github / github/copilot-release-notes

Suggestion: Document job's `permissions: copilot-requests: write` as an auth mechanism

Open Beginner friendly
#18 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
20
Forks
4
Avg merge
2d 6h
Merged PRs (30d)
3

Description

Currently the readme advises using a PAT to allow Copilot to be used: https://github.com/github/copilot-release-notes#authentication

However, for most use cases when using workflows it's a better practice to have the workflow run under the repo's budget rather than as an invidiual user (which would use their AI credits and would break if they left / lost their copilot license / etc).

Is it worth updating the root README.md with a note on using the job's permissions to enable `copilot-requests: write` for this, per guidance: https://docs.github.com/en/copilot/how-tos/copilot-cli/use-copilot-cli-in-actions#recommended-approach-github-agentic-workflows

Contributor guide

Open the contributing guide

Research direction

Start with the authentication guidance in the root README.md and compare it with the linked GitHub documentation for the recommended approach. Document how a workflow job can use `permissions: copilot-requests: write` instead of a PAT, and confirm the README clearly explains when this budget-based authentication is preferable.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, documentation
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
88/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.