docs: explain why WASM builds no-op repository feature validation - #48736
Merged
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Document why WASM builds skip repository feature validation
docs: explain why WASM builds no-op repository feature validation
Jul 28, 2026
pelikhan
marked this pull request as ready for review
July 28, 2026 21:46
Contributor
There was a problem hiding this comment.
Pull request overview
Documents why repository feature validation is skipped in WASM/playground builds.
Changes:
- Explains WASM validation constraints.
- Documents compatibility-only types and no-op behavior.
- References the native implementation.
Show a summary per file
| File | Description |
|---|---|
pkg/workflow/repository_features_validation_wasm.go |
Adds explanatory documentation for WASM behavior. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comments suppressed due to low confidence (1)
pkg/workflow/repository_features_validation_wasm.go:42
- Runtime does not invoke repository feature validation. The validator runs during native compilation (
compiler.go:239); at runtime, a disabled feature merely causes the corresponding GitHub API operation to fail. Please avoid promising validation at workflow runtime.
// Validation will still occur at workflow runtime on the native host.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Medium
Comment on lines
+18
to
+19
| // - Feature validation is a compile-time advisory check, not a security gate. Any | ||
| // actual enforcement happens at workflow runtime on the native host. |
Contributor
|
🎉 This pull request is included in a new release. Release: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
repository_features_validation_wasm.gowas a bare 12-line stub with no explanation of why it skips the GitHub API calls that the native build performs, making the behavioral split between CLI and WASM playground opaque.Changes
js || wasmbuilds and explains the three reasons: no outbound network access to the GitHub API, no authenticated gh CLI session, and validation being advisory (not a security gate). Points to the native file for reference.RepositoryFeaturesstruct comment — notes the struct exists solely for cross-build API compatibility; fields are never populated in WASM builds.validateRepositoryFeaturesfunc comment — explicitly documents the no-op contract and its rationale.No functional changes.