mirror of
https://github.com/github/awesome-copilot.git
synced 2026-09-16 20:01:09 +00:00
9ce814859eaa473178a1463ee3aa0c54a8860b86
141
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9ce814859e |
Rebuild website on Primer Brand design (#2703)
* feat(website): rebuild site on Primer Brand design prototype Replace the Astro + Starlight site with the Brand Engineering design prototype, ported component-for-component onto plain Astro + React islands. The prototype is treated as the authority on markup and styling; dynamic data is injected into its components rather than the components being reinterpreted. Framework: - Remove @astrojs/starlight entirely, along with its document shell, search, footer and language selector. BaseLayout.astro now owns the document head, CSP, social meta and analytics. - Add @primer/react-brand and @astrojs/react. Alias the package to its ESM build in vite.resolve, since the default CJS entrypoint breaks named-export detection during SSR, and mark it noExternal so its stylesheet imports resolve. - Promote pagefind to an explicit devDependency; it was previously pulled in transitively by Starlight. Pages: home, the five catalogs, the five detail routes, contributors, Playbook index and articles, and the cookbook are all rendered by ported prototype components inside a shared PageShell. Detail pages share a DetailChassis (hero, breadcrumbs, sticky TOC with scroll-spy, prev/next) while keeping what makes each type distinct: a file switcher over bundled skill assets, an included-items grid and external provenance for plugins, and a hero-scale preview for extensions. i18n: resolve translated Playbook entries via Astro.currentLocale inside the shared article route instead of separate [locale] routes. The explicit routes collided with the i18n fallback routes, so translated articles were being shadowed by their English originals and 900 nonsensical double-locale pages were emitted. Search: TopNavSearch now queries the Pagefind index client-side in addition to the static resource index, merging on href and degrading to the static index in dev, where no index has been built. Also delete the superseded vanilla-TS page renderers and Astro partials, which the ported React components fully replace. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): resolve accessibility violations in ported detail pages Fixes the three axe violations surfaced by the a11y audit after the Primer Brand redesign: - aria-prohibited-attr: `aria-label` was set on roleless `div`s in InstructionDetail and PluginDetail. The "Applies to" list now uses list/listitem roles; plugin provenance uses a group role. - scrollable-region-focusable: the install command `code` element overflows horizontally but was not keyboard reachable. Added tabIndex to all three render sites. - color-contrast: the Playbook "New" label used the brand's success-fg on success-subtle, reaching only 4.09:1 in light mode. Stepped one down the same green ramp for 6.14:1. Scoped to light mode; dark mode already passed and its green-7 is near-black. Also corrects the stale route list in the audit script: /hooks/, /workflows/ and /tools/ have never existed as pages. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): collapse long filter facets and unpin detail-page footer Two issues surfaced by review of the redesigned site: Catalog facets rendered every option. The prototype's filter groups were built from small hardcoded arrays, but real data produces 193 tool options on /agents/ and 245 "Applies to" values on /instructions/. The sidebar grew to ~10,000px and stretched the whole catalog row, pushing the (already present) pagination control far below the fold so it read as missing. Adopt the prototype's own solution for this, which it had already applied to the extensions page: collapse groups past 10 options behind a "Show N more" toggle, and cap .filterOptions with an internal scroll area. Ported verbatim to the agents, instructions, skills, and plugins catalogs. Detail pages scroll inside .scrollHost rather than the document, but the footer came from PageShell, outside that element, so it stayed pinned over the content instead of appearing at the end. The prototype renders its footer inside the scroll host; PageShell now takes a renderFooter flag so DetailChassis can do the same. LearningArticleLayout already did this. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): source contributor count from .all-contributorsrc Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Removing playwright-mcp files * fix(website): resolve article text colour inside themed scope Injected markdown inherited color from body, which sits outside the ThemeProvider and always resolved the light-mode token, making body copy unreadable in dark mode. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): drop 'In this article' TOC from resource detail pages Resource detail pages (agent, instruction, skill, plugin, extension) are not articles, and their markdown headings do not form a meaningful outline. Playbook and cookbook articles keep their TOC. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * style(website): thin the sidebar scrollbar on detail pages Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): use themed link colour for markdown links in dark mode Raw markdown-injected <a> elements previously fell back to the browser's default blue/purple link colours, which are harsh against the dark-mode background. Route them through --brand-color-text-link-rest (and the pressed/hover token) instead. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): apply ThemeProvider to Playbook article layout so dark mode works LearningArticleLayout replaces PageShell for Playbook articles but never wrapped itself in a ThemeProvider, so its useTheme() call always fell back to Primer's light default regardless of the site's actual theme preference. Split the component into a thin ThemeProvider wrapper plus the existing implementation (now LearningArticleLayoutBody), matching the pattern already used by PageShell. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): align raw markdown code blocks with prototype styling Astro's default Shiki config bakes in the fixed 'github-dark' theme's literal colors, ignoring the site's actual light/dark mode - this made plain markdown-fenced code blocks (as opposed to the prototype's own SyntaxHighlightedCode component) always render a hardcoded dark box regardless of theme. Switch shikiConfig to the 'css-variables' theme so highlighted tokens resolve through --astro-code-* custom properties instead, then map those to the same brand color tokens the prototype's codeBlock uses (canvas-subtle background, border-muted border, brand text/link/accent colors for tokens). Raw markdown code blocks now match the prototype's bordered, canvas-subtle surface in both color modes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): show real contributor count on every page shell The contributor badge rendered 0 on Playbook, Cookbook, home and custom pages, and reverted to 0 on hydration everywhere else. Two causes: - Shells that bypass PageShell (LearningArticleLayout, PlaybookIndex, PlaybookArticleBody, CookbookIndex, HomePage, TopNav, Custom) defaulted contributorsTotal to 0 instead of the site-data value. - site-data read .all-contributorsrc with node:fs at module scope. Those shells are client:load hydrated, so the read threw in the browser and the count reset to 0 after hydration. The count is now read once in astro.config.mjs and inlined through vite.define as __CONTRIBUTORS_TOTAL__, so it is a literal in both the server render and the client bundle. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * style(website): soften catalog filter list scrollbars The filter option lists only set scrollbar-width: thin, so they rendered the platform default scrollbar. They now use the same muted, transparent track treatment as the article sidebar, which resolves through --brand-color-border-muted in both colour modes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * refactor(website): remove Access from tools panel from plugins catalog Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * feat(website): make Copilot app deep link the default plugin install Plugin detail pages exposed only a copyable CLI command. They now lead with a ghapp://plugins/install deep link in the same split-button ActionMenu the other detail pages use, keeping the CLI command available as a Copy action in the menu. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): migrate markdown remark plugins to unified processor Astro 7 deprecates markdown.remarkPlugins in favour of passing a unified() processor from @astrojs/markdown-remark. Moves the GitHub admonitions plugin into markdown.processor, clearing the startup deprecation warning. shikiConfig stays at the markdown level as it is not part of UnifiedProcessorOptions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): fail the build when the contributor manifest is unreadable Silently falling back to 0 is how the contributor badge regressed before, so a missing or malformed .all-contributorsrc now throws in production builds and warns in dev instead of shipping a wrong count. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Fix codespell and CodeQL findings in website components - Fix real typos flagged by codespell: 'Couldn't' -> 'Couldn't' (plain apostrophe, matching convention elsewhere in JSX) and 'Unparseable' -> 'Unparsable' in catalogFilters.ts - DetailChassis.tsx: replace sequential HTML entity unescaping with a single-pass replace to avoid double-unescape/injection risk flagged by CodeQL - SyntaxHighlightedCode.tsx: make the markup HTML comment regex match newlines so multi-line comments cannot break out of the token (Bad HTML filtering regexp) - pagefindSearch.ts: strip HTML tags in a loop until stable so nested/ malformed markup can't survive a single-pass strip (Incomplete multi-character sanitization) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): harden detail heading sanitization Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * github-app settings * Fix light-theme flash before dark mode applies on page load ThemeProvider colorMode="auto" from @primer/react-brand only resolves the real OS colour-scheme preference inside a useEffect, so its first render is always light. Add a synchronous inline script in <head> that reads prefers-color-scheme and stamps data-color-mode onto <html> before first paint, using the same attribute Primer Brand's CSS already keys off. React's own data-color-mode on the inner element takes over once it hydrates. Fixes #2820 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Fix light-mode scrollbar rendering in dark mode on Playbook articles .scrollHost (the article scroll region shared by Playbook articles, cookbook recipes, and extension detail pages) never declared a color-scheme, so the browser always painted its native scrollbar using light-mode chrome regardless of the site's active theme. Set color-scheme: light dark as a baseline and pin it explicitly to the resolved data-mode, and add scrollbar-color so Firefox picks up the themed thumb colour too. Fixes #2822 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Widen and center extension card preview image The Canvas Extensions overview card thumbnail was fixed at 360px, leaving uneven left/right margins within the card. Let it grow up to 440px and center it with margin-inline: auto so the image is balanced within the card. Fixes #2823 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Link Submit CTAs to each resource's contribution section The bottom "Submit" CTA on every catalog page pointed at the top of CONTRIBUTING.md, forcing readers to scroll and hunt for the relevant "how to contribute" instructions for that specific resource type. Point each catalog's CTA directly at the section that documents how to contribute that resource: agents, instructions, plugins, and skills link to their dedicated docs/README.*.md "How to Contribute" section, and canvas extensions link to CONTRIBUTING.md's "Adding Canvas Extensions" section (extensions have no dedicated README doc). Fixes #2824 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Center-align "View on GitHub" source link with its icon The source-link label sat on the default inline text baseline instead of being vertically centered against the GitHub mark icon next to it, so the two visually drifted apart. Wrap the icon and label in an inline-flex container with align-items: center so they share the same vertical center. Fixes #2825 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Fix mobile resource and Playbook article layout issues Clean up the shared resource detail and Playbook article styling so mobile pages no longer show unintended divider lines or overflow horizontally. - remove article-section divider borders so content separates with spacing instead of white/muted horizontal rules - drop the detail-page breadcrumb divider on mobile to match the Playbook mobile treatment - constrain raw markdown pre/code blocks to their column and let long code scroll horizontally - allow metadata chips to wrap inside the mobile sidebar instead of widening the page Fixes #2827 Fixes #2828 Fixes #2829 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Only show language selector on pages with real translations Most of the site is English-only, but the language selector rendered unconditionally on every page even though only the learning-hub/copilot-workshops/app track has mirrored translations. Add hasTranslations() to playbook-routes.ts, thread a showLanguageSelect prop through PageShell, TopNav and LearningArticleLayout, and compute it from the article's englishId in learning-hub/[...slug].astro so only translated Playbook articles show the selector. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Add Workshop recommended card to Playbook index The copilot-workshops hands-on tracks (VS Code, CLI, App, Cloud harnesses) existed and rendered correctly at direct URLs, but had no entry point in the new Playbook index UI -- the Articles grid intentionally excludes nested multi-page tracks by design, and the only prior link was buried in body prose. Adds a 'Workshop' recommended card (following the existing cli-for-beginners precedent) linking to /learning-hub/copilot-workshops/, and registers the route in pageHref.ts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Add a Workshop content-type filter to the Playbook The hands-on workshop tracks (CLI for Beginners, and the copilot-workshops harnesses) had no shared way to discover them from the Articles grid -- each had a recommended card, but no consistent categorization. Tags both workshop landing pages 'workshop', adds a new 'Workshop' Kind/content-type facet (derived the same way as the existing Terminology/Tutorial/Example kinds), and includes both landing pages in the Articles grid dataset so filtering by Content type > Workshop surfaces exactly the two tracks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Fix P0/P1 items from Brand Engineering audit (brand-experience#458) - P0: html lang now reflects the actually-rendered locale for a page, not the requested URL locale (BaseLayout.astro, playbook-routes.ts, PlaybookArticle.astro) - P0: markdown tables get tabindex=0 via enhanceMarkdownA11y, which Playbook articles were never running (PlaybookArticle.astro) - P0: long inline content and breadcrumbs no longer clip on narrow viewports (dotnet-upgrade.module.css, github-copilot-app.module.css) - P1: strip the markdown document's own leading H1 so detail pages don't render the title twice (detail-page.ts) - P1: document the hero secondary-CTA hex and InstructionsCatalog illustration colors as intentional prototype-fidelity values rather than defects (styles.module.css) - P1: add explicit Heading size props in PlaybookIndex.tsx Ref: github/brand-experience#458 * Rename Playbook to Learning Hub across UI and code Renames PlaybookIndex.tsx -> LearningHubIndex.tsx, PlaybookArticle.astro -> LearningHubArticle.astro, PlaybookArticleBody.tsx -> LearningHubArticleBody.tsx, PlaybookIcon.tsx -> LearningHubIcon.tsx, lib/playbook-routes.ts -> lib/learning-hub-routes.ts, and lib/playbook-article.ts -> lib/learning-hub-article.ts. Updates all call sites, UI copy, TopNav's playbookLabel prop, nav/search entries, and home page CTA data to use Learning Hub terminology. URLs under /learning-hub/* are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Port github-copilot-app as bespoke Learning Hub article Adopts the prototype's github-copilot-app.tsx directly as a dedicated React component instead of rendering it through the generic markdown pipeline, preserving its video carousel, comparison list, learn-more band, and other bespoke JSX exactly as designed. - New GithubCopilotApp.tsx under components/brand/learning-hub/, ported near-verbatim from the prototype (data-wiring only: pageHref import swap, media paths). - The two large source videos (~23MB, ~32MB) are not committed; the article falls back to their poster/webp images with a TODO to host them externally. - learning-hub-bespoke-articles.ts lists slugs that bypass the generic LearningHubArticle.astro pipeline. - [...slug].astro branches to the bespoke component for "github-copilot-app" (English only for now); all other slugs and locales keep the generic path. * Port bespoke Learning Hub articles Add bespoke Learning Hub article components for the remaining prototype-backed article pages, wire the cookbook index to the data-driven port, and route the CLI overview page through the new bespoke component. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Resolve merge validation blockers in astro config * Regenerate README docs after merging origin/main Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Fix Learning Hub Get started pages disappearing after opening (#2960) The bespoke Learning Hub article components (GithubCopilotApp, AgentsAndSubagents, CopilotConfigurationBasics, GithubCopilotTerminologyGlossary, UsingAutomationsInCopilotApp, WhatAreAgentsSkillsInstructions, WorkingWithCanvasExtensions, CliForBeginnersOverview, CookbookIndex) received the `pageHref` helper as a function prop passed into a `client:load` React island. Functions cannot survive Astro's client-hydration prop serialization, so the prop arrived as `undefined` on the client. The page rendered correctly server-side (visible briefly), then React threw `TypeError: pageHref is not a function` during hydration and unmounted the tree, making the page appear to disappear. Fixed by having each component import the `pageHref` singleton directly (as AgentDetail, HomePage, and the other catalog components already do) instead of receiving it as a prop, and removed the now unnecessary `pageHref={pageHref}` prop and its import from the two Astro routes that render these islands. Verified in the dev server: all 9 previously affected routes now hydrate without error, and `npm run build` completes successfully (1097 pages). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * Strip stray trailing divider from Learning Hub articles (#2961) Several Learning Hub markdown articles end their body with a trailing --- thematic break, left over from an authoring template. Rendered as-is it produced an unlabeled <hr> sitting directly above the page footer, with no heading/section boundary to justify it. Fix this generically in buildArticleSections() by stripping a single trailing <hr> from the rendered HTML before it's split into sections, rather than hand-editing every affected content file. This also protects future articles authored with the same trailing-rule habit. Legitimate mid-content dividers (e.g. between CLI lesson steps) are left untouched. * Remove emojis from Learning Hub article nav (#2962) CLI for Beginners lessons decorate their ## headings with emoji (e.g. "🎯 Learning Objectives"), which is fine inline in the article body but read as stray glyphs once surfaced as plain-text labels in the "In this article" nav — other Learning Hub pages don't emoji-decorate their nav, so this was inconsistent. Add a shared stripEmoji() helper and apply it to the nav labels built from markdown headings in LearningHubArticle.astro. The article body headings themselves are untouched. * Fix hero code blocks blending into background (#2963) Detail page hero install-command code blocks (SyntaxHighlightedCode via heroExtras) used the same background token as the hero surface itself (--brand-color-canvas-subtle), making them visually indistinguishable except for a thin border. Add a scoped .heroContent .codeBlock override in both shared style modules (dotnet-upgrade.module.css for catalog Detail pages/Cookbook, github-copilot-app.module.css for Learning Hub) that sets the background to --brand-color-canvas-default instead, so hero code blocks stand apart from the hero background. The base .codeBlock rule is left untouched since body-content code blocks (e.g. Cookbook recipe steps) correctly rely on canvas-subtle being distinct from the page's canvas-default background. * Tie color-scheme to dark mode for native scrollbars (#2964) Native scrollbars (the page scrollbar, and any overflow container without custom scrollbar styling, e.g. code block <pre> elements) are painted by the browser based on the color-scheme CSS property, not our design tokens. Only a handful of scoped containers (.scrollHost, .filterOptions, .sidebarSticky) had custom scrollbar-color rules; the page scrollbar and plain code-block overflow scrollbars had no color-scheme set at all, so they rendered with light OS-default scrollbars even when data-color-mode="dark" was set on <html>. Add a global rule tying html's color-scheme to the same data-color-mode attribute BaseLayout.astro already stamps on <html>, so every native scrollbar (and other UA-drawn form controls) follows the site's theme. * Unify article/detail page typography, tables, and dividers (#2965) Raw markdown injected into .articleSection (Skill/Agent/Instruction/ Plugin/Extension Detail pages via dotnet-upgrade.module.css, and Learning Hub articles via github-copilot-app.module.css) had no styling for headings, tables, horizontal rules, blockquotes, or inline code, so it fell back to inconsistent browser UA defaults -- most visibly, tables rendered with no borders or header emphasis at all. Add a shared set of rules to both CSS modules, scoped under .articleSection, that: - map raw h1-h6 onto the brand type scale (font, weight, line-height) - give hr a full-width divider matching the border-muted token - style blockquote with a left accent bar - render inline `code` (outside <pre>) as a small chip, matching .inlineCode used elsewhere for hand-authored tokens - style table/th/td with bordered cells and a canvas-subtle header row, scrolling horizontally on narrow viewports Also fix skills/acquire-codebase-knowledge/SKILL.md: a stray blank line inside the "Bundled Assets" table split it into a lone header row and a second block with no header, so GFM table parsing stopped after the first row and the remaining rows rendered as literal pipe-delimited text instead of a table -- this was the exact bug shown in the issue screenshot. * fix: align previous/next navigation links horizontally on Detail pages Detail page Previous/Up next links were stacked vertically. Change .nextUp to a row layout (space-between) so Previous sits left-aligned and Up next right-aligned on the same row, with a max-width: 40rem media query reverting to a stacked column layout on small screens. Use an explicit .nextUpNext modifier class (applied to the "Up next" link specifically) with margin-inline-start: auto instead of a positional :last-child selector, so the link right-aligns correctly even when it is the only link present (e.g. the first item in a catalog, which has no Previous link). Fixes #2966 * fix: align callout blocks with article content width The .proTip callout (Note/Tip/Caution admonitions in Learning Hub articles, and the "Maintained outside this repository" notice on external Plugin Detail pages) had its own 32px horizontal margin. The prototype places this callout as a sibling of .articleSection (which has no horizontal padding of its own), using that margin to align its edges with the section's own 32px padding. Our port always renders it nested *inside* an already-padded .articleSection, so the extra margin doubled up with that padding, making the callout visibly narrower than the surrounding paragraph/table text -- most obvious on narrow viewports. Remove the horizontal margin (keep only the bottom spacing) in both dotnet-upgrade.module.css and github-copilot-app.module.css so the callout's internal padding lines up with the article text on both edges, at all viewport widths. Fixes #2967 * fix: standardize mobile card padding across resource pages Agents, Instructions, Skills, and Plugins catalog cards (.item) used the desktop 60px padding at every viewport, including phone widths, because their @media (max-width: 47.99rem) block never reduced it -- unlike the Extension catalog, which drops to a 32px inset at that breakpoint. This made cards on those four catalogs look inconsistently over-indented on mobile compared to Extension cards. Add the same `.item { padding: var(--base-size-32); }` override to the mobile media query in agents.module.css, instructions.module.css, and skills.module.css. plugins.module.css already had an override, but with an asymmetric 32px/24px padding -- normalized it to the same 32px on all sides used everywhere else. Fixes #2968 * fix(website): address PR review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): preserve legacy resource links Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): bump transitive js-yaml to patched versions Force astro's js-yaml dependency to 4.3.2 and front-matter/gray-matter's to 3.15.2 via npm overrides, fixing GHSA-52cp-r559-cp3m and GHSA-5p4m-2wfm-xmqj (quadratic-complexity DoS via YAML merge keys and !!omap resolution). Addresses github/vuln-mgmt#209786. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): address redesign follow-up issues Fix light-mode favicon contrast with an adaptive SVG mark, allow YouTube embeds through the site CSP, and align resource catalog sort controls with the Playbook article sort treatment across Agents, Instructions, Skills, Plugins, and Extensions. Addresses #3006, #3007, #3008. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): address PR review feedback Respect reduced-motion preferences in detail TOC scrolling, restore default search indexes for bespoke Playbook pages, add pagination scroll/focus handling to the Agents catalog, sanitize contributor and cookbook URLs before rendering external links, index extension records in Pagefind, and restore install affordances for marketplace-backed external extensions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): revert Learning Hub naming from Playbook rename Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * chore(website): update stale Playbook comments to Learning Hub Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): align source label in detail sidebar Fixes #3207 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 * fix(website): address security review feedback Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80686fef-efe3-4cdd-8cd6-bfa61a5d0af6 |
||
|
|
aa5b334aac |
Fixing readme (#2969)
* Had a bad readme merge recently, fixing * Excluding the bin and obj of .NET output from skills file list |
||
|
|
2ba72cd142 |
Fix external canvas extension validation (#2928)
* fix(intake): accept nested canvas extension entry points Allow canvas entry points at any depth under the com.github.copilot namespace, including materialized extensions/<name> layouts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eb2554c-9e4a-408c-92f5-36306c99d33b * fix(intake): require named canvas extension directories Require canvas entry points at com.github.copilot/<extension-name>/extension.mjs and reject flat or deeper layouts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eb2554c-9e4a-408c-92f5-36306c99d33b * fix: align external canvas plugin layout Require canvas extensions under com.github.copilot/extensions/<extension>/extension.mjs, matching github-app discovery and reject legacy layouts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eb2554c-9e4a-408c-92f5-36306c99d33b * test: cover canvas logo validation, fix directory-mismatch message Add intake regression tests for a missing/malformed com.github.copilot namespace and an incorrect logo path. Fix the quality gate to report a file-vs-directory mismatch instead of a generic missing-entry-point message when extension.mjs exists but is a directory. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eb2554c-9e4a-408c-92f5-36306c99d33b --------- Copilot-Session: 3eb2554c-9e4a-408c-92f5-36306c99d33b |
||
|
|
71f7c9b1dc |
fix(eng): list nested skill assets instead of directory names 🤖🤖🤖 (#2765)
* fix(eng): list nested skill assets instead of directory names * test(eng): clean up temp dirs and cover nested SKILL.md assets * fix(eng): do not follow symlinks when listing bundled assets * fix(eng): keep file symlinks in bundled asset lists |
||
|
|
37dcfd2325 |
fix(plugins): discover MCP servers from mcp.json at plugin root (#2713)
* fix(plugins): discover MCP servers from spec-mandated mcp.json at plugin root MCP config was declared via an extensions.com.github.awesome-copilot.mcpServers pointer to a .mcp.json file. That namespace is stripped from the served manifest, so nothing carried the MCP declaration through materialization. Per Agent Plugins v1.0.0 the fixed location is mcp.json at the plugin root, which already ships as-is. Drop the pointer, rename both .mcp.json files, and validate mcp.json (schema, closed top-level fields, server transport variants). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Validate mcp.json against the full v1.0.0 schema with Ajv Replace the hand-rolled MCP checks with Ajv validation against the canonical Agent Plugins v1.0.0 MCP schema, so non-spec configs (empty command/url, non-string args, reserved PLUGIN_ROOT/PLUGIN_DATA env keys, invalid cwd, unknown server fields) are rejected. Per-server errors are re-derived from the matching discriminated branch to avoid unhelpful oneOf output. Also reject a top-level extensions.mcpServers placement, which slipped through because the manifest schema allows arbitrary object-valued extension keys. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Strengthen mcpServers and stdio semantic validation Reject mcpServers under any extensions namespace in plugin.json so inline MCP config cannot bypass root-level mcp.json enforcement. Also run stdio semantic checks after schema validation to reject absolute command paths and cwd values that escape the plugin root, with regression tests for both cases. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Enforce MCP path containment across platform path styles Resolve plugin-relative commands and placeholder-rooted cwd values against the plugin root, normalize Windows separators, and reject lexical or symlink escapes. Add regression coverage for traversal, placeholders, Windows paths, and symlink targets. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Align MCP semantics with the v1.0.0 specification Restore the canonical cwd pattern and literal ./ command prefix. Validate remote HTTP URLs and headers, including HTTPS requirements, header syntax, control characters, and case-insensitive duplicates. Keep PLUGIN_DATA checks lexical-only so it is not conflated with the plugin filesystem root. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Reject unsafe MCP symlink paths Resolve mcp.json through the filesystem and require a regular file inside the real plugin root, reporting dangling links explicitly. Harden command and PLUGIN_ROOT containment checks to inspect symlink ancestors with lstat and realpath instead of treating unresolved paths as ordinary missing segments. Add regression coverage for outside, dangling, and ancestor symlink cases. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Handle mixed separators in MCP data paths Split PLUGIN_DATA traversal checks on both slash types so mixed separators cannot bypass lexical containment on Windows clients. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 * Reject credentials in MCP package headers MCP headers are visible package data, so reject credential-bearing headers including authorization, proxy authorization, cookies, and common API-key or token names. Preserve ordinary custom headers and add focused regression coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 764c5bb4-2811-4dc1-b61d-56c4a5597cc9 |
||
|
|
55b952d2f9 |
fix(plugins): namespace Copilot materialized content (#2643)
Place Copilot-specific content in com.github.copilot and remove unsupported command handling. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 04c14c3f-d248-4a7f-93ab-93fd8b2b119e |
||
|
|
280b05dc88 |
feat: surface external plugin review signals (#2623)
* feat: surface external plugin review signals Add repository and homepage heuristics to external plugin intake and use eyes reactions for approval decisions.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: b745e915-6c5a-4354-ab77-5b52f9e66fea * fix: harden external plugin review signals Validate homepage destinations and bound response reads, and correct repository activity metrics.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: b745e915-6c5a-4354-ab77-5b52f9e66fea * fix: pin external homepage requests Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: b745e915-6c5a-4354-ab77-5b52f9e66fea * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: b745e915-6c5a-4354-ab77-5b52f9e66fea |
||
|
|
39225356d9 |
fix(website): resolve extension owner plugin
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 31016278-f98b-48ef-8a77-430091b34b91 |
||
|
|
ec705989e3 |
fix(plugin-validation): allow parent-bundled extensions
Accept reusable canvas sources that are referenced by an existing parent plugin, matching the post-#2546 scaffolding guidance, while continuing to reject orphaned sources. Cover parent-only, standalone, and orphaned registrations. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 52be9c67-3ae4-4610-93d0-fe0b7ab95ccb |
||
|
|
a7fdcd5006 |
Migrate plugins and canvas extensions to Agent Plugins spec (#2546)
* feat: migrate plugins and extensions to Agent Plugins v1.0.0 spec - Add \ to all 69 curated plugin manifests - Migrate all 18 extension manifests: add \, move logo into xtensions.com.github.copilot.logo namespace, remove top-level logo and string xtensions: '.' - Update eng/validate-plugins.mjs: require \, validate namespace-keyed extensions object for canvas extensions, widen name pattern to allow dots (spec §5.5, max 64 chars) - Update eng/materialize-plugins.mjs: emit spec-clean served manifests (only spec fields: \, name, version, description, author, homepage, repository, license, keywords, extensions) - Update eng/generate-website-data.mjs: read logo from namespace with fallback to top-level logo for compatibility - Update eng/create-plugin.mjs: scaffold emits \ - Add .github/workflows/validate-plugins.yml: blocking CI for PRs touching plugins/** or extensions/** - Add spec compliance check to external plugin quality gates: non-blocking warnings with ✅/⚠️/🛑 emoji legend - Update AGENTS.md: document new extension manifest shape, add \ to plugin checklist Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * refactor: consolidate canvas extension plugins - Move all extension plugin manifests from extensions/<name> to plugins/<name> - Keep extensions/<name> as reusable source only - Remove standalone extension discovery from marketplace and website plugin catalogs - Auto-bundle same-name extension sources during materialization - Add build-only extensions.json references for sharing extensions across plugins - Remove x-awesome-copilot extension metadata support - Update validation and contributor documentation Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * feat: add canvas extension scaffolding skill - Add repo-local skill for creating canvas extension sources - Generate spec-compliant plugin manifests under plugins/ - Support registering reusable extensions with multiple plugins - Remove guidance for extension-local plugin manifests and custom fields Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * fix: align extension namespaces with current guidance - Use each extension ID as its manifest namespace key - Update validation and website generation to resolve extension-specific namespaces - Upsert plugin validation PR comments using the existing repository pattern Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * fix: use Copilot extension namespace - Adopt com.github.copilot for all canvas extension manifests - Require the namespace during validation and website generation - Update extension scaffolding guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * docs: regenerate plugin catalog after merge Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * refactor(plugins): move manifests to plugin roots Use root plugin.json manifests and namespaced extension directories throughout local tooling, validation, generation, and contributor documentation. Restore materialize-plugins.mjs line breaks so the source remains readable in GitHub. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * feat(plugins): migrate manifests to namespaced composition Move repository composition metadata under com.github.awesome-copilot, materialize reusable extensions into the plugin extensions directory, and improve contributor and PR validation guidance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * fix(validation): address plugin review findings Restore executable build scripts, validate namespaced manifests and hook directories, improve README item counts, and manage validation comments across reruns. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: 8f3a88cb-e01e-4760-8125-460490dc1a76 |
||
|
|
be7a1cf734 |
Harden external plugin validation: semver, SPDX, email, and unknown-field checks (#2445)
* Harden external plugin validation: semver, SPDX, email, unknown fields Extend the canonical external-plugin validator with Open-Plugins-aligned rules, reusing the shared validation functions rather than duplicating checks: - version: enforce Semantic Versioning (allows prerelease/build metadata) - license: validate SPDX identifiers/expressions; warn (not error) on well-formed-but-unrecognized ids so existing entries like SSAL-1.0 pass - author.email: validate format when present - unknown-field detection: warn on typo'd top-level/author/source keys - immutable locator: marketplace warns when source lacks ref/sha; publicSubmission keeps the existing hard error Add eng/external-plugin-validation.test.mjs (node:test) covering each rule plus a regression that committed external.json passes marketplace policy with zero errors. Update CONTRIBUTING.md accordingly. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Make license non-SPDX a warning and share license check with local plugins The agent-plugins-spec schema does not enforce SPDX, and plugins may use proprietary/non-OSS licenses. Relax license validation so any non-empty license string that isn't a recognized SPDX identifier/expression produces a warning rather than an error. Extract the license check into a reusable validateLicenseField() and apply it to both external plugins and local plugin.json manifests via eng/validate-plugins.mjs, so licenses are validated consistently in one place. Update tests and CONTRIBUTING.md accordingly. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Extract shared license validation into eng/lib/license.mjs Move the SPDX constants and license validation (validateLicenseField, isRecognizedSpdxExpression) out of external-plugin-validation.mjs into a dedicated eng/lib/license.mjs module. Both the external plugin catalog validator and the local plugin.json validator now import license logic from this neutral shared module instead of one validator importing from the other. Behavior is unchanged; tests import from the new home. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Fix SPDX license parsing correctness and warning-message injection Rewrite isRecognizedSpdxExpression as a recursive-descent SPDX license expression parser to address PR review feedback: - Validate LicenseRef-/DocumentRef- grammar (non-empty idstring; DocumentRef requires the ":LicenseRef-<id>" suffix) instead of accepting any token with that prefix. - Parse parentheses with balance and placement checks rather than stripping them, so malformed groupings like "(MIT", "MIT)", and "MIT OR (Apache-2.0))" are no longer silently treated as valid. - Treat WITH as a distinct operator whose right operand must be a known SPDX license exception, so "MIT WITH Apache-2.0" and "GPL-2.0-only WITH MIT" are rejected while "GPL-2.0-only WITH Classpath-exception-2.0" is recognized. - Sanitize the untrusted license value in the non-SPDX warning (collapse whitespace, truncate, escape backticks, wrap as inline code) since the warning is rendered verbatim into a Markdown bot comment during intake. Malformed SPDX stays a warning (never an error) so proprietary and non-OSS license strings remain allowed. Adds targeted grammar and sanitization tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Complete backslash escaping and run source unknown-field check for all sources Address two PR review findings: - eng/lib/license.mjs: sanitizeForMessage now escapes backslashes before backticks so the inline-code warning value is fully escaped, resolving a CodeQL "incomplete string escaping" alert. A raw backslash in a license value is now doubled rather than left to combine with a following escaped backtick. - eng/external-plugin-validation.mjs: move the source unknown-field check out of validateGitHubSource into the outer source-object branch so it runs for every object source and then dispatch by source.source. A typo in the source discriminator (e.g. "soruce") or an unsupported source type now still surfaces the unknown-field warning instead of being silently skipped. Adds regression tests for both behaviors. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Harden Markdown safety of validation warnings via inlineCode helper External-plugin validation warnings are rendered verbatim as Markdown list items in the intake bot comment, so untrusted values interpolated into them are an injection vector. Add eng/lib/markdown.mjs exporting inlineCode(), which wraps a value in a code span fenced with more backticks than any run in the content (and pads leading/trailing backticks). This cannot be broken out of, unlike the previous backslash escaping, which does not work inside code spans. - lib/license.mjs: replace sanitizeForMessage with inlineCode for the non-SPDX license warning. - external-plugin-validation.mjs: wrap unknown-field keys (attacker controlled JSON object keys) with inlineCode so newlines/Markdown in a key can no longer inject a new list item. - Add inlineCode unit tests and injection-neutralization tests for both the license value and unknown-field key paths. Addresses PR review comments 3679379606 and 3679434134. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 * Fixing codespell --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: eaa5eed6-5b65-4b28-9904-24f380d26728 |
||
|
|
8ae5a99109 |
Enforce external plugin ref/sha consistency (#2463)
* Enforce external plugin ref/sha consistency Extract shared ref/sha normalization and consistency checks into eng/lib and reuse them in intake plus quality gate flows. Add a dedicated ref/sha consistency quality gate surfaced in PR/intake summaries, and add targeted tests for matching and mismatched refs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 6afe21ad-eafa-4c90-a1f2-053dedac7625 * Address review: tree/blob ref errors and PR workflow ref/sha column - resolveCommitShaAtReadRef: classify rev-parse failure as 'fail' instead of 'infra_error' because a successfully-fetched ref that doesn't dereference to a commit is a submitter problem, not infra. - validateRemoteRepository (intake): treat HTTP 422 from the commit endpoint as a submitter error; all other non-404 errors remain transient warnings requiring maintainer re-run. - external-plugin-pr-quality-gates.yml: add ref/sha consistency column to the per-plugin quality table and failure details block. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 6afe21ad-eafa-4c90-a1f2-053dedac7625 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 6afe21ad-eafa-4c90-a1f2-053dedac7625 |
||
|
|
63c2527ace |
Accept nested extensions/<name>/extension.mjs in external-plugin canvas checks (#2403)
* Accept nested extensions/<name>/extension.mjs in external-plugin canvas checks The external-plugin canvas structure check (quality gate) and intake validation both hardcoded a flat extensions/extension.mjs entry point, falsely rejecting the documented nested extensions/<name>/extension.mjs layout that installs and runs fine. Scan the extensions/ directory for a nested subfolder containing extension.mjs while still accepting the flat form for backward compatibility. Applied to both runCanvasStructureGate (git-object lookups) and validateCanvasPluginMetadata (Contents API), keeping them behaviorally aligned. Added regression coverage for both paths. Fixes #2402 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Harden nested canvas extension detection after adversarial review Address multi-model review findings on the nested canvas extension fix: - Quality gate: enumerate extensions/ via 'git ls-tree -z' with spawnSync (NUL-delimited, untruncated) so large directories no longer drop the real entry past the 12KB output cap. - Intake: decouple the flat extensions/extension.mjs check from the directory listing, require an array listing (Array.isArray) before treating it as a directory, and surface an unverifiable (warning) result instead of a false rejection when the listing or a nested lookup hits a transient API error. - Add regression tests: nested entry beyond the legacy output cap (gate) and unverifiable/flat-still-accepted paths when the listing errors (intake). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Enumerate canvas extensions via a single recursive Git Trees call in intake Address PR review: the Contents API caps directory listings at 1,000 entries and required one request per extension subfolder, so a nested entry beyond the cap could be falsely rejected (the same truncation class the git gate avoids) and large repos risked latency / rate-limit exhaustion. Replace the per-subfolder Contents API enumeration with one recursive 'git/trees/<locator>?recursive=1' fetch and inspect 'extensions/extension.mjs' and immediate 'extensions/<name>/extension.mjs' paths locally. A truncated tree without a located entry point is reported as unverifiable (warning) rather than rejected, and refs are normalized so 'refs/tags/<tag>' resolves as a tree-ish. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Bound canvas extension discovery to plugin scope Address reviewer feedback on unbounded scaling for untrusted/large repos: - Quality gate: replace the per-candidate-directory git cat-file spawns in locateCanvasEntryPoint with a single recursive git ls-tree over the extensions subtree, classifying flat/nested entry points in memory. Process count is now constant regardless of how many folders live under extensions/. - Intake: stop fetching the recursive git tree from the repo root (which a large unrelated monorepo can push past the Trees API truncation limit and never validate). Walk to the plugin's extensions directory one level at a time to resolve its tree SHA, then fetch only that subtree recursively, so verifiability depends on the plugin's own size, not the whole repository. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> |
||
|
|
8e137c3c09 |
Harden external plugin PR quality gate rendering and name validation (#2444)
* Harden external plugin PR quality gates Reference: https://github.com/github/awesome-copilot/pull/2398 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: a79923be-c65f-4d51-8fe3-a86e05fd02f1 * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: a79923be-c65f-4d51-8fe3-a86e05fd02f1 |
||
|
|
7351f9f692 |
Fix external-plugin quality gates for tag-name locators (#2397) (#2399)
runVersionMatchGate and runCanvasStructureGate read locator content with git show/cat-file. For a tag-name locator, `git fetch origin <tag>` only updates FETCH_HEAD and never creates refs/tags/<tag>, so `git show <tag>:...` died with 'invalid object name' and produced a false infra_error. Read the primary locator via HEAD (already checked out during clone) and non-primary locators via FETCH_HEAD after fetching, instead of the bare locator. This handles SHAs, short tag names, and fully-qualified tag refs uniformly without classifying the locator. Adds regression coverage for the tag-locator path in both gates. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> |
||
|
|
26fe2d126b |
Fix extension materialization to move bundles into container (#2339)
* Migrate extension plugin materialization layout Materialize extension plugins into a dedicated extensions/ container, validate the new manifest convention, and bump extension plugin versions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Keep extension manifests source-compatible Restore source extension manifests to "extensions": "." while preserving materialization-time rewrite to "extensions" in distribution output. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Validate canvas extension layout for external submissions Add intake and quality-gate checks for canvas-tagged external plugins so they must include extensions/extension.mjs and optional manifest extensions is validated when present. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Fix plugin clean extension pass and typo guard text Declare EXTENSIONS_DIR in clean-materialized-plugins and run extension cleanup once after plugin cleanup. Also normalize misspelled-key detection strings to satisfy spelling checks without changing validation behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Proper codespell fix * Separate canvas structure quality gate status Track canvas structure as its own gate status and output, include it in aggregate summaries, and enforce Git object types so extensions/ is a tree and extensions/extension.mjs is a blob. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Move extension bundles during materialization Change extension-plugin materialization to move root bundle entries into extensions/ instead of copying them, and assert originals are removed in test coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Nest materialized extension bundles by plugin name Materialize extension plugins into extensions/<plugin-name>/... (moved entries) so resulting paths are duplicated by design, and bump extension plugin versions to the next patch release. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Fix extension materialization publish and cleanup Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Preserve root extension logo asset Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 |
||
|
|
40665c23b7 |
Migrate extension plugin materialization to extensions container (#2334)
* Migrate extension plugin materialization layout Materialize extension plugins into a dedicated extensions/ container, validate the new manifest convention, and bump extension plugin versions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Keep extension manifests source-compatible Restore source extension manifests to "extensions": "." while preserving materialization-time rewrite to "extensions" in distribution output. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Validate canvas extension layout for external submissions Add intake and quality-gate checks for canvas-tagged external plugins so they must include extensions/extension.mjs and optional manifest extensions is validated when present. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Fix plugin clean extension pass and typo guard text Declare EXTENSIONS_DIR in clean-materialized-plugins and run extension cleanup once after plugin cleanup. Also normalize misspelled-key detection strings to satisfy spelling checks without changing validation behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Proper codespell fix * Separate canvas structure quality gate status Track canvas structure as its own gate status and output, include it in aggregate summaries, and enforce Git object types so extensions/ is a tree and extensions/extension.mjs is a blob. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: d26008fb-9928-4ba7-b7c8-36f35320f7c1 * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
f0da81e14a |
Adding logic to render external plugins with canvases in the canvas gallery (#2323)
* Adding logic to render external plugins with canvases in the canvas gallery * Fix external canvas plugin URL encoding and keyword detection Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: db85480e-d839-4f69-8271-08f8cc845596 * Fail fast on external plugin errors and fix external install links Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: db85480e-d839-4f69-8271-08f8cc845596 |
||
|
|
fb80ec4f21 |
Add canvas-specific intake validation for external plugins (#2319)
* Add canvas-aware checks to external plugin intake Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f03fd92-3bfa-4c67-a709-177fbd46c40e * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
9cdc660675 |
Removing hooks, workflows, and tools from website (#2292)
* Removing some features from the home page of the website hooks, agentic workflows, and tools are removed - these are minimally used parts of the website * Removing the pages and their references * removing from the readme * Adding the awesome copilot MCP server to our plugin and showing that in the rendered page * Fix broken docs links and MCP plugin docs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4215785a-7e6e-49c5-abaa-c39b0793a11e |
||
|
|
61dda50523 |
Add version parity checks to external plugin quality gates (#2307)
* Add external plugin version-match gate Enforce external.json version matching against remote plugin.json for source ref and/or sha in shared quality gates, and surface the new gate status/output in intake and PR workflows. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8aa3e98d-1873-4cab-8866-1b2efd0f24ad * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
bb4766e226 |
Fix external plugin gate manifest paths and diagnostics (#2261)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> |
||
|
|
e03696a5bf |
Replace resource modals with dedicated detail pages and richer install options (#2246)
* feat(website): dedicated agent detail pages instead of modal Replace the popup/modal viewer for agents with dedicated per-agent pages at /agent/<id>/ for real URLs and better deep linking. - Build-time rendered docs (marked + gray-matter) with a details sidebar - Sidebar Actions card: Install split-button (VS Code/Insiders/Download/Copy markdown), Share, View on GitHub - Cards now link natively via anchors (no modal); card-render gains optional href (backward compatible for other types) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * feat(website): dedicated instruction detail pages + shared detail layout Extend the dedicated detail-page pattern (introduced for agents) to instructions, and factor the shared behavior/styles out for reuse: - Add instruction/[id].astro with build-time markdown render, breadcrumb, install split-button (VS Code/Insiders/Download/Copy markdown), Share, View on GitHub, and a details sidebar (Applies to / Source / Last updated) plus collapsible frontmatter. - Extract shared client behavior into resource-detail.ts (renamed from agent-detail.ts) keyed on [data-resource-detail]. - Move detail-page CSS into global.css under .resource-detail-page. - Point the agent detail page at the shared script/styles. - Instruction cards now link to /instruction/<id>/ and the modal is removed from the instructions listing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor(website): extract shared detail-page components Break the agent and instruction detail pages down into reusable Astro components under src/components/pages: Breadcrumb, Header, Main, Sidebar, SidebarChips, InstallButtons, and RawMarkdown. Both detail pages now compose these components instead of duplicating markup. Fix RawMarkdown to read the `markdown` prop (matching both call sites) and emit exact text via set:text, which restores the Copy markdown action that had silently broken when the hidden textarea stopped rendering. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor(website): share detail-page build logic in lib/detail-page Both detail pages duplicated the install/GitHub URL builders, the build-time markdown read+render, and the last-updated formatting. Move all of it into a DOM-free build-time helper (src/lib/detail-page.ts) exposing loadDetailPage(item, type), and reduce each [id].astro to a single call plus its type-specific chip data. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add dedicated skill detail pages with multi-file browser Migrate skills from the popup/modal viewer to dedicated per-item pages (/skill/<id>/) matching the agent and instruction detail pages. Skills need a few skill-specific mechanics: - Install via `gh skills install github/awesome-copilot <id>` (copyable), since skills have no VS Code install URL. - Download ZIP for the multi-file skill contents. - A file browser that defaults to SKILL.md and lets you inspect other files, with Shiki syntax highlighting for code and marked-rendered markdown. SKILL.md is embedded (rendered + raw) at build time; other files are lazy-fetched on demand and cached. Deep links via #file=. Also fixes a production build regression in the shared detail-page helper: repoRoot now resolves via process.cwd() instead of import.meta .url, which resolved incorrectly once bundled and silently returned empty markdown (breaking rendered docs + copy-markdown for agents and instructions too). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Replace skill file list with a dropdown selector The two-column file browser (side list + content pane) was cramped, splitting the already-narrow main column in half. Replace the side list with a dropdown in the file view header so the content pane spans the full width. - Multi-file skills get a <select> grouped by folder via <optgroup>, SKILL.md first. Single-file skills keep a static filename label. - Client script drives selection from the <select> change event instead of the removed file buttons; deep links, copy-file, Download ZIP, and Share all read the file list from the select options. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix skill sidebar card overflowing its column The install command in the actions card used white-space: nowrap, which gave the grid tracks a large min-content size. Grid items default to min-width: auto (won't shrink below content), so the actions card grew past the 352px sidebar, making it look wider than the agent/instruction sidebars. Add min-width: 0 down the sidebar grid chain so the command box stays within the column and scrolls horizontally instead. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Make skill file content pane grow to full page height Remove the fixed max-height/overflow on .skill-file-content so file content flows to natural height and the page scrolls, instead of a nested inner scroll region. Shiki <pre> keeps its own horizontal scroll. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Center-align skill file picker label with the select Reset the Starlight-injected margin-top on .skill-file-select so the 'File' label and the dropdown share a common vertical midline. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Render code files edge-to-edge in skill file viewer For code files, drop the container padding and the pre border/radius so the highlighted code fills the full column width. Markdown files keep their padded, bordered layout. Toggled via an is-code class on the content pane based on the selected file kind. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add dedicated detail pages for hooks with a reusable file browser Hooks had no good install path (manual copy or ZIP), so mirror the Skills dedicated-page pattern: a multi-file browser plus a Download ZIP action, replacing the modal on the hooks listing. Generalise the Skills-specific file browser so both resource types share one implementation: - Rename SkillFileBrowser.astro -> FileBrowser.astro with neutral props. - Rename skill-detail.ts -> file-browser.ts with neutral data attributes (data-file-browser-page, data-bundle-id, data-primary-file). - Rescope install-slot styles under a shared .bundle-detail-page class. - generate-website-data: rename getSkillFiles -> getFolderFiles and emit a files[] + readmeFileName for each hook. Hooks list cards now deep-link to /hook/<id>/ instead of opening a modal. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add dedicated detail pages for workflows Migrate agentic workflows from the popup/modal viewer to dedicated per-item pages (/workflow/<id>/) with deep linking, matching the pattern used for agents, instructions, skills, and hooks. Workflows are single .md files, so they reuse the single-file detail components (Main, Sidebar, Header, Breadcrumb, RawMarkdown) and the resource-detail client script. Since workflows have no VS Code install, the install slot instead documents the gh aw CLI flow and offers Download + Copy markdown actions. Also rescope the shared install-slot CSS from .bundle-detail-page to .detail-actions-card so skill, hook, and workflow pages share it without a page-specific class, and drop the now-unused bundle-detail-page class from the skill and hook pages. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Format workflow install note Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add dedicated plugin detail pages Replace the plugins modal with dedicated /plugin/<id>/ pages that deep link, render the bundled README, and surface an Included items section linking each constituent agent/skill/instruction/hook to its own detail page (falling back to GitHub for items without a page, e.g. extensions). - generate-website-data: resolve plugin items to detail URLs + titles, add readmeFile for local and extension-derived plugins - new IncludedItems component groups bundled resources by kind - plugin/[id].astro handles local, extension-derived, and external plugins with VS Code + CLI install actions - resource-detail: copy-install handler shared with detail pages - plugins list cards now deep link; modal wiring removed Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Show plugin version, ref, and commit in detail sidebar Capture version from plugin.json (local + extension-derived) and external.json, and surface it in the plugin detail Details card. For external plugins, also show the pinned source ref and short commit SHA when present. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add dedicated canvas extension detail pages with preview gallery Replace the extensions modal with per-extension pages at /extension/<id>/, mirroring the skill/plugin detail layout. Each page shows a preview image gallery, README docs (or an About fallback), and a sidebar with install actions and details (version, canvas ID, keywords, author, commit). - generate-website-data.mjs: emit readmeFile for extensions - extensions-render.ts: deep-link cards to detail pages - extensions.ts: strip modal/gallery wiring, keep filter/sort/copy actions - resource-detail.ts: add copy-install-url action - extension-gallery.ts: thumbnail switching for multi-image previews Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add VS Code Insiders and GitHub Copilot app install links Introduce a shared PluginInstall component used by both plugin and canvas extension detail pages. It renders a split-button dropdown deep-linking into VS Code, VS Code Insiders, and the GitHub Copilot app (ghapp://), plus the CLI command for internal items. - Internal plugins/extensions: ghapp://plugins/install?source=<id>@awesome-copilot - External plugins: ghapp://plugins/marketplace/add?source=<owner/repo> - ghapp source values are URL-encoded per the app's deep-link contract Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Make GitHub Copilot app the default install option Promote the ghapp:// deep link to the primary split-button action and list it first in the dropdown, ahead of VS Code and VS Code Insiders. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Ignoring impeccable files * Make Extensions grid Copy Install a direct Copilot app install Replace the CLI-command copy button on extension cards with an 'Install in Copilot app' deep link (ghapp://plugins/install) for internal extensions, matching the detail page. External extensions keep the Copy URL fallback since they have no Copilot app install path. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR review feedback on detail pages - Remove DOM innerHTML read/write round trip in file browser cache (CodeQL js/xss-through-dom); seed primary file from raw text and render lazily. - Use Shiki dual light/dark themes in the file browser and add dark mode CSS overrides. - Guard decodeURIComponent for #file= deep links against malformed percent-encoding. - Slugify SidebarChips title before using it in the tag class name. - Use a neutral aria-label on the shared detail Sidebar. - URL-encode the external plugin source in VS Code and Insiders install links. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Prevent client-side path traversal in file deep links Addresses the CSPT-to-XSS class reported in github/open-source#1739. A '#file=' hash value containing '../' sequences could resolve outside the awesome-copilot repo prefix once normalized by fetch, loading attacker-controlled content that was then rendered into the page. - Add isSafeRepoFilePath() and enforce it at the raw-URL choke point (getRawGitHubUrl, fetchFileContent, downloadFile, getVSCodeInstallUrl), so no consumer can escape the repo prefix. - Validate the decoded '#file=' path in the modal hash handler and guard its decodeURIComponent against malformed input. The new hash-based file browser already restricts deep links to an allowlist of build-time file descriptors; the choke-point guard is an additional backstop. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix accessibility violations on resource detail pages Run the a11y audit against the new detail pages and resolve every critical/serious axe violation it surfaced: - Nest the detail column as a <div> instead of a second <main>, fixing the duplicate/non-top-level/non-unique landmark rules on every detail page. - Add a shared enhanceMarkdownA11y() helper that makes rendered <pre>/<table> blocks keyboard focusable and gives task-list checkboxes a state-based accessible name; apply it at build time and in the client file browser. - Make Shiki-highlighted code and install-command <code> blocks focusable. - Underline links inside rendered docs and install notes so they are distinguishable without color, overriding the global #main-content reset. - Extend the a11y audit to cover one representative page per detail type. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix file browser GitHub URL handling Encode selected file paths before assigning GitHub detail links and render load errors with DOM APIs so DOM-derived file names are not reinterpreted as markup. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR review feedback on detail pages and file browser - Deep-link plugin extension items to their /extension/<id>/ detail pages: generate canvas extensions before building the resource index, and index extensions (by id and folder basename) so resolvePluginItem can resolve them. - Render image files in the bundle file browser via an <img> tag built from the safe raw URL instead of decoding binary assets as UTF-8 text; skip the copy-file action for images. - Use a neutral 'Install' heading on internal plugin and extension pages so the split-button primary label accurately communicates the target. - Warn (with the file path) when readResourceMarkdown fails instead of swallowing the error silently, keeping the build unbroken. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR review feedback on install links, dropdown a11y, and ZIP downloads - externalRepoUrl (plugin detail pages) now builds the 'View on GitHub' tree URL from the pinned source.ref or source.sha, falling back to main only when neither is present, so the link matches the sidebar Ref/Commit chips. - Install split-button dropdown on resource detail pages is now keyboard accessible: opening focuses the first item, ArrowUp/ArrowDown wrap, Home/End jump, and Escape closes and restores focus to the toggle, mirroring modal.ts. - downloadZipBundle fetches each file as an ArrayBuffer and hands it to JSZip so binary assets (PNG/JPG/etc.) are preserved instead of corrupted by UTF-8 text decoding. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR review feedback on external repo links and workflow install note - externalRepoUrl now uses a pinned source.ref/sha even when the external plugin has no path, returning /tree/<ref> so "View on GitHub" points at the pinned revision and stays consistent with the sidebar Ref/Commit chips. - Reflow the workflow install note so each inline code and link element stays on a single line (using explicit whitespace expressions for word spacing), removing the split end-tag artifacts while preserving the exact rendered text and spacing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Harden repo path validation and fix Included Items file links - isSafeRepoFilePath now fails closed on any "%" so percent-encoded dot-segments (%2e%2e and double-encoded %252e%252e) cannot be normalized back into path traversal by the browser URL parser during fetch, and also rejects "." and empty path segments. Legitimate repo paths never contain these. - IncludedItems githubHref now links file paths via /blob/ and directories via /tree/, detecting files by a trailing extension on the last path segment, so the fallback links for agent/instruction/command items no longer 404. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Harden detail pages: sanitize markdown, fix search deep-links and external URLs Addresses rubber-duck review items 1-5 for the detail-page migration: 1. Sanitize rendered markdown as untrusted HTML. Add isomorphic sanitize-html helper (isomorphic-dompurify) applied in the build-time pipeline (detail-page.ts) and the client file browser before a11y enhancement, so marked output can no longer inject scripts/handlers. 2. Point Pagefind search results at canonical /type/id/ detail pages instead of inert #file= listing hashes for types that have a detail page. 3. Sanitize external/generated URLs on plugin and extension detail pages and their render scripts so only http(s) links are emitted. 4. Add a shared externalRepoUrl helper that pins GitHub links to the source ref/sha (preferring sha) with encoded path segments, replacing the duplicated always-main logic in the pages, modal, and renderers. 5. Handle #file= hash navigation after initial load in the file browser via a hashchange listener. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Detail pages: clickable filter chips + code-block copy buttons (#2255) * Add clickable filter chips on detail pages Turn read-only metadata chips into navigation: tags (hooks/plugins), keywords (extensions), and extensions (instructions) now link to their list page pre-filtered by that value (e.g. /hooks/?tag=testing). SidebarChips gains optional filterBase/filterParam props; when both are set each chip renders as an <a> with an aria-label and hover/focus styling, otherwise it stays a plain <span>. Agent/skill/workflow chips are unchanged. Filtering was verified end to end against each list page's existing query-param handling. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add copy buttons to documentation code blocks Detail-page markdown is rendered as plain <pre><code> with no syntax highlighter, so code and config snippets had no copy affordance. Add a hover-revealed copy button to every code block in the rendered docs: copies to the clipboard, shows a toast, and swaps to a check icon for confirmation. Buttons are keyboard-accessible, always visible on touch devices, and respect reduced-motion. The sidebar frontmatter block is left untouched. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Fix detail-page GitHub links, empty-state link contrast, and file cache Addresses four PR review comments on the detail-page migration: - skill/hook detail pages: build the sidebar "View on GitHub" link from a /tree/main base instead of /blob/main, since item.path is a directory and /blob/<dir> URLs 404. The FileBrowser githubBase stays on /blob for individual file links. - global.css: include .detail-empty a in the underline override so links in empty-state notes stay distinguishable without relying on color alone (WCAG 1.4.1 / axe link-in-text-block). - file-browser.ts: seed the primary file's cache with its already-rendered (frontmatter-stripped) HTML in addition to raw text, so re-selecting the primary file after navigating away no longer re-renders the raw source and surfaces frontmatter. Copy still uses the full raw text. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Ayan Gupta <74832088+ayangupt@users.noreply.github.com> |
||
|
|
2b8b7b2fd1 |
Narrow risk scan version matching (#2251)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> |
||
|
|
e986f49695 |
Migrate extension metadata to plugin.json and enforce conventions (#2177)
* Remove pluginRoots property from marketplace.json The pluginRoots property is not used by install tooling and was only informational about the extension/plugin source directories. Removing it simplifies the marketplace.json structure while maintaining all functionality. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Migrate java-modernization-studio to plugin.json and update validation workflow - Create .github/plugin/plugin.json for java-modernization-studio extension - Remove legacy canvas.json from java-modernization-studio - Update validate-canvas-extensions.yml workflow to check for plugin.json instead of canvas.json - Update workflow to trigger on .schemas/plugin.schema.json changes (instead of canvas.schema.json) - Remove schema validation logic that relied on canvas.schema.json - All 12 extensions now use plugin.json for metadata Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add extensions field to all extension plugin.json files Per https://github.com/github/copilot-agent-runtime/pull/9929, plugins that ship extensions need to include an extensions field specifying where the extension code is located. All 12 extensions now have extensions set to '.' to reference the current directory where extension.mjs is located. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Enforce convention-based extension metadata and remove x-awesome-copilot - Remove x-awesome-copilot.screenshots from all extension plugin.json files - Enforce logo=assets/preview.png convention for all extensions - Enforce extensions=. per copilot-agent-runtime#9929 - Update validate-plugins.mjs to enforce conventions - Update validate-canvas-extensions.yml workflow with convention checks - Update AGENTS.md and CONTRIBUTING.md documentation All 12 extensions validated successfully. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Use standard plugin validation for extensions Remove the custom extension schema and schema validation helper, and validate extension plugin.json files through the existing plugin validator instead. Update workflows to stop depending on the removed schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
79cda6bb19 |
Add canvas schema validation to extension submission workflow (#2161)
* Add canvas schema and extension submission checks Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: use namespace import for js-yaml Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * Fix contributors page build markup Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * Address PR feedback on canvas schema validation - Add ajv-cli@5 as a pinned devDependency; install via npm ci in CI instead of npx --yes - Fix screenshot path regex to prevent .. traversal segments - Validate canvas.schema.json is parseable JSON even on schema-only PRs Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Harden canvas extension workflow against injection attacks Switch from newline to null-terminated git diff output (git diff -z) so filenames containing newlines are read atomically, matching the existing skill-check.yml pattern. Add an allowlist regex guard on the extracted extension directory name immediately after it is parsed from git diff output. Any name not matching ^[a-z0-9][a-z0-9-]*$ (e.g. names containing dollar signs, parentheses, spaces, or other shell metacharacters) is silently skipped before being used anywhere in the script. Add a matching allowlist guard on each screenshot path extracted from canvas.json before the file-existence check, so a crafted manifest cannot supply a path with shell metacharacters or traversal segments even after the schema check passes. Follows the same defence-in-depth pattern introduced after the injection PoCs in #1236 and #1240. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Replace ajv-cli with in-repo schema validator - Remove ajv-cli to avoid vulnerable/deprecated transitive dependencies - Add eng/validate-json-schema.mjs using ajv + ajv-formats - Update validate-canvas-extensions workflow to use local script - Use npm ci --ignore-scripts in PR validation job Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
28c3a14af4 |
Switch skill CI validation workflows to vally lint (#2030)
* Switch skill CI checks to vally lint Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Adding Vally to allowed words * case sensitivity * Migrate external plugin quality gates from skill-validator to vally lint Replace the downloaded skill-validator binary with px @microsoft/vally-cli lint in the external plugin quality gates pipeline: - Remove downloadSkillValidator() and SKILL_VALIDATOR_ARCHIVE_URL constant - Replace uildSkillValidatorArgs() + unSkillValidatorGate() with uildVallyLintArgs() + unVallyLintGate() that run px vally-cli lint per resolved skill directory (falling back to the full plugin root when no specific skill paths can be resolved from plugin.json) - Rename result keys skill_validator_status / skill_validator_output to ally_lint_status / ally_lint_output throughout both ng/external-plugin-quality-gates.mjs and ng/external-plugin-intake.mjs - Update PR comment markdown to show 'vally lint' instead of 'skill-validator' - Update CONTRIBUTING.md prose references accordingly Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Use @microsoft/vally library directly instead of vally-cli subprocess Replace the npx-spawned vally-cli process with a direct call to the @microsoft/vally core library in the external plugin quality gates scripts: - Add @microsoft/vally as a devDependency in package.json - Import runLint and LintConsoleReporter from @microsoft/vally - Replace runVallyLintGate() process spawn with async API call: - runLint({ rootPath }) returns structured LintResults - LintConsoleReporter with a Writable capture stream collects text output without printing to stdout - Make runExternalPluginQualityGates() async (propagated to runExternalPluginPrQualityGates() and both main entry points) - Use Promise.all in runExternalPluginPrQualityGates() for parallel plugin checks - Fix remaining skill_validator_status reference in pr-quality-gates summary string (now vally-lint=...) and YAML workflow table header - Add 'npm install @microsoft/vally' step to both calling workflows This removes a layer of indirection (Node -> npx -> CLI -> library) and replaces it with a direct in-process library call, which is faster, more reliable, and gives structured access to lint results. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
e9c8e37041 |
Add contributor attribution to canvas extension cards (#2111)
Show "by @handle" on each canvas extension card and in the details
modal, linking to the contributor's GitHub profile. Author metadata
lives in each extension's canvas.json (and external.json for external
extensions), where the rest of the canvas metadata is stored.
- Store author {name, url} in canvas.json / external.json
- Read author from canvas.json in the website data generator and emit
it to extensions.json
- Render the GitHub @handle, derived from the profile URL, as the link
text, with the contributor's name as the link title
- Escape the sanitized author URL before interpolating it into href
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
||
|
|
0eb6062f94 |
chore(phase2): retarget all automation and contributor guidance from staged to main (#2122)
* chore(phase2): retarget all automation from staged to main - publish.yml: trigger on main, publish only to marketplace - check-pr-target.yml: invert — now blocks PRs targeting staged, welcomes main - 10 PR validation workflows: branches [staged] → [main] - external-plugin-command-router.yml: --base staged → main (3×), message text - external-plugin-rereview-command.yml: --base staged → main (2×), message text - external-plugin-rereview.yml: staged reference in review comment text - external-plugin-intake.yml: ref: staged checkout → main - external-plugin-pr-quality-gates.yml: ref: staged checkout → main - external-plugin-quality-gates.yml: ref: staged checkout → main - check-plugin-structure.yml: error messages updated for new branch model - contributors.yml: ref and base target → main - setup-labels.yml: targets-main label description updated - cli-for-beginners-sync.md + .lock.yml: base-branch staged → main - codeowner-update.md + .lock.yml: base-branch staged → main - learning-hub-updater.md + .lock.yml: base-branch staged → main Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(phase2): update contributor guidance from staged to main - CONTRIBUTING.md: branch from main, PR targets main; remove Phase 2 gate note - AGENTS.md: PR target + external plugin PR automation references - .github/pull_request_template.md: PR checklist targets main - website/src/content/docs/learning-hub/agentic-workflows.md: PR target Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * aw updates --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
fb1b124ed7 |
Fix canvas extension install links (#2109)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Aaron Powell <me@aaron-powell.com> |
||
|
|
ec8cb2a8ae |
fix: make SHA and Ref values links to tree in external plugin intake comments (#2100)
* fix: make SHA and Ref values links to tree in external plugin intake comments Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fix: use plain link labels for Ref/SHA to avoid backtick markdown issues Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: escape backticks in Ref/SHA link labels Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
b253270faa |
Phase 1: split source vs published refs and verify dual publish (#2085)
* chore: finalize phase 1 marketplace migration wiring Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: avoid hardcoded source branch in plugin docs links Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
17b174fb0a |
Canvas manifest implementation for extensions (#2029)
* Add keyword display to extension cards on website - Add .resource-keywords and .keyword-tag CSS styles for rendering keyword badges - Update renderExtensionsHtml() to display keywords below extension description - Keywords now visible on the website extensions page with styled badges - Regenerate website data to include keyword metadata Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Canvas manifest implementation for all extensions Add per-extension canvas manifests with: - Structured canvas metadata (name, description, version, keywords) - Screenshot definitions (icon and gallery with path/type) - Relative paths for images within each extension directory Enhance extension metadata: - Generate meaningful descriptions from source analysis - Extract and assign keywords for discoverability - Store metadata in package.json and extension source files Update website rendering and data generation: - Include keywords in extension cards and search index - Add per-extension canvas.json files for independent evolution - Support screenshot metadata in manifest structure - Generate extensions.json with full canonical paths for website All 9 local canvas extensions now have complete manifests with descriptions, keywords, and screenshot references. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Tweaking some descriptions * Fix description priority to prefer package.json over in-source metadata Reverse the priority in canvasDescription so that package.json descriptions (which contain the enhanced, manually-curated descriptions) take precedence over older in-source descriptions extracted from createCanvas(...) calls. This prevents regression when npm run website:data regenerates outputs, ensuring that committed canvas.json files maintain the current descriptions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix canvas validation to skip external.json file The validation script was treating extensions/external.json as if it were a directory, causing false validation failures. Added check to skip files (identified by presence of dot in filename) and only validate actual canvas extension directories. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
fae6a92c9d |
Centralize label management and fix permission issues (#2018)
* fix: Allow label operations on pull requests in external plugin approval workflow The sync-merged-pr-labels job needs pull-requests: write permission to add/remove labels on merged PRs. Previously it only had issues: write which is for issues, not pull requests. This fixes the permission error when workflows try to modify PR labels from a non-contributor account. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: Handle 403 permission errors when creating external plugin intake labels When running on PRs from fork contributors, the GitHub token may not have permission to create labels in the repository. This is expected and should not cause the workflow to fail. Allow the ensureLabel function to gracefully handle 403 Forbidden errors in addition to 422 (label already exists) errors. This fixes the sync-pr-state job failure in external-plugin-pr-quality-gates.yml when run on PRs from external contributors. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * refactor: Centralize label management into a single workflow_dispatch workflow Create a new 'setup-labels' workflow that is manually dispatched and handles all label creation and updates. This workflow: - Creates all labels used by the repository - Updates descriptions if labels already exist - Reports success/failure counts - Fails if any labels cannot be created All individual workflows now assume labels exist and will fail (loudly) if they don't. This makes it clear to maintainers when the setup-labels workflow needs to be dispatched: - label-pr-intent.yml - skill-check-comment.yml - external-plugin-approval-command.yml - external-plugin-command-router.yml - external-plugin-rereview.yml - external-plugin-rereview-command.yml - eng/external-plugin-intake-state.mjs This approach is better because: - Single source of truth for label definitions - Avoids permission issues with fork contributors - Clear failure modes when labels are missing - Easier to maintain consistent label configuration - No more scattered label creation logic across workflows Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove unused ensureLabel methods and managedLabels constants Labels are now centrally managed by the setup-labels workflow and assumed to exist in all other workflows. Removed: - ensureLabel() methods from all 6 workflows and 1 JS module - managedLabels constants that were only used by ensureLabel - Promise.all() calls that invoked ensureLabel for each label - Updated syncManagedLabels in skill-check-comment.yml to remove ensureLabel call All workflows now assume labels exist and will fail if they don't, which is the desired behavior—it signals maintainers to dispatch the setup-labels workflow when new labels need to be created. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
ea5d3f4acb |
Add canvas previews, external extension links, and release notes showcase (#1987)
* Add extension thumbnails and preview assets Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add clickable extension image preview modal Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update website/src/styles/global.css * Add preview assets for canvas extensions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update canvas extension preview images Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Delete extensions/backlog-swipe-triage/assets/swipe-canvas-triage.png * Support external canvas extensions and add Coffilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add homepage link to GitHub repository Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add release notes showcase canvas extension Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Enhance release notes canvas sourcing and layout Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Aaron Powell <me@aaron-powell.com> |
||
|
|
a34c98bfbf |
Automate external plugin update PR quality checks (#2005)
* Add PR quality gates for external plugin updates Automate external plugin update PR review by running skill-validator and install smoke checks against changed entries in plugins/external.json. Sync PR workflow-state labels and upsert a marker-based status comment with source tree links for each changed plugin. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Tighten external plugin PR workflow permissions Scope write permissions to the PR synchronization job, keep the quality-gate job read-only, and handle no-op and detection-failure states explicitly. Also fix source tree link encoding for refs, SHAs, and plugin paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Fix external plugin workflow job steps Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> |
||
|
|
3ae6b2007c |
Add soft-gate PR risk scan automation for agentic PRs (#1969)
* Add soft-gate PR risk scanning automation Introduce a PR risk scanner script plus two workflows: one to scan changed files and upload findings, and one to upsert a sticky PR comment with a summary table and findings. This adds non-blocking supply-chain risk visibility for agentic contributions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Harden path checks and reduce scanner false positives Reject absolute paths, enforce repo-root containment after resolution, and tighten unpinned-version detection to dependency/version contexts to avoid markdown noise. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Harden soft-gate behavior and scanner coverage Make PR risk scan workflows non-blocking on scanner/artifact edge cases, always upload artifacts, reduce required permissions, and extend scanner script detection to plugin skill paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
c4a0a3ef5a |
Route intake failures to submitter fixes (#1970)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
50854076f2 | The new lines weren't working properly as we'd filter them out, whoops (#1951) | ||
|
|
dbd45cf6f2 |
Fix external plugin intake rate limits (#1953)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
ecf170397b |
fix: respect all manifest locations in smoke-test post-install verification (#1952)
The install smoke gate was hardcoding .github/plugin/plugin.json as the expected manifest path after copilot plugin install, which caused a false ail for plugins whose manifests live at plugin.json (root) or .plugins/plugin.json instead of the Copilot CLI convention. Replace the hardcoded path with a call to the existing indPluginJson() helper that already probes all three candidate locations in priority order. Separate the 'install directory missing' check from 'no manifest found' so error messages surface the actual root cause. Also fix a .plugin/ → .plugins/ typo in EXTERNAL_PLUGIN_ROOT_MANIFEST_PATHS (external-plugin-validation.mjs) which caused the error message shown to submitters to reference a path that indPluginJson never actually checks. Add cross-reference comments on both constants so they stay in sync. Closes: reported in issue #1837 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
0adac0dadd |
React to accepted rerun intake comments (#1948)
* React to rerun intake comments Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * some whitespace fixes * more whitespace fixes --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
c66449b4fa |
fix: skill-validator invocation for .github/plugin/plugin.json convention (#1916)
* fix: skill-validator invocation for .github/plugin/plugin.json convention The skill-validator --plugin mode looks for plugin.json at <dir>/plugin.json, but external plugins (and the Copilot CLI) place it at .github/plugin/plugin.json. This caused every external plugin with skills or agents to fail the skill-validator gate with a misleading 'No plugin.json found' error, even when the install smoke test passed correctly. Extract buildSkillValidatorArgs() which reads plugin.json from .github/plugin/plugin.json, resolves skills/agents paths relative to the plugin root, and invokes skill-validator with --skills/--agents instead of --plugin. Falls back to --plugin if the conventional path is not present. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: also check .plugins/plugin.json and root plugin.json locations Extend buildSkillValidatorArgs to probe three candidate plugin.json locations in priority order before falling back to --plugin: 1. .github/plugin/plugin.json (Copilot CLI convention) 2. .plugins/plugin.json 3. plugin.json (root — also the skill-validator's native --plugin expectation) Extract findPluginJson() and PLUGIN_JSON_CANDIDATES constant so the list is easy to extend. Paths in plugin.json are always resolved relative to the plugin root regardless of where the manifest lives. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
d11fb21f3a |
Add workflow run link to external plugin intake comments (#1915)
* Add workflow run link to external plugin intake comments - Include a link to the GitHub Actions workflow run in intake comment - Helps users trace which action run generated the intake report - Works for both initial intake and re-run intake flows - Link appears at bottom of comment for all intake states (passed/failed/quality gates) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review feedback on intake comment formatting - Remove leading spaces from runLink construction to preserve markdown formatting - Remove unnecessary newline prefix before runLink in quality gates section - Move workflow run link to the very end of all comment types (after warnings) - For merged intake comments, append link as final element - Remove unused runId parameter from applyExternalPluginIntakeEvaluation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
36cdc52037 |
Add Canvas Extensions website page (#1900)
Generate extensions data, add the extensions listing route/navigation, and include install URL copy actions pinned to the build commit SHA. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
47701d25f4 |
Add external plugin quality gates and maintainer override flow (#1860)
* Add external plugin quality gates and override flow Introduce a dedicated reusable quality-gates workflow for external plugin submissions and wire intake/rerun orchestration to consume its results. Add quality-aware intake state handling, including a submitter-fix blocker state and richer intake comments. Also add a maintainer /mark-ready-for-review command workflow for explicit overrides, update related approval-label handling, and document the new external plugin review flow in CONTRIBUTING and AGENTS guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fix: use specific auth/network patterns in classifySmokeFailure Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * refactor: hoist INFRA_ERROR_PATTERNS to module level, fix timeout regex Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * fix: install Copilot CLI in external-plugin-quality-gates workflow Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> |
||
|
|
78d62afc0c |
fix: stabilize generated instructions README ordering (#1846)
Pass an explicit 'en' locale to localeCompare for instruction title sorting in update-readme.mjs. Previously the default OS locale was used, causing String.prototype.localeCompare to produce different orderings on Windows vs Ubuntu (affecting characters like Korean and Japanese CJK titles), which made the validate-readme CI workflow non-deterministic. Fixes the root cause of the locale-dependent sort instability. |
||
|
|
6fc05f480e |
Splitting ref and sha into two fields correctly for the intake form (#1788)
* Splitting ref and sha into two fields correctly for the intake form * Enforce 40-character commit SHA in validateImmutableRef Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * Add backward compatibility for legacy checklist text and field title Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> * Avoid unnecessary array spread when iterating checklist equivalents Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> |
||
|
|
2ca49df9d4 |
Adding a new /rerun-intake command for when updates are required (#1786)
* Adding a new /rerun-intake command for when updates are required Reruns the intake process if feedback is given that will require the submitter to update something about the submittion. * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Use rerun command constant in parser regex Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: aaronpowell <434140+aaronpowell@users.noreply.github.com> |
||
|
|
a303e17975 |
Fix path for Chrome DevTools external plugin (#1784)
* Fixing path on chrome devtools external pluginPath is to the folder in the repo where the plugin structure starts, not where the plugin.json file lives. * Updating validation scripts and guidance to avoid this mistake again |