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE kM/-uhe5QAXLP6-UlRCMVLF/uovOn_unremote.origin.url (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/3/artifacts
    • Triggering command: /usr/bin/gh gh run download 3 --dir test-logs/run-3 GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env hub/workflows GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/4/artifacts
    • Triggering command: /usr/bin/gh gh run download 4 --dir test-logs/run-4 GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/runs/5/artifacts
    • Triggering command: /usr/bin/gh gh run download 5 --dir test-logs/run-5 GO111MODULE x_amd64/vet GOINSECURE GOMOD GOMODCACHE x_amd64/vet env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/actions/workflows
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path g/timeutil/formaGOINSECURE g/timeutil/formaGOMOD 64/bin/go GOINSECURE erignore GOMODCACHE ache/go/1.25.0/xGO111MODULE env 2554470/b412/_pkGOINSECURE GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh run list --json databaseId,number,url,status,conclusion,workflowName,createdAt,startedAt,updatedAt,event,headBranch,headSha,displayTitle --workflow nonexistent-workflow-12345 --limit 100 b/gh-aw/cmd/gh-a-V=full GOMODCACHE go env UrBQ/KTd3XeKfmQjGOSUMDB GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE 2554470/b371/importcfg (http block)
    • Triggering command: /usr/bin/gh gh run list --json databaseId,number,url,status,conclusion,workflowName,createdAt,startedAt,updatedAt,event,headBranch,headSha,displayTitle --workflow nonexistent-workflow-12345 --limit 6 GOMOD GOMODCACHE x_amd64/vet env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/a70c5eada06553e3510ac27f2c3bda9d3705bccb
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/a70c5eada06553e3510ac27f2c3bda9d3705bccb --jq .object.sha h ../../../.pret.prettierignore GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/github/gh-aw/git/ref/tags/v1.0.0
    • Triggering command: /usr/bin/gh gh api /repos/github/gh-aw/git/ref/tags/v1.0.0 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/githubnext/agentics/git/ref/tags/
    • Triggering command: /usr/bin/gh gh api /repos/githubnext/agentics/git/ref/tags/# --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/nonexistent/action/git/ref/tags/v999.999.999
    • Triggering command: /usr/bin/gh gh api /repos/nonexistent/action/git/ref/tags/v999.999.999 --jq .object.sha -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go env 4235064001/.github/workflows GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/nonexistent/repo/actions/runs/12345
    • Triggering command: /usr/bin/gh gh run view 12345 --repo nonexistent/repo --json status,conclusion GOINSECURE GOMOD GOMODCACHE go env -json GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
  • https://api.github.com/repos/owner/repo/actions/workflows
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path --repo owner/repo 64/bin/go GOINSECURE GOMOD erignore ache/go/1.25.0/xGO111MODULE env 2554470/b417/_pkGOINSECURE GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)
    • Triggering command: /usr/bin/gh gh workflow list --json name,state,path --repo owner/repo 64/bin/go GOINSECURE GOMOD erignore ache/go/1.25.0/xGO111MODULE env 2554470/b352/_pkGOINSECURE GO111MODULE 64/bin/go GOINSECURE b/gh-aw/pkg/cli GOMODCACHE go (http block)
  • https://api.github.com/repos/owner/repo/contents/file.md
    • Triggering command: /tmp/go-build24194183/b381/cli.test /tmp/go-build24194183/b381/cli.test -test.testlogfile=/tmp/go-build24194183/b381/testlog.txt -test.paniconexit0 -test.v=true -test.parallel=4 -test.timeout=10m0s -test.run=^Test -test.short=true GOINSECURE GOMOD GOMODCACHE erignore env GOPATH); \ if coGOINSECURE GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE o fix."; \ exitGO111MODULE (http block)
  • https://api.github.com/repos/test-owner/test-repo/actions/secrets
    • Triggering command: /usr/bin/gh gh api /repos/test-owner/test-repo/actions/secrets --jq .secrets[].name g/testutil/tempdGOINSECURE GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE ache/go/1.25.0/xGO111MODULE env 2554470/b410/_pkGOINSECURE GO111MODULE 64/bin/go GOINSECURE GOMOD GOMODCACHE go (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>safe_outputs checkout fails for pull_request_review events</issue_title>
<issue_description>## Bug

The safe_outputs job checkout step uses ref: ${{ github.base_ref || github.ref_name }}. For pull_request_review events, github.base_ref is empty (GitHub only populates it for pull_request and pull_request_target events), so the expression falls through to github.ref_name which is N/merge — an invalid ref for checkout.

ref: 648/merge
[command]/usr/bin/git fetch ... +refs/heads/648/merge*:refs/remotes/origin/648/merge*
The process '/usr/bin/git' failed with exit code 1

Both push_to_pull_request_branch.cjs and create_pull_request.cjs do their own git fetch + git checkout -B at runtime, so the initial checkout just needs to succeed.

Introduced in

Affected locations

  • compiler_safe_outputs_steps.go:158 — checkout ref
  • compiler_safe_outputs_config.go:464,484base_branch in handler config
  • create_pull_request.go:103GH_AW_BASE_BRANCH env var
  • create_agent_session.go:115GITHUB_AW_AGENT_SESSION_BASE env var

Fix

Add github.event.pull_request.base.ref or github.event.repository.default_branch as a middle fallback:

${{ github.base_ref || github.event.pull_request.base.ref || github.ref_name }}
```</issue_description>

## Comments on the Issue (you are @copilot in this section)

<comments>
</comments>


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

…_review events

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix safe_outputs checkout failure for pull_request_review events Fix safe_outputs checkout failure for pull_request_review events Feb 26, 2026
@pelikhan
pelikhan marked this pull request as ready for review February 26, 2026 20:28
@pelikhan
pelikhan merged commit 25d5de0 into main Feb 26, 2026
2 checks passed
@pelikhan
pelikhan deleted the copilot/fix-safe-outputs-checkout branch February 26, 2026 20:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the default “base branch / checkout ref” GitHub Actions expression to correctly resolve the PR base branch for pull_request_review events (where github.base_ref is empty and github.ref_name can be an invalid N/merge ref).

Changes:

  • Add github.event.pull_request.base.ref as a middle fallback in the default ref/base-branch expression across workflow compilation paths.
  • Update unit/integration tests to assert the new default expression.
  • Recompile workflow lock files to embed the updated expression in generated YAML/JSON config.

Reviewed changes

Copilot reviewed 42 out of 42 changed files in this pull request and generated no comments.

Show a summary per file
File Description
pkg/workflow/compiler_safe_outputs_steps.go Uses the new fallback chain for the checkout ref used by safe_outputs workflows.
pkg/workflow/compiler_safe_outputs_steps_test.go Updates expectations for the default checkout ref expression.
pkg/workflow/compiler_safe_outputs_config.go Updates default base_branch expression for safe_outputs handler configs (create PR and push-to-PR-branch).
pkg/workflow/compiler_safe_outputs_config_test.go Updates expected default base_branch expression in config tests.
pkg/workflow/create_pull_request.go Updates default GH_AW_BASE_BRANCH env var expression used by the create PR workflow/job.
pkg/workflow/create_agent_session.go Updates default GITHUB_AW_AGENT_SESSION_BASE env var expression to avoid invalid merge refs on PR review events.
pkg/workflow/create_pull_request_base_branch_integration_test.go Updates integration assertions for default handler-config base_branch expression.
.github/workflows/weekly-safe-outputs-spec-review.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/weekly-editors-health-check.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/unbloat-docs.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/ubuntu-image-analyzer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/tidy.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (create PR + push branch).
.github/workflows/test-create-pr-error-handling.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/technical-doc-writer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/smoke-project.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/smoke-multi-pr.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/smoke-claude.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (push branch).
.github/workflows/slide-deck-maintainer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/refiner.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/q.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/poem-bot.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (create PR + push branch).
.github/workflows/mergefest.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (push branch).
.github/workflows/layout-spec-maintainer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/jsweep.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/instructions-janitor.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/hourly-ci-cleaner.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/go-logger.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/glossary-maintainer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/github-mcp-tools-report.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/functional-pragmatist.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/dictation-prompt.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/developer-docs-consolidator.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/daily-workflow-updater.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/daily-rendering-scripts-verifier.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/daily-doc-updater.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/daily-doc-healer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/craft.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (push branch).
.github/workflows/code-simplifier.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/code-scanning-fixer.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/cloclo.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/ci-coach.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression.
.github/workflows/changeset.lock.yml Recompiled lockfile embeds updated checkout ref and handler-config base_branch expression (push branch).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

safe_outputs checkout fails for pull_request_review events

4 participants