Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: Local website and workshop checks

on:
push:
branches: ['**']
pull_request:

permissions:
contents: read

jobs:
check:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
cache: npm
- run: npm ci --no-audit --no-fund
- run: npm run check
98 changes: 98 additions & 0 deletions .github/workflows/plugin-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
name: Package learner-authored skills

on:
push:
tags: ['v*']

permissions:
contents: read

concurrency:
group: plugin-release-${{ github.ref }}
cancel-in-progress: false

jobs:
package:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
- name: Require the authored source and matching tag
env:
RELEASE_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
[[ "$RELEASE_TAG" =~ ^v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)$ ]]
git ls-files --error-unmatch agent-package/apm.yml agent-package/apm.lock.yaml \
.github/skills/intake/SKILL.md .github/skills/plan-to-spec/SKILL.md \
.github/skills/code-review/SKILL.md
node scripts/package.mjs stage "$RELEASE_TAG"
- name: Download and verify APM 0.31.0
run: |
set -euo pipefail
mkdir -p .workshop/tools
curl --fail --silent --show-error --location \
https://github.com/microsoft/apm/releases/download/v0.31.0/apm-linux-x86_64.tar.gz \
--output .workshop/tools/apm-linux-x86_64.tar.gz
printf '%s %s\n' \
'866d7f2cc095e858e52c4c81e2fc0acb99d1fb1948fe5464165bb362d08e9645' \
'.workshop/tools/apm-linux-x86_64.tar.gz' | sha256sum --check -
tar -xzf .workshop/tools/apm-linux-x86_64.tar.gz -C .workshop/tools
echo "$GITHUB_WORKSPACE/.workshop/tools/apm-linux-x86_64" >> "$GITHUB_PATH"
- name: Audit and pack only the staged skills
working-directory: .workshop/package
run: |
set -euo pipefail
apm --version | grep -Eq 'version 0\.31\.0([ (]|$)'
apm audit --file .apm/skills/intake/SKILL.md
apm audit --file .apm/skills/plan-to-spec/SKILL.md
apm audit --file .apm/skills/code-review/SKILL.md
apm pack --offline --format agent-plugin --archive --archive-format zip --output ../release
- name: Inspect the actual archive and checksum it
env:
RELEASE_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
version="${RELEASE_TAG#v}"
file="caldova-workshop-skills-$version.zip"
node scripts/verify-package.mjs ".workshop/release/$file" "$version"
cd .workshop/release
sha256sum "$file" > "$file.sha256"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: caldova-plugin-${{ github.run_id }}
path: |
.workshop/release/*.zip
.workshop/release/*.zip.sha256
include-hidden-files: true
if-no-files-found: error

draft-release:
needs: package
runs-on: ubuntu-24.04
permissions:
contents: write
steps:
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: caldova-plugin-${{ github.run_id }}
path: release-files
- name: Create a draft for human review
working-directory: release-files
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
RELEASE_TAG: ${{ github.ref_name }}
SOURCE_SHA: ${{ github.sha }}
run: |
set -euo pipefail
[[ "$RELEASE_TAG" =~ ^v(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)$ ]]
file="caldova-workshop-skills-${RELEASE_TAG#v}.zip"
sha256sum --check "$file.sha256"
gh release create "$RELEASE_TAG" "$file" "$file.sha256" \
--verify-tag --draft --title "$RELEASE_TAG" \
--notes "Three learner-authored workshop skills from source $SOURCE_SHA. Verify the package, checksum, and candidate before a human publishes this draft. This does not deploy the website."
8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
node_modules/
dist/
.workshop/
apm_modules/
.DS_Store
.env
.env.*
*.log
1 change: 1 addition & 0 deletions .nvmrc
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
24.21.0
21 changes: 21 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2026 Caldova Pharma workshop contributors

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
116 changes: 114 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,2 +1,114 @@
# caldova-pharma-workshop
Hands-on GitHub Copilot App workshop: from workplace requirements to reusable agent skills and plugins, with a simple local Caldova Pharma website.
# Caldova Pharma: from a request to reusable skills

**Build one small website improvement. Learn when a prompt is enough—and when
to turn repeated work into a skill.**

In this beginner GitHub Copilot App workshop, you start with a working lab
document board. You capture a fictional request, plan a change, implement it,
and review a real pull request. Along the way, you author three skills, then
package them for sharing.

**Full journey:** allow **5–6 hours**, or two sessions. The suggested schedule
is **5 hours 40 minutes including breaks**, covering all 13 labs: three
learner-authored skills, native cloud review, APM packaging, release, and
distribution/configuration review. Only live enterprise-admin execution is
optional and role-gated; the distribution lesson is included for everyone.

An **optional abbreviated ~3-hour track** covers selected hands-on work and
previews the later stages. It is not completion of the full journey.
No previous skill-authoring experience is needed.

> All Caldova people, messages, teams, and documents are original fiction for
> training. Editorial labels such as “Needs review” are not scientific or
> clinical judgments. This is not a validated quality-management system, and
> must not be used for patient care, laboratory operations, or regulated approval.
> Never put real workplace content or credentials in a public issue or commit.

## Start your own copy

1. Open this repository on GitHub. Choose **Use this template → Create a new
repository**, under your own account or an approved training organization.
**Do not perform exercises in the shared upstream repository.**
2. Install/sign in to the [GitHub Copilot App](https://github.com/features/ai/github-app).
Add **your copy** in **Projects**, and start an Interactive project session.
3. Follow [Lab 00: setup](docs/labs/00-setup.md) to find that session's **actual
worktree checkout**. Run the following in a terminal in that exact directory,
not a different clone.

**Cross-platform** (macOS, Linux, or PowerShell; Node and npm on PATH):

```sh
npm ci
npm run dev
```

Open **http://127.0.0.1:5173**. The starter shows six fictional records, `CDOC-101`
through `CDOC-106`, with **no filter**. Keep the terminal running. In a second
terminal in the same checkout:

```sh
npm test
npm run build
npm run check
```

The app uses vanilla JavaScript, HTML, CSS, Vite **7.3.6**, and Node's built-in
test runner. Use **Node 24.21.0 LTS** for the rehearsed path (at least that patch
within Node 24 LTS) plus Git. No database, container, Azure setup, deployment,
website login, or WorkIQ connection is needed to run it. The local server binds
to loopback with a strict port; it will fail rather than silently use 5174.

## What is already here?

| Starter provides | You create during the workshop |
| --- | --- |
| Working six-document board and baseline tests | A small view/filter and count, with tests you derive |
| Public fictional source messages | One human-confirmed feature issue in your copy |
| Step-by-step labs and blank, inert worksheets | A bounded plan and short, human-approved spec |
| Packaging helpers and an inert manifest example | `intake`, `plan-to-spec`, and `code-review` skills |
| App CI and a tag-triggered draft-release workflow | A reviewed PR, package manifest/lock, verified archive, and human-published plugin release |

There are **no active solution skills or completed feature spec** in the starter.
Instructor reference files are optional teaching material, not learner context:
do not ask Copilot to inspect them. An inert filename prevents automatic
registration; it does **not** prevent an agent from reading that file.

## Before the event

**Participants:** Git, Node 24.21.0 LTS, a browser, the Copilot App, a GitHub
account with access to your training copy, and a paid Copilot entitlement for
cloud code review. Check AI-credit budgets and applicable App/review policies.
The App itself supports more access options, but those do not necessarily
include cloud review. APM **0.31.0** is introduced only after you author skills;
its native binary needs no Python.
The later packaging lab resolves one pinned public **development dependency**
with `apm lock`; that lock-only path does not install its guidance into the App
or export it as runtime content.

**Facilitator / administrators:** preflight App builds, review eligibility and
Actions resources, and arrange the authorized WorkIQ training account, billing,
consent, and seeded fictional sources. Repository Admin or an **edit repository
rules** role is needed for the review ruleset. Enterprise ownership is needed
only to execute the optional live admin portion of the included distribution
lesson. Participants do not provision cloud services. If live prerequisites
are unavailable, use explicitly labeled offline practice or a facilitator
demonstration and schedule the missing full-journey evidence for later; do not
count those substitutes as completed live stages.

## Workshop map

- **[Full-journey schedule and abbreviated track](docs/README.md)** — start here
after setup.
- [Capability and licensing preflight](docs/capabilities.md) — dated public
references, supported surfaces, and limits.
- [Glossary](docs/glossary.md) — issue, worktree, skill, PR, package, and policy.
- [Facilitator guide](docs/facilitator.md) — preparation and honest fallback paths.
- [Fictional source](fixtures/teams-request.md) — the starting request, not a
completed issue.

The story is small:

**fictional source → issue → plan/spec → PR and tests → reusable skills → plugin**

Human review remains at the issue, spec, merge, publication, and administration
boundaries. Releasing the skills does **not** deploy the website.
15 changes: 15 additions & 0 deletions agent-package/apm.yml.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: caldova-workshop-skills
version: "0.1.0"
description: Three skills authored during the Caldova Pharma workshop
author: Caldova Pharma workshop contributors
license: MIT
dependencies: {}
devDependencies:
apm:
- devexpgbb/zava-agent-config/plugins/secure-baseline#931cfb58663154415f8a13e14680f548114d4555
compilation:
source_attribution: true
includes:
- .apm/skills/intake/SKILL.md
- .apm/skills/plan-to-spec/SKILL.md
- .apm/skills/code-review/SKILL.md
Loading