Skip to content

Sync eng/common directory with azure-sdk-tools for PR 14219#45437

Merged
azure-sdk merged 5 commits intomainfrom
sync-eng/common-AddGHAppWorkflowLogin-14219
Mar 2, 2026
Merged

Sync eng/common directory with azure-sdk-tools for PR 14219#45437
azure-sdk merged 5 commits intomainfrom
sync-eng/common-AddGHAppWorkflowLogin-14219

Conversation

@azure-sdk
Copy link
Collaborator

Sync eng/common directory with azure-sdk-tools for PR Azure/azure-sdk-tools#14219 See eng/common workflow

@azure-sdk azure-sdk added EngSys This issue is impacting the engineering system. Central-EngSys This issue is owned by the Engineering System team. labels Feb 27, 2026
@azure-sdk azure-sdk requested a review from a team as a code owner February 27, 2026 23:05
@azure-sdk azure-sdk added EngSys This issue is impacting the engineering system. Central-EngSys This issue is owned by the Engineering System team. labels Feb 27, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Syncs eng/common GitHub login tooling with azure-sdk-tools PR 14219 by extending the existing PowerShell token-minting script to work in GitHub Actions and adding a composite GitHub Action wrapper.

Changes:

  • Update eng/common/scripts/login-to-github.ps1 to export tokens in GitHub Actions via GITHUB_ENV and mask them.
  • Add eng/common/actions/login-to-github/action.yml composite action that wraps the PowerShell script for GitHub Actions usage.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
eng/common/scripts/login-to-github.ps1 Adds GitHub Actions support (mask + export to GITHUB_ENV) and tweaks Key Vault signing error output.
eng/common/actions/login-to-github/action.yml New composite action wrapper to call the script from GitHub Actions workflows.
Comments suppressed due to low confidence (2)

eng/common/scripts/login-to-github.ps1:107

  • az keyvault key sign ... | ConvertFrom-Json can throw before the $LASTEXITCODE check if az outputs non-JSON on failure (and with $ErrorActionPreference='Stop' this becomes a terminating error). This can also make the new error message unhelpful (e.g., $SignResultJson is unset/partial). Consider capturing the raw az output (stdout+stderr), checking $LASTEXITCODE, then parsing JSON only on success so failures reliably surface the real CLI error text.
      --digest $Base64Value | ConvertFrom-Json

  if ($LASTEXITCODE -ne 0) {
    throw "Failed to sign JWT with Azure Key Vault. Error: $($SignResultJson | ConvertTo-Json -Compress)"

eng/common/actions/login-to-github/action.yml:43

  • The “multiple owners” example uses token-owners: Azure,azure-sdk,MicrosoftDocs, but the documented variable naming scheme (GH_TOKEN_<Owner>) would yield GH_TOKEN_azure-sdk, which is not a valid env var name for GitHub Actions and can’t be referenced via ${{ env.* }}. Update the example and/or documentation to reflect the sanitized variable name that will be exported (or restrict owners to names that produce valid env var identifiers).
# Usage (multiple owners):
#         - uses: ./eng/common/actions/login-to-github
#           with:
#             token-owners: Azure,azure-sdk,MicrosoftDocs
#

@azure-sdk azure-sdk merged commit fd7fc6b into main Mar 2, 2026
27 checks passed
@azure-sdk azure-sdk deleted the sync-eng/common-AddGHAppWorkflowLogin-14219 branch March 2, 2026 20:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Central-EngSys This issue is owned by the Engineering System team. EngSys This issue is impacting the engineering system.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants