From b0d50c2548f89aff38c65f3ed1a6ef647f4187ef Mon Sep 17 00:00:00 2001 From: Changyong Gong Date: Sat, 10 Oct 2026 14:40:15 +0800 Subject: [PATCH 1/2] Queue team-memory updates through Java Pack Replace the source agent invocation with the pinned standalone dispatcher and a scoped dispatch App token. Preserve the source opt-in and document source/central credential prerequisites and central manual maintenance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/team-memory-post-merge.yml | 59 +++++++++++--------- CONTRIBUTING.md | 47 ++++++++++++++++ 2 files changed, 80 insertions(+), 26 deletions(-) diff --git a/.github/workflows/team-memory-post-merge.yml b/.github/workflows/team-memory-post-merge.yml index 0bc11414..c2695109 100644 --- a/.github/workflows/team-memory-post-merge.yml +++ b/.github/workflows/team-memory-post-merge.yml @@ -1,43 +1,50 @@ -name: Update IssueLens Team Memory +name: Queue IssueLens Team Memory on: push: branches: [main] - workflow_dispatch: - inputs: - pull_request_number: - description: 'Merged pull request number to learn from' - required: true - type: string permissions: {} concurrency: - group: issuelens-${{ github.repository }}-team-memory-${{ github.event.after || inputs.pull_request_number || github.run_id }} + group: issuelens-${{ github.repository }}-team-memory-${{ github.sha }} cancel-in-progress: false jobs: - team-memory: + dispatch: if: >- ${{ vars.ISSUELENS_TEAM_MEMORY_ENABLED == 'true' && + github.repository == 'microsoft/vscode-java-dependency' && github.ref == format('refs/heads/{0}', github.event.repository.default_branch) && - (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }} + github.event_name == 'push' && + github.workflow_sha == github.sha && + github.event.created == false && + github.event.deleted == false && + github.event.forced == false }} runs-on: ubuntu-latest - timeout-minutes: 30 - permissions: - contents: read - pull-requests: read - id-token: write + timeout-minutes: 10 steps: - - name: Maintain IssueLens team memory - uses: microsoft/IssueLens/.github/actions/issuelens@2b5317815e15179899014a02c41678620ce2d390 + - name: Get token to dispatch the Java Pack coordinator + id: dispatch-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - request-type: team-memory - pull-request-number: ${{ inputs.pull_request_number }} - azure-client-id: ${{ secrets.AZURE_CLIENT_ID }} - azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }} - azure-subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} - agent-url: ${{ secrets.ISSUELENS_AGENT_URL }} - agent-scope: ${{ secrets.ISSUELENS_AGENT_SCOPE }} - output-mode: activity - summary-mode: status + client-id: ${{ vars.ISSUELENS_DISPATCH_APP_CLIENT_ID }} + private-key: ${{ secrets.ISSUELENS_DISPATCH_APP_PRIVATE_KEY }} + owner: microsoft + repositories: vscode-java-pack + permission-contents: read + permission-actions: write + + - name: Queue team-memory request + uses: microsoft/IssueLens/.github/actions/queue-team-memory@a81d2d96167fc0e69ac631c2edc85f858e693289 + with: + dispatch-token: ${{ steps.dispatch-token.outputs.token }} + coordinator-repository: microsoft/vscode-java-pack + coordinator-workflow: team-memory-coordinator.yml + coordinator-ref: main + workflow-inputs: >- + {"source_repository":"${{ github.repository }}", + "source_run_id":"${{ github.run_id }}", + "source_run_attempt":"${{ github.run_attempt }}", + "push_before":"${{ github.event.before }}", + "push_after":"${{ github.sha }}"} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 70d9e112..880b0733 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -42,4 +42,51 @@ These tests exercise the tool implementations with real VS Code URI, range, erro `lmTool.findSymbol` records `initialQueryDurationMs` and `retryQueryDurationMs` separately from total `durationMs`. These measure client-observed provider calls, not internal JDT phases; retry duration is zero when no retry occurs. No query text, source paths or symbol names are added to these events. +## IssueLens Team-Memory Queue + +The existing [team-memory workflow](.github/workflows/team-memory-post-merge.yml) +only dispatches requests for ordinary pushes to this repository's default branch. +It retains the source opt-in `ISSUELENS_TEAM_MEMORY_ENABLED == 'true'` and rejects +created, deleted, or forced pushes and mismatched workflow/head SHAs. The +[Java Pack coordinator](https://github.com/microsoft/vscode-java-pack/blob/main/.github/workflows/team-memory-coordinator.yml) +on `main` owns the shared wiki queue, source validation, IssueLens invocation, and +final maintenance validation; the source workflow does not invoke the agent. + +Before merging while the existing source opt-in is `true`, configure these +rollout prerequisites. Merging switches the caller to queue dispatch immediately; +it does not configure credentials or change either repository's live opt-in. + +- In this repository, provide variable `ISSUELENS_DISPATCH_APP_CLIENT_ID` and + secret `ISSUELENS_DISPATCH_APP_PRIVATE_KEY` for a dedicated dispatch GitHub App + installed only on `microsoft/vscode-java-pack`, with **Contents: read** and + **Actions: write**. These are proposed caller setup names, not inherited central + credentials. The pinned token action uses `client-id`; its installation token + is explicitly limited to Java Pack and these two permissions and is revoked + at job completion. The source + `GITHUB_TOKEN` cannot dispatch a workflow in another repository. +- In Java Pack, separately configure secrets + `ISSUELENS_SOURCE_READ_APP_CLIENT_ID` and + `ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY` for the source-read App with + **Actions: read**, **Contents: read**, and **Pull requests: read** access to + `microsoft/vscode-java-dependency`. The coordinator must be enabled and retain + this source in its allowlist. A successful Java Pack own-repository run does not + establish readiness to read external sources. + +Do not reuse the hosted IssueLens App key or the central source-read App key for +dispatch. Missing credentials are rollout prerequisites, not a reason to fall +back to direct agent invocation or broaden token permissions. + +The request contains only five strings: source repository, workflow run ID, +attempt, requested ancestor (`push_before`), and run head (`push_after`). +The ancestor authorizes reconciliation; it is not attested original-event +provenance. Dispatch acceptance does not confirm queue admission or maintenance +completion. On an ambiguous dispatch failure, inspect the central workflow runs +before retrying; the dispatcher does not automatically retry. + +For manual merged-PR maintenance, use **Run workflow** on Java Pack's +`team-memory-coordinator.yml`, with `source_repository` set to +`microsoft/vscode-java-dependency` and `pull_request_number` set to the merged PR. +Leave the automatic run/attempt and before/after inputs empty. There is no local +manual workflow or direct-invocation bypass. + Thank you for your contributions and support! \ No newline at end of file From a6303888341c57160d1b305fbaffd6c26deb03aa Mon Sep 17 00:00:00 2001 From: Changyong Gong Date: Sat, 10 Oct 2026 15:02:02 +0800 Subject: [PATCH 2/2] Remove public documentation from team-memory migration Restore CONTRIBUTING.md to its pre-migration content per user direction. Keep the workflow migration and safeguards unchanged; rollout prerequisites remain in the pull request description. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CONTRIBUTING.md | 47 ----------------------------------------------- 1 file changed, 47 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 880b0733..70d9e112 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -42,51 +42,4 @@ These tests exercise the tool implementations with real VS Code URI, range, erro `lmTool.findSymbol` records `initialQueryDurationMs` and `retryQueryDurationMs` separately from total `durationMs`. These measure client-observed provider calls, not internal JDT phases; retry duration is zero when no retry occurs. No query text, source paths or symbol names are added to these events. -## IssueLens Team-Memory Queue - -The existing [team-memory workflow](.github/workflows/team-memory-post-merge.yml) -only dispatches requests for ordinary pushes to this repository's default branch. -It retains the source opt-in `ISSUELENS_TEAM_MEMORY_ENABLED == 'true'` and rejects -created, deleted, or forced pushes and mismatched workflow/head SHAs. The -[Java Pack coordinator](https://github.com/microsoft/vscode-java-pack/blob/main/.github/workflows/team-memory-coordinator.yml) -on `main` owns the shared wiki queue, source validation, IssueLens invocation, and -final maintenance validation; the source workflow does not invoke the agent. - -Before merging while the existing source opt-in is `true`, configure these -rollout prerequisites. Merging switches the caller to queue dispatch immediately; -it does not configure credentials or change either repository's live opt-in. - -- In this repository, provide variable `ISSUELENS_DISPATCH_APP_CLIENT_ID` and - secret `ISSUELENS_DISPATCH_APP_PRIVATE_KEY` for a dedicated dispatch GitHub App - installed only on `microsoft/vscode-java-pack`, with **Contents: read** and - **Actions: write**. These are proposed caller setup names, not inherited central - credentials. The pinned token action uses `client-id`; its installation token - is explicitly limited to Java Pack and these two permissions and is revoked - at job completion. The source - `GITHUB_TOKEN` cannot dispatch a workflow in another repository. -- In Java Pack, separately configure secrets - `ISSUELENS_SOURCE_READ_APP_CLIENT_ID` and - `ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY` for the source-read App with - **Actions: read**, **Contents: read**, and **Pull requests: read** access to - `microsoft/vscode-java-dependency`. The coordinator must be enabled and retain - this source in its allowlist. A successful Java Pack own-repository run does not - establish readiness to read external sources. - -Do not reuse the hosted IssueLens App key or the central source-read App key for -dispatch. Missing credentials are rollout prerequisites, not a reason to fall -back to direct agent invocation or broaden token permissions. - -The request contains only five strings: source repository, workflow run ID, -attempt, requested ancestor (`push_before`), and run head (`push_after`). -The ancestor authorizes reconciliation; it is not attested original-event -provenance. Dispatch acceptance does not confirm queue admission or maintenance -completion. On an ambiguous dispatch failure, inspect the central workflow runs -before retrying; the dispatcher does not automatically retry. - -For manual merged-PR maintenance, use **Run workflow** on Java Pack's -`team-memory-coordinator.yml`, with `source_repository` set to -`microsoft/vscode-java-dependency` and `pull_request_number` set to the merged PR. -Leave the automatic run/attempt and before/after inputs empty. There is no local -manual workflow or direct-invocation bypass. - Thank you for your contributions and support! \ No newline at end of file