diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json
index ffe6c94d496..0540eda0972 100644
--- a/.github/aw/actions-lock.json
+++ b/.github/aw/actions-lock.json
@@ -1,761 +1,761 @@
{
- "entries": {
- "actions-ecosystem/action-add-labels@v1.1.3": {
- "repo": "actions-ecosystem/action-add-labels",
- "version": "v1.1.3",
- "sha": "c96b68fec76a0987cd93957189e9abd0b9a72ff1",
- "inputs": {
- "github_token": {
- "description": "A GitHub token.",
- "default": "${{ github.token }}"
- },
- "labels": {
- "description": "The labels' name to be added. Must be separated with line breaks if there're multiple labels.",
- "required": true
- },
- "number": {
- "description": "The number of the issue or pull request."
- },
- "repo": {
- "description": "The owner and repository name. e.g.) Codertocat/Hello-World",
- "default": "${{ github.repository }}"
- }
- },
- "action_description": "Add labels to an issue or a pull request."
- },
- "actions/cache/restore@v6.1.0": {
- "repo": "actions/cache/restore",
- "version": "v6.1.0",
- "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
- },
- "actions/cache/save@v6.1.0": {
- "repo": "actions/cache/save",
- "version": "v6.1.0",
- "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
- },
- "actions/cache@v6.1.0": {
- "repo": "actions/cache",
- "version": "v6.1.0",
- "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
- },
- "actions/checkout@v7.0.0": {
- "repo": "actions/checkout",
- "version": "v7.0.0",
- "sha": "9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"
- },
- "actions/create-github-app-token@v3.2.0": {
- "repo": "actions/create-github-app-token",
- "version": "v3.2.0",
- "sha": "bcd2ba49218906704ab6c1aa796996da409d3eb1"
- },
- "actions/download-artifact@v8.0.1": {
- "repo": "actions/download-artifact",
- "version": "v8.0.1",
- "sha": "3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c"
- },
- "actions/github-script@v9.0.0": {
- "repo": "actions/github-script",
- "version": "v9.0.0",
- "sha": "3a2844b7e9c422d3c10d287c895573f7108da1b3"
- },
- "actions/setup-dotnet@v5.4.0": {
- "repo": "actions/setup-dotnet",
- "version": "v5.4.0",
- "sha": "26b0ec14cb23fa6904739307f278c14f94c95bf1"
- },
- "actions/setup-go@v6.5.0": {
- "repo": "actions/setup-go",
- "version": "v6.5.0",
- "sha": "924ae3a1cded613372ab5595356fb5720e22ba16"
- },
- "actions/setup-java@v5.4.0": {
- "repo": "actions/setup-java",
- "version": "v5.4.0",
- "sha": "1bcf9fb12cf4aa7d266a90ae39939e61372fe520"
- },
- "actions/setup-node@v6.4.0": {
- "repo": "actions/setup-node",
- "version": "v6.4.0",
- "sha": "48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e"
- },
- "actions/setup-python@v6.3.0": {
- "repo": "actions/setup-python",
- "version": "v6.3.0",
- "sha": "ece7cb06caefa5fff74198d8649806c4678c61a1"
- },
- "actions/upload-artifact@v7.0.1": {
- "repo": "actions/upload-artifact",
- "version": "v7.0.1",
- "sha": "043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"
- },
- "anchore/sbom-action@v0.24.0": {
- "repo": "anchore/sbom-action",
- "version": "v0.24.0",
- "sha": "e22c389904149dbc22b58101806040fa8d37a610"
- },
- "astral-sh/setup-uv@v8.2.0": {
- "repo": "astral-sh/setup-uv",
- "version": "v8.2.0",
- "sha": "fac544c07dec837d0ccb6301d7b5580bf5edae39"
- },
- "denoland/setup-deno@v2.0.4": {
- "repo": "denoland/setup-deno",
- "version": "v2.0.4",
- "sha": "667a34cdef165d8d2b2e98dde39547c9daac7282"
- },
- "docker/build-push-action@v7.2.0": {
- "repo": "docker/build-push-action",
- "version": "v7.2.0",
- "sha": "f9f3042f7e2789586610d6e8b85c8f03e5195baf",
- "released_at": "2026-05-21T15:23:58Z"
- },
- "docker/login-action@v4.2.0": {
- "repo": "docker/login-action",
- "version": "v4.2.0",
- "sha": "650006c6eb7dba73a995cc03b0b2d7f5ca915bee",
- "released_at": "2026-05-22T11:55:00Z"
- },
- "docker/metadata-action@v6.1.0": {
- "repo": "docker/metadata-action",
- "version": "v6.1.0",
- "sha": "80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9"
- },
- "docker/setup-buildx-action@v4.1.0": {
- "repo": "docker/setup-buildx-action",
- "version": "v4.1.0",
- "sha": "d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5"
- },
- "erlef/setup-beam@v1.24.0": {
- "repo": "erlef/setup-beam",
- "version": "v1.24.0",
- "sha": "fc68ffb90438ef2936bbb3251622353b3dcb2f93"
- },
- "github/codeql-action/upload-sarif@v4.36.2": {
- "repo": "github/codeql-action/upload-sarif",
- "version": "v4.36.2",
- "sha": "8aad20d150bbac5944a9f9d289da16a4b0d87c1e"
- },
- "github/stale-repos@v9.0.15": {
- "repo": "github/stale-repos",
- "version": "v9.0.15",
- "sha": "a0db8bfe2318ed6ddbd01e95d7633803f99f77e9"
- },
- "haskell-actions/setup@v2.11.0": {
- "repo": "haskell-actions/setup",
- "version": "v2.11.0",
- "sha": "cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553"
- },
- "oven-sh/setup-bun@v2.2.0": {
- "repo": "oven-sh/setup-bun",
- "version": "v2.2.0",
- "sha": "0c5077e51419868618aeaa5fe8019c62421857d6"
- },
- "ruby/setup-ruby@v1.314.0": {
- "repo": "ruby/setup-ruby",
- "version": "v1.314.0",
- "sha": "9eb537ca036ebaed86729dcb9309076e4c5c3b74"
- },
- "safedep/pmg@v1": {
- "repo": "safedep/pmg",
- "version": "v1",
- "sha": "46cc70db535107183c9e752bb55d1d5c5f1a9290"
- },
- "super-linter/super-linter@v8.7.0": {
- "repo": "super-linter/super-linter",
- "version": "v8.7.0",
- "sha": "4ce20838b8ab83717e78138c5b3a1407148e0918"
+ "entries": {
+ "actions-ecosystem/action-add-labels@v1.1.3": {
+ "repo": "actions-ecosystem/action-add-labels",
+ "version": "v1.1.3",
+ "sha": "c96b68fec76a0987cd93957189e9abd0b9a72ff1",
+ "inputs": {
+ "github_token": {
+ "description": "A GitHub token.",
+ "default": "${{ github.token }}"
+ },
+ "labels": {
+ "description": "The labels' name to be added. Must be separated with line breaks if there're multiple labels.",
+ "required": true
+ },
+ "number": {
+ "description": "The number of the issue or pull request."
+ },
+ "repo": {
+ "description": "The owner and repository name. e.g.) Codertocat/Hello-World",
+ "default": "${{ github.repository }}"
}
+ },
+ "action_description": "Add labels to an issue or a pull request."
},
- "containers": {
- "alpine:latest": {
- "image": "alpine:latest",
- "digest": "sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11",
- "pinned_image": "alpine:latest@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11"
- },
- "docker.io/mcp/brave-search": {
- "image": "docker.io/mcp/brave-search",
- "digest": "sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22",
- "pinned_image": "docker.io/mcp/brave-search@sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22"
- },
- "ghcr.io/chopratejas/headroom:latest": {
- "image": "ghcr.io/chopratejas/headroom:latest",
- "digest": "sha256:af709363c4f9515a88a50939baec513be13c7cd778fb6635527b104d5173cb1e",
- "pinned_image": "ghcr.io/chopratejas/headroom:latest@sha256:af709363c4f9515a88a50939baec513be13c7cd778fb6635527b104d5173cb1e"
- },
- "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29": {
- "image": "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29",
- "digest": "sha256:97b4cc14dc2123a45b9d5b9927489f66882dec5857de6afc0e5bab257be92ef1",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29@sha256:97b4cc14dc2123a45b9d5b9927489f66882dec5857de6afc0e5bab257be92ef1"
- },
- "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13": {
- "image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13",
- "digest": "sha256:676de58a0abad8054cd9d4fc45b861715856819f083a268372d60bca0090018c",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13@sha256:676de58a0abad8054cd9d4fc45b861715856819f083a268372d60bca0090018c"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.18": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.18",
- "digest": "sha256:c77e8c26bab6c39e8568d8e2f8c17015944849a8cbcdfb4bd9725d8893725ca2",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.18@sha256:c77e8c26bab6c39e8568d8e2f8c17015944849a8cbcdfb4bd9725d8893725ca2"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.20": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.20",
- "digest": "sha256:9161f2415a3306a344aca34dd671ee69f122317e0a512e66dc64c94b9c508682",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.20@sha256:9161f2415a3306a344aca34dd671ee69f122317e0a512e66dc64c94b9c508682"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.28": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.28",
- "digest": "sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.29": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.29",
- "digest": "sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.29@sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.40": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.40",
- "digest": "sha256:14ff567e8d9d4c2fbc5e55c973488381c71d7e0fdbe72d30ee7b8a738fd86504",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.40@sha256:14ff567e8d9d4c2fbc5e55c973488381c71d7e0fdbe72d30ee7b8a738fd86504"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.41": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.41",
- "digest": "sha256:cb2b565d070116d4b67e355775340528b5a2c3cb18b2c9049638bcc2df681770",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.41@sha256:cb2b565d070116d4b67e355775340528b5a2c3cb18b2c9049638bcc2df681770"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.66": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.66",
- "digest": "sha256:8373ba626ffd28ce1af503a3218205fa7744a5774479173f92e50a378a1ed00d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.66@sha256:8373ba626ffd28ce1af503a3218205fa7744a5774479173f92e50a378a1ed00d"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.25.67": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.67",
- "digest": "sha256:0f54fa48dd1a03ef6d171574eecf9a9edbf0406cea011a534cd12ed1fcb46715",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.67@sha256:0f54fa48dd1a03ef6d171574eecf9a9edbf0406cea011a534cd12ed1fcb46715"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.0": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.0",
- "digest": "sha256:3816d1692e6d96887b27f1e4f1d64b8d7edb43ed9d7506b8f203913cbb81c248",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.0@sha256:3816d1692e6d96887b27f1e4f1d64b8d7edb43ed9d7506b8f203913cbb81c248"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.1": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.1",
- "digest": "sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.1@sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.11": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.11",
- "digest": "sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.11@sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.12": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.12",
- "digest": "sha256:a3911ae633bfc49a96be10e660d447b65023731850fee3de8a074ff8861ffde3",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.12@sha256:a3911ae633bfc49a96be10e660d447b65023731850fee3de8a074ff8861ffde3"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.13": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.13",
- "digest": "sha256:691a06b64961b5b35aac117eaace202fa721e91da19d1d2e22dcdd6663cd571b",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.13@sha256:691a06b64961b5b35aac117eaace202fa721e91da19d1d2e22dcdd6663cd571b"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.2": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.2",
- "digest": "sha256:f88e5b17b6b7a600117bc121114d6ce2155c88c983c0c939c5df884f730fa1d6",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.2@sha256:f88e5b17b6b7a600117bc121114d6ce2155c88c983c0c939c5df884f730fa1d6"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.22": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.22",
- "digest": "sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.4": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.4",
- "digest": "sha256:b268ebf37df2428b19efcb383f001d65dc6a5ec10af43feb886d1a8477ab0e3a",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.4@sha256:b268ebf37df2428b19efcb383f001d65dc6a5ec10af43feb886d1a8477ab0e3a"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.6": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.6",
- "digest": "sha256:5b778c712a25397a38a47cee3467a9cbc726b16320cc133a0758c0592a6f0792",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.6@sha256:5b778c712a25397a38a47cee3467a9cbc726b16320cc133a0758c0592a6f0792"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.7": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.7",
- "digest": "sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.7@sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c"
- },
- "ghcr.io/github/gh-aw-firewall/agent:0.27.9": {
- "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.9",
- "digest": "sha256:13f522853a688bfe24b04adbbe40b68101e8ef4b6fe0b636068527141bf1c269",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.9@sha256:13f522853a688bfe24b04adbbe40b68101e8ef4b6fe0b636068527141bf1c269"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18",
- "digest": "sha256:d16a40a3ca6e989896d0cef9f31b9412bb1fcc8755bafcafb95012ae1078539b",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18@sha256:d16a40a3ca6e989896d0cef9f31b9412bb1fcc8755bafcafb95012ae1078539b"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20",
- "digest": "sha256:6971639e381e82e45134bcd333181f456df3a52cd6f818a3e3d6de068ff91519",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20@sha256:6971639e381e82e45134bcd333181f456df3a52cd6f818a3e3d6de068ff91519"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28",
- "digest": "sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29",
- "digest": "sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29@sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40",
- "digest": "sha256:2883ca3e5ae9f330cafdd9345bfd4ae17fc8da36c96d4c9a1f76e922b4c45280",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40@sha256:2883ca3e5ae9f330cafdd9345bfd4ae17fc8da36c96d4c9a1f76e922b4c45280"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41",
- "digest": "sha256:fadd0de387209f69a9a7a1b8722bb5e7fdfb80ba9749a5c60f0e4cd7582a74d0",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41@sha256:fadd0de387209f69a9a7a1b8722bb5e7fdfb80ba9749a5c60f0e4cd7582a74d0"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66",
- "digest": "sha256:4da87d0c633816cec29a26b1d1ed5fbcb0df38de19075f0429bf1d6deec3dcdc",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66@sha256:4da87d0c633816cec29a26b1d1ed5fbcb0df38de19075f0429bf1d6deec3dcdc"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67",
- "digest": "sha256:d3f51df1869bda0e1f71ae31a81450641c6ae67404e0769469aae34c2738aeb5",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67@sha256:d3f51df1869bda0e1f71ae31a81450641c6ae67404e0769469aae34c2738aeb5"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0",
- "digest": "sha256:f28d2bd3197fb6ef9ec40ef345bbf2bb33e50151a8e72e89abb618fc3d0066eb",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0@sha256:f28d2bd3197fb6ef9ec40ef345bbf2bb33e50151a8e72e89abb618fc3d0066eb"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1",
- "digest": "sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1@sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11",
- "digest": "sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11@sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12",
- "digest": "sha256:2329aff5e54bb5bf466ad94182eebbdfe4a4db497a9dfbe87442eb3400aa4a86",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12@sha256:2329aff5e54bb5bf466ad94182eebbdfe4a4db497a9dfbe87442eb3400aa4a86"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13",
- "digest": "sha256:c57febf4aeeefbb4fd96f5b12c07f4279ca55edca6a700032debf9dd0787286e",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13@sha256:c57febf4aeeefbb4fd96f5b12c07f4279ca55edca6a700032debf9dd0787286e"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2",
- "digest": "sha256:ee39841d980878ebbb87592903b06d31a1af500c71525c9616f7e8e2a27041a4",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2@sha256:ee39841d980878ebbb87592903b06d31a1af500c71525c9616f7e8e2a27041a4"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22",
- "digest": "sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4",
- "digest": "sha256:3ea0d12a2d124db8ed6e2d18aff040e30ab3568161f258a132fccdeede4198cd",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4@sha256:3ea0d12a2d124db8ed6e2d18aff040e30ab3568161f258a132fccdeede4198cd"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6",
- "digest": "sha256:7b14e481f3a9898f1e9be50acc4e58541d9fcd85b49b1e4945b708f1bf1bf68e",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6@sha256:7b14e481f3a9898f1e9be50acc4e58541d9fcd85b49b1e4945b708f1bf1bf68e"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7",
- "digest": "sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7@sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6"
- },
- "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9": {
- "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9",
- "digest": "sha256:9fec93937dc9d3e04f3954705c2c42f58976ebb8479b10778602631b5316e1e2",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9@sha256:9fec93937dc9d3e04f3954705c2c42f58976ebb8479b10778602631b5316e1e2"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28",
- "digest": "sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28@sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29",
- "digest": "sha256:29917488eb90a01ff9544ffeeb5cc26434a8ea16d69ae8972f5f6be0e567e276",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29@sha256:29917488eb90a01ff9544ffeeb5cc26434a8ea16d69ae8972f5f6be0e567e276"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40",
- "digest": "sha256:3e7152911d4b4b7b97beef9d3d7d924ff7902227e86001ef3838fb728d5d514c",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40@sha256:3e7152911d4b4b7b97beef9d3d7d924ff7902227e86001ef3838fb728d5d514c"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41",
- "digest": "sha256:62171f2fa508667b8b0a9e096f826983f312e3da0ce894f80c0f83a875af60fe",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41@sha256:62171f2fa508667b8b0a9e096f826983f312e3da0ce894f80c0f83a875af60fe"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66",
- "digest": "sha256:ff53f2b227ceaf7334baeab5daa2537211089aca251af9630cb0b5a8899492d0",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66@sha256:ff53f2b227ceaf7334baeab5daa2537211089aca251af9630cb0b5a8899492d0"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67",
- "digest": "sha256:97387002ec54c8ab9f255d5aaf3d435071642e058f528c8268ca0e80b201609a",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67@sha256:97387002ec54c8ab9f255d5aaf3d435071642e058f528c8268ca0e80b201609a"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0",
- "digest": "sha256:42529ecb9f90da5adb00593d268dfdbd35d14bb1dc92dd897286b27ce1e3d58d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0@sha256:42529ecb9f90da5adb00593d268dfdbd35d14bb1dc92dd897286b27ce1e3d58d"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1",
- "digest": "sha256:2e6dc98321dbf82840f83ec0ef8b198506149255a15d3a7854d59c0d34063e27",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1@sha256:2e6dc98321dbf82840f83ec0ef8b198506149255a15d3a7854d59c0d34063e27"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12",
- "digest": "sha256:7d267199839cc0f23c01fd39f8c050a5d86cb6cc5058aa829cd472f405fb1a1d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12@sha256:7d267199839cc0f23c01fd39f8c050a5d86cb6cc5058aa829cd472f405fb1a1d"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13",
- "digest": "sha256:79dfd3a5d139bd1956ba6d7d1782b831a07175cf5afa29c45cb20bb0140f23c5",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13@sha256:79dfd3a5d139bd1956ba6d7d1782b831a07175cf5afa29c45cb20bb0140f23c5"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2",
- "digest": "sha256:02f3ec08f32dc26c5427920c6a2e2f3036238fce44802f2f11ef49ed8621b5d0",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2@sha256:02f3ec08f32dc26c5427920c6a2e2f3036238fce44802f2f11ef49ed8621b5d0"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22",
- "digest": "sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4",
- "digest": "sha256:72c378c029d2fad4684847ab44c329e526ac6b1a78cdf97656870ea11d201545",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4@sha256:72c378c029d2fad4684847ab44c329e526ac6b1a78cdf97656870ea11d201545"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6",
- "digest": "sha256:194b21f5d3284b0b2abf2603a14ec607f89d798165a7ef453667706c69401735",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6@sha256:194b21f5d3284b0b2abf2603a14ec607f89d798165a7ef453667706c69401735"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7",
- "digest": "sha256:4757f198a3fa20f88bdbe70be7ae1a05f127d9c0a9e96a5d6460ef40c08fc83d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7@sha256:4757f198a3fa20f88bdbe70be7ae1a05f127d9c0a9e96a5d6460ef40c08fc83d"
- },
- "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9": {
- "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9",
- "digest": "sha256:89b715de241408e03d35d5c4851361ae350f69aa56d7955dd2ed1d6d3ce037cc",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9@sha256:89b715de241408e03d35d5c4851361ae350f69aa56d7955dd2ed1d6d3ce037cc"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.18": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.18",
- "digest": "sha256:eb102afcfbae26ffcec016adebb74d3be7b0a5bf376ba306599cdf3effbe288e",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.18@sha256:eb102afcfbae26ffcec016adebb74d3be7b0a5bf376ba306599cdf3effbe288e"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.20": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.20",
- "digest": "sha256:5411d903f73ee597e6a084971c2adef3eb0bd405910df3ed7bf5e3d6bd58a236",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.20@sha256:5411d903f73ee597e6a084971c2adef3eb0bd405910df3ed7bf5e3d6bd58a236"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.28": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.28",
- "digest": "sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.29": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.29",
- "digest": "sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.29@sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.40": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.40",
- "digest": "sha256:b084f4a2c771f584ee68084ced52fa6b3245197a1889645d817462d307d3ac51",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.40@sha256:b084f4a2c771f584ee68084ced52fa6b3245197a1889645d817462d307d3ac51"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.41": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.41",
- "digest": "sha256:1260445d25968dbf3ae70143964177a0e5914cf2ce07a6117f7d3caec6c3e3c4",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.41@sha256:1260445d25968dbf3ae70143964177a0e5914cf2ce07a6117f7d3caec6c3e3c4"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.66": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.66",
- "digest": "sha256:9c47e6d0210c5b1581b56d1fe8ac32c1d8fdd7cb04ef95592f2431e59f533bd3",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.66@sha256:9c47e6d0210c5b1581b56d1fe8ac32c1d8fdd7cb04ef95592f2431e59f533bd3"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.25.67": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.67",
- "digest": "sha256:9a05085db054f41bd67c772bcfc25cabc15bc33ee993b051a31e30669dd2031f",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.67@sha256:9a05085db054f41bd67c772bcfc25cabc15bc33ee993b051a31e30669dd2031f"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.0": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.0",
- "digest": "sha256:d6a01d4cf3d928e6a7fc42e34afef228e753dce87646edc91d8a5cd0b612d9a6",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.0@sha256:d6a01d4cf3d928e6a7fc42e34afef228e753dce87646edc91d8a5cd0b612d9a6"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.1": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.1",
- "digest": "sha256:1f3df3207dc9faa9080088115ca50a5ab0d7a692c61dffa8c8898d0b7b750413",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.1@sha256:1f3df3207dc9faa9080088115ca50a5ab0d7a692c61dffa8c8898d0b7b750413"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.11": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.11",
- "digest": "sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.11@sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.12": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.12",
- "digest": "sha256:f5d9403364543b23a8510278854cf5517345419daed19de044a7130c03388484",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.12@sha256:f5d9403364543b23a8510278854cf5517345419daed19de044a7130c03388484"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.13": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.13",
- "digest": "sha256:700b1b5a73098373b04fb684f291e95d9be0124ab559717b04f27acaf8b41bed",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.13@sha256:700b1b5a73098373b04fb684f291e95d9be0124ab559717b04f27acaf8b41bed"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.2": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.2",
- "digest": "sha256:2e3a717e5f19a654cd9a2263beb52012b56bcb68562ec5ae2e42f9d156b49591",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.2@sha256:2e3a717e5f19a654cd9a2263beb52012b56bcb68562ec5ae2e42f9d156b49591"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.22": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.22",
- "digest": "sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.4": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.4",
- "digest": "sha256:87979038897e40caed22245b64d1daa796390d2dca289b99d3d1174c85740af8",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.4@sha256:87979038897e40caed22245b64d1daa796390d2dca289b99d3d1174c85740af8"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.6": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.6",
- "digest": "sha256:730985e67931b9774545bce76b3ac5a354aa1dc11f19ee8f2d9cbf3211d73c3a",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.6@sha256:730985e67931b9774545bce76b3ac5a354aa1dc11f19ee8f2d9cbf3211d73c3a"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.7": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.7",
- "digest": "sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.7@sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96"
- },
- "ghcr.io/github/gh-aw-firewall/squid:0.27.9": {
- "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.9",
- "digest": "sha256:f186085bd04864e59f5057ff9e6bbd506475275ffe165111517d7d1acdc1de9c",
- "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.9@sha256:f186085bd04864e59f5057ff9e6bbd506475275ffe165111517d7d1acdc1de9c"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.2.19": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.2.19",
- "digest": "sha256:44d4d8de7e6c37aaea484eba489940c52df6a0b54078ddcbc9327592d5b3c3dd",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.2.19@sha256:44d4d8de7e6c37aaea484eba489940c52df6a0b54078ddcbc9327592d5b3c3dd"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.2.30": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.2.30",
- "digest": "sha256:e950e6d39f003862d33bfb8d4eb93e242d919cf6ca874b90728e5e0ea7434c6f",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.2.30@sha256:e950e6d39f003862d33bfb8d4eb93e242d919cf6ca874b90728e5e0ea7434c6f"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.0": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.0",
- "digest": "sha256:9c2228324fb1f26f39dc9471612e530ae3efc3156dac05efb2e8d212878d454d",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.0@sha256:9c2228324fb1f26f39dc9471612e530ae3efc3156dac05efb2e8d212878d454d"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.1": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.1",
- "digest": "sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.1@sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.16": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.16",
- "digest": "sha256:8001e4bfa52d45abd05c45a8f855ce62bc893eb66e4807bb487bf2ff07fc1473",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.16@sha256:8001e4bfa52d45abd05c45a8f855ce62bc893eb66e4807bb487bf2ff07fc1473"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.23": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.23",
- "digest": "sha256:0dd1bd91a41e24a3ccc31b1ec6cb61d36608997fabf91f2d643b64e3fc33180a",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.23@sha256:0dd1bd91a41e24a3ccc31b1ec6cb61d36608997fabf91f2d643b64e3fc33180a"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.24": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.24",
- "digest": "sha256:72cc921901afa1d67b6fee568f110c6b84436624c437fb2996d14c83e90a2b54",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.24@sha256:72cc921901afa1d67b6fee568f110c6b84436624c437fb2996d14c83e90a2b54"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.25": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.25",
- "digest": "sha256:c10331ad17668ef89f38f5e356678788a40b0cd5fef96e8f92e1d9c1de47cbaa",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.25@sha256:c10331ad17668ef89f38f5e356678788a40b0cd5fef96e8f92e1d9c1de47cbaa"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.26": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.26",
- "digest": "sha256:d3b03f54eee3a8176818c9a52087623e45b7f644a28814337fcc0838e2534490",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.26@sha256:d3b03f54eee3a8176818c9a52087623e45b7f644a28814337fcc0838e2534490"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.27": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.27",
- "digest": "sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.27@sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.29": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.29",
- "digest": "sha256:f24e968e6e5aeb819e9a98b9d273efe36b0fc1a0cb17e9ace263b5ab20de87cd",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.29@sha256:f24e968e6e5aeb819e9a98b9d273efe36b0fc1a0cb17e9ace263b5ab20de87cd"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.30": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.30",
- "digest": "sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.30@sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.31": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.31",
- "digest": "sha256:3147d7332939aeb2bc6a4220d96f6a0ca600b5cc0971200eca3d1e948fc8122a",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.31@sha256:3147d7332939aeb2bc6a4220d96f6a0ca600b5cc0971200eca3d1e948fc8122a"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.32": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.32",
- "digest": "sha256:63e46b56dfd70895a701b6fc6dd0189e11e2d875f327f1781e81b31848735477",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.32@sha256:63e46b56dfd70895a701b6fc6dd0189e11e2d875f327f1781e81b31848735477"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.33": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.33",
- "digest": "sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.6": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.6",
- "digest": "sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.6@sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.8": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.8",
- "digest": "sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.8@sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4"
- },
- "ghcr.io/github/gh-aw-mcpg:v0.3.9": {
- "image": "ghcr.io/github/gh-aw-mcpg:v0.3.9",
- "digest": "sha256:64828b42a4482f58fab16509d7f8f495a6d97c972a98a68aff20543531ac0388",
- "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.9@sha256:64828b42a4482f58fab16509d7f8f495a6d97c972a98a68aff20543531ac0388"
- },
- "ghcr.io/github/gh-aw-node": {
- "image": "ghcr.io/github/gh-aw-node",
- "digest": "sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b",
- "pinned_image": "ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"
- },
- "ghcr.io/github/github-mcp-server:v0.32.0": {
- "image": "ghcr.io/github/github-mcp-server:v0.32.0",
- "digest": "sha256:2763823c63bcca718ce53850a1d7fcf2f501ec84028394f1b63ce7e9f4f9be28",
- "pinned_image": "ghcr.io/github/github-mcp-server:v0.32.0@sha256:2763823c63bcca718ce53850a1d7fcf2f501ec84028394f1b63ce7e9f4f9be28"
- },
- "ghcr.io/github/github-mcp-server:v1.0.0": {
- "image": "ghcr.io/github/github-mcp-server:v1.0.0",
- "digest": "sha256:d2550953f8050bc5a1c8f80d1678766f66f60bbfbcd953fdeaf661fe4269bd95",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.0@sha256:d2550953f8050bc5a1c8f80d1678766f66f60bbfbcd953fdeaf661fe4269bd95"
- },
- "ghcr.io/github/github-mcp-server:v1.0.3": {
- "image": "ghcr.io/github/github-mcp-server:v1.0.3",
- "digest": "sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.3@sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959"
- },
- "ghcr.io/github/github-mcp-server:v1.0.4": {
- "image": "ghcr.io/github/github-mcp-server:v1.0.4",
- "digest": "sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.4@sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4"
- },
- "ghcr.io/github/github-mcp-server:v1.1.0": {
- "image": "ghcr.io/github/github-mcp-server:v1.1.0",
- "digest": "sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.0@sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029"
- },
- "ghcr.io/github/github-mcp-server:v1.1.2": {
- "image": "ghcr.io/github/github-mcp-server:v1.1.2",
- "digest": "sha256:30197479d8036c7811892bc07e06f9a05c9ef3cdd79bc59f256d50647f95788c",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.2@sha256:30197479d8036c7811892bc07e06f9a05c9ef3cdd79bc59f256d50647f95788c"
- },
- "ghcr.io/github/github-mcp-server:v1.3.0": {
- "image": "ghcr.io/github/github-mcp-server:v1.3.0",
- "digest": "sha256:5c83359327a0bacc3d34db730bea6557d39d341cee0bf6c58c9a896e33150e80",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.3.0@sha256:5c83359327a0bacc3d34db730bea6557d39d341cee0bf6c58c9a896e33150e80"
- },
- "ghcr.io/github/github-mcp-server:v1.4.0": {
- "image": "ghcr.io/github/github-mcp-server:v1.4.0",
- "digest": "sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"
- },
- "ghcr.io/github/github-mcp-server:v1.5.0": {
- "image": "ghcr.io/github/github-mcp-server:v1.5.0",
- "digest": "sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4",
- "pinned_image": "ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"
- },
- "ghcr.io/github/serena-mcp-server:latest": {
- "image": "ghcr.io/github/serena-mcp-server:latest",
- "digest": "sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5",
- "pinned_image": "ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"
- },
- "grafana/mcp-grafana": {
- "image": "grafana/mcp-grafana",
- "digest": "sha256:60a4e3a417a69eeb864a72052c53b4aa4466ff3577d6ef9bacc671f4b77d7090",
- "pinned_image": "grafana/mcp-grafana@sha256:60a4e3a417a69eeb864a72052c53b4aa4466ff3577d6ef9bacc671f4b77d7090"
- },
- "mcp/arxiv-mcp-server": {
- "image": "mcp/arxiv-mcp-server",
- "digest": "sha256:6dc6bba6dfed97f4ad6eb8d23a5c98ef5b7fa6184937d54b2d675801cd9dd29e",
- "pinned_image": "mcp/arxiv-mcp-server@sha256:6dc6bba6dfed97f4ad6eb8d23a5c98ef5b7fa6184937d54b2d675801cd9dd29e"
- },
- "mcp/ast-grep:latest": {
- "image": "mcp/ast-grep:latest",
- "digest": "sha256:5fc3f2e9dcf2c019e92662f608b8d89e12134ed6d91e6f5461de6efd506a1e72",
- "pinned_image": "mcp/ast-grep:latest@sha256:5fc3f2e9dcf2c019e92662f608b8d89e12134ed6d91e6f5461de6efd506a1e72"
- },
- "mcp/context7": {
- "image": "mcp/context7",
- "digest": "sha256:1174e6a29634a83b2be93ac1fefabf63265f498c02c72201fe3464e687dd8836",
- "pinned_image": "mcp/context7@sha256:1174e6a29634a83b2be93ac1fefabf63265f498c02c72201fe3464e687dd8836"
- },
- "mcp/markitdown": {
- "image": "mcp/markitdown",
- "digest": "sha256:1cef3bf502503310ed0884441874ccf6cdaac20136dc1179797fa048269dc4cb",
- "pinned_image": "mcp/markitdown@sha256:1cef3bf502503310ed0884441874ccf6cdaac20136dc1179797fa048269dc4cb"
- },
- "mcp/memory": {
- "image": "mcp/memory",
- "digest": "sha256:db0c2db07a44b6797eba7a832b1bda142ffc899588aae82c92780cbb2252407f",
- "pinned_image": "mcp/memory@sha256:db0c2db07a44b6797eba7a832b1bda142ffc899588aae82c92780cbb2252407f"
- },
- "mcp/notion": {
- "image": "mcp/notion",
- "digest": "sha256:4de8eb0de33402fcbd3740b4f4039918e4893155c7ea833c7a0c472001b88367",
- "pinned_image": "mcp/notion@sha256:4de8eb0de33402fcbd3740b4f4039918e4893155c7ea833c7a0c472001b88367"
- },
- "mcr.microsoft.com/playwright/mcp": {
- "image": "mcr.microsoft.com/playwright/mcp",
- "digest": "sha256:7b82f29c6ef83480a97f612d53ac3fd5f30a32df3fea1e06923d4204d3532bb2",
- "pinned_image": "mcr.microsoft.com/playwright/mcp@sha256:7b82f29c6ef83480a97f612d53ac3fd5f30a32df3fea1e06923d4204d3532bb2"
- },
- "node:lts-alpine": {
- "image": "node:lts-alpine",
- "digest": "sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14",
- "pinned_image": "node:lts-alpine@sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14"
- },
- "python:alpine": {
- "image": "python:alpine",
- "digest": "sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116",
- "pinned_image": "python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"
- },
- "semgrep/semgrep:latest": {
- "image": "semgrep/semgrep:latest",
- "digest": "sha256:17d89ddd91a7729bbd5de09402f7f79a70204289e2a94635086e9db532a495f2",
- "pinned_image": "semgrep/semgrep:latest@sha256:17d89ddd91a7729bbd5de09402f7f79a70204289e2a94635086e9db532a495f2"
- }
+ "actions/cache/restore@v6.1.0": {
+ "repo": "actions/cache/restore",
+ "version": "v6.1.0",
+ "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
+ },
+ "actions/cache/save@v6.1.0": {
+ "repo": "actions/cache/save",
+ "version": "v6.1.0",
+ "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
+ },
+ "actions/cache@v6.1.0": {
+ "repo": "actions/cache",
+ "version": "v6.1.0",
+ "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9"
+ },
+ "actions/checkout@v7.0.0": {
+ "repo": "actions/checkout",
+ "version": "v7.0.0",
+ "sha": "9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"
+ },
+ "actions/create-github-app-token@v3.2.0": {
+ "repo": "actions/create-github-app-token",
+ "version": "v3.2.0",
+ "sha": "bcd2ba49218906704ab6c1aa796996da409d3eb1"
+ },
+ "actions/download-artifact@v8.0.1": {
+ "repo": "actions/download-artifact",
+ "version": "v8.0.1",
+ "sha": "3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c"
+ },
+ "actions/github-script@v9.0.0": {
+ "repo": "actions/github-script",
+ "version": "v9.0.0",
+ "sha": "3a2844b7e9c422d3c10d287c895573f7108da1b3"
+ },
+ "actions/setup-dotnet@v5.4.0": {
+ "repo": "actions/setup-dotnet",
+ "version": "v5.4.0",
+ "sha": "26b0ec14cb23fa6904739307f278c14f94c95bf1"
+ },
+ "actions/setup-go@v6.5.0": {
+ "repo": "actions/setup-go",
+ "version": "v6.5.0",
+ "sha": "924ae3a1cded613372ab5595356fb5720e22ba16"
+ },
+ "actions/setup-java@v5.4.0": {
+ "repo": "actions/setup-java",
+ "version": "v5.4.0",
+ "sha": "1bcf9fb12cf4aa7d266a90ae39939e61372fe520"
+ },
+ "actions/setup-node@v6.4.0": {
+ "repo": "actions/setup-node",
+ "version": "v6.4.0",
+ "sha": "48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e"
+ },
+ "actions/setup-python@v6.3.0": {
+ "repo": "actions/setup-python",
+ "version": "v6.3.0",
+ "sha": "ece7cb06caefa5fff74198d8649806c4678c61a1"
+ },
+ "actions/upload-artifact@v7.0.1": {
+ "repo": "actions/upload-artifact",
+ "version": "v7.0.1",
+ "sha": "043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"
+ },
+ "anchore/sbom-action@v0.24.0": {
+ "repo": "anchore/sbom-action",
+ "version": "v0.24.0",
+ "sha": "e22c389904149dbc22b58101806040fa8d37a610"
+ },
+ "astral-sh/setup-uv@v8.2.0": {
+ "repo": "astral-sh/setup-uv",
+ "version": "v8.2.0",
+ "sha": "fac544c07dec837d0ccb6301d7b5580bf5edae39"
+ },
+ "denoland/setup-deno@v2.0.4": {
+ "repo": "denoland/setup-deno",
+ "version": "v2.0.4",
+ "sha": "667a34cdef165d8d2b2e98dde39547c9daac7282"
+ },
+ "docker/build-push-action@v7.2.0": {
+ "repo": "docker/build-push-action",
+ "version": "v7.2.0",
+ "sha": "f9f3042f7e2789586610d6e8b85c8f03e5195baf",
+ "released_at": "2026-05-21T15:23:58Z"
+ },
+ "docker/login-action@v4.2.0": {
+ "repo": "docker/login-action",
+ "version": "v4.2.0",
+ "sha": "650006c6eb7dba73a995cc03b0b2d7f5ca915bee",
+ "released_at": "2026-05-22T11:55:00Z"
+ },
+ "docker/metadata-action@v6.1.0": {
+ "repo": "docker/metadata-action",
+ "version": "v6.1.0",
+ "sha": "80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9"
+ },
+ "docker/setup-buildx-action@v4.1.0": {
+ "repo": "docker/setup-buildx-action",
+ "version": "v4.1.0",
+ "sha": "d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5"
+ },
+ "erlef/setup-beam@v1.24.0": {
+ "repo": "erlef/setup-beam",
+ "version": "v1.24.0",
+ "sha": "fc68ffb90438ef2936bbb3251622353b3dcb2f93"
+ },
+ "github/codeql-action/upload-sarif@v4.36.2": {
+ "repo": "github/codeql-action/upload-sarif",
+ "version": "v4.36.2",
+ "sha": "8aad20d150bbac5944a9f9d289da16a4b0d87c1e"
+ },
+ "github/stale-repos@v9.0.15": {
+ "repo": "github/stale-repos",
+ "version": "v9.0.15",
+ "sha": "a0db8bfe2318ed6ddbd01e95d7633803f99f77e9"
+ },
+ "haskell-actions/setup@v2.11.0": {
+ "repo": "haskell-actions/setup",
+ "version": "v2.11.0",
+ "sha": "cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553"
+ },
+ "oven-sh/setup-bun@v2.2.0": {
+ "repo": "oven-sh/setup-bun",
+ "version": "v2.2.0",
+ "sha": "0c5077e51419868618aeaa5fe8019c62421857d6"
+ },
+ "ruby/setup-ruby@v1.314.0": {
+ "repo": "ruby/setup-ruby",
+ "version": "v1.314.0",
+ "sha": "9eb537ca036ebaed86729dcb9309076e4c5c3b74"
+ },
+ "safedep/pmg@v1": {
+ "repo": "safedep/pmg",
+ "version": "v1",
+ "sha": "46cc70db535107183c9e752bb55d1d5c5f1a9290"
+ },
+ "super-linter/super-linter@v8.7.0": {
+ "repo": "super-linter/super-linter",
+ "version": "v8.7.0",
+ "sha": "4ce20838b8ab83717e78138c5b3a1407148e0918"
+ }
+ },
+ "containers": {
+ "alpine:latest": {
+ "image": "alpine:latest",
+ "digest": "sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11",
+ "pinned_image": "alpine:latest@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11"
+ },
+ "docker.io/mcp/brave-search": {
+ "image": "docker.io/mcp/brave-search",
+ "digest": "sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22",
+ "pinned_image": "docker.io/mcp/brave-search@sha256:ca96b8acb27d8cf601a8faef86a084602cffa41d8cb18caa1e29ba4d16989d22"
+ },
+ "ghcr.io/chopratejas/headroom:latest": {
+ "image": "ghcr.io/chopratejas/headroom:latest",
+ "digest": "sha256:af709363c4f9515a88a50939baec513be13c7cd778fb6635527b104d5173cb1e",
+ "pinned_image": "ghcr.io/chopratejas/headroom:latest@sha256:af709363c4f9515a88a50939baec513be13c7cd778fb6635527b104d5173cb1e"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29",
+ "digest": "sha256:97b4cc14dc2123a45b9d5b9927489f66882dec5857de6afc0e5bab257be92ef1",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.25.29@sha256:97b4cc14dc2123a45b9d5b9927489f66882dec5857de6afc0e5bab257be92ef1"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13",
+ "digest": "sha256:676de58a0abad8054cd9d4fc45b861715856819f083a268372d60bca0090018c",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.13@sha256:676de58a0abad8054cd9d4fc45b861715856819f083a268372d60bca0090018c"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.18": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.18",
+ "digest": "sha256:c77e8c26bab6c39e8568d8e2f8c17015944849a8cbcdfb4bd9725d8893725ca2",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.18@sha256:c77e8c26bab6c39e8568d8e2f8c17015944849a8cbcdfb4bd9725d8893725ca2"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.20": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.20",
+ "digest": "sha256:9161f2415a3306a344aca34dd671ee69f122317e0a512e66dc64c94b9c508682",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.20@sha256:9161f2415a3306a344aca34dd671ee69f122317e0a512e66dc64c94b9c508682"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.28": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.28",
+ "digest": "sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.29": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.29",
+ "digest": "sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.29@sha256:e68f37e36962dcb3f3d1de680a49bc2302cefd001b941a7dc377155ec7ce42f4"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.40": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.40",
+ "digest": "sha256:14ff567e8d9d4c2fbc5e55c973488381c71d7e0fdbe72d30ee7b8a738fd86504",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.40@sha256:14ff567e8d9d4c2fbc5e55c973488381c71d7e0fdbe72d30ee7b8a738fd86504"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.41": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.41",
+ "digest": "sha256:cb2b565d070116d4b67e355775340528b5a2c3cb18b2c9049638bcc2df681770",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.41@sha256:cb2b565d070116d4b67e355775340528b5a2c3cb18b2c9049638bcc2df681770"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.66": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.66",
+ "digest": "sha256:8373ba626ffd28ce1af503a3218205fa7744a5774479173f92e50a378a1ed00d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.66@sha256:8373ba626ffd28ce1af503a3218205fa7744a5774479173f92e50a378a1ed00d"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.67": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.67",
+ "digest": "sha256:0f54fa48dd1a03ef6d171574eecf9a9edbf0406cea011a534cd12ed1fcb46715",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.67@sha256:0f54fa48dd1a03ef6d171574eecf9a9edbf0406cea011a534cd12ed1fcb46715"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.0": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.0",
+ "digest": "sha256:3816d1692e6d96887b27f1e4f1d64b8d7edb43ed9d7506b8f203913cbb81c248",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.0@sha256:3816d1692e6d96887b27f1e4f1d64b8d7edb43ed9d7506b8f203913cbb81c248"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.1": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.1",
+ "digest": "sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.1@sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.11": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.11",
+ "digest": "sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.11@sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.12": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.12",
+ "digest": "sha256:a3911ae633bfc49a96be10e660d447b65023731850fee3de8a074ff8861ffde3",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.12@sha256:a3911ae633bfc49a96be10e660d447b65023731850fee3de8a074ff8861ffde3"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.13": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.13",
+ "digest": "sha256:691a06b64961b5b35aac117eaace202fa721e91da19d1d2e22dcdd6663cd571b",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.13@sha256:691a06b64961b5b35aac117eaace202fa721e91da19d1d2e22dcdd6663cd571b"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.2": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.2",
+ "digest": "sha256:f88e5b17b6b7a600117bc121114d6ce2155c88c983c0c939c5df884f730fa1d6",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.2@sha256:f88e5b17b6b7a600117bc121114d6ce2155c88c983c0c939c5df884f730fa1d6"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.22": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.22",
+ "digest": "sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.4": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.4",
+ "digest": "sha256:b268ebf37df2428b19efcb383f001d65dc6a5ec10af43feb886d1a8477ab0e3a",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.4@sha256:b268ebf37df2428b19efcb383f001d65dc6a5ec10af43feb886d1a8477ab0e3a"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.6": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.6",
+ "digest": "sha256:5b778c712a25397a38a47cee3467a9cbc726b16320cc133a0758c0592a6f0792",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.6@sha256:5b778c712a25397a38a47cee3467a9cbc726b16320cc133a0758c0592a6f0792"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.7": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.7",
+ "digest": "sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.7@sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c"
+ },
+ "ghcr.io/github/gh-aw-firewall/agent:0.27.9": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.27.9",
+ "digest": "sha256:13f522853a688bfe24b04adbbe40b68101e8ef4b6fe0b636068527141bf1c269",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.9@sha256:13f522853a688bfe24b04adbbe40b68101e8ef4b6fe0b636068527141bf1c269"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18",
+ "digest": "sha256:d16a40a3ca6e989896d0cef9f31b9412bb1fcc8755bafcafb95012ae1078539b",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.18@sha256:d16a40a3ca6e989896d0cef9f31b9412bb1fcc8755bafcafb95012ae1078539b"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20",
+ "digest": "sha256:6971639e381e82e45134bcd333181f456df3a52cd6f818a3e3d6de068ff91519",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.20@sha256:6971639e381e82e45134bcd333181f456df3a52cd6f818a3e3d6de068ff91519"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28",
+ "digest": "sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29",
+ "digest": "sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.29@sha256:d1219e4110684402aabbeb5a43858f26790c9d0be210581cf3f7a521bd2c87b6"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40",
+ "digest": "sha256:2883ca3e5ae9f330cafdd9345bfd4ae17fc8da36c96d4c9a1f76e922b4c45280",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.40@sha256:2883ca3e5ae9f330cafdd9345bfd4ae17fc8da36c96d4c9a1f76e922b4c45280"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41",
+ "digest": "sha256:fadd0de387209f69a9a7a1b8722bb5e7fdfb80ba9749a5c60f0e4cd7582a74d0",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.41@sha256:fadd0de387209f69a9a7a1b8722bb5e7fdfb80ba9749a5c60f0e4cd7582a74d0"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66",
+ "digest": "sha256:4da87d0c633816cec29a26b1d1ed5fbcb0df38de19075f0429bf1d6deec3dcdc",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.66@sha256:4da87d0c633816cec29a26b1d1ed5fbcb0df38de19075f0429bf1d6deec3dcdc"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67",
+ "digest": "sha256:d3f51df1869bda0e1f71ae31a81450641c6ae67404e0769469aae34c2738aeb5",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.67@sha256:d3f51df1869bda0e1f71ae31a81450641c6ae67404e0769469aae34c2738aeb5"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0",
+ "digest": "sha256:f28d2bd3197fb6ef9ec40ef345bbf2bb33e50151a8e72e89abb618fc3d0066eb",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.0@sha256:f28d2bd3197fb6ef9ec40ef345bbf2bb33e50151a8e72e89abb618fc3d0066eb"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1",
+ "digest": "sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1@sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11",
+ "digest": "sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11@sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12",
+ "digest": "sha256:2329aff5e54bb5bf466ad94182eebbdfe4a4db497a9dfbe87442eb3400aa4a86",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.12@sha256:2329aff5e54bb5bf466ad94182eebbdfe4a4db497a9dfbe87442eb3400aa4a86"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13",
+ "digest": "sha256:c57febf4aeeefbb4fd96f5b12c07f4279ca55edca6a700032debf9dd0787286e",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.13@sha256:c57febf4aeeefbb4fd96f5b12c07f4279ca55edca6a700032debf9dd0787286e"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2",
+ "digest": "sha256:ee39841d980878ebbb87592903b06d31a1af500c71525c9616f7e8e2a27041a4",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2@sha256:ee39841d980878ebbb87592903b06d31a1af500c71525c9616f7e8e2a27041a4"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22",
+ "digest": "sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4",
+ "digest": "sha256:3ea0d12a2d124db8ed6e2d18aff040e30ab3568161f258a132fccdeede4198cd",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4@sha256:3ea0d12a2d124db8ed6e2d18aff040e30ab3568161f258a132fccdeede4198cd"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6",
+ "digest": "sha256:7b14e481f3a9898f1e9be50acc4e58541d9fcd85b49b1e4945b708f1bf1bf68e",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.6@sha256:7b14e481f3a9898f1e9be50acc4e58541d9fcd85b49b1e4945b708f1bf1bf68e"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7",
+ "digest": "sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7@sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9",
+ "digest": "sha256:9fec93937dc9d3e04f3954705c2c42f58976ebb8479b10778602631b5316e1e2",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.9@sha256:9fec93937dc9d3e04f3954705c2c42f58976ebb8479b10778602631b5316e1e2"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28",
+ "digest": "sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28@sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29",
+ "digest": "sha256:29917488eb90a01ff9544ffeeb5cc26434a8ea16d69ae8972f5f6be0e567e276",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.29@sha256:29917488eb90a01ff9544ffeeb5cc26434a8ea16d69ae8972f5f6be0e567e276"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40",
+ "digest": "sha256:3e7152911d4b4b7b97beef9d3d7d924ff7902227e86001ef3838fb728d5d514c",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.40@sha256:3e7152911d4b4b7b97beef9d3d7d924ff7902227e86001ef3838fb728d5d514c"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41",
+ "digest": "sha256:62171f2fa508667b8b0a9e096f826983f312e3da0ce894f80c0f83a875af60fe",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.41@sha256:62171f2fa508667b8b0a9e096f826983f312e3da0ce894f80c0f83a875af60fe"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66",
+ "digest": "sha256:ff53f2b227ceaf7334baeab5daa2537211089aca251af9630cb0b5a8899492d0",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.66@sha256:ff53f2b227ceaf7334baeab5daa2537211089aca251af9630cb0b5a8899492d0"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67",
+ "digest": "sha256:97387002ec54c8ab9f255d5aaf3d435071642e058f528c8268ca0e80b201609a",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.67@sha256:97387002ec54c8ab9f255d5aaf3d435071642e058f528c8268ca0e80b201609a"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0",
+ "digest": "sha256:42529ecb9f90da5adb00593d268dfdbd35d14bb1dc92dd897286b27ce1e3d58d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.0@sha256:42529ecb9f90da5adb00593d268dfdbd35d14bb1dc92dd897286b27ce1e3d58d"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1",
+ "digest": "sha256:2e6dc98321dbf82840f83ec0ef8b198506149255a15d3a7854d59c0d34063e27",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.1@sha256:2e6dc98321dbf82840f83ec0ef8b198506149255a15d3a7854d59c0d34063e27"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12",
+ "digest": "sha256:7d267199839cc0f23c01fd39f8c050a5d86cb6cc5058aa829cd472f405fb1a1d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.12@sha256:7d267199839cc0f23c01fd39f8c050a5d86cb6cc5058aa829cd472f405fb1a1d"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13",
+ "digest": "sha256:79dfd3a5d139bd1956ba6d7d1782b831a07175cf5afa29c45cb20bb0140f23c5",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.13@sha256:79dfd3a5d139bd1956ba6d7d1782b831a07175cf5afa29c45cb20bb0140f23c5"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2",
+ "digest": "sha256:02f3ec08f32dc26c5427920c6a2e2f3036238fce44802f2f11ef49ed8621b5d0",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.2@sha256:02f3ec08f32dc26c5427920c6a2e2f3036238fce44802f2f11ef49ed8621b5d0"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22",
+ "digest": "sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4",
+ "digest": "sha256:72c378c029d2fad4684847ab44c329e526ac6b1a78cdf97656870ea11d201545",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4@sha256:72c378c029d2fad4684847ab44c329e526ac6b1a78cdf97656870ea11d201545"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6",
+ "digest": "sha256:194b21f5d3284b0b2abf2603a14ec607f89d798165a7ef453667706c69401735",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.6@sha256:194b21f5d3284b0b2abf2603a14ec607f89d798165a7ef453667706c69401735"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7",
+ "digest": "sha256:4757f198a3fa20f88bdbe70be7ae1a05f127d9c0a9e96a5d6460ef40c08fc83d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.7@sha256:4757f198a3fa20f88bdbe70be7ae1a05f127d9c0a9e96a5d6460ef40c08fc83d"
+ },
+ "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9": {
+ "image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9",
+ "digest": "sha256:89b715de241408e03d35d5c4851361ae350f69aa56d7955dd2ed1d6d3ce037cc",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.9@sha256:89b715de241408e03d35d5c4851361ae350f69aa56d7955dd2ed1d6d3ce037cc"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.18": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.18",
+ "digest": "sha256:eb102afcfbae26ffcec016adebb74d3be7b0a5bf376ba306599cdf3effbe288e",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.18@sha256:eb102afcfbae26ffcec016adebb74d3be7b0a5bf376ba306599cdf3effbe288e"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.20": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.20",
+ "digest": "sha256:5411d903f73ee597e6a084971c2adef3eb0bd405910df3ed7bf5e3d6bd58a236",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.20@sha256:5411d903f73ee597e6a084971c2adef3eb0bd405910df3ed7bf5e3d6bd58a236"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.28": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.28",
+ "digest": "sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.29": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.29",
+ "digest": "sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.29@sha256:8a71ad9e40454051672312917e51567abfb8251d7c294d086c48f63d84e4cb53"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.40": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.40",
+ "digest": "sha256:b084f4a2c771f584ee68084ced52fa6b3245197a1889645d817462d307d3ac51",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.40@sha256:b084f4a2c771f584ee68084ced52fa6b3245197a1889645d817462d307d3ac51"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.41": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.41",
+ "digest": "sha256:1260445d25968dbf3ae70143964177a0e5914cf2ce07a6117f7d3caec6c3e3c4",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.41@sha256:1260445d25968dbf3ae70143964177a0e5914cf2ce07a6117f7d3caec6c3e3c4"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.66": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.66",
+ "digest": "sha256:9c47e6d0210c5b1581b56d1fe8ac32c1d8fdd7cb04ef95592f2431e59f533bd3",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.66@sha256:9c47e6d0210c5b1581b56d1fe8ac32c1d8fdd7cb04ef95592f2431e59f533bd3"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.67": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.67",
+ "digest": "sha256:9a05085db054f41bd67c772bcfc25cabc15bc33ee993b051a31e30669dd2031f",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.67@sha256:9a05085db054f41bd67c772bcfc25cabc15bc33ee993b051a31e30669dd2031f"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.0": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.0",
+ "digest": "sha256:d6a01d4cf3d928e6a7fc42e34afef228e753dce87646edc91d8a5cd0b612d9a6",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.0@sha256:d6a01d4cf3d928e6a7fc42e34afef228e753dce87646edc91d8a5cd0b612d9a6"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.1": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.1",
+ "digest": "sha256:1f3df3207dc9faa9080088115ca50a5ab0d7a692c61dffa8c8898d0b7b750413",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.1@sha256:1f3df3207dc9faa9080088115ca50a5ab0d7a692c61dffa8c8898d0b7b750413"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.11": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.11",
+ "digest": "sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.11@sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.12": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.12",
+ "digest": "sha256:f5d9403364543b23a8510278854cf5517345419daed19de044a7130c03388484",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.12@sha256:f5d9403364543b23a8510278854cf5517345419daed19de044a7130c03388484"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.13": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.13",
+ "digest": "sha256:700b1b5a73098373b04fb684f291e95d9be0124ab559717b04f27acaf8b41bed",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.13@sha256:700b1b5a73098373b04fb684f291e95d9be0124ab559717b04f27acaf8b41bed"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.2": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.2",
+ "digest": "sha256:2e3a717e5f19a654cd9a2263beb52012b56bcb68562ec5ae2e42f9d156b49591",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.2@sha256:2e3a717e5f19a654cd9a2263beb52012b56bcb68562ec5ae2e42f9d156b49591"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.22": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.22",
+ "digest": "sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.4": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.4",
+ "digest": "sha256:87979038897e40caed22245b64d1daa796390d2dca289b99d3d1174c85740af8",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.4@sha256:87979038897e40caed22245b64d1daa796390d2dca289b99d3d1174c85740af8"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.6": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.6",
+ "digest": "sha256:730985e67931b9774545bce76b3ac5a354aa1dc11f19ee8f2d9cbf3211d73c3a",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.6@sha256:730985e67931b9774545bce76b3ac5a354aa1dc11f19ee8f2d9cbf3211d73c3a"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.7": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.7",
+ "digest": "sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.7@sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.27.9": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.27.9",
+ "digest": "sha256:f186085bd04864e59f5057ff9e6bbd506475275ffe165111517d7d1acdc1de9c",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.9@sha256:f186085bd04864e59f5057ff9e6bbd506475275ffe165111517d7d1acdc1de9c"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.2.19": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.2.19",
+ "digest": "sha256:44d4d8de7e6c37aaea484eba489940c52df6a0b54078ddcbc9327592d5b3c3dd",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.2.19@sha256:44d4d8de7e6c37aaea484eba489940c52df6a0b54078ddcbc9327592d5b3c3dd"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.2.30": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.2.30",
+ "digest": "sha256:e950e6d39f003862d33bfb8d4eb93e242d919cf6ca874b90728e5e0ea7434c6f",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.2.30@sha256:e950e6d39f003862d33bfb8d4eb93e242d919cf6ca874b90728e5e0ea7434c6f"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.0": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.0",
+ "digest": "sha256:9c2228324fb1f26f39dc9471612e530ae3efc3156dac05efb2e8d212878d454d",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.0@sha256:9c2228324fb1f26f39dc9471612e530ae3efc3156dac05efb2e8d212878d454d"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.1": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.1",
+ "digest": "sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.1@sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.16": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.16",
+ "digest": "sha256:8001e4bfa52d45abd05c45a8f855ce62bc893eb66e4807bb487bf2ff07fc1473",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.16@sha256:8001e4bfa52d45abd05c45a8f855ce62bc893eb66e4807bb487bf2ff07fc1473"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.23": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.23",
+ "digest": "sha256:0dd1bd91a41e24a3ccc31b1ec6cb61d36608997fabf91f2d643b64e3fc33180a",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.23@sha256:0dd1bd91a41e24a3ccc31b1ec6cb61d36608997fabf91f2d643b64e3fc33180a"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.24": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.24",
+ "digest": "sha256:72cc921901afa1d67b6fee568f110c6b84436624c437fb2996d14c83e90a2b54",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.24@sha256:72cc921901afa1d67b6fee568f110c6b84436624c437fb2996d14c83e90a2b54"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.25": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.25",
+ "digest": "sha256:c10331ad17668ef89f38f5e356678788a40b0cd5fef96e8f92e1d9c1de47cbaa",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.25@sha256:c10331ad17668ef89f38f5e356678788a40b0cd5fef96e8f92e1d9c1de47cbaa"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.26": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.26",
+ "digest": "sha256:d3b03f54eee3a8176818c9a52087623e45b7f644a28814337fcc0838e2534490",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.26@sha256:d3b03f54eee3a8176818c9a52087623e45b7f644a28814337fcc0838e2534490"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.27": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.27",
+ "digest": "sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.27@sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.29": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.29",
+ "digest": "sha256:f24e968e6e5aeb819e9a98b9d273efe36b0fc1a0cb17e9ace263b5ab20de87cd",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.29@sha256:f24e968e6e5aeb819e9a98b9d273efe36b0fc1a0cb17e9ace263b5ab20de87cd"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.30": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.30",
+ "digest": "sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.30@sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.31": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.31",
+ "digest": "sha256:3147d7332939aeb2bc6a4220d96f6a0ca600b5cc0971200eca3d1e948fc8122a",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.31@sha256:3147d7332939aeb2bc6a4220d96f6a0ca600b5cc0971200eca3d1e948fc8122a"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.32": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.32",
+ "digest": "sha256:63e46b56dfd70895a701b6fc6dd0189e11e2d875f327f1781e81b31848735477",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.32@sha256:63e46b56dfd70895a701b6fc6dd0189e11e2d875f327f1781e81b31848735477"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.33": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.33",
+ "digest": "sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.6": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.6",
+ "digest": "sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.6@sha256:2bb8eef86006a4c5963c55616a9c51c32f27bfdecb023b8aa6f91f6718d9171c"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.8": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.8",
+ "digest": "sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.8@sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.9": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.9",
+ "digest": "sha256:64828b42a4482f58fab16509d7f8f495a6d97c972a98a68aff20543531ac0388",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.9@sha256:64828b42a4482f58fab16509d7f8f495a6d97c972a98a68aff20543531ac0388"
+ },
+ "ghcr.io/github/gh-aw-node": {
+ "image": "ghcr.io/github/gh-aw-node",
+ "digest": "sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b",
+ "pinned_image": "ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"
+ },
+ "ghcr.io/github/github-mcp-server:v0.32.0": {
+ "image": "ghcr.io/github/github-mcp-server:v0.32.0",
+ "digest": "sha256:2763823c63bcca718ce53850a1d7fcf2f501ec84028394f1b63ce7e9f4f9be28",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v0.32.0@sha256:2763823c63bcca718ce53850a1d7fcf2f501ec84028394f1b63ce7e9f4f9be28"
+ },
+ "ghcr.io/github/github-mcp-server:v1.0.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.0.0",
+ "digest": "sha256:d2550953f8050bc5a1c8f80d1678766f66f60bbfbcd953fdeaf661fe4269bd95",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.0@sha256:d2550953f8050bc5a1c8f80d1678766f66f60bbfbcd953fdeaf661fe4269bd95"
+ },
+ "ghcr.io/github/github-mcp-server:v1.0.3": {
+ "image": "ghcr.io/github/github-mcp-server:v1.0.3",
+ "digest": "sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.3@sha256:2ac27ef03461ef2b877031b838a7d1fd7f12b12d4ace7796d8cad91446d55959"
+ },
+ "ghcr.io/github/github-mcp-server:v1.0.4": {
+ "image": "ghcr.io/github/github-mcp-server:v1.0.4",
+ "digest": "sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.0.4@sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4"
+ },
+ "ghcr.io/github/github-mcp-server:v1.1.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.1.0",
+ "digest": "sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.0@sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029"
+ },
+ "ghcr.io/github/github-mcp-server:v1.1.2": {
+ "image": "ghcr.io/github/github-mcp-server:v1.1.2",
+ "digest": "sha256:30197479d8036c7811892bc07e06f9a05c9ef3cdd79bc59f256d50647f95788c",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.2@sha256:30197479d8036c7811892bc07e06f9a05c9ef3cdd79bc59f256d50647f95788c"
+ },
+ "ghcr.io/github/github-mcp-server:v1.3.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.3.0",
+ "digest": "sha256:5c83359327a0bacc3d34db730bea6557d39d341cee0bf6c58c9a896e33150e80",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.3.0@sha256:5c83359327a0bacc3d34db730bea6557d39d341cee0bf6c58c9a896e33150e80"
+ },
+ "ghcr.io/github/github-mcp-server:v1.4.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.4.0",
+ "digest": "sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"
+ },
+ "ghcr.io/github/github-mcp-server:v1.5.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.5.0",
+ "digest": "sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"
+ },
+ "ghcr.io/github/serena-mcp-server:latest": {
+ "image": "ghcr.io/github/serena-mcp-server:latest",
+ "digest": "sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5",
+ "pinned_image": "ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"
+ },
+ "grafana/mcp-grafana": {
+ "image": "grafana/mcp-grafana",
+ "digest": "sha256:60a4e3a417a69eeb864a72052c53b4aa4466ff3577d6ef9bacc671f4b77d7090",
+ "pinned_image": "grafana/mcp-grafana@sha256:60a4e3a417a69eeb864a72052c53b4aa4466ff3577d6ef9bacc671f4b77d7090"
+ },
+ "mcp/arxiv-mcp-server": {
+ "image": "mcp/arxiv-mcp-server",
+ "digest": "sha256:6dc6bba6dfed97f4ad6eb8d23a5c98ef5b7fa6184937d54b2d675801cd9dd29e",
+ "pinned_image": "mcp/arxiv-mcp-server@sha256:6dc6bba6dfed97f4ad6eb8d23a5c98ef5b7fa6184937d54b2d675801cd9dd29e"
+ },
+ "mcp/ast-grep:latest": {
+ "image": "mcp/ast-grep:latest",
+ "digest": "sha256:5fc3f2e9dcf2c019e92662f608b8d89e12134ed6d91e6f5461de6efd506a1e72",
+ "pinned_image": "mcp/ast-grep:latest@sha256:5fc3f2e9dcf2c019e92662f608b8d89e12134ed6d91e6f5461de6efd506a1e72"
+ },
+ "mcp/context7": {
+ "image": "mcp/context7",
+ "digest": "sha256:1174e6a29634a83b2be93ac1fefabf63265f498c02c72201fe3464e687dd8836",
+ "pinned_image": "mcp/context7@sha256:1174e6a29634a83b2be93ac1fefabf63265f498c02c72201fe3464e687dd8836"
+ },
+ "mcp/markitdown": {
+ "image": "mcp/markitdown",
+ "digest": "sha256:1cef3bf502503310ed0884441874ccf6cdaac20136dc1179797fa048269dc4cb",
+ "pinned_image": "mcp/markitdown@sha256:1cef3bf502503310ed0884441874ccf6cdaac20136dc1179797fa048269dc4cb"
+ },
+ "mcp/memory": {
+ "image": "mcp/memory",
+ "digest": "sha256:db0c2db07a44b6797eba7a832b1bda142ffc899588aae82c92780cbb2252407f",
+ "pinned_image": "mcp/memory@sha256:db0c2db07a44b6797eba7a832b1bda142ffc899588aae82c92780cbb2252407f"
+ },
+ "mcp/notion": {
+ "image": "mcp/notion",
+ "digest": "sha256:4de8eb0de33402fcbd3740b4f4039918e4893155c7ea833c7a0c472001b88367",
+ "pinned_image": "mcp/notion@sha256:4de8eb0de33402fcbd3740b4f4039918e4893155c7ea833c7a0c472001b88367"
+ },
+ "mcr.microsoft.com/playwright/mcp": {
+ "image": "mcr.microsoft.com/playwright/mcp",
+ "digest": "sha256:7b82f29c6ef83480a97f612d53ac3fd5f30a32df3fea1e06923d4204d3532bb2",
+ "pinned_image": "mcr.microsoft.com/playwright/mcp@sha256:7b82f29c6ef83480a97f612d53ac3fd5f30a32df3fea1e06923d4204d3532bb2"
+ },
+ "node:lts-alpine": {
+ "image": "node:lts-alpine",
+ "digest": "sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14",
+ "pinned_image": "node:lts-alpine@sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14"
+ },
+ "python:alpine": {
+ "image": "python:alpine",
+ "digest": "sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116",
+ "pinned_image": "python:alpine@sha256:6f873e340e6786787a632c919ecfb1d2301eb33ccfbe9f0d0add16cbc0892116"
+ },
+ "semgrep/semgrep:latest": {
+ "image": "semgrep/semgrep:latest",
+ "digest": "sha256:17d89ddd91a7729bbd5de09402f7f79a70204289e2a94635086e9db532a495f2",
+ "pinned_image": "semgrep/semgrep:latest@sha256:17d89ddd91a7729bbd5de09402f7f79a70204289e2a94635086e9db532a495f2"
}
+ }
}
diff --git a/.github/workflows/shared/token-telemetry-check.md b/.github/workflows/shared/token-telemetry-check.md
new file mode 100644
index 00000000000..88036e9861f
--- /dev/null
+++ b/.github/workflows/shared/token-telemetry-check.md
@@ -0,0 +1,90 @@
+---
+jobs:
+ check_token_telemetry:
+ runs-on: ubuntu-latest
+ needs: [agent]
+ if: needs.agent.result == 'success'
+ permissions:
+ contents: read
+ steps:
+ - name: Download agent artifact
+ id: download-agent
+ continue-on-error: true
+ uses: actions/download-artifact@v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+---
+
diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml
index 86a7d0985f4..794d0b7b902 100644
--- a/.github/workflows/smoke-claude.lock.yml
+++ b/.github/workflows/smoke-claude.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3bb54a9af96721ea336a4258cc72a97f2cf1d57bfebeaf81badedab154b87260","body_hash":"36c065e0560b79a1c971cb1ef686449073e0170c2e67f5e10ecd9ebd481b02fc","strict":true,"agent_id":"claude","engine_versions":{"claude":"2.1.201"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"475e266b0c4312ac38303cf66aaa7efbec91e0b70f987b3e08039fb0e77c5ad9","body_hash":"001852ff1ecf9859257ef5bdf7fa0efbf3bb9e2db1ed46535696062e80aeb45c","strict":true,"agent_id":"claude","engine_versions":{"claude":"2.1.201"}}
# gh-aw-manifest: {"version":1,"secrets":["ANTHROPIC_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","TAVILY_API_KEY"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"f9f3042f7e2789586610d6e8b85c8f03e5195baf","version":"v7.2.0"},{"repo":"docker/setup-buildx-action","sha":"d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5","version":"v4.1.0"},{"repo":"github/codeql-action/upload-sarif","sha":"8aad20d150bbac5944a9f9d289da16a4b0d87c1e","version":"v4.36.2"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -32,6 +32,7 @@
# - shared/go-make.md
# - shared/mcp/tavily.md
# - shared/otlp.md
+# - shared/token-telemetry-check.md
#
# inlined-imports: true
#
@@ -429,6 +430,7 @@ jobs:
+
**Important**: If no action is needed after completing your analysis, you **MUST** call the `noop` safe-output tool with a brief explanation. Pass arguments directly to the tool. Do **NOT** wrap them under a `noop` key. Failing to call any safe-output tool is the most common cause of safe-output workflow failures.
```json
@@ -1954,10 +1956,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
- update_cache_memory
diff --git a/.github/workflows/smoke-claude.md b/.github/workflows/smoke-claude.md
index aba38480226..3b66179dc2a 100644
--- a/.github/workflows/smoke-claude.md
+++ b/.github/workflows/smoke-claude.md
@@ -34,6 +34,7 @@ imports:
- shared/go-make.md
- shared/github-mcp-app.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml
index dbd60c76839..9d952f4e388 100644
--- a/.github/workflows/smoke-codex.lock.yml
+++ b/.github/workflows/smoke-codex.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"42a605ac96d9044f6b6da08a4ebdf7db4c1c2f261b7660d34fabd9d0e9701da0","body_hash":"2148439cf2a717e019b1235ae583d7f6087ecc038accee7a93e3b54b3c24c6b9","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.142.5"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f4c25dc4e3ebaa00201eec60464e37b5d059d7c2c14344ad95baab84851c84c8","body_hash":"71703d81d442ba6c0853517c3c7256b6456ac4af23b6f6424182ef84b9e94523","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.142.5"}}
# gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions-ecosystem/action-add-labels","sha":"c96b68fec76a0987cd93957189e9abd0b9a72ff1","version":"v1.1.3"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -33,6 +33,7 @@
# - shared/otlp.md
# - shared/reporting.md
# - shared/reporting-otlp.md
+# - shared/token-telemetry-check.md
# - shared/trufflehog.md
#
# Secrets used:
@@ -329,25 +330,25 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_5315c6df59ccee24_EOF'
+ cat << 'GH_AW_PROMPT_d4067f64d6a77e8d_EOF'
- GH_AW_PROMPT_5315c6df59ccee24_EOF
+ GH_AW_PROMPT_d4067f64d6a77e8d_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_5315c6df59ccee24_EOF'
+ cat << 'GH_AW_PROMPT_d4067f64d6a77e8d_EOF'
Tools: add_comment(max:2), create_issue, add_labels, remove_labels, unassign_from_user, hide_comment(max:5), set_issue_field, missing_tool, missing_data, noop, add_smoked_label
- GH_AW_PROMPT_5315c6df59ccee24_EOF
+ GH_AW_PROMPT_d4067f64d6a77e8d_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_comment_memory.md"
- cat << 'GH_AW_PROMPT_5315c6df59ccee24_EOF'
+ cat << 'GH_AW_PROMPT_d4067f64d6a77e8d_EOF'
- GH_AW_PROMPT_5315c6df59ccee24_EOF
+ GH_AW_PROMPT_d4067f64d6a77e8d_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_5315c6df59ccee24_EOF'
+ cat << 'GH_AW_PROMPT_d4067f64d6a77e8d_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -389,25 +390,26 @@ jobs:
stop immediately and report the limitation rather than spending turns trying to work around it.
- GH_AW_PROMPT_5315c6df59ccee24_EOF
+ GH_AW_PROMPT_d4067f64d6a77e8d_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_5315c6df59ccee24_EOF'
+ cat << 'GH_AW_PROMPT_d4067f64d6a77e8d_EOF'
{{#runtime-import .github/workflows/shared/gh.md}}
{{#runtime-import .github/workflows/shared/reporting-otlp.md}}
{{#runtime-import .github/workflows/shared/mcp/serena-go.md}}
{{#runtime-import .github/workflows/shared/trufflehog.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/reporting.md}}
## Serena Code Analysis
Serena is enabled for **["go"]** in `__GH_AW_GITHUB_WORKSPACE__`. Start by calling `activate_project` with that workspace path, then prefer Serena semantic tools for symbol lookup, references, docs, diagnostics, and structured edits.
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-codex.md}}
- GH_AW_PROMPT_5315c6df59ccee24_EOF
+ GH_AW_PROMPT_d4067f64d6a77e8d_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1473,10 +1475,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
- trufflehog_scan
diff --git a/.github/workflows/smoke-codex.md b/.github/workflows/smoke-codex.md
index 159e8ebb169..ef9e4b82194 100644
--- a/.github/workflows/smoke-codex.md
+++ b/.github/workflows/smoke-codex.md
@@ -31,6 +31,7 @@ imports:
- shared/mcp/serena-go.md
- shared/trufflehog.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml
index 4e850828440..a0b985d9bb3 100644
--- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml
+++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"375f6474ae21f8b625f17901cc43c512496306cc98a1e6c08bde14a3f6fae730","body_hash":"a13876411448bd11c97a456387470b0f60ff28cfee436da38ec13d1abdbd7584","strict":true,"agent_id":"copilot","agent_model":"o4-mini-aw","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e7a11d2101f5cb4b30040d7009126f732a10632260f98866a7efc76da7446fd6","body_hash":"0e13cfa0290b65aff1b709d8b9ef21101a50c0560621f6531d2cac29fa714f74","strict":true,"agent_id":"copilot","agent_model":"o4-mini-aw","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["FOUNDRY_API_KEY","FOUNDRY_OPENAI_ENDPOINT","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"f9f3042f7e2789586610d6e8b85c8f03e5195baf","version":"v7.2.0"},{"repo":"docker/setup-buildx-action","sha":"d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5","version":"v4.1.0"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -34,6 +34,7 @@
# - shared/mcp/serena.md
# - shared/otlp.md
# - shared/reporting.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - FOUNDRY_API_KEY
@@ -372,25 +373,25 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_17ad83e4a655e128_EOF'
+ cat << 'GH_AW_PROMPT_c6fbd5be9f015671_EOF'
- GH_AW_PROMPT_17ad83e4a655e128_EOF
+ GH_AW_PROMPT_c6fbd5be9f015671_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_17ad83e4a655e128_EOF'
+ cat << 'GH_AW_PROMPT_c6fbd5be9f015671_EOF'
Tools: add_comment(max:2), create_issue, create_discussion, create_pull_request_review_comment(max:5), submit_pull_request_review, reply_to_pull_request_review_comment(max:5), add_labels, remove_labels, create_check_run, set_issue_type, dispatch_workflow, missing_tool, missing_data, noop, send_slack_message
- GH_AW_PROMPT_17ad83e4a655e128_EOF
+ GH_AW_PROMPT_c6fbd5be9f015671_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_comment_memory.md"
- cat << 'GH_AW_PROMPT_17ad83e4a655e128_EOF'
+ cat << 'GH_AW_PROMPT_c6fbd5be9f015671_EOF'
- GH_AW_PROMPT_17ad83e4a655e128_EOF
+ GH_AW_PROMPT_c6fbd5be9f015671_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_17ad83e4a655e128_EOF'
+ cat << 'GH_AW_PROMPT_c6fbd5be9f015671_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -419,12 +420,12 @@ jobs:
{{/if}}
- GH_AW_PROMPT_17ad83e4a655e128_EOF
+ GH_AW_PROMPT_c6fbd5be9f015671_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_17ad83e4a655e128_EOF'
+ cat << 'GH_AW_PROMPT_c6fbd5be9f015671_EOF'
{{#runtime-import .github/workflows/shared/github-guard-policy.md}}
{{#runtime-import .github/workflows/shared/gh.md}}
@@ -432,12 +433,13 @@ jobs:
{{#runtime-import .github/workflows/shared/github-queries-mcp-script.md}}
{{#runtime-import .github/workflows/shared/mcp/serena-go.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
## Serena Code Analysis
Serena is enabled for **["go"]** in `__GH_AW_GITHUB_WORKSPACE__`. Start by calling `activate_project` with that workspace path, then prefer Serena semantic tools for symbol lookup, references, docs, diagnostics, and structured edits.
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-copilot-aoai-apikey.md}}
- GH_AW_PROMPT_17ad83e4a655e128_EOF
+ GH_AW_PROMPT_c6fbd5be9f015671_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -2142,10 +2144,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-copilot-aoai-apikey.md b/.github/workflows/smoke-copilot-aoai-apikey.md
index 748a65a0272..e163ef82df1 100644
--- a/.github/workflows/smoke-copilot-aoai-apikey.md
+++ b/.github/workflows/smoke-copilot-aoai-apikey.md
@@ -40,6 +40,7 @@ imports:
- shared/github-queries-mcp-script.md
- shared/mcp/serena-go.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml
index 342f775a4fb..a06e6c03f56 100644
--- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml
+++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8ec2a94375e8330338a191ac08d92ece0a7eab4906dfed6975b0a4133332f057","body_hash":"37cb91ca24bfc273335fc9f42352436fb55cec08dde128c0b67e1c13dc516e7f","strict":true,"agent_id":"copilot","agent_model":"o4-mini-aw","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"32e19287d5401cd1b0bb25d24385340b6ce3f163537b86942cc3cba78ccda1c5","body_hash":"ed920da6b492875697d51da3258d3b5c57fdbb22ce259798ab3b71e2c500aa68","strict":true,"agent_id":"copilot","agent_model":"o4-mini-aw","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["FOUNDRY_OPENAI_ENDPOINT","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"f9f3042f7e2789586610d6e8b85c8f03e5195baf","version":"v7.2.0"},{"repo":"docker/setup-buildx-action","sha":"d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5","version":"v4.1.0"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -34,6 +34,7 @@
# - shared/mcp/serena.md
# - shared/otlp.md
# - shared/reporting.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - FOUNDRY_OPENAI_ENDPOINT
@@ -371,25 +372,25 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_0688b38d643fbc31_EOF'
+ cat << 'GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF'
- GH_AW_PROMPT_0688b38d643fbc31_EOF
+ GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_0688b38d643fbc31_EOF'
+ cat << 'GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF'
Tools: add_comment(max:2), create_issue, create_discussion, create_pull_request_review_comment(max:5), submit_pull_request_review, reply_to_pull_request_review_comment(max:5), add_labels, remove_labels, create_check_run, set_issue_type, dispatch_workflow, missing_tool, missing_data, noop, send_slack_message
- GH_AW_PROMPT_0688b38d643fbc31_EOF
+ GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_comment_memory.md"
- cat << 'GH_AW_PROMPT_0688b38d643fbc31_EOF'
+ cat << 'GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF'
- GH_AW_PROMPT_0688b38d643fbc31_EOF
+ GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_0688b38d643fbc31_EOF'
+ cat << 'GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -418,12 +419,12 @@ jobs:
{{/if}}
- GH_AW_PROMPT_0688b38d643fbc31_EOF
+ GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_0688b38d643fbc31_EOF'
+ cat << 'GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF'
{{#runtime-import .github/workflows/shared/github-guard-policy.md}}
{{#runtime-import .github/workflows/shared/gh.md}}
@@ -431,12 +432,13 @@ jobs:
{{#runtime-import .github/workflows/shared/github-queries-mcp-script.md}}
{{#runtime-import .github/workflows/shared/mcp/serena-go.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
## Serena Code Analysis
Serena is enabled for **["go"]** in `__GH_AW_GITHUB_WORKSPACE__`. Start by calling `activate_project` with that workspace path, then prefer Serena semantic tools for symbol lookup, references, docs, diagnostics, and structured edits.
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-copilot-aoai-entra.md}}
- GH_AW_PROMPT_0688b38d643fbc31_EOF
+ GH_AW_PROMPT_5c2f43dbb4d1a32a_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -2145,10 +2147,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-copilot-aoai-entra.md b/.github/workflows/smoke-copilot-aoai-entra.md
index bd220a5e92a..e68d915795d 100644
--- a/.github/workflows/smoke-copilot-aoai-entra.md
+++ b/.github/workflows/smoke-copilot-aoai-entra.md
@@ -46,6 +46,7 @@ imports:
- shared/github-queries-mcp-script.md
- shared/mcp/serena-go.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml
index 255f1958a59..d7a178d6e8b 100644
--- a/.github/workflows/smoke-copilot-arm.lock.yml
+++ b/.github/workflows/smoke-copilot-arm.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8eaba5348986a9df90593129269c5ffff388e7c77be8c9eb453e6379e09f566a","body_hash":"26c548a1139a15cdaed6d80164ccd26e682ca333ff33ce2e701aa7e60337e0e6","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"},"agent_image_runner":"ubuntu-24.04-arm"}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"34278b8861a90f011fa58af393c8c80f002a46043cbd6aa772414aaf68e66369","body_hash":"1a60ee31c1feb7e1a1ed0c60e2190d71d9026b0c5829f7f15f5cc547f0e63f50","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"},"agent_image_runner":"ubuntu-24.04-arm"}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"f9f3042f7e2789586610d6e8b85c8f03e5195baf","version":"v7.2.0"},{"repo":"docker/setup-buildx-action","sha":"d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5","version":"v4.1.0"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -34,6 +34,7 @@
# - shared/otlp.md
# - shared/reporting.md
# - shared/reporting-otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -326,22 +327,22 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_f9fc99e8b1ad011d_EOF'
+ cat << 'GH_AW_PROMPT_e009e9031142ebae_EOF'
- GH_AW_PROMPT_f9fc99e8b1ad011d_EOF
+ GH_AW_PROMPT_e009e9031142ebae_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_f9fc99e8b1ad011d_EOF'
+ cat << 'GH_AW_PROMPT_e009e9031142ebae_EOF'
Tools: add_comment(max:2), create_issue, create_discussion, create_pull_request_review_comment(max:5), submit_pull_request_review, add_labels, remove_labels, dispatch_workflow, missing_tool, missing_data, noop, send_slack_message
- GH_AW_PROMPT_f9fc99e8b1ad011d_EOF
+ GH_AW_PROMPT_e009e9031142ebae_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_f9fc99e8b1ad011d_EOF'
+ cat << 'GH_AW_PROMPT_e009e9031142ebae_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -370,25 +371,26 @@ jobs:
{{/if}}
- GH_AW_PROMPT_f9fc99e8b1ad011d_EOF
+ GH_AW_PROMPT_e009e9031142ebae_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_f9fc99e8b1ad011d_EOF'
+ cat << 'GH_AW_PROMPT_e009e9031142ebae_EOF'
{{#runtime-import .github/workflows/shared/gh.md}}
{{#runtime-import .github/workflows/shared/reporting-otlp.md}}
{{#runtime-import .github/workflows/shared/github-queries-mcp-script.md}}
{{#runtime-import .github/workflows/shared/mcp/serena-go.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/reporting.md}}
## Serena Code Analysis
Serena is enabled for **["go"]** in `__GH_AW_GITHUB_WORKSPACE__`. Start by calling `activate_project` with that workspace path, then prefer Serena semantic tools for symbol lookup, references, docs, diagnostics, and structured edits.
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-copilot-arm.md}}
- GH_AW_PROMPT_f9fc99e8b1ad011d_EOF
+ GH_AW_PROMPT_e009e9031142ebae_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1977,10 +1979,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
- send_slack_message
diff --git a/.github/workflows/smoke-copilot-arm.md b/.github/workflows/smoke-copilot-arm.md
index 2cafe6602ee..ae11e429077 100644
--- a/.github/workflows/smoke-copilot-arm.md
+++ b/.github/workflows/smoke-copilot-arm.md
@@ -28,6 +28,7 @@ imports:
- shared/github-queries-mcp-script.md
- shared/mcp/serena-go.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml
index 811c3dafccd..4dc2bc59550 100644
--- a/.github/workflows/smoke-copilot.lock.yml
+++ b/.github/workflows/smoke-copilot.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"16ce3056a07e9a41d38b404bbd8dc1ccb2de9962ce637c211ade0ad8977c9af5","body_hash":"05f195a76bd7e9205e793331c9962f6c401e1b29da2e99592ee537c3289df44e","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"cd1db4da83dbeb24e508e618607ddd371bdce795962c9e5d58257d2a911dfc81","body_hash":"0a3dc6816650c6e520f369948cef7c7db057b0e10b5770d1de795bafaa2e7b28","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"docker/build-push-action","sha":"f9f3042f7e2789586610d6e8b85c8f03e5195baf","version":"v7.2.0"},{"repo":"docker/setup-buildx-action","sha":"d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5","version":"v4.1.0"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -34,6 +34,7 @@
# - shared/mcp/serena.md
# - shared/otlp.md
# - shared/reporting.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -378,25 +379,25 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_f85a2f2ae80e4629_EOF'
+ cat << 'GH_AW_PROMPT_92bcb4f2a41cf78c_EOF'
- GH_AW_PROMPT_f85a2f2ae80e4629_EOF
+ GH_AW_PROMPT_92bcb4f2a41cf78c_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/playwright_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_f85a2f2ae80e4629_EOF'
+ cat << 'GH_AW_PROMPT_92bcb4f2a41cf78c_EOF'
Tools: add_comment(max:2), create_issue, create_discussion, create_pull_request_review_comment(max:5), submit_pull_request_review, reply_to_pull_request_review_comment(max:5), add_labels, remove_labels, create_check_run, set_issue_type, dispatch_workflow, missing_tool, missing_data, noop, send_slack_message
- GH_AW_PROMPT_f85a2f2ae80e4629_EOF
+ GH_AW_PROMPT_92bcb4f2a41cf78c_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_comment_memory.md"
- cat << 'GH_AW_PROMPT_f85a2f2ae80e4629_EOF'
+ cat << 'GH_AW_PROMPT_92bcb4f2a41cf78c_EOF'
- GH_AW_PROMPT_f85a2f2ae80e4629_EOF
+ GH_AW_PROMPT_92bcb4f2a41cf78c_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_f85a2f2ae80e4629_EOF'
+ cat << 'GH_AW_PROMPT_92bcb4f2a41cf78c_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -425,12 +426,12 @@ jobs:
{{/if}}
- GH_AW_PROMPT_f85a2f2ae80e4629_EOF
+ GH_AW_PROMPT_92bcb4f2a41cf78c_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_f85a2f2ae80e4629_EOF'
+ cat << 'GH_AW_PROMPT_92bcb4f2a41cf78c_EOF'
{{#runtime-import .github/workflows/shared/github-guard-policy.md}}
{{#runtime-import .github/workflows/shared/gh.md}}
@@ -438,12 +439,13 @@ jobs:
{{#runtime-import .github/workflows/shared/github-queries-mcp-script.md}}
{{#runtime-import .github/workflows/shared/mcp/serena-go.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
## Serena Code Analysis
Serena is enabled for **["go"]** in `__GH_AW_GITHUB_WORKSPACE__`. Start by calling `activate_project` with that workspace path, then prefer Serena semantic tools for symbol lookup, references, docs, diagnostics, and structured edits.
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-copilot.md}}
- GH_AW_PROMPT_f85a2f2ae80e4629_EOF
+ GH_AW_PROMPT_92bcb4f2a41cf78c_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -2155,10 +2157,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-copilot.md b/.github/workflows/smoke-copilot.md
index 3193e2b1bbf..1141f111f06 100644
--- a/.github/workflows/smoke-copilot.md
+++ b/.github/workflows/smoke-copilot.md
@@ -33,6 +33,7 @@ imports:
- shared/github-queries-mcp-script.md
- shared/mcp/serena-go.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml
index ad4828f7079..84f41a9d196 100644
--- a/.github/workflows/smoke-crush.lock.yml
+++ b/.github/workflows/smoke-crush.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"de3ee20e06b09683fda7ca602e67cfc9507eb73e2b6c6f17363425093fcbedc7","body_hash":"cc2ef81f034ad1a5a273c6e10b2297d10ee6e25484f18a23ba46525842e74e5e","strict":true,"agent_id":"crush","agent_model":"anthropic/claude-sonnet-4-20250514","engine_versions":{"crush":"0.59.0"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8137dad322d50cb949a65af7f22d3232bdded2ba5029f75a51656d1d1180d491","body_hash":"b0b4650fccfa1722b34bb18583b431aff118fe48341fecad23a09256b643c7c7","strict":true,"agent_id":"crush","agent_model":"anthropic/claude-sonnet-4-20250514","engine_versions":{"crush":"0.59.0"}}
# gh-aw-manifest: {"version":1,"secrets":["ANTHROPIC_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -30,6 +30,7 @@
# - shared/gh.md
# - shared/otlp.md
# - shared/reporting.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - ANTHROPIC_API_KEY
@@ -316,20 +317,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_7136928fa05f6ebe_EOF'
+ cat << 'GH_AW_PROMPT_3e0b6449aeee3947_EOF'
- GH_AW_PROMPT_7136928fa05f6ebe_EOF
+ GH_AW_PROMPT_3e0b6449aeee3947_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_7136928fa05f6ebe_EOF'
+ cat << 'GH_AW_PROMPT_3e0b6449aeee3947_EOF'
Tools: add_comment(max:2), create_issue, add_labels, missing_tool, missing_data, noop
- GH_AW_PROMPT_7136928fa05f6ebe_EOF
+ GH_AW_PROMPT_3e0b6449aeee3947_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_7136928fa05f6ebe_EOF'
+ cat << 'GH_AW_PROMPT_3e0b6449aeee3947_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -358,19 +359,20 @@ jobs:
{{/if}}
- GH_AW_PROMPT_7136928fa05f6ebe_EOF
+ GH_AW_PROMPT_3e0b6449aeee3947_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_7136928fa05f6ebe_EOF'
+ cat << 'GH_AW_PROMPT_3e0b6449aeee3947_EOF'
{{#runtime-import .github/workflows/shared/gh.md}}
{{#runtime-import .github/workflows/shared/reporting.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-crush.md}}
- GH_AW_PROMPT_7136928fa05f6ebe_EOF
+ GH_AW_PROMPT_3e0b6449aeee3947_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1087,10 +1089,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
if: >
diff --git a/.github/workflows/smoke-crush.md b/.github/workflows/smoke-crush.md
index 487969d12ea..d79ab4fc402 100644
--- a/.github/workflows/smoke-crush.md
+++ b/.github/workflows/smoke-crush.md
@@ -26,6 +26,7 @@ imports:
- shared/gh.md
- shared/reporting.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml
index 263d6f1be46..f1e2f3b3505 100644
--- a/.github/workflows/smoke-gemini.lock.yml
+++ b/.github/workflows/smoke-gemini.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c0fc379529b8efffd7d734bbc31e3a3df2c9286c69c03c75e54a0bbeaa4c9e18","body_hash":"e6391525e0b408c59088189c4afeac1d643885a1f4f9d68465795d4e65427502","strict":true,"agent_id":"gemini","engine_versions":{"gemini":"0.39.1"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"a43b274adbcfa67b48edc1e6c8bc75d8b0891de537ba8d3d2c9ef67ca6378191","body_hash":"31a3f365078fdd4d39b8a4c6c98c4078a22c810819ad066131c2ce16520325f3","strict":true,"agent_id":"gemini","engine_versions":{"gemini":"0.39.1"}}
# gh-aw-manifest: {"version":1,"secrets":["GEMINI_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22","digest":"sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.22@sha256:e23e1604241f579b418e6522d938285b57ada31bc27742a65c90ee2250b1755c"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -31,6 +31,7 @@
# - shared/otlp.md
# - shared/reporting.md
# - shared/reporting-otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - GEMINI_API_KEY
@@ -354,21 +355,21 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_13366d92a8d2cf24_EOF'
+ cat << 'GH_AW_PROMPT_32d6fae0714cfe73_EOF'
- GH_AW_PROMPT_13366d92a8d2cf24_EOF
+ GH_AW_PROMPT_32d6fae0714cfe73_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/cache_memory_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_13366d92a8d2cf24_EOF'
+ cat << 'GH_AW_PROMPT_32d6fae0714cfe73_EOF'
Tools: add_comment(max:2), create_issue, add_labels, missing_tool, missing_data, noop
- GH_AW_PROMPT_13366d92a8d2cf24_EOF
+ GH_AW_PROMPT_32d6fae0714cfe73_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_13366d92a8d2cf24_EOF'
+ cat << 'GH_AW_PROMPT_32d6fae0714cfe73_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -397,20 +398,21 @@ jobs:
{{/if}}
- GH_AW_PROMPT_13366d92a8d2cf24_EOF
+ GH_AW_PROMPT_32d6fae0714cfe73_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_13366d92a8d2cf24_EOF'
+ cat << 'GH_AW_PROMPT_32d6fae0714cfe73_EOF'
{{#runtime-import .github/workflows/shared/gh.md}}
{{#runtime-import .github/workflows/shared/reporting-otlp.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/reporting.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-gemini.md}}
- GH_AW_PROMPT_13366d92a8d2cf24_EOF
+ GH_AW_PROMPT_32d6fae0714cfe73_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1197,10 +1199,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-gemini.md b/.github/workflows/smoke-gemini.md
index 54032a4fa6e..9c6b714c4a0 100644
--- a/.github/workflows/smoke-gemini.md
+++ b/.github/workflows/smoke-gemini.md
@@ -40,6 +40,7 @@ imports:
- shared/gh.md
- shared/reporting-otlp.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml
index fafdffaca1e..69de6786328 100644
--- a/.github/workflows/smoke-opencode.lock.yml
+++ b/.github/workflows/smoke-opencode.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"d6a00159ea49120815fb5373d14199b4a32ea8c2ec97968dbfa5bfee8ed78cf2","body_hash":"fd8a2bdc8108d3170cf3743ed350b5139285a58f4d68875cf729458566659a22","strict":true,"agent_id":"opencode","agent_model":"copilot/gpt-5","engine_versions":{"opencode":"1.2.14"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"1f2828d89a07fdfcf41990e440495f1911d86e0318407d46df2d4a49a24f0236","body_hash":"ad6162a2491bc6a039914c9ccb464bf47d04bb5e28b25e746f3d5d1be14025f2","strict":true,"agent_id":"opencode","agent_model":"copilot/gpt-5","engine_versions":{"opencode":"1.2.14"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -31,6 +31,7 @@
# - shared/otlp.md
# - shared/reporting.md
# - shared/reporting-otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -318,20 +319,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_2a98ed4f634b97b9_EOF'
+ cat << 'GH_AW_PROMPT_5d9b4e5b09b20f20_EOF'
- GH_AW_PROMPT_2a98ed4f634b97b9_EOF
+ GH_AW_PROMPT_5d9b4e5b09b20f20_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_2a98ed4f634b97b9_EOF'
+ cat << 'GH_AW_PROMPT_5d9b4e5b09b20f20_EOF'
Tools: add_comment(max:2), create_issue, add_labels, missing_tool, missing_data, noop
- GH_AW_PROMPT_2a98ed4f634b97b9_EOF
+ GH_AW_PROMPT_5d9b4e5b09b20f20_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_2a98ed4f634b97b9_EOF'
+ cat << 'GH_AW_PROMPT_5d9b4e5b09b20f20_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -360,20 +361,21 @@ jobs:
{{/if}}
- GH_AW_PROMPT_2a98ed4f634b97b9_EOF
+ GH_AW_PROMPT_5d9b4e5b09b20f20_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_2a98ed4f634b97b9_EOF'
+ cat << 'GH_AW_PROMPT_5d9b4e5b09b20f20_EOF'
{{#runtime-import .github/workflows/shared/gh.md}}
{{#runtime-import .github/workflows/shared/reporting-otlp.md}}
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/reporting.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-opencode.md}}
- GH_AW_PROMPT_2a98ed4f634b97b9_EOF
+ GH_AW_PROMPT_5d9b4e5b09b20f20_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1092,10 +1094,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
if: >
diff --git a/.github/workflows/smoke-opencode.md b/.github/workflows/smoke-opencode.md
index 3b7e6efbc5b..2bb01feca9b 100644
--- a/.github/workflows/smoke-opencode.md
+++ b/.github/workflows/smoke-opencode.md
@@ -26,6 +26,7 @@ imports:
- shared/gh.md
- shared/reporting-otlp.md
- shared/otlp.md
+ - shared/token-telemetry-check.md
network:
allowed:
- defaults
diff --git a/.github/workflows/smoke-project.lock.yml b/.github/workflows/smoke-project.lock.yml
index c39150b1450..ed5ce61e85a 100644
--- a/.github/workflows/smoke-project.lock.yml
+++ b/.github/workflows/smoke-project.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"d859471e6176db44927c32c185e5c4e9a44607f500a808de98210551a6523cc0","body_hash":"a06527944f758e799e436bef444ec14e9c38546538220b343897f74877fb3c1c","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"168a5e6e5b002f538cfb700c71be4eb15088d2a56ac50ac6803169c503aad013","body_hash":"d3e86b65d04757c43703b11dfe533a6f852e2ecc903cd646eff4667a94f302a9","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GH_AW_PROJECT_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -28,6 +28,7 @@
# Resolved workflow manifest:
# Imports:
# - shared/otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -354,23 +355,23 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_a0507a40057c6822_EOF'
+ cat << 'GH_AW_PROMPT_ced7b8c9e639a437_EOF'
- GH_AW_PROMPT_a0507a40057c6822_EOF
+ GH_AW_PROMPT_ced7b8c9e639a437_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_a0507a40057c6822_EOF'
+ cat << 'GH_AW_PROMPT_ced7b8c9e639a437_EOF'
Tools: add_comment(max:2), create_issue, create_pull_request, add_labels, remove_labels, update_project(max:20), create_project_status_update, missing_tool, missing_data, noop
- GH_AW_PROMPT_a0507a40057c6822_EOF
+ GH_AW_PROMPT_ced7b8c9e639a437_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md"
- cat << 'GH_AW_PROMPT_a0507a40057c6822_EOF'
+ cat << 'GH_AW_PROMPT_ced7b8c9e639a437_EOF'
- GH_AW_PROMPT_a0507a40057c6822_EOF
+ GH_AW_PROMPT_ced7b8c9e639a437_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_a0507a40057c6822_EOF'
+ cat << 'GH_AW_PROMPT_ced7b8c9e639a437_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -399,17 +400,18 @@ jobs:
{{/if}}
- GH_AW_PROMPT_a0507a40057c6822_EOF
+ GH_AW_PROMPT_ced7b8c9e639a437_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_a0507a40057c6822_EOF'
+ cat << 'GH_AW_PROMPT_ced7b8c9e639a437_EOF'
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-project.md}}
- GH_AW_PROMPT_a0507a40057c6822_EOF
+ GH_AW_PROMPT_ced7b8c9e639a437_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1313,10 +1315,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-project.md b/.github/workflows/smoke-project.md
index 38c6889caa1..2037026ff85 100644
--- a/.github/workflows/smoke-project.md
+++ b/.github/workflows/smoke-project.md
@@ -89,6 +89,7 @@ experiments:
issue: 37302
imports:
- shared/otlp.md
+ - shared/token-telemetry-check.md
features:
gh-aw-detection: false
---
diff --git a/.github/workflows/smoke-service-ports.lock.yml b/.github/workflows/smoke-service-ports.lock.yml
index 1f71f23718e..86ebda74503 100644
--- a/.github/workflows/smoke-service-ports.lock.yml
+++ b/.github/workflows/smoke-service-ports.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"daaa2adced53566ee21a8c36d89f56052a12aa170ad6972e14af883311f46673","body_hash":"f0d52a8ac256d3e86659f87c0811c0ad3901a243a5b96432e69002106b780c42","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3c56208145af0b3ffbda97f9d0371eaa0adcf59a0f0c882db7db0baef46f53af","body_hash":"1104977033f3c713b638f0c4236aeca750ec5890c4d5897658851dd39b8effe1","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -28,6 +28,7 @@
# Resolved workflow manifest:
# Imports:
# - shared/otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -308,20 +309,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_8676aedd5232efa7_EOF'
+ cat << 'GH_AW_PROMPT_4c7aa5beeceed398_EOF'
- GH_AW_PROMPT_8676aedd5232efa7_EOF
+ GH_AW_PROMPT_4c7aa5beeceed398_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_8676aedd5232efa7_EOF'
+ cat << 'GH_AW_PROMPT_4c7aa5beeceed398_EOF'
Tools: add_comment(max:2), missing_tool, missing_data, noop
- GH_AW_PROMPT_8676aedd5232efa7_EOF
+ GH_AW_PROMPT_4c7aa5beeceed398_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_8676aedd5232efa7_EOF'
+ cat << 'GH_AW_PROMPT_4c7aa5beeceed398_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -350,16 +351,17 @@ jobs:
{{/if}}
- GH_AW_PROMPT_8676aedd5232efa7_EOF
+ GH_AW_PROMPT_4c7aa5beeceed398_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_8676aedd5232efa7_EOF'
+ cat << 'GH_AW_PROMPT_4c7aa5beeceed398_EOF'
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/smoke-service-ports.md}}
- GH_AW_PROMPT_8676aedd5232efa7_EOF
+ GH_AW_PROMPT_4c7aa5beeceed398_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1064,10 +1066,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
if: >
diff --git a/.github/workflows/smoke-service-ports.md b/.github/workflows/smoke-service-ports.md
index 92def18275f..792487d43e3 100644
--- a/.github/workflows/smoke-service-ports.md
+++ b/.github/workflows/smoke-service-ports.md
@@ -46,6 +46,7 @@ safe-outputs:
timeout-minutes: 5
imports:
- shared/otlp.md
+ - shared/token-telemetry-check.md
features:
gh-aw-detection: false
---
diff --git a/.github/workflows/smoke-temporary-id.lock.yml b/.github/workflows/smoke-temporary-id.lock.yml
index 3fd9e8a1f16..7ee49541c0d 100644
--- a/.github/workflows/smoke-temporary-id.lock.yml
+++ b/.github/workflows/smoke-temporary-id.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3e4271b8ed01954621f0b41f638d0b57f2e1afbd57ae577f7274312e0d938817","body_hash":"837357879ba43b6a872a306ef6aa48f02a2b63b43cf0a142dd3860175463961b","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8edff1954fd913b37dccc602d01c690bee7052e688320d85d3f36abb70e551ab","body_hash":"428092bc63e0e9f7d493de670e6bf0a7e9a78b43456e00179474228201807a14","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -28,6 +28,7 @@
# Resolved workflow manifest:
# Imports:
# - shared/otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -352,20 +353,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_42902931571bc859_EOF'
+ cat << 'GH_AW_PROMPT_141a03aeb3c586c0_EOF'
- GH_AW_PROMPT_42902931571bc859_EOF
+ GH_AW_PROMPT_141a03aeb3c586c0_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_42902931571bc859_EOF'
+ cat << 'GH_AW_PROMPT_141a03aeb3c586c0_EOF'
Tools: add_comment(max:2), create_issue(max:5), link_sub_issue(max:3), missing_tool, missing_data, noop
- GH_AW_PROMPT_42902931571bc859_EOF
+ GH_AW_PROMPT_141a03aeb3c586c0_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_42902931571bc859_EOF'
+ cat << 'GH_AW_PROMPT_141a03aeb3c586c0_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -394,17 +395,18 @@ jobs:
{{/if}}
- GH_AW_PROMPT_42902931571bc859_EOF
+ GH_AW_PROMPT_141a03aeb3c586c0_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_42902931571bc859_EOF'
+ cat << 'GH_AW_PROMPT_141a03aeb3c586c0_EOF'
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-temporary-id.md}}
- GH_AW_PROMPT_42902931571bc859_EOF
+ GH_AW_PROMPT_141a03aeb3c586c0_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1164,10 +1166,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- push_experiments_state
- safe_outputs
diff --git a/.github/workflows/smoke-temporary-id.md b/.github/workflows/smoke-temporary-id.md
index 9cce4b09b4e..9ec6be5facf 100644
--- a/.github/workflows/smoke-temporary-id.md
+++ b/.github/workflows/smoke-temporary-id.md
@@ -48,6 +48,7 @@ safe-outputs:
timeout-minutes: 10
imports:
- shared/otlp.md
+ - shared/token-telemetry-check.md
tools:
cli-proxy: true
experiments:
diff --git a/.github/workflows/smoke-test-tools.lock.yml b/.github/workflows/smoke-test-tools.lock.yml
index 0259d7724d1..f11c2415d3d 100644
--- a/.github/workflows/smoke-test-tools.lock.yml
+++ b/.github/workflows/smoke-test-tools.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4a947ad618503b28a686a16364f047871969a8fda8d345b13a10f28ac02f5521","body_hash":"81f2125a67a8ec3e67401b66459850f8ca4c45d4f70c874e470b359ae4733083","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"fef4d3cd05c76ebe71c7ea3703d83446e561550acf3080cd88c53110a6abc18d","body_hash":"cf53a834b09d4e5b794c651454718653367ede664f6a2610ec130969528828ac","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.68"}}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-dotnet","sha":"26b0ec14cb23fa6904739307f278c14f94c95bf1","version":"v5.4.0"},{"repo":"actions/setup-go","sha":"924ae3a1cded613372ab5595356fb5720e22ba16","version":"v6.5.0"},{"repo":"actions/setup-java","sha":"1bcf9fb12cf4aa7d266a90ae39939e61372fe520","version":"v5.4.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/setup-python","sha":"ece7cb06caefa5fff74198d8649806c4678c61a1","version":"v6.3.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22","digest":"sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.22@sha256:55f06588411008b7148eb64b8dfe28602a0cce3675b36c6b190b54aca138468e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22","digest":"sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.22@sha256:afb9ff9140b17d38871dfb9dbac5ff8689ea634c2f91c435da2825192d4881c1"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22","digest":"sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.22@sha256:3cdcc1e2b4b4fe602ba69fd3e21aac7ac512d5c1fce24df4ce69dc4f98164b59"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.33","digest":"sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.33@sha256:f0e1f1d562f01e737f3ef125cb4d7057ff87a68a97927f5ea9fd6d3f5091da06"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.5.0","digest":"sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4","pinned_image":"ghcr.io/github/github-mcp-server:v1.5.0@sha256:e25564dccc9110a70a77b9df560cbde11aa392fcb5f08b9abe5c4ebc6d146ea4"}]}
# This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md
#
@@ -28,6 +28,7 @@
# Resolved workflow manifest:
# Imports:
# - shared/otlp.md
+# - shared/token-telemetry-check.md
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -319,20 +320,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_697463475cfdd779_EOF'
+ cat << 'GH_AW_PROMPT_e1d660274ca48bb6_EOF'
- GH_AW_PROMPT_697463475cfdd779_EOF
+ GH_AW_PROMPT_e1d660274ca48bb6_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_697463475cfdd779_EOF'
+ cat << 'GH_AW_PROMPT_e1d660274ca48bb6_EOF'
Tools: add_comment(max:2), missing_tool, missing_data, noop
- GH_AW_PROMPT_697463475cfdd779_EOF
+ GH_AW_PROMPT_e1d660274ca48bb6_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_697463475cfdd779_EOF'
+ cat << 'GH_AW_PROMPT_e1d660274ca48bb6_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -361,17 +362,18 @@ jobs:
{{/if}}
- GH_AW_PROMPT_697463475cfdd779_EOF
+ GH_AW_PROMPT_e1d660274ca48bb6_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_697463475cfdd779_EOF'
+ cat << 'GH_AW_PROMPT_e1d660274ca48bb6_EOF'
{{#runtime-import .github/workflows/shared/otlp.md}}
+ {{#runtime-import .github/workflows/shared/token-telemetry-check.md}}
{{#runtime-import .github/workflows/shared/noop-reminder.md}}
{{#runtime-import .github/workflows/smoke-test-tools.md}}
- GH_AW_PROMPT_697463475cfdd779_EOF
+ GH_AW_PROMPT_e1d660274ca48bb6_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -1095,10 +1097,79 @@ jobs:
/tmp/gh-aw/sandbox/firewall/awf-reflect.json
if-no-files-found: ignore
+ check_token_telemetry:
+ needs: agent
+ if: needs.agent.result == 'success'
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+
+ steps:
+ - name: Configure GH_HOST for enterprise compatibility
+ id: ghes-host-config
+ shell: bash
+ run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input.
+ # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
+ # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
+ GH_HOST="${GITHUB_SERVER_URL#https://}"
+ GH_HOST="${GH_HOST#http://}"
+ echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
+ - name: Download agent artifact
+ id: download-agent
+ uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
+ with:
+ name: agent
+ path: /tmp/gh-aw/
+ continue-on-error: true
+ - name: Assert token_usage.jsonl is non-empty
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ # The AWF firewall proxy writes token_usage.jsonl for every LLM API call.
+ # If all token_usage.jsonl files are missing or empty, the emitter is broken.
+ TOKEN_FILES=(
+ "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl"
+ "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl"
+ )
+
+ FOUND_NONEMPTY=false
+ for f in "${TOKEN_FILES[@]}"; do
+ if [ -s "$f" ]; then
+ COUNT=$(grep -c . "$f" 2>/dev/null || echo "0")
+ echo "OK: $f — ${COUNT} record(s)"
+ FOUND_NONEMPTY=true
+ else
+ [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f"
+ fi
+ done
+
+ if [ "${FOUND_NONEMPTY}" != "true" ]; then
+ echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run."
+ echo "::error::The AWF firewall proxy token telemetry emitter may be broken."
+ echo "::error::See tracking issue: https://github.com/github/gh-aw/issues/42791"
+ exit 1
+ fi
+ - name: Assert agent_usage.json has non-zero token counts
+ if: steps.download-agent.outcome == 'success'
+ run: |
+ USAGE_FILE="/tmp/gh-aw/agent_usage.json"
+ if [ ! -f "${USAGE_FILE}" ]; then
+ echo "::error::agent_usage.json not found in agent artifact — token summary was not written."
+ exit 1
+ fi
+ INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))")
+ if [ "${INPUT_TOKENS}" -le 0 ]; then
+ echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken."
+ cat "${USAGE_FILE}"
+ exit 1
+ fi
+ echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens"
+
conclusion:
needs:
- activation
- agent
+ - check_token_telemetry
- detection
- safe_outputs
if: >
diff --git a/.github/workflows/smoke-test-tools.md b/.github/workflows/smoke-test-tools.md
index 1994bb857cf..548ad71351a 100644
--- a/.github/workflows/smoke-test-tools.md
+++ b/.github/workflows/smoke-test-tools.md
@@ -51,6 +51,7 @@ safe-outputs:
timeout-minutes: 5
imports:
- shared/otlp.md
+ - shared/token-telemetry-check.md
features:
gh-aw-detection: false
---