Skip to content

fix: upgrade cli-proxy gh to 2.97.0 - #6845

Merged
lpcox merged 1 commit into
mainfrom
fix-gh-cli-297
Aug 2, 2026
Merged

fix: upgrade cli-proxy gh to 2.97.0#6845
lpcox merged 1 commit into
mainfrom
fix-gh-cli-297

Conversation

@lpcox

@lpcox lpcox commented Aug 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • upgrade the CLI-proxy image from gh 2.96.0 to 2.97.0 using official per-architecture checksums
  • pick up google.golang.org/grpc 1.82.1 and golang.org/x/text 0.40.0
  • remove the obsolete Grype exceptions for GHSA-hrxh-6v49-42gf and GO-2026-5970

Testing

  • npm test -- --runInBand (4,964 passed, 1 skipped)
  • npm run lint
  • npm run build
  • verified the release artifact checksum and embedded Go module versions

Closes #6555

Upgrade the cli-proxy image to the first gh release containing patched grpc and x/text dependencies.

Remove the obsolete Grype exceptions.

Closes #6555

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 95adf431-ca48-4118-bb79-bd1cfc0f9feb
Copilot AI review requested due to automatic review settings August 2, 2026 17:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Upgrades the CLI-proxy’s GitHub CLI binary to 2.97.0, resolving vulnerable embedded dependencies and removing obsolete scanner exceptions.

Changes:

  • Updates per-architecture GitHub CLI binaries and checksums.
  • Removes resolved gRPC and x/text Grype exceptions.
Show a summary per file
File Description
containers/cli-proxy/Dockerfile Pins GitHub CLI 2.97.0 with verified checksums.
.grype.yaml Removes obsolete vulnerability suppressions.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Claude passed

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Contribution Check completed successfully!

Contribution check complete — no guideline issues found in PR #6845. The PR has a clear description, references related issue #6555, includes tests/build/lint validation in the description, and places changes in the correct container config file. No comment needed.

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Gemini completed. All facets verified. 💎

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Build Test Suite completed successfully!

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Security Guard completed successfully!

PR #6845 reviewed: gh CLI upgrade 2.96.0→2.97.0 in cli-proxy container. No security weakening detected. Checksums updated correctly for all architectures. No firewall rules, capabilities, egress policies, or ACLs modified. This is a standard dependency update with no security concerns.

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

Check Result
API status ✅ PASS
gh check ✅ PASS
File status ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #6845 · haiku45 · 54.8 AIC · ⊞ 3.6K ·
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

@lpcox Network isolation egress smoke test results:

EGRESS_RESULT allow=pass deny=pass

✅ Allowed domain (github.com) reachable: allowed=200
✅ Denied domain (example.com) blocked: CONNECT tunnel failed (403)

Overall: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • example.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"

See Network Configuration for more information.

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions github-actions Bot added the smoke-copilot-network-isolation Copilot network-isolation egress smoke test label Aug 2, 2026
@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot Engine — PASS ✅

Overall: PASS

cc @lpcox

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

🔥 Smoke Test: Copilot BYOK (Direct) Mode

Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com

Overall: PASS

cc @lpcox

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: GitHub Actions Services Connectivity

  • Redis PING: ❌ (name resolution failure)
  • PostgreSQL pg_isready: ❌ (no response)
  • PostgreSQL SELECT 1: ❌ (name resolution failure)

Overall: FAILhost.docker.internal could not be resolved from the sandbox; all connectivity checks failed with "Temporary failure in name resolution".

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

📡 OTel Tracing Smoke Test Results

Scenario Result
1. Module Loading otel.js loads successfully; isEnabled() returns true; exports: startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled, _parseOtlpHeaders, _buildResourceSpans, etc.
2. Test Suite ✅ 59/59 tests passed (2 suites: otel.test.js, otel-fanout.test.js) — 0 failures
3. Env Var Forwarding ⚠️ src/services/api-proxy-service.ts does not yet forward OTEL_EXPORTER_OTLP_ENDPOINT / GITHUB_AW_OTEL_TRACE_ID (expected during development — not yet wired up)
4. Token Tracker Integration token-tracker-http.js contains onUsage callback (4 references) — OTEL hook point present
5. OTEL Diagnostics ⚠️ No /tmp/gh-aw/sandbox/firewall/logs/api-proxy/otel.jsonl produced this run — no live api-proxy invocation occurred in this smoke test, so no spans were exported

Summary: Core OTEL module (span creation, token usage attributes via GenAI semantic conventions, OTLP export, graceful degradation) is fully implemented and unit-tested (59/59 passing). Remaining gap: env var forwarding from api-proxy-service.ts to the container is not yet implemented — this is expected/pending development work, not a regression. No unexpected failures detected.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions github-actions Bot mentioned this pull request Aug 2, 2026
@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Gemini Smoke Test Results

  • GitHub MCP Testing: ❌ (Tools missing)
  • GitHub.com Connectivity: ❌ (Status 000)
  • File Writing Testing: ✅
  • Bash Tool Testing: ✅

PR Title:

Overall Status: FAIL

💎 Faceted by Smoke Gemini
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia 1/1 passed ✅ PASS
Bun hono 1/1 passed ✅ PASS
C++ fmt N/A ✅ PASS
C++ json N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world N/A ✅ PASS
.NET json-parse N/A ✅ PASS
Go color 1/1 passed ✅ PASS
Go env 1/1 passed ✅ PASS
Go uuid 1/1 passed ✅ PASS
Java gson 1/1 passed ✅ PASS
Java caffeine 1/1 passed ✅ PASS
Node.js clsx passed ✅ PASS
Node.js execa passed ✅ PASS
Node.js p-limit passed ✅ PASS
Rust fd 1/1 passed ✅ PASS
Rust zoxide 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — PASS

Notes:

  • All repositories cloned successfully.
  • Java: Maven required -Dmaven.repo.local override (default ~/.m2/repository was owned by root in this environment, not writable by the runner user); ~/.m2/settings.xml proxy config applied as instructed.
  • No failures encountered in any ecosystem.

Generated by Build Test Suite for #6845 · auto · 39.9 AIC · ⊞ 11.4K ·
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison Results

Runtime Host Version Chroot Version Match?
Python Python 3.12.13 Python 3.12.13 ✅ YES
Node.js v24.18.0 v22.23.1 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Overall: FAILED — Node.js version mismatch between host and chroot environment. smoke-chroot label not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke test summary:

  • chore: upgrade gh-aw to v0.84.2 pre-release and recompile workflows
  • test: fix gvisor runtime matrix fixture
  • Overall: FAIL
  • Build failed during npm ci with 403 Forbidden fetching yocto-queue from registry.npmjs.org

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • registry.npmjs.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "registry.npmjs.org"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Docker Sbx Validation

  • ✅ GitHub MCP connectivity verified
  • ✅ github.com connectivity (HTTP 200)
  • ✅ File write/read test passed

Overall: PASS

cc @lpcox

📰 BREAKING: Report filed by Smoke Docker Sbx
Add label ready-for-aw to run again

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump gh CLI to >= v2.97.0 (grpc >= 1.82.1) and drop GHSA-hrxh-6v49-42gf grype ignore

2 participants