Skip to content

Support separate repository publishing and human review identities #4638

Description

@Wouittone

Problem

I want to use the Copilot app's native push and Create PR commands to publish agent work as a repository-specific GitHub App bot, while staying signed in as my human account for integrated PR reviews and approvals.

Currently, I have to use a separate PowerShell publisher that generates a GitHub App installation token, pushes the branch, and creates the PR through the REST API. The app remains signed in as my human account for reviews. This works, but bypasses the native publishing flow and does not automatically attach the resulting PR to the originating session.

Changing Git commit author metadata does not change the authenticated push actor or PR creator. A Git hook cannot solve this: it cannot change its parent Git process's credentials, and it does not affect the separate API request used for native PR creation. A credential helper can address Git push authentication alone, not PR authorship.

Requested behavior

Add a repository-scoped publishing identity setting that is independent of the human account used for browsing, integrated reviews, and approvals:

  • Allow native Git pushes and PR creation to authenticate as an installed, repository-specific GitHub App.
  • Keep review submission and approval authenticated as the selected human account.
  • Renew short-lived installation tokens automatically and keep credentials in secure storage, never in committed repository configuration or remote URLs.
  • Apply least-privilege repository permissions and fail explicitly rather than silently falling back to human publishing credentials.
  • Show the publishing and reviewing identities clearly before actions.
  • Preserve the native session-to-PR linkage and PR lifecycle experience.

Example

In Wouittone/orskit, existing PRs created as the custom orskit-copilot[bot] can be reviewed by the human account Wouittone. I want that same identity separation through the app's native commands, without an external publisher.

This request is for custom GitHub App installation authentication, not merely a Copilot co-author trailer or impersonation of GitHub's managed Copilot agent.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions