diff --git a/.github/workflows/claude-token-optimizer.lock.yml b/.github/workflows/claude-token-optimizer.lock.yml index 00b3f449..22f831bd 100644 --- a/.github/workflows/claude-token-optimizer.lock.yml +++ b/.github/workflows/claude-token-optimizer.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"2411820c88f5375c13dad739e702b3a44884bafefd727f337acff508351fe29e","compiler_version":"v0.72.1","strict":true,"agent_id":"copilot"} +# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"2c82ce3d82443275e002aa31ce0a3b374168d4ef9557cc51b1bcf357032e7ef7","compiler_version":"v0.72.1","strict":true,"agent_id":"copilot"} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"bc56a0cad2f450c562810785ef38649c04db812a","version":"v0.72.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.25.29","digest":"sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.25.29@sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29","digest":"sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29@sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.25.29","digest":"sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.25.29@sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.6","digest":"sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.6@sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c"},{"image":"ghcr.io/github/github-mcp-server:v1.0.3","digest":"sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959","pinned_image":"ghcr.io/github/github-mcp-server:v1.0.3@sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959"},{"image":"node:lts-alpine","digest":"sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f","pinned_image":"node:lts-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f"}]} # ___ _ _ # / _ \ | | (_) @@ -142,6 +142,15 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false + sparse-checkout: | + .github + .agents + .claude + .codex + .crush + .gemini + .opencode + .pi sparse-checkout-cone-mode: true fetch-depth: 1 - name: Save agent config folders for base branch restoration @@ -188,20 +197,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_8b664a185cd4a2cc_EOF' + cat << 'GH_AW_PROMPT_f3af41a5fc18fb3a_EOF' - GH_AW_PROMPT_8b664a185cd4a2cc_EOF + GH_AW_PROMPT_f3af41a5fc18fb3a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_8b664a185cd4a2cc_EOF' + cat << 'GH_AW_PROMPT_f3af41a5fc18fb3a_EOF' Tools: create_issue, missing_tool, missing_data, noop - GH_AW_PROMPT_8b664a185cd4a2cc_EOF + GH_AW_PROMPT_f3af41a5fc18fb3a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_8b664a185cd4a2cc_EOF' + cat << 'GH_AW_PROMPT_f3af41a5fc18fb3a_EOF' The following GitHub context information is available for this workflow: {{#if __GH_AW_GITHUB_ACTOR__ }} @@ -230,13 +239,13 @@ jobs: {{/if}} - GH_AW_PROMPT_8b664a185cd4a2cc_EOF + GH_AW_PROMPT_f3af41a5fc18fb3a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_8b664a185cd4a2cc_EOF' + cat << 'GH_AW_PROMPT_f3af41a5fc18fb3a_EOF' {{#runtime-import .github/workflows/shared/mcp/gh-aw.md}} {{#runtime-import .github/workflows/claude-token-optimizer.md}} - GH_AW_PROMPT_8b664a185cd4a2cc_EOF + GH_AW_PROMPT_f3af41a5fc18fb3a_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -385,7 +394,7 @@ jobs: name: List workflows already covered by open optimization issues run: "set -euo pipefail\n\necho \"🔍 Checking for open optimization issues...\"\n\n# Fetch open optimization issues and extract workflow names from titles\n# Title format: \"⚡ Claude Token Optimization YYYY-MM-DD — \"\nif ! gh issue list --repo \"$GITHUB_REPOSITORY\" \\\n --label claude-token-optimization \\\n --state open --limit 50 \\\n --json title -q '.[].title' \\\n| sed -n 's/.*— //p' \\\n| sort -u > /tmp/gh-aw/token-audit/already-optimized.txt; then\n echo \"âš ī¸ Failed to list open optimization issues; proceeding with an empty exclusion list\"\n : > /tmp/gh-aw/token-audit/already-optimized.txt\nfi\n\nCOUNT=$(wc -l < /tmp/gh-aw/token-audit/already-optimized.txt | tr -d ' ')\nif [ \"$COUNT\" -gt 0 ]; then\n echo \"â­ī¸ $COUNT workflow(s) already have open optimization issues:\"\n cat /tmp/gh-aw/token-audit/already-optimized.txt\nelse\n echo \"✅ No open optimization issues — all workflows are eligible\"\nfi\n" - name: Identify top workflow and stage its file - run: "set -euo pipefail\n\necho \"📊 Selecting the top Claude workflow candidate...\"\n\nEXCLUDED_JSON=$(jq -R -s 'split(\"\\n\") | map(select(length > 0))' /tmp/gh-aw/token-audit/already-optimized.txt 2>/dev/null || echo '[]')\n\nTOP_WORKFLOW=$(jq -r --argjson excluded \"$EXCLUDED_JSON\" '\n [.runs[] | select(.token_usage != null and (.workflow_name // \"\") != \"\") | {workflow_name, token_usage}]\n | sort_by(.workflow_name)\n | group_by(.workflow_name)\n | map({\n name: .[0].workflow_name,\n average_token_usage: (map(.token_usage) | add / length)\n })\n | map(select(.name as $name | ($excluded | index($name)) == null))\n | sort_by(.average_token_usage)\n | reverse\n | .[0].name // \"\"\n' /tmp/gh-aw/token-audit/claude-logs.json)\n\necho \"TOP_WORKFLOW=${TOP_WORKFLOW}\" >> \"$GITHUB_ENV\"\n\nif [ -z \"$TOP_WORKFLOW\" ]; then\n echo \"â„šī¸ No eligible Claude workflow found in the downloaded run data\"\n echo \"WORKFLOW_FILE=\" >> \"$GITHUB_ENV\"\n echo \"TARGET_NOT_FOUND=1\" >> \"$GITHUB_ENV\"\n touch /tmp/gh-aw/token-audit/target-workflow.md\n exit 0\nfi\n\nKEBAB=$(printf '%s' \"$TOP_WORKFLOW\" | tr '[:upper:]' '[:lower:]' | sed -E 's/[^a-z0-9]+/-/g; s/^-+|-+$//g')\nFILE=$(grep -Flx -- \"name: ${TOP_WORKFLOW}\" .github/workflows/*.md 2>/dev/null | head -1)\n[ -z \"$FILE\" ] && FILE=\".github/workflows/${KEBAB}.md\"\n\necho \"WORKFLOW_FILE=${FILE}\" >> \"$GITHUB_ENV\"\n\nif [ -f \"$FILE\" ]; then\n cp \"$FILE\" /tmp/gh-aw/token-audit/target-workflow.md\n echo \"✅ Top workflow: ${TOP_WORKFLOW} → ${FILE}\"\nelse\n echo \"âš ī¸ Unable to locate workflow file for ${TOP_WORKFLOW}\"\n echo \"TARGET_NOT_FOUND=1\" >> \"$GITHUB_ENV\"\n touch /tmp/gh-aw/token-audit/target-workflow.md\nfi\n" + run: "set -euo pipefail\n\necho \"📊 Selecting the top Claude workflow candidate...\"\n\nEXCLUDED_JSON=$(jq -R -s 'split(\"\\n\") | map(select(length > 0))' /tmp/gh-aw/token-audit/already-optimized.txt 2>/dev/null || echo '[]')\n\nTOP_WORKFLOW=$(jq -r --argjson excluded \"$EXCLUDED_JSON\" '\n [.runs[] | select(.token_usage != null and (.workflow_name // \"\") != \"\") | {workflow_name, token_usage}]\n | sort_by(.workflow_name)\n | group_by(.workflow_name)\n | map({\n name: .[0].workflow_name,\n average_token_usage: (map(.token_usage) | add / length)\n })\n | map(select(.name as $name | ($excluded | index($name)) == null))\n | sort_by(.average_token_usage)\n | reverse\n | .[0].name // \"\"\n' /tmp/gh-aw/token-audit/claude-logs.json)\n\necho \"TOP_WORKFLOW=${TOP_WORKFLOW}\" >> \"$GITHUB_ENV\"\n\nif [ -z \"$TOP_WORKFLOW\" ]; then\n echo \"â„šī¸ No eligible Claude workflow found in the downloaded run data\"\n echo \"WORKFLOW_FILE=\" >> \"$GITHUB_ENV\"\n echo \"TARGET_NOT_FOUND=1\" >> \"$GITHUB_ENV\"\n touch /tmp/gh-aw/token-audit/target-workflow.md\n exit 0\nfi\n\nKEBAB=$(printf '%s' \"$TOP_WORKFLOW\" | tr '[:upper:]' '[:lower:]' | sed -E 's/[^a-z0-9]+/-/g; s/^-+|-+$//g')\nFILE=$(grep -Flx -- \"name: ${TOP_WORKFLOW}\" .github/workflows/*.md 2>/dev/null | head -1 || true)\n[ -z \"$FILE\" ] && FILE=\".github/workflows/${KEBAB}.md\"\n\necho \"WORKFLOW_FILE=${FILE}\" >> \"$GITHUB_ENV\"\n\nif [ -f \"$FILE\" ]; then\n cp \"$FILE\" /tmp/gh-aw/token-audit/target-workflow.md\n echo \"✅ Top workflow: ${TOP_WORKFLOW} → ${FILE}\"\nelse\n echo \"âš ī¸ Unable to locate workflow file for ${TOP_WORKFLOW}\"\n echo \"TARGET_NOT_FOUND=1\" >> \"$GITHUB_ENV\"\n touch /tmp/gh-aw/token-audit/target-workflow.md\nfi\n" - name: Configure Git credentials env: @@ -418,31 +427,8 @@ jobs: run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.40 env: GH_HOST: github.com - - name: Install awf dependencies - run: npm ci - - name: Build awf - run: npm run build - - name: Install awf binary (local) - run: | - WORKSPACE_PATH="${GITHUB_WORKSPACE:-$(pwd)}" - NODE_BIN="$(command -v node)" - if [ ! -d "$WORKSPACE_PATH" ]; then - echo "Workspace path not found: $WORKSPACE_PATH" - exit 1 - fi - if [ ! -x "$NODE_BIN" ]; then - echo "Node binary not found: $NODE_BIN" - exit 1 - fi - if [ ! -d "/usr/local/bin" ]; then - echo "/usr/local/bin is missing" - exit 1 - fi - sudo tee /usr/local/bin/awf > /dev/null < "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_b8dc261934f059c5_EOF' + cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_506f7d14a4e90be4_EOF' {"create_issue":{"close_older_issues":true,"labels":["claude-token-optimization"],"max":1,"title_prefix":"⚡ Claude Token Optimization"},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{}} - GH_AW_SAFE_OUTPUTS_CONFIG_b8dc261934f059c5_EOF + GH_AW_SAFE_OUTPUTS_CONFIG_506f7d14a4e90be4_EOF - name: Generate Safe Outputs Tools env: GH_AW_TOOLS_META_JSON: | @@ -678,7 +664,7 @@ jobs: mkdir -p /home/runner/.copilot GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_01bd34f06c0d10f6_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_49395a5bb86d2d3c_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -719,7 +705,7 @@ jobs: "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}" } } - GH_AW_MCP_CONFIG_01bd34f06c0d10f6_EOF + GH_AW_MCP_CONFIG_49395a5bb86d2d3c_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -753,7 +739,7 @@ jobs: (umask 177 && touch /tmp/gh-aw/agent-stdio.log) printf '%s\n' '{"$schema":"https://github.com/github/gh-aw-firewall/releases/download/v0.25.29/awf-config.schema.json","network":{"allowDomains":["*.githubusercontent.com","api.business.githubcopilot.com","api.enterprise.githubcopilot.com","api.github.com","api.githubcopilot.com","api.individual.githubcopilot.com","codeload.github.com","docs.github.com","github-cloud.githubusercontent.com","github-cloud.s3.amazonaws.com","github.blog","github.com","github.githubassets.com","host.docker.internal","lfs.github.com","objects.githubusercontent.com","raw.githubusercontent.com","registry.npmjs.org","telemetry.enterprise.githubcopilot.com"]},"apiProxy":{"enabled":true,"models":{"auto":["large"],"deep-research":["copilot/deep-research*","copilot/o3-deep-research*","copilot/o4-mini-deep-research*","google/deep-research*","openai/o3-deep-research*","openai/o4-mini-deep-research*"],"gemini-flash":["copilot/gemini-*flash*","google/gemini-*flash*"],"gemini-pro":["copilot/gemini-*pro*","google/gemini-*pro*"],"gpt-4.1":["copilot/gpt-4.1*","openai/gpt-4.1*"],"gpt-5":["copilot/gpt-5*","openai/gpt-5*"],"gpt-5-codex":["copilot/gpt-5*codex*","openai/gpt-5*codex*"],"gpt-5-mini":["copilot/gpt-5*mini*","openai/gpt-5*mini*"],"gpt-5-nano":["copilot/gpt-5*nano*","openai/gpt-5*nano*"],"gpt-5-pro":["copilot/gpt-5*pro*","openai/gpt-5*pro*"],"haiku":["copilot/*haiku*","anthropic/*haiku*"],"large":["sonnet","gpt-5-pro","gpt-5","gemini-pro"],"mini":["haiku","gpt-5-mini","gpt-5-nano","gemini-flash"],"opus":["copilot/*opus*","anthropic/*opus*"],"reasoning":["copilot/o1*","copilot/o3*","copilot/o4*","openai/o1*","openai/o3*","openai/o4*"],"small":["mini"],"sonnet":["copilot/*sonnet*","anthropic/*sonnet*"]}},"container":{"imageTag":"0.25.29,squid=sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53,agent=sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4,agent-act=sha256:97b4cc14dc2123a45b9d5b9927489f66882dec5857de6afc0e5bab257be92ef1,api-proxy=sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6,cli-proxy=sha256:29917488eb90a01ff9544ffeeb5cc26434a8ea16d69ae8972f5f6be0e567e276"}}' > "${RUNNER_TEMP}/gh-aw/awf-config.json" && cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json # shellcheck disable=SC1003 - sudo -E awf --config "${RUNNER_TEMP}/gh-aw/awf-config.json" --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" --env-all --exclude-env COPILOT_GITHUB_TOKEN --exclude-env GITHUB_MCP_SERVER_TOKEN --exclude-env MCP_GATEWAY_API_KEY --log-level info --proxy-logs-dir /tmp/gh-aw/sandbox/firewall/logs --audit-dir /tmp/gh-aw/sandbox/firewall/audit --session-state-dir /tmp/gh-aw/sandbox/agent/session-state --enable-host-access --allow-host-ports 80,443,8080 --skip-pull \ + sudo -E awf --config "${RUNNER_TEMP}/gh-aw/awf-config.json" --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" --env-all --exclude-env COPILOT_GITHUB_TOKEN --exclude-env GITHUB_MCP_SERVER_TOKEN --exclude-env MCP_GATEWAY_API_KEY --log-level info --proxy-logs-dir /tmp/gh-aw/sandbox/firewall/logs --audit-dir /tmp/gh-aw/sandbox/firewall/audit --enable-host-access --allow-host-ports 80,443,8080 --skip-pull \ -- /bin/bash -c 'export PATH="${RUNNER_TEMP}/gh-aw/mcp-cli/bin:$PATH" && export PATH="$(find /opt/hostedtoolcache /home/runner/work/_tool -maxdepth 4 -type d -name bin 2>/dev/null | tr '\''\n'\'' '\'':'\'')$PATH"; [ -n "$GOROOT" ] && export PATH="$GOROOT/bin:$PATH" || true && GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || echo node)"; fi; "$GH_AW_NODE_EXEC" ${RUNNER_TEMP}/gh-aw/actions/copilot_harness.cjs /usr/local/bin/copilot --add-dir /tmp/gh-aw/ --log-level all --log-dir /tmp/gh-aw/sandbox/agent/logs/ --disable-builtin-mcps --no-ask-user --allow-all-tools --allow-all-paths --add-dir "${GITHUB_WORKSPACE}" --prompt-file /tmp/gh-aw/aw-prompts/prompt.txt' 2>&1 | tee -a /tmp/gh-aw/agent-stdio.log env: AWF_REFLECT_ENABLED: 1 @@ -801,16 +787,7 @@ jobs: - name: Copy Copilot session state files to logs if: always() continue-on-error: true - run: | - SESSION_STATE_SRC="/tmp/gh-aw/sandbox/agent/session-state" - LOGS_DIR="/tmp/gh-aw/sandbox/agent/logs" - if [ -d "$SESSION_STATE_SRC" ] && [ -n "$(ls -A "$SESSION_STATE_SRC" 2>/dev/null)" ]; then - mkdir -p "$LOGS_DIR/session-state" - cp -rp "$SESSION_STATE_SRC/." "$LOGS_DIR/session-state/" - echo "Copied session state to $LOGS_DIR/session-state" - else - echo "No session state found at $SESSION_STATE_SRC" - fi + run: bash "${RUNNER_TEMP}/gh-aw/actions/copy_copilot_session_state.sh" - name: Stop MCP Gateway if: always() continue-on-error: true diff --git a/.github/workflows/claude-token-optimizer.md b/.github/workflows/claude-token-optimizer.md index 0b9a07e0..78089410 100644 --- a/.github/workflows/claude-token-optimizer.md +++ b/.github/workflows/claude-token-optimizer.md @@ -121,7 +121,7 @@ steps: fi KEBAB=$(printf '%s' "$TOP_WORKFLOW" | tr '[:upper:]' '[:lower:]' | sed -E 's/[^a-z0-9]+/-/g; s/^-+|-+$//g') - FILE=$(grep -Flx -- "name: ${TOP_WORKFLOW}" .github/workflows/*.md 2>/dev/null | head -1) + FILE=$(grep -Flx -- "name: ${TOP_WORKFLOW}" .github/workflows/*.md 2>/dev/null | head -1 || true) [ -z "$FILE" ] && FILE=".github/workflows/${KEBAB}.md" echo "WORKFLOW_FILE=${FILE}" >> "$GITHUB_ENV"