Conversation
- Publish runs under exploratory-report-* instead of playwright-report-* (new prefix input on gen-report-dir; other callers unchanged). - Launch Positron with ANTHROPIC_API_KEY so Assistant starts signed in, and redact the key from run output before it is published. - Add a focus input (dispatch field, or text after /test) that replaces the diff as the explorer's target and skips the worthiness gate.
|
E2E Tests 🚀 Note No feature tags detected. If this PR needs feature coverage, add the tag above and retrigger the workflow. |
Drop focus parsing from /test comments; the membership job is back to main's version.
…l secrets List what the explore job provides and what it does not (web, Docker-hosted remotes, databases, non-Anthropic providers) in both prompts, so the gate can decline changes only reachable there and the explorer drops them instead of filing them as bugs. Drop the unused QA AWS role from the explore job and redact GITHUB_TOKEN alongside the Anthropic key before publishing.
…ob of its own The explore job now gets the e2e lane's Postgres service and the OpenAI, Foundry, Snowflake Cortex, Snowflake and Databricks credentials, loaded after the launch so the app starts signed in to Anthropic only. The environment list the gate and explorer read moves them to available, and the explorer is told to refer to a key only by its variable name. The S3 upload moves to a new publish job that reads the redacted artifact, so id-token: write and the report bucket role never share a runner with the PR's code or the agent. The worthiness gate loses its unused id-token too.
…in the SHA A dispatch skips membership, and its ref went straight to checkout, so refs/pull/N/head or a SHA could run a fork PR's code with the job's credentials. A dispatch-ref job now resolves the input as an exact branch of this repo and fails otherwise, and worthiness and explore check out the SHA it resolved rather than the moving branch.
…d fields are masked Positron's PostgreSQL form shows its password unmasked, so a run published the e2e Postgres secret in a screenshot, where text redaction cannot reach. The service database lives only for the job, so its login is now a fixed test value set in the workflow rather than a secret. The explorer is told a Password field is not always masked, to check after filling one, and to blur it when the value shows.
…ly the value A run blurred every line of console input to hide the Postgres password, which left its queries unreadable as evidence. That login is now a fixed test value, and a real key is blurred only where it shows.
It holds the raw app logs, the agent's action log and its workspace, and anyone signed in can download it on a public repo. The published report on S3 is a separate copy and is not affected. Matches the e2e log artifacts.
…nk, before falling back to copying
… issues link back to it
…listing its files
…the caveats on one line
…blish a file redaction failed on
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Gives the exploratory-test workflow more to test, locks it down, and polishes the report.
exploratory-report-*; newfocusdispatch input tells the explorer what to test (and skips the worthiness check)publishjob, the only one withid-token: write; dispatch accepts only this repo's branches, pinned to a SHAQA Notes
Workflow and skill only; no e2e suites affected. Verify with a dispatch from this branch, with and without
focus.