Skip to content

exploratory-test: report path, Assistant sign-in, and a focus input - #16262

Draft
midleman wants to merge 22 commits into
mainfrom
midleman/exploratory-report-url-fix
Draft

midleman wants to merge 22 commits into
mainfrom
midleman/exploratory-report-url-fix

Conversation

@midleman

@midleman midleman commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Gives the exploratory-test workflow more to test, locks it down, and polishes the report.

  • Runs publish under exploratory-report-*; new focus dispatch input tells the explorer what to test (and skips the worthiness check)
  • Explorer gets Assistant signed in, a Postgres service, and OpenAI / Foundry / Cortex / Snowflake / Databricks test credentials; all secrets are redacted before publishing
  • S3 upload moved to its own publish job, the only one with id-token: write; dispatch accepts only this repo's branches, pinned to a SHA
  • Run artifact kept 3 days; the published report is unaffected
  • Report: Coverage rows link every finding they hit; issue links trim sections to fit instead of dropping the body, and link back to the report
  • Local skill runs offer to publish the report to the same CDN

QA Notes

Workflow and skill only; no e2e suites affected. Verify with a dispatch from this branch, with and without focus.

- Publish runs under exploratory-report-* instead of playwright-report-*
  (new prefix input on gen-report-dir; other callers unchanged).
- Launch Positron with ANTHROPIC_API_KEY so Assistant starts signed in,
  and redact the key from run output before it is published.
- Add a focus input (dispatch field, or text after /test) that replaces
  the diff as the explorer's target and skips the worthiness gate.
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

E2E Tests 🚀
This PR will run tests tagged with: @:critical

Note

No feature tags detected. If this PR needs feature coverage, add the tag above and retrigger the workflow.

readme  valid tags

Drop focus parsing from /test comments; the membership job is back to
main's version.
…l secrets

List what the explore job provides and what it does not (web, Docker-hosted
remotes, databases, non-Anthropic providers) in both prompts, so the gate can
decline changes only reachable there and the explorer drops them instead of
filing them as bugs. Drop the unused QA AWS role from the explore job and
redact GITHUB_TOKEN alongside the Anthropic key before publishing.
…ob of its own

The explore job now gets the e2e lane's Postgres service and the OpenAI,
Foundry, Snowflake Cortex, Snowflake and Databricks credentials, loaded after
the launch so the app starts signed in to Anthropic only. The environment list
the gate and explorer read moves them to available, and the explorer is told
to refer to a key only by its variable name.

The S3 upload moves to a new publish job that reads the redacted artifact, so
id-token: write and the report bucket role never share a runner with the PR's
code or the agent. The worthiness gate loses its unused id-token too.
…in the SHA

A dispatch skips membership, and its ref went straight to checkout, so
refs/pull/N/head or a SHA could run a fork PR's code with the job's
credentials. A dispatch-ref job now resolves the input as an exact branch
of this repo and fails otherwise, and worthiness and explore check out the
SHA it resolved rather than the moving branch.
…d fields are masked

Positron's PostgreSQL form shows its password unmasked, so a run published
the e2e Postgres secret in a screenshot, where text redaction cannot reach.
The service database lives only for the job, so its login is now a fixed
test value set in the workflow rather than a secret. The explorer is told a
Password field is not always masked, to check after filling one, and to blur
it when the value shows.
…ly the value

A run blurred every line of console input to hide the Postgres password,
which left its queries unreadable as evidence. That login is now a fixed
test value, and a real key is blurred only where it shows.
It holds the raw app logs, the agent's action log and its workspace, and
anyone signed in can download it on a public repo. The published report on
S3 is a separate copy and is not affected. Matches the e2e log artifacts.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant