Conversation
Use stable GraphQL node IDs instead of viewer login values when selecting the current user's pending pull request review. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
| return utils.NewToolResultText("pull request review comment successfully added to pending review"), nil | ||
| } | ||
|
|
||
| func getPendingPullRequestReviewForViewer(ctx context.Context, client *githubv4.Client, owner, repo string, pullNumber int32) (*githubv4.ID, *mcp.CallToolResult) { |
Contributor
Author
There was a problem hiding this comment.
Live MCP validation: concrete Actor fragments expose the stable node ID even when viewer and review author types differ.
Select actor node IDs through GraphQL fragments because the Actor interface does not expose id directly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
timrogers
marked this pull request as ready for review
September 30, 2026 15:00
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The newly introduced pagination and cursor-update path lacks coverage.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates pending-review lookup to match authenticated actors by stable node ID, fixing Copilot bot operations.
Changes:
- Centralizes pending-review lookup across comment, submit, and delete operations.
- Filters and paginates pending reviews, matching viewer and author node IDs.
- Updates mocks and tests for User/Bot identity matching.
| File | Description |
|---|---|
pkg/github/pullrequests.go |
Implements shared node-ID-based review lookup. |
pkg/github/pullrequests_test.go |
Updates pending-review tests and GraphQL mocks. |
pkg/github/granular_tools_test.go |
Adapts granular tool testing to ID-based lookup. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Cover cursor propagation and viewer review selection on a second page. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
timrogers
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Pull request review tools which pull the current pending review for the user don't work when authenticated with a Copilot installation (server-to-server/S2S) token.
This fixes it by changing how we pull the current pending review to to be more resilient to the specific implementation of Copilot bots.
Why
Many of our pull request review tools rely on using the GitHub GraphQL API to look up the current pending review:
Under the hood, we do this by fetching the current
viewer.loginand then fetching reviewers where theauthormatches that login.This is currently broken for Copilot bots. When authenticated as Copilot cloud agent, the GraphQL API reports
Copilotforviewer.login, but this isn't the bot's real login.The real login is
copilot-swe-agent(the bot identity represented ascopilot-swe-agent[bot]elsewhere).Filtering the reviews connection with the reported viewer login therefore returns no pending review, so adding comments, submitting, and deleting pending reviews fail.
GraphQL node IDs are stable across those representations, so they are a more reliable identity key.
No linked issue.
What changed
viewer.idinstead ofviewer.login.PENDINGreviews without an author-login filter, paginate them, and select the first review whose author node ID matches the viewer node ID.Actorfragments because the interface does not exposeid; compare only globally unique node IDs because this token presents the viewer asUserand the review author asBot.MCP impact
The schemas are unchanged. The existing pending-review operations now work when the authenticated viewer's reported login does not match the review author's real login.
Prompts tested (tool changes only)
Live validation on this draft used the built MCP server over stdio to create a pending review, add a line comment, and submit it. The old
author: "Copilot"query returned no review, while the new query matched viewer and author node IDBOT_kgDOC9w8XQ.Security / limits
The API currently returns only the viewer's own pending reviews, but the client still matches author ID defensively in case that behavior changes. Results are fetched in pages of 100 and stop as soon as the viewer's review is found.
Tool renaming
deprecated_tool_aliases.goLint & tests
./script/lint./script/testgofmt -s,go vet ./..., focused tests, the full race-enabled test suite, and the live MCP create/comment/submit flow pass../script/lintcould not installgolangci-lintbecause its installer host is blocked in this environment; running the pinned linter through Go modules reached a Go export-data compatibility error.Docs