Skip to content

fix: request Copilot reviews as an unlicensed machine user - #12

Merged
cwillisf merged 1 commit into
mainfrom
fix/copilot-review-machine-user
Sep 29, 2026
Merged

cwillisf merged 1 commit into
mainfrom
fix/copilot-review-machine-user

Conversation

@cwillisf

Copy link
Copy Markdown
Contributor

Summary

Makes the Copilot review workflow request reviews as an org member that has no Copilot license, using a fine-grained PAT passed in as COPILOT_REVIEW_TOKEN, instead of as github-actions[bot].

Reviews requested with GITHUB_TOKEN turned out to be billed to the PR author, so PRs from people whose personal Copilot plan had run out were still refused. A review requested by a user is billed to that user, and for an org member with no Copilot license the org's policy bills the organization. Label removal still uses GITHUB_TOKEN.

Callers now need to pass the secret explicitly. The header comment shows the updated caller and lists what the account and its PAT need.

Resolves

N/A

Testing

actionlint passes. With the previous version, a review requested on a PR authored by a user with no remaining Copilot quota was refused on that user's quota, while one on a Renovate PR went through. After this merges, the scratch-blocks caller will be updated to pass the secret and re-tested on both kinds of PR, then checked in the org's usage report.

Reviews requested with GITHUB_TOKEN are billed to the PR author, so PRs by people on exhausted personal Copilot plans were refused. Requesting as an org member with no Copilot license bills the organization regardless of author. Callers now pass COPILOT_REVIEW_TOKEN; label removal still uses GITHUB_TOKEN.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments remain, and all approval assessments indicate readiness.

Review effort: Lite
Findings: None

What changed in this PR

Updates the reusable Copilot review workflow to use a dedicated unlicensed machine-user PAT for review requests while retaining GITHUB_TOKEN for label removal.

Changes:

  • Requires and forwards COPILOT_REVIEW_TOKEN.
  • Uses the PAT for Copilot review requests.
  • Documents caller setup and security requirements.
File Description
.github/​workflows/​copilot-review.yml Updates workflow authentication, secret handling, and caller instructions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cwillisf
cwillisf merged commit ad754c2 into main Sep 29, 2026
2 checks passed
@cwillisf
cwillisf deleted the fix/copilot-review-machine-user branch September 29, 2026 18:59
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants