diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index 73f4148a..973c0195 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -40,6 +40,11 @@ "version": "v5", "sha": "e58605a9b6da7c637471fab8847a5e5a6b8df081" }, + "astral-sh/setup-uv@v6": { + "repo": "astral-sh/setup-uv", + "version": "v6", + "sha": "d0cc045d04ccac9d8b7881df0226f9e82c39688e" + }, "github/gh-aw-actions/setup-cli@v0.82.14": { "repo": "github/gh-aw-actions/setup-cli", "version": "v0.82.14", diff --git a/.github/workflows/agent-deep-dive.lock.yml b/.github/workflows/agent-deep-dive.lock.yml index 4cbf2d1c..66f35622 100644 --- a/.github/workflows/agent-deep-dive.lock.yml +++ b/.github/workflows/agent-deep-dive.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"a33459e6a428f0e98360f53f5c92cbf5fd08e656c8bf9fb51a1d1dbb94600aa2","body_hash":"8a85edff45fa8ff74963b7d6f826b967c2aa91734ed58b974abeac873de21665","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ca00f7fbdad90379d08de1b8c366afd931d477459261aadc437618305c5b23f4","body_hash":"8a85edff45fa8ff74963b7d6f826b967c2aa91734ed58b974abeac873de21665","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -50,15 +50,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -77,7 +77,7 @@ on: # - maintainer # Roles processed as role check in pre-activation job # - write # Roles processed as role check in pre-activation job schedule: - - cron: "27 14 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) + - cron: "49 14 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) # stale-check: false # Stale-check processed as frontmatter hash check step in activation job workflow_dispatch: inputs: @@ -717,35 +717,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' diff --git a/.github/workflows/agent-deep-dive.md b/.github/workflows/agent-deep-dive.md index a85145da..76975df9 100644 --- a/.github/workflows/agent-deep-dive.md +++ b/.github/workflows/agent-deep-dive.md @@ -12,7 +12,7 @@ imports: - gh-aw-fragments/scheduled-audit.md engine: id: copilot - model: gpt-5.3-codex +model: gpt-5.3-codex on: stale-check: false schedule: diff --git a/.github/workflows/agent-efficiency.lock.yml b/.github/workflows/agent-efficiency.lock.yml index b8e9b5c8..88c569d7 100644 --- a/.github/workflows/agent-efficiency.lock.yml +++ b/.github/workflows/agent-efficiency.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3d0adc875614dad4817e29ef3179ee8e93530662f33f05d547e1f97607d96033","body_hash":"1d536f8b85e11df18e3d4e52af813300f6189bf159ea649fab9382c4074bc94b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"5e97f93086dc5a34c9bbd13e5513f437b5d1783b9a32b4c9dbe36559d9395c0e","body_hash":"1d536f8b85e11df18e3d4e52af813300f6189bf159ea649fab9382c4074bc94b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -50,15 +50,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -77,7 +77,7 @@ on: # - maintainer # Roles processed as role check in pre-activation job # - write # Roles processed as role check in pre-activation job schedule: - - cron: "49 16 * * 1-5" # Friendly format: daily around 16:00 on weekdays (scattered) + - cron: "19 15 * * 1-5" # Friendly format: daily around 16:00 on weekdays (scattered) # stale-check: false # Stale-check processed as frontmatter hash check step in activation job workflow_dispatch: inputs: @@ -684,35 +684,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' diff --git a/.github/workflows/agent-efficiency.md b/.github/workflows/agent-efficiency.md index 095dc77a..90d1bb9a 100644 --- a/.github/workflows/agent-efficiency.md +++ b/.github/workflows/agent-efficiency.md @@ -12,7 +12,7 @@ imports: - gh-aw-fragments/scheduled-audit.md engine: id: copilot - model: gpt-5.3-codex +model: gpt-5.3-codex on: stale-check: false schedule: diff --git a/.github/workflows/gh-aw-agent-suggestions.lock.yml b/.github/workflows/gh-aw-agent-suggestions.lock.yml index 3d2ec41e..8b4c40ec 100644 --- a/.github/workflows/gh-aw-agent-suggestions.lock.yml +++ b/.github/workflows/gh-aw-agent-suggestions.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6957591ec60d5ea68d1cd947aba7aff323e2290d294a59608394a10dd2641640","body_hash":"14e991053a988ea1cdfc6bc020d9110a27980869be52ca06e6839eaa304e786f","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6fa49bf7d16b42ec9c4b3ac7fdc34eda7f09eb1c199bd7a9a6d02741e5d90523","body_hash":"d43eacaef38760815c4796a8c2d5b6a2df4b1219e7f7f55ce4f236df3be5485a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_75c7b4dffbd39cac_EOF' + cat << 'GH_AW_PROMPT_0ab415bd597ad48c_EOF' - GH_AW_PROMPT_75c7b4dffbd39cac_EOF + GH_AW_PROMPT_0ab415bd597ad48c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_75c7b4dffbd39cac_EOF' + cat << 'GH_AW_PROMPT_0ab415bd597ad48c_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_75c7b4dffbd39cac_EOF + GH_AW_PROMPT_0ab415bd597ad48c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_75c7b4dffbd39cac_EOF' + cat << 'GH_AW_PROMPT_0ab415bd597ad48c_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_75c7b4dffbd39cac_EOF + GH_AW_PROMPT_0ab415bd597ad48c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_75c7b4dffbd39cac_EOF' + cat << 'GH_AW_PROMPT_0ab415bd597ad48c_EOF' ## MCP Servers @@ -436,9 +436,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -596,7 +596,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_75c7b4dffbd39cac_EOF + GH_AW_PROMPT_0ab415bd597ad48c_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -767,35 +767,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -814,7 +814,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1611,7 +1611,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-agent-suggestions.md b/.github/workflows/gh-aw-agent-suggestions.md index f536b74c..ae70ceda 100644 --- a/.github/workflows/gh-aw-agent-suggestions.md +++ b/.github/workflows/gh-aw-agent-suggestions.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-autonomy-atomicity-analyzer.lock.yml b/.github/workflows/gh-aw-autonomy-atomicity-analyzer.lock.yml index 8903e812..7006c9a3 100644 --- a/.github/workflows/gh-aw-autonomy-atomicity-analyzer.lock.yml +++ b/.github/workflows/gh-aw-autonomy-atomicity-analyzer.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3a7c9d6ef6734d4c641fc650ed735dabd91a9caec2224f849970e039afd00302","body_hash":"eb09c0f086c3c00f7a3ea2898636ea2a2cde5e336dc72f89ad2956dce99b2a90","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"60997e5f5d26fc62164b469108b2664d90a2a990fbf377c0dd56c8757e88fa39","body_hash":"5337fbf2c4b3b9179d5d99e3f75ebd93b8255986e81e58f3363fdf504a060263","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_325fc347d1db8f33_EOF' + cat << 'GH_AW_PROMPT_77b411771dd81a88_EOF' - GH_AW_PROMPT_325fc347d1db8f33_EOF + GH_AW_PROMPT_77b411771dd81a88_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_325fc347d1db8f33_EOF' + cat << 'GH_AW_PROMPT_77b411771dd81a88_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_325fc347d1db8f33_EOF + GH_AW_PROMPT_77b411771dd81a88_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_325fc347d1db8f33_EOF' + cat << 'GH_AW_PROMPT_77b411771dd81a88_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_325fc347d1db8f33_EOF + GH_AW_PROMPT_77b411771dd81a88_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_325fc347d1db8f33_EOF' + cat << 'GH_AW_PROMPT_77b411771dd81a88_EOF' ## MCP Servers @@ -436,9 +436,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -549,7 +549,7 @@ jobs: 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "__GH_AW_EXPR_BF503D80__"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For @@ -600,7 +600,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_325fc347d1db8f33_EOF + GH_AW_PROMPT_77b411771dd81a88_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -771,35 +771,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -818,7 +818,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1615,7 +1615,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-autonomy-atomicity-analyzer.md b/.github/workflows/gh-aw-autonomy-atomicity-analyzer.md index 39347066..b53f0571 100644 --- a/.github/workflows/gh-aw-autonomy-atomicity-analyzer.md +++ b/.github/workflows/gh-aw-autonomy-atomicity-analyzer.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -115,7 +115,7 @@ Your task is to analyze the codebase for autonomy and atomicity blockers — pat 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "${{ inputs.title-prefix }}"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For diff --git a/.github/workflows/gh-aw-branch-actions-detective.lock.yml b/.github/workflows/gh-aw-branch-actions-detective.lock.yml index 4da77401..ce2854cf 100644 --- a/.github/workflows/gh-aw-branch-actions-detective.lock.yml +++ b/.github/workflows/gh-aw-branch-actions-detective.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"391b3f468974ea14d43d7b57dfe10ccde4704bbd83e99d7569a7c7814697ad36","body_hash":"614b0f19644f845151c0d8a29b04e9eab7e927e80fd7641a823c43cb67e73b10","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"9cacd68da3e5c04038216344c6b362198201c48a6e8c2702dc0ea4fb49b14356","body_hash":"dd52a2ca91cef378ac18a55ccb1a47d3b525c99be7cc10b69622b594ba43b85a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_732df137dd277b89_EOF' + cat << 'GH_AW_PROMPT_a6b7c83f11cca969_EOF' - GH_AW_PROMPT_732df137dd277b89_EOF + GH_AW_PROMPT_a6b7c83f11cca969_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_732df137dd277b89_EOF' + cat << 'GH_AW_PROMPT_a6b7c83f11cca969_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_732df137dd277b89_EOF + GH_AW_PROMPT_a6b7c83f11cca969_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_732df137dd277b89_EOF' + cat << 'GH_AW_PROMPT_a6b7c83f11cca969_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_732df137dd277b89_EOF + GH_AW_PROMPT_a6b7c83f11cca969_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_732df137dd277b89_EOF' + cat << 'GH_AW_PROMPT_a6b7c83f11cca969_EOF' ## MCP Servers @@ -436,9 +436,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. @@ -521,7 +521,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_732df137dd277b89_EOF + GH_AW_PROMPT_a6b7c83f11cca969_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -699,35 +699,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -746,7 +746,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1543,7 +1543,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-branch-actions-detective.md b/.github/workflows/gh-aw-branch-actions-detective.md index bb7df2dd..3789b092 100644 --- a/.github/workflows/gh-aw-branch-actions-detective.md +++ b/.github/workflows/gh-aw-branch-actions-detective.md @@ -13,7 +13,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-breaking-change-detector.lock.yml b/.github/workflows/gh-aw-breaking-change-detector.lock.yml index c3721013..98fa93eb 100644 --- a/.github/workflows/gh-aw-breaking-change-detector.lock.yml +++ b/.github/workflows/gh-aw-breaking-change-detector.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"028f25769a00604eafbfd0db828f3b22fe4f536df88a9b85ed60d46f43f5fa00","body_hash":"d52bb0064082cca13ed3a6c0018d29ed7d02066e63f1466e7372da3d07123976","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6e5eb51a367c02fd4becfead1d1f17ff9a6f3db6936df773fe848a2e445d5425","body_hash":"ddd26a2cc5e5c23f60047f91cb2a11a762de9675477771813aac0062f860c00a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_3ef3b2dc109fbae8_EOF' + cat << 'GH_AW_PROMPT_79ea8e9b2a639d08_EOF' - GH_AW_PROMPT_3ef3b2dc109fbae8_EOF + GH_AW_PROMPT_79ea8e9b2a639d08_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_3ef3b2dc109fbae8_EOF' + cat << 'GH_AW_PROMPT_79ea8e9b2a639d08_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_3ef3b2dc109fbae8_EOF + GH_AW_PROMPT_79ea8e9b2a639d08_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_3ef3b2dc109fbae8_EOF' + cat << 'GH_AW_PROMPT_79ea8e9b2a639d08_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_3ef3b2dc109fbae8_EOF + GH_AW_PROMPT_79ea8e9b2a639d08_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_3ef3b2dc109fbae8_EOF' + cat << 'GH_AW_PROMPT_79ea8e9b2a639d08_EOF' ## MCP Servers @@ -437,9 +437,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -603,7 +603,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_3ef3b2dc109fbae8_EOF + GH_AW_PROMPT_79ea8e9b2a639d08_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -771,35 +771,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -824,7 +824,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1621,7 +1621,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-breaking-change-detector.md b/.github/workflows/gh-aw-breaking-change-detector.md index 1ef4ee9e..21ba967d 100644 --- a/.github/workflows/gh-aw-breaking-change-detector.md +++ b/.github/workflows/gh-aw-breaking-change-detector.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-bug-hunter.lock.yml b/.github/workflows/gh-aw-bug-hunter.lock.yml index efd2e74f..06f67bd1 100644 --- a/.github/workflows/gh-aw-bug-hunter.lock.yml +++ b/.github/workflows/gh-aw-bug-hunter.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"1dc5c3acc537006b88a72e1338957c199704394021c71a67283f98658e9d04fc","body_hash":"0b00e203c11010012eaf7254f89e4ca1ee3dbba384d9ef09e3efb4533dd6847c","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"1b0647fddc99cbae603d71a77562aa44bc1cda24c4a4bc25f9f140a5e6a771b8","body_hash":"dca8f62e2ef5d1fa4e49069ae7e35b82ced1bd7566ccfd7e21be29bfd3196d26","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -322,20 +322,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF' + cat << 'GH_AW_PROMPT_b39d1ba59debc6dc_EOF' - GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF + GH_AW_PROMPT_b39d1ba59debc6dc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF' + cat << 'GH_AW_PROMPT_b39d1ba59debc6dc_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF + GH_AW_PROMPT_b39d1ba59debc6dc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF' + cat << 'GH_AW_PROMPT_b39d1ba59debc6dc_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -364,9 +364,9 @@ jobs: {{/if}} - GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF + GH_AW_PROMPT_b39d1ba59debc6dc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF' + cat << 'GH_AW_PROMPT_b39d1ba59debc6dc_EOF' ## MCP Servers @@ -438,9 +438,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -600,7 +600,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_5b5ecfcfe7c6727c_EOF + GH_AW_PROMPT_b39d1ba59debc6dc_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -772,35 +772,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -825,7 +825,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1622,7 +1622,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-bug-hunter.md b/.github/workflows/gh-aw-bug-hunter.md index f26d5b7f..0e4bcff3 100644 --- a/.github/workflows/gh-aw-bug-hunter.md +++ b/.github/workflows/gh-aw-bug-hunter.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-code-complexity-detector.lock.yml b/.github/workflows/gh-aw-code-complexity-detector.lock.yml index a7430bc8..01561e66 100644 --- a/.github/workflows/gh-aw-code-complexity-detector.lock.yml +++ b/.github/workflows/gh-aw-code-complexity-detector.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"976ed693cefc2b31b5a1376a348ba183e0123832d43381d39a1c4d50886c7605","body_hash":"9093ac6de5974444d33d2722509cafc0485d145dda32da622cff794a8a2a7241","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"python:alpine","digest":"sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116","pinned_image":"python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f6ed0e55a85cf3752d9a7faeee9e7c764e7c910d166896847b508fae40dffebc","body_hash":"45bbe9625a34794cdd03eafde718f207cc787ee2c7cbf8e3a2a7a7de6bd8ae98","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"python:alpine","digest":"sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116","pinned_image":"python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) # - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 # - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -340,20 +340,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_7676ac9978b520ce_EOF' + cat << 'GH_AW_PROMPT_8f5ef3cc44a2752e_EOF' - GH_AW_PROMPT_7676ac9978b520ce_EOF + GH_AW_PROMPT_8f5ef3cc44a2752e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_7676ac9978b520ce_EOF' + cat << 'GH_AW_PROMPT_8f5ef3cc44a2752e_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_7676ac9978b520ce_EOF + GH_AW_PROMPT_8f5ef3cc44a2752e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_7676ac9978b520ce_EOF' + cat << 'GH_AW_PROMPT_8f5ef3cc44a2752e_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -382,9 +382,9 @@ jobs: {{/if}} - GH_AW_PROMPT_7676ac9978b520ce_EOF + GH_AW_PROMPT_8f5ef3cc44a2752e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_7676ac9978b520ce_EOF' + cat << 'GH_AW_PROMPT_8f5ef3cc44a2752e_EOF' ## MCP Servers @@ -455,9 +455,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -708,7 +708,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_7676ac9978b520ce_EOF + GH_AW_PROMPT_8f5ef3cc44a2752e_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -893,23 +893,23 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version @@ -931,7 +931,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1757,7 +1757,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-code-complexity-detector.md b/.github/workflows/gh-aw-code-complexity-detector.md index 9fba1b80..da815f44 100644 --- a/.github/workflows/gh-aw-code-complexity-detector.md +++ b/.github/workflows/gh-aw-code-complexity-detector.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/code-quality-audit.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-code-duplication-detector.lock.yml b/.github/workflows/gh-aw-code-duplication-detector.lock.yml index b79e4362..b67837aa 100644 --- a/.github/workflows/gh-aw-code-duplication-detector.lock.yml +++ b/.github/workflows/gh-aw-code-duplication-detector.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"63306be9cd396b04f29e9ed1080cd46bc493012469293c63e69c877719768055","body_hash":"309bc0eba75c26685a3a2fbe1a0950a157e7f5c5369ae23c6ccbd7f9a1de1273","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"python:alpine","digest":"sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116","pinned_image":"python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ef8ae092a1b5a54bbd563fb0d0a1a533cca805ebab932a9450cf195fe65df66d","body_hash":"1204be08f3daab6224e75ec409716ed38bd68a179732fcd728d3e67a937e0f4d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"python:alpine","digest":"sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116","pinned_image":"python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) # - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 # - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -340,20 +340,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_8e036876d137713c_EOF' + cat << 'GH_AW_PROMPT_9134e4cdcd65cf9c_EOF' - GH_AW_PROMPT_8e036876d137713c_EOF + GH_AW_PROMPT_9134e4cdcd65cf9c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_8e036876d137713c_EOF' + cat << 'GH_AW_PROMPT_9134e4cdcd65cf9c_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_8e036876d137713c_EOF + GH_AW_PROMPT_9134e4cdcd65cf9c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_8e036876d137713c_EOF' + cat << 'GH_AW_PROMPT_9134e4cdcd65cf9c_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -382,9 +382,9 @@ jobs: {{/if}} - GH_AW_PROMPT_8e036876d137713c_EOF + GH_AW_PROMPT_9134e4cdcd65cf9c_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_8e036876d137713c_EOF' + cat << 'GH_AW_PROMPT_9134e4cdcd65cf9c_EOF' ## MCP Servers @@ -455,9 +455,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -693,7 +693,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_8e036876d137713c_EOF + GH_AW_PROMPT_9134e4cdcd65cf9c_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -878,23 +878,23 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version @@ -916,7 +916,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1742,7 +1742,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-code-duplication-detector.md b/.github/workflows/gh-aw-code-duplication-detector.md index bc1b9860..53ae4f8f 100644 --- a/.github/workflows/gh-aw-code-duplication-detector.md +++ b/.github/workflows/gh-aw-code-duplication-detector.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/code-quality-audit.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-code-quality-audit.lock.yml b/.github/workflows/gh-aw-code-quality-audit.lock.yml index 5f504905..a5582606 100644 --- a/.github/workflows/gh-aw-code-quality-audit.lock.yml +++ b/.github/workflows/gh-aw-code-quality-audit.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2d09e575832d111856c3b28f2d0d6037f67cbd8b33500b70a7674f0da4bdb25c","body_hash":"4dbd1861beff45ffcfeed9f1a50ad82e0c427efe9753e7046a057b2ae3c04e70","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c0f1e0d3405d7211fe23f43a7d92a5c46e15fab58b31d0cab89ef3ba8ed80322","body_hash":"6e882199f0ba905580e59e449f26a2bcdeb7101b09c3004a3e3e3da31167486e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,15 +56,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -327,20 +327,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_ac34c35c5a21ef92_EOF' + cat << 'GH_AW_PROMPT_41195d52200974e9_EOF' - GH_AW_PROMPT_ac34c35c5a21ef92_EOF + GH_AW_PROMPT_41195d52200974e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_ac34c35c5a21ef92_EOF' + cat << 'GH_AW_PROMPT_41195d52200974e9_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_ac34c35c5a21ef92_EOF + GH_AW_PROMPT_41195d52200974e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_ac34c35c5a21ef92_EOF' + cat << 'GH_AW_PROMPT_41195d52200974e9_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -369,9 +369,9 @@ jobs: {{/if}} - GH_AW_PROMPT_ac34c35c5a21ef92_EOF + GH_AW_PROMPT_41195d52200974e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_ac34c35c5a21ef92_EOF' + cat << 'GH_AW_PROMPT_41195d52200974e9_EOF' ## MCP Servers @@ -443,9 +443,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -595,7 +595,7 @@ jobs: - Wait for all sub-agents to complete, then merge and deduplicate. 3. Check for duplicates: - - Read `/tmp/previous-findings.json` for issues already filed by this agent. + - Read `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "__GH_AW_EXPR_BF503D80__"`. - Drop any finding that closely matches an existing open issue. @@ -607,7 +607,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_ac34c35c5a21ef92_EOF + GH_AW_PROMPT_41195d52200974e9_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -782,35 +782,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -835,7 +835,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: SEVERITY_THRESHOLD: ${{ inputs.severity-threshold }} name: Validate severity threshold @@ -1636,7 +1636,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-code-quality-audit.md b/.github/workflows/gh-aw-code-quality-audit.md index 5760d975..0065cf2a 100644 --- a/.github/workflows/gh-aw-code-quality-audit.md +++ b/.github/workflows/gh-aw-code-quality-audit.md @@ -18,7 +18,7 @@ imports: - gh-aw-fragments/code-quality-audit.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -124,7 +124,7 @@ steps: - Wait for all sub-agents to complete, then merge and deduplicate. 3. Check for duplicates: - - Read `/tmp/previous-findings.json` for issues already filed by this agent. + - Read `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "${{ inputs.title-prefix }}"`. - Drop any finding that closely matches an existing open issue. diff --git a/.github/workflows/gh-aw-create-comment-on-issue.lock.yml b/.github/workflows/gh-aw-create-comment-on-issue.lock.yml index d5154ebc..c54cb48c 100644 --- a/.github/workflows/gh-aw-create-comment-on-issue.lock.yml +++ b/.github/workflows/gh-aw-create-comment-on-issue.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3e80cc4c81c3d14ba25929c7074fb4fa85fe261feb5e48578ba625897da614d8","body_hash":"8464c3fad1f0038c88a1163ffd672cd2ddef3dd28d438142a80dcdfa70b39737","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"31d92114698d97048c402c9b88d6dbf3e892a002589a135ff2c6de3a81ca334c","body_hash":"8ef8229601520e647ac8b592c78f586f8c6a4a6ceff3ad8ecc731bf721dcd476","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -70,7 +70,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Create Comment On Issue" on: @@ -320,21 +319,21 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_943fbb05c41ee4a5_EOF' + cat << 'GH_AW_PROMPT_8cf3affbe324ca6e_EOF' - GH_AW_PROMPT_943fbb05c41ee4a5_EOF + GH_AW_PROMPT_8cf3affbe324ca6e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_943fbb05c41ee4a5_EOF' + cat << 'GH_AW_PROMPT_8cf3affbe324ca6e_EOF' Tools: add_comment, missing_tool, missing_data, noop - GH_AW_PROMPT_943fbb05c41ee4a5_EOF + GH_AW_PROMPT_8cf3affbe324ca6e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_943fbb05c41ee4a5_EOF' + cat << 'GH_AW_PROMPT_8cf3affbe324ca6e_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +362,9 @@ jobs: {{/if}} - GH_AW_PROMPT_943fbb05c41ee4a5_EOF + GH_AW_PROMPT_8cf3affbe324ca6e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_943fbb05c41ee4a5_EOF' + cat << 'GH_AW_PROMPT_8cf3affbe324ca6e_EOF' ## MCP Servers @@ -430,9 +429,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -467,7 +466,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_943fbb05c41ee4a5_EOF + GH_AW_PROMPT_8cf3affbe324ca6e_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -629,13 +628,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -647,31 +639,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -687,7 +685,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -722,6 +720,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -748,7 +756,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_TARGET_ISSUE_NUMBER: ${{ inputs.target-issue-number }} @@ -888,8 +896,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -911,7 +917,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -931,21 +937,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1003,7 +994,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1486,7 +1477,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-create-comment-on-issue.md b/.github/workflows/gh-aw-create-comment-on-issue.md index 838a5ab3..7760ec15 100644 --- a/.github/workflows/gh-aw-create-comment-on-issue.md +++ b/.github/workflows/gh-aw-create-comment-on-issue.md @@ -15,9 +15,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-create-comment-on-issue-${{ inputs.target-issue-number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-create-pr-from-issue.lock.yml b/.github/workflows/gh-aw-create-pr-from-issue.lock.yml index 15d7ae64..5b6218d3 100644 --- a/.github/workflows/gh-aw-create-pr-from-issue.lock.yml +++ b/.github/workflows/gh-aw-create-pr-from-issue.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"35f1163fed7ecd6eb33964e71944b786437640d2c2d8a2962fa98c780b5d5e8f","body_hash":"476f72547afd3b4a16067b501e96564ccd28bc405a71699c4f33cf1ae2412434","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e977a1f6fef785235549b9baca882c7488e2e8f1c5e5a4e0dae69893a925af35","body_hash":"e9e476cdfe6f3e8b12fc78d7b6c620ce5f800f351c11bbb84e99f7bfcdff6f55","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -72,7 +72,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Create PR From Issue" on: @@ -335,24 +334,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_39729f64f074511b_EOF' + cat << 'GH_AW_PROMPT_77fbc5c9c515deca_EOF' - GH_AW_PROMPT_39729f64f074511b_EOF + GH_AW_PROMPT_77fbc5c9c515deca_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_39729f64f074511b_EOF' + cat << 'GH_AW_PROMPT_77fbc5c9c515deca_EOF' Tools: add_comment, create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_39729f64f074511b_EOF + GH_AW_PROMPT_77fbc5c9c515deca_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_39729f64f074511b_EOF' + cat << 'GH_AW_PROMPT_77fbc5c9c515deca_EOF' - GH_AW_PROMPT_39729f64f074511b_EOF + GH_AW_PROMPT_77fbc5c9c515deca_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_39729f64f074511b_EOF' + cat << 'GH_AW_PROMPT_77fbc5c9c515deca_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -381,9 +380,9 @@ jobs: {{/if}} - GH_AW_PROMPT_39729f64f074511b_EOF + GH_AW_PROMPT_77fbc5c9c515deca_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_39729f64f074511b_EOF' + cat << 'GH_AW_PROMPT_77fbc5c9c515deca_EOF' ## MCP Servers @@ -448,9 +447,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -499,7 +498,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_39729f64f074511b_EOF + GH_AW_PROMPT_77fbc5c9c515deca_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -661,13 +660,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -679,31 +671,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -719,7 +717,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -754,6 +752,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -780,7 +788,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_DRAFT_PRS: ${{ inputs.draft-prs }} @@ -963,8 +971,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -986,7 +992,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1006,21 +1012,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1078,7 +1069,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1564,7 +1555,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-create-pr-from-issue.md b/.github/workflows/gh-aw-create-pr-from-issue.md index 12ef6401..df15aa23 100644 --- a/.github/workflows/gh-aw-create-pr-from-issue.md +++ b/.github/workflows/gh-aw-create-pr-from-issue.md @@ -16,9 +16,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-create-pr-from-issue-${{ inputs.target-issue-number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-dependency-review.lock.yml b/.github/workflows/gh-aw-dependency-review.lock.yml index 6877743e..232db02c 100644 --- a/.github/workflows/gh-aw-dependency-review.lock.yml +++ b/.github/workflows/gh-aw-dependency-review.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f2a55bc9100fca792d7023a02efaa593e5e1b1f7419bbb01799163008f8a3c29","body_hash":"38e80fc61b9184149ce7ec81dfc74ff08337f9010b951791dfd0a301c0698df4","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ef9da864bd7d99c6ce7bf8e2ae781cccb90217545d3c372766e3fef59c10677e","body_hash":"38e80fc61b9184149ce7ec81dfc74ff08337f9010b951791dfd0a301c0698df4","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -813,35 +813,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1653,7 +1653,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-dependency-review.md b/.github/workflows/gh-aw-dependency-review.md index 97612131..9a9f68e7 100644 --- a/.github/workflows/gh-aw-dependency-review.md +++ b/.github/workflows/gh-aw-dependency-review.md @@ -14,9 +14,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-dependency-review-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-docs-patrol.lock.yml b/.github/workflows/gh-aw-docs-patrol.lock.yml index 3e08a7e8..d431147f 100644 --- a/.github/workflows/gh-aw-docs-patrol.lock.yml +++ b/.github/workflows/gh-aw-docs-patrol.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c7d74f313c3436b5fba528b52d1016af68403ffacd923afdbb739949778737b0","body_hash":"29437bc646f99ad647066b75b943e22a1e6d5e589678b8096e7762af3991a874","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2d1f4f75142bde05a67b334bb8fba4ad222e14a783bd5c3afda27a97210bf5d4","body_hash":"e8e77517eba61319b58ac95640dd57c547350e2aa621a96a3b05ce8285b9b991","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -327,20 +327,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_5bcbce62b7599447_EOF' + cat << 'GH_AW_PROMPT_1b3b7a06e9967b27_EOF' - GH_AW_PROMPT_5bcbce62b7599447_EOF + GH_AW_PROMPT_1b3b7a06e9967b27_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_5bcbce62b7599447_EOF' + cat << 'GH_AW_PROMPT_1b3b7a06e9967b27_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_5bcbce62b7599447_EOF + GH_AW_PROMPT_1b3b7a06e9967b27_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_5bcbce62b7599447_EOF' + cat << 'GH_AW_PROMPT_1b3b7a06e9967b27_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -369,9 +369,9 @@ jobs: {{/if}} - GH_AW_PROMPT_5bcbce62b7599447_EOF + GH_AW_PROMPT_1b3b7a06e9967b27_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_5bcbce62b7599447_EOF' + cat << 'GH_AW_PROMPT_1b3b7a06e9967b27_EOF' ## MCP Servers @@ -443,9 +443,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -608,7 +608,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_5bcbce62b7599447_EOF + GH_AW_PROMPT_1b3b7a06e9967b27_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -779,35 +779,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -832,7 +832,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1629,7 +1629,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-docs-patrol.md b/.github/workflows/gh-aw-docs-patrol.md index 53fc9660..214fee91 100644 --- a/.github/workflows/gh-aw-docs-patrol.md +++ b/.github/workflows/gh-aw-docs-patrol.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-duplicate-issue-detector.lock.yml b/.github/workflows/gh-aw-duplicate-issue-detector.lock.yml index a03b3cf4..4cccba26 100644 --- a/.github/workflows/gh-aw-duplicate-issue-detector.lock.yml +++ b/.github/workflows/gh-aw-duplicate-issue-detector.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"cc3ab56be5852b3616d5b0477aa8424acaa0de38ce5f1ad54d88235c601af1ea","body_hash":"a4be8e1604b95edfbd66035b325336d6c48bc3758b4178f72e95e91363bc3c9d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"a5881a3abeb6b09903bb2e6996ceef172ff3a4180aa1f11c6c0423ac05576173","body_hash":"a4be8e1604b95edfbd66035b325336d6c48bc3758b4178f72e95e91363bc3c9d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -1506,7 +1506,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-duplicate-issue-detector.md b/.github/workflows/gh-aw-duplicate-issue-detector.md index 4bf4bb3d..d7bb3ba3 100644 --- a/.github/workflows/gh-aw-duplicate-issue-detector.md +++ b/.github/workflows/gh-aw-duplicate-issue-detector.md @@ -10,9 +10,9 @@ imports: - gh-aw-fragments/safe-output-add-comment-issue.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-duplicate-issue-detector-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.lock.yml b/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.lock.yml index 5204feb3..16e52325 100644 --- a/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.lock.yml +++ b/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e8a41c657172f9c95ba21dddbbc049fee170d01a8210b3b91ba4d6e10b1e85b2","body_hash":"ac695b16d5fc965c686ebf1f06120b17eea23d6807ab0ac6bf9cfc839ec061a6","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c546079950a112c19c197d140d187a8b0b4b01a82d5428bd95de84bf32e9cfbb","body_hash":"e14de9ce11702b39679c3132ad169212af1a2870fb7333e6489627447958b9e9","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -331,20 +331,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_2fd9da708e732660_EOF' + cat << 'GH_AW_PROMPT_79ae5663556f70c0_EOF' - GH_AW_PROMPT_2fd9da708e732660_EOF + GH_AW_PROMPT_79ae5663556f70c0_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_2fd9da708e732660_EOF' + cat << 'GH_AW_PROMPT_79ae5663556f70c0_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_2fd9da708e732660_EOF + GH_AW_PROMPT_79ae5663556f70c0_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_2fd9da708e732660_EOF' + cat << 'GH_AW_PROMPT_79ae5663556f70c0_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -373,9 +373,9 @@ jobs: {{/if}} - GH_AW_PROMPT_2fd9da708e732660_EOF + GH_AW_PROMPT_79ae5663556f70c0_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_2fd9da708e732660_EOF' + cat << 'GH_AW_PROMPT_79ae5663556f70c0_EOF' ## MCP Servers @@ -446,9 +446,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. @@ -555,7 +555,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_2fd9da708e732660_EOF + GH_AW_PROMPT_79ae5663556f70c0_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -734,35 +734,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -781,7 +781,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} GH_TOKEN: ${{ github.token }} @@ -1585,7 +1585,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.md b/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.md index 160034ff..0d61eff4 100644 --- a/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.md +++ b/.github/workflows/gh-aw-estc-actions-resource-not-accessible-detector.md @@ -13,7 +13,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-estc-docs-patrol-external.lock.yml b/.github/workflows/gh-aw-estc-docs-patrol-external.lock.yml index b4159d3e..87d5ef83 100644 --- a/.github/workflows/gh-aw-estc-docs-patrol-external.lock.yml +++ b/.github/workflows/gh-aw-estc-docs-patrol-external.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"038f5a6b881417126c0e6ebb97f34882ece89eab8e3a955e2137b7130b6549bf","body_hash":"42a5ccd8514c7f38daa82a570516f7e961b3522562f3f827085bd98a2854ed48","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4a6e410171788bf901122f131db62936b24b34a31982b9ab0abfdb8635f60f04","body_hash":"8796422e1ba52974859da28395afba5458edf3e87185627077d77ad3e8c0bc6b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -325,20 +325,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_d60df3e6d3c57836_EOF' + cat << 'GH_AW_PROMPT_40c91c5678def396_EOF' - GH_AW_PROMPT_d60df3e6d3c57836_EOF + GH_AW_PROMPT_40c91c5678def396_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_d60df3e6d3c57836_EOF' + cat << 'GH_AW_PROMPT_40c91c5678def396_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_d60df3e6d3c57836_EOF + GH_AW_PROMPT_40c91c5678def396_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_d60df3e6d3c57836_EOF' + cat << 'GH_AW_PROMPT_40c91c5678def396_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -367,9 +367,9 @@ jobs: {{/if}} - GH_AW_PROMPT_d60df3e6d3c57836_EOF + GH_AW_PROMPT_40c91c5678def396_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_d60df3e6d3c57836_EOF' + cat << 'GH_AW_PROMPT_40c91c5678def396_EOF' ## MCP Servers @@ -441,9 +441,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -604,7 +604,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_d60df3e6d3c57836_EOF + GH_AW_PROMPT_40c91c5678def396_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -772,35 +772,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -825,7 +825,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1640,7 +1640,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-estc-docs-patrol-external.md b/.github/workflows/gh-aw-estc-docs-patrol-external.md index 9688810f..0460c1cd 100644 --- a/.github/workflows/gh-aw-estc-docs-patrol-external.md +++ b/.github/workflows/gh-aw-estc-docs-patrol-external.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-estc-docs-pr-review.lock.yml b/.github/workflows/gh-aw-estc-docs-pr-review.lock.yml index d61c0602..612f9f41 100644 --- a/.github/workflows/gh-aw-estc-docs-pr-review.lock.yml +++ b/.github/workflows/gh-aw-estc-docs-pr-review.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c1118ac1119ae9456d95dc6ef4b5e8a304d72596b76c7fc704e7f838aef088e5","body_hash":"1900007d50c0ff1430c7691416de68611d04ab97cc1df66e941ed1e6ee2a05e0","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"b918d4ddc5ea6ab8bafa02353df4ee90ac209aec3145e6b9aa5cf0e2a7ad29c0","body_hash":"15965ca85d4ac50a1c426e4591b0950dc8a3d261be018c276e397ed2daf40862","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -325,20 +325,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_f467d608e7ed79a8_EOF' + cat << 'GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF' - GH_AW_PROMPT_f467d608e7ed79a8_EOF + GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_f467d608e7ed79a8_EOF' + cat << 'GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF' Tools: create_pull_request_review_comment(max:30), submit_pull_request_review, missing_tool, missing_data, noop - GH_AW_PROMPT_f467d608e7ed79a8_EOF + GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_f467d608e7ed79a8_EOF' + cat << 'GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -367,9 +367,9 @@ jobs: {{/if}} - GH_AW_PROMPT_f467d608e7ed79a8_EOF + GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_f467d608e7ed79a8_EOF' + cat << 'GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF' ## MCP Servers @@ -474,9 +474,9 @@ jobs: ### Step 2: Load Review Guidelines - The style guide and `applies_to` reference pages have been pre-downloaded to `/tmp/style-guide/`. Read them from disk before reviewing any files — they are your primary review criteria. + The style guide and `applies_to` reference pages have been pre-downloaded to `/tmp/gh-aw/agent/style-guide/`. Read them from disk before reviewing any files — they are your primary review criteria. - 1. Run `ls /tmp/style-guide/` to list available files. + 1. Run `ls /tmp/gh-aw/agent/style-guide/` to list available files. 2. Read each file to load the guidelines into your working context. The files correspond to: - Style guide overview, voice and tone, grammar and spelling, formatting, word choice, accessibility, UI writing - `applies_to` and cumulative docs guidelines, reference, and syntax @@ -612,7 +612,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_f467d608e7ed79a8_EOF + GH_AW_PROMPT_6f3c9ac4d525a9e8_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -797,35 +797,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -841,7 +841,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Download style guide reference pages - run: "set -euo pipefail\nmkdir -p /tmp/style-guide\nurls=(\n \"https://www.elastic.co/docs/contribute-docs/style-guide\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/voice-tone\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/grammar-spelling\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/formatting\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/word-choice\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/accessibility\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/ui-writing\"\n \"https://www.elastic.co/docs/contribute-docs/how-to/cumulative-docs/guidelines\"\n \"https://www.elastic.co/docs/contribute-docs/how-to/cumulative-docs/reference\"\n \"https://docs-v3-preview.elastic.dev/elastic/docs-builder/tree/main/syntax/applies\"\n)\nfor url in \"${urls[@]}\"; do\n slug=$(echo \"$url\" | sed 's|https\\?://||; s|/|_|g; s|[^a-zA-Z0-9_-]||g')\n curl -sSfL --retry 2 --max-time 30 \"$url\" -o \"/tmp/style-guide/${slug}.html\" || echo \"::warning::Failed to download ${url}\"\ndone\necho \"Downloaded $(ls /tmp/style-guide/ | wc -l) style guide pages to /tmp/style-guide/\"\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/style-guide\nurls=(\n \"https://www.elastic.co/docs/contribute-docs/style-guide\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/voice-tone\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/grammar-spelling\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/formatting\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/word-choice\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/accessibility\"\n \"https://www.elastic.co/docs/contribute-docs/style-guide/ui-writing\"\n \"https://www.elastic.co/docs/contribute-docs/how-to/cumulative-docs/guidelines\"\n \"https://www.elastic.co/docs/contribute-docs/how-to/cumulative-docs/reference\"\n \"https://docs-v3-preview.elastic.dev/elastic/docs-builder/tree/main/syntax/applies\"\n)\nfor url in \"${urls[@]}\"; do\n slug=$(echo \"$url\" | sed 's|https\\?://||; s|/|_|g; s|[^a-zA-Z0-9_-]||g')\n curl -sSfL --retry 2 --max-time 30 \"$url\" -o \"/tmp/gh-aw/agent/style-guide/${slug}.html\" || echo \"::warning::Failed to download ${url}\"\ndone\necho \"Downloaded $(ls /tmp/gh-aw/agent/style-guide/ | wc -l) style guide pages to /tmp/gh-aw/agent/style-guide/\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1683,7 +1683,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-estc-docs-pr-review.md b/.github/workflows/gh-aw-estc-docs-pr-review.md index 32be1b7b..78431a0a 100644 --- a/.github/workflows/gh-aw-estc-docs-pr-review.md +++ b/.github/workflows/gh-aw-estc-docs-pr-review.md @@ -14,9 +14,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-docs-pr-review-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -107,7 +107,7 @@ steps: - name: Download style guide reference pages run: | set -euo pipefail - mkdir -p /tmp/style-guide + mkdir -p /tmp/gh-aw/agent/style-guide urls=( "https://www.elastic.co/docs/contribute-docs/style-guide" "https://www.elastic.co/docs/contribute-docs/style-guide/voice-tone" @@ -122,9 +122,9 @@ steps: ) for url in "${urls[@]}"; do slug=$(echo "$url" | sed 's|https\?://||; s|/|_|g; s|[^a-zA-Z0-9_-]||g') - curl -sSfL --retry 2 --max-time 30 "$url" -o "/tmp/style-guide/${slug}.html" || echo "::warning::Failed to download ${url}" + curl -sSfL --retry 2 --max-time 30 "$url" -o "/tmp/gh-aw/agent/style-guide/${slug}.html" || echo "::warning::Failed to download ${url}" done - echo "Downloaded $(ls /tmp/style-guide/ | wc -l) style guide pages to /tmp/style-guide/" + echo "Downloaded $(ls /tmp/gh-aw/agent/style-guide/ | wc -l) style guide pages to /tmp/gh-aw/agent/style-guide/" - name: Repo-specific setup if: ${{ inputs.setup-commands != '' }} env: @@ -160,9 +160,9 @@ Follow these steps in order. ### Step 2: Load Review Guidelines -The style guide and `applies_to` reference pages have been pre-downloaded to `/tmp/style-guide/`. Read them from disk before reviewing any files — they are your primary review criteria. +The style guide and `applies_to` reference pages have been pre-downloaded to `/tmp/gh-aw/agent/style-guide/`. Read them from disk before reviewing any files — they are your primary review criteria. -1. Run `ls /tmp/style-guide/` to list available files. +1. Run `ls /tmp/gh-aw/agent/style-guide/` to list available files. 2. Read each file to load the guidelines into your working context. The files correspond to: - Style guide overview, voice and tone, grammar and spelling, formatting, word choice, accessibility, UI writing - `applies_to` and cumulative docs guidelines, reference, and syntax diff --git a/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.lock.yml b/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.lock.yml index 03cfaf2f..41a0a8da 100644 --- a/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.lock.yml +++ b/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"0359b185b74c6ea4658259976985b1a35d0ccdfbddae7f4e0a1326f0d6013a89","body_hash":"106e8c54d169dfd478aab63589eebd9605614d4c1c7f2a079dcffee0d2e36d49","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"0f28d64dd90cd77cde3e8597e1be784f890eb0370a4584b18b090a4f849192d5","body_hash":"0ef66303d6a9fd2843e0673eb67f25beb5efb202ca3ce89b7a253740acf09211","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -318,20 +318,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_39c013c3cab0bcf2_EOF' + cat << 'GH_AW_PROMPT_3b8718699432dbd2_EOF' - GH_AW_PROMPT_39c013c3cab0bcf2_EOF + GH_AW_PROMPT_3b8718699432dbd2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_39c013c3cab0bcf2_EOF' + cat << 'GH_AW_PROMPT_3b8718699432dbd2_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_39c013c3cab0bcf2_EOF + GH_AW_PROMPT_3b8718699432dbd2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_39c013c3cab0bcf2_EOF' + cat << 'GH_AW_PROMPT_3b8718699432dbd2_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -360,9 +360,9 @@ jobs: {{/if}} - GH_AW_PROMPT_39c013c3cab0bcf2_EOF + GH_AW_PROMPT_3b8718699432dbd2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_39c013c3cab0bcf2_EOF' + cat << 'GH_AW_PROMPT_3b8718699432dbd2_EOF' ## MCP Servers @@ -433,9 +433,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -557,7 +557,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_39c013c3cab0bcf2_EOF + GH_AW_PROMPT_3b8718699432dbd2_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -722,35 +722,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -769,7 +769,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1583,7 +1583,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.md b/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.md index 9e94f280..e76b1c19 100644 --- a/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.md +++ b/.github/workflows/gh-aw-estc-newbie-contributor-patrol-external.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-estc-pr-buildkite-detective.lock.yml b/.github/workflows/gh-aw-estc-pr-buildkite-detective.lock.yml index f9f147fc..6471c682 100644 --- a/.github/workflows/gh-aw-estc-pr-buildkite-detective.lock.yml +++ b/.github/workflows/gh-aw-estc-pr-buildkite-detective.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"d17061d0a2117f5813e68e9a765d76d4c980e28c7ef9dc09844efe6e6fbbda39","body_hash":"9cd3b52ebec5747dd266ff2460983488ce6e37e069cb591cd606ada5c5e88df9","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["BUILDKITE_API_TOKEN","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"349d8790ab335202b6f9dc0d4ba679bcbfc7c26bed258829f0f4c43b4fb432e5","body_hash":"9cd3b52ebec5747dd266ff2460983488ce6e37e069cb591cd606ada5c5e88df9","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["BUILDKITE_API_TOKEN","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -51,15 +51,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -641,35 +641,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1471,7 +1471,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-estc-pr-buildkite-detective.md b/.github/workflows/gh-aw-estc-pr-buildkite-detective.md index 3aed9ab2..87865342 100644 --- a/.github/workflows/gh-aw-estc-pr-buildkite-detective.md +++ b/.github/workflows/gh-aw-estc-pr-buildkite-detective.md @@ -11,7 +11,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-flaky-test-investigator.lock.yml b/.github/workflows/gh-aw-flaky-test-investigator.lock.yml index 014d64b1..4a25159d 100644 --- a/.github/workflows/gh-aw-flaky-test-investigator.lock.yml +++ b/.github/workflows/gh-aw-flaky-test-investigator.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"bd37adf0033d927bce60930573617bc326e46749c161dde77addadf9f4af126d","body_hash":"4ef86b4551e997eacda0e40589db389d953b9c6e522ac4d10477e3a8acc2ab14","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ce5dcfb3202a92339af134369af26f8b06976aa537ab8edb1c9206a9a59d660a","body_hash":"4ec53030abae43226d6ca63c70bdd1c13f20d8f37589f4d7a0bfb50918bf37a3","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -318,20 +318,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_6615849f5841c7c8_EOF' + cat << 'GH_AW_PROMPT_66b400fef61cb3a8_EOF' - GH_AW_PROMPT_6615849f5841c7c8_EOF + GH_AW_PROMPT_66b400fef61cb3a8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_6615849f5841c7c8_EOF' + cat << 'GH_AW_PROMPT_66b400fef61cb3a8_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_6615849f5841c7c8_EOF + GH_AW_PROMPT_66b400fef61cb3a8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_6615849f5841c7c8_EOF' + cat << 'GH_AW_PROMPT_66b400fef61cb3a8_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -360,9 +360,9 @@ jobs: {{/if}} - GH_AW_PROMPT_6615849f5841c7c8_EOF + GH_AW_PROMPT_66b400fef61cb3a8_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_6615849f5841c7c8_EOF' + cat << 'GH_AW_PROMPT_66b400fef61cb3a8_EOF' ## MCP Servers @@ -433,9 +433,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -585,7 +585,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_6615849f5841c7c8_EOF + GH_AW_PROMPT_66b400fef61cb3a8_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -751,35 +751,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -798,7 +798,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1595,7 +1595,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-flaky-test-investigator.md b/.github/workflows/gh-aw-flaky-test-investigator.md index 87b2c91a..abadf440 100644 --- a/.github/workflows/gh-aw-flaky-test-investigator.md +++ b/.github/workflows/gh-aw-flaky-test-investigator.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-fragments/playwright-mcp-explorer.md b/.github/workflows/gh-aw-fragments/playwright-mcp-explorer.md index e369b5d5..c847ac7d 100644 --- a/.github/workflows/gh-aw-fragments/playwright-mcp-explorer.md +++ b/.github/workflows/gh-aw-fragments/playwright-mcp-explorer.md @@ -1,109 +1,58 @@ --- tools: playwright: - args: ["--snapshot-mode", "none"] + mode: cli steps: - name: Write Playwright instructions to disk run: | - cat > /tmp/playwright-instructions.md << 'EOF' - # Playwright MCP Tools + mkdir -p /tmp/gh-aw/agent + cat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF' + # Playwright CLI - Use Playwright MCP tools for interactive browser automation. - Unless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts. + Use `playwright-cli` in bash for interactive browser automation. + Run all Playwright commands as bash subprocesses — do not use MCP browser tools. - ## Available tools + ## Basic usage - - `browser_navigate` — go to a URL - - `browser_click` — click an element - - `browser_type` — type text into an input - - `browser_snapshot` — get an accessibility tree (YAML) of the current page - - `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG) - - `browser_run_code` — run a Playwright code snippet - - `browser_wait_for` — wait for text to appear/disappear - - `browser_press_key` — press a keyboard key - - ## Automatic snapshots are disabled - - `browser_click`, `browser_type`, `browser_wait_for`, and - `browser_run_code` do NOT return page state. You choose when to - inspect the page. - - ## Batch actions with `browser_run_code` - - When you know the UI structure (button names, input labels), batch - multiple actions in a single `browser_run_code` call using Playwright's - role selectors. This is much more efficient than individual tool calls: - - ```js - async (page) => { - await page.getByRole('button', { name: 'Settings' }).click(); - await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark'); - await page.getByRole('button', { name: 'Save' }).click(); - return 'Settings saved'; - } - ``` - - **Keep return values small** — return only what you need: - ```js - async (page) => { - const res = await page.request.post(url, {data}); - const json = await res.json(); - // Good: ~50 chars - return JSON.stringify({success: json.success, errors: json.errors?.length || 0}); - // Bad: entire response body (can be 20K+ chars) - } - ``` - - ## Discover elements with snapshots - - When you don't know what's on the page, save a snapshot to disk and - search it: - ``` - browser_snapshot(filename="/tmp/gh-aw/mcp-logs/page.md") - ``` - Then grep for elements: ```bash - grep 'button.*Save\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md + # Navigate and take a snapshot (accessibility tree) + playwright-cli snapshot + + # Take a screenshot + playwright-cli screenshot /tmp/gh-aw/agent/screenshot.png + + # Navigate, interact, then snapshot + playwright-cli run - << 'JS' + const { chromium } = require('playwright'); + (async () => { + const browser = await chromium.launch(); + const page = await browser.newPage(); + await page.goto('https://example.com'); + await page.click('button[name="Submit"]'); + console.log(await page.title()); + await browser.close(); + })(); + JS ``` - Use the `ref` value from grep results with `browser_click(ref="...")`. - - Only take snapshots when you need to discover unknown elements. - If you know the button name or role, use `browser_run_code` instead. - ## Error handling in `browser_run_code` + ## Discover page structure - `browser_run_code` blocks can fail mid-execution if a selector doesn't - match. Keep blocks focused — if a sequence has uncertain steps, split - it into separate `browser_run_code` calls so you can inspect and adapt - between them. - - ## Measuring DOM properties - - For programmatic checks (e.g. element heights, contrast), use - `browser_run_code`: - - ```javascript - async (page) => { - const els = await page.locator('input, button, [role="combobox"]').all(); - const results = []; - for (const el of els.slice(0, 10)) { - const box = await el.boundingBox(); - const text = await el.textContent(); - if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) }); - } - return JSON.stringify(results); - } + Save a snapshot to disk and search it: + ```bash + playwright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt + grep -i 'button\|input\|link' /tmp/gh-aw/agent/page-snapshot.txt ``` - ## Handling failures + ## Error handling - - Do not retry the same action more than twice — the page is in a different state than expected. - - Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check. - - Adapt (different selector, different path) or report the failure as a finding. - - Never claim you verified something you didn't — if it failed and you skipped it, say so. + - Do not retry the same action more than twice. + - If a step fails, take a screenshot to diagnose: + `playwright-cli screenshot /tmp/gh-aw/agent/debug.png` + - Adapt (different selector, different path) or report the failure. + - Never claim you verified something you didn't. EOF --- -## Playwright MCP Tools +## Playwright CLI -Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. +Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. diff --git a/.github/workflows/gh-aw-fragments/pr-context.md b/.github/workflows/gh-aw-fragments/pr-context.md index 48bbc902..b6932599 100644 --- a/.github/workflows/gh-aw-fragments/pr-context.md +++ b/.github/workflows/gh-aw-fragments/pr-context.md @@ -6,54 +6,54 @@ steps: PR_NUMBER: "${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }}" run: | set -euo pipefail - mkdir -p /tmp/pr-context + mkdir -p /tmp/gh-aw/agent/pr-context # PR metadata gh pr view "$PR_NUMBER" --json title,body,author,baseRefName,headRefName,headRefOid,url \ - > /tmp/pr-context/pr.json + > /tmp/gh-aw/agent/pr-context/pr.json # Full diff - if ! gh pr diff "$PR_NUMBER" > /tmp/pr-context/pr.diff; then + if ! gh pr diff "$PR_NUMBER" > /tmp/gh-aw/agent/pr-context/pr.diff; then echo "::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available." - : > /tmp/pr-context/pr.diff + : > /tmp/gh-aw/agent/pr-context/pr.diff fi # Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them) gh api "repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files" --paginate \ - | jq -s 'add // []' > /tmp/pr-context/files.json + | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json # Per-file diffs with line numbers # Lines with a number prefix are commentable (RIGHT side: added or context). # Deleted lines get no number (LEFT side only). - jq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do + jq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do filename=$(echo "$entry" | jq -r '.filename') - mkdir -p "/tmp/pr-context/diffs/$(dirname "$filename")" + mkdir -p "/tmp/gh-aw/agent/pr-context/diffs/$(dirname "$filename")" echo "$entry" | jq -r '.patch // empty' | awk ' /^@@/ { s=$3; gsub(/\+/,"",s); split(s,a,","); line=a[1]+0; print; next } /^\+/ { printf "%d\t%s\n", line++, $0; next } /^-/ { printf " \t%s\n", $0; next } /^ / { printf "%d\t%s\n", line++, $0; next } { print } - ' > "/tmp/pr-context/diffs/${filename}.diff" + ' > "/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff" done # File orderings for sub-agent review (3 strategies) - jq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \ - > /tmp/pr-context/file_order_az.txt - jq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \ - > /tmp/pr-context/file_order_za.txt - jq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \ - > /tmp/pr-context/file_order_largest.txt + jq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \ + > /tmp/gh-aw/agent/pr-context/file_order_az.txt + jq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \ + > /tmp/gh-aw/agent/pr-context/file_order_za.txt + jq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \ + > /tmp/gh-aw/agent/pr-context/file_order_largest.txt # Compute PR size metrics for review fan-out decisions - FILE_COUNT=$(jq 'length' /tmp/pr-context/files.json) - DIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ') - echo "${FILE_COUNT} files, ${DIFF_LINES} diff lines" > /tmp/pr-context/pr-size.txt + FILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json) + DIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ') + echo "${FILE_COUNT} files, ${DIFF_LINES} diff lines" > /tmp/gh-aw/agent/pr-context/pr-size.txt echo "PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines" # Existing reviews gh api "repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews" --paginate \ - | jq -s 'add // []' > /tmp/pr-context/reviews.json + | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json # Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated) gh api graphql --paginate -f query=' @@ -86,48 +86,48 @@ steps: } ' -F owner="${GITHUB_REPOSITORY%/*}" -F repo="${GITHUB_REPOSITORY#*/}" -F "number=$PR_NUMBER" \ --jq '.data.repository.pullRequest.reviewThreads.nodes' \ - | jq -s 'add // []' > /tmp/pr-context/review_comments.json + | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json # Filtered review thread views (pre-computed so agents don't need to parse review_comments.json) - jq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \ - > /tmp/pr-context/unresolved_threads.json - jq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \ - > /tmp/pr-context/resolved_threads.json - jq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \ - > /tmp/pr-context/outdated_threads.json + jq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \ + > /tmp/gh-aw/agent/pr-context/unresolved_threads.json + jq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \ + > /tmp/gh-aw/agent/pr-context/resolved_threads.json + jq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \ + > /tmp/gh-aw/agent/pr-context/outdated_threads.json # Per-file review threads (mirrors diffs/ structure) - jq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do + jq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do filepath=$(echo "$thread" | jq -r '.path // empty') [ -z "$filepath" ] && continue - mkdir -p "/tmp/pr-context/threads/$(dirname "$filepath")" - echo "$thread" >> "/tmp/pr-context/threads/${filepath}.jsonl" + mkdir -p "/tmp/gh-aw/agent/pr-context/threads/$(dirname "$filepath")" + echo "$thread" >> "/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl" done # Convert per-file JSONL to proper JSON arrays - mkdir -p /tmp/pr-context/threads - find /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do + mkdir -p /tmp/gh-aw/agent/pr-context/threads + find /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do jq -s '.' "$jsonl" > "${jsonl%.jsonl}.json" rm "$jsonl" done # PR discussion comments gh api "repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments" --paginate \ - | jq -s 'add // []' > /tmp/pr-context/comments.json + | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json # Linked issues - jq -r '.body // ""' /tmp/pr-context/pr.json 2>/dev/null \ + jq -r '.body // ""' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \ | grep -oiE '(fixes|closes|resolves)\s+#[0-9]+' \ | grep -oE '[0-9]+$' \ | sort -u \ | while read -r issue; do - gh api "repos/$GITHUB_REPOSITORY/issues/$issue" > "/tmp/pr-context/issue-${issue}.json" || true + gh api "repos/$GITHUB_REPOSITORY/issues/$issue" > "/tmp/gh-aw/agent/pr-context/issue-${issue}.json" || true done || true # Write manifest - cat > /tmp/pr-context/README.md << 'MANIFEST' + cat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST' # PR Context - Pre-fetched PR data. All files are in `/tmp/pr-context/`. + Pre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`. | File | Description | | --- | --- | @@ -154,10 +154,10 @@ steps: | `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) | MANIFEST - echo "PR context written to /tmp/pr-context/" - ls -la /tmp/pr-context/ + echo "PR context written to /tmp/gh-aw/agent/pr-context/" + ls -la /tmp/gh-aw/agent/pr-context/ --- ## PR Context -PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. +PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. diff --git a/.github/workflows/gh-aw-fragments/previous-findings.md b/.github/workflows/gh-aw-fragments/previous-findings.md index fa3b1f9a..cdacd412 100644 --- a/.github/workflows/gh-aw-fragments/previous-findings.md +++ b/.github/workflows/gh-aw-fragments/previous-findings.md @@ -6,19 +6,20 @@ steps: TITLE_PREFIX: ${{ inputs.title-prefix }} run: | set -euo pipefail + mkdir -p /tmp/gh-aw/agent gh issue list \ --repo "$GITHUB_REPOSITORY" \ --search "in:title \"$TITLE_PREFIX\"" \ --state all \ --limit 100 \ --json number,title,state \ - > /tmp/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/previous-findings.json; } + > /tmp/gh-aw/agent/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/gh-aw/agent/previous-findings.json; } --- ## Previous Findings -Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. +Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. -- Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. +- Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. diff --git a/.github/workflows/gh-aw-fragments/runtime-setup.md b/.github/workflows/gh-aw-fragments/runtime-setup.md index 8c2e312d..c65d5fc5 100644 --- a/.github/workflows/gh-aw-fragments/runtime-setup.md +++ b/.github/workflows/gh-aw-fragments/runtime-setup.md @@ -2,26 +2,26 @@ steps: - name: Setup Go if: hashFiles('go.mod') != '' - uses: actions/setup-go@v5 + uses: actions/setup-go@v7 with: go-version-file: go.mod cache: true - name: Setup Python if: hashFiles('.python-version') != '' - uses: actions/setup-python@v5 + uses: actions/setup-python@v6 with: python-version-file: '.python-version' - name: Setup Node.js (.node-version) if: hashFiles('.node-version') != '' - uses: actions/setup-node@v6 + uses: actions/setup-node@v7 with: node-version-file: '.node-version' - name: Setup Node.js (.nvmrc) if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' - uses: actions/setup-node@v6 + uses: actions/setup-node@v7 with: node-version-file: '.nvmrc' @@ -34,7 +34,7 @@ steps: - name: Setup uv if: hashFiles('pyproject.toml', 'uv.lock') != '' - uses: astral-sh/setup-uv@v5 + uses: astral-sh/setup-uv@v8 id: setup-uv - name: Expose uv in workspace diff --git a/.github/workflows/gh-aw-fragments/safe-output-code-review.md b/.github/workflows/gh-aw-fragments/safe-output-code-review.md index 29435cb4..a845151c 100644 --- a/.github/workflows/gh-aw-fragments/safe-output-code-review.md +++ b/.github/workflows/gh-aw-fragments/safe-output-code-review.md @@ -1,119 +1,2 @@ --- -safe-inputs: - ready-to-code-review: - description: "Prepare code review instructions based on PR size — writes agent-review.md, parent-review.md, and subagent-*.md to /tmp/pr-context/" - py: | - import os, json, re - - os.makedirs('/tmp/pr-context', exist_ok=True) - - # Read PR size written by the pr-context step - try: - with open('/tmp/pr-context/pr-size.txt') as f: - pr_size = f.read().strip() - m = re.search(r', (\d+) diff', pr_size) - diff_lines = int(m.group(1)) if m else 0 - except Exception: - pr_size = 'unknown size' - diff_lines = 0 - - # Determine review approach based on PR size - def write_subagent(key, desc): - sa_lines = [ - '# PR Review Sub-Agent', - '', - 'Review the PR as a code review sub-agent. Return findings only \u2014 do NOT leave inline comments.', - '', - '## Instructions', - '', - 'Read `/tmp/pr-context/review-instructions.md` for the full review process, criteria, calibration examples, and output format.', - '', - '## Context', - '', - '- Repository conventions: `/tmp/agents.md` (skip if missing)', - '- PR details: `/tmp/pr-context/pr.json`', - '- All context files: `/tmp/pr-context/README.md`', - '- Per-file diffs: `/tmp/pr-context/diffs/.diff`', - '- Full file contents: read from the workspace (PR branch is checked out)', - '', - '## Your File Order', - '', - f'Review files in this order: `/tmp/pr-context/file_order_{key}.txt` ({desc})', - ] - with open(f'/tmp/pr-context/subagent-{key}.md', 'w') as sa_f: - sa_f.write('\n'.join(sa_lines) + '\n') - - if diff_lines < 200: - approach_lines = [ - f'**Small PR ({pr_size}):** Review directly \u2014 no sub-agents. Review files in order from `/tmp/pr-context/file_order_az.txt`, reading each diff from `/tmp/pr-context/diffs/.diff` and the full file from the workspace.', - ] - size_key = 'small' - elif diff_lines < 800: - write_subagent('az', 'A \u2192 Z (alphabetical)') - write_subagent('za', 'Z \u2192 A (reverse alphabetical)') - approach_lines = [ - f'**Medium PR ({pr_size}):** Use the **Pick Three, Keep Many** process \u2014 spawn 2 `code-review` sub-agents in parallel:', - '', - '- **Agent 1**: prompt it to read `/tmp/pr-context/subagent-az.md` and follow it', - '- **Agent 2**: prompt it to read `/tmp/pr-context/subagent-za.md` and follow it', - '', - 'Each sub-agent returns a structured findings list. They do NOT leave inline comments.', - ] - size_key = 'medium' - else: - write_subagent('az', 'A \u2192 Z (alphabetical)') - write_subagent('za', 'Z \u2192 A (reverse alphabetical)') - write_subagent('largest', 'largest diff first') - approach_lines = [ - f'**Large PR ({pr_size}):** Use the **Pick Three, Keep Many** process \u2014 spawn 3 `code-review` sub-agents in parallel:', - '', - '- **Agent 1**: prompt it to read `/tmp/pr-context/subagent-az.md` and follow it', - '- **Agent 2**: prompt it to read `/tmp/pr-context/subagent-za.md` and follow it', - '- **Agent 3**: prompt it to read `/tmp/pr-context/subagent-largest.md` and follow it', - '', - 'Each sub-agent returns a structured findings list. They do NOT leave inline comments.', - ] - size_key = 'large' - - with open('/tmp/pr-context/agent-review.md', 'w') as f: - f.write('\n'.join(approach_lines) + '\n') - - # Write parent-agent comment format and threshold instructions - t3 = chr(96) * 3 - t5 = chr(96) * 5 - threshold = os.environ.get('GH_AW_INPUTS_MINIMUM_SEVERITY', 'low') or 'low' - parent_lines = [ - '# Code Review: Comment Format and Threshold', - '', - '## Comment Format', - '', - 'Call **`create_pull_request_review_comment`** with:', - '- The file path and a **line number that appears in the numbered diff** (`/tmp/pr-context/diffs/.diff`). Only lines with a number prefix are commentable. If your target line has no number in the diff, include the finding in the review body instead.', - '', - t5, - '**[SEVERITY] Brief title**', - '', - 'Description of the issue and why it matters.', - '', - f'{t3}suggestion', - 'corrected code here', - t3, - t5, - '', - 'Only include a `suggestion` block when you can provide a concrete code fix that **actually changes** the code. If the fix requires structural changes, describe the fix in prose instead — never include a suggestion identical to the original line.', - '', - '## Inline Comment Threshold', - '', - f'The minimum severity for inline comments is `{threshold}`.', - '', - 'Issues at or above the threshold get **inline review comments** on the specific code line. Issues below the threshold should be collected into a **collapsible section** of the review body — use a `
` block titled "Lower-priority observations (N)" with each item listing its severity, title, file:line, and why it matters.', - '', - 'Severity order (highest to lowest): critical > high > medium > low > nitpick.', - '', - 'If the threshold is `low`, only nitpick-severity issues go in the review body. If `medium`, both low and nitpick go in the body. If the value is unrecognized, treat it as `low`.', - ] - with open('/tmp/pr-context/parent-review.md', 'w') as f: - f.write('\n'.join(parent_lines) + '\n') - - print(json.dumps({'status': 'ok', 'size': size_key, 'diff_lines': diff_lines, 'agent_review': '/tmp/pr-context/agent-review.md', 'parent_review': '/tmp/pr-context/parent-review.md'})) --- diff --git a/.github/workflows/gh-aw-fragments/safe-output-create-pr.md b/.github/workflows/gh-aw-fragments/safe-output-create-pr.md index fd8b5800..f944c8f7 100644 --- a/.github/workflows/gh-aw-fragments/safe-output-create-pr.md +++ b/.github/workflows/gh-aw-fragments/safe-output-create-pr.md @@ -1,126 +1,4 @@ --- -safe-inputs: - ready-to-make-pr: - description: "Run the PR readiness checklist before creating or updating a PR" - py: | - import os, json, subprocess - def find(*paths): - return next((p for p in paths if os.path.isfile(p)), None) - def run(cmd): - try: - return subprocess.run(cmd, capture_output=True, text=True, timeout=60) - except subprocess.TimeoutExpired: - return subprocess.CompletedProcess(cmd, 1, stdout='', stderr='diff timed out') - - # Find the fork point with the upstream branch to scope diff - upstream_sha = '' - for ref in ['@{upstream}', 'origin/HEAD', 'origin/main']: - r = run(['git', 'merge-base', 'HEAD', ref]) - if r.returncode == 0 and r.stdout.strip(): - upstream_sha = r.stdout.strip() - break - if not upstream_sha: - print(json.dumps({'status': 'error', 'error': 'Unable to determine upstream fork point. Fix: ensure remotes are fetched and a tracking branch is set (e.g., `git branch --set-upstream-to origin/`), then rerun ready_to_make_pr.'})) - raise SystemExit(0) - - contributing = find('CONTRIBUTING.md', 'CONTRIBUTING.rst', 'docs/CONTRIBUTING.md', 'docs/contributing.md') - pr_template = find('.github/pull_request_template.md', '.github/PULL_REQUEST_TEMPLATE.md', '.github/PULL_REQUEST_TEMPLATE/pull_request_template.md') - agents_md = find('AGENTS.md', 'agents.md', '.github/agents.md', '.github/AGENTS.md') - # Generate diff of all local changes vs upstream for self-review - # Try --merge-base (vs common ancestor), fall back to - # @{upstream} 2-dot (vs upstream tip), then HEAD (uncommitted only) - diff_text = '' - for diff_cmd in [ - ['git', 'diff', '--merge-base', '@{upstream}'], - ['git', 'diff', '@{upstream}'], - ['git', 'diff', 'HEAD'], - ]: - result = run(diff_cmd) - if result.stdout.strip(): - diff_text = result.stdout.strip() - break - stat_text = '' - for stat_cmd in [ - ['git', 'diff', '--stat', '--merge-base', '@{upstream}'], - ['git', 'diff', '--stat', '@{upstream}'], - ['git', 'diff', '--stat', 'HEAD'], - ]: - result = run(stat_cmd) - if result.stdout.strip(): - stat_text = result.stdout.strip() - break - # Capture commit messages so the sub-agent knows what changed and why - commits_text = '' - for log_cmd in [ - ['git', 'log', '--format=### %s%n%n%b', f'{upstream_sha}..HEAD'], - ['git', 'log', '--format=### %s%n%n%b', '-10'], - ]: - result = run(log_cmd) - if result.stdout.strip(): - commits_text = result.stdout.strip() - break - os.makedirs('/tmp/self-review', exist_ok=True) - with open('/tmp/self-review/diff.patch', 'w') as f: - f.write(diff_text) - with open('/tmp/self-review/stat.txt', 'w') as f: - f.write(stat_text) - with open('/tmp/self-review/commits.txt', 'w') as f: - f.write(commits_text) - # Write manifest so the sub-agent has structured context without - # relying on the main agent to manually pass it in the prompt - diff_line_count = len(diff_text.splitlines()) - manifest_lines = [ - '# Self-Review Context', - '', - 'You are reviewing unpushed changes before they are submitted as a new PR.', - '', - '## Available files', - '', - 'All files are in `/tmp/self-review/`:', - '', - f'- `diff.patch` : Full unified diff of all changes ({diff_line_count} lines)', - '- `stat.txt` : File-level change summary', - '- `commits.txt` : Commit messages describing what was changed and why', - '- `notes.md` : Author notes on what was done, why, and key decisions made', - '', - '## How to review', - '', - '1. Read `notes.md` to understand what the author did, why, and what decisions they made.', - '2. Read `commits.txt` for the commit-level view of what changed.', - '3. Read `stat.txt` for a high-level view of which files changed.', - '4. Read `diff.patch` and the relevant source files from the workspace (the branch is checked out).', - ] - step = 5 - if agents_md: - manifest_lines.append(f'{step}. Read `{agents_md}` in the workspace for repository coding conventions.') - step += 1 - review_instructions = '/tmp/pr-context/review-instructions.md' - if os.path.isfile(review_instructions): - manifest_lines.append(f'{step}. Read `{review_instructions}` for full review criteria, severity levels, false positive guidance, and calibration examples.') - step += 1 - manifest_lines += [ - '', - '## Focus areas', - '', - 'Look for bugs, logic errors, missed edge cases, and style issues.', - 'Focus on what the author might have MISSED rather than re-deriving their reasoning.', - 'Do not run tests, linters, or type checkers in this self-review step; the parent agent is responsible for validation and has already run the required checks.', - '', - '## What NOT to flag', - '', - '- Pre-existing issues not introduced by these changes', - '- Style preferences handled by linters or formatters', - '- Theoretical performance concerns without evidence of real-world impact', - ] - with open('/tmp/self-review/README.md', 'w') as f: - f.write('\n'.join(manifest_lines) + '\n') - checklist = [] - if contributing: checklist.append(f'Review the contributing guide ({contributing}) before opening or updating a PR.') - if pr_template: checklist.append(f'Follow the PR template ({pr_template}) for title, description, and validation notes.') - checklist.append('Confirm the requested task is fully completed and validated before creating or pushing PR changes.') - if diff_line_count > 0: - checklist.append(f'A diff of your unpushed changes ({diff_line_count} lines) and supporting context have been saved to `/tmp/self-review/`. Before spawning the sub-agent, write `/tmp/self-review/notes.md` with: what you changed and why, which files matter most and what they do, edge cases you already handled, and what test coverage exists. Then spawn a `code-review` sub-agent via `runSubagent` and tell it to start by reading `/tmp/self-review/README.md`. If the sub-agent finds legitimate issues, fix them, commit, and call `ready_to_make_pr` again.') - print(json.dumps({'status': 'ok', 'checklist': checklist, 'contributing_guide': contributing, 'pr_template': pr_template, 'diff_line_count': diff_line_count})) safe-outputs: create-pull-request: patch-format: bundle diff --git a/.github/workflows/gh-aw-fragments/safe-output-push-to-pr.md b/.github/workflows/gh-aw-fragments/safe-output-push-to-pr.md index 341e3d44..f28ce5b6 100644 --- a/.github/workflows/gh-aw-fragments/safe-output-push-to-pr.md +++ b/.github/workflows/gh-aw-fragments/safe-output-push-to-pr.md @@ -1,149 +1,4 @@ --- -safe-inputs: - ready-to-push-to-pr: - description: "Run the PR readiness checklist before pushing to a PR" - py: | - import os, json, subprocess - def find(*paths): - return next((p for p in paths if os.path.isfile(p)), None) - def run(cmd): - try: - return subprocess.run(cmd, capture_output=True, text=True, timeout=60) - except subprocess.TimeoutExpired: - return subprocess.CompletedProcess(cmd, 1, stdout='', stderr='diff timed out') - - # Guard: detect history rewrites (rebase/reset/cherry-pick) - pr_head_sha = '' - pr_json_path = '/tmp/pr-context/pr.json' - if os.path.isfile(pr_json_path): - with open(pr_json_path) as f: - pr_data = json.load(f) - pr_head_sha = pr_data.get('headRefOid', '') - if pr_head_sha: - # Check 1: PR head must be an ancestor of HEAD (no rebase/reset) - anc = run(['git', 'merge-base', '--is-ancestor', pr_head_sha, 'HEAD']) - if anc.returncode != 0: - print(json.dumps({'status': 'error', 'error': f'History rewrite detected: the original PR head ({pr_head_sha[:12]}) is not an ancestor of HEAD. This means git rebase, reset, or cherry-pick rewrote history. push_to_pull_request_branch will fail. Fix: run `git reset --hard {pr_head_sha}` to restore the PR branch to its original head, then re-apply your changes as direct file edits and commit as regular commits.'})) - raise SystemExit(0) - - contributing = find('CONTRIBUTING.md', 'CONTRIBUTING.rst', 'docs/CONTRIBUTING.md', 'docs/contributing.md') - pr_template = find('.github/pull_request_template.md', '.github/PULL_REQUEST_TEMPLATE.md', '.github/PULL_REQUEST_TEMPLATE/pull_request_template.md') - agents_md = find('AGENTS.md', 'agents.md', '.github/agents.md', '.github/AGENTS.md') - # Generate diff of local changes for self-review. - # Prefer anchoring to original PR head when available so base->PR merge - # commits do not flood the self-review with upstream-only changes. - diff_text = '' - diff_cmds = [] - if pr_head_sha: - diff_cmds.append(['git', 'diff', pr_head_sha]) - diff_cmds.extend([ - ['git', 'diff', '--merge-base', '@{upstream}'], - ['git', 'diff', '@{upstream}'], - ['git', 'diff', 'HEAD'], - ]) - for diff_cmd in diff_cmds: - result = run(diff_cmd) - if result.stdout.strip(): - diff_text = result.stdout.strip() - break - stat_text = '' - stat_cmds = [] - if pr_head_sha: - stat_cmds.append(['git', 'diff', '--stat', pr_head_sha]) - stat_cmds.extend([ - ['git', 'diff', '--stat', '--merge-base', '@{upstream}'], - ['git', 'diff', '--stat', '@{upstream}'], - ['git', 'diff', '--stat', 'HEAD'], - ]) - for stat_cmd in stat_cmds: - result = run(stat_cmd) - if result.stdout.strip(): - stat_text = result.stdout.strip() - break - # Capture commit messages so the sub-agent knows what changed and why - commits_text = '' - log_cmds = [] - if pr_head_sha: - log_cmds.append(['git', 'log', '--format=### %s%n%n%b', f'{pr_head_sha}..HEAD']) - log_cmds.extend([ - ['git', 'log', '--format=### %s%n%n%b', '@{upstream}..HEAD'], - ['git', 'log', '--format=### %s%n%n%b', '-10'], - ]) - for log_cmd in log_cmds: - result = run(log_cmd) - if result.stdout.strip(): - commits_text = result.stdout.strip() - break - os.makedirs('/tmp/self-review', exist_ok=True) - with open('/tmp/self-review/diff.patch', 'w') as f: - f.write(diff_text) - with open('/tmp/self-review/stat.txt', 'w') as f: - f.write(stat_text) - with open('/tmp/self-review/commits.txt', 'w') as f: - f.write(commits_text) - # Copy task context if available (PR metadata from the pr-context step) - has_task = False - if os.path.isfile('/tmp/pr-context/pr.json'): - import shutil - shutil.copy('/tmp/pr-context/pr.json', '/tmp/self-review/task.json') - has_task = True - # Write manifest so the sub-agent has structured context without - # relying on the main agent to manually pass it in the prompt - manifest_lines = [ - '# Self-Review Context', - '', - 'You are reviewing unpushed changes before they are submitted to a PR.', - '', - '## Available files', - '', - 'All files are in `/tmp/self-review/`:', - '', - f'- `diff.patch` : Full unified diff of all changes ({len(diff_text.splitlines())} lines)', - '- `stat.txt` : File-level change summary', - '- `commits.txt` : Commit messages describing what was changed and why', - '- `notes.md` : Author notes on what was done, why, and key decisions made', - ] - if has_task: - manifest_lines.append('- `task.json` : Original PR context (title, body, author, branches)') - step = 1 - manifest_lines += ['', '## How to review', ''] - manifest_lines.append(f'{step}. Read `notes.md` to understand what the author did, why, and what decisions they made.') - step += 1 - manifest_lines.append(f'{step}. Read `commits.txt` for the commit-level view of what changed.') - step += 1 - if has_task: - manifest_lines.append(f'{step}. Read `task.json` to understand the original task or issue being addressed.') - step += 1 - manifest_lines.append(f'{step}. Read `stat.txt` for a high-level view of which files changed.') - step += 1 - manifest_lines.append(f'{step}. Read `diff.patch` and the relevant source files from the workspace (the branch is checked out).') - step += 1 - if agents_md: - manifest_lines.append(f'{step}. Read `{agents_md}` in the workspace for repository coding conventions.') - manifest_lines += [ - '', - '## Focus areas', - '', - 'Look for bugs, logic errors, missed edge cases, and style issues.', - 'Focus on what the author might have MISSED rather than re-deriving their reasoning.', - 'Do not run tests, linters, or type checkers in this self-review step; the parent agent is responsible for validation and has already run the required checks.', - '', - '## What NOT to flag', - '', - '- Pre-existing issues not introduced by these changes', - '- Style preferences handled by linters or formatters', - '- Theoretical performance concerns without evidence of real-world impact', - ] - with open('/tmp/self-review/README.md', 'w') as f: - f.write('\n'.join(manifest_lines) + '\n') - diff_line_count = len(diff_text.splitlines()) - checklist = [] - if contributing: checklist.append(f'Review the contributing guide ({contributing}) before opening or updating a PR.') - if pr_template: checklist.append(f'Follow the PR template ({pr_template}) for title, description, and validation notes.') - checklist.append('Confirm the requested task is fully completed and validated before creating or pushing PR changes.') - if diff_line_count > 0: - checklist.append(f'A diff of your unpushed changes ({diff_line_count} lines) and supporting context have been saved to `/tmp/self-review/`. Before spawning the sub-agent, write `/tmp/self-review/notes.md` with: what you changed and why, which files matter most and what they do, edge cases you already handled, and what test coverage exists. Then spawn a `code-review` sub-agent via `runSubagent` and tell it to start by reading `/tmp/self-review/README.md`. If the sub-agent finds legitimate issues, fix them, commit, and call `ready_to_push_to_pr` again.') - print(json.dumps({'status': 'ok', 'checklist': checklist, 'contributing_guide': contributing, 'pr_template': pr_template, 'diff_line_count': diff_line_count})) safe-outputs: push-to-pull-request-branch: target: "triggering" @@ -162,7 +17,7 @@ Before calling `push_to_pull_request_branch`, call `ready_to_push_to_pr` and app Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: -1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. +1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. diff --git a/.github/workflows/gh-aw-framework-best-practices.lock.yml b/.github/workflows/gh-aw-framework-best-practices.lock.yml index 8f8521bf..de4acfb8 100644 --- a/.github/workflows/gh-aw-framework-best-practices.lock.yml +++ b/.github/workflows/gh-aw-framework-best-practices.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ecc9b0fd63f102e2aea18d06d10fcc227fe6ffe955fa08bc41870fa47a1db8e5","body_hash":"f6170c1fe3643796b2c09337f04c90098729bd6997329a45462be3de0bc3f37e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"d0748f9b57600ff131e9542eed82f02ec0026bed03d0d830b3bf4c3cc0025bde","body_hash":"202eb4b831c50a86618ef888f0f73b0936e5f0eac9544df8e683467c2ca1a391","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -328,20 +328,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_5eca7af573c65458_EOF' + cat << 'GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF' - GH_AW_PROMPT_5eca7af573c65458_EOF + GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_5eca7af573c65458_EOF' + cat << 'GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_5eca7af573c65458_EOF + GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_5eca7af573c65458_EOF' + cat << 'GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -370,9 +370,9 @@ jobs: {{/if}} - GH_AW_PROMPT_5eca7af573c65458_EOF + GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_5eca7af573c65458_EOF' + cat << 'GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF' ## MCP Servers @@ -443,9 +443,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -609,7 +609,7 @@ jobs: 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "__GH_AW_EXPR_BF503D80__"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For @@ -661,7 +661,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_5eca7af573c65458_EOF + GH_AW_PROMPT_c147fbbf0d2e3a4d_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -835,35 +835,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -882,7 +882,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1679,7 +1679,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-framework-best-practices.md b/.github/workflows/gh-aw-framework-best-practices.md index 00dcd195..8e7adf89 100644 --- a/.github/workflows/gh-aw-framework-best-practices.md +++ b/.github/workflows/gh-aw-framework-best-practices.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/code-quality-audit.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -125,7 +125,7 @@ Your task is to analyze the codebase, identify the frameworks and libraries in u 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "${{ inputs.title-prefix }}"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For diff --git a/.github/workflows/gh-aw-information-architecture.lock.yml b/.github/workflows/gh-aw-information-architecture.lock.yml index 71d5e58e..e4a39b65 100644 --- a/.github/workflows/gh-aw-information-architecture.lock.yml +++ b/.github/workflows/gh-aw-information-architecture.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"044f0e53757f14cb5ee3d624ea4b93a6aa2cd008413d92ae170a993c237b1f9a","body_hash":"2ad9fa54037b1648bcb08dff97f0ee5e960e1a1936a85bf277d1fbe104af822c","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4150fa6eabf4777225d214e754ec50a0cfd4ca76dc0f61e13233237c9e797123","body_hash":"626e553fabb5a695ff1bbc6105d3b0d1aa7f1a0857e3d8dd48c94eacbda47d6e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_70a7c997a87782bd_EOF' + cat << 'GH_AW_PROMPT_1d348add2f8cf516_EOF' - GH_AW_PROMPT_70a7c997a87782bd_EOF + GH_AW_PROMPT_1d348add2f8cf516_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_70a7c997a87782bd_EOF' + cat << 'GH_AW_PROMPT_1d348add2f8cf516_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_70a7c997a87782bd_EOF + GH_AW_PROMPT_1d348add2f8cf516_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_70a7c997a87782bd_EOF' + cat << 'GH_AW_PROMPT_1d348add2f8cf516_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_70a7c997a87782bd_EOF + GH_AW_PROMPT_1d348add2f8cf516_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_70a7c997a87782bd_EOF' + cat << 'GH_AW_PROMPT_1d348add2f8cf516_EOF' ## MCP Servers @@ -436,9 +436,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -548,7 +548,7 @@ jobs: 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "__GH_AW_EXPR_BF503D80__"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For @@ -601,7 +601,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_70a7c997a87782bd_EOF + GH_AW_PROMPT_1d348add2f8cf516_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -772,35 +772,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -819,7 +819,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1616,7 +1616,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-information-architecture.md b/.github/workflows/gh-aw-information-architecture.md index 63c00eb5..12ba427e 100644 --- a/.github/workflows/gh-aw-information-architecture.md +++ b/.github/workflows/gh-aw-information-architecture.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -115,7 +115,7 @@ Your task is to analyze the codebase and identify concrete information architect 4. **Check for duplicates** - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "${{ inputs.title-prefix }}"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. ### What to Look For diff --git a/.github/workflows/gh-aw-internal-gemini-cli-web-search.lock.yml b/.github/workflows/gh-aw-internal-gemini-cli-web-search.lock.yml index ce918f61..9763a12c 100644 --- a/.github/workflows/gh-aw-internal-gemini-cli-web-search.lock.yml +++ b/.github/workflows/gh-aw-internal-gemini-cli-web-search.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"490fae39346a006a9149d19390bf9f6f28eafd89d3eb6b92ac7cae569e234afb","body_hash":"b6e31f37a316f01780d47023ca7192a88069e0e927ae48e7b04c06e9d676683b","compiler_version":"v0.82.14","agent_id":"gemini","agent_model":"${{ inputs.model }}","engine_versions":{"gemini":"0.39.1"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GEMINI_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3cfb016286f65c2305d6d0af1a6452f0bc0ec58d5cfcfd8dbfeffb004350f109","body_hash":"b6e31f37a316f01780d47023ca7192a88069e0e927ae48e7b04c06e9d676683b","compiler_version":"v0.82.14","agent_id":"gemini","agent_model":"${{ inputs.model }}","engine_versions":{"gemini":"0.39.1"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GEMINI_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -712,35 +712,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1560,7 +1560,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-internal-gemini-cli-web-search.md b/.github/workflows/gh-aw-internal-gemini-cli-web-search.md index 010ed7ac..8d839bc1 100644 --- a/.github/workflows/gh-aw-internal-gemini-cli-web-search.md +++ b/.github/workflows/gh-aw-internal-gemini-cli-web-search.md @@ -13,11 +13,11 @@ imports: - gh-aw-fragments/safe-output-create-issue.md engine: id: gemini - model: ${{ inputs.model }} env: GEMINI_MAX_ATTEMPTS: "10" concurrency: group: "gh-aw-gemini-${{ github.workflow }}-internal-gemini-cli-web-search-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-internal-gemini-cli.lock.yml b/.github/workflows/gh-aw-internal-gemini-cli.lock.yml index 1a3c4a1e..93f10386 100644 --- a/.github/workflows/gh-aw-internal-gemini-cli.lock.yml +++ b/.github/workflows/gh-aw-internal-gemini-cli.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"81ac8c35c2a016719a2ade1ce1fea10312056865e15f3e043d9e1409f8508e45","body_hash":"1663f8690bb0a00c347c3b96bf7a3aa80c58c93d8f2e4bfb9ecb287639b80944","compiler_version":"v0.82.14","agent_id":"gemini","agent_model":"${{ inputs.model }}","engine_versions":{"gemini":"0.39.1"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GEMINI_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2dcef90c87dd9f565c9495a2fa538d1729f2bf60aab09a244b061cb975cdbc43","body_hash":"afccf0922a54738983f3956353963d398cb3bc3b798f7fd0595d1dbc52552f66","compiler_version":"v0.82.14","agent_id":"gemini","agent_model":"${{ inputs.model }}","engine_versions":{"gemini":"0.39.1"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GEMINI_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -71,7 +71,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Internal Gemini CLI" on: @@ -366,21 +365,21 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_4ee00587ead49c93_EOF' + cat << 'GH_AW_PROMPT_fdc02cbb6019f1f6_EOF' - GH_AW_PROMPT_4ee00587ead49c93_EOF + GH_AW_PROMPT_fdc02cbb6019f1f6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_4ee00587ead49c93_EOF' + cat << 'GH_AW_PROMPT_fdc02cbb6019f1f6_EOF' Tools: add_comment, create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_4ee00587ead49c93_EOF + GH_AW_PROMPT_fdc02cbb6019f1f6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_4ee00587ead49c93_EOF' + cat << 'GH_AW_PROMPT_fdc02cbb6019f1f6_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -409,9 +408,9 @@ jobs: {{/if}} - GH_AW_PROMPT_4ee00587ead49c93_EOF + GH_AW_PROMPT_fdc02cbb6019f1f6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_4ee00587ead49c93_EOF' + cat << 'GH_AW_PROMPT_fdc02cbb6019f1f6_EOF' ## MCP Servers @@ -473,9 +472,9 @@ jobs: A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -549,7 +548,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_4ee00587ead49c93_EOF + GH_AW_PROMPT_fdc02cbb6019f1f6_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -705,13 +704,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -723,31 +715,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -763,7 +761,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -801,6 +799,16 @@ jobs: run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless - name: Install Gemini CLI run: npm install --ignore-scripts -g @google/gemini-cli@0.39.1 + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -827,7 +835,7 @@ jobs: GH_AW_SKILL_DIR: ".gemini/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_TITLE_PREFIX: ${{ inputs.title-prefix }} @@ -1005,8 +1013,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1027,7 +1033,7 @@ jobs: export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network bridge -p 127.0.0.1:'"${MCP_GATEWAY_PORT}"':'"${MCP_GATEWAY_PORT}"' --name awmg-mcpg --add-host host.docker.internal:host-gateway --user '"${MCP_GATEWAY_UID}"':'"${MCP_GATEWAY_GID}"' --group-add '"${DOCKER_SOCK_GID}"' -v '"${DOCKER_SOCK_PATH}"':/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DOCKER_HOST=unix:///var/run/docker.sock -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e RUNNER_TEMP -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw -v '"${RUNNER_TEMP}"'/gh-aw/safeoutputs:'"${RUNNER_TEMP}"'/gh-aw/safeoutputs:rw ghcr.io/github/gh-aw-mcpg:v0.4.1' GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_1f218be10b3365f2_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_35d6b3def7e93f83_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1046,33 +1052,6 @@ jobs: } } }, - "playwright": { - "container": "mcr.microsoft.com/playwright/mcp", - "args": [ - "--init", - "--network", - "host", - "--security-opt", - "seccomp=unconfined", - "--ipc=host" - ], - "entrypointArgs": [ - "--output-dir", - "/tmp/gh-aw/mcp-logs/playwright", - "--no-sandbox", - "--snapshot-mode", - "none" - ], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1129,7 +1108,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_1f218be10b3365f2_EOF + GH_AW_MCP_CONFIG_35d6b3def7e93f83_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1598,7 +1577,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-internal-gemini-cli.md b/.github/workflows/gh-aw-internal-gemini-cli.md index 74733381..70bf5ef4 100644 --- a/.github/workflows/gh-aw-internal-gemini-cli.md +++ b/.github/workflows/gh-aw-internal-gemini-cli.md @@ -15,11 +15,11 @@ imports: - gh-aw-fragments/safe-output-create-issue.md engine: id: gemini - model: ${{ inputs.model }} env: GEMINI_MAX_ATTEMPTS: "10" concurrency: group: "gh-aw-gemini-${{ github.workflow }}-internal-gemini-cli-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-issue-fixer.lock.yml b/.github/workflows/gh-aw-issue-fixer.lock.yml index deabdd9b..9db6a830 100644 --- a/.github/workflows/gh-aw-issue-fixer.lock.yml +++ b/.github/workflows/gh-aw-issue-fixer.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"0695251997261f97e54f38886a0a5954de0f0128daee32069c17b112442b54f6","body_hash":"78bf330619972dd5729669480a34e81ff123442065931abfe5ba9f79eb9778ef","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8f331db0bd7d2d9c718200b9f60a81a3f227cda3a72306dd20695e4d89738447","body_hash":"78bf330619972dd5729669480a34e81ff123442065931abfe5ba9f79eb9778ef","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -716,35 +716,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1586,7 +1586,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-issue-fixer.md b/.github/workflows/gh-aw-issue-fixer.md index aa74436d..56343534 100644 --- a/.github/workflows/gh-aw-issue-fixer.md +++ b/.github/workflows/gh-aw-issue-fixer.md @@ -15,9 +15,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-issue-fixer-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-issue-triage.lock.yml b/.github/workflows/gh-aw-issue-triage.lock.yml index eb670641..d14b0937 100644 --- a/.github/workflows/gh-aw-issue-triage.lock.yml +++ b/.github/workflows/gh-aw-issue-triage.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"d5ae16a11611ebc065f6d78f7011d233f4067b5156b5d6c005bd9454e37eeb44","body_hash":"10d2d496f8e7e47348253a77f63060b9653d580d3763f86e89e8daf1e0d75175","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"80dc455c5edd6240c64450fc2e111ba1f7e2ccdd368a3a7e492d7e6398c8a146","body_hash":"951033dbc2ebacb1c0fec4cf4d72715ca2aef59199d2b02d42e1517085147d3d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -71,7 +71,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Issue Triage" on: @@ -340,21 +339,21 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_e6afe73896e193ea_EOF' + cat << 'GH_AW_PROMPT_7d94625da97c52ed_EOF' - GH_AW_PROMPT_e6afe73896e193ea_EOF + GH_AW_PROMPT_7d94625da97c52ed_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_e6afe73896e193ea_EOF' + cat << 'GH_AW_PROMPT_7d94625da97c52ed_EOF' Tools: add_comment, add_labels(max:3), missing_tool, missing_data, noop - GH_AW_PROMPT_e6afe73896e193ea_EOF + GH_AW_PROMPT_7d94625da97c52ed_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_e6afe73896e193ea_EOF' + cat << 'GH_AW_PROMPT_7d94625da97c52ed_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -383,9 +382,9 @@ jobs: {{/if}} - GH_AW_PROMPT_e6afe73896e193ea_EOF + GH_AW_PROMPT_7d94625da97c52ed_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_e6afe73896e193ea_EOF' + cat << 'GH_AW_PROMPT_7d94625da97c52ed_EOF' ## MCP Servers @@ -446,9 +445,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -590,7 +589,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_e6afe73896e193ea_EOF + GH_AW_PROMPT_7d94625da97c52ed_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -758,13 +757,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -776,31 +768,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -816,7 +814,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -851,6 +849,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -877,7 +885,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config run: | mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" @@ -1032,8 +1040,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1055,7 +1061,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1075,21 +1081,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1147,7 +1138,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1632,7 +1623,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-issue-triage.md b/.github/workflows/gh-aw-issue-triage.md index 125d8676..17ec1bb6 100644 --- a/.github/workflows/gh-aw-issue-triage.md +++ b/.github/workflows/gh-aw-issue-triage.md @@ -16,9 +16,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-issue-triage-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-mention-in-issue-by-id.lock.yml b/.github/workflows/gh-aw-mention-in-issue-by-id.lock.yml index 256635fe..9a8555b2 100644 --- a/.github/workflows/gh-aw-mention-in-issue-by-id.lock.yml +++ b/.github/workflows/gh-aw-mention-in-issue-by-id.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"333c54df02e37ea1282081c7624cc328032d060274baefe2a8b794cd95acd48f","body_hash":"b70d478ab2ec8c5a773c0553ab009c5feb7901893043d79d10341de06c3a78b8","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"21752b676975cfb66e15b146c0516d3cf71711fe152cf1f13bebfeccd5e7aa85","body_hash":"f6b49b034b6be75bddb36857d68b28a008b7a89eb7c228e5fc4140888b088b11","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,15 +56,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -73,7 +73,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Mention in Issue by ID" on: @@ -341,24 +340,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_b5e028b4ed15fd83_EOF' + cat << 'GH_AW_PROMPT_644a4c5d75840ca4_EOF' - GH_AW_PROMPT_b5e028b4ed15fd83_EOF + GH_AW_PROMPT_644a4c5d75840ca4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_b5e028b4ed15fd83_EOF' + cat << 'GH_AW_PROMPT_644a4c5d75840ca4_EOF' Tools: add_comment, create_issue, create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_b5e028b4ed15fd83_EOF + GH_AW_PROMPT_644a4c5d75840ca4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_b5e028b4ed15fd83_EOF' + cat << 'GH_AW_PROMPT_644a4c5d75840ca4_EOF' - GH_AW_PROMPT_b5e028b4ed15fd83_EOF + GH_AW_PROMPT_644a4c5d75840ca4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_b5e028b4ed15fd83_EOF' + cat << 'GH_AW_PROMPT_644a4c5d75840ca4_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -387,9 +386,9 @@ jobs: {{/if}} - GH_AW_PROMPT_b5e028b4ed15fd83_EOF + GH_AW_PROMPT_644a4c5d75840ca4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_b5e028b4ed15fd83_EOF' + cat << 'GH_AW_PROMPT_644a4c5d75840ca4_EOF' ## MCP Servers @@ -454,9 +453,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -517,7 +516,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_b5e028b4ed15fd83_EOF + GH_AW_PROMPT_644a4c5d75840ca4_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -679,13 +678,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -697,31 +689,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -737,7 +735,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -772,6 +770,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -798,7 +806,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_DRAFT_PRS: ${{ inputs.draft-prs }} @@ -1019,8 +1027,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1042,7 +1048,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1062,21 +1068,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1134,7 +1125,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1620,7 +1611,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-mention-in-issue-by-id.md b/.github/workflows/gh-aw-mention-in-issue-by-id.md index bd95f0b2..c0c64aeb 100644 --- a/.github/workflows/gh-aw-mention-in-issue-by-id.md +++ b/.github/workflows/gh-aw-mention-in-issue-by-id.md @@ -17,9 +17,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-mention-issue-by-id-${{ inputs.target-issue-number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-mention-in-issue-no-sandbox.lock.yml b/.github/workflows/gh-aw-mention-in-issue-no-sandbox.lock.yml index 9b3c9e26..67d34b1e 100644 --- a/.github/workflows/gh-aw-mention-in-issue-no-sandbox.lock.yml +++ b/.github/workflows/gh-aw-mention-in-issue-no-sandbox.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"b6bd640e5801556124428783b4a3a4732ffa9278b416e45e3ab52f7e7a697bbc","body_hash":"9ed6423131d3a7c2c73daaac542d01d9c53825a9cae2506559c06246a7ca18a8","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"53beeb164df07a3205a505dc6087de3910cd13d46f00ed88583b4d4e6c1ae7f5","body_hash":"c18f7221ebb801d854c1a6ba98987b399d0ba0fece1f3b6c96a330768a04ad7d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,19 +56,18 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Mention in Issue (no sandbox)" on: @@ -365,24 +364,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_ba3a6c2059eaab7e_EOF' + cat << 'GH_AW_PROMPT_e827c35ed47b0fa5_EOF' - GH_AW_PROMPT_ba3a6c2059eaab7e_EOF + GH_AW_PROMPT_e827c35ed47b0fa5_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_ba3a6c2059eaab7e_EOF' + cat << 'GH_AW_PROMPT_e827c35ed47b0fa5_EOF' Tools: add_comment, create_issue, create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_ba3a6c2059eaab7e_EOF + GH_AW_PROMPT_e827c35ed47b0fa5_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_ba3a6c2059eaab7e_EOF' + cat << 'GH_AW_PROMPT_e827c35ed47b0fa5_EOF' - GH_AW_PROMPT_ba3a6c2059eaab7e_EOF + GH_AW_PROMPT_e827c35ed47b0fa5_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_ba3a6c2059eaab7e_EOF' + cat << 'GH_AW_PROMPT_e827c35ed47b0fa5_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -411,9 +410,9 @@ jobs: {{/if}} - GH_AW_PROMPT_ba3a6c2059eaab7e_EOF + GH_AW_PROMPT_e827c35ed47b0fa5_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_ba3a6c2059eaab7e_EOF' + cat << 'GH_AW_PROMPT_e827c35ed47b0fa5_EOF' ## MCP Servers @@ -478,9 +477,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -561,7 +560,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_ba3a6c2059eaab7e_EOF + GH_AW_PROMPT_e827c35ed47b0fa5_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -725,13 +724,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -743,31 +735,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -783,7 +781,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -816,6 +814,16 @@ jobs: run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.71 env: GH_HOST: github.com + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -842,7 +850,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_DRAFT_PRS: ${{ inputs.draft-prs }} @@ -1062,8 +1070,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1085,7 +1091,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1105,21 +1111,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1177,7 +1168,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1587,7 +1578,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-mention-in-issue-no-sandbox.md b/.github/workflows/gh-aw-mention-in-issue-no-sandbox.md index daea5066..eddcfd4f 100644 --- a/.github/workflows/gh-aw-mention-in-issue-no-sandbox.md +++ b/.github/workflows/gh-aw-mention-in-issue-no-sandbox.md @@ -17,9 +17,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-mention-issue-no-sandbox-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-mention-in-issue.lock.yml b/.github/workflows/gh-aw-mention-in-issue.lock.yml index 874b0c35..46e54a8e 100644 --- a/.github/workflows/gh-aw-mention-in-issue.lock.yml +++ b/.github/workflows/gh-aw-mention-in-issue.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ed6ffe4944c8996780df6c22f0327341e483358eb7cb01d8f295795acb85ef46","body_hash":"ba834a1d518b853f970a4aea8fa86922f18ef834f2cb9c189fe098c77cc715b8","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6f51cbc889e69d6cab9424a0827151f5272dbaa72ab8d07e00801761687b211a","body_hash":"ddb0630bd080989f1ad54f25d756b265b03cb42bccff559c04715007f581fd9c","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,15 +56,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -73,7 +73,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Mention in Issue" on: @@ -370,24 +369,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_ce72da1ec016db58_EOF' + cat << 'GH_AW_PROMPT_7e94bfb5bf813045_EOF' - GH_AW_PROMPT_ce72da1ec016db58_EOF + GH_AW_PROMPT_7e94bfb5bf813045_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_ce72da1ec016db58_EOF' + cat << 'GH_AW_PROMPT_7e94bfb5bf813045_EOF' Tools: add_comment, create_issue, create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_ce72da1ec016db58_EOF + GH_AW_PROMPT_7e94bfb5bf813045_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_ce72da1ec016db58_EOF' + cat << 'GH_AW_PROMPT_7e94bfb5bf813045_EOF' - GH_AW_PROMPT_ce72da1ec016db58_EOF + GH_AW_PROMPT_7e94bfb5bf813045_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_ce72da1ec016db58_EOF' + cat << 'GH_AW_PROMPT_7e94bfb5bf813045_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -416,9 +415,9 @@ jobs: {{/if}} - GH_AW_PROMPT_ce72da1ec016db58_EOF + GH_AW_PROMPT_7e94bfb5bf813045_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_ce72da1ec016db58_EOF' + cat << 'GH_AW_PROMPT_7e94bfb5bf813045_EOF' ## MCP Servers @@ -483,9 +482,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## add-comment Limitations - **Body**: Max 65,536 characters (including any footer added by gh-aw). Keep well under this limit. @@ -568,7 +567,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_ce72da1ec016db58_EOF + GH_AW_PROMPT_7e94bfb5bf813045_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -733,13 +732,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -751,31 +743,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -791,7 +789,7 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -826,6 +824,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -852,7 +860,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_DRAFT_PRS: ${{ inputs.draft-prs }} @@ -1072,8 +1080,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1095,7 +1101,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1115,21 +1121,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1187,7 +1178,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1674,7 +1665,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-mention-in-issue.md b/.github/workflows/gh-aw-mention-in-issue.md index abcfdbaf..ef2af929 100644 --- a/.github/workflows/gh-aw-mention-in-issue.md +++ b/.github/workflows/gh-aw-mention-in-issue.md @@ -17,9 +17,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-mention-issue-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-mention-in-pr-no-sandbox.lock.yml b/.github/workflows/gh-aw-mention-in-pr-no-sandbox.lock.yml index 75cc2027..f703887f 100644 --- a/.github/workflows/gh-aw-mention-in-pr-no-sandbox.lock.yml +++ b/.github/workflows/gh-aw-mention-in-pr-no-sandbox.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"09e232ca160af2e9502e5c1e8204132ee3f852cef76e83a982a7152dcd43fb90","body_hash":"b52eddb4210ee7d2cc04671266721c92070115cde5789b068d0f034be846025d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ec4006aed2389a9e85aa19a6a183d961eeabdbf3b25871bf1dc9dc69a1a90e03","body_hash":"3dfbcdc5f9a6e9b8759cbde059a7163554e65bf20a674b1edb82b8d943b55afe","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -63,19 +63,18 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Mention in PR (no sandbox)" on: @@ -372,24 +371,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_123a7da282e9de5d_EOF' + cat << 'GH_AW_PROMPT_abc9d072193c71b7_EOF' - GH_AW_PROMPT_123a7da282e9de5d_EOF + GH_AW_PROMPT_abc9d072193c71b7_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_123a7da282e9de5d_EOF' + cat << 'GH_AW_PROMPT_abc9d072193c71b7_EOF' Tools: add_comment, create_pull_request_review_comment(max:30), submit_pull_request_review, reply_to_pull_request_review_comment(max:10), resolve_pull_request_review_thread(max:10), push_to_pull_request_branch, missing_tool, missing_data, noop - GH_AW_PROMPT_123a7da282e9de5d_EOF + GH_AW_PROMPT_abc9d072193c71b7_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_push_to_pr_branch.md" - cat << 'GH_AW_PROMPT_123a7da282e9de5d_EOF' + cat << 'GH_AW_PROMPT_abc9d072193c71b7_EOF' - GH_AW_PROMPT_123a7da282e9de5d_EOF + GH_AW_PROMPT_abc9d072193c71b7_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_123a7da282e9de5d_EOF' + cat << 'GH_AW_PROMPT_abc9d072193c71b7_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -418,9 +417,9 @@ jobs: {{/if}} - GH_AW_PROMPT_123a7da282e9de5d_EOF + GH_AW_PROMPT_abc9d072193c71b7_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_123a7da282e9de5d_EOF' + cat << 'GH_AW_PROMPT_abc9d072193c71b7_EOF' ## MCP Servers @@ -484,16 +483,16 @@ jobs: ## PR Context - PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. + PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. ## Code Review Reference Review criteria, severity levels, intensity, false positives, and calibration examples are in `/tmp/pr-context/review-instructions.md` (pre-written at startup). Inline comment format and the minimum severity threshold are in `/tmp/pr-context/parent-review.md` (written when `ready_to_code_review` is called). ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ### Pick Three, Keep Many Parallelize your work using sub-agents. Spawn multiple sub-agents, each approaching the task from a different angle — e.g., different focus areas, different heuristics, or different parts of the codebase. Each sub-agent works independently and should return its own list of findings. @@ -556,7 +555,7 @@ jobs: Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: - 1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. + 1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. @@ -580,7 +579,7 @@ jobs: - **Repository**: __GH_AW_GITHUB_REPOSITORY__ - **PR**: #__GH_AW_EXPR_AE61BB68__ — __GH_AW_EXPR_DF6A62B0__ - - **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. + - **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. - **Request**: "__GH_AW_STEPS_SANITIZED_OUTPUTS_TEXT__" ## Constraints @@ -594,11 +593,11 @@ jobs: ### Step 1: Gather Context - PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. + PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. - 1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). - 2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. - 3. Read `/tmp/pr-context/comments.json` and `/tmp/pr-context/review_comments.json` to understand the conversation context and what's being asked. + 1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). + 2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. + 3. Read `/tmp/gh-aw/agent/pr-context/comments.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to understand the conversation context and what's being asked. 4. Do not modify, review, comment on, or resolve threads for any PR other than #__GH_AW_EXPR_AE61BB68__. ### Step 2: Handle the Request @@ -607,8 +606,8 @@ jobs: **If asked to review the PR:** - Call `ready_to_code_review` to prepare the review approach based on PR size. - - Read `/tmp/pr-context/reviews.json` and `/tmp/pr-context/review_comments.json` to check prior reviews and existing threads — do not duplicate feedback. - - Read `/tmp/pr-context/agent-review.md` for the review approach and follow it. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/pr-context/subagent-*.md` instruction file). + - Read `/tmp/gh-aw/agent/pr-context/reviews.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to check prior reviews and existing threads — do not duplicate feedback. + - Read `/tmp/gh-aw/agent/pr-context/agent-review.md` for the review approach and follow it. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/gh-aw/agent/pr-context/subagent-*.md` instruction file). - When sub-agents return findings, merge and deduplicate per the Pick Three, Keep Many process. Then verify each surviving finding before leaving a comment: 1. **Read the file and surrounding context** — open the full file, not just the diff. 2. **Construct a concrete failure scenario** — what specific input or state causes the bug? If you cannot describe one, drop the finding. @@ -619,7 +618,7 @@ jobs: - **Bot-authored PRs**: If the PR author is `github-actions[bot]`, you can only submit a `COMMENT` review — `APPROVE` and `REQUEST_CHANGES` will fail because GitHub does not allow bot accounts to approve or request changes on their own PRs. Use `COMMENT` and state your verdict in the review body instead. **If asked to fix code or address review feedback:** - - Read `/tmp/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. + - Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. - For each unresolved thread you address: - Make the code changes in the workspace. - If the fix isn't obvious from the code change alone, call `reply_to_pull_request_review_comment` with the comment's numeric ID to briefly explain what you changed. @@ -628,7 +627,7 @@ jobs: - Use `ready_to_push_to_pr` to check if the changes are ready to push. - If `ready_to_push_to_pr` results in any additional edits (including merge-conflict resolutions), rerun the same required repo commands against the final state before pushing. If required commands cannot be run, explain why and do not push. - Use `push_to_pull_request_branch` to push your changes. - - After pushing, resolve every review thread that your changes address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. + - After pushing, resolve every review thread that your changes address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. - **Fork PRs**: Check via `pull_request_read` with method `get` whether the PR head repo differs from the base repo. If it's a fork, you cannot push — reply explaining that you do not have permission to push to fork branches and suggest that the PR author apply the changes themselves. This is a GitHub security limitation. You can still review code, make local changes, and provide suggestions. **If asked a question about the code:** @@ -651,7 +650,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_123a7da282e9de5d_EOF + GH_AW_PROMPT_abc9d072193c71b7_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -818,13 +817,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -836,31 +828,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -879,11 +877,11 @@ jobs: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }} name: Fetch PR context to disk - run: "set -euo pipefail\nmkdir -p /tmp/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/pr-context/threads\nfind /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/pr-context/\"\nls -la /tmp/pr-context/\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/gh-aw/agent/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/gh-aw/agent/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/gh-aw/agent/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/gh-aw/agent/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/gh-aw/agent/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/gh-aw/agent/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/gh-aw/agent/pr-context/threads\nfind /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/gh-aw/agent/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/gh-aw/agent/pr-context/\"\nls -la /tmp/gh-aw/agent/pr-context/\n" - name: Write review instructions to disk run: "mkdir -p /tmp/pr-context\ncat > /tmp/pr-context/review-instructions.md << 'REVIEW_EOF'\n# Review Instructions for Sub-agents\n\nYou are a code review sub-agent. Read these instructions, then review the PR files in the order provided in your prompt.\n\n## Context\n\nBefore reviewing files, read these to understand the PR:\n\n1. `/tmp/pr-context/pr.json` — PR title, description, author, and branches. Understand what the PR is trying to accomplish.\n2. `/tmp/agents.md` — Repository coding conventions and guidelines (skip if missing).\n3. `/tmp/pr-context/review_comments.json` — Existing review threads. Note which files already have threads so you don't duplicate.\n4. `/tmp/pr-context/issue-*.json` — Linked issue details (if any). Understand the motivation and acceptance criteria.\n\n## Process\n\nReview the PR diff file by file in your assigned order. For each changed file:\n\n1. **Read the diff** for this file from `/tmp/pr-context/diffs/.diff` to understand what changed. Each line is prefixed with its line number (e.g., `405\\t+ code`). Lines with numbers are commentable; lines without numbers are deleted lines (LEFT side only). If the diff is empty or truncated (e.g., binary files or very large changes), fall back to reading the full file from the workspace and comparing against context.\n2. **Read the full file from the workspace.** The PR branch is checked out locally — open the file directly to get complete contents with line numbers.\n3. **Check existing threads** for this file from `/tmp/pr-context/threads/.json` (if it exists). Skip issues that are already under discussion — each thread has `isResolved` and `isOutdated` fields.\n4. **Identify potential issues** matching the review criteria below.\n5. **Quick-check each issue** before including it:\n - What specific code pattern or change triggers this concern?\n - Is there an obvious guard, handler, or mitigation visible in the immediate context?\n - Can you describe a concrete failure scenario (the `evidence` field)? If you cannot articulate what specific input or state triggers the problem, drop the finding.\n - If the issue is clearly handled, skip it. If you're unsure, include it — the parent will verify.\n6. **Add to your findings list.** Do NOT leave inline comments — you don't have that tool. Return findings in this format:\n\n```\n- file: path/to/file\n line: 42\n severity: HIGH\n title: Brief title\n description: What the issue is and why it matters\n evidence: The specific code pattern and failure scenario\n suggestion: corrected code here (optional — only if you can provide a concrete fix)\n```\n\n**Review every file in your assigned order.** Files reviewed earlier get more attention, which is why different sub-agents use different orderings.\n\n**Check existing threads** — per-file threads are at `/tmp/pr-context/threads/.json` (step 3 above). The full list is at `/tmp/pr-context/review_comments.json`. Do not flag issues that are already under discussion (resolved or unresolved). For outdated threads, only re-flag if the issue still applies to the current diff.\n\n**Return your full findings list** when done, or an empty list if no issues were found.\n\n## Review Criteria\n\nFocus on these categories in priority order:\n\n1. Security vulnerabilities (injection, XSS, auth bypass, secrets exposure)\n2. Logic bugs that could cause runtime failures or incorrect behavior\n3. Data integrity issues (race conditions, missing transactions, corruption risk)\n4. Performance bottlenecks (N+1 queries, memory leaks, blocking operations)\n5. Error handling gaps (unhandled exceptions, missing validation)\n6. Breaking changes to public APIs without migration path\n7. Missing or incorrect test coverage for critical paths\n\n## What NOT to Flag\n\nOnly review the diff — do not flag issues in unchanged code, pre-existing problems not introduced by this PR, or style preferences handled by linters or formatters.\n\n**Common false positives** — these patterns look like issues but usually aren't. Before flagging anything in these categories, confirm the problem is real by reading the surrounding code:\n\n- **Security — input already sanitized:** Don't flag injection or XSS risks when inputs are sanitized upstream, parameterized queries are used, or the framework auto-escapes output.\n- **Null/undefined — guarded elsewhere:** Don't flag potential null dereferences if the value is guaranteed by a type guard, assertion, schema validation, or upstream null check.\n- **Error handling — handled at a different layer:** Don't flag missing try/catch if the caller, middleware, or framework catches and handles the error (e.g., Express error middleware, React error boundaries).\n- **Performance — theoretical, not practical:** Don't flag algorithmic complexity (e.g., O(n^2)) unless N is demonstrably large enough to matter in the actual usage context. \"This could be slow\" without evidence is not actionable.\n- **Validation — exists at another layer:** Don't flag missing input validation if it's handled by an API gateway, middleware, schema validator, or type system.\n- **Test coverage — trivial or generated code:** Don't flag missing tests for trivial getters/setters, auto-generated code, or simple delegation methods.\n- **Style or naming — not in coding guidelines:** Don't flag naming conventions or code style unless they violate the repository's documented coding guidelines (from `/tmp/agents.md` or CONTRIBUTING docs).\n\n**Existing review threads** — check BEFORE flagging any issue:\n\n- **Resolved with reviewer reply** (e.g. \"This is intentional\") — reviewer's decision is final. Do NOT re-flag.\n- **Resolved without reply** — author likely fixed it. Do NOT re-raise unless the fix introduced a new problem.\n- **Unresolved** — already flagged. Do NOT duplicate.\n- **Outdated** — only re-flag if the issue still applies to the current diff.\n\nWhen in doubt, do not duplicate. Redundant comments erode trust.\n\nFinding no issues is a valid and valuable outcome. An empty findings list is better than findings that waste the author's time or erode trust. Do not manufacture findings to justify your review — if the code is sound, return an empty list.\n\n## Severity Classification\n\nDetermine severity AFTER investigating the issue, not before. First identify the problem and trace through the code, then assign a severity based on the evidence you found.\n\n- 🔴 CRITICAL — Must fix before merge (security vulnerabilities, data corruption, production-breaking bugs)\n- 🟠 HIGH — Should fix before merge (logic errors, missing validation, significant performance issues)\n- 🟡 MEDIUM — Address soon, non-blocking (error handling gaps, suboptimal patterns, missing edge cases)\n- ⚪ LOW — Author discretion (minor improvements, documentation gaps)\n- 💬 NITPICK — Truly optional (stylistic preferences, alternative approaches)\n\n## Review Intensity\n\nThe review intensity is `${{ inputs.intensity || 'balanced' }}`.\n\n- **conservative**: High evidence bar. Only flag when you can demonstrate a concrete failure scenario. If you can construct a reasonable counterargument, do not flag. Approval with zero findings is the expected outcome for most PRs.\n- **balanced**: Standard evidence bar. Flag when you can point to specific code that would fail. If the issue is ambiguous, lean toward not flagging.\n- **aggressive**: Lower evidence bar. Flag when evidence exists even if the failure scenario is not fully confirmed. Improvement suggestions welcome but must cite specific code.\n\n## Calibration Examples\n\nUse these examples to calibrate your judgment. Each pair shows a real issue and a similar-looking pattern that is NOT an issue.\n\n### Example 1: Null/Undefined Access\n\n**True positive — flag this:**\n\n```js\n// PR adds this handler\napp.get('/user/:id', async (req, res) => {\n const user = await db.findUser(req.params.id);\n res.json({ name: user.name, email: user.email });\n});\n```\n\nWhy flag: `db.findUser()` can return `null` when no user matches the ID. Accessing `user.name` will throw a TypeError at runtime. No upstream guard exists — the route handler is the entry point.\n\n**False positive — do NOT flag this:**\n\n```ts\n// PR adds this line inside an existing function\nconst settings = user.getSettings();\n```\n\nWhy skip: Reading the full file reveals `user` is typed as `User` (not `User | null`), and the calling function only runs after `authenticateUser()` middleware which guarantees a valid user object. The null case is handled at a different layer.\n\n### Example 2: SQL Injection\n\n**True positive — flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE customer_id = '{customer_id}'\")\n```\n\nWhy flag: String interpolation in a SQL query with user-controlled input (`customer_id` comes from the request). No parameterization or sanitization anywhere in the call chain.\n\n**False positive — do NOT flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE status = '{OrderStatus.PENDING.value}'\")\n```\n\nWhy skip: The interpolated value is a hardcoded enum constant (`OrderStatus.PENDING`), not user input. There is no injection vector.\n\n### Example 3: Borderline — Do NOT Flag\n\n```go\n// PR adds this function\nfunc processItems(items []Item) []Result {\n results := make([]Result, 0)\n for _, item := range items {\n for _, tag := range item.Tags {\n results = append(results, process(item, tag))\n }\n }\n return results\n}\n```\n\nThis looks like an O(n*m) performance concern. But without evidence that `items` or `Tags` are large in practice, this is speculative. The function processes a bounded dataset (items from a single user request). Do not flag theoretical performance issues without evidence of real-world impact.\nREVIEW_EOF\n" - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GITHUB_TOKEN: ${{ github.token }} REPO_NAME: ${{ github.repository }} @@ -922,6 +920,16 @@ jobs: run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.71 env: GH_HOST: github.com + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -948,7 +956,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config run: | mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" @@ -1202,8 +1210,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1225,7 +1231,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1245,21 +1251,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1317,7 +1308,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1725,7 +1716,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-mention-in-pr-no-sandbox.md b/.github/workflows/gh-aw-mention-in-pr-no-sandbox.md index 11c422d6..d4550d04 100644 --- a/.github/workflows/gh-aw-mention-in-pr-no-sandbox.md +++ b/.github/workflows/gh-aw-mention-in-pr-no-sandbox.md @@ -24,9 +24,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-mention-pr-no-sandbox-${{ github.event.pull_request.number || github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -129,7 +129,7 @@ Assist with pull requests on ${{ github.repository }} — review code, fix issue - **Repository**: ${{ github.repository }} - **PR**: #${{ github.event.pull_request.number || github.event.issue.number }} — ${{ github.event.pull_request.title || github.event.issue.title }} -- **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. +- **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. - **Request**: "${{ steps.sanitized.outputs.text }}" ## Constraints @@ -143,11 +143,11 @@ Understand the request, investigate the code, and respond appropriately. ### Step 1: Gather Context -PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. +PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. -1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). -2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. -3. Read `/tmp/pr-context/comments.json` and `/tmp/pr-context/review_comments.json` to understand the conversation context and what's being asked. +1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). +2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. +3. Read `/tmp/gh-aw/agent/pr-context/comments.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to understand the conversation context and what's being asked. 4. Do not modify, review, comment on, or resolve threads for any PR other than #${{ github.event.pull_request.number || github.event.issue.number }}. ### Step 2: Handle the Request @@ -156,8 +156,8 @@ Based on what's asked, do the appropriate thing: **If asked to review the PR:** - Call `ready_to_code_review` to prepare the review approach based on PR size. -- Read `/tmp/pr-context/reviews.json` and `/tmp/pr-context/review_comments.json` to check prior reviews and existing threads — do not duplicate feedback. -- Read `/tmp/pr-context/agent-review.md` for the review approach and follow it. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/pr-context/subagent-*.md` instruction file). +- Read `/tmp/gh-aw/agent/pr-context/reviews.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to check prior reviews and existing threads — do not duplicate feedback. +- Read `/tmp/gh-aw/agent/pr-context/agent-review.md` for the review approach and follow it. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/gh-aw/agent/pr-context/subagent-*.md` instruction file). - When sub-agents return findings, merge and deduplicate per the Pick Three, Keep Many process. Then verify each surviving finding before leaving a comment: 1. **Read the file and surrounding context** — open the full file, not just the diff. 2. **Construct a concrete failure scenario** — what specific input or state causes the bug? If you cannot describe one, drop the finding. @@ -168,7 +168,7 @@ Based on what's asked, do the appropriate thing: - **Bot-authored PRs**: If the PR author is `github-actions[bot]`, you can only submit a `COMMENT` review — `APPROVE` and `REQUEST_CHANGES` will fail because GitHub does not allow bot accounts to approve or request changes on their own PRs. Use `COMMENT` and state your verdict in the review body instead. **If asked to fix code or address review feedback:** -- Read `/tmp/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. +- Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. - For each unresolved thread you address: - Make the code changes in the workspace. - If the fix isn't obvious from the code change alone, call `reply_to_pull_request_review_comment` with the comment's numeric ID to briefly explain what you changed. @@ -177,7 +177,7 @@ Based on what's asked, do the appropriate thing: - Use `ready_to_push_to_pr` to check if the changes are ready to push. - If `ready_to_push_to_pr` results in any additional edits (including merge-conflict resolutions), rerun the same required repo commands against the final state before pushing. If required commands cannot be run, explain why and do not push. - Use `push_to_pull_request_branch` to push your changes. -- After pushing, resolve every review thread that your changes address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. +- After pushing, resolve every review thread that your changes address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. - **Fork PRs**: Check via `pull_request_read` with method `get` whether the PR head repo differs from the base repo. If it's a fork, you cannot push — reply explaining that you do not have permission to push to fork branches and suggest that the PR author apply the changes themselves. This is a GitHub security limitation. You can still review code, make local changes, and provide suggestions. **If asked a question about the code:** diff --git a/.github/workflows/gh-aw-mention-in-pr.lock.yml b/.github/workflows/gh-aw-mention-in-pr.lock.yml index 38940803..efd7c0b9 100644 --- a/.github/workflows/gh-aw-mention-in-pr.lock.yml +++ b/.github/workflows/gh-aw-mention-in-pr.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"392b5ec0745730fa3f08f62926791412b073370a8d017dbc7240aa91f1fb0ca9","body_hash":"68d5ba7e0ae4b7da62997cf976face7070d03574d02a38873d3e35becba653f6","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8219487c4cc8123ab5dee4ab4f66a97b257763ea04ce48f65aa4e4324f7589e6","body_hash":"baa5e0f6d828c43f62368544302ec45f5469d6fc03d5ea328750417dab767372","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -63,15 +63,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -80,7 +80,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Mention in PR" on: @@ -383,24 +382,24 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_12d951a2013a28a1_EOF' + cat << 'GH_AW_PROMPT_30ec120227c2b3da_EOF' - GH_AW_PROMPT_12d951a2013a28a1_EOF + GH_AW_PROMPT_30ec120227c2b3da_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_12d951a2013a28a1_EOF' + cat << 'GH_AW_PROMPT_30ec120227c2b3da_EOF' Tools: add_comment, create_pull_request_review_comment(max:30), submit_pull_request_review, reply_to_pull_request_review_comment(max:10), resolve_pull_request_review_thread(max:10), push_to_pull_request_branch, missing_tool, missing_data, noop - GH_AW_PROMPT_12d951a2013a28a1_EOF + GH_AW_PROMPT_30ec120227c2b3da_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_push_to_pr_branch.md" - cat << 'GH_AW_PROMPT_12d951a2013a28a1_EOF' + cat << 'GH_AW_PROMPT_30ec120227c2b3da_EOF' - GH_AW_PROMPT_12d951a2013a28a1_EOF + GH_AW_PROMPT_30ec120227c2b3da_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_12d951a2013a28a1_EOF' + cat << 'GH_AW_PROMPT_30ec120227c2b3da_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -429,9 +428,9 @@ jobs: {{/if}} - GH_AW_PROMPT_12d951a2013a28a1_EOF + GH_AW_PROMPT_30ec120227c2b3da_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_12d951a2013a28a1_EOF' + cat << 'GH_AW_PROMPT_30ec120227c2b3da_EOF' ## MCP Servers @@ -495,16 +494,16 @@ jobs: ## PR Context - PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. + PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. ## Code Review Reference Review criteria, severity levels, intensity, false positives, and calibration examples are in `/tmp/pr-context/review-instructions.md` (pre-written at startup). Inline comment format and the minimum severity threshold are in `/tmp/pr-context/parent-review.md` (written when `ready_to_code_review` is called). ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ### Pick Three, Keep Many Parallelize your work using sub-agents. Spawn multiple sub-agents, each approaching the task from a different angle — e.g., different focus areas, different heuristics, or different parts of the codebase. Each sub-agent works independently and should return its own list of findings. @@ -567,7 +566,7 @@ jobs: Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: - 1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. + 1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. @@ -591,7 +590,7 @@ jobs: - **Repository**: __GH_AW_GITHUB_REPOSITORY__ - **PR**: #__GH_AW_EXPR_AE61BB68__ — __GH_AW_EXPR_DF6A62B0__ - - **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. + - **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. - **Request**: "__GH_AW_STEPS_SANITIZED_OUTPUTS_TEXT__" - **Explicit prompt**: "__GH_AW_INPUTS_PROMPT__" @@ -606,12 +605,12 @@ jobs: ### Step 1: Gather Context - PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. + PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. - 1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). - 2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. - 3. Read `/tmp/pr-context/comments.json` and `/tmp/pr-context/review_comments.json` to understand the conversation context and what's being asked. - 4. Read `/tmp/pr-context/reviews.json` to check prior review submissions — note any prior verdicts to avoid redundant reviews. + 1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). + 2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. + 3. Read `/tmp/gh-aw/agent/pr-context/comments.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to understand the conversation context and what's being asked. + 4. Read `/tmp/gh-aw/agent/pr-context/reviews.json` to check prior review submissions — note any prior verdicts to avoid redundant reviews. 5. Do not modify, review, comment on, or resolve threads for any PR other than #__GH_AW_EXPR_AE61BB68__. ### Step 2: Handle the Request @@ -624,8 +623,8 @@ jobs: **If asked to review the PR:** - - Call `ready_to_code_review` — this writes `/tmp/pr-context/agent-review.md` (review approach) and `/tmp/pr-context/parent-review.md` (comment format and inline severity threshold). Read both files. - - Review the PR following `agent-review.md`. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/pr-context/subagent-*.md` instruction file). + - Call `ready_to_code_review` — this writes `/tmp/gh-aw/agent/pr-context/agent-review.md` (review approach) and `/tmp/gh-aw/agent/pr-context/parent-review.md` (comment format and inline severity threshold). Read both files. + - Review the PR following `agent-review.md`. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/gh-aw/agent/pr-context/subagent-*.md` instruction file). - When sub-agents return findings, merge and deduplicate per the Pick Three, Keep Many process. Then verify each surviving finding before leaving a comment: 1. **Read the file and surrounding context** — open the full file, not just the diff. 2. **Construct a concrete failure scenario** — what specific input or state causes the bug? If you cannot describe one, drop the finding. @@ -637,7 +636,7 @@ jobs: **If asked to fix code or address review feedback:** - - Read `/tmp/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. + - Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. - For each unresolved thread you address: - Make the code changes in the workspace. - If the fix isn't obvious from the code change alone, call `reply_to_pull_request_review_comment` with the comment's numeric ID to briefly explain what you changed. @@ -646,7 +645,7 @@ jobs: - Call `ready_to_push_to_pr` to confirm the branch is safe to push. - If `ready_to_push_to_pr` results in any additional edits (including merge-conflict resolutions), rerun the same required repo commands against the final state before pushing. If required commands cannot be run, explain why and do not push. - Use `push_to_pull_request_branch` to push your changes. - - After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. + - After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. - **Important completion step**: when feedback is completed and no further reviewer action is needed, resolving the corresponding thread is required. Do not leave fully addressed threads open. - If `resolve_pull_request_review_thread` fails for any thread you fully addressed, call `add_comment` summarizing the specific thread IDs that could not be resolved and why. - **Fork PRs**: Check via `pull_request_read` with method `get` whether the PR head repo differs from the base repo. If it's a fork, you cannot push — reply explaining that you do not have permission to push to fork branches and suggest that the PR author apply the changes themselves. This is a GitHub security limitation. You can still review code, make local changes, and provide suggestions. @@ -654,7 +653,7 @@ jobs: **If asked to fix merge conflicts:** - Check via `pull_request_read` (method `get`) whether this is a fork PR. If so, reply that you cannot push to fork branches and suggest the author resolve locally. - - Read `/tmp/pr-context/pr.json` for the head and base branch names. + - Read `/tmp/gh-aw/agent/pr-context/pr.json` for the head and base branch names. - Follow the merge-conflict/update-branch guidance in `ready_to_push_to_pr` and resolve conflicts with a merge-based flow. Do **not** use `git rebase` or other history-rewrite flows. - If conflicts are too complex to resolve confidently (large structural changes, binary files, ambiguous intent), reply explaining what you found and suggest the author resolve locally. - If the request includes additional work (code fixes, review feedback), complete all of it before pushing — `push_to_pull_request_branch` can only be called once. Resolve merge conflicts first, then make other requested changes on top, then push everything together. @@ -684,7 +683,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_12d951a2013a28a1_EOF + GH_AW_PROMPT_30ec120227c2b3da_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -855,13 +854,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -873,31 +865,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -916,11 +914,11 @@ jobs: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }} name: Fetch PR context to disk - run: "set -euo pipefail\nmkdir -p /tmp/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/pr-context/threads\nfind /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/pr-context/\"\nls -la /tmp/pr-context/\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/gh-aw/agent/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/gh-aw/agent/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/gh-aw/agent/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/gh-aw/agent/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/gh-aw/agent/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/gh-aw/agent/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/gh-aw/agent/pr-context/threads\nfind /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/gh-aw/agent/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/gh-aw/agent/pr-context/\"\nls -la /tmp/gh-aw/agent/pr-context/\n" - name: Write review instructions to disk run: "mkdir -p /tmp/pr-context\ncat > /tmp/pr-context/review-instructions.md << 'REVIEW_EOF'\n# Review Instructions for Sub-agents\n\nYou are a code review sub-agent. Read these instructions, then review the PR files in the order provided in your prompt.\n\n## Context\n\nBefore reviewing files, read these to understand the PR:\n\n1. `/tmp/pr-context/pr.json` — PR title, description, author, and branches. Understand what the PR is trying to accomplish.\n2. `/tmp/agents.md` — Repository coding conventions and guidelines (skip if missing).\n3. `/tmp/pr-context/review_comments.json` — Existing review threads. Note which files already have threads so you don't duplicate.\n4. `/tmp/pr-context/issue-*.json` — Linked issue details (if any). Understand the motivation and acceptance criteria.\n\n## Process\n\nReview the PR diff file by file in your assigned order. For each changed file:\n\n1. **Read the diff** for this file from `/tmp/pr-context/diffs/.diff` to understand what changed. Each line is prefixed with its line number (e.g., `405\\t+ code`). Lines with numbers are commentable; lines without numbers are deleted lines (LEFT side only). If the diff is empty or truncated (e.g., binary files or very large changes), fall back to reading the full file from the workspace and comparing against context.\n2. **Read the full file from the workspace.** The PR branch is checked out locally — open the file directly to get complete contents with line numbers.\n3. **Check existing threads** for this file from `/tmp/pr-context/threads/.json` (if it exists). Skip issues that are already under discussion — each thread has `isResolved` and `isOutdated` fields.\n4. **Identify potential issues** matching the review criteria below.\n5. **Quick-check each issue** before including it:\n - What specific code pattern or change triggers this concern?\n - Is there an obvious guard, handler, or mitigation visible in the immediate context?\n - Can you describe a concrete failure scenario (the `evidence` field)? If you cannot articulate what specific input or state triggers the problem, drop the finding.\n - If the issue is clearly handled, skip it. If you're unsure, include it — the parent will verify.\n6. **Add to your findings list.** Do NOT leave inline comments — you don't have that tool. Return findings in this format:\n\n```\n- file: path/to/file\n line: 42\n severity: HIGH\n title: Brief title\n description: What the issue is and why it matters\n evidence: The specific code pattern and failure scenario\n suggestion: corrected code here (optional — only if you can provide a concrete fix)\n```\n\n**Review every file in your assigned order.** Files reviewed earlier get more attention, which is why different sub-agents use different orderings.\n\n**Check existing threads** — per-file threads are at `/tmp/pr-context/threads/.json` (step 3 above). The full list is at `/tmp/pr-context/review_comments.json`. Do not flag issues that are already under discussion (resolved or unresolved). For outdated threads, only re-flag if the issue still applies to the current diff.\n\n**Return your full findings list** when done, or an empty list if no issues were found.\n\n## Review Criteria\n\nFocus on these categories in priority order:\n\n1. Security vulnerabilities (injection, XSS, auth bypass, secrets exposure)\n2. Logic bugs that could cause runtime failures or incorrect behavior\n3. Data integrity issues (race conditions, missing transactions, corruption risk)\n4. Performance bottlenecks (N+1 queries, memory leaks, blocking operations)\n5. Error handling gaps (unhandled exceptions, missing validation)\n6. Breaking changes to public APIs without migration path\n7. Missing or incorrect test coverage for critical paths\n\n## What NOT to Flag\n\nOnly review the diff — do not flag issues in unchanged code, pre-existing problems not introduced by this PR, or style preferences handled by linters or formatters.\n\n**Common false positives** — these patterns look like issues but usually aren't. Before flagging anything in these categories, confirm the problem is real by reading the surrounding code:\n\n- **Security — input already sanitized:** Don't flag injection or XSS risks when inputs are sanitized upstream, parameterized queries are used, or the framework auto-escapes output.\n- **Null/undefined — guarded elsewhere:** Don't flag potential null dereferences if the value is guaranteed by a type guard, assertion, schema validation, or upstream null check.\n- **Error handling — handled at a different layer:** Don't flag missing try/catch if the caller, middleware, or framework catches and handles the error (e.g., Express error middleware, React error boundaries).\n- **Performance — theoretical, not practical:** Don't flag algorithmic complexity (e.g., O(n^2)) unless N is demonstrably large enough to matter in the actual usage context. \"This could be slow\" without evidence is not actionable.\n- **Validation — exists at another layer:** Don't flag missing input validation if it's handled by an API gateway, middleware, schema validator, or type system.\n- **Test coverage — trivial or generated code:** Don't flag missing tests for trivial getters/setters, auto-generated code, or simple delegation methods.\n- **Style or naming — not in coding guidelines:** Don't flag naming conventions or code style unless they violate the repository's documented coding guidelines (from `/tmp/agents.md` or CONTRIBUTING docs).\n\n**Existing review threads** — check BEFORE flagging any issue:\n\n- **Resolved with reviewer reply** (e.g. \"This is intentional\") — reviewer's decision is final. Do NOT re-flag.\n- **Resolved without reply** — author likely fixed it. Do NOT re-raise unless the fix introduced a new problem.\n- **Unresolved** — already flagged. Do NOT duplicate.\n- **Outdated** — only re-flag if the issue still applies to the current diff.\n\nWhen in doubt, do not duplicate. Redundant comments erode trust.\n\nFinding no issues is a valid and valuable outcome. An empty findings list is better than findings that waste the author's time or erode trust. Do not manufacture findings to justify your review — if the code is sound, return an empty list.\n\n## Severity Classification\n\nDetermine severity AFTER investigating the issue, not before. First identify the problem and trace through the code, then assign a severity based on the evidence you found.\n\n- 🔴 CRITICAL — Must fix before merge (security vulnerabilities, data corruption, production-breaking bugs)\n- 🟠 HIGH — Should fix before merge (logic errors, missing validation, significant performance issues)\n- 🟡 MEDIUM — Address soon, non-blocking (error handling gaps, suboptimal patterns, missing edge cases)\n- ⚪ LOW — Author discretion (minor improvements, documentation gaps)\n- 💬 NITPICK — Truly optional (stylistic preferences, alternative approaches)\n\n## Review Intensity\n\nThe review intensity is `${{ inputs.intensity || 'balanced' }}`.\n\n- **conservative**: High evidence bar. Only flag when you can demonstrate a concrete failure scenario. If you can construct a reasonable counterargument, do not flag. Approval with zero findings is the expected outcome for most PRs.\n- **balanced**: Standard evidence bar. Flag when you can point to specific code that would fail. If the issue is ambiguous, lean toward not flagging.\n- **aggressive**: Lower evidence bar. Flag when evidence exists even if the failure scenario is not fully confirmed. Improvement suggestions welcome but must cite specific code.\n\n## Calibration Examples\n\nUse these examples to calibrate your judgment. Each pair shows a real issue and a similar-looking pattern that is NOT an issue.\n\n### Example 1: Null/Undefined Access\n\n**True positive — flag this:**\n\n```js\n// PR adds this handler\napp.get('/user/:id', async (req, res) => {\n const user = await db.findUser(req.params.id);\n res.json({ name: user.name, email: user.email });\n});\n```\n\nWhy flag: `db.findUser()` can return `null` when no user matches the ID. Accessing `user.name` will throw a TypeError at runtime. No upstream guard exists — the route handler is the entry point.\n\n**False positive — do NOT flag this:**\n\n```ts\n// PR adds this line inside an existing function\nconst settings = user.getSettings();\n```\n\nWhy skip: Reading the full file reveals `user` is typed as `User` (not `User | null`), and the calling function only runs after `authenticateUser()` middleware which guarantees a valid user object. The null case is handled at a different layer.\n\n### Example 2: SQL Injection\n\n**True positive — flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE customer_id = '{customer_id}'\")\n```\n\nWhy flag: String interpolation in a SQL query with user-controlled input (`customer_id` comes from the request). No parameterization or sanitization anywhere in the call chain.\n\n**False positive — do NOT flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE status = '{OrderStatus.PENDING.value}'\")\n```\n\nWhy skip: The interpolated value is a hardcoded enum constant (`OrderStatus.PENDING`), not user input. There is no injection vector.\n\n### Example 3: Borderline — Do NOT Flag\n\n```go\n// PR adds this function\nfunc processItems(items []Item) []Result {\n results := make([]Result, 0)\n for _, item := range items {\n for _, tag := range item.Tags {\n results = append(results, process(item, tag))\n }\n }\n return results\n}\n```\n\nThis looks like an O(n*m) performance concern. But without evidence that `items` or `Tags` are large in practice, this is speculative. The function processes a bounded dataset (items from a single user request). Do not flag theoretical performance issues without evidence of real-world impact.\nREVIEW_EOF\n" - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GITHUB_TOKEN: ${{ github.token }} REPO_NAME: ${{ github.repository }} @@ -961,6 +959,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -987,7 +995,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config run: | mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" @@ -1241,8 +1249,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -1264,7 +1270,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_e512af0534038d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1284,21 +1290,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1356,7 +1347,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_94928899e4e2daf0_EOF + GH_AW_MCP_CONFIG_e512af0534038d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1841,7 +1832,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-mention-in-pr.md b/.github/workflows/gh-aw-mention-in-pr.md index ccb0b7bd..0cf8f780 100644 --- a/.github/workflows/gh-aw-mention-in-pr.md +++ b/.github/workflows/gh-aw-mention-in-pr.md @@ -24,9 +24,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-mention-pr-${{ github.event.pull_request.number || github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -129,7 +129,7 @@ Assist with pull requests on ${{ github.repository }} — review code, fix issue - **Repository**: ${{ github.repository }} - **PR**: #${{ github.event.pull_request.number || github.event.issue.number }} — ${{ github.event.pull_request.title || github.event.issue.title }} -- **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. +- **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. - **Request**: "${{ steps.sanitized.outputs.text }}" - **Explicit prompt**: "${{ inputs.prompt }}" @@ -144,12 +144,12 @@ Understand the request, investigate the code, and respond appropriately. ### Step 1: Gather Context -PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. +PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. -1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). -2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. -3. Read `/tmp/pr-context/comments.json` and `/tmp/pr-context/review_comments.json` to understand the conversation context and what's being asked. -4. Read `/tmp/pr-context/reviews.json` to check prior review submissions — note any prior verdicts to avoid redundant reviews. +1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). +2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. +3. Read `/tmp/gh-aw/agent/pr-context/comments.json` and `/tmp/gh-aw/agent/pr-context/review_comments.json` to understand the conversation context and what's being asked. +4. Read `/tmp/gh-aw/agent/pr-context/reviews.json` to check prior review submissions — note any prior verdicts to avoid redundant reviews. 5. Do not modify, review, comment on, or resolve threads for any PR other than #${{ github.event.pull_request.number || github.event.issue.number }}. ### Step 2: Handle the Request @@ -162,8 +162,8 @@ Based on what's asked, do the appropriate thing. **If asked to review the PR:** -- Call `ready_to_code_review` — this writes `/tmp/pr-context/agent-review.md` (review approach) and `/tmp/pr-context/parent-review.md` (comment format and inline severity threshold). Read both files. -- Review the PR following `agent-review.md`. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/pr-context/subagent-*.md` instruction file). +- Call `ready_to_code_review` — this writes `/tmp/gh-aw/agent/pr-context/agent-review.md` (review approach) and `/tmp/gh-aw/agent/pr-context/parent-review.md` (comment format and inline severity threshold). Read both files. +- Review the PR following `agent-review.md`. For small PRs, review directly. For medium/large PRs, spawn the specified number of `code-review` sub-agents in parallel (each reads its `/tmp/gh-aw/agent/pr-context/subagent-*.md` instruction file). - When sub-agents return findings, merge and deduplicate per the Pick Three, Keep Many process. Then verify each surviving finding before leaving a comment: 1. **Read the file and surrounding context** — open the full file, not just the diff. 2. **Construct a concrete failure scenario** — what specific input or state causes the bug? If you cannot describe one, drop the finding. @@ -175,7 +175,7 @@ Based on what's asked, do the appropriate thing. **If asked to fix code or address review feedback:** -- Read `/tmp/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. +- Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to see open review threads and understand what needs to be addressed. - For each unresolved thread you address: - Make the code changes in the workspace. - If the fix isn't obvious from the code change alone, call `reply_to_pull_request_review_comment` with the comment's numeric ID to briefly explain what you changed. @@ -184,7 +184,7 @@ Based on what's asked, do the appropriate thing. - Call `ready_to_push_to_pr` to confirm the branch is safe to push. - If `ready_to_push_to_pr` results in any additional edits (including merge-conflict resolutions), rerun the same required repo commands against the final state before pushing. If required commands cannot be run, explain why and do not push. - Use `push_to_pull_request_branch` to push your changes. -- After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. +- After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads left by other reviewers AND threads from your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. - **Important completion step**: when feedback is completed and no further reviewer action is needed, resolving the corresponding thread is required. Do not leave fully addressed threads open. - If `resolve_pull_request_review_thread` fails for any thread you fully addressed, call `add_comment` summarizing the specific thread IDs that could not be resolved and why. - **Fork PRs**: Check via `pull_request_read` with method `get` whether the PR head repo differs from the base repo. If it's a fork, you cannot push — reply explaining that you do not have permission to push to fork branches and suggest that the PR author apply the changes themselves. This is a GitHub security limitation. You can still review code, make local changes, and provide suggestions. @@ -192,7 +192,7 @@ Based on what's asked, do the appropriate thing. **If asked to fix merge conflicts:** - Check via `pull_request_read` (method `get`) whether this is a fork PR. If so, reply that you cannot push to fork branches and suggest the author resolve locally. -- Read `/tmp/pr-context/pr.json` for the head and base branch names. +- Read `/tmp/gh-aw/agent/pr-context/pr.json` for the head and base branch names. - Follow the merge-conflict/update-branch guidance in `ready_to_push_to_pr` and resolve conflicts with a merge-based flow. Do **not** use `git rebase` or other history-rewrite flows. - If conflicts are too complex to resolve confidently (large structural changes, binary files, ambiguous intent), reply explaining what you found and suggest the author resolve locally. - If the request includes additional work (code fixes, review feedback), complete all of it before pushing — `push_to_pull_request_branch` can only be called once. Resolve merge conflicts first, then make other requested changes on top, then push everything together. diff --git a/.github/workflows/gh-aw-newbie-contributor-patrol.lock.yml b/.github/workflows/gh-aw-newbie-contributor-patrol.lock.yml index 16887bbf..7fd4c2c3 100644 --- a/.github/workflows/gh-aw-newbie-contributor-patrol.lock.yml +++ b/.github/workflows/gh-aw-newbie-contributor-patrol.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"b1d1bab9cb86254bada1d1051d1ece8c704a4352d98821210e2bd29102eada00","body_hash":"5f460a351208cdacdf43e584e9c8d3a33ebc8516f66e8ba2e05392df7f859328","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"9f674eba3fa2c66a7c2685feab6b3fb81df101c1a377f6505c5c2ddeb22ec4c7","body_hash":"10f2a27982897b4841d104a998ec2422375f1c5b74d502be2682dc44790a3b6a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -318,20 +318,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_defa65187c7aae88_EOF' + cat << 'GH_AW_PROMPT_1207f0f9d2603728_EOF' - GH_AW_PROMPT_defa65187c7aae88_EOF + GH_AW_PROMPT_1207f0f9d2603728_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_defa65187c7aae88_EOF' + cat << 'GH_AW_PROMPT_1207f0f9d2603728_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_defa65187c7aae88_EOF + GH_AW_PROMPT_1207f0f9d2603728_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_defa65187c7aae88_EOF' + cat << 'GH_AW_PROMPT_1207f0f9d2603728_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -360,9 +360,9 @@ jobs: {{/if}} - GH_AW_PROMPT_defa65187c7aae88_EOF + GH_AW_PROMPT_1207f0f9d2603728_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_defa65187c7aae88_EOF' + cat << 'GH_AW_PROMPT_1207f0f9d2603728_EOF' ## MCP Servers @@ -433,9 +433,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -548,7 +548,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_defa65187c7aae88_EOF + GH_AW_PROMPT_1207f0f9d2603728_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -713,35 +713,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -760,7 +760,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1557,7 +1557,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-newbie-contributor-patrol.md b/.github/workflows/gh-aw-newbie-contributor-patrol.md index 791ed79f..321d3a66 100644 --- a/.github/workflows/gh-aw-newbie-contributor-patrol.md +++ b/.github/workflows/gh-aw-newbie-contributor-patrol.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-performance-profiler.lock.yml b/.github/workflows/gh-aw-performance-profiler.lock.yml index bfe39d28..cedc4e77 100644 --- a/.github/workflows/gh-aw-performance-profiler.lock.yml +++ b/.github/workflows/gh-aw-performance-profiler.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f19117cd3bc492ecd82d79735196aa65ab2f55b2affc8f188bd9d1372ee146ba","body_hash":"d197de3c01f371b9e11ecf29e877eb9213a89b9e96ae707d3ef0dcd51ace4927","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"1493602bc117eaaf5c78cad365ac83e98af33a94bc460d92beef65d58d568a4a","body_hash":"03be2f980cfaeff8cad5aaa0a1a0acc3951954b616e755ddba96dcbafb1a134e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -322,20 +322,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_26b8e068640560f9_EOF' + cat << 'GH_AW_PROMPT_ded87f0d7d64a119_EOF' - GH_AW_PROMPT_26b8e068640560f9_EOF + GH_AW_PROMPT_ded87f0d7d64a119_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_26b8e068640560f9_EOF' + cat << 'GH_AW_PROMPT_ded87f0d7d64a119_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_26b8e068640560f9_EOF + GH_AW_PROMPT_ded87f0d7d64a119_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_26b8e068640560f9_EOF' + cat << 'GH_AW_PROMPT_ded87f0d7d64a119_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -364,9 +364,9 @@ jobs: {{/if}} - GH_AW_PROMPT_26b8e068640560f9_EOF + GH_AW_PROMPT_ded87f0d7d64a119_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_26b8e068640560f9_EOF' + cat << 'GH_AW_PROMPT_ded87f0d7d64a119_EOF' ## MCP Servers @@ -438,9 +438,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -646,7 +646,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_26b8e068640560f9_EOF + GH_AW_PROMPT_ded87f0d7d64a119_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -817,35 +817,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -870,7 +870,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1667,7 +1667,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-performance-profiler.md b/.github/workflows/gh-aw-performance-profiler.md index 90e2c4bd..38a31fc5 100644 --- a/.github/workflows/gh-aw-performance-profiler.md +++ b/.github/workflows/gh-aw-performance-profiler.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-plan.lock.yml b/.github/workflows/gh-aw-plan.lock.yml index 132a805a..5dda4261 100644 --- a/.github/workflows/gh-aw-plan.lock.yml +++ b/.github/workflows/gh-aw-plan.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"47e0fd21c079d912de60766235202d948641670b63a01e08a7acd33bcf0e4cf2","body_hash":"7e6f033717163fec02811ebcb6069d5026b05174de00bd7113ba0838d59a5261","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"18aa1d097d60083cff2d8b41703b4956e25a21b9ffdd14d63b60703f18b75bae","body_hash":"7e6f033717163fec02811ebcb6069d5026b05174de00bd7113ba0838d59a5261","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -708,35 +708,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1570,7 +1570,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-plan.md b/.github/workflows/gh-aw-plan.md index 48ad34cd..526f91d8 100644 --- a/.github/workflows/gh-aw-plan.md +++ b/.github/workflows/gh-aw-plan.md @@ -14,9 +14,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-plan-${{ github.event.issue.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-pr-actions-detective.lock.yml b/.github/workflows/gh-aw-pr-actions-detective.lock.yml index a6b630d1..d42f93f2 100644 --- a/.github/workflows/gh-aw-pr-actions-detective.lock.yml +++ b/.github/workflows/gh-aw-pr-actions-detective.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"70ff0822e873537d501a297c50df7cc58334d7ecae1efa0d25269a3b1c9bc41e","body_hash":"d1df9031e0f9d77bdcd205845223edc4003d1898260462f6c6e74585ae129a95","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"01b6a338ea80d697230b2f313f647d958512cc4bcfdd7971bc42150c9efb5215","body_hash":"d1df9031e0f9d77bdcd205845223edc4003d1898260462f6c6e74585ae129a95","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -51,15 +51,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -689,35 +689,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1511,7 +1511,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-pr-actions-detective.md b/.github/workflows/gh-aw-pr-actions-detective.md index 3f3f9fd0..988a07c8 100644 --- a/.github/workflows/gh-aw-pr-actions-detective.md +++ b/.github/workflows/gh-aw-pr-actions-detective.md @@ -12,7 +12,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-pr-actions-fixer.lock.yml b/.github/workflows/gh-aw-pr-actions-fixer.lock.yml index 1dd0c25d..145bbe2a 100644 --- a/.github/workflows/gh-aw-pr-actions-fixer.lock.yml +++ b/.github/workflows/gh-aw-pr-actions-fixer.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"841319ecdba8bc5ba813da454034040694d5bd14beaa750bfa3cc8cd78f19c7c","body_hash":"60b704cd5fa160df90b14351e518bb957ff5b25f738849bdf6b2d178d5081d36","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"1c11864e74d013f3be7d30fd0055386d692e66cc5402294c068d3ba9661e3003","body_hash":"1956bf0eb482d12cfabf22d574b545eea8a155f7c143d6a127b1dfc98296014a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -327,23 +327,23 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_6fdf0b9100c0019f_EOF' + cat << 'GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF' - GH_AW_PROMPT_6fdf0b9100c0019f_EOF + GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_6fdf0b9100c0019f_EOF' + cat << 'GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF' Tools: add_comment, push_to_pull_request_branch, missing_tool, missing_data, noop - GH_AW_PROMPT_6fdf0b9100c0019f_EOF + GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_push_to_pr_branch.md" - cat << 'GH_AW_PROMPT_6fdf0b9100c0019f_EOF' + cat << 'GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF' - GH_AW_PROMPT_6fdf0b9100c0019f_EOF + GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_6fdf0b9100c0019f_EOF' + cat << 'GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -372,9 +372,9 @@ jobs: {{/if}} - GH_AW_PROMPT_6fdf0b9100c0019f_EOF + GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_6fdf0b9100c0019f_EOF' + cat << 'GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF' ## MCP Servers @@ -456,7 +456,7 @@ jobs: Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: - 1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. + 1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. @@ -521,7 +521,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_6fdf0b9100c0019f_EOF + GH_AW_PROMPT_e0d7e0aaa2520c1e_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -694,35 +694,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1537,7 +1537,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-pr-actions-fixer.md b/.github/workflows/gh-aw-pr-actions-fixer.md index b3751183..445e4991 100644 --- a/.github/workflows/gh-aw-pr-actions-fixer.md +++ b/.github/workflows/gh-aw-pr-actions-fixer.md @@ -13,7 +13,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-pr-conflict-addresser.lock.yml b/.github/workflows/gh-aw-pr-conflict-addresser.lock.yml index 33332497..a399011e 100644 --- a/.github/workflows/gh-aw-pr-conflict-addresser.lock.yml +++ b/.github/workflows/gh-aw-pr-conflict-addresser.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"669a4fcc7b5eac3cee43220b981783550edd5478aaca079c59ae4e1c3007ff36","body_hash":"a705eb31d3c55bf1888ac3ee96cdf37b8155cc379c646250ed1e5d70cb22eba2","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"75bbdae41945c9f3c7bd9ea83d69660f924bf7d3f7958c3ebb54ee6eaae9a6a4","body_hash":"6b0ba05235964e5a07ae225cf512f6388e2517ecee39687f9cf9da96b75c9408","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -329,23 +329,23 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_7bc360aad47ad750_EOF' + cat << 'GH_AW_PROMPT_b7e19aa42e9900bd_EOF' - GH_AW_PROMPT_7bc360aad47ad750_EOF + GH_AW_PROMPT_b7e19aa42e9900bd_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_7bc360aad47ad750_EOF' + cat << 'GH_AW_PROMPT_b7e19aa42e9900bd_EOF' Tools: add_comment, push_to_pull_request_branch, missing_tool, missing_data, noop - GH_AW_PROMPT_7bc360aad47ad750_EOF + GH_AW_PROMPT_b7e19aa42e9900bd_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_push_to_pr_branch.md" - cat << 'GH_AW_PROMPT_7bc360aad47ad750_EOF' + cat << 'GH_AW_PROMPT_b7e19aa42e9900bd_EOF' - GH_AW_PROMPT_7bc360aad47ad750_EOF + GH_AW_PROMPT_b7e19aa42e9900bd_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_7bc360aad47ad750_EOF' + cat << 'GH_AW_PROMPT_b7e19aa42e9900bd_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -374,9 +374,9 @@ jobs: {{/if}} - GH_AW_PROMPT_7bc360aad47ad750_EOF + GH_AW_PROMPT_b7e19aa42e9900bd_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_7bc360aad47ad750_EOF' + cat << 'GH_AW_PROMPT_b7e19aa42e9900bd_EOF' ## MCP Servers @@ -440,7 +440,7 @@ jobs: ## PR Context - PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. + PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. @@ -455,7 +455,7 @@ jobs: Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: - 1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. + 1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. @@ -468,11 +468,11 @@ jobs: - **Repository**: __GH_AW_GITHUB_REPOSITORY__ - **PR**: #__GH_AW_EXPR_91DD53F2__ - - **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. + - **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. ## Instructions - 1. Read `/tmp/pr-context/pr.json` for PR details including `baseRefName` (the target branch). + 1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details including `baseRefName` (the target branch). 2. Merge the base branch into the PR branch: `git merge origin/`. 3. If there are merge conflicts, resolve them by examining the conflicting files and making sensible choices that preserve the intent of both sides. 4. After resolving all conflicts, run any relevant build/lint/test commands to verify the resolution doesn't break anything. @@ -486,7 +486,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_7bc360aad47ad750_EOF + GH_AW_PROMPT_b7e19aa42e9900bd_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -658,35 +658,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -705,7 +705,7 @@ jobs: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }} name: Fetch PR context to disk - run: "set -euo pipefail\nmkdir -p /tmp/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/pr-context/threads\nfind /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/pr-context/\"\nls -la /tmp/pr-context/\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/gh-aw/agent/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/gh-aw/agent/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/gh-aw/agent/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/gh-aw/agent/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/gh-aw/agent/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/gh-aw/agent/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/gh-aw/agent/pr-context/threads\nfind /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/gh-aw/agent/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/gh-aw/agent/pr-context/\"\nls -la /tmp/gh-aw/agent/pr-context/\n" - env: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ inputs.target-pr-number }} @@ -1521,7 +1521,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-pr-conflict-addresser.md b/.github/workflows/gh-aw-pr-conflict-addresser.md index 7404ae14..eef40b94 100644 --- a/.github/workflows/gh-aw-pr-conflict-addresser.md +++ b/.github/workflows/gh-aw-pr-conflict-addresser.md @@ -15,9 +15,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-pr-conflict-addresser-${{ inputs.target-pr-number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -119,11 +119,11 @@ Resolve merge conflicts on pull request #${{ inputs.target-pr-number }} in ${{ g - **Repository**: ${{ github.repository }} - **PR**: #${{ inputs.target-pr-number }} -- **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. +- **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Use these as your primary source; fall back to API tools only when required data is unavailable. ## Instructions -1. Read `/tmp/pr-context/pr.json` for PR details including `baseRefName` (the target branch). +1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details including `baseRefName` (the target branch). 2. Merge the base branch into the PR branch: `git merge origin/`. 3. If there are merge conflicts, resolve them by examining the conflicting files and making sensible choices that preserve the intent of both sides. 4. After resolving all conflicts, run any relevant build/lint/test commands to verify the resolution doesn't break anything. diff --git a/.github/workflows/gh-aw-pr-labeler.lock.yml b/.github/workflows/gh-aw-pr-labeler.lock.yml index dbfc5285..7e2af124 100644 --- a/.github/workflows/gh-aw-pr-labeler.lock.yml +++ b/.github/workflows/gh-aw-pr-labeler.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"06b28627510f4294b4be9fc649dc0df0bae9d6509af862ba172dfb7812f2736f","body_hash":"5ff401feb453d620168489c2319659b0608dad7baed1931ca19857e568daf72b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/github-script","sha":"f28e40c7f34bde8b3046d885e986cb6290c5673b","version":"v7"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"50a348fe351a2949e7ff0132a31b164f39e4512392b6e38e44f7fc17495ec412","body_hash":"5ff401feb453d620168489c2319659b0608dad7baed1931ca19857e568daf72b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -49,16 +49,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -609,35 +608,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1443,7 +1442,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" @@ -1815,7 +1814,7 @@ jobs: GH_HOST="${GH_HOST#http://}" echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV" - name: Pre-sanitize label operations from input allowlist - uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7 + uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 env: ALLOWED_LABELS: ${{ inputs.classification-labels }} with: diff --git a/.github/workflows/gh-aw-pr-labeler.md b/.github/workflows/gh-aw-pr-labeler.md index 83cffa86..d90971f1 100644 --- a/.github/workflows/gh-aw-pr-labeler.md +++ b/.github/workflows/gh-aw-pr-labeler.md @@ -11,9 +11,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-pr-labeler-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -69,7 +69,7 @@ safe-outputs: target: "${{ github.event.pull_request.number }}" steps: - name: Pre-sanitize label operations from input allowlist - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: ALLOWED_LABELS: ${{ inputs.classification-labels }} with: diff --git a/.github/workflows/gh-aw-pr-review-addresser.lock.yml b/.github/workflows/gh-aw-pr-review-addresser.lock.yml index ab61cb70..619a0d81 100644 --- a/.github/workflows/gh-aw-pr-review-addresser.lock.yml +++ b/.github/workflows/gh-aw-pr-review-addresser.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8b14dd25d9767f079906500d825b5e1d273d78812b207efae04bf254c2a63fe6","body_hash":"63433380d8366801437f8cb18177f12955082dd18aaa6f18803aeb78f452505d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8f370a0d8eebc2a02c78bc58b4e9b4b46075eb51fca40bf064d5c1f6ffb51b8b","body_hash":"62cfedd92a8c5502e62624489189f814a339d4034ef77b78f606941ef3dd48ab","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,15 +56,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -334,23 +334,23 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_5cbca98f72e67222_EOF' + cat << 'GH_AW_PROMPT_f51c8e10bda77521_EOF' - GH_AW_PROMPT_5cbca98f72e67222_EOF + GH_AW_PROMPT_f51c8e10bda77521_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_5cbca98f72e67222_EOF' + cat << 'GH_AW_PROMPT_f51c8e10bda77521_EOF' Tools: add_comment, reply_to_pull_request_review_comment(max:10), resolve_pull_request_review_thread(max:10), push_to_pull_request_branch, missing_tool, missing_data, noop - GH_AW_PROMPT_5cbca98f72e67222_EOF + GH_AW_PROMPT_f51c8e10bda77521_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_push_to_pr_branch.md" - cat << 'GH_AW_PROMPT_5cbca98f72e67222_EOF' + cat << 'GH_AW_PROMPT_f51c8e10bda77521_EOF' - GH_AW_PROMPT_5cbca98f72e67222_EOF + GH_AW_PROMPT_f51c8e10bda77521_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_5cbca98f72e67222_EOF' + cat << 'GH_AW_PROMPT_f51c8e10bda77521_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -379,9 +379,9 @@ jobs: {{/if}} - GH_AW_PROMPT_5cbca98f72e67222_EOF + GH_AW_PROMPT_f51c8e10bda77521_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_5cbca98f72e67222_EOF' + cat << 'GH_AW_PROMPT_f51c8e10bda77521_EOF' ## MCP Servers @@ -441,7 +441,7 @@ jobs: ## PR Context - PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. + PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. @@ -466,7 +466,7 @@ jobs: Trying to resolve merge conflicts? Use merge-based conflict resolution. Rebase remains disallowed: - 1. Compare with the base branch (from `/tmp/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. + 1. Compare with the base branch (from `/tmp/gh-aw/agent/pr-context/pr.json` field `baseRefName`) and update your local base branch refs as needed. 2. Run a merge from base into the PR branch, resolve conflicts, and commit the merge result. 3. Do **not** use `git rebase` (or other history-rewrite flows like `reset --hard` + cherry-pick). 4. Call `ready_to_push_to_pr` (which catches rewritten history) and then `push_to_pull_request_branch` to push. @@ -503,12 +503,12 @@ jobs: ### Step 1: Gather Context - PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. + PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. - 1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). Check whether this is a fork PR — if the head repo differs from the base repo, you cannot push changes. - 2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. - 3. Read `/tmp/pr-context/unresolved_threads.json` to get unresolved review threads that need attention. For full context including resolved threads, see `review_comments.json`. - 4. Read `/tmp/pr-context/diffs/` to understand the current state of changes. + 1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). Check whether this is a fork PR — if the head repo differs from the base repo, you cannot push changes. + 2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. + 3. Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to get unresolved review threads that need attention. For full context including resolved threads, see `review_comments.json`. + 4. Read `/tmp/gh-aw/agent/pr-context/diffs/` to understand the current state of changes. ### Step 2: Address Each Review Thread @@ -531,7 +531,7 @@ jobs: Skip this step for fork PRs where you could not push. - After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads from any reviewer — external reviewers, bots, and your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. Fall back to `pull_request_read` with method `get_review_comments` if the pre-fetched data is unavailable. + After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads from any reviewer — external reviewers, bots, and your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. Fall back to `pull_request_read` with method `get_review_comments` if the pre-fetched data is unavailable. **Important completion requirement**: when feedback is completed and no further reviewer action is needed, resolving the corresponding thread is required. Do not leave fully addressed threads open. @@ -553,7 +553,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_5cbca98f72e67222_EOF + GH_AW_PROMPT_f51c8e10bda77521_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -731,35 +731,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -778,7 +778,7 @@ jobs: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }} name: Fetch PR context to disk - run: "set -euo pipefail\nmkdir -p /tmp/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/pr-context/threads\nfind /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/pr-context/\"\nls -la /tmp/pr-context/\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/gh-aw/agent/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/gh-aw/agent/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/gh-aw/agent/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/gh-aw/agent/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/gh-aw/agent/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/gh-aw/agent/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/gh-aw/agent/pr-context/threads\nfind /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/gh-aw/agent/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/gh-aw/agent/pr-context/\"\nls -la /tmp/gh-aw/agent/pr-context/\n" - env: GITHUB_TOKEN: ${{ github.token }} REPO_NAME: ${{ github.repository }} @@ -1618,7 +1618,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-pr-review-addresser.md b/.github/workflows/gh-aw-pr-review-addresser.md index 982cdfc2..09c82b2e 100644 --- a/.github/workflows/gh-aw-pr-review-addresser.md +++ b/.github/workflows/gh-aw-pr-review-addresser.md @@ -17,9 +17,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-pr-review-addresser-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -123,12 +123,12 @@ Address the review feedback surgically — make only the minimum changes needed. ### Step 1: Gather Context -PR context is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. +PR context is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. -1. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). Check whether this is a fork PR — if the head repo differs from the base repo, you cannot push changes. -2. Read `/tmp/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. -3. Read `/tmp/pr-context/unresolved_threads.json` to get unresolved review threads that need attention. For full context including resolved threads, see `review_comments.json`. -4. Read `/tmp/pr-context/diffs/` to understand the current state of changes. +1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). Check whether this is a fork PR — if the head repo differs from the base repo, you cannot push changes. +2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` if any exist to understand linked issue motivation and requirements. +3. Read `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` to get unresolved review threads that need attention. For full context including resolved threads, see `review_comments.json`. +4. Read `/tmp/gh-aw/agent/pr-context/diffs/` to understand the current state of changes. ### Step 2: Address Each Review Thread @@ -151,7 +151,7 @@ For each unresolved review thread: Skip this step for fork PRs where you could not push. -After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads from any reviewer — external reviewers, bots, and your own prior reviews. Check `/tmp/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. Fall back to `pull_request_read` with method `get_review_comments` if the pre-fetched data is unavailable. +After pushing, resolve every review thread that your changes fully address by calling `resolve_pull_request_review_thread` with the thread's GraphQL node ID (the `id` field, e.g., `PRRT_kwDO...`). This includes threads from any reviewer — external reviewers, bots, and your own prior reviews. Check `/tmp/gh-aw/agent/pr-context/unresolved_threads.json` for all unresolved threads — also check `/tmp/gh-aw/agent/pr-context/outdated_threads.json` for threads where the underlying code changed since the comment was made and verify whether your changes address them. Do NOT resolve threads you disagreed with, skipped, or only partially addressed — leave those open for the reviewer. Fall back to `pull_request_read` with method `get_review_comments` if the pre-fetched data is unavailable. **Important completion requirement**: when feedback is completed and no further reviewer action is needed, resolving the corresponding thread is required. Do not leave fully addressed threads open. diff --git a/.github/workflows/gh-aw-pr-review.lock.yml b/.github/workflows/gh-aw-pr-review.lock.yml index 203695f3..0192e929 100644 --- a/.github/workflows/gh-aw-pr-review.lock.yml +++ b/.github/workflows/gh-aw-pr-review.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f0e6318c00ed59efca2c6bbc1c6c8531495e58554fca6c6c9a4e0dfe3c61edf9","body_hash":"f03d4ebb04aab1d1b87479103c5325704b553cd783e5dcdfaf27bf41b557c8c8","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f0a4de99b512b25071663b9f4408920ab225c7aea9707edfce13b7ffb4eb9c08","body_hash":"516441b69a719bc802fa9d700f492d75478a26085cb6be18044925f50a9fbdcb","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -56,15 +56,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -329,20 +329,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_58f1e24032a9ec12_EOF' + cat << 'GH_AW_PROMPT_bc7d158162ea8aef_EOF' - GH_AW_PROMPT_58f1e24032a9ec12_EOF + GH_AW_PROMPT_bc7d158162ea8aef_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_58f1e24032a9ec12_EOF' + cat << 'GH_AW_PROMPT_bc7d158162ea8aef_EOF' Tools: create_pull_request_review_comment(max:30), submit_pull_request_review, missing_tool, missing_data, noop - GH_AW_PROMPT_58f1e24032a9ec12_EOF + GH_AW_PROMPT_bc7d158162ea8aef_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_58f1e24032a9ec12_EOF' + cat << 'GH_AW_PROMPT_bc7d158162ea8aef_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -371,9 +371,9 @@ jobs: {{/if}} - GH_AW_PROMPT_58f1e24032a9ec12_EOF + GH_AW_PROMPT_bc7d158162ea8aef_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_58f1e24032a9ec12_EOF' + cat << 'GH_AW_PROMPT_bc7d158162ea8aef_EOF' ## MCP Servers @@ -433,7 +433,7 @@ jobs: ## PR Context - PR data is pre-fetched to `/tmp/pr-context/`. Read `/tmp/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. + PR data is pre-fetched to `/tmp/gh-aw/agent/pr-context/`. Read `/tmp/gh-aw/agent/pr-context/README.md` for a manifest of all available files. Use these as your primary source for PR metadata, diffs, reviews, comments, and linked issues; fall back to API tools only when required data is unavailable. **Never mention these file paths or on-disk data sources in your responses** — they are internal implementation details invisible to users. ## Code Review Reference Review criteria, severity levels, intensity, false positives, and calibration examples are in `/tmp/pr-context/review-instructions.md` (pre-written at startup). Inline comment format and the minimum severity threshold are in `/tmp/pr-context/parent-review.md` (written when `ready_to_code_review` is called). @@ -489,7 +489,7 @@ jobs: - **Repository**: __GH_AW_GITHUB_REPOSITORY__ - **PR**: #__GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER__ — __GH_AW_GITHUB_EVENT_PULL_REQUEST_TITLE__ - - **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Read from these files instead of calling the API. + - **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Read from these files instead of calling the API. ## Constraints @@ -501,15 +501,14 @@ jobs: ### Step 1: Gather Context - 1. Read `/tmp/agents.md` for repository conventions (skip if missing). - 2. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). - 3. Read `/tmp/pr-context/issue-*.json` files if any exist to understand linked issue motivation and acceptance criteria. - 4. Read `/tmp/pr-context/reviews.json` to check prior review submissions from this bot. Note any prior verdicts to avoid redundant reviews. - 5. Read `/tmp/pr-context/review_comments.json` to check existing review threads. Note which files already have threads and whether they are resolved, unresolved, or outdated. + 1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). + 2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` files if any exist to understand linked issue motivation and acceptance criteria. + 3. Read `/tmp/gh-aw/agent/pr-context/reviews.json` to check prior review submissions from this bot. Note any prior verdicts to avoid redundant reviews. + 4. Read `/tmp/gh-aw/agent/pr-context/review_comments.json` to check existing review threads. Note which files already have threads and whether they are resolved, unresolved, or outdated. ### Step 2: Review - 1. Call `ready_to_code_review` — this writes `/tmp/pr-context/agent-review.md` (review approach) and `/tmp/pr-context/parent-review.md` (comment format and inline severity threshold). + 1. Call `ready_to_code_review` — this writes `/tmp/gh-aw/agent/pr-context/agent-review.md` (review approach) and `/tmp/gh-aw/agent/pr-context/parent-review.md` (comment format and inline severity threshold). 2. Read both files, then follow the approach in `agent-review.md`. ### Step 3: Verify and Comment @@ -523,7 +522,7 @@ jobs: Only leave a comment if the finding survives all four checks. Findings flagged independently by multiple sub-agents are stronger candidates. Findings from only one sub-agent deserve extra scrutiny. - Before posting each comment, **verify the target line is in the numbered diff**: check `/tmp/pr-context/diffs/.diff` — only lines with a number prefix are commentable. If the line has no number in the diff, do NOT attempt an inline comment — include the finding in the review body instead. + Before posting each comment, **verify the target line is in the numbered diff**: check `/tmp/gh-aw/agent/pr-context/diffs/.diff` — only lines with a number prefix are commentable. If the line has no number in the diff, do NOT attempt an inline comment — include the finding in the review body instead. Leave inline comments (`create_pull_request_review_comment`) per the **Code Review Reference** above for each finding that survives verification. Comment on each file's findings before moving to the next file. If no findings survive verification, proceed directly to Step 4. @@ -550,7 +549,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_58f1e24032a9ec12_EOF + GH_AW_PROMPT_bc7d158162ea8aef_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -734,35 +733,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -781,7 +780,7 @@ jobs: GH_TOKEN: ${{ github.token }} PR_NUMBER: ${{ github.event.pull_request.number || inputs.target-pr-number || github.event.issue.number }} name: Fetch PR context to disk - run: "set -euo pipefail\nmkdir -p /tmp/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/pr-context/files.json \\\n > /tmp/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/pr-context/review_comments.json \\\n > /tmp/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/pr-context/threads\nfind /tmp/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/pr-context/\"\nls -la /tmp/pr-context/\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent/pr-context\n\n# PR metadata\ngh pr view \"$PR_NUMBER\" --json title,body,author,baseRefName,headRefName,headRefOid,url \\\n > /tmp/gh-aw/agent/pr-context/pr.json\n\n# Full diff\nif ! gh pr diff \"$PR_NUMBER\" > /tmp/gh-aw/agent/pr-context/pr.diff; then\n echo \"::warning::Failed to fetch full PR diff; per-file diffs from files.json are still available.\"\n : > /tmp/gh-aw/agent/pr-context/pr.diff\nfi\n\n# Changed files list (--paginate may output concatenated arrays; jq -s 'add' merges them)\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/files\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/files.json\n\n# Per-file diffs with line numbers\n# Lines with a number prefix are commentable (RIGHT side: added or context).\n# Deleted lines get no number (LEFT side only).\njq -c '.[]' /tmp/gh-aw/agent/pr-context/files.json | while IFS= read -r entry; do\n filename=$(echo \"$entry\" | jq -r '.filename')\n mkdir -p \"/tmp/gh-aw/agent/pr-context/diffs/$(dirname \"$filename\")\"\n echo \"$entry\" | jq -r '.patch // empty' | awk '\n /^@@/ { s=$3; gsub(/\\+/,\"\",s); split(s,a,\",\"); line=a[1]+0; print; next }\n /^\\+/ { printf \"%d\\t%s\\n\", line++, $0; next }\n /^-/ { printf \" \\t%s\\n\", $0; next }\n /^ / { printf \"%d\\t%s\\n\", line++, $0; next }\n { print }\n ' > \"/tmp/gh-aw/agent/pr-context/diffs/${filename}.diff\"\ndone\n\n# File orderings for sub-agent review (3 strategies)\njq -r '[.[] | .filename] | sort | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_az.txt\njq -r '[.[] | .filename] | sort | reverse | .[]' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_za.txt\njq -r '[.[] | {filename, size: ((.additions // 0) + (.deletions // 0))}] | sort_by(-.size) | .[].filename' /tmp/gh-aw/agent/pr-context/files.json \\\n > /tmp/gh-aw/agent/pr-context/file_order_largest.txt\n\n# Compute PR size metrics for review fan-out decisions\nFILE_COUNT=$(jq 'length' /tmp/gh-aw/agent/pr-context/files.json)\nDIFF_LINES=$(wc -l < /tmp/gh-aw/agent/pr-context/pr.diff | tr -d ' ')\necho \"${FILE_COUNT} files, ${DIFF_LINES} diff lines\" > /tmp/gh-aw/agent/pr-context/pr-size.txt\necho \"PR size: ${FILE_COUNT} files, ${DIFF_LINES} diff lines\"\n\n# Existing reviews\ngh api \"repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/reviews\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/reviews.json\n\n# Review threads with resolution status (GraphQL — REST lacks isResolved/isOutdated)\ngh api graphql --paginate -f query='\n query($owner: String!, $repo: String!, $number: Int!, $endCursor: String) {\n repository(owner: $owner, name: $repo) {\n pullRequest(number: $number) {\n reviewThreads(first: 100, after: $endCursor) {\n pageInfo { hasNextPage endCursor }\n nodes {\n id\n isResolved\n isOutdated\n isCollapsed\n path\n line\n startLine\n comments(first: 100) {\n nodes {\n id\n databaseId\n body\n author { login }\n createdAt\n }\n }\n }\n }\n }\n }\n }\n' -F owner=\"${GITHUB_REPOSITORY%/*}\" -F repo=\"${GITHUB_REPOSITORY#*/}\" -F \"number=$PR_NUMBER\" \\\n --jq '.data.repository.pullRequest.reviewThreads.nodes' \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/review_comments.json\n\n# Filtered review thread views (pre-computed so agents don't need to parse review_comments.json)\njq '[.[] | select(.isResolved == false)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/unresolved_threads.json\njq '[.[] | select(.isResolved == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/resolved_threads.json\njq '[.[] | select(.isOutdated == true)]' /tmp/gh-aw/agent/pr-context/review_comments.json \\\n > /tmp/gh-aw/agent/pr-context/outdated_threads.json\n\n# Per-file review threads (mirrors diffs/ structure)\njq -c '.[]' /tmp/gh-aw/agent/pr-context/review_comments.json | while IFS= read -r thread; do\n filepath=$(echo \"$thread\" | jq -r '.path // empty')\n [ -z \"$filepath\" ] && continue\n mkdir -p \"/tmp/gh-aw/agent/pr-context/threads/$(dirname \"$filepath\")\"\n echo \"$thread\" >> \"/tmp/gh-aw/agent/pr-context/threads/${filepath}.jsonl\"\ndone\n# Convert per-file JSONL to proper JSON arrays\nmkdir -p /tmp/gh-aw/agent/pr-context/threads\nfind /tmp/gh-aw/agent/pr-context/threads -name '*.jsonl' 2>/dev/null | while IFS= read -r jsonl; do\n jq -s '.' \"$jsonl\" > \"${jsonl%.jsonl}.json\"\n rm \"$jsonl\"\ndone\n\n# PR discussion comments\ngh api \"repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments\" --paginate \\\n | jq -s 'add // []' > /tmp/gh-aw/agent/pr-context/comments.json\n\n# Linked issues\njq -r '.body // \"\"' /tmp/gh-aw/agent/pr-context/pr.json 2>/dev/null \\\n | grep -oiE '(fixes|closes|resolves)\\s+#[0-9]+' \\\n | grep -oE '[0-9]+$' \\\n | sort -u \\\n | while read -r issue; do\n gh api \"repos/$GITHUB_REPOSITORY/issues/$issue\" > \"/tmp/gh-aw/agent/pr-context/issue-${issue}.json\" || true\n done || true\n\n# Write manifest\ncat > /tmp/gh-aw/agent/pr-context/README.md << 'MANIFEST'\n# PR Context\n\nPre-fetched PR data. All files are in `/tmp/gh-aw/agent/pr-context/`.\n\n| File | Description |\n| --- | --- |\n| `pr.json` | PR metadata — title, body, author, base/head branches, head commit SHA (`headRefOid`), URL |\n| `pr.diff` | Full unified diff of all changes |\n| `files.json` | Changed files array — each entry has `filename`, `status`, `additions`, `deletions`, `patch` |\n| `diffs/.diff` | Per-file diffs with line numbers — numbered lines (e.g. `405\\t+ code`) are commentable; lines without numbers are deleted (LEFT side only) |\n| `file_order_az.txt` | Changed files sorted alphabetically (A→Z), one filename per line |\n| `file_order_za.txt` | Changed files sorted reverse-alphabetically (Z→A), one filename per line |\n| `file_order_largest.txt` | Changed files sorted by diff size descending (largest first), one filename per line |\n| `reviews.json` | Prior review submissions — author, state (APPROVED/CHANGES_REQUESTED/COMMENTED), body |\n| `review_comments.json` | All review threads (GraphQL) — each thread has `id` (node ID for resolving), `isResolved`, `isOutdated`, `path`, `line`, and nested `comments` with `id`, `databaseId` (numeric REST ID for replies), body/author |\n| `unresolved_threads.json` | Unresolved review threads — subset of `review_comments.json` where `isResolved` is false |\n| `resolved_threads.json` | Resolved review threads — subset of `review_comments.json` where `isResolved` is true |\n| `outdated_threads.json` | Outdated review threads — subset of `review_comments.json` where `isOutdated` is true (code changed since comment) |\n| `threads/.json` | Per-file review threads — one file per changed file with existing threads, mirroring the repo path under `threads/` |\n| `comments.json` | PR discussion comments (not inline) |\n| `issue-{N}.json` | Linked issue details (one file per linked issue, if any) |\n| `pr-size.txt` | PR size metrics: `{N} files, {M} diff lines` — used by the agent to decide review fan-out |\n| `agents.md` | Not used in PR context — repository conventions are at `/tmp/agents.md` (pre-fetched) |\n| `review-instructions.md` | Review instructions, criteria, and calibration examples for sub-agents |\n| `agent-review.md` | Main agent instructions — review approach resolved from PR size (written when `ready_to_code_review` is called) |\n| `parent-review.md` | Comment format and inline severity threshold for the parent agent (written when `ready_to_code_review` is called) |\n| `subagent-*.md` | Sub-agent instructions (only written for medium/large PRs when `ready_to_code_review` is called — check `agent-review.md` for which exist) |\nMANIFEST\n\necho \"PR context written to /tmp/gh-aw/agent/pr-context/\"\nls -la /tmp/gh-aw/agent/pr-context/\n" - name: Write review instructions to disk run: "mkdir -p /tmp/pr-context\ncat > /tmp/pr-context/review-instructions.md << 'REVIEW_EOF'\n# Review Instructions for Sub-agents\n\nYou are a code review sub-agent. Read these instructions, then review the PR files in the order provided in your prompt.\n\n## Context\n\nBefore reviewing files, read these to understand the PR:\n\n1. `/tmp/pr-context/pr.json` — PR title, description, author, and branches. Understand what the PR is trying to accomplish.\n2. `/tmp/agents.md` — Repository coding conventions and guidelines (skip if missing).\n3. `/tmp/pr-context/review_comments.json` — Existing review threads. Note which files already have threads so you don't duplicate.\n4. `/tmp/pr-context/issue-*.json` — Linked issue details (if any). Understand the motivation and acceptance criteria.\n\n## Process\n\nReview the PR diff file by file in your assigned order. For each changed file:\n\n1. **Read the diff** for this file from `/tmp/pr-context/diffs/.diff` to understand what changed. Each line is prefixed with its line number (e.g., `405\\t+ code`). Lines with numbers are commentable; lines without numbers are deleted lines (LEFT side only). If the diff is empty or truncated (e.g., binary files or very large changes), fall back to reading the full file from the workspace and comparing against context.\n2. **Read the full file from the workspace.** The PR branch is checked out locally — open the file directly to get complete contents with line numbers.\n3. **Check existing threads** for this file from `/tmp/pr-context/threads/.json` (if it exists). Skip issues that are already under discussion — each thread has `isResolved` and `isOutdated` fields.\n4. **Identify potential issues** matching the review criteria below.\n5. **Quick-check each issue** before including it:\n - What specific code pattern or change triggers this concern?\n - Is there an obvious guard, handler, or mitigation visible in the immediate context?\n - Can you describe a concrete failure scenario (the `evidence` field)? If you cannot articulate what specific input or state triggers the problem, drop the finding.\n - If the issue is clearly handled, skip it. If you're unsure, include it — the parent will verify.\n6. **Add to your findings list.** Do NOT leave inline comments — you don't have that tool. Return findings in this format:\n\n```\n- file: path/to/file\n line: 42\n severity: HIGH\n title: Brief title\n description: What the issue is and why it matters\n evidence: The specific code pattern and failure scenario\n suggestion: corrected code here (optional — only if you can provide a concrete fix)\n```\n\n**Review every file in your assigned order.** Files reviewed earlier get more attention, which is why different sub-agents use different orderings.\n\n**Check existing threads** — per-file threads are at `/tmp/pr-context/threads/.json` (step 3 above). The full list is at `/tmp/pr-context/review_comments.json`. Do not flag issues that are already under discussion (resolved or unresolved). For outdated threads, only re-flag if the issue still applies to the current diff.\n\n**Return your full findings list** when done, or an empty list if no issues were found.\n\n## Review Criteria\n\nFocus on these categories in priority order:\n\n1. Security vulnerabilities (injection, XSS, auth bypass, secrets exposure)\n2. Logic bugs that could cause runtime failures or incorrect behavior\n3. Data integrity issues (race conditions, missing transactions, corruption risk)\n4. Performance bottlenecks (N+1 queries, memory leaks, blocking operations)\n5. Error handling gaps (unhandled exceptions, missing validation)\n6. Breaking changes to public APIs without migration path\n7. Missing or incorrect test coverage for critical paths\n\n## What NOT to Flag\n\nOnly review the diff — do not flag issues in unchanged code, pre-existing problems not introduced by this PR, or style preferences handled by linters or formatters.\n\n**Common false positives** — these patterns look like issues but usually aren't. Before flagging anything in these categories, confirm the problem is real by reading the surrounding code:\n\n- **Security — input already sanitized:** Don't flag injection or XSS risks when inputs are sanitized upstream, parameterized queries are used, or the framework auto-escapes output.\n- **Null/undefined — guarded elsewhere:** Don't flag potential null dereferences if the value is guaranteed by a type guard, assertion, schema validation, or upstream null check.\n- **Error handling — handled at a different layer:** Don't flag missing try/catch if the caller, middleware, or framework catches and handles the error (e.g., Express error middleware, React error boundaries).\n- **Performance — theoretical, not practical:** Don't flag algorithmic complexity (e.g., O(n^2)) unless N is demonstrably large enough to matter in the actual usage context. \"This could be slow\" without evidence is not actionable.\n- **Validation — exists at another layer:** Don't flag missing input validation if it's handled by an API gateway, middleware, schema validator, or type system.\n- **Test coverage — trivial or generated code:** Don't flag missing tests for trivial getters/setters, auto-generated code, or simple delegation methods.\n- **Style or naming — not in coding guidelines:** Don't flag naming conventions or code style unless they violate the repository's documented coding guidelines (from `/tmp/agents.md` or CONTRIBUTING docs).\n\n**Existing review threads** — check BEFORE flagging any issue:\n\n- **Resolved with reviewer reply** (e.g. \"This is intentional\") — reviewer's decision is final. Do NOT re-flag.\n- **Resolved without reply** — author likely fixed it. Do NOT re-raise unless the fix introduced a new problem.\n- **Unresolved** — already flagged. Do NOT duplicate.\n- **Outdated** — only re-flag if the issue still applies to the current diff.\n\nWhen in doubt, do not duplicate. Redundant comments erode trust.\n\nFinding no issues is a valid and valuable outcome. An empty findings list is better than findings that waste the author's time or erode trust. Do not manufacture findings to justify your review — if the code is sound, return an empty list.\n\n## Severity Classification\n\nDetermine severity AFTER investigating the issue, not before. First identify the problem and trace through the code, then assign a severity based on the evidence you found.\n\n- 🔴 CRITICAL — Must fix before merge (security vulnerabilities, data corruption, production-breaking bugs)\n- 🟠 HIGH — Should fix before merge (logic errors, missing validation, significant performance issues)\n- 🟡 MEDIUM — Address soon, non-blocking (error handling gaps, suboptimal patterns, missing edge cases)\n- ⚪ LOW — Author discretion (minor improvements, documentation gaps)\n- 💬 NITPICK — Truly optional (stylistic preferences, alternative approaches)\n\n## Review Intensity\n\nThe review intensity is `${{ inputs.intensity || 'balanced' }}`.\n\n- **conservative**: High evidence bar. Only flag when you can demonstrate a concrete failure scenario. If you can construct a reasonable counterargument, do not flag. Approval with zero findings is the expected outcome for most PRs.\n- **balanced**: Standard evidence bar. Flag when you can point to specific code that would fail. If the issue is ambiguous, lean toward not flagging.\n- **aggressive**: Lower evidence bar. Flag when evidence exists even if the failure scenario is not fully confirmed. Improvement suggestions welcome but must cite specific code.\n\n## Calibration Examples\n\nUse these examples to calibrate your judgment. Each pair shows a real issue and a similar-looking pattern that is NOT an issue.\n\n### Example 1: Null/Undefined Access\n\n**True positive — flag this:**\n\n```js\n// PR adds this handler\napp.get('/user/:id', async (req, res) => {\n const user = await db.findUser(req.params.id);\n res.json({ name: user.name, email: user.email });\n});\n```\n\nWhy flag: `db.findUser()` can return `null` when no user matches the ID. Accessing `user.name` will throw a TypeError at runtime. No upstream guard exists — the route handler is the entry point.\n\n**False positive — do NOT flag this:**\n\n```ts\n// PR adds this line inside an existing function\nconst settings = user.getSettings();\n```\n\nWhy skip: Reading the full file reveals `user` is typed as `User` (not `User | null`), and the calling function only runs after `authenticateUser()` middleware which guarantees a valid user object. The null case is handled at a different layer.\n\n### Example 2: SQL Injection\n\n**True positive — flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE customer_id = '{customer_id}'\")\n```\n\nWhy flag: String interpolation in a SQL query with user-controlled input (`customer_id` comes from the request). No parameterization or sanitization anywhere in the call chain.\n\n**False positive — do NOT flag this:**\n\n```python\n# PR adds this query\ncursor.execute(f\"SELECT * FROM orders WHERE status = '{OrderStatus.PENDING.value}'\")\n```\n\nWhy skip: The interpolated value is a hardcoded enum constant (`OrderStatus.PENDING`), not user input. There is no injection vector.\n\n### Example 3: Borderline — Do NOT Flag\n\n```go\n// PR adds this function\nfunc processItems(items []Item) []Result {\n results := make([]Result, 0)\n for _, item := range items {\n for _, tag := range item.Tags {\n results = append(results, process(item, tag))\n }\n }\n return results\n}\n```\n\nThis looks like an O(n*m) performance concern. But without evidence that `items` or `Tags` are large in practice, this is speculative. The function processes a bounded dataset (items from a single user request). Do not flag theoretical performance issues without evidence of real-world impact.\nREVIEW_EOF\n" - env: @@ -1604,7 +1603,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-pr-review.md b/.github/workflows/gh-aw-pr-review.md index d3d6e921..6fc52435 100644 --- a/.github/workflows/gh-aw-pr-review.md +++ b/.github/workflows/gh-aw-pr-review.md @@ -18,9 +18,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-pr-review-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -109,7 +109,7 @@ Review pull requests in ${{ github.repository }} and provide actionable feedback - **Repository**: ${{ github.repository }} - **PR**: #${{ github.event.pull_request.number }} — ${{ github.event.pull_request.title }} -- **PR context on disk**: `/tmp/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Read from these files instead of calling the API. +- **PR context on disk**: `/tmp/gh-aw/agent/pr-context/` — PR metadata, diff, files, reviews, comments, and linked issues are pre-fetched. Read from these files instead of calling the API. ## Constraints @@ -121,15 +121,14 @@ Follow these steps in order. ### Step 1: Gather Context -1. Read `/tmp/agents.md` for repository conventions (skip if missing). -2. Read `/tmp/pr-context/pr.json` for PR details (author, description, branches). -3. Read `/tmp/pr-context/issue-*.json` files if any exist to understand linked issue motivation and acceptance criteria. -4. Read `/tmp/pr-context/reviews.json` to check prior review submissions from this bot. Note any prior verdicts to avoid redundant reviews. -5. Read `/tmp/pr-context/review_comments.json` to check existing review threads. Note which files already have threads and whether they are resolved, unresolved, or outdated. +1. Read `/tmp/gh-aw/agent/pr-context/pr.json` for PR details (author, description, branches). +2. Read `/tmp/gh-aw/agent/pr-context/issue-*.json` files if any exist to understand linked issue motivation and acceptance criteria. +3. Read `/tmp/gh-aw/agent/pr-context/reviews.json` to check prior review submissions from this bot. Note any prior verdicts to avoid redundant reviews. +4. Read `/tmp/gh-aw/agent/pr-context/review_comments.json` to check existing review threads. Note which files already have threads and whether they are resolved, unresolved, or outdated. ### Step 2: Review -1. Call `ready_to_code_review` — this writes `/tmp/pr-context/agent-review.md` (review approach) and `/tmp/pr-context/parent-review.md` (comment format and inline severity threshold). +1. Call `ready_to_code_review` — this writes `/tmp/gh-aw/agent/pr-context/agent-review.md` (review approach) and `/tmp/gh-aw/agent/pr-context/parent-review.md` (comment format and inline severity threshold). 2. Read both files, then follow the approach in `agent-review.md`. ### Step 3: Verify and Comment @@ -143,7 +142,7 @@ If sub-agents were used, merge and deduplicate findings per the Pick Three, Keep Only leave a comment if the finding survives all four checks. Findings flagged independently by multiple sub-agents are stronger candidates. Findings from only one sub-agent deserve extra scrutiny. -Before posting each comment, **verify the target line is in the numbered diff**: check `/tmp/pr-context/diffs/.diff` — only lines with a number prefix are commentable. If the line has no number in the diff, do NOT attempt an inline comment — include the finding in the review body instead. +Before posting each comment, **verify the target line is in the numbered diff**: check `/tmp/gh-aw/agent/pr-context/diffs/.diff` — only lines with a number prefix are commentable. If the line has no number in the diff, do NOT attempt an inline comment — include the finding in the review body instead. Leave inline comments (`create_pull_request_review_comment`) per the **Code Review Reference** above for each finding that survives verification. Comment on each file's findings before moving to the next file. If no findings survive verification, proceed directly to Step 4. diff --git a/.github/workflows/gh-aw-product-manager-impersonator.lock.yml b/.github/workflows/gh-aw-product-manager-impersonator.lock.yml index 4fdcf3ee..6fbbce9a 100644 --- a/.github/workflows/gh-aw-product-manager-impersonator.lock.yml +++ b/.github/workflows/gh-aw-product-manager-impersonator.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"aa995b5ddf44a83a7ed93537ae720182e9bba68436196ea2848c798a181064b1","body_hash":"f4004e65a88b2e97544fe9f1063990e97698b40bc1f86a585f9b824cecdcfbb6","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"63502d6e4d5653d8bc43164660f5d293fad0a17096b7ea931c0f78cc028b9281","body_hash":"f5a5369ff56f585cea8e9390bdc7ffe9204d3bb558f5c3d8706774872b84af23","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -333,20 +333,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_5dfccd5e3c6151f6_EOF' + cat << 'GH_AW_PROMPT_7db87eaf296e205d_EOF' - GH_AW_PROMPT_5dfccd5e3c6151f6_EOF + GH_AW_PROMPT_7db87eaf296e205d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_5dfccd5e3c6151f6_EOF' + cat << 'GH_AW_PROMPT_7db87eaf296e205d_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_5dfccd5e3c6151f6_EOF + GH_AW_PROMPT_7db87eaf296e205d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_5dfccd5e3c6151f6_EOF' + cat << 'GH_AW_PROMPT_7db87eaf296e205d_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -375,9 +375,9 @@ jobs: {{/if}} - GH_AW_PROMPT_5dfccd5e3c6151f6_EOF + GH_AW_PROMPT_7db87eaf296e205d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_5dfccd5e3c6151f6_EOF' + cat << 'GH_AW_PROMPT_7db87eaf296e205d_EOF' ## MCP Servers @@ -448,9 +448,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -563,7 +563,7 @@ jobs: 4. **Check for duplicates** - Search open issues for existing feature requests: `repo:{owner}/{repo} is:issue is:open (feature OR enhancement OR idea)`. - Search past reports: `repo:{owner}/{repo} is:issue in:title "__GH_AW_EXPR_BF503D80__"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. - If your idea duplicates an existing request, pick a different angle. ### What to Propose @@ -643,7 +643,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_5dfccd5e3c6151f6_EOF + GH_AW_PROMPT_7db87eaf296e205d_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -820,35 +820,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -867,7 +867,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1664,7 +1664,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-product-manager-impersonator.md b/.github/workflows/gh-aw-product-manager-impersonator.md index 56fdb57a..31fea186 100644 --- a/.github/workflows/gh-aw-product-manager-impersonator.md +++ b/.github/workflows/gh-aw-product-manager-impersonator.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -128,7 +128,7 @@ Your task is to propose **one** well-researched new feature idea for this reposi 4. **Check for duplicates** - Search open issues for existing feature requests: `repo:{owner}/{repo} is:issue is:open (feature OR enhancement OR idea)`. - Search past reports: `repo:{owner}/{repo} is:issue in:title "${{ inputs.title-prefix }}"`. - - Review `/tmp/previous-findings.json` for issues already filed by this agent. + - Review `/tmp/gh-aw/agent/previous-findings.json` for issues already filed by this agent. - If your idea duplicates an existing request, pick a different angle. ### What to Propose diff --git a/.github/workflows/gh-aw-project-summary.lock.yml b/.github/workflows/gh-aw-project-summary.lock.yml index 2be3294c..61d2ba1f 100644 --- a/.github/workflows/gh-aw-project-summary.lock.yml +++ b/.github/workflows/gh-aw-project-summary.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e3a25d6b13878ea22bf9414e64b872fe9f2b23f47ac526f720c7d03fd46fe122","body_hash":"286b29ca94ea13944868c44da598027fd09dd699f8955b4440803a13bc14332d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"98ebae06a4c67b9715fce9b4a61f2114c8730b58fe2eee3e773dbc4a1dcd6b1d","body_hash":"3c4fa14ddd3864f20aac49e8ec1ff94ff1ab9d2e70982f7b6c4baeeadba8b9b6","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_9943e34fbca5fd9c_EOF' + cat << 'GH_AW_PROMPT_f75960afae6ff8bc_EOF' - GH_AW_PROMPT_9943e34fbca5fd9c_EOF + GH_AW_PROMPT_f75960afae6ff8bc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_9943e34fbca5fd9c_EOF' + cat << 'GH_AW_PROMPT_f75960afae6ff8bc_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_9943e34fbca5fd9c_EOF + GH_AW_PROMPT_f75960afae6ff8bc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_9943e34fbca5fd9c_EOF' + cat << 'GH_AW_PROMPT_f75960afae6ff8bc_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_9943e34fbca5fd9c_EOF + GH_AW_PROMPT_f75960afae6ff8bc_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_9943e34fbca5fd9c_EOF' + cat << 'GH_AW_PROMPT_f75960afae6ff8bc_EOF' ## MCP Servers @@ -437,9 +437,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -569,7 +569,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_9943e34fbca5fd9c_EOF + GH_AW_PROMPT_f75960afae6ff8bc_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -740,35 +740,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -793,7 +793,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1590,7 +1590,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-project-summary.md b/.github/workflows/gh-aw-project-summary.md index 2a8a794b..08259dcf 100644 --- a/.github/workflows/gh-aw-project-summary.md +++ b/.github/workflows/gh-aw-project-summary.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-refactor-opportunist.lock.yml b/.github/workflows/gh-aw-refactor-opportunist.lock.yml index 169741dd..bc1773c5 100644 --- a/.github/workflows/gh-aw-refactor-opportunist.lock.yml +++ b/.github/workflows/gh-aw-refactor-opportunist.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"68ccc9a934125a7ed3afca689700061207ba761e68b9902b059d03259d327160","body_hash":"76e0d7d9dae54243115b9189d671b3d7827982fa29457ecb08dd3ba74583171a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"046c437cbbde1a7d56aae3d7bdb0769daad6ec399163c303a839128f52cc594e","body_hash":"c82e08a0d12efef00a4615150063fc74099b16537d891d5bd440803d4a3778d7","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -321,20 +321,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_79ffbc6c1dca9275_EOF' + cat << 'GH_AW_PROMPT_2467951f9452fa95_EOF' - GH_AW_PROMPT_79ffbc6c1dca9275_EOF + GH_AW_PROMPT_2467951f9452fa95_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_79ffbc6c1dca9275_EOF' + cat << 'GH_AW_PROMPT_2467951f9452fa95_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_79ffbc6c1dca9275_EOF + GH_AW_PROMPT_2467951f9452fa95_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_79ffbc6c1dca9275_EOF' + cat << 'GH_AW_PROMPT_2467951f9452fa95_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -363,9 +363,9 @@ jobs: {{/if}} - GH_AW_PROMPT_79ffbc6c1dca9275_EOF + GH_AW_PROMPT_2467951f9452fa95_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_79ffbc6c1dca9275_EOF' + cat << 'GH_AW_PROMPT_2467951f9452fa95_EOF' ## MCP Servers @@ -437,9 +437,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -623,7 +623,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_79ffbc6c1dca9275_EOF + GH_AW_PROMPT_2467951f9452fa95_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -792,35 +792,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -845,7 +845,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1642,7 +1642,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-refactor-opportunist.md b/.github/workflows/gh-aw-refactor-opportunist.md index 46d75587..31b72a95 100644 --- a/.github/workflows/gh-aw-refactor-opportunist.md +++ b/.github/workflows/gh-aw-refactor-opportunist.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-release-update.lock.yml b/.github/workflows/gh-aw-release-update.lock.yml index 0ea73f57..82dcb69f 100644 --- a/.github/workflows/gh-aw-release-update.lock.yml +++ b/.github/workflows/gh-aw-release-update.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"37f45a03b14808cfc998408d849f858a821d571ba4315988521876ff5d32f80f","body_hash":"5f925c394c2f717e3d5d1bdc709ef4582aab10a1a078f21163ad9596349ca67a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"77e3b0c24597aae131dd036fd93b58064d9ddd4c760332fe814b84dddc8e6734","body_hash":"5f925c394c2f717e3d5d1bdc709ef4582aab10a1a078f21163ad9596349ca67a","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,15 +52,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -655,35 +655,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1501,7 +1501,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-release-update.md b/.github/workflows/gh-aw-release-update.md index 96be5b44..bcc8a696 100644 --- a/.github/workflows/gh-aw-release-update.md +++ b/.github/workflows/gh-aw-release-update.md @@ -12,7 +12,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-scheduled-audit.lock.yml b/.github/workflows/gh-aw-scheduled-audit.lock.yml index 950aa053..3b34070f 100644 --- a/.github/workflows/gh-aw-scheduled-audit.lock.yml +++ b/.github/workflows/gh-aw-scheduled-audit.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"cd03d3c0220ef07f1abd314e715e8df5015bf17ec6ab8d5fb7242d56cc036c32","body_hash":"531343946246cb62c28db9c05090c680e489b15ed3337e6f8049d7f8511d2dec","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"},{"image":"mcr.microsoft.com/playwright/mcp"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6b53993a6893ff25f9b0ac13d2a265e3f6543e1e36ce35c08f95270835f4a624","body_hash":"ef4394b1f16919ef35a1407eb4585310f862be7543b401cb571bb54e678e394d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -70,7 +70,6 @@ # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 -# - mcr.microsoft.com/playwright/mcp name: "Scheduled Audit" on: @@ -329,21 +328,21 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_d7f913843fad5a9b_EOF' + cat << 'GH_AW_PROMPT_37b595b44973e752_EOF' - GH_AW_PROMPT_d7f913843fad5a9b_EOF + GH_AW_PROMPT_37b595b44973e752_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_d7f913843fad5a9b_EOF' + cat << 'GH_AW_PROMPT_37b595b44973e752_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_d7f913843fad5a9b_EOF + GH_AW_PROMPT_37b595b44973e752_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_d7f913843fad5a9b_EOF' + cat << 'GH_AW_PROMPT_37b595b44973e752_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -372,9 +371,9 @@ jobs: {{/if}} - GH_AW_PROMPT_d7f913843fad5a9b_EOF + GH_AW_PROMPT_37b595b44973e752_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_d7f913843fad5a9b_EOF' + cat << 'GH_AW_PROMPT_37b595b44973e752_EOF' ## MCP Servers @@ -435,9 +434,9 @@ jobs: ## Message Footer A footer is automatically appended to all comments and reviews. Do not add your own footer or sign-off — the runtime handles this. - ## Playwright MCP Tools + ## Playwright CLI - Playwright MCP tools are available for interactive browser automation. Full instructions are in `/tmp/playwright-instructions.md` — read it before using any Playwright tools. + Playwright CLI is available for interactive browser automation. Run `playwright-cli ` in bash. Full instructions are in `/tmp/gh-aw/agent/playwright-instructions.md` — read it before using Playwright. ## create-issue Limitations - **Title**: Max 128 characters. Sanitized (special characters escaped). @@ -511,9 +510,9 @@ jobs: ## Previous Findings - When `close-older-issues` is `false` (current: `__GH_AW_EXPR_539E03E1__`), check `/tmp/previous-findings.json` for issues this agent has already filed before filing a new one. + When `close-older-issues` is `false` (current: `__GH_AW_EXPR_539E03E1__`), check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed before filing a new one. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. @@ -525,7 +524,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_d7f913843fad5a9b_EOF + GH_AW_PROMPT_37b595b44973e752_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -684,13 +683,6 @@ jobs: uses: github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 with: version: 'v0.82.14' - - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: '1.26' - cache: false - - name: Capture GOROOT for AWF chroot mode - run: echo "GOROOT=$(go env GOROOT)" >> "$GITHUB_ENV" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -702,31 +694,37 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw + - if: hashFiles('go.mod') != '' + name: Setup Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) + with: + cache: true + go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -742,13 +740,13 @@ jobs: run: "set -euo pipefail\nif [ -f \"AGENTS.md\" ]; then\n cp AGENTS.md /tmp/agents.md\n echo \"Repository conventions copied from AGENTS.md to /tmp/agents.md\"\nelse\n OWNER=\"${GITHUB_REPOSITORY%/*}\"\n REPO=\"${GITHUB_REPOSITORY#*/}\"\n summary=$(curl -sf --max-time 15 -X POST https://agents-md-generator.fastmcp.app/mcp \\\n -H \"Content-Type: application/json\" \\\n -H \"Accept: application/json, text/event-stream\" \\\n -d \"{\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":1,\\\"method\\\":\\\"tools/call\\\",\\\"params\\\":{\\\"name\\\":\\\"generate_agents_md\\\",\\\"arguments\\\":{\\\"owner\\\":\\\"${OWNER}\\\",\\\"repo\\\":\\\"${REPO}\\\"}}}\" \\\n | sed 's/^data: //' \\\n | jq -r '.result.structuredContent.summary // empty' 2>/dev/null) || true\n if [ -n \"$summary\" ]; then\n echo \"$summary\" > /tmp/agents.md\n echo \"Repository conventions written to /tmp/agents.md\"\n else\n echo \"::warning::Could not fetch repository conventions; continuing without them\"\n fi\nfi\n" shell: bash - name: Write Playwright instructions to disk - run: "cat > /tmp/playwright-instructions.md << 'EOF'\n# Playwright MCP Tools\n\nUse Playwright MCP tools for interactive browser automation.\nUnless otherwise instructed, use the MCP tools directly rather than writing standalone Node.js scripts.\n\n## Available tools\n\n- `browser_navigate` — go to a URL\n- `browser_click` — click an element\n- `browser_type` — type text into an input\n- `browser_snapshot` — get an accessibility tree (YAML) of the current page\n- `browser_take_screenshot` — capture a visual screenshot (PNG/JPEG)\n- `browser_run_code` — run a Playwright code snippet\n- `browser_wait_for` — wait for text to appear/disappear\n- `browser_press_key` — press a keyboard key\n\n## Automatic snapshots are disabled\n\n`browser_click`, `browser_type`, `browser_wait_for`, and\n`browser_run_code` do NOT return page state. You choose when to\ninspect the page.\n\n## Batch actions with `browser_run_code`\n\nWhen you know the UI structure (button names, input labels), batch\nmultiple actions in a single `browser_run_code` call using Playwright's\nrole selectors. This is much more efficient than individual tool calls:\n\n```js\nasync (page) => {\n await page.getByRole('button', { name: 'Settings' }).click();\n await page.getByRole('combobox', { name: 'Theme' }).selectOption('dark');\n await page.getByRole('button', { name: 'Save' }).click();\n return 'Settings saved';\n}\n```\n\n**Keep return values small** — return only what you need:\n```js\nasync (page) => {\n const res = await page.request.post(url, {data});\n const json = await res.json();\n // Good: ~50 chars\n return JSON.stringify({success: json.success, errors: json.errors?.length || 0});\n // Bad: entire response body (can be 20K+ chars)\n}\n```\n\n## Discover elements with snapshots\n\nWhen you don't know what's on the page, save a snapshot to disk and\nsearch it:\n```\nbrowser_snapshot(filename=\"/tmp/gh-aw/mcp-logs/page.md\")\n```\nThen grep for elements:\n```bash\ngrep 'button.*Save\\|button.*Submit' /tmp/gh-aw/mcp-logs/page.md\n```\nUse the `ref` value from grep results with `browser_click(ref=\"...\")`.\n\nOnly take snapshots when you need to discover unknown elements.\nIf you know the button name or role, use `browser_run_code` instead.\n\n## Error handling in `browser_run_code`\n\n`browser_run_code` blocks can fail mid-execution if a selector doesn't\nmatch. Keep blocks focused — if a sequence has uncertain steps, split\nit into separate `browser_run_code` calls so you can inspect and adapt\nbetween them.\n\n## Measuring DOM properties\n\nFor programmatic checks (e.g. element heights, contrast), use\n`browser_run_code`:\n\n```javascript\nasync (page) => {\n const els = await page.locator('input, button, [role=\"combobox\"]').all();\n const results = [];\n for (const el of els.slice(0, 10)) {\n const box = await el.boundingBox();\n const text = await el.textContent();\n if (box) results.push({ h: Math.round(box.height), text: text?.trim().slice(0, 20) });\n }\n return JSON.stringify(results);\n}\n```\n\n## Handling failures\n\n- Do not retry the same action more than twice — the page is in a different state than expected.\n- Diagnose before moving on: save a snapshot to disk and grep it, or use `browser_take_screenshot` for a visual check.\n- Adapt (different selector, different path) or report the failure as a finding.\n- Never claim you verified something you didn't — if it failed and you skipped it, say so.\nEOF\n" + run: "mkdir -p /tmp/gh-aw/agent\ncat > /tmp/gh-aw/agent/playwright-instructions.md << 'EOF'\n# Playwright CLI\n\nUse `playwright-cli` in bash for interactive browser automation.\nRun all Playwright commands as bash subprocesses — do not use MCP browser tools.\n\n## Basic usage\n\n```bash\n# Navigate and take a snapshot (accessibility tree)\nplaywright-cli snapshot \n\n# Take a screenshot\nplaywright-cli screenshot /tmp/gh-aw/agent/screenshot.png\n\n# Navigate, interact, then snapshot\nplaywright-cli run - << 'JS'\nconst { chromium } = require('playwright');\n(async () => {\n const browser = await chromium.launch();\n const page = await browser.newPage();\n await page.goto('https://example.com');\n await page.click('button[name=\"Submit\"]');\n console.log(await page.title());\n await browser.close();\n})();\nJS\n```\n\n## Discover page structure\n\nSave a snapshot to disk and search it:\n```bash\nplaywright-cli snapshot https://example.com > /tmp/gh-aw/agent/page-snapshot.txt\ngrep -i 'button\\|input\\|link' /tmp/gh-aw/agent/page-snapshot.txt\n```\n\n## Error handling\n\n- Do not retry the same action more than twice.\n- If a step fails, take a screenshot to diagnose:\n `playwright-cli screenshot /tmp/gh-aw/agent/debug.png`\n- Adapt (different selector, different path) or report the failure.\n- Never claim you verified something you didn't.\nEOF\n" - env: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} if: ${{ !inputs.close-older-issues }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -783,6 +781,16 @@ jobs: GH_HOST: github.com - name: Install AWF binary run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless + - name: Install Playwright CLI + run: npm install -g @playwright/cli@0.1.17 + env: + NPM_CONFIG_MIN_RELEASE_AGE: '3' + timeout-minutes: 10 + - name: Install Playwright CLI skills + run: playwright-cli install --skills + env: + PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1' + timeout-minutes: 10 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 @@ -809,7 +817,7 @@ jobs: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 mcr.microsoft.com/playwright/mcp + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config env: GH_AW_INPUT_CLOSE_OLDER_ISSUES: ${{ inputs.close-older-issues }} @@ -965,8 +973,6 @@ jobs: run: | set -eo pipefail mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" - mkdir -p /tmp/gh-aw/mcp-logs/playwright - chmod 777 /tmp/gh-aw/mcp-logs/playwright # Export gateway environment variables for MCP config and gateway script export MCP_GATEWAY_PORT="8080" @@ -988,7 +994,7 @@ jobs: mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_ed7241d522585459_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_52b31550c48a73f9_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -1008,21 +1014,6 @@ jobs: } } }, - "playwright": { - "type": "stdio", - "container": "mcr.microsoft.com/playwright/mcp", - "args": ["--init", "--network", "host", "--security-opt", "seccomp=unconfined", "--ipc=host"], - "entrypointArgs": ["--output-dir", "/tmp/gh-aw/mcp-logs/playwright", "--no-sandbox", "--snapshot-mode", "none"], - "mounts": ["/tmp/gh-aw/mcp-logs:/tmp/gh-aw/mcp-logs:rw"], - "guard-policies": { - "write-sink": { - "accept": [ - "*" - ], - "sink-visibility": ${{ toJSON(steps.determine-automatic-lockdown.outputs.visibility) }} - } - } - }, "public-code-search": { "type": "http", "url": "https://public-code-search.fastmcp.app/mcp", @@ -1080,7 +1071,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_ed7241d522585459_EOF + GH_AW_MCP_CONFIG_52b31550c48a73f9_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1563,7 +1554,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-scheduled-audit.md b/.github/workflows/gh-aw-scheduled-audit.md index 1a1d02bd..69a936d3 100644 --- a/.github/workflows/gh-aw-scheduled-audit.md +++ b/.github/workflows/gh-aw-scheduled-audit.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -93,13 +93,14 @@ steps: TITLE_PREFIX: ${{ inputs.title-prefix }} run: | set -euo pipefail + mkdir -p /tmp/gh-aw/agent gh issue list \ --repo "$GITHUB_REPOSITORY" \ --search "in:title \"$TITLE_PREFIX\"" \ --state all \ --limit 100 \ --json number,title,state \ - > /tmp/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/previous-findings.json; } + > /tmp/gh-aw/agent/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/gh-aw/agent/previous-findings.json; } - name: Repo-specific setup if: ${{ inputs.setup-commands != '' }} env: @@ -111,9 +112,9 @@ steps: ## Previous Findings -When `close-older-issues` is `false` (current: `${{ inputs.close-older-issues }}`), check `/tmp/previous-findings.json` for issues this agent has already filed before filing a new one. +When `close-older-issues` is `false` (current: `${{ inputs.close-older-issues }}`), check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed before filing a new one. -- Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. +- Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. diff --git a/.github/workflows/gh-aw-scheduled-fix.lock.yml b/.github/workflows/gh-aw-scheduled-fix.lock.yml index b9f7da40..7454eeff 100644 --- a/.github/workflows/gh-aw-scheduled-fix.lock.yml +++ b/.github/workflows/gh-aw-scheduled-fix.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"48ab79e529b00937946c3e62f29e798015df2f076ab9b67823fa0860b637b05d","body_hash":"4d77e7d2fee826ff30fb89181921306c010db0a1f9db77a492a8561de3a7fa9f","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e9ebc137560a27cccffdbc9ec912c2d99d53dc38f97bc0317332b61f37a8ec92","body_hash":"b530c7f027ade8b203cc4d7ff98a71274acfff9adf912ae95ef7853a7371e476","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -330,23 +330,23 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_30f951551c8e9fe9_EOF' + cat << 'GH_AW_PROMPT_ae133ce2df3aa4c9_EOF' - GH_AW_PROMPT_30f951551c8e9fe9_EOF + GH_AW_PROMPT_ae133ce2df3aa4c9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_30f951551c8e9fe9_EOF' + cat << 'GH_AW_PROMPT_ae133ce2df3aa4c9_EOF' Tools: create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_30f951551c8e9fe9_EOF + GH_AW_PROMPT_ae133ce2df3aa4c9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_30f951551c8e9fe9_EOF' + cat << 'GH_AW_PROMPT_ae133ce2df3aa4c9_EOF' - GH_AW_PROMPT_30f951551c8e9fe9_EOF + GH_AW_PROMPT_ae133ce2df3aa4c9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_30f951551c8e9fe9_EOF' + cat << 'GH_AW_PROMPT_ae133ce2df3aa4c9_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -375,9 +375,9 @@ jobs: {{/if}} - GH_AW_PROMPT_30f951551c8e9fe9_EOF + GH_AW_PROMPT_ae133ce2df3aa4c9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_30f951551c8e9fe9_EOF' + cat << 'GH_AW_PROMPT_ae133ce2df3aa4c9_EOF' ## MCP Servers @@ -510,9 +510,9 @@ jobs: ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. @@ -534,7 +534,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_30f951551c8e9fe9_EOF + GH_AW_PROMPT_ae133ce2df3aa4c9_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -706,35 +706,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -753,7 +753,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1557,7 +1557,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-scheduled-fix.md b/.github/workflows/gh-aw-scheduled-fix.md index 2b8b3d23..c5812adc 100644 --- a/.github/workflows/gh-aw-scheduled-fix.md +++ b/.github/workflows/gh-aw-scheduled-fix.md @@ -14,7 +14,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -95,13 +95,14 @@ steps: TITLE_PREFIX: ${{ inputs.title-prefix }} run: | set -euo pipefail + mkdir -p /tmp/gh-aw/agent gh issue list \ --repo "$GITHUB_REPOSITORY" \ --search "in:title \"$TITLE_PREFIX\"" \ --state all \ --limit 100 \ --json number,title,state \ - > /tmp/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/previous-findings.json; } + > /tmp/gh-aw/agent/previous-findings.json || { echo "::warning::Failed to fetch previous findings — dedup will be skipped"; echo "[]" > /tmp/gh-aw/agent/previous-findings.json; } - name: Repo-specific setup if: ${{ inputs.setup-commands != '' }} env: @@ -113,9 +114,9 @@ steps: ## Previous Findings -Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. +Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. -- Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. +- Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. diff --git a/.github/workflows/gh-aw-small-problem-fixer.lock.yml b/.github/workflows/gh-aw-small-problem-fixer.lock.yml index 920426bd..2c853107 100644 --- a/.github/workflows/gh-aw-small-problem-fixer.lock.yml +++ b/.github/workflows/gh-aw-small-problem-fixer.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4759ef726db931aef1ce68db26d98d564fc934c1abfe30ee92d0b010759fc369","body_hash":"a9851bb76738e4f9b6396a24ef3aae5ab754f3a54ce9d0485f810a39dc8befb9","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8a5584989b858c248ebd33a9188ccd637f074e755115f5650117a67401b22053","body_hash":"a9851bb76738e4f9b6396a24ef3aae5ab754f3a54ce9d0485f810a39dc8befb9","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","EXTRA_COMMIT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -705,35 +705,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1575,7 +1575,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-small-problem-fixer.md b/.github/workflows/gh-aw-small-problem-fixer.md index a7ce7315..2d3f6af5 100644 --- a/.github/workflows/gh-aw-small-problem-fixer.md +++ b/.github/workflows/gh-aw-small-problem-fixer.md @@ -13,7 +13,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-stale-issues-investigator.lock.yml b/.github/workflows/gh-aw-stale-issues-investigator.lock.yml index f58a454f..aa17e5d1 100644 --- a/.github/workflows/gh-aw-stale-issues-investigator.lock.yml +++ b/.github/workflows/gh-aw-stale-issues-investigator.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"18b1e995dc5a9ed0ec22de4c8f8c8784701daaf5ce97006de285fe77873bde20","body_hash":"2a9dcd9ab91ac088874d6203c02e69cd2a1673a451179e018f0c99d4b1ac136e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"513abc9711314e4cbac87b2ee71f5d636bfe651a2a7cb1ac71f32ce9e22b2618","body_hash":"749946b4d010fb50004bcca9a83e9478dcf1fbca69f7d0cef4a0609cb9bcd24e","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -324,20 +324,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_7ba9c1202495e673_EOF' + cat << 'GH_AW_PROMPT_98dcfff1a8be60f3_EOF' - GH_AW_PROMPT_7ba9c1202495e673_EOF + GH_AW_PROMPT_98dcfff1a8be60f3_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_7ba9c1202495e673_EOF' + cat << 'GH_AW_PROMPT_98dcfff1a8be60f3_EOF' Tools: create_issue, add_labels(max:10), missing_tool, missing_data, noop - GH_AW_PROMPT_7ba9c1202495e673_EOF + GH_AW_PROMPT_98dcfff1a8be60f3_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_7ba9c1202495e673_EOF' + cat << 'GH_AW_PROMPT_98dcfff1a8be60f3_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -366,9 +366,9 @@ jobs: {{/if}} - GH_AW_PROMPT_7ba9c1202495e673_EOF + GH_AW_PROMPT_98dcfff1a8be60f3_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_7ba9c1202495e673_EOF' + cat << 'GH_AW_PROMPT_98dcfff1a8be60f3_EOF' ## MCP Servers @@ -439,9 +439,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -622,7 +622,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_7ba9c1202495e673_EOF + GH_AW_PROMPT_98dcfff1a8be60f3_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -790,35 +790,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -837,7 +837,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ github.token }} name: Prescan open issues @@ -1657,7 +1657,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "60" diff --git a/.github/workflows/gh-aw-stale-issues-investigator.md b/.github/workflows/gh-aw-stale-issues-investigator.md index 5b27efd3..5dfd1a24 100644 --- a/.github/workflows/gh-aw-stale-issues-investigator.md +++ b/.github/workflows/gh-aw-stale-issues-investigator.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-stale-issues-remediator.lock.yml b/.github/workflows/gh-aw-stale-issues-remediator.lock.yml index 337e0dc7..ed46e5e6 100644 --- a/.github/workflows/gh-aw-stale-issues-remediator.lock.yml +++ b/.github/workflows/gh-aw-stale-issues-remediator.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c8d965ee1b66d7192efefb7ca1c56df41a004e77d51c4153d6a5780aaaf11f80","body_hash":"c187af23857467975150e1a433e914dac8f83989eb7a3075f7ffc020793aaa4c","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"674e29d95262a5c5adbf3503760369d6b48a418c6a77c7d446bf12baff5c7c52","body_hash":"3d0c0aa6f85e43d22e2de21a09935f3e3686c935506659cb806a02a28a560c6c","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -50,15 +50,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -309,20 +309,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_81387a7da37fe934_EOF' + cat << 'GH_AW_PROMPT_d88422cf23b73ad1_EOF' - GH_AW_PROMPT_81387a7da37fe934_EOF + GH_AW_PROMPT_d88422cf23b73ad1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_81387a7da37fe934_EOF' + cat << 'GH_AW_PROMPT_d88422cf23b73ad1_EOF' Tools: close_issue(max:10), remove_labels(max:10), missing_tool, missing_data, noop - GH_AW_PROMPT_81387a7da37fe934_EOF + GH_AW_PROMPT_d88422cf23b73ad1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_81387a7da37fe934_EOF' + cat << 'GH_AW_PROMPT_d88422cf23b73ad1_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -351,9 +351,9 @@ jobs: {{/if}} - GH_AW_PROMPT_81387a7da37fe934_EOF + GH_AW_PROMPT_d88422cf23b73ad1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_81387a7da37fe934_EOF' + cat << 'GH_AW_PROMPT_d88422cf23b73ad1_EOF' ## MCP Servers @@ -420,11 +420,11 @@ jobs: ### Data Files A prep step has already fetched: - - `/tmp/stale-labeled-issues.json` — all open issues labeled `__GH_AW_EXPR_AACB8011__` (fields: number, title, updatedAt, labels, createdAt) - - `/tmp/stale-recent-comments.json` — the last 5 comments on each stale-labeled issue (fields: author, createdAt, body) - - `/tmp/stale-label-events.json` — label add/remove timeline events (fields: number, event, created_at) + - `/tmp/gh-aw/agent/stale-labeled-issues.json` — all open issues labeled `__GH_AW_EXPR_AACB8011__` (fields: number, title, updatedAt, labels, createdAt) + - `/tmp/gh-aw/agent/stale-recent-comments.json` — the last 5 comments on each stale-labeled issue (fields: author, createdAt, body) + - `/tmp/gh-aw/agent/stale-label-events.json` — label add/remove timeline events (fields: number, event, created_at) - Start by reading these files to get an overview. If `/tmp/stale-labeled-issues.json` is empty or contains zero issues, call `noop` with message "No stale-labeled issues to process" and stop. + Start by reading these files to get an overview. If `/tmp/gh-aw/agent/stale-labeled-issues.json` is empty or contains zero issues, call `noop` with message "No stale-labeled issues to process" and stop. ### Processing Rules @@ -433,7 +433,7 @@ jobs: 1. **"Not stale" objections** — If any comment posted **after** the `__GH_AW_EXPR_AACB8011__` label was most recently added contains phrases like "not stale", "still relevant", "still needed", "still an issue", or "still a problem" (case-insensitive), call `remove_labels` to remove the `__GH_AW_EXPR_AACB8011__` label from the issue. Skip this issue from closure — the objection overrides the stale determination. - 2. **30-day expiry** — For issues with no such objection, compute the last labeled timestamp from `/tmp/stale-label-events.json` (find the most recent `"labeled"` event after any later `"unlabeled"` event for that issue number). If the label was added **30 or more days ago**, close the issue using `close_issue` with a comment explaining: + 2. **30-day expiry** — For issues with no such objection, compute the last labeled timestamp from `/tmp/gh-aw/agent/stale-label-events.json` (find the most recent `"labeled"` event after any later `"unlabeled"` event for that issue number). If the label was added **30 or more days ago**, close the issue using `close_issue` with a comment explaining: > This issue was labeled `__GH_AW_EXPR_AACB8011__` on [date] and has had no further activity for 30 days. Closing automatically. If this issue is still relevant, please reopen it. @@ -447,7 +447,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_81387a7da37fe934_EOF + GH_AW_PROMPT_d88422cf23b73ad1_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -614,35 +614,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -661,7 +661,7 @@ jobs: GH_TOKEN: ${{ github.token }} STALE_LABEL: ${{ inputs.stale-label }} name: Collect stale-labeled issues - run: "set -euo pipefail\n\n# Fetch all open issues carrying the stale label\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --label \"$STALE_LABEL\" \\\n --state open \\\n --limit 200 \\\n --json number,title,updatedAt,labels,createdAt \\\n > /tmp/stale-labeled-issues.json || { echo \"::warning::Failed to fetch stale-labeled issues\"; echo \"[]\" > /tmp/stale-labeled-issues.json; }\n\necho \"Stale-labeled issues: $(jq length /tmp/stale-labeled-issues.json)\"\n\n# For each stale-labeled issue, grab recent comments and label timeline events.\njq -c '.[]' /tmp/stale-labeled-issues.json | while IFS= read -r issue; do\n num=$(echo \"$issue\" | jq -r '.number')\n gh issue view \"$num\" \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --json comments \\\n --jq '.comments[-5:] | .[] | {author: .author.login, createdAt: .createdAt, body: .body[0:500]}' \\\n 2>/dev/null || true\ndone | jq -s '.' > /tmp/stale-recent-comments.json || echo \"[]\" > /tmp/stale-recent-comments.json\n\n# Fetch label add/remove events for each stale-labeled issue (for 30-day expiry)\njq -r '.[].number' /tmp/stale-labeled-issues.json | while IFS= read -r num; do\n gh api --paginate \"repos/$GITHUB_REPOSITORY/issues/$num/events\" 2>/dev/null \\\n | jq --arg lbl \"$STALE_LABEL\" --argjson num \"$num\" \\\n '[.[] | select((.event==\"labeled\" or .event==\"unlabeled\") and .label.name==$lbl) | {number: $num, event: .event, created_at: .created_at}]' \\\n || echo \"[]\"\ndone | jq -s 'add // []' > /tmp/stale-label-events.json || echo \"[]\" > /tmp/stale-label-events.json\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\n\n# Fetch all open issues carrying the stale label\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --label \"$STALE_LABEL\" \\\n --state open \\\n --limit 200 \\\n --json number,title,updatedAt,labels,createdAt \\\n > /tmp/gh-aw/agent/stale-labeled-issues.json || { echo \"::warning::Failed to fetch stale-labeled issues\"; echo \"[]\" > /tmp/gh-aw/agent/stale-labeled-issues.json; }\n\necho \"Stale-labeled issues: $(jq length /tmp/gh-aw/agent/stale-labeled-issues.json)\"\n\n# For each stale-labeled issue, grab recent comments and label timeline events.\njq -c '.[]' /tmp/gh-aw/agent/stale-labeled-issues.json | while IFS= read -r issue; do\n num=$(echo \"$issue\" | jq -r '.number')\n gh issue view \"$num\" \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --json comments \\\n --jq '.comments[-5:] | .[] | {author: .author.login, createdAt: .createdAt, body: .body[0:500]}' \\\n 2>/dev/null || true\ndone | jq -s '.' > /tmp/gh-aw/agent/stale-recent-comments.json || echo \"[]\" > /tmp/gh-aw/agent/stale-recent-comments.json\n\n# Fetch label add/remove events for each stale-labeled issue (for 30-day expiry)\njq -r '.[].number' /tmp/gh-aw/agent/stale-labeled-issues.json | while IFS= read -r num; do\n gh api --paginate \"repos/$GITHUB_REPOSITORY/issues/$num/events\" 2>/dev/null \\\n | jq --arg lbl \"$STALE_LABEL\" --argjson num \"$num\" \\\n '[.[] | select((.event==\"labeled\" or .event==\"unlabeled\") and .label.name==$lbl) | {number: $num, event: .event, created_at: .created_at}]' \\\n || echo \"[]\"\ndone | jq -s 'add // []' > /tmp/gh-aw/agent/stale-label-events.json || echo \"[]\" > /tmp/gh-aw/agent/stale-label-events.json\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1474,7 +1474,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-stale-issues-remediator.md b/.github/workflows/gh-aw-stale-issues-remediator.md index 7acdc5f3..f5b3b04e 100644 --- a/.github/workflows/gh-aw-stale-issues-remediator.md +++ b/.github/workflows/gh-aw-stale-issues-remediator.md @@ -12,7 +12,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -88,6 +88,7 @@ steps: STALE_LABEL: ${{ inputs.stale-label }} run: | set -euo pipefail + mkdir -p /tmp/gh-aw/agent # Fetch all open issues carrying the stale label gh issue list \ @@ -96,27 +97,27 @@ steps: --state open \ --limit 200 \ --json number,title,updatedAt,labels,createdAt \ - > /tmp/stale-labeled-issues.json || { echo "::warning::Failed to fetch stale-labeled issues"; echo "[]" > /tmp/stale-labeled-issues.json; } + > /tmp/gh-aw/agent/stale-labeled-issues.json || { echo "::warning::Failed to fetch stale-labeled issues"; echo "[]" > /tmp/gh-aw/agent/stale-labeled-issues.json; } - echo "Stale-labeled issues: $(jq length /tmp/stale-labeled-issues.json)" + echo "Stale-labeled issues: $(jq length /tmp/gh-aw/agent/stale-labeled-issues.json)" # For each stale-labeled issue, grab recent comments and label timeline events. - jq -c '.[]' /tmp/stale-labeled-issues.json | while IFS= read -r issue; do + jq -c '.[]' /tmp/gh-aw/agent/stale-labeled-issues.json | while IFS= read -r issue; do num=$(echo "$issue" | jq -r '.number') gh issue view "$num" \ --repo "$GITHUB_REPOSITORY" \ --json comments \ --jq '.comments[-5:] | .[] | {author: .author.login, createdAt: .createdAt, body: .body[0:500]}' \ 2>/dev/null || true - done | jq -s '.' > /tmp/stale-recent-comments.json || echo "[]" > /tmp/stale-recent-comments.json + done | jq -s '.' > /tmp/gh-aw/agent/stale-recent-comments.json || echo "[]" > /tmp/gh-aw/agent/stale-recent-comments.json # Fetch label add/remove events for each stale-labeled issue (for 30-day expiry) - jq -r '.[].number' /tmp/stale-labeled-issues.json | while IFS= read -r num; do + jq -r '.[].number' /tmp/gh-aw/agent/stale-labeled-issues.json | while IFS= read -r num; do gh api --paginate "repos/$GITHUB_REPOSITORY/issues/$num/events" 2>/dev/null \ | jq --arg lbl "$STALE_LABEL" --argjson num "$num" \ '[.[] | select((.event=="labeled" or .event=="unlabeled") and .label.name==$lbl) | {number: $num, event: .event, created_at: .created_at}]' \ || echo "[]" - done | jq -s 'add // []' > /tmp/stale-label-events.json || echo "[]" > /tmp/stale-label-events.json + done | jq -s 'add // []' > /tmp/gh-aw/agent/stale-label-events.json || echo "[]" > /tmp/gh-aw/agent/stale-label-events.json - name: Repo-specific setup if: ${{ inputs.setup-commands != '' }} env: @@ -131,11 +132,11 @@ Process open issues that carry the `${{ inputs.stale-label }}` label. Handle obj ### Data Files A prep step has already fetched: -- `/tmp/stale-labeled-issues.json` — all open issues labeled `${{ inputs.stale-label }}` (fields: number, title, updatedAt, labels, createdAt) -- `/tmp/stale-recent-comments.json` — the last 5 comments on each stale-labeled issue (fields: author, createdAt, body) -- `/tmp/stale-label-events.json` — label add/remove timeline events (fields: number, event, created_at) +- `/tmp/gh-aw/agent/stale-labeled-issues.json` — all open issues labeled `${{ inputs.stale-label }}` (fields: number, title, updatedAt, labels, createdAt) +- `/tmp/gh-aw/agent/stale-recent-comments.json` — the last 5 comments on each stale-labeled issue (fields: author, createdAt, body) +- `/tmp/gh-aw/agent/stale-label-events.json` — label add/remove timeline events (fields: number, event, created_at) -Start by reading these files to get an overview. If `/tmp/stale-labeled-issues.json` is empty or contains zero issues, call `noop` with message "No stale-labeled issues to process" and stop. +Start by reading these files to get an overview. If `/tmp/gh-aw/agent/stale-labeled-issues.json` is empty or contains zero issues, call `noop` with message "No stale-labeled issues to process" and stop. ### Processing Rules @@ -144,7 +145,7 @@ For each open issue labeled `${{ inputs.stale-label }}`, fetch the full comment 1. **"Not stale" objections** — If any comment posted **after** the `${{ inputs.stale-label }}` label was most recently added contains phrases like "not stale", "still relevant", "still needed", "still an issue", or "still a problem" (case-insensitive), call `remove_labels` to remove the `${{ inputs.stale-label }}` label from the issue. Skip this issue from closure — the objection overrides the stale determination. -2. **30-day expiry** — For issues with no such objection, compute the last labeled timestamp from `/tmp/stale-label-events.json` (find the most recent `"labeled"` event after any later `"unlabeled"` event for that issue number). If the label was added **30 or more days ago**, close the issue using `close_issue` with a comment explaining: +2. **30-day expiry** — For issues with no such objection, compute the last labeled timestamp from `/tmp/gh-aw/agent/stale-label-events.json` (find the most recent `"labeled"` event after any later `"unlabeled"` event for that issue number). If the label was added **30 or more days ago**, close the issue using `close_issue` with a comment explaining: > This issue was labeled `${{ inputs.stale-label }}` on [date] and has had no further activity for 30 days. Closing automatically. If this issue is still relevant, please reopen it. diff --git a/.github/workflows/gh-aw-test-coverage-detector.lock.yml b/.github/workflows/gh-aw-test-coverage-detector.lock.yml index 8b92ab01..b38cdab2 100644 --- a/.github/workflows/gh-aw-test-coverage-detector.lock.yml +++ b/.github/workflows/gh-aw-test-coverage-detector.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e0b1b059f2805a4d9c6e7f34d73de2cdc61d0691da4639eecd096665e642057e","body_hash":"10753fdfaf067807319a6c8e799e75d70fa051238f5de8198b381afeab3c3588","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"a47d551f7d3b88e94385e8fefdfb2f5f5f25ccb7bd1e2688d718e28ac00390d9","body_hash":"10c26807a47aba8253019d2d3cbe9a308feffe400db8877dd5668bba44c470ce","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -328,20 +328,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_b69c1c793fd75551_EOF' + cat << 'GH_AW_PROMPT_541991ef65c701b1_EOF' - GH_AW_PROMPT_b69c1c793fd75551_EOF + GH_AW_PROMPT_541991ef65c701b1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_b69c1c793fd75551_EOF' + cat << 'GH_AW_PROMPT_541991ef65c701b1_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_b69c1c793fd75551_EOF + GH_AW_PROMPT_541991ef65c701b1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_b69c1c793fd75551_EOF' + cat << 'GH_AW_PROMPT_541991ef65c701b1_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -370,9 +370,9 @@ jobs: {{/if}} - GH_AW_PROMPT_b69c1c793fd75551_EOF + GH_AW_PROMPT_541991ef65c701b1_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_b69c1c793fd75551_EOF' + cat << 'GH_AW_PROMPT_541991ef65c701b1_EOF' ## MCP Servers @@ -443,9 +443,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -655,7 +655,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_b69c1c793fd75551_EOF + GH_AW_PROMPT_541991ef65c701b1_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -830,35 +830,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -877,7 +877,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: SEVERITY_THRESHOLD: ${{ inputs.severity-threshold }} name: Validate severity threshold @@ -1678,7 +1678,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-test-coverage-detector.md b/.github/workflows/gh-aw-test-coverage-detector.md index 70fcebe6..6f439572 100644 --- a/.github/workflows/gh-aw-test-coverage-detector.md +++ b/.github/workflows/gh-aw-test-coverage-detector.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/code-quality-audit.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-text-auditor.lock.yml b/.github/workflows/gh-aw-text-auditor.lock.yml index e81fbe30..4a3b769f 100644 --- a/.github/workflows/gh-aw-text-auditor.lock.yml +++ b/.github/workflows/gh-aw-text-auditor.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ef6d272629a548450c1b9a2dff38c565e3b92b599e18e47aa9946bfb5b0a6c4c","body_hash":"891c64c474681cc9168ea83ffbad2b9ee11b8e42ce81cbfac9a09e8b7cbf616f","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f7cae08266ca9f174690c4fdd09da92a0e7b36ab19d0d5b1f8d6609a661e21de","body_hash":"046429c28e5545287e143a3a4940ac51d4cb3c51aef93856c19a511a3567f50d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -54,15 +54,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -351,20 +351,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_882ec6986b7f6e84_EOF' + cat << 'GH_AW_PROMPT_448102590fc2d0d4_EOF' - GH_AW_PROMPT_882ec6986b7f6e84_EOF + GH_AW_PROMPT_448102590fc2d0d4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_882ec6986b7f6e84_EOF' + cat << 'GH_AW_PROMPT_448102590fc2d0d4_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_882ec6986b7f6e84_EOF + GH_AW_PROMPT_448102590fc2d0d4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_882ec6986b7f6e84_EOF' + cat << 'GH_AW_PROMPT_448102590fc2d0d4_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -393,9 +393,9 @@ jobs: {{/if}} - GH_AW_PROMPT_882ec6986b7f6e84_EOF + GH_AW_PROMPT_448102590fc2d0d4_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_882ec6986b7f6e84_EOF' + cat << 'GH_AW_PROMPT_448102590fc2d0d4_EOF' ## MCP Servers @@ -466,9 +466,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep Many @@ -591,7 +591,7 @@ jobs: - In each sub-agent prompt, include identified text sources, edit-level configuration, and the full "What to Look For by Dimension" and "What to Skip" criteria. - Wait for all three results, then merge and deduplicate before proceeding. 3. Read the identified files and search for text issues. - 4. Before deciding to file, check `/tmp/previous-findings.json` and current open `__GH_AW_EXPR_BF503D80__` issues to avoid creating a new issue for already-tracked typo families. + 4. Before deciding to file, check `/tmp/gh-aw/agent/previous-findings.json` and current open `__GH_AW_EXPR_BF503D80__` issues to avoid creating a new issue for already-tracked typo families. ### What to Look For by Dimension @@ -665,7 +665,7 @@ jobs: Score the run on these four criteria: - 1. **Novelty** — findings are not already tracked in open `__GH_AW_EXPR_BF503D80__` issues or `/tmp/previous-findings.json` + 1. **Novelty** — findings are not already tracked in open `__GH_AW_EXPR_BF503D80__` issues or `/tmp/gh-aw/agent/previous-findings.json` 2. **Materiality** — at least one finding clearly improves user-facing runtime/help/CLI/docs text quality 3. **Batch quality** — findings are meaningfully consolidated (not fragmented into many tiny one-off reports) 4. **Actionability** — each finding includes exact file path, concrete current text, and a defensible suggested fix @@ -718,7 +718,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_882ec6986b7f6e84_EOF + GH_AW_PROMPT_448102590fc2d0d4_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -904,35 +904,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -951,7 +951,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1748,7 +1748,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-text-auditor.md b/.github/workflows/gh-aw-text-auditor.md index b1231a73..5f0d346e 100644 --- a/.github/workflows/gh-aw-text-auditor.md +++ b/.github/workflows/gh-aw-text-auditor.md @@ -16,7 +16,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: @@ -152,7 +152,7 @@ Level semantics: - In each sub-agent prompt, include identified text sources, edit-level configuration, and the full "What to Look For by Dimension" and "What to Skip" criteria. - Wait for all three results, then merge and deduplicate before proceeding. 3. Read the identified files and search for text issues. -4. Before deciding to file, check `/tmp/previous-findings.json` and current open `${{ inputs.title-prefix }}` issues to avoid creating a new issue for already-tracked typo families. +4. Before deciding to file, check `/tmp/gh-aw/agent/previous-findings.json` and current open `${{ inputs.title-prefix }}` issues to avoid creating a new issue for already-tracked typo families. ### What to Look For by Dimension @@ -226,7 +226,7 @@ Use this sequence to decide `create_issue` vs `noop`: Score the run on these four criteria: -1. **Novelty** — findings are not already tracked in open `${{ inputs.title-prefix }}` issues or `/tmp/previous-findings.json` +1. **Novelty** — findings are not already tracked in open `${{ inputs.title-prefix }}` issues or `/tmp/gh-aw/agent/previous-findings.json` 2. **Materiality** — at least one finding clearly improves user-facing runtime/help/CLI/docs text quality 3. **Batch quality** — findings are meaningfully consolidated (not fragmented into many tiny one-off reports) 4. **Actionability** — each finding includes exact file path, concrete current text, and a defensible suggested fix diff --git a/.github/workflows/gh-aw-update-pr-body.lock.yml b/.github/workflows/gh-aw-update-pr-body.lock.yml index 9be84d6b..96c90198 100644 --- a/.github/workflows/gh-aw-update-pr-body.lock.yml +++ b/.github/workflows/gh-aw-update-pr-body.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"cf244e2c345ed02b094fbb223b37a379e7630c82474ce7aa8c429b3fa5618958","body_hash":"b8091dc990f73f97eb45e7b2c5612a1a5a5fe4e682cf67753af3f05c8817cedd","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"fdbd8032ab906566340dcdccb3d4ded1878a3c65d573031161fa0ac2283359dd","body_hash":"b8091dc990f73f97eb45e7b2c5612a1a5a5fe4e682cf67753af3f05c8817cedd","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -50,15 +50,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -760,35 +760,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -1597,7 +1597,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\nThe body of this PR [is automatically managed](https://ela.st/github-ai-tools) by the [{0} workflow]({{run_url}}).', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "30" diff --git a/.github/workflows/gh-aw-update-pr-body.md b/.github/workflows/gh-aw-update-pr-body.md index dc950196..90aee617 100644 --- a/.github/workflows/gh-aw-update-pr-body.md +++ b/.github/workflows/gh-aw-update-pr-body.md @@ -12,9 +12,9 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} concurrency: group: "gh-aw-copilot-${{ github.workflow }}-update-pr-body-${{ github.event.pull_request.number }}" +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/gh-aw-ux-design-patrol.lock.yml b/.github/workflows/gh-aw-ux-design-patrol.lock.yml index f507cf0e..bedeb8fd 100644 --- a/.github/workflows/gh-aw-ux-design-patrol.lock.yml +++ b/.github/workflows/gh-aw-ux-design-patrol.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8c2e836e9f391f43ac98521e7c96a56411d548276ee1744d18062da303265117","body_hash":"d8b4135dd0b42b38c25c902d3d74b1028d963f005c951b886a345e6a38ceeb02","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"31d54c95f22c6de1c25839a8880fde6e4cd2e6d139eb6f8c62a927e1199824fe","body_hash":"ca2202ba08aba5abe7a35b84e18edc27d99fdcdacf7d22f283d08fae3113b3a2","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -55,15 +55,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -327,20 +327,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_3697572cc698f186_EOF' + cat << 'GH_AW_PROMPT_c99b18a176f332a6_EOF' - GH_AW_PROMPT_3697572cc698f186_EOF + GH_AW_PROMPT_c99b18a176f332a6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_3697572cc698f186_EOF' + cat << 'GH_AW_PROMPT_c99b18a176f332a6_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_3697572cc698f186_EOF + GH_AW_PROMPT_c99b18a176f332a6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_3697572cc698f186_EOF' + cat << 'GH_AW_PROMPT_c99b18a176f332a6_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -369,9 +369,9 @@ jobs: {{/if}} - GH_AW_PROMPT_3697572cc698f186_EOF + GH_AW_PROMPT_c99b18a176f332a6_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_3697572cc698f186_EOF' + cat << 'GH_AW_PROMPT_c99b18a176f332a6_EOF' ## MCP Servers @@ -443,9 +443,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -617,7 +617,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_3697572cc698f186_EOF + GH_AW_PROMPT_c99b18a176f332a6_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -788,35 +788,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -841,7 +841,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1638,7 +1638,7 @@ jobs: GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"${{ inputs.messages-footer || format('---\\n[What is this?](https://ela.st/github-ai-tools) | [From workflow: {0}]({{run_url}})\\n\\nGive us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.', github.workflow) }}\",\"activationComments\":\"false\"}" GH_AW_GROUP_REPORTS: "false" - GH_AW_FAILURE_REPORT_AS_ISSUE: ${{ inputs.report-failure-as-issue && 'true' || 'false' }} + GH_AW_FAILURE_REPORT_AS_ISSUE: "true" GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" GH_AW_TIMEOUT_MINUTES: "90" diff --git a/.github/workflows/gh-aw-ux-design-patrol.md b/.github/workflows/gh-aw-ux-design-patrol.md index ad563d50..8121d387 100644 --- a/.github/workflows/gh-aw-ux-design-patrol.md +++ b/.github/workflows/gh-aw-ux-design-patrol.md @@ -17,7 +17,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/internal-downstream-health.lock.yml b/.github/workflows/internal-downstream-health.lock.yml index 77fd26b3..05264fcd 100644 --- a/.github/workflows/internal-downstream-health.lock.yml +++ b/.github/workflows/internal-downstream-health.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"b9520672b1cfdb4c8708da6f10a021bcaba25fb829db7a8b797ef322f9df0cad","body_hash":"80aabfa8dfb0fe536ef2a191a72c6794d15e5328940c08d00a65bcc7eb4ea68d","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"bda7ac678c3e8f4ebe004f8042555d2a66d82ad979d21e9808575b693fec9262","body_hash":"f6693bdc3f49402e8b59a3f6b0c22b1e699355bfd1c4544a0ddcbf2d86b4d8c5","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -313,20 +313,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_d68915d5526ecaa8_EOF' + cat << 'GH_AW_PROMPT_bf5cbe935f5c7748_EOF' - GH_AW_PROMPT_d68915d5526ecaa8_EOF + GH_AW_PROMPT_bf5cbe935f5c7748_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_d68915d5526ecaa8_EOF' + cat << 'GH_AW_PROMPT_bf5cbe935f5c7748_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_d68915d5526ecaa8_EOF + GH_AW_PROMPT_bf5cbe935f5c7748_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_d68915d5526ecaa8_EOF' + cat << 'GH_AW_PROMPT_bf5cbe935f5c7748_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -355,9 +355,9 @@ jobs: {{/if}} - GH_AW_PROMPT_d68915d5526ecaa8_EOF + GH_AW_PROMPT_bf5cbe935f5c7748_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_d68915d5526ecaa8_EOF' + cat << 'GH_AW_PROMPT_bf5cbe935f5c7748_EOF' ## MCP Servers @@ -428,9 +428,9 @@ jobs: - **Mentions**: `@mentions` in the body are neutralized (backticked). ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below. @@ -612,7 +612,7 @@ jobs: __GH_AW_EXPR_49B959F1__ - GH_AW_PROMPT_d68915d5526ecaa8_EOF + GH_AW_PROMPT_bf5cbe935f5c7748_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -778,35 +778,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -825,7 +825,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/internal-downstream-health.md b/.github/workflows/internal-downstream-health.md index cdbcbe28..9ada0732 100644 --- a/.github/workflows/internal-downstream-health.md +++ b/.github/workflows/internal-downstream-health.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: ${{ inputs.model }} +model: ${{ inputs.model }} on: stale-check: false workflow_call: diff --git a/.github/workflows/upgrade-check.lock.yml b/.github/workflows/upgrade-check.lock.yml index 8360c59a..c3a4ee48 100644 --- a/.github/workflows/upgrade-check.lock.yml +++ b/.github/workflows/upgrade-check.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6b1462500bc0fccf8aca78946562ee46b39d8e0ae65b52326ac15973cc1ce6f4","body_hash":"a504874616846b02dd4a6ed697942aa0744c0f4e7076326af488464e0cfa0009","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"84ef85be6413beeb876f5f77da7fac9902006074bee988aac66d0c3d098b4459","body_hash":"f91a47fbf81d980d1b74980bb443eaa7965031431563ed58744b31b55a51304b","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -80,7 +80,7 @@ on: # - maintainer # Roles processed as role check in pre-activation job # - write # Roles processed as role check in pre-activation job schedule: - - cron: "29 13 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) + - cron: "20 13 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) # stale-check: false # Stale-check processed as frontmatter hash check step in activation job workflow_dispatch: inputs: @@ -275,20 +275,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_8b4fdc651a0648b0_EOF' + cat << 'GH_AW_PROMPT_572035632a9f3f70_EOF' - GH_AW_PROMPT_8b4fdc651a0648b0_EOF + GH_AW_PROMPT_572035632a9f3f70_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_8b4fdc651a0648b0_EOF' + cat << 'GH_AW_PROMPT_572035632a9f3f70_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_8b4fdc651a0648b0_EOF + GH_AW_PROMPT_572035632a9f3f70_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_8b4fdc651a0648b0_EOF' + cat << 'GH_AW_PROMPT_572035632a9f3f70_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -317,9 +317,9 @@ jobs: {{/if}} - GH_AW_PROMPT_8b4fdc651a0648b0_EOF + GH_AW_PROMPT_572035632a9f3f70_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_8b4fdc651a0648b0_EOF' + cat << 'GH_AW_PROMPT_572035632a9f3f70_EOF' ## MCP Servers @@ -449,9 +449,9 @@ jobs: ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -548,7 +548,7 @@ jobs: > - [ ] Run `make compile` and verify 0 errors, 0 warnings > - [ ] [Any other specific steps] - GH_AW_PROMPT_8b4fdc651a0648b0_EOF + GH_AW_PROMPT_572035632a9f3f70_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -711,35 +711,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -758,7 +758,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - name: Configure Git credentials env: diff --git a/.github/workflows/upgrade-check.md b/.github/workflows/upgrade-check.md index c32cdc0b..11b19c25 100644 --- a/.github/workflows/upgrade-check.md +++ b/.github/workflows/upgrade-check.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: gpt-5.3-codex +model: gpt-5.3-codex on: stale-check: false schedule: diff --git a/.github/workflows/workflow-patrol.lock.yml b/.github/workflows/workflow-patrol.lock.yml index 6efc3887..f60cb8c2 100644 --- a/.github/workflows/workflow-patrol.lock.yml +++ b/.github/workflows/workflow-patrol.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"662c22024681f2b51e6778a636396731eb15c8118557902a40883247c4dec2db","body_hash":"458b05e062a2387e9c5748bb5a2b41c9ee0148accb4e9c685e430b4018d2cfd0","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"","version":"v1.319.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"62bf0c37c23d198202199d155029da99a01cc4df11cdd22a2cd02ae2300a2127","body_hash":"ea42387c50ce9fc1f951458c3b3d312c706e0005abacd46360cab6c28a50d0a8","compiler_version":"v0.82.14","agent_id":"copilot","agent_model":"gpt-5.3-codex","engine_versions":{"copilot":"1.0.71"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0 (source v7)"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0 (source v6)"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"11f9893b081a58869d3b5fccaea48c9e9e46f990","version":"v8.3.2 (source v8)"},{"repo":"github/gh-aw-actions/setup-cli","sha":"b6d1443e05b8716267fa19425b99aa4f12006b4a","version":"v0.82.14"},{"repo":"github/gh-aw/actions/setup","sha":"8b820ae1073f301991aaf2f307f7e271f618bb9f","version":"v0.82.14"},{"repo":"ruby/setup-ruby","sha":"v1","version":"v1"}],"resolution_failures":[{"repo":"ruby/setup-ruby","ref":"v1","error_type":"dynamic_resolution_failed"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw (v0.82.14). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -53,15 +53,15 @@ # - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 # - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9 # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 -# - actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 -# - actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 +# - actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 -# - actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 +# - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) +# - actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 +# - astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) # - github/gh-aw-actions/setup-cli@b6d1443e05b8716267fa19425b99aa4f12006b4a # v0.82.14 # - github/gh-aw/actions/setup@8b820ae1073f301991aaf2f307f7e271f618bb9f # v0.82.14 -# - ruby/setup-ruby@ # v1.319.0 (source v1) +# - ruby/setup-ruby@v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 @@ -80,7 +80,7 @@ on: # - maintainer # Roles processed as role check in pre-activation job # - write # Roles processed as role check in pre-activation job schedule: - - cron: "52 13 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) + - cron: "5 13 * * 1-5" # Friendly format: daily around 14:00 on weekdays (scattered) # stale-check: false # Stale-check processed as frontmatter hash check step in activation job workflow_dispatch: inputs: @@ -275,20 +275,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF' + cat << 'GH_AW_PROMPT_cb1b5ede7e78268d_EOF' - GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF + GH_AW_PROMPT_cb1b5ede7e78268d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF' + cat << 'GH_AW_PROMPT_cb1b5ede7e78268d_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF + GH_AW_PROMPT_cb1b5ede7e78268d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF' + cat << 'GH_AW_PROMPT_cb1b5ede7e78268d_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -317,9 +317,9 @@ jobs: {{/if}} - GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF + GH_AW_PROMPT_cb1b5ede7e78268d_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF' + cat << 'GH_AW_PROMPT_cb1b5ede7e78268d_EOF' ## MCP Servers @@ -449,9 +449,9 @@ jobs: ## Previous Findings - Before filing a new issue, check `/tmp/previous-findings.json` for issues this agent has already filed. + Before filing a new issue, check `/tmp/gh-aw/agent/previous-findings.json` for issues this agent has already filed. - - Run `cat /tmp/previous-findings.json` to read the list of previously filed issue numbers and titles. + - Run `cat /tmp/gh-aw/agent/previous-findings.json` to read the list of previously filed issue numbers and titles. - If your finding closely matches an open or recently-closed issue in that list, call `noop` instead of filing a duplicate. - Only file a new issue when the finding is genuinely distinct from all previous findings. ### Pick Three, Keep One @@ -538,7 +538,7 @@ jobs: End with a checklist of actionable items, one per finding. - GH_AW_PROMPT_8a3b1b8cb3d0eb4d_EOF + GH_AW_PROMPT_cb1b5ede7e78268d_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -701,35 +701,35 @@ jobs: path: /tmp/gh-aw - if: hashFiles('go.mod') != '' name: Setup Go - uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 (source v7) with: cache: true go-version-file: go.mod - if: hashFiles('.python-version') != '' name: Setup Python - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 + uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 (source v6) with: python-version-file: .python-version - if: hashFiles('.node-version') != '' name: Setup Node.js (.node-version) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .node-version - if: hashFiles('.node-version') == '' && hashFiles('.nvmrc') != '' name: Setup Node.js (.nvmrc) - uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 (source v7) with: node-version-file: .nvmrc - if: hashFiles('.ruby-version') != '' name: Setup Ruby - uses: ruby/setup-ruby@ # v1.319.0 (source v1) + uses: ruby/setup-ruby@v1 with: bundler-cache: true ruby-version: .ruby-version - id: setup-uv if: hashFiles('pyproject.toml', 'uv.lock') != '' name: Setup uv - uses: astral-sh/setup-uv@e58605a9b6da7c637471fab8847a5e5a6b8df081 # v5 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 (source v8) - env: UV_PATH: ${{ steps.setup-uv.outputs.uv-path }} if: hashFiles('pyproject.toml', 'uv.lock') != '' @@ -748,7 +748,7 @@ jobs: GH_TOKEN: ${{ github.token }} TITLE_PREFIX: ${{ inputs.title-prefix }} name: List previous findings - run: "set -euo pipefail\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/previous-findings.json; }\n" + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/agent\ngh issue list \\\n --repo \"$GITHUB_REPOSITORY\" \\\n --search \"in:title \\\"$TITLE_PREFIX\\\"\" \\\n --state all \\\n --limit 100 \\\n --json number,title,state \\\n > /tmp/gh-aw/agent/previous-findings.json || { echo \"::warning::Failed to fetch previous findings — dedup will be skipped\"; echo \"[]\" > /tmp/gh-aw/agent/previous-findings.json; }\n" - name: Configure Git credentials env: diff --git a/.github/workflows/workflow-patrol.md b/.github/workflows/workflow-patrol.md index 531bd61f..d37fb9b8 100644 --- a/.github/workflows/workflow-patrol.md +++ b/.github/workflows/workflow-patrol.md @@ -15,7 +15,7 @@ imports: - gh-aw-fragments/network-ecosystems.md engine: id: copilot - model: gpt-5.3-codex +model: gpt-5.3-codex on: stale-check: false schedule: