Repository navigation
Add --authmode to setup all: control agent identity permission grants (OBO/S2S/both) #719
release-drafter.yml
on: pull_request
update_release_draft
0s
label_pr
19s
Annotations
2 errors and 5 warnings
|
label_pr
HttpError: Resource not accessible by integration
at /home/runner/work/_actions/release-drafter/release-drafter/v6/dist/index.js:7146:21
at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
at async Job.doExecute (/home/runner/work/_actions/release-drafter/release-drafter/v6/dist/index.js:56365:18)
{
name: 'AggregateError',
event: {
id: '25089390201',
name: 'pull_request',
payload: {
action: 'closed',
enterprise: {
avatar_url: 'https://avatars.githubusercontent.com/b/1578?v=4',
created_at: '2019-12-09T02:41:53Z',
description: "Microsoft's organizations for open source collaboration",
html_url: 'https://github.com/enterprises/microsoftopensource',
id: 1578,
name: 'Microsoft Open Source',
node_id: 'MDEwOkVudGVycHJpc2UxNTc4',
slug: 'microsoftopensource',
updated_at: '2025-08-12T20:59:29Z',
website_url: 'https://opensource.microsoft.com'
},
number: 391,
organization: {
avatar_url: 'https://avatars.githubusercontent.com/u/6154722?v=4',
description: 'Open source projects and samples from Microsoft',
events_url: 'https://api.github.com/orgs/microsoft/events',
hooks_url: 'https://api.github.com/orgs/microsoft/hooks',
id: 6154722,
issues_url: 'https://api.github.com/orgs/microsoft/issues',
login: 'microsoft',
members_url: 'https://api.github.com/orgs/microsoft/members{/member}',
node_id: 'MDEyOk9yZ2FuaXphdGlvbjYxNTQ3MjI=',
public_members_url: 'https://api.github.com/orgs/microsoft/public_members{/member}',
repos_url: 'https://api.github.com/orgs/microsoft/repos',
url: 'https://api.github.com/orgs/microsoft'
},
pull_request: {
_links: {
comments: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/issues/391/comments'
},
commits: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/pulls/391/commits'
},
html: {
href: 'https://github.com/microsoft/Agent365-devTools/pull/391'
},
issue: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/issues/391'
},
review_comment: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/pulls/comments{/number}'
},
review_comments: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/pulls/391/comments'
},
self: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/pulls/391'
},
statuses: {
href: 'https://api.github.com/repos/microsoft/Agent365-devTools/statuses/c3061d569065941a367582a35a10586a2266eed7'
}
},
active_lock_reason: null,
additions: 1185,
assignee: null,
assignees: [],
author_association: 'CONTRIBUTOR',
auto_merge: {
commit_message: '* Add --authmode option to setup; gate agent grants by mode\n' +
'\n' +
'Introduce --authmode (obo|s2s|both) to a365 setup all and related flows, allowing users to control how agent identity permissions are granted. For non-DW agents, inheritable permissions and AllPrincipals grants are always skipped to avoid requiring Global Admin. The orchestrator now applies delegated grants, app role assignments, or both based on authMode, with PowerShell fallback for S2S if needed. The dry-run plan and summary output reflect these changes. Agent365Config and docs updated to support authMode. Includes extensive tests for all authMode values and validation logic. GraphApiService now treats "Permission entry already exists" as success.\n' +
'\n' +
'* Update setup all dry-run output and clarify error messages\n' +
'\n' +
'- Dry-run no longer detects tenant ID via az CLI when not needed.\n' +
'- "Inheritable Permis
|
|
label_pr
Resource not accessible by integration
{
name: 'HttpError',
id: '25089390201',
status: 403,
response: {
url: 'https://api.github.com/repos/microsoft/Agent365-devTools/releases',
status: 403,
headers: {
'access-control-allow-origin': '*',
'access-control-expose-headers': 'ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset',
'content-encoding': 'gzip',
'content-security-policy': "default-src 'none'",
'content-type': 'application/json; charset=utf-8',
date: 'Wed, 29 Apr 2026 03:27:16 GMT',
'referrer-policy': 'origin-when-cross-origin, strict-origin-when-cross-origin',
server: 'github.com',
'strict-transport-security': 'max-age=31536000; includeSubdomains; preload',
'transfer-encoding': 'chunked',
vary: 'Accept-Encoding, Accept, X-Requested-With',
'x-accepted-github-permissions': 'contents=write; contents=write,workflows=write',
'x-content-type-options': 'nosniff',
'x-frame-options': 'deny',
'x-github-api-version-selected': '2022-11-28',
'x-github-media-type': 'github.v3; format=json',
'x-github-request-id': '37C1:80FC9:3F4D174:FB6A6C9:69F17A93',
'x-ratelimit-limit': '15000',
'x-ratelimit-remaining': '14984',
'x-ratelimit-reset': '1777436814',
'x-ratelimit-resource': 'core',
'x-ratelimit-used': '16',
'x-xss-protection': '0'
},
data: {
message: 'Resource not accessible by integration',
documentation_url: 'https://docs.github.com/rest/releases/releases#create-a-release',
status: '403'
}
},
request: {
method: 'POST',
url: 'https://api.github.com/repos/microsoft/Agent365-devTools/releases',
headers: {
accept: 'application/vnd.github.v3+json',
'user-agent': 'probot/12.4.0 octokit-core.js/3.6.0 Node.js/20.20.2 (linux; x64)',
'x-github-delivery': '25089390201',
authorization: 'token [REDACTED]',
'content-type': 'application/json; charset=utf-8'
},
body: '{"target_commitish":"refs/heads/main","name":"v0.1.0","tag_name":"v0.1.0","body":"## What\'s Changed\\n\\n- build: produce separate portable PDB files (#390)\\n- Harden LLM output handling against prompt injection (#383)\\n- Add idempotency and reuse tracking to agent setup flow (#384)\\n- Update agent setup Q\\\\&A and capability selection logic (#382)\\n- Remove Azure App Service deployment and infra from CLI/tests (#379)\\n- fix: add MCP V2 audience support and prevent removal by setup blueprint (#373)\\n- fix: pass -NoProfile when invoking pwsh in requirement checks (#380)\\n- feat: non-DW blueprint setup and config-free provisioning via --agent-name (#365)\\n- Add managed by attribute to blueprint (#372)\\n- feat: MCP V1-to-V2 discovery migration (#327)\\n- fix: Fix crash during agent blueprint creation by improving error handling and logging in AgentBlueprintService (#366) (#369)\\n- Add observability instructions for coding agents (#371)\\n- Fix python builds with a365 deploy (#355)\\n- Add S2S app role assignment support to setup process (#367)\\n- fix(docs): correct Developer Portal configuration in setup instructions (#364)\\n- Defend Copilot against prompt injection (#354)\\n- Add OtelWrite scope, dedupe API specs, update Graph scopes (#348)\\n- feat: CMS autoTriage improvements and review feedback (#283)\\n- Add confirmation prompts for app registration changes (#325)\\n- fix: replace az CLI token acquisition with MSAL.NET to eliminate proy resets (#324)\\n- fix: automatic device code fallback when Conditional Access Policy blocks browser/WAM auth (#294) (#323)\\n- feat: non-admin setup flow, a365 setup admin command, and cleanup 403 fixes (#320)\\n- feat: add notice system for CLI security and upgrade announcements (#316)\\n- cleanup: remove service references from docs and code (#317)\\n- fix: publish
|
|
label_pr
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: release-drafter/release-drafter@v6. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
label_pr
"pull_request_target.edited" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
label_pr
"pull_request_target.synchronize" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
label_pr
"pull_request_target.reopened" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
label_pr
"pull_request_target.opened" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|