Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/aw/safe-outputs-content.md
Original file line number Diff line number Diff line change
Expand Up @@ -287,7 +287,7 @@ description: Safe-output reference for issue, discussion, comment, and pull requ
target-repo: "owner/repo" # Optional: cross-repository
head-repo: "fork-owner/repo" # Optional: head (fork) repository for cross-repository PRs; defaults to target-repo
head-github-token: ${{ secrets.HEAD_REPO_PAT }} # Optional: token for branch writes to head-repo when it differs from target-repo
github-token-for-extra-empty-commit: ${{ secrets.MY_CI_PAT }} # Optional: PAT or "app" to trigger CI on created PRs
github-token-for-extra-empty-commit: ${{ secrets.MY_CI_PAT }} # Optional: PAT, "app" to trigger CI on created PRs, or "none" to omit GH_AW_CI_TRIGGER_TOKEN entirely
allowed-files: # Recommended: always restrict to specific paths or extensions to limit agent scope
- "src/**/*.ts" # e.g. restrict to TypeScript source files
- "docs/**/*.md" # e.g. restrict to Markdown docs
Expand Down Expand Up @@ -316,7 +316,7 @@ description: Safe-output reference for issue, discussion, comment, and pull requ

**Workflow File Changes**: To modify files under `.github/workflows/`, set `allow-workflows: true`. This adds `workflows: write` to the token used for the PR — a permission that requires `safe-outputs.github-app` to be configured, since `GITHUB_TOKEN` cannot hold this permission.

**CI Triggering**: By default, PRs created with `GITHUB_TOKEN` do not trigger CI workflow runs. To trigger CI, set `github-token-for-extra-empty-commit` to a PAT with `Contents: Read & Write` permission, or to `"app"` to use the configured GitHub App. Alternatively, set the magic secret `GH_AW_CI_TRIGGER_TOKEN` to a suitable PAT — this is automatically used without requiring explicit configuration in the workflow.
**CI Triggering**: By default, PRs created with `GITHUB_TOKEN` do not trigger CI workflow runs. To trigger CI, set `github-token-for-extra-empty-commit` to a PAT with `Contents: Read & Write` permission, or to `"app"` to use the configured GitHub App. Alternatively, set the magic secret `GH_AW_CI_TRIGGER_TOKEN` to a suitable PAT — this is automatically used without requiring explicit configuration in the workflow. Set `github-token-for-extra-empty-commit: none` to skip the extra empty commit and keep `GH_AW_CI_TRIGGER_TOKEN` out of the compiled lock file and manifest entirely.

- `create-pull-request-review-comment:` - Safe PR review comment creation on code lines

Expand Down
4 changes: 2 additions & 2 deletions .github/aw/safe-outputs-management.md
Original file line number Diff line number Diff line change
Expand Up @@ -281,7 +281,7 @@ description: Safe-output reference for update, label, milestone, project, releas
ignore-missing-branch-failure: false # Optional: treat deleted PR branches as skipped pushes (default: false)
commit-title-suffix: "[auto]" # Optional: suffix appended to commit title
staged: true # Optional: preview mode (default: follows global staged)
github-token-for-extra-empty-commit: ${{ secrets.MY_CI_PAT }} # Optional: PAT or "app" to trigger CI on pushed commits
github-token-for-extra-empty-commit: ${{ secrets.MY_CI_PAT }} # Optional: PAT, "app" to trigger CI on pushed commits, or "none" to omit GH_AW_CI_TRIGGER_TOKEN entirely
fallback-as-pull-request: true # Optional: when push fails (e.g. diverged branch), open a fallback PR targeting the original branch (default: true)
patch-format: "bundle" # Optional: "bundle" (default, supports merge commits) or "am"; auto-falls back to "bundle" when the incremental range contains a merge commit
signed-commits: true # Optional: when true (default), push via createCommitOnBranch GraphQL so GitHub signs commits; set false to push merge commits via plain git push
Expand All @@ -295,7 +295,7 @@ description: Safe-output reference for update, label, milestone, project, releas
max-patch-size: 2048 # Optional: per-output cap on git patch size in KB (overrides global; default: 4096 KB, max: 10240)
```

Cross-repository pushes are supported via `target-repo` (and `head-repo`/`head-github-token` for fork-backed PRs) plus an `allowed-repos` allowlist. To trigger CI on pushed commits, use `github-token-for-extra-empty-commit` or set the magic secret `GH_AW_CI_TRIGGER_TOKEN`.
Cross-repository pushes are supported via `target-repo` (and `head-repo`/`head-github-token` for fork-backed PRs) plus an `allowed-repos` allowlist. To trigger CI on pushed commits, use `github-token-for-extra-empty-commit` or set the magic secret `GH_AW_CI_TRIGGER_TOKEN`. Set `github-token-for-extra-empty-commit: none` to skip the extra empty commit and keep `GH_AW_CI_TRIGGER_TOKEN` out of the compiled lock file and manifest entirely.

**File Restrictions**: Same as `create-pull-request`: **always specify `allowed-files`** scoped to specific file extensions or paths to limit the agent's reach. `excluded-files` strips files before all checks, and `protected-files` controls handling of sensitive files. Object form supported: `protected-files: { policy: fallback-to-issue, exclude: [AGENTS.md] }`.

Expand Down