Skip to content

Comments

fix(ci): disable lockdown mode in agentic workflow#167

Open
DimaBir wants to merge 3 commits intomainfrom
fix/agentic-workflow-lockdown
Open

fix(ci): disable lockdown mode in agentic workflow#167
DimaBir wants to merge 3 commits intomainfrom
fix/agentic-workflow-lockdown

Conversation

@DimaBir
Copy link
Collaborator

@DimaBir DimaBir commented Feb 19, 2026

Summary

  • Disable lockdown: true in the gh-aw issue assistant workflow
  • The microsoft org blocks SSO authorization for personal classic PATs, making lockdown mode unusable
  • With lockdown: false, the workflow uses the built-in GITHUB_TOKEN which already has org access
  • Security is still enforced via safe-outputs (comment limits, allowed labels, allowed domains)

Root cause

The agentic workflow was deployed with lockdown: true, which requires a custom GH_AW_GITHUB_TOKEN secret. However:

  1. Fine-grained PATs can't scope to org repos you don't own
  2. Classic PATs from personal accounts can't be SSO-authorized for the microsoft org

Test plan

@DimaBir DimaBir self-assigned this Feb 19, 2026
Signed-off-by: Dima Birenbaum <dvlasenko86@gmail.com>
Signed-off-by: Dima Birenbaum <dvlasenko86@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants