github / github/copilot-release-notes
Suggestion: Document job's `permissions: copilot-requests: write` as an auth mechanism
- Dominant language
- TypeScript
- Stars
- 20
- Forks
- 4
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 3
Description
Currently the readme advises using a PAT to allow Copilot to be used: https://github.com/github/copilot-release-notes#authentication
However, for most use cases when using workflows it's a better practice to have the workflow run under the repo's budget rather than as an invidiual user (which would use their AI credits and would break if they left / lost their copilot license / etc).
Is it worth updating the root README.md with a note on using the job's permissions to enable `copilot-requests: write` for this, per guidance: https://docs.github.com/en/copilot/how-tos/copilot-cli/use-copilot-cli-in-actions#recommended-approach-github-agentic-workflows
Contributor guide
Research direction
Start with the authentication guidance in the root README.md and compare it with the linked GitHub documentation for the recommended approach. Document how a workflow job can use `permissions: copilot-requests: write` instead of a PAT, and confirm the README clearly explains when this budget-based authentication is preferable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, documentation
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 88/100