diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index 33af79622f0..8c5696f68ca 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8e0e6a1c9fb128aefa2bbf3a464619f43d0564d3b353b8fc98aaaa33a234cbff","body_hash":"4eeb5a40aec90878678132ad978afda0d44c1fe67be93ffb4a67e3b6c117aef4","strict":true,"agent_id":"pi","agent_model":"copilot/gpt-5.4","engine_versions":{"pi":"0.80.10"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f316370db5b60a0e57e30ebb5a074ecb9f01fc223a7b45e3eef77e2ce3d3189f","body_hash":"ff68fa0375c63d2ca0bc19208d27bf8e02eb9e8bf44e66319649699bac5e1a8d","strict":true,"agent_id":"pi","agent_model":"copilot/gpt-5.4","engine_versions":{"pi":"0.80.10"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.37","digest":"sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.37@sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.3","digest":"sha256:3c744710ea275cd5ee65db92a1099e0d980754bd9fafda9ce67704c67004dc83","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.3@sha256:3c744710ea275cd5ee65db92a1099e0d980754bd9fafda9ce67704c67004dc83"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -66,6 +66,7 @@ on: types: - opened - edited + # roles: all # Roles processed as role check in pre-activation job schedule: - cron: "11 */6 * * *" workflow_dispatch: @@ -610,15 +611,15 @@ jobs: mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_b802e386e3a021cd_EOF' - {"add_labels":{"max":10},"create_discussion":{"category":"audits","close_older_discussions":true,"expires":24,"fallback_to_issue":true,"max":1,"title_prefix":"[Auto-Triage] "},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{}} - GH_AW_SAFE_OUTPUTS_CONFIG_b802e386e3a021cd_EOF + cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_669bd12baa1bc2d9_EOF' + {"add_labels":{"allowed":["automation","bug","cli","community","compiler","copilot","dependencies","documentation","enhancement","good-first-issue","high-priority","mcp","needs-triage","observability","performance","question","refactoring","safe-outputs","security","testing","threat-detection","workflows"],"max":10},"create_discussion":{"category":"audits","close_older_discussions":true,"expires":24,"fallback_to_issue":true,"max":1,"title_prefix":"[Auto-Triage] "},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{}} + GH_AW_SAFE_OUTPUTS_CONFIG_669bd12baa1bc2d9_EOF - name: Generate Safe Outputs Tools env: GH_AW_TOOLS_META_JSON: | { "description_suffixes": { - "add_labels": " CONSTRAINTS: Maximum 10 label(s) can be added.", + "add_labels": " CONSTRAINTS: Maximum 10 label(s) can be added. Only these labels are allowed: [\"automation\" \"bug\" \"cli\" \"community\" \"compiler\" \"copilot\" \"dependencies\" \"documentation\" \"enhancement\" \"good-first-issue\" \"high-priority\" \"mcp\" \"needs-triage\" \"observability\" \"performance\" \"question\" \"refactoring\" \"safe-outputs\" \"security\" \"testing\" \"threat-detection\" \"workflows\"].", "create_discussion": " CONSTRAINTS: Maximum 1 discussion(s) can be created. Title will be prefixed with \"[Auto-Triage] \". Discussions will be created in category \"audits\"." }, "repo_params": {}, @@ -1759,7 +1760,7 @@ jobs: env: GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} outputs: - activated: ${{ steps.check_membership.outputs.is_team_member == 'true' && steps.check_rate_limit.outputs.rate_limit_ok == 'true' }} + activated: ${{ steps.check_rate_limit.outputs.rate_limit_ok == 'true' }} matched_command: '' setup-parent-span-id: ${{ steps.setup.outputs.parent-span-id || steps.setup.outputs.span-id }} setup-span-id: ${{ steps.setup.outputs.span-id }} @@ -1785,18 +1786,6 @@ jobs: GH_AW_INFO_VERSION: "0.80.10" GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "pi" - - name: Check team membership for workflow - id: check_membership - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 - env: - GH_AW_REQUIRED_ROLES: "admin,maintainer,write" - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - script: | - const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs'); - setupGlobals(core, github, context, exec, io, getOctokit); - const { main } = require('${{ runner.temp }}/gh-aw/actions/check_membership.cjs'); - await main(); - name: Check user rate limit id: check_rate_limit uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -1986,7 +1975,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.githubusercontent.com,*.grafana.net,*.sentry.io,api.githubcopilot.com,api.pi.ai,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,codeload.github.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,docs.github.com,github-cloud.githubusercontent.com,github-cloud.s3.amazonaws.com,github.blog,github.com,github.githubassets.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,lfs.github.com,objects.githubusercontent.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,patch-diff.githubusercontent.com,patchdiff.githubusercontent.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"add_labels\":{\"max\":10},\"create_discussion\":{\"category\":\"audits\",\"close_older_discussions\":true,\"expires\":24,\"fallback_to_issue\":true,\"max\":1,\"title_prefix\":\"[Auto-Triage] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"add_labels\":{\"allowed\":[\"automation\",\"bug\",\"cli\",\"community\",\"compiler\",\"copilot\",\"dependencies\",\"documentation\",\"enhancement\",\"good-first-issue\",\"high-priority\",\"mcp\",\"needs-triage\",\"observability\",\"performance\",\"question\",\"refactoring\",\"safe-outputs\",\"security\",\"testing\",\"threat-detection\",\"workflows\"],\"max\":10},\"create_discussion\":{\"category\":\"audits\",\"close_older_discussions\":true,\"expires\":24,\"fallback_to_issue\":true,\"max\":1,\"title_prefix\":\"[Auto-Triage] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/auto-triage-issues.md b/.github/workflows/auto-triage-issues.md index b43eb5090e9..a342411f41c 100644 --- a/.github/workflows/auto-triage-issues.md +++ b/.github/workflows/auto-triage-issues.md @@ -3,6 +3,7 @@ emoji: "🔧" name: Auto-Triage Issues description: Automatically labels new and existing unlabeled issues to improve discoverability and triage efficiency on: + roles: all issues: types: [opened, edited] schedule: @@ -34,6 +35,7 @@ tools: mode: gh-proxy toolsets: - issues + - labels min-integrity: approved bash: - "jq *" @@ -61,6 +63,29 @@ steps: echo "Partial-labeled issues (type-only, missing component): $(jq length /tmp/gh-aw/agent/partial-labeled-issues.json)" safe-outputs: add-labels: + allowed: + - automation + - bug + - cli + - community + - compiler + - copilot + - dependencies + - documentation + - enhancement + - good-first-issue + - high-priority + - mcp + - needs-triage + - observability + - performance + - question + - refactoring + - safe-outputs + - security + - testing + - threat-detection + - workflows max: 10 create-discussion: expires: 1d @@ -104,6 +129,7 @@ When an issue is opened or edited: 4. **Classify the issue** based on its title and body content 5. **Apply all labels** (including `community` if applicable) in a single `add_labels` call 6. If uncertain about classification, add the `needs-triage` label for human review +7. If a needed label does not exist yet (for example `observability`), create it first with the GitHub labels toolset, then apply all labels in a single `add_labels` call ### On Scheduled Runs (Every 6 Hours) @@ -170,6 +196,7 @@ Apply component labels based on mentioned areas: - `mcp` - Mentions MCP servers, tools, integrations, `tools/list`, MCP gateway, `awmg-mcpg`, CLI-mounted MCP servers - `safe-outputs` - Mentions safe-outputs, safeoutputs, `push_to_pull_request_branch`, `add_comment` via safeoutputs, `outputs.jsonl`, safe-output gateway, "unknown tool" on safeoutputs tools, `report_incomplete` (safeoutputs context) - `copilot` - Mentions Copilot engine, copilot CLI (`copilot` engine id), `--disable-builtin-mcps`, Copilot coding agent +- `observability` - Mentions observability, telemetry, OTel, OTLP, spans, tracing, trace continuity, Grafana, Sentry, Application Insights, `status_code`, or mismatched `run.status` telemetry - `security` - Mentions security issues, vulnerabilities, CVE, authentication - `performance` - Mentions speed, performance, slow, optimization, memory usage - `threat-detection` - Mentions threat detection, detection job, `detection_agentic_execution`, safe outputs detection @@ -177,7 +204,7 @@ Apply component labels based on mentioned areas: ### Priority Indicators - `high-priority` - Contains "critical", "urgent", "blocking", "important", "silent failure", "silent no-op", "silent green", "indistinguishable from", "laundered into", "masks real", "no channel to report", "every call fails" -- `good first issue` - Explicitly labeled as beginner-friendly or mentions "first time", "newcomer" +- `good-first-issue` - Explicitly labeled as beginner-friendly or mentions "first time", "newcomer" ### Community Label @@ -195,7 +222,7 @@ This label identifies issues opened by external community members and read-only ### Known Automation Title Patterns (high-confidence, apply immediately) -These title patterns identify machine-generated operational issues. Apply `automation` without further analysis and **do not** apply `needs-triage`: +These title patterns identify machine-generated operational issues. Apply `automation` immediately and **do not** apply `needs-triage` just because the issue is machine-generated. Continue the rest of the classification flow so the issue still gets the correct type and component labels. | Title prefix / pattern | Label(s) to apply | |---|---| @@ -203,7 +230,11 @@ These title patterns identify machine-generated operational issues. Apply `autom | `[deep-report]` | `automation` | | `[auto-triage]` (case-insensitive) | `automation` | -When an issue title matches one of these patterns, apply the specified label(s) and skip all other classification rules for that issue. +When an issue title matches one of these patterns: + +1. Apply the specified automation label(s) immediately. +2. Continue evaluating the underlying issue content for type, component, and priority labels. +3. For `[deep-report]` issues, treat the bug title/body after the wrapper prefix as the primary classification signal. Deep Report issues often wrap a real defect that still needs labels like `bug`, `observability`, or `high-priority`. ### Uncertainty Handling diff --git a/.github/workflows/smoke-call-workflow.lock.yml b/.github/workflows/smoke-call-workflow.lock.yml index b7fb052fab3..fbe4cdd2d92 100644 --- a/.github/workflows/smoke-call-workflow.lock.yml +++ b/.github/workflows/smoke-call-workflow.lock.yml @@ -1112,7 +1112,7 @@ jobs: # Imported from called workflow "smoke-workflow-call" because GitHub requires the caller job to grant permissions requested by reusable workflow jobs. # Review the called workflow's job-level permissions in ./.github/workflows/smoke-workflow-call.lock.yml. permissions: - actions: write + actions: read contents: read issues: write pull-requests: write