• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

Alan-Jowett / CoPilot-For-Consensus / 20631882992
78%

Build:
DEFAULT BRANCH: main
Ran 01 Jan 2026 03:30AM UTC
Jobs 0
Files 0
Run time –
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
  cancel
20631882992

push

github

web-flow
security: Scope GitHub OIDC to validation resource group only (#667)

* Initial plan

* security: Scope GitHub OIDC permissions to validation RG only

- Scope Contributor role to copilot-bicep-validation-rg (not subscription)
- Scope User Access Administrator to validation RG
- Auto-create validation RG if it doesn't exist
- Remove subscription-level permissions to prevent malicious PRs
- Update documentation to reflect security improvements
- Add clear security boundary warnings in output

Fixes subscription-level access issue where PRs had full Contributor permissions

Co-authored-by: Alan-Jowett <20480683+Alan-Jowett@users.noreply.github.com>

* Fix code review comments: error handling, duplicate docs, configurable location

- Add proper error checking for resource group creation with exit on failure
- Remove duplicate "Subscription not found" section in GITHUB_OIDC_SETUP.md
- Make validation RG location configurable via VALIDATION_LOCATION env var (default: eastus)

Co-authored-by: Alan-Jowett <20480683+Alan-Jowett@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Alan-Jowett <20480683+Alan-Jowett@users.noreply.github.com>
Source Files on build 20631882992
Detailed source file information is not available for this build.
  • Back to Repo
  • Github Actions Build #20631882992
  • 4ad3e3c1 on github
  • Prev Build on main (#20626659897)
  • Next Build on main (#20646713635)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc