Skip to content

Clarify Autofix deviation approval metadata - #1193

Closed
mbaluda wants to merge 1 commit into
mbaluda-autofixfrom
mbaluda/fix-autofix-approval-guidance
Closed

Clarify Autofix deviation approval metadata#1193
mbaluda wants to merge 1 commit into
mbaluda-autofixfrom
mbaluda/fix-autofix-approval-guidance

Conversation

@mbaluda

@mbaluda mbaluda commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator

Description

Clarify that Agentic Autofix must omit both raised-by and approved-by from an initial false-positive deviation record. The deviation format requires these fields to be specified together, so a human reviewer may add both when approving the deviation.

This prevents Autofix from generating an invalid record while preserving human approval of deviations.

Change request type

  • Release or process automation (GitHub workflows, internal scripts)
  • Internal documentation
  • External documentation
  • Query files (.ql, .qll, .qls or unit tests)
  • External scripts (analysis report or other code shipped as part of a release)

Rules with added or modified queries

  • No rules added
  • Queries have been added for the following rules:
  • Queries have been modified for the following rules:

Release change checklist

A change note is required for changes to release artifact structure, query performance, or query results. This documentation-only change affects none of those.

Author: Is a change note required?

  • Yes
  • No

Reviewer: Confirm that format of shared queries is valid by running them within VS Code.

  • Confirmed (not applicable; no query files changed)

Reviewer: Confirm that either a change note is not required or the change note is required and has been added.

  • Confirmed

Query development review checklist

Not applicable; this pull request does not add or modify queries.

@mbaluda
mbaluda marked this pull request as ready for review September 4, 2026 16:48
Copilot AI balanced review requested due to automatic review settings September 4, 2026 16:48
@mbaluda mbaluda closed this Sep 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation now matches the deviation format’s enforced requirements.

Review tier: Balanced
Findings: None

What changed in this PR

Clarifies valid deviation metadata for Agentic Autofix.

Changes:

  • Requires initial fixes to omit both approval metadata fields.
  • Allows human reviewers to add both fields during approval.
File Description
docs/​autofix-instructions.md Documents valid handling of deviation approval metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mbaluda
mbaluda deleted the mbaluda/fix-autofix-approval-guidance branch September 4, 2026 16:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants