Skip to content

chore: upgrade gh-aw extension to latest pre-release and recompile workflows - #6495

Merged
lpcox merged 4 commits into
mainfrom
lpcox-upgrade-gh-aw-prerelease-v2
Jul 22, 2026
Merged

chore: upgrade gh-aw extension to latest pre-release and recompile workflows#6495
lpcox merged 4 commits into
mainfrom
lpcox-upgrade-gh-aw-prerelease-v2

Conversation

@lpcox

@lpcox lpcox commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

Upgrades the gh-aw extension to the latest pre-release version and recompiles all agentic workflows.

Changes

  • Ran gh aw upgrade --pre-releases to update the extension
  • Ran gh aw compile to recompile all 59 workflows (0 errors, 42 warnings)
  • Ran postprocess-smoke-workflows.ts post-processing script
  • All 4011 tests pass (npm test)

Files changed

  • .github/aw/actions-lock.json — Updated action pins
  • .github/workflows/*.lock.yml — Regenerated lock files
  • .github/workflows/agentics-maintenance.yml — Updated workflow

…rkflows

Ran 'gh aw upgrade --pre-releases' and 'gh aw compile' followed by
post-processing via postprocess-smoke-workflows.ts.

All 4011 tests pass.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 22, 2026 12:04
@github-actions

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 98.99% 99.02% 📈 +0.03%
Statements 98.92% 98.95% 📈 +0.03%
Functions 99.40% 99.40% ➡️ +0.00%
Branches 95.34% 95.34% ➡️ +0.00%
📁 Per-file Coverage Changes (1 files)
File Lines (Before → After) Statements (Before → After)
src/log-directory-setup.ts 96.2% → 100.0% (+3.78%) 96.3% → 100.0% (+3.71%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Upgrades gh-aw to v0.82.15 and regenerates associated workflows and action pins.

Changes:

  • Updates compiler and setup-action pins.
  • Regenerates workflow metadata, model aliases, and MCP CLI handling.
  • Refreshes maintenance workflow and setup-uv versions.
Show a summary per file
File Description
.github/aw/actions-lock.json Updates setup-uv to v9.0.0.
.github/workflows/agentics-maintenance.yml Pins maintenance actions to v0.82.15.
.github/workflows/doc-maintainer.lock.yml Recompiles documentation workflow.
.github/workflows/sbx-gvisor-doc-updater.lock.yml Recompiles documentation updater.
.github/workflows/self-hosted-runner-doctor.lock.yml Refreshes generated metadata.
.github/workflows/self-hosted-runner-doctor-updater.lock.yml Refreshes generated metadata.
.github/workflows/smoke-chroot.lock.yml Synchronizes chroot smoke commands.
.github/workflows/smoke-copilot-byok-aoai-entra.lock.yml Refreshes generated metadata.
.github/workflows/smoke-copilot-network-isolation.lock.yml Updates compiler output and model aliases.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 9/9 changed files
  • Comments generated: 3
  • Review effort level: Medium

Comment thread .github/workflows/doc-maintainer.lock.yml Outdated
Comment thread .github/workflows/sbx-gvisor-doc-updater.lock.yml Outdated
Comment thread .github/workflows/smoke-copilot-network-isolation.lock.yml Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@lpcox Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

lpcox and others added 2 commits July 22, 2026 09:00
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Claude passed

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Build Test Suite completed successfully!

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Contribution Check completed successfully!

Contribution check complete: no blocking issues found. The PR is a workflow/version bump with regenerated files in the correct locations, and the description is clear enough for this maintenance change. No comment needed.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (api-key) completed. Copilot AOAI BYOK (api-key) mode operational. 🔓

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Smoke Gemini completed. All facets verified. 💎

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

Check Result
API status ✅ PASS
GH check ✅ PASS
File status ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #6495 · 31.3 AIC · ⊞ 3.2K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔥 AWF Network Isolation Smoke Test

@lpcox

EGRESS_RESULT allow=pass deny=pass
  • ✅ Allowed domain (api.github.com) — HTTP 200
  • ✅ Blocked domain (example.com) — 403 via proxy, curl blocked

Overall: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • example.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"

See Network Configuration for more information.

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions github-actions Bot added the smoke-copilot-network-isolation Copilot network-isolation egress smoke test label Jul 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Smoke Test Results

Test Result
GitHub MCP connectivity
GitHub.com HTTP connectivity ⚠️ (pre-step data unavailable — template vars unresolved)
File write/read ⚠️ (pre-step data unavailable — template vars unresolved)

Overall: PARTIAL — MCP connectivity verified; pre-computed test data was not injected (template expressions unresolved at agent runtime).

PR author: @lpcox

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results — Auth mode: PAT (COPILOT_GITHUB_TOKEN)

Test Status
GitHub MCP connectivity
GitHub.com HTTP ⚠️ pre-step data not expanded
File write/read ⚠️ pre-step data not expanded

Overall: PARTIAL — MCP connectivity confirmed, but workflow template variables (${{ steps.smoke-data.outputs.* }}) were not expanded before reaching the agent. Pre-computed test data unavailable.

@lpcox — please verify the smoke-data step runs before this agent step in the workflow.

🔑 PAT report filed by Smoke Copilot PAT
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results — Services Connectivity

Check Result
Redis PING ❌ Name resolution failure (host.docker.internal unresolvable)
PostgreSQL pg_isready ❌ No response
PostgreSQL SELECT 1 ❌ Name resolution failure

Overall: FAILhost.docker.internal DNS is not resolvable in this environment. Service containers are unreachable.

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: API Proxy OTEL Tracing Results

Scenario Status Notes
1. Module Loading ✅ Pass otel.js loads successfully; exports: startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled
2. Test Suite ⚠️ Expected-pending No TypeScript OTEL tests found in src/ (Jest only scans .test.ts); otel.test.js and otel-fanout.test.js exist in containers/api-proxy/ but are JS, not picked up by project Jest config
3. Env Var Forwarding ✅ Pass src/services/api-proxy-env-config.ts forwards GH_AW_OTLP_ENDPOINTS, OTEL_EXPORTER_OTLP_ENDPOINT, OTEL_EXPORTER_OTLP_HEADERS, GITHUB_AW_OTEL_TRACE_ID, GITHUB_AW_OTEL_PARENT_SPAN_ID, OTEL_SERVICE_NAME
4. Token Tracker Integration ✅ Pass onUsage callback exists in token-tracker-http.js (line 285, 343); serves as OTEL hook point
5. OTEL Diagnostics i️ N/A No live containers running in this smoke test; file fallback (/var/log/api-proxy/otel.jsonl) would capture spans when not configured

Overall: All scenarios pass or are expected-pending during development.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) — PASS

  • ✅ MCP connectivity (GitHub API)
  • ✅ GitHub.com connectivity (HTTP 200)
  • ✅ File write/read capability
  • ✅ BYOK inference (running in direct mode via api-proxy → api.githubcopilot.com)

Running in direct BYOK mode: COPILOT_PROVIDER_API_KEY forwarded to api-proxy sidecar, placeholder injected in agent.

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

  • GitHub MCP Testing: ❌ (Access Denied)
  • GitHub.com Connectivity: ❌ (Connection Failed)
  • File Writing Testing: ✅
  • Bash Tool Testing: ✅

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

💎 Faceted by Smoke Gemini
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

👋 @lpcox

  • GitHub MCP Test: ✅
  • GitHub.com connectivity: ✅
  • File read/write test: ✅
  • BYOK inference: ✅

Running in direct BYOK mode (AWF_AUTH_TYPE=github-oidc + AWF_AUTH_AZURE_* + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw)

Overall: PASS

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test results:

  • ✅ Support COPILOT_MODEL=auto in AWF validation and api-proxy resolution
  • ✅ Auto-allow topology-attached container hostnames in Squid ACL
  • ✅ GitHub title contains "GitHub"
  • ✅ Smoke file written/read
  • npm ci && npm run build
    Overall: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • registry.npmjs.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "registry.npmjs.org"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Chroot Version Comparison Results ✅

All runtime versions match between host and chroot environments.

Runtime Host Version Chroot Version Match?
Python Python 3.12.13 Python 3.12.13 ✅ YES
Node.js v24.18.0 v24.18.0 ✅ YES
Go go1.22.12 go1.22.12 ✅ YES

All tests passed — chroot environment correctly mirrors host runtime versions.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

@lpcox
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw)

  • GitHub MCP connectivity: ✅
  • GitHub.com connectivity: ✅
  • File I/O test: ✅
  • BYOK inference test: ✅
    Overall: PASS

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia 1/1 passed ✅ PASS
Bun hono 1/1 passed ✅ PASS
C++ fmt N/A ✅ PASS
C++ json N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world N/A ✅ PASS
.NET json-parse N/A ✅ PASS
Go color 1/1 passed ✅ PASS
Go env 1/1 passed ✅ PASS
Go uuid 1/1 passed ✅ PASS
Java gson 1/1 passed ✅ PASS
Java caffeine 1/1 passed ✅ PASS
Node.js clsx All passed ✅ PASS
Node.js execa All passed ✅ PASS
Node.js p-limit All passed ✅ PASS
Rust fd 1/1 passed ✅ PASS
Rust zoxide 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — ✅ PASS

Generated by Build Test Suite for #6495 · 53.3 AIC · ⊞ 8.2K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🔥 Smoke Test: Docker Sbx — PASS

Test Result
GitHub MCP connectivity
GitHub.com HTTP connectivity
File write/read ✅ (smoke-test-docker-sbx-29936821180.txt verified)

Overall: PASS

📰 BREAKING: Report filed by Smoke Docker Sbx
Add label ready-for-aw to run again

@lpcox
lpcox enabled auto-merge (squash) July 22, 2026 16:21
@lpcox
lpcox merged commit 2c5446b into main Jul 22, 2026
138 of 140 checks passed
@lpcox
lpcox deleted the lpcox-upgrade-gh-aw-prerelease-v2 branch July 22, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants