Skip to content

docs: Documentation analysis and improvement#795

Draft
github-actions[bot] wants to merge 1 commit intomainfrom
docs/issue-793-doc-analysis-improvement-b3eea03578736fe0
Draft

docs: Documentation analysis and improvement#795
github-actions[bot] wants to merge 1 commit intomainfrom
docs/issue-793-doc-analysis-improvement-b3eea03578736fe0

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented May 5, 2026

Closes #793

Summary of files analyzed

  • .github/workflows/gh-aw-dependency-review.yml
  • .github/workflows/gh-aw-resource-not-accessible-by-integration-triage.yml
  • .github/workflows/gh-aw-security-triage.yml
  • docs/workflows/gh-aw-dependency-review.md
  • docs/workflows/gh-aw-resource-not-accessible-by-integration-triage.md
  • docs/workflows/gh-aw-security-triage.md

Issues found

  • docs/workflows/gh-aw-dependency-review.md: permissions section still documented a removed mint-gh-aw-github-token job and did not document the follow-up relabel signaling job.
  • docs/workflows/gh-aw-resource-not-accessible-by-integration-triage.md: still documented mint-job/GH_AW_GITHUB_TOKEN model and omitted signal-res-not-accessible-triage-followups relabel behavior.
  • docs/workflows/gh-aw-security-triage.md: still documented mint-job/GH_AW_GITHUB_TOKEN model and omitted signal-security-triage-followups relabel behavior.

Changes made

  • Updated docs/workflows/gh-aw-dependency-review.md to remove obsolete mint-job permission text and document signal-dependency-review-followups, including OIDC/token-minting location and merge-ready relabel signaling behavior.
  • Updated docs/workflows/gh-aw-resource-not-accessible-by-integration-triage.md to replace stale token contract text with current COPILOT_GITHUB_TOKEN contract for triage, and added the signal-res-not-accessible-triage-followups label re-apply flow plus its permissions.
  • Updated docs/workflows/gh-aw-security-triage.md to replace stale token contract text with current COPILOT_GITHUB_TOKEN contract for triage, and added the signal-security-triage-followups label re-apply flow plus its permissions.

Rationale: align runbook docs with current workflow topology so operators can correctly reason about where OIDC token minting now occurs and how installation-token labeled events are intentionally emitted for downstream routing.


What is this? | From workflow: Observability Agentic Workflow Entrypoint

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[oblt-aw][autodoc] Update GH-AW triage/dependency docs for follow-up relabel jobs

0 participants