Repository navigation
PR Sous Chef #7081
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"acdfa31dfcd2d7802aca7bdedffbebaa8ac4bd9e811a415f8da6f40e489555f4","body_hash":"492943aa23c5fa71c52481742d50e8409432931dee20031a8a08754089c44505","strict":true,"agent_id":"pi","agent_model":"copilot/claude-haiku-4.5","engine_versions":{"pi":"1.0.0"}} | |
| # gh-aw-manifest: {"version":1,"secrets":["AWI_MAINTENANCE_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"9000827ccba6bdab643e8b6fd33ac0654aef8333","version":"v8.0.2"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"949feb2413d6458794dcd2491c4babbbce0c15c1","version":"v7.1.0"},{"repo":"actions/upload-artifact","sha":"cf430e030ddbb5b0abf93d22962f4752f3646cd9","version":"v7.0.2"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.50","digest":"sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.50@sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50","digest":"sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50@sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50","digest":"sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50@sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.50","digest":"sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.50@sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.30","digest":"sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f","pinned_image":"ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"safeoutputs","tools":["add_comment","approve_workflow_run","create_issue","dismiss_pull_request_review","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} | |
| # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md | |
| # | |
| # ___ _ _ | |
| # / _ \ | | (_) | |
| # | |_| | __ _ ___ _ __ | |_ _ ___ | |
| # | _ |/ _` |/ _ \ '_ \| __| |/ __| | |
| # | | | | (_| | __/ | | | |_| | (__ | |
| # \_| |_/\__, |\___|_| |_|\__|_|\___| | |
| # __/ | | |
| # _ _ |___/ | |
| # | | | | / _| | | |
| # | | | | ___ _ __ _ __| |_| | _____ ____ | |
| # | |/\| |/ _ \ '__| |/ /| _| |/ _ \ \ /\ / / ___| | |
| # \ /\ / (_) | | | | ( | | | | (_) \ V V /\__ \ | |
| # \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/ | |
| # | |
| # | |
| # To update this file, edit the corresponding .md file and run: | |
| # gh aw compile | |
| # Not all edits will cause changes to this file. | |
| # | |
| # For more information: https://github.github.com/gh-aw/introduction/overview/ | |
| # | |
| # Nudges PRs idle for ten minutes with unanswered reviews and a branch update, without duplicate agent work | |
| # | |
| # Resolved workflow manifest: | |
| # Imports: | |
| # - shared/mcp-pagination.md | |
| # - shared/otlp.md | |
| # | |
| # Frontmatter env variables: | |
| # - PR_SOUS_CHEF_REPOSITORY: (main workflow) | |
| # | |
| # Secrets used: | |
| # - AWI_MAINTENANCE_TOKEN | |
| # - GH_AW_GITHUB_MCP_SERVER_TOKEN | |
| # - GH_AW_GITHUB_TOKEN | |
| # - GH_AW_OTEL_GRAFANA_AUTHORIZATION | |
| # - GH_AW_OTEL_GRAFANA_ENDPOINT | |
| # - GH_AW_OTEL_SENTRY_AUTHORIZATION | |
| # - GH_AW_OTEL_SENTRY_ENDPOINT | |
| # - GITHUB_TOKEN | |
| # | |
| # Custom actions used: | |
| # - actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| # - actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| # - actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 | |
| # - actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| # | |
| # Container images used: | |
| # - ghcr.io/github/gh-aw-firewall/agent:0.28.50@sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620 | |
| # - ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50@sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965 | |
| # - ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50@sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce | |
| # - ghcr.io/github/gh-aw-firewall/squid:0.28.50@sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9 | |
| # - ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba | |
| # - ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f | |
| # - ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6 | |
| name: "PR Sous Chef" | |
| on: | |
| schedule: | |
| - cron: "3/5 * * * *" | |
| # skip-if-no-match: is:pr is:open -is:draft -author:app/dependabot -author:app/renovate -label:broccoli # Skip-if-no-match processed as search check in pre-activation job | |
| workflow_dispatch: | |
| inputs: | |
| aw_context: | |
| default: "" | |
| description: "Agent caller context (Reserved for Agentic Workflows)." | |
| required: false | |
| type: string | |
| # Jobs receive only their explicitly declared permissions. | |
| permissions: {} | |
| concurrency: | |
| cancel-in-progress: false | |
| group: gh-aw-pr-sous-chef | |
| queue: max | |
| run-name: "PR Sous Chef" | |
| env: | |
| PR_SOUS_CHEF_REPOSITORY: ${{ github.repository }} | |
| OTEL_EXPORTER_OTLP_ENDPOINT: ${{ secrets.GH_AW_OTEL_SENTRY_ENDPOINT }} | |
| OTEL_SERVICE_NAME: gh-aw.pr-sous-chef | |
| OTEL_RESOURCE_ATTRIBUTES: 'gh-aw.workflow.name=PR%20Sous%20Chef,gh-aw.repository=${{ github.repository }},gh-aw.run.id=${{ github.run_id }},github.run_id=${{ github.run_id }},gh-aw.engine.id=pi' | |
| OTEL_EXPORTER_OTLP_HEADERS: x-sentry-auth=${{ secrets.GH_AW_OTEL_SENTRY_AUTHORIZATION }} | |
| GH_AW_OTLP_ALL_HEADERS: x-sentry-auth=${{ secrets.GH_AW_OTEL_SENTRY_AUTHORIZATION }},Authorization=${{ secrets.GH_AW_OTEL_GRAFANA_AUTHORIZATION }} | |
| GH_AW_OTLP_ENDPOINTS: '[{"url":"${{ secrets.GH_AW_OTEL_SENTRY_ENDPOINT }}","headers":"x-sentry-auth=${{ secrets.GH_AW_OTEL_SENTRY_AUTHORIZATION }}"},{"url":"${{ secrets.GH_AW_OTEL_GRAFANA_ENDPOINT }}","headers":"Authorization=${{ secrets.GH_AW_OTEL_GRAFANA_AUTHORIZATION }}"}]' | |
| jobs: | |
| activation: | |
| name: activation | |
| needs: pre_activation | |
| if: needs.pre_activation.outputs.activated == 'true' | |
| runs-on: ubuntu-slim | |
| # Permissions for the activation job (workflow permissions default to none). | |
| permissions: | |
| actions: read | |
| contents: read | |
| issues: write | |
| pull-requests: write | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| outputs: | |
| aw_context: ${{ steps.generate_aw_info.outputs.aw_context }} | |
| body: ${{ steps.sanitized.outputs.body }} | |
| comment_id: ${{ steps.add-comment.outputs.comment-id }} | |
| comment_repo: ${{ steps.add-comment.outputs.comment-repo }} | |
| comment_url: ${{ steps.add-comment.outputs.comment-url }} | |
| engine_id: ${{ steps.generate_aw_info.outputs.engine_id }} | |
| lockdown_check_failed: ${{ steps.generate_aw_info.outputs.lockdown_check_failed == 'true' }} | |
| model: ${{ steps.generate_aw_info.outputs.model }} | |
| oauth_token_check_failed: ${{ steps.check-oauth-tokens.outputs.oauth_token_check_failed == 'true' }} | |
| setup-parent-span-id: ${{ steps.setup.outputs.parent-span-id || steps.setup.outputs.span-id }} | |
| setup-span-id: ${{ steps.setup.outputs.span-id }} | |
| setup-trace-id: ${{ steps.setup.outputs.trace-id }} | |
| slash_command: ${{ needs.pre_activation.outputs.matched_command }} | |
| stale_lock_file_failed: ${{ steps.check-lock-file.outputs.stale_lock_file_failed == 'true' }} | |
| text: ${{ steps.sanitized.outputs.text }} | |
| title: ${{ steps.sanitized.outputs.title }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.pre_activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.pre_activation.outputs.setup-parent-span-id || needs.pre_activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Mask OTLP telemetry headers | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" | |
| - name: Generate agentic run info | |
| id: generate_aw_info | |
| env: | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_INFO_ENGINE_NAME: "Pi" | |
| GH_AW_INFO_MODEL: "copilot/claude-haiku-4.5" | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AGENT_VERSION: "1.0.0" | |
| GH_AW_INFO_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_INFO_EXPERIMENTAL: "false" | |
| GH_AW_INFO_SUPPORTS_TOOLS_ALLOWLIST: "true" | |
| GH_AW_INFO_STAGED: "false" | |
| GH_AW_INFO_ALLOWED_DOMAINS: '["*.grafana.net","*.sentry.io","defaults"]' | |
| GH_AW_INFO_FIREWALL_ENABLED: "true" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_AWMG_VERSION: "" | |
| GH_AW_INFO_FIREWALL_TYPE: "squid" | |
| GH_AW_INFO_AGENT_RUNTIME: "" | |
| GH_AW_INFO_FRONTMATTER_EMOJI: "👨\u200d🍳" | |
| GH_AW_COMPILED_STRICT: "true" | |
| GH_AW_INFO_MODEL_COSTS: '{"providers":{"github-copilot":{"models":{"claude-haiku-4.5":{"cost":{"cache_read":"1.0000000000000001e-07","cache_write":"1.25e-06","input":"1e-06","output":"5e-06"}}}}}}' | |
| GH_AW_INFO_FEATURES: '{"gh-aw-detection":true}' | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'generate_aw_info.cjs')); | |
| await main(core, context); | |
| - name: Add eyes reaction for immediate feedback | |
| id: react | |
| if: github.event_name == 'issues' || github.event_name == 'issue_comment' || github.event_name == 'pull_request_review_comment' || github.event_name == 'discussion' || github.event_name == 'discussion_comment' || github.event_name == 'pull_request' && github.event.pull_request.head.repo.id == github.repository_id || github.event_name == 'workflow_dispatch' && (fromJSON(github.event.inputs.aw_context || '{}').event_type == 'issues' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'issue_comment' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'pull_request_review_comment' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'pull_request' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'discussion' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'discussion_comment') | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_REACTION: "eyes" | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'add_reaction.cjs')); | |
| await main(); | |
| - name: Check for OAuth tokens | |
| id: check-oauth-tokens | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/check_oauth_tokens.sh" | |
| env: | |
| GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }} | |
| GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }} | |
| - name: Checkout .github and .agents folders | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| sparse-checkout: | | |
| .github | |
| .agents | |
| actions/setup | |
| .claude | |
| .codex | |
| .gemini | |
| .pi | |
| sparse-checkout-cone-mode: true | |
| fetch-depth: 1 | |
| - name: Save agent config folders for base branch restoration | |
| env: | |
| GH_AW_AGENT_FOLDERS: ".agents .github .pi" | |
| GH_AW_AGENT_FILES: "AGENTS.MD AGENTS.md AGENTS.override.md CLAUDE.MD CLAUDE.md PI.md" | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/save_base_github_folders.sh" | |
| - name: Check workflow lock file | |
| id: check-lock-file | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_WORKFLOW_FILE: "pr-sous-chef.lock.yml" | |
| GH_AW_CONTEXT_WORKFLOW_REF: "${{ github.workflow_ref }}" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'check_workflow_timestamp_api.cjs')); | |
| await main(); | |
| - name: Compute current body text | |
| id: sanitized | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_ALLOWED_DOMAINS: "*.grafana.net,*.sentry.io,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,s.symcb.com,s.symcd.com,security.ubuntu.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'compute_text.cjs')); | |
| await main(); | |
| - name: Add comment with workflow run link | |
| id: add-comment | |
| if: github.event_name == 'issues' || github.event_name == 'issue_comment' || github.event_name == 'pull_request_review_comment' || github.event_name == 'discussion' || github.event_name == 'discussion_comment' || github.event_name == 'pull_request' && github.event.pull_request.head.repo.id == github.repository_id || github.event_name == 'workflow_dispatch' && (fromJSON(github.event.inputs.aw_context || '{}').event_type == 'issues' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'issue_comment' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'pull_request_review_comment' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'pull_request' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'discussion' || fromJSON(github.event.inputs.aw_context || '{}').event_type == 'discussion_comment') | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_EMOJI: "👨\u200d🍳" | |
| GH_AW_SAFE_OUTPUT_MESSAGES: "{\"runStarted\":\"🍳 [{workflow_name}]({run_url}) is preparing PRs for maintainer investigation.\",\"runSuccess\":\"✅ [{workflow_name}]({run_url}) finished PR sous-chef nudges.\",\"runFailure\":\"⚠️ [{workflow_name}]({run_url}) {status} while preparing PRs.\"}" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'add_workflow_run_comment.cjs')); | |
| await main(); | |
| - name: Log runtime features | |
| if: ${{ contains(toJSON(vars), '"GH_AW_RUNTIME_FEATURES":') }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/log_runtime_features_summary.sh" | |
| - name: Create prompt with built-in context | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_ACTIONS_DIR: ${{ runner.temp }}/gh-aw/actions | |
| GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_SAFE_OUTPUTS: ${{ runner.temp }}/gh-aw/safeoutputs/outputs.jsonl | |
| GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_cli_only_transport_prompt.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"cli_proxy_with_safeoutputs_prompt.md\"},{\"file\":\"pr_context_prompt.md\",\"condition_env\":\"GH_AW_INCLUDE_PR_CONTEXT\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0006\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0007\"}],\"system_item_count\":13}" | |
| GH_AW_EXPR_76DF9333: ${{ github.event.pull_request.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'pull_request' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_EXPR_77C1A4D2: ${{ github.event.comment.id || fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').comment_id }} | |
| GH_AW_EXPR_7C248226: ${{ github.event.issue.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'issue' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_EXPR_C19C384F: ${{ github.event.discussion.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'discussion' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_GITHUB_ACTOR: ${{ github.actor }} | |
| GH_AW_GITHUB_REPOSITORY: ${{ github.repository }} | |
| GH_AW_GITHUB_RUN_ID: ${{ github.run_id }} | |
| GH_AW_GITHUB_WORKSPACE: ${{ github.workspace }} | |
| GH_AW_INCLUDE_PR_CONTEXT: ${{ (github.event_name == 'issue_comment' && github.event.issue.pull_request != null) || github.event_name == 'pull_request_review_comment' || github.event_name == 'pull_request_review' }} | |
| GH_AW_PROMPT_CONTENT_0000: "<system>\n" | |
| GH_AW_PROMPT_CONTENT_0001: "<safe-output-tools>\nTools: add_comment(max:5), create_issue, approve_workflow_run(max:8), dismiss_pull_request_review(max:20), missing_tool, missing_data, noop(max:2)\n" | |
| GH_AW_PROMPT_CONTENT_0002: "</safe-output-tools>\n" | |
| GH_AW_PROMPT_CONTENT_0003: "<github-context>\nThe following GitHub context information is available for this workflow:\n{{#if github.actor}}\n- **actor**: __GH_AW_GITHUB_ACTOR__\n{{/if}}\n{{#if github.repository}}\n- **repository**: __GH_AW_GITHUB_REPOSITORY__\n{{/if}}\n{{#if github.workspace}}\n- **workspace**: __GH_AW_GITHUB_WORKSPACE__\n{{/if}}\n{{#if github.event.issue.number || (github.aw.context.item_type == 'issue' && github.aw.context.item_number)}}\n- **issue-number**: #__GH_AW_EXPR_7C248226__\n{{/if}}\n{{#if github.event.discussion.number || (github.aw.context.item_type == 'discussion' && github.aw.context.item_number)}}\n- **discussion-number**: #__GH_AW_EXPR_C19C384F__\n{{/if}}\n{{#if github.event.pull_request.number || (github.aw.context.item_type == 'pull_request' && github.aw.context.item_number)}}\n- **pull-request-number**: #__GH_AW_EXPR_76DF9333__\n{{/if}}\n{{#if github.event.comment.id || github.aw.context.comment_id}}\n- **comment-id**: __GH_AW_EXPR_77C1A4D2__\n{{/if}}\n{{#if github.run_id}}\n- **workflow-run-id**: __GH_AW_GITHUB_RUN_ID__\n{{/if}}\n- **checkouts**: The following repositories have been checked out and are available in the workspace:\n - repo `__GH_AW_GITHUB_REPOSITORY__` → `__GH_AW_GITHUB_WORKSPACE__` (cwd) [shallow clone, fetch-depth=1 (default)] [sparse checkout enabled]\n - **Note**: The workspace path reported above may contain a separate shallow, credential-free checkout of the host repository. Use the exact checkout path shown for the repository you need. Before concluding that a branch is unavailable, confirm your working directory matches that path and inspect refs there. If the branch is not present in that checkout and is not listed as an additional fetched ref, it has NOT been checked out. For private repositories you cannot fetch it. If the branch is required and not available, exit with an error and ask the user to add it to the `fetch:` option of the `checkout:` configuration (e.g., `fetch: [\"refs/pulls/open/*\"]` for all open PR refs, or `fetch: [\"main\", \"feature/my-branch\"]` for specific branches).\n - **Warning: No git credentials are available to the agent.** Credentials are\n intentionally removed after the checkout step for security. This means any git\n operation that needs to authenticate to the remote will fail. In private repositories, that includes:\n - `git fetch`, `git pull`, `git clone`, and `git push` (direct push, not via safe-output tools)\n - Checking out or switching to a remote branch that is not already fetched\n - Deepening a shallow clone (`git fetch --unshallow`)\n - On-demand blob fetches in partial/blobless clones (operations on files not in the initial checkout)\n Do NOT attempt to configure credentials, run `git credential fill`, or modify `.gitconfig` —\n authentication will not succeed. If you encounter credential prompts or authentication errors,\n stop immediately and report the limitation rather than spending turns trying to work around it.\n</github-context>\n\n" | |
| GH_AW_PROMPT_CONTENT_0004: "</system>\n" | |
| GH_AW_PROMPT_CONTENT_0005: "{{#runtime-import .github/workflows/shared/mcp-pagination.md}}\n" | |
| GH_AW_PROMPT_CONTENT_0006: "{{#runtime-import .github/workflows/shared/otlp.md}}\n" | |
| GH_AW_PROMPT_CONTENT_0007: "{{#runtime-import .github/workflows/pr-sous-chef.md}}\n" | |
| with: | |
| script: | | |
| const { setupGlobals } = require(process.env.GH_AW_ACTIONS_DIR + '/setup_globals.cjs'); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(process.env.GH_AW_ACTIONS_DIR + '/create_prompt.cjs'); | |
| await main(core); | |
| - name: Interpolate variables and render templates | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_SUB_AGENT_DIR: ".pi/agents" | |
| GH_AW_SUB_AGENT_EXT: ".md" | |
| GH_AW_SKILL_DIR: ".pi/skills" | |
| GH_AW_SKILL_EXT: "/SKILL.md" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'interpolate_prompt.cjs')); | |
| await main(); | |
| - name: Substitute placeholders | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_EXPR_76DF9333: ${{ github.event.pull_request.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'pull_request' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_EXPR_77C1A4D2: ${{ github.event.comment.id || fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').comment_id }} | |
| GH_AW_EXPR_7C248226: ${{ github.event.issue.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'issue' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_EXPR_C19C384F: ${{ github.event.discussion.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'discussion' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} | |
| GH_AW_GITHUB_ACTOR: ${{ github.actor }} | |
| GH_AW_GITHUB_REPOSITORY: ${{ github.repository }} | |
| GH_AW_GITHUB_RUN_ID: ${{ github.run_id }} | |
| GH_AW_GITHUB_WORKSPACE: ${{ github.workspace }} | |
| GH_AW_INCLUDE_PR_CONTEXT: ${{ (github.event_name == 'issue_comment' && github.event.issue.pull_request != null) || github.event_name == 'pull_request_review_comment' || github.event_name == 'pull_request_review' }} | |
| GH_AW_MCP_CLI_SERVERS_LIST: '- `safeoutputs` — run `safeoutputs --help` to see available tools' | |
| GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_ACTIVATED: ${{ needs.pre_activation.outputs.activated }} | |
| GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_MATCHED_COMMAND: ${{ needs.pre_activation.outputs.matched_command }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const substitutePlaceholders = require(path.join(actionsDir, 'substitute_placeholders.cjs')); | |
| // Call the substitution function | |
| return await substitutePlaceholders({ | |
| file: process.env.GH_AW_PROMPT, | |
| substitutions: { | |
| GH_AW_EXPR_76DF9333: process.env.GH_AW_EXPR_76DF9333, | |
| GH_AW_EXPR_77C1A4D2: process.env.GH_AW_EXPR_77C1A4D2, | |
| GH_AW_EXPR_7C248226: process.env.GH_AW_EXPR_7C248226, | |
| GH_AW_EXPR_C19C384F: process.env.GH_AW_EXPR_C19C384F, | |
| GH_AW_GITHUB_ACTOR: process.env.GH_AW_GITHUB_ACTOR, | |
| GH_AW_GITHUB_REPOSITORY: process.env.GH_AW_GITHUB_REPOSITORY, | |
| GH_AW_GITHUB_RUN_ID: process.env.GH_AW_GITHUB_RUN_ID, | |
| GH_AW_GITHUB_WORKSPACE: process.env.GH_AW_GITHUB_WORKSPACE, | |
| GH_AW_INCLUDE_PR_CONTEXT: process.env.GH_AW_INCLUDE_PR_CONTEXT, | |
| GH_AW_MCP_CLI_SERVERS_LIST: process.env.GH_AW_MCP_CLI_SERVERS_LIST, | |
| GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_ACTIVATED: process.env.GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_ACTIVATED, | |
| GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_MATCHED_COMMAND: process.env.GH_AW_NEEDS_PRE_ACTIVATION_OUTPUTS_MATCHED_COMMAND | |
| } | |
| }); | |
| - name: Validate prompt placeholders | |
| env: | |
| GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/validate_prompt_placeholders.sh" | |
| - name: Print prompt | |
| env: | |
| GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/print_prompt_summary.sh" | |
| - name: Upload info artifact | |
| if: success() || failure() | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: info | |
| path: /tmp/gh-aw/aw_info.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Stage prompt files for artifact upload | |
| run: | | |
| mkdir -p /tmp/gh-aw/aw-prompts | |
| cp -a "${RUNNER_TEMP}/gh-aw/aw-prompts/." /tmp/gh-aw/aw-prompts/ | |
| - name: Upload activation artifact | |
| if: success() || failure() | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: activation | |
| include-hidden-files: true | |
| path: | | |
| /tmp/gh-aw/aw_info.json | |
| /tmp/gh-aw/models.json | |
| /tmp/gh-aw/aw-prompts/prompt.txt | |
| /tmp/gh-aw/aw-prompts/system.txt | |
| /tmp/gh-aw/aw-prompts/user.txt | |
| /tmp/gh-aw/aw-prompts/prompt-template.txt | |
| /tmp/gh-aw/aw-prompts/prompt-import-tree.json | |
| /tmp/gh-aw/github_rate_limits.jsonl | |
| /tmp/gh-aw/base | |
| /tmp/gh-aw/.pi/agents | |
| /tmp/gh-aw/.pi/skills | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '1' }} | |
| agent: | |
| name: agent | |
| needs: | |
| - activation | |
| - prefilter | |
| if: > | |
| needs.prefilter.outputs.rate_limit_low == 'false' && (needs.prefilter.outputs.eligible_count > 0 || needs.activation.outputs.slash_command == 'souschef') | |
| runs-on: ubuntu-latest | |
| # Permissions for the agent job (workflow permissions default to none). | |
| permissions: | |
| actions: read | |
| contents: read | |
| copilot-requests: write | |
| issues: read | |
| pull-requests: read | |
| concurrency: | |
| group: "gh-aw-pi-${{ github.workflow }}" | |
| queue: max | |
| timeout-minutes: 60 | |
| env: | |
| DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} | |
| GH_AW_ASSETS_ALLOWED_EXTS: "" | |
| GH_AW_ASSETS_BRANCH: "" | |
| GH_AW_ASSETS_MAX_SIZE_KB: 0 | |
| GH_AW_MCP_LOG_DIR: /tmp/gh-aw/mcp-logs/safeoutputs | |
| GH_AW_PROJECT_UTC: "-08:00" | |
| GH_AW_PR_HEAD_BASE_BRANCH: "" | |
| GH_AW_PR_HEAD_BASE_PR_NUMBER: "" | |
| GH_AW_PR_HEAD_BASE_REF: "" | |
| GH_AW_PR_HEAD_BASE_REPO: "" | |
| GH_AW_PR_HEAD_BASE_SHA: "" | |
| GH_AW_PR_HEAD_REPO: "" | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| GH_AW_WORKFLOW_ID_SANITIZED: prsouschef | |
| outputs: | |
| ai_credits_rate_limit_error: ${{ steps.parse-mcp-gateway.outputs.ai_credits_rate_limit_error || 'false' }} | |
| aic: ${{ steps.parse-token-usage.outputs.aic }} | |
| ambient_context: ${{ steps.parse-token-usage.outputs.ambient_context }} | |
| checkout_pr_success: ${{ steps.checkout-pr.outputs.checkout_pr_success || 'true' }} | |
| has_patch: ${{ steps.collect_output.outputs.has_patch }} | |
| model: ${{ needs.activation.outputs.model }} | |
| output: ${{ steps.collect_output.outputs.output }} | |
| output_types: ${{ steps.collect_output.outputs.output_types }} | |
| setup-parent-span-id: ${{ steps.setup.outputs.parent-span-id || steps.setup.outputs.span-id }} | |
| setup-span-id: ${{ steps.setup.outputs.span-id }} | |
| setup-trace-id: ${{ steps.setup.outputs.trace-id }} | |
| unknown_model_ai_credits: ${{ steps.parse-mcp-gateway.outputs.unknown_model_ai_credits || 'false' }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Set runtime paths | |
| id: set-runtime-paths | |
| env: | |
| GH_AW_RUNNER_TOOL_CACHE: ${{ runner.tool_cache }} | |
| run: | # zizmor: ignore[github-env] - runner.tool_cache is set by GitHub Actions, not user input. | |
| if [ -z "${RUNNER_TOOL_CACHE:-}" ]; then | |
| echo "RUNNER_TOOL_CACHE=${GH_AW_RUNNER_TOOL_CACHE}" >> "$GITHUB_ENV" | |
| fi | |
| { | |
| echo "GH_AW_SAFE_OUTPUTS=${RUNNER_TEMP}/gh-aw/safeoutputs/outputs.jsonl" | |
| echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" | |
| echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" | |
| } >> "$GITHUB_OUTPUT" | |
| - name: Mask OTLP telemetry headers | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" | |
| - name: Checkout repository (gh-aw default) | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| filter: 'blob:limit=1073741824' | |
| sparse-checkout: | | |
| scripts | |
| actions | |
| .github/scripts | |
| - name: Clear partial clone markers after sparse checkout | |
| continue-on-error: true | |
| run: | | |
| git config --local --unset-all remote.origin.promisor || true | |
| git config --local --unset-all remote.origin.partialclonefilter || true | |
| - name: Initialize agent execution evidence | |
| run: | | |
| mkdir -p "/tmp/gh-aw" | |
| evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" | |
| printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" | |
| - name: Create gh-aw temp directory | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" | |
| - name: Configure gh CLI for GitHub Enterprise | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_gh_for_ghe.sh" | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| - name: Download activation artifact | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| name: activation | |
| path: /tmp/gh-aw | |
| - name: Download compact queue | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| name: pr-sous-chef-queue | |
| path: /tmp/gh-aw/agent | |
| - name: Configure Git credentials | |
| env: | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh" | |
| - name: Checkout PR branch | |
| id: checkout-pr | |
| if: | | |
| github.event.pull_request || github.event.issue.pull_request || github.event_name == 'workflow_dispatch' | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'checkout_pr_branch.cjs')); | |
| await main(); | |
| - name: Setup Node.js | |
| uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 | |
| with: | |
| node-version: '24' | |
| package-manager-cache: false | |
| - name: Install AWF binary | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.28.50 --rootless | |
| - name: Install Pi CLI | |
| run: npm install --ignore-scripts -g @earendil-works/pi-coding-agent@1.0.0 | |
| - name: Record Pi package location | |
| run: | | |
| GH_AW_PI_PACKAGE_ROOT="$(npm root -g)/@earendil-works/pi-coding-agent" | |
| printf 'GH_AW_PI_PACKAGE_ROOT=%s\n' "$GH_AW_PI_PACKAGE_ROOT" >> "$GITHUB_ENV" | |
| - name: Determine automatic lockdown mode for GitHub MCP Server | |
| id: determine-automatic-lockdown | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }} | |
| GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }} | |
| GH_AW_GITHUB_MIN_INTEGRITY: 'none' | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const determineAutomaticLockdown = require(path.join(actionsDir, 'determine_automatic_lockdown.cjs')); | |
| await determineAutomaticLockdown(github, context, core); | |
| - name: Parse integrity filter lists | |
| id: parse-guard-vars | |
| env: | |
| GH_AW_BLOCKED_USERS_VAR: ${{ vars.GH_AW_GITHUB_BLOCKED_USERS || '' }} | |
| GH_AW_TRUSTED_USERS_VAR: ${{ vars.GH_AW_GITHUB_TRUSTED_USERS || '' }} | |
| GH_AW_APPROVAL_LABELS_VAR: ${{ vars.GH_AW_GITHUB_APPROVAL_LABELS || '' }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/parse_guard_list.sh" | |
| - name: Restore agent config folders from base branch | |
| if: steps.checkout-pr.outcome == 'success' | |
| env: | |
| GH_AW_AGENT_FOLDERS: ".agents .github .pi" | |
| GH_AW_AGENT_FILES: "AGENTS.MD AGENTS.md AGENTS.override.md CLAUDE.MD CLAUDE.md PI.md" | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_base_github_folders.sh" | |
| - name: Restore inline sub-agents from activation artifact | |
| env: | |
| GH_AW_SUB_AGENT_DIR: ".pi/agents" | |
| GH_AW_SUB_AGENT_EXT: ".md" | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_sub_agents.sh" | |
| - name: Restore inline skills from activation artifact | |
| env: | |
| GH_AW_SKILL_DIR: ".pi/skills" | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" | |
| - name: Download container images | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.50@sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50@sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50@sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce ghcr.io/github/gh-aw-firewall/squid:0.28.50@sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9 ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6 | |
| - name: Prepare Safe Outputs Directories | |
| run: | | |
| mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" | |
| mkdir -p /tmp/gh-aw/safeoutputs | |
| mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs | |
| - name: Generate Safe Outputs Config | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_FILE_ROOT: "${{ runner.temp }}/gh-aw" | |
| GH_AW_FILE_CONFIG: "{\"files\":[{\"path\":\"safeoutputs/config.json\",\"content_env\":\"GH_AW_SAFE_OUTPUTS_CONFIG\"}]}" | |
| GH_AW_SAFE_OUTPUTS_CONFIG: "{\"add_comment\":{\"github-token\":\"${GH_AW_SECRET_AWI_MAINTENANCE_TOKEN}\",\"max\":5,\"target\":\"*\"},\"approve_workflow_run\":{\"allowed_pull_requests\":${{ toJSON(needs.prefilter.outputs.eligible_pull_request_numbers) }},\"allowed_workflows\":[\"cjs.yml\",\"cgo.yml\",\"CWI.yml\"],\"comment\":true,\"github-token\":\"${GH_AW_SECRET_AWI_MAINTENANCE_TOKEN}\",\"max\":8,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"CHANGELOG.md\",\"PI.md\",\"AGENTS.md\",\"AGENTS.override.md\",\"AGENTS.MD\",\"CLAUDE.md\",\"CLAUDE.MD\"]},\"create_issue\":{\"close_older_issues\":true,\"expires\":72,\"group_by_day\":true,\"labels\":[\"automation\"],\"max\":1,\"title_prefix\":\"[pr-sous-chef] \"},\"create_report_incomplete_issue\":{},\"dismiss_pull_request_review\":{\"max\":20,\"target\":\"*\"},\"mentions\":{\"allowed\":[\"copilot\"]},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" | |
| GH_AW_SECRET_AWI_MAINTENANCE_TOKEN: ${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| GH_AW_SECRET_GH_AW_GITHUB_TOKEN: ${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| GH_AW_SECRET_GITHUB_TOKEN: ${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'create_files.cjs')); | |
| await main(); | |
| - name: Generate Safe Outputs Tools | |
| env: | |
| GH_AW_TOOLS_META_JSON: | | |
| { | |
| "description_suffixes": { | |
| "add_comment": " CONSTRAINTS: Maximum 5 comment(s) can be added. Target: *. Supports reply_to_id for discussion threading.", | |
| "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"[pr-sous-chef] \". Labels [\"automation\"] will be automatically added.", | |
| "dismiss_pull_request_review": " CONSTRAINTS: Maximum 20 review dismissal(s) can be performed. Target: *. justification must contain at least 20 characters." | |
| }, | |
| "repo_params": {}, | |
| "dynamic_tools": [] | |
| } | |
| GH_AW_VALIDATION_JSON: | | |
| { | |
| "add_comment": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "comment_id": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "item_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pr": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pr_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "reply_to_id": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "target": { | |
| "type": "string", | |
| "enum": [ | |
| "status" | |
| ] | |
| }, | |
| "temporary_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| } | |
| } | |
| }, | |
| "add_labels": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "item_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "labels": { | |
| "required": true, | |
| "type": "array" | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "add_reviewer": { | |
| "defaultMax": 3, | |
| "fields": { | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "reviewers": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 39 | |
| }, | |
| "team_reviewers": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 100 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:reviewers,team_reviewers" | |
| }, | |
| "ado_assign_work_item": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "assignee": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256, | |
| "minLength": 1 | |
| }, | |
| "work_item_id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| } | |
| } | |
| }, | |
| "ado_comment_on_work_item": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 10 | |
| }, | |
| "work_item_id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| } | |
| } | |
| }, | |
| "ado_create_work_item": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "description": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 31 | |
| }, | |
| "tags": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 256 | |
| }, | |
| "temporary_id": { | |
| "required": true, | |
| "type": "string", | |
| "pattern": "^#aw_[A-Za-z0-9_]{3,12}$", | |
| "temporaryId": true | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 255, | |
| "minLength": 6 | |
| } | |
| } | |
| }, | |
| "ado_link_work_items": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "comment": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 1024, | |
| "minLength": 5 | |
| }, | |
| "link_type": { | |
| "required": true, | |
| "type": "string", | |
| "enum": [ | |
| "parent", | |
| "child", | |
| "related", | |
| "predecessor", | |
| "successor", | |
| "duplicate", | |
| "duplicate-of" | |
| ] | |
| }, | |
| "source_id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "target_id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| } | |
| } | |
| }, | |
| "ado_update_work_item": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "area_path": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| }, | |
| "assignee": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "iteration_path": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| }, | |
| "state": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "tags": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 256 | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 255, | |
| "minLength": 1 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:title,body,state,area_path,iteration_path,assignee,tags" | |
| }, | |
| "ado_upload_workitem_attachment": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "comment": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 1024, | |
| "minLength": 3 | |
| }, | |
| "file_path": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 1024 | |
| }, | |
| "staged_file": { | |
| "required": true, | |
| "type": "string", | |
| "pattern": "^[A-Za-z0-9._/-]+$" | |
| }, | |
| "work_item_id": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| } | |
| } | |
| }, | |
| "approve_workflow_run": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "run_id": { | |
| "required": true, | |
| "positiveInteger": true | |
| } | |
| } | |
| }, | |
| "assign_milestone": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "issue_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "milestone_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "milestone_title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:milestone_number,milestone_title" | |
| }, | |
| "assign_to_agent": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "agent": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "confidence": { | |
| "type": "string", | |
| "enum": [ | |
| "LOW", | |
| "MEDIUM", | |
| "HIGH" | |
| ], | |
| "x-strip-on-error": true | |
| }, | |
| "issue_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "pull_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "pull_request_repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "rationale": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 280, | |
| "x-strip-on-error": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "suggest": { | |
| "type": "boolean" | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:issue_number,pull_number" | |
| }, | |
| "assign_to_user": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "assignee": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 39 | |
| }, | |
| "assignees": { | |
| "type": "[]string", | |
| "sanitize": true, | |
| "maxLength": 39 | |
| }, | |
| "confidence": { | |
| "type": "string", | |
| "enum": [ | |
| "LOW", | |
| "MEDIUM", | |
| "HIGH" | |
| ], | |
| "x-strip-on-error": true | |
| }, | |
| "issue_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "rationale": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 280, | |
| "x-strip-on-error": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "suggest": { | |
| "type": "boolean" | |
| } | |
| } | |
| }, | |
| "autofix_code_scanning_alert": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "alert_number": { | |
| "positiveInteger": true | |
| }, | |
| "fix_code": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 65000 | |
| }, | |
| "fix_description": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| } | |
| } | |
| }, | |
| "call_workflow": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "inputs": { | |
| "type": "object" | |
| }, | |
| "workflow_name": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| } | |
| } | |
| }, | |
| "close_discussion": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "discussion_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "reason": { | |
| "type": "string", | |
| "enum": [ | |
| "RESOLVED", | |
| "DUPLICATE", | |
| "OUTDATED", | |
| "ANSWERED" | |
| ] | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "close_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "confidence": { | |
| "type": "string", | |
| "enum": [ | |
| "LOW", | |
| "MEDIUM", | |
| "HIGH" | |
| ], | |
| "x-strip-on-error": true | |
| }, | |
| "duplicate_of": { | |
| "issueOrPRNumber": true | |
| }, | |
| "issue_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "rationale": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 280, | |
| "x-strip-on-error": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "state_reason": { | |
| "type": "string", | |
| "enum": [ | |
| "completed", | |
| "not_planned", | |
| "duplicate" | |
| ] | |
| }, | |
| "suggest": { | |
| "type": "boolean" | |
| } | |
| } | |
| }, | |
| "close_pull_request": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "pull_request_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "comment_memory": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "item_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "memory_id": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128, | |
| "pattern": "^[a-zA-Z0-9_-]+$", | |
| "patternError": "must contain only alphanumeric characters, hyphens, and underscores" | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "create_agent_session": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "create_check_run": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "conclusion": { | |
| "required": true, | |
| "type": "string", | |
| "enum": [ | |
| "success", | |
| "failure", | |
| "neutral", | |
| "cancelled", | |
| "skipped", | |
| "timed_out", | |
| "action_required" | |
| ] | |
| }, | |
| "pr": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pr_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pull_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "summary": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "text": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "create_code_scanning_alert": { | |
| "defaultMax": 40, | |
| "fields": { | |
| "column": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "file": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| }, | |
| "line": { | |
| "required": true, | |
| "positiveInteger": true | |
| }, | |
| "message": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 2048 | |
| }, | |
| "ruleIdSuffix": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128, | |
| "pattern": "^[a-zA-Z0-9_-]+$", | |
| "patternError": "must contain only alphanumeric characters, hyphens, and underscores" | |
| }, | |
| "severity": { | |
| "required": true, | |
| "type": "string", | |
| "enum": [ | |
| "error", | |
| "warning", | |
| "info", | |
| "note" | |
| ] | |
| } | |
| } | |
| }, | |
| "create_discussion": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 64 | |
| }, | |
| "category": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| } | |
| }, | |
| "create_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "blocked_by": {}, | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 20 | |
| }, | |
| "fields": { | |
| "type": "array" | |
| }, | |
| "labels": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 128 | |
| }, | |
| "parent": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "temporary_id": { | |
| "type": "string" | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| }, | |
| "collapseData": true | |
| }, | |
| "create_project": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "item_url": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| }, | |
| "owner": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "owner_type": { | |
| "type": "string", | |
| "enum": [ | |
| "org", | |
| "user" | |
| ] | |
| }, | |
| "temporary_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "create_project_status_update": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65536 | |
| }, | |
| "project": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512, | |
| "pattern": "^https://[^/]+/(orgs|users)/[^/]+/projects/\\d+", | |
| "patternError": "must be a full GitHub project URL (e.g., https://github.com/orgs/myorg/projects/42)" | |
| }, | |
| "start_date": { | |
| "type": "string", | |
| "pattern": "^\\d{4}-\\d{2}-\\d{2}$", | |
| "patternError": "must be in YYYY-MM-DD format" | |
| }, | |
| "status": { | |
| "type": "string", | |
| "enum": [ | |
| "INACTIVE", | |
| "ON_TRACK", | |
| "AT_RISK", | |
| "OFF_TRACK", | |
| "COMPLETE" | |
| ] | |
| }, | |
| "target_date": { | |
| "type": "string", | |
| "pattern": "^\\d{4}-\\d{2}-\\d{2}$", | |
| "patternError": "must be in YYYY-MM-DD format" | |
| } | |
| } | |
| }, | |
| "create_pull_request": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "base": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "branch": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "dependencies": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 256 | |
| }, | |
| "draft": { | |
| "type": "boolean" | |
| }, | |
| "labels": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 128 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "stack_position": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "stack_root": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "temporary_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| } | |
| }, | |
| "create_pull_request_review_comment": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "line": { | |
| "required": true, | |
| "positiveInteger": true | |
| }, | |
| "path": { | |
| "required": true, | |
| "type": "string" | |
| }, | |
| "pull_request_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "side": { | |
| "type": "string", | |
| "enum": [ | |
| "LEFT", | |
| "RIGHT" | |
| ] | |
| }, | |
| "start_line": { | |
| "optionalPositiveInteger": true | |
| } | |
| }, | |
| "customValidation": "startLineLessOrEqualLine" | |
| }, | |
| "dismiss_pull_request_review": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "author": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "justification": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 20 | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "review_id": { | |
| "optionalPositiveInteger": true, | |
| "allowAuto": true | |
| } | |
| } | |
| }, | |
| "dispatch_workflow": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "inputs": { | |
| "type": "object" | |
| }, | |
| "ref": { | |
| "type": "string", | |
| "maxLength": 256, | |
| "minLength": 1, | |
| "pattern": "^[^\\x00-\\x20\\x7f~^:?*\\[\\\\]+$", | |
| "patternError": "must be a valid git ref" | |
| }, | |
| "workflow_name": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| } | |
| } | |
| }, | |
| "hide_comment": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "comment_id": { | |
| "required": true, | |
| "type": "string", | |
| "typeHint": "GraphQL node ID string (e.g. 'IC_kwDOABCD123456'); numeric REST comment IDs are accepted but may not resolve for all comment types (e.g. PR review comments)", | |
| "maxLength": 256 | |
| }, | |
| "reason": { | |
| "type": "string", | |
| "enum": [ | |
| "SPAM", | |
| "ABUSE", | |
| "OFF_TOPIC", | |
| "OUTDATED", | |
| "RESOLVED", | |
| "LOW_QUALITY" | |
| ] | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "jira_add_comment": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 32767, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "issue_key": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| } | |
| } | |
| }, | |
| "jira_add_label": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "issue_key": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "label": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": "^[A-Za-z0-9_.-]+$", | |
| "patternError": "must contain only letters, numbers, periods, hyphens, and underscores" | |
| } | |
| } | |
| }, | |
| "jira_create_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "description": { | |
| "type": "string", | |
| "maxLength": 32767, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "issue_type": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "project_key": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "summary": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "temporary_id": { | |
| "required": true, | |
| "type": "string", | |
| "pattern": "^#aw_[A-Za-z0-9_]{3,12}$", | |
| "temporaryId": true | |
| } | |
| } | |
| }, | |
| "jira_update_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "description": { | |
| "type": "string", | |
| "maxLength": 32767, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "issue_key": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| }, | |
| "summary": { | |
| "type": "string", | |
| "maxLength": 255, | |
| "minLength": 1, | |
| "pattern": ".*\\S.*", | |
| "patternError": "must not be empty" | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:summary,description" | |
| }, | |
| "ledger_append": { | |
| "defaultMax": 100, | |
| "fields": { | |
| "amount": { | |
| "type": "number" | |
| }, | |
| "citations": { | |
| "type": "array", | |
| "itemType": "object" | |
| }, | |
| "filter": { | |
| "type": "object" | |
| }, | |
| "key": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "ledger": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 64 | |
| }, | |
| "name": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "note": { | |
| "type": "string", | |
| "maxLength": 4096 | |
| }, | |
| "note_id": { | |
| "type": "string", | |
| "maxLength": 128 | |
| }, | |
| "operation": { | |
| "type": "string", | |
| "maxLength": 32 | |
| }, | |
| "patch": { | |
| "type": "object" | |
| }, | |
| "reason": { | |
| "type": "string", | |
| "maxLength": 1024 | |
| }, | |
| "record": { | |
| "type": "object" | |
| }, | |
| "result": { | |
| "allowNull": true | |
| }, | |
| "subject": { | |
| "type": "string", | |
| "maxLength": 512 | |
| }, | |
| "temp_id": { | |
| "type": "string", | |
| "pattern": "^#?[A-Za-z0-9][A-Za-z0-9_-]{0,63}$" | |
| }, | |
| "value": { | |
| "allowNull": true | |
| }, | |
| "vote": { | |
| "type": "string", | |
| "enum": [ | |
| "up", | |
| "down" | |
| ] | |
| }, | |
| "work": { | |
| "type": "object" | |
| } | |
| } | |
| }, | |
| "ledger_mutation": { | |
| "defaultMax": 1000, | |
| "fields": { | |
| "operation": { | |
| "required": true, | |
| "type": "string", | |
| "enum": [ | |
| "append" | |
| ] | |
| }, | |
| "record": { | |
| "required": true, | |
| "type": "object" | |
| }, | |
| "timestamp": { | |
| "type": "string", | |
| "maxLength": 64 | |
| } | |
| } | |
| }, | |
| "ledger_request_compaction": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "ledger": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 64 | |
| }, | |
| "reason": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| } | |
| } | |
| }, | |
| "linear_add_comment": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "rejectIfOversized": true | |
| } | |
| } | |
| }, | |
| "linear_create_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 20, | |
| "rejectIfOversized": true | |
| }, | |
| "title": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128, | |
| "rejectIfOversized": true | |
| } | |
| } | |
| }, | |
| "linear_update_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "rejectIfOversized": true | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128, | |
| "rejectIfOversized": true | |
| } | |
| } | |
| }, | |
| "link_sub_issue": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "parent_issue_number": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "sub_issue_number": { | |
| "required": true, | |
| "issueNumberOrTemporaryId": true | |
| } | |
| }, | |
| "customValidation": "parentAndSubDifferent" | |
| }, | |
| "mark_pull_request_as_ready_for_review": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "reason": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "mentions": { | |
| "allowed": [ | |
| "copilot" | |
| ] | |
| }, | |
| "merge_pull_request": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "commit_message": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "commit_title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "merge_method": { | |
| "type": "string", | |
| "enum": [ | |
| "merge", | |
| "squash", | |
| "rebase" | |
| ] | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "missing_data": { | |
| "defaultMax": 20, | |
| "fields": { | |
| "alternatives": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "context": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "data_type": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "reason": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "missing_tool": { | |
| "defaultMax": 20, | |
| "fields": { | |
| "alternatives": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512 | |
| }, | |
| "reason": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "tool": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| } | |
| }, | |
| "noop": { | |
| "defaultMax": 2, | |
| "fields": { | |
| "message": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| } | |
| } | |
| }, | |
| "push_repo_memory": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "memory_id": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| } | |
| }, | |
| "push_to_pull_request_branch": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "branch": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "message": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "remove_labels": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "item_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "labels": { | |
| "required": true, | |
| "type": "array" | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "replace_label": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "item_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "label_to_add": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "label_to_remove": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "reply_to_pull_request_review_comment": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "comment_id": { | |
| "required": true, | |
| "positiveInteger": true | |
| }, | |
| "pull_request_number": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "report_incomplete": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "details": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "reason": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 1024 | |
| } | |
| } | |
| }, | |
| "resolve_pull_request_review_thread": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "thread_id": { | |
| "required": true, | |
| "type": "string" | |
| } | |
| } | |
| }, | |
| "set_issue_field": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "confidence": { | |
| "type": "string", | |
| "enum": [ | |
| "LOW", | |
| "MEDIUM", | |
| "HIGH" | |
| ], | |
| "x-strip-on-error": true | |
| }, | |
| "field_name": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| }, | |
| "field_node_id": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "issue_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "rationale": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 280, | |
| "x-strip-on-error": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "suggest": { | |
| "type": "boolean" | |
| }, | |
| "value": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:field_name,field_node_id" | |
| }, | |
| "set_issue_type": { | |
| "defaultMax": 5, | |
| "fields": { | |
| "confidence": { | |
| "type": "string", | |
| "enum": [ | |
| "LOW", | |
| "MEDIUM", | |
| "HIGH" | |
| ], | |
| "x-strip-on-error": true | |
| }, | |
| "issue_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "issue_type": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128, | |
| "allowEmpty": true | |
| }, | |
| "rationale": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 280, | |
| "x-strip-on-error": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "suggest": { | |
| "type": "boolean" | |
| } | |
| } | |
| }, | |
| "submit_pull_request_review": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "event": { | |
| "type": "string", | |
| "enum": [ | |
| "APPROVE", | |
| "REQUEST_CHANGES", | |
| "COMMENT" | |
| ] | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "unassign_from_user": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "assignee": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 39 | |
| }, | |
| "assignees": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 39 | |
| }, | |
| "issue_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "update_discussion": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "discussion_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "labels": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 128 | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:title,body,labels" | |
| }, | |
| "update_issue": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "assignees": { | |
| "type": "array", | |
| "itemType": "string", | |
| "itemSanitize": true, | |
| "itemMaxLength": 39 | |
| }, | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "issue_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "labels": { | |
| "type": "array" | |
| }, | |
| "milestone": { | |
| "optionalPositiveInteger": true, | |
| "allowNull": true | |
| }, | |
| "operation": { | |
| "type": "string", | |
| "enum": [ | |
| "replace", | |
| "append", | |
| "prepend", | |
| "replace-island" | |
| ] | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "status": { | |
| "type": "string", | |
| "enum": [ | |
| "open", | |
| "closed" | |
| ] | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 128 | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:status,title,body,labels,assignees,milestone" | |
| }, | |
| "update_project": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "content_number": { | |
| "issueNumberOrTemporaryId": true | |
| }, | |
| "content_type": { | |
| "type": "string", | |
| "enum": [ | |
| "issue", | |
| "pull_request", | |
| "draft_issue" | |
| ] | |
| }, | |
| "create_if_missing": { | |
| "type": "boolean" | |
| }, | |
| "draft_body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "draft_issue_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| }, | |
| "draft_title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "field_definitions": { | |
| "type": "array" | |
| }, | |
| "fields": { | |
| "type": "object" | |
| }, | |
| "issue": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "operation": { | |
| "type": "string", | |
| "enum": [ | |
| "create_fields", | |
| "create_view" | |
| ] | |
| }, | |
| "project": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 512, | |
| "pattern": "^(https://[^/]+/(orgs|users)/[^/]+/projects/\\d+|#?aw_[A-Za-z0-9_]{3,12})$", | |
| "patternError": "must be a full GitHub project URL (e.g., https://github.com/orgs/myorg/projects/42) or temporary project ID (e.g., #aw_project1)" | |
| }, | |
| "pull_request": { | |
| "optionalPositiveInteger": true | |
| }, | |
| "target_repo": { | |
| "type": "string", | |
| "pattern": "^[a-zA-Z0-9_.-]+/[a-zA-Z0-9_.-]+$" | |
| }, | |
| "temporary_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| }, | |
| "view": { | |
| "type": "object" | |
| } | |
| } | |
| }, | |
| "update_pull_request": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000 | |
| }, | |
| "draft": { | |
| "type": "boolean" | |
| }, | |
| "operation": { | |
| "type": "string", | |
| "enum": [ | |
| "replace", | |
| "append", | |
| "prepend", | |
| "replace-island" | |
| ] | |
| }, | |
| "pr": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pr_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "pull_request_number": { | |
| "issueOrPRNumber": true | |
| }, | |
| "repo": { | |
| "type": "string", | |
| "maxLength": 256 | |
| }, | |
| "title": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "update_branch": { | |
| "type": "boolean" | |
| } | |
| }, | |
| "customValidation": "requiresOneOf:title,body,update_branch" | |
| }, | |
| "update_release": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "body": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 65000, | |
| "minLength": 20 | |
| }, | |
| "operation": { | |
| "required": true, | |
| "type": "string", | |
| "enum": [ | |
| "replace", | |
| "append", | |
| "prepend" | |
| ] | |
| }, | |
| "tag": { | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| } | |
| } | |
| }, | |
| "upload_artifact": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "filters": { | |
| "type": "object" | |
| }, | |
| "path": { | |
| "type": "string" | |
| }, | |
| "temporary_id": { | |
| "type": "string", | |
| "pattern": "^#?aw_[A-Za-z0-9_]{3,12}$" | |
| } | |
| } | |
| }, | |
| "upload_asset": { | |
| "defaultMax": 10, | |
| "fields": { | |
| "path": { | |
| "required": true, | |
| "type": "string" | |
| } | |
| } | |
| }, | |
| "upload_code_coverage": { | |
| "defaultMax": 1, | |
| "fields": { | |
| "file": { | |
| "required": true, | |
| "type": "string", | |
| "maxLength": 4096, | |
| "pattern": "^(?!/)(?!.*\\.\\.).+$", | |
| "patternError": "must be a relative path within the upload-code-coverage staging directory (no leading \"/\" or \"..\" segments)" | |
| }, | |
| "label": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 256 | |
| }, | |
| "language": { | |
| "required": true, | |
| "type": "string", | |
| "sanitize": true, | |
| "maxLength": 64 | |
| } | |
| } | |
| } | |
| } | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'generate_safe_outputs_tools.cjs')); | |
| await main(); | |
| - name: Start MCP Gateway | |
| id: start-mcp-gateway | |
| env: | |
| GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST: ${{ vars.GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST || 'true' }} | |
| GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} | |
| GH_AW_SAFE_OUTPUTS_CONFIG_PATH: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS_CONFIG_PATH }} | |
| GH_AW_SAFE_OUTPUTS_TOOLS_PATH: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS_TOOLS_PATH }} | |
| GH_AW_SINK_VISIBILITY: ${{ steps.determine-automatic-lockdown.outputs.visibility }} | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| set -eo pipefail | |
| mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config" | |
| if [ -n "${GITHUB_EVENT_PATH:-}" ] && [ -r "${GITHUB_EVENT_PATH}" ]; then | |
| GH_AW_SAFEOUTPUTS_EVENT_PATH="${RUNNER_TEMP}/gh-aw/safeoutputs/github_event.json" | |
| cp "${GITHUB_EVENT_PATH}" "${GH_AW_SAFEOUTPUTS_EVENT_PATH}" | |
| export GITHUB_EVENT_PATH="${GH_AW_SAFEOUTPUTS_EVENT_PATH}" | |
| fi | |
| # Export gateway environment variables for MCP config and gateway script | |
| export MCP_GATEWAY_PORT="8080" | |
| export MCP_GATEWAY_DOMAIN="awmg-mcpg" | |
| export MCP_GATEWAY_HOST_DOMAIN="localhost" | |
| MCP_GATEWAY_AGENT_ID=$(openssl rand -base64 45 | tr -d '/+=') | |
| echo "::add-mask::${MCP_GATEWAY_AGENT_ID}" | |
| export MCP_GATEWAY_AGENT_ID | |
| export MCP_GATEWAY_PAYLOAD_DIR="/tmp/gh-aw/mcp-payloads" | |
| mkdir -p "${MCP_GATEWAY_PAYLOAD_DIR}" | |
| export MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD="524288" | |
| export MCP_GATEWAY_ALLOWED_MOUNT_ROOTS="${GITHUB_WORKSPACE}:rw,${RUNNER_TEMP}/gh-aw:ro,${RUNNER_TEMP}/gh-aw/safeoutputs:rw,/opt:ro,/tmp:rw,/usr/bin/gh:ro" | |
| export GH_AW_PR_HEAD_BASE_BRANCH="${GH_AW_PR_HEAD_BASE_BRANCH:-}" | |
| export GH_AW_PR_HEAD_BASE_SHA="${GH_AW_PR_HEAD_BASE_SHA:-}" | |
| export GH_AW_PR_HEAD_BASE_REPO="${GH_AW_PR_HEAD_BASE_REPO:-}" | |
| export GH_AW_PR_HEAD_BASE_PR_NUMBER="${GH_AW_PR_HEAD_BASE_PR_NUMBER:-}" | |
| export GH_AW_PR_HEAD_BASE_REF="${GH_AW_PR_HEAD_BASE_REF:-}" | |
| export GH_AW_PR_HEAD_REPO="${GH_AW_PR_HEAD_REPO:-}" | |
| export DEBUG="*" | |
| export GH_AW_ENGINE="pi" | |
| export GH_AW_MCP_CLI_SERVERS='["safeoutputs"]' | |
| MCP_GATEWAY_UID=$(id -u 2>/dev/null || echo '0') | |
| MCP_GATEWAY_GID=$(id -g 2>/dev/null || echo '0') | |
| source "${RUNNER_TEMP}/gh-aw/actions/resolve_docker_socket_gid.sh" | |
| export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network bridge -p 127.0.0.1:'"${MCP_GATEWAY_PORT}"':'"${MCP_GATEWAY_PORT}"' --name awmg-mcpg --add-host host.docker.internal:host-gateway --user '"${MCP_GATEWAY_UID}"':'"${MCP_GATEWAY_GID}"' --group-add '"${DOCKER_SOCK_GID}"' -v '"${DOCKER_SOCK_PATH}"':/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_AGENT_ID -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DOCKER_HOST=unix:///var/run/docker.sock -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_PR_HEAD_BASE_BRANCH -e GH_AW_PR_HEAD_BASE_SHA -e GH_AW_PR_HEAD_BASE_REPO -e GH_AW_PR_HEAD_BASE_PR_NUMBER -e GH_AW_PR_HEAD_BASE_REF -e GH_AW_PR_HEAD_REPO -e GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GH_AW_SINK_VISIBILITY -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e RUNNER_TEMP -e RUNNER_TOOL_CACHE -e MCP_GATEWAY_ALLOWED_MOUNT_ROOTS -e GITHUB_AW_OTEL_TRACE_ID -e GITHUB_AW_OTEL_PARENT_SPAN_ID -e OTEL_EXPORTER_OTLP_HEADERS -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw -v '"${RUNNER_TEMP}"'/gh-aw/safeoutputs:'"${RUNNER_TEMP}"'/gh-aw/safeoutputs:rw ghcr.io/github/gh-aw-mcpg:v0.4.30@sha256:ab5a436a1490438db473e4e3d4c973cb1d75e3cb233fb08b73d31b42d7d18fba' | |
| GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) | |
| cat << GH_AW_MCP_CONFIG_dbcafd561cd90286_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" | |
| { | |
| "mcpServers": { | |
| "safeoutputs": { | |
| "container": "ghcr.io/github/gh-aw-node", | |
| "mounts": ["\${GITHUB_WORKSPACE}:\${GITHUB_WORKSPACE}:rw", "${RUNNER_TEMP}/gh-aw/safeoutputs:${RUNNER_TEMP}/gh-aw/safeoutputs:rw", "/tmp/gh-aw:/tmp/gh-aw:rw"], | |
| "args": ["-w", "\${GITHUB_WORKSPACE}"], | |
| "entrypoint": "sh", | |
| "entrypointArgs": ["-c", "sh ${RUNNER_TEMP}/gh-aw/safeoutputs/start_safe_outputs_mcp.sh"], | |
| "env": { | |
| "DEBUG": "*", | |
| "DEFAULT_BRANCH": "\${DEFAULT_BRANCH}", | |
| "GH_AW_ASSETS_ALLOWED_EXTS": "\${GH_AW_ASSETS_ALLOWED_EXTS}", | |
| "GH_AW_ASSETS_BRANCH": "\${GH_AW_ASSETS_BRANCH}", | |
| "GH_AW_ASSETS_MAX_SIZE_KB": "\${GH_AW_ASSETS_MAX_SIZE_KB}", | |
| "GH_AW_MCP_LOG_DIR": "\${GH_AW_MCP_LOG_DIR}", | |
| "GH_AW_SAFE_OUTPUTS": "\${GH_AW_SAFE_OUTPUTS}", | |
| "GH_AW_SAFE_OUTPUTS_CONFIG_PATH": "\${GH_AW_SAFE_OUTPUTS_CONFIG_PATH}", | |
| "GH_AW_SAFE_OUTPUTS_TOOLS_PATH": "\${GH_AW_SAFE_OUTPUTS_TOOLS_PATH}", | |
| "GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST": "\${GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST}", | |
| "GH_AW_PR_HEAD_BASE_BRANCH": "\${GH_AW_PR_HEAD_BASE_BRANCH}", | |
| "GH_AW_PR_HEAD_BASE_SHA": "\${GH_AW_PR_HEAD_BASE_SHA}", | |
| "GH_AW_PR_HEAD_BASE_REPO": "\${GH_AW_PR_HEAD_BASE_REPO}", | |
| "GH_AW_PR_HEAD_BASE_PR_NUMBER": "\${GH_AW_PR_HEAD_BASE_PR_NUMBER}", | |
| "GH_AW_PR_HEAD_BASE_REF": "\${GH_AW_PR_HEAD_BASE_REF}", | |
| "GH_AW_PR_HEAD_REPO": "\${GH_AW_PR_HEAD_REPO}", | |
| "GITHUB_EVENT_NAME": "\${GITHUB_EVENT_NAME}", | |
| "GITHUB_EVENT_PATH": "\${GITHUB_EVENT_PATH}", | |
| "GITHUB_REPOSITORY": "\${GITHUB_REPOSITORY}", | |
| "GITHUB_SHA": "\${GITHUB_SHA}", | |
| "GITHUB_TOKEN": "\${GITHUB_TOKEN}", | |
| "GITHUB_WORKSPACE": "\${GITHUB_WORKSPACE}", | |
| "RUNNER_TEMP": "\${RUNNER_TEMP}" | |
| }, | |
| "guard-policies": { | |
| "write-sink": { | |
| "accept": [ | |
| "*" | |
| ], | |
| "sink-visibility": "${GH_AW_SINK_VISIBILITY}" | |
| } | |
| } | |
| } | |
| }, | |
| "gateway": { | |
| "port": $MCP_GATEWAY_PORT, | |
| "domain": "${MCP_GATEWAY_DOMAIN}", | |
| "agentId": "${MCP_GATEWAY_AGENT_ID}", | |
| "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}", | |
| "startupTimeout": 120, | |
| "opentelemetry": { | |
| "endpoint": "${OTEL_EXPORTER_OTLP_ENDPOINT}", | |
| "traceId": "${GITHUB_AW_OTEL_TRACE_ID}", | |
| "spanId": "${GITHUB_AW_OTEL_PARENT_SPAN_ID}" | |
| } | |
| } | |
| } | |
| GH_AW_MCP_CONFIG_dbcafd561cd90286_EOF | |
| - name: Mount MCP servers as CLIs | |
| id: mount-mcp-clis | |
| continue-on-error: true | |
| env: | |
| MCP_GATEWAY_AGENT_ID: ${{ steps.start-mcp-gateway.outputs.gateway-agent-id }} | |
| MCP_GATEWAY_DOMAIN: ${{ steps.start-mcp-gateway.outputs.gateway-domain }} | |
| MCP_GATEWAY_PORT: ${{ steps.start-mcp-gateway.outputs.gateway-port }} | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io); | |
| const { main } = require(path.join(actionsDir, 'mount_mcp_as_cli.cjs')); | |
| await main(); | |
| - name: Clean credentials | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/clean_git_credentials.sh" | |
| bash "${RUNNER_TEMP}/gh-aw/actions/verify_git_credentials.sh" | |
| - name: Audit pre-agent workspace | |
| id: pre_agent_audit | |
| continue-on-error: true | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" | |
| - name: Start CLI Proxy | |
| env: | |
| GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_API_URL: ${{ github.api_url }} | |
| GH_HOST: ${{ env.GH_HOST }} | |
| GITHUB_HOST: ${{ env.GITHUB_HOST }} | |
| GITHUB_ENTERPRISE_HOST: ${{ env.GITHUB_ENTERPRISE_HOST }} | |
| GITHUB_GRAPHQL_URL: ${{ env.GITHUB_GRAPHQL_URL }} | |
| GITHUB_COPILOT_BASE_URL: ${{ env.GITHUB_COPILOT_BASE_URL }} | |
| GH_AW_NETWORK_ISOLATION: 'true' | |
| CLI_PROXY_POLICY: '{"allow-only":{"min-integrity":"none","repos":"${{ steps.determine-automatic-lockdown.outputs.repos }}"}}' | |
| CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.30' | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" | |
| - name: Execute Pi CLI | |
| id: agentic_execution | |
| timeout-minutes: 15 | |
| run: | | |
| set -o pipefail | |
| gh_aw_exit_code=0 | |
| trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT | |
| printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt | |
| touch /tmp/gh-aw/agent-step-summary.md | |
| GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) | |
| export GH_AW_NODE_BIN | |
| (umask 177 && touch /tmp/gh-aw/agent-stdio.log) | |
| GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" | |
| if [[ ! "$GH_AW_MAX_AI_CREDITS" =~ ^[0-9]+$ ]]; then | |
| GH_AW_MAX_AI_CREDITS="1000" | |
| fi | |
| printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.50/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.grafana.net\",\"*.sentry.io\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"ppa.launchpad.net\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\",\"www.googleapis.com\"],\"isolation\":true,\"topologyAttach\":[\"awmg-mcpg\",\"awmg-cli-proxy\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"providers\":{\"github-copilot\":{\"models\":{\"claude-haiku-4.5\":{\"cost\":{\"cache_read\":\"1.0000000000000001e-07\",\"cache_write\":\"1.25e-06\",\"input\":\"1e-06\",\"output\":\"5e-06\"}}}}},\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.50,squid=sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9,agent=sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620,api-proxy=sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965,cli-proxy=sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" | |
| cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json | |
| export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" | |
| GH_AW_DOCKER_HOST="" | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| GH_AW_DOCKER_HOST="${DOCKER_HOST}" | |
| fi | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| GH_AW_CHROOT_BINARIES_SOURCE_PATH="${RUNNER_TEMP}/gh-aw" GH_AW_CHROOT_IDENTITY_HOME="${RUNNER_TEMP}/gh-aw/home" node "${RUNNER_TEMP}/gh-aw/actions/patch_awf_chroot_config.cjs" | |
| fi | |
| GH_AW_TOOL_CACHE_MOUNT="" | |
| GH_AW_TOOL_CACHE="${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}" | |
| if [ -d "$GH_AW_TOOL_CACHE" ]; then | |
| if [[ "$GH_AW_TOOL_CACHE" != /opt/* ]]; then | |
| GH_AW_TOOL_CACHE_MOUNT="$GH_AW_TOOL_CACHE:$GH_AW_TOOL_CACHE:ro" | |
| fi | |
| fi | |
| # shellcheck disable=SC1003,SC2016,SC2086 | |
| mkdir -p "/tmp/gh-aw" | |
| evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" | |
| printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" | |
| export GH_AW_AWF_EXECUTION_COMPONENT="agent" | |
| export GH_AW_AWF_EXECUTION_EVIDENCE_FILE="/tmp/gh-aw/agent_execution.json" | |
| GH_AW_AWF_ENGINE_NAME=pi \ | |
| GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ | |
| GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ | |
| GH_AW_AWF_ATTEMPT_LOG_NAME=pi \ | |
| bash "${RUNNER_TEMP}/gh-aw/actions/run_awf_with_startup_retries.sh" -- \ | |
| awf --config "${RUNNER_TEMP}/gh-aw/awf-config.json" --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" ${GH_AW_TOOL_CACHE_MOUNT:+--mount "$GH_AW_TOOL_CACHE_MOUNT"} ${GH_AW_DOCKER_HOST:+--docker-host "$GH_AW_DOCKER_HOST"} --env-all --exclude-env ACTIONS_ID_TOKEN_REQUEST_TOKEN --exclude-env ACTIONS_ID_TOKEN_REQUEST_URL --exclude-env AI_GATEWAY_API_KEY --exclude-env ANTHROPIC_API_KEY --exclude-env ANTHROPIC_AUTH_TOKEN --exclude-env ANTHROPIC_OAUTH_TOKEN --exclude-env AWS_ACCESS_KEY_ID --exclude-env AWS_BEARER_TOKEN_BEDROCK --exclude-env AWS_SECRET_ACCESS_KEY --exclude-env AWS_SESSION_TOKEN --exclude-env AZURE_OPENAI_API_KEY --exclude-env BASETEN_API_KEY --exclude-env CEREBRAS_API_KEY --exclude-env CODEX_API_KEY --exclude-env COPILOT_GITHUB_TOKEN --exclude-env DEEPSEEK_API_KEY --exclude-env FIREWORKS_API_KEY --exclude-env GEMINI_API_KEY --exclude-env GH_AW_OTLP_ENDPOINTS --exclude-env GH_TOKEN --exclude-env GITHUB_MCP_SERVER_TOKEN --exclude-env GOOGLE_CLOUD_API_KEY --exclude-env GROQ_API_KEY --exclude-env HF_TOKEN --exclude-env KIMI_API_KEY --exclude-env MCP_GATEWAY_AGENT_ID --exclude-env MINIMAX_API_KEY --exclude-env MISTRAL_API_KEY --exclude-env NVIDIA_API_KEY --exclude-env OPENAI_API_KEY --exclude-env OPENCODE_API_KEY --exclude-env OPENROUTER_API_KEY --exclude-env OTEL_EXPORTER_OTLP_ENDPOINT --exclude-env OTEL_EXPORTER_OTLP_HEADERS --exclude-env RADIUS_API_KEY --exclude-env TOGETHER_API_KEY --exclude-env TYPESAFE_API_KEY --exclude-env XAI_API_KEY --mount /tmp/gh-aw:/tmp/gh-aw:rw --log-level info --skip-pull --difc-proxy-host awmg-cli-proxy:18443 --difc-proxy-ca-cert /tmp/gh-aw/difc-proxy-tls/ca.crt \ | |
| -- /bin/bash -c 'set +o histexpand; GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" ${RUNNER_TEMP}/gh-aw/actions/shell_harness.cjs pi '\''export PATH="${RUNNER_TEMP}/gh-aw/mcp-cli/bin:$PATH" && : "${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}"; GH_AW_TOOL_CACHE="$RUNNER_TOOL_CACHE"; GH_AW_TOOL_BINS="$(find "$GH_AW_TOOL_CACHE" -maxdepth 5 -type d -name bin 2>/dev/null | tr "\n" ":")"; GH_AW_TOOL_BINS="${GH_AW_TOOL_BINS%:}"; export PATH="$PATH${GH_AW_TOOL_BINS:+:}$GH_AW_TOOL_BINS"; [ -n "$GOROOT" ] && export PATH="$GOROOT/bin:$PATH" || true; [ -n "$ERLANG_HOME" ] && export PATH="$ERLANG_HOME/bin:$PATH" || true && cd "${GITHUB_WORKSPACE}" && GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" "${RUNNER_TEMP}/gh-aw/actions/pi_runtime.cjs" && export GH_AW_PI_MODEL_ID=claude-haiku-4.5 && export GH_AW_PI_GATEWAY_SECRET_ENV=COPILOT_GITHUB_TOKEN GH_AW_PI_GATEWAY_FALLBACK_PORT=10002 GH_AW_LLM_PROVIDER=github && ( GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" "${RUNNER_TEMP}/gh-aw/actions/pi_models_json.cjs" ) && cat /tmp/gh-aw/aw-prompts/user.txt | pi --print --mode json --no-session --no-approve --model aw-gateway/claude-haiku-4.5 --append-system-prompt /tmp/gh-aw/aw-prompts/system.txt --extension "${RUNNER_TEMP}/gh-aw/actions/pi_provider.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_steering_extension.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_tool_policy.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_subagent_extension.cjs" --extension builtin:mcp --extension builtin:codemode --extension builtin:tool-search 2>&1 | tee /tmp/gh-aw/pi-streaming.jsonl'\''' | |
| env: | |
| AWF_REFLECT_ENABLED: 1 | |
| COPILOT_GITHUB_TOKEN: ${{ github.token }} | |
| GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_MAX_AI_CREDITS || '1000' }} | |
| GH_AW_MAX_TURNS: ${{ vars.GH_AW_DEFAULT_MAX_TURNS || '' }} | |
| GH_AW_PHASE: agent | |
| GH_AW_PI_BARE: false | |
| GH_AW_PI_CONFIG: '{}' | |
| GH_AW_PI_MODEL: copilot/claude-haiku-4.5 | |
| GH_AW_PI_MODEL_ALIASES: '{"agent":["sonnet-6x","gpt-6","gpt-5.4","gpt-5.5","gpt-5.6","gpt-5.3","gemini-pro","any"],"antigravity":["copilot/antigravity*","google/antigravity*","gemini/antigravity*"],"any":["copilot/*","anthropic/*","openai/*","google/*","gemini/*"],"auto":["copilot/auto","large"],"claude":["agent"],"codex":["agent"],"coding":["copilot/gpt-5*codex*","openai/gpt-5*codex*","gpt-5-codex","kimi"],"computer-use":["copilot/*computer-use*","google/*computer-use*","gemini/*computer-use*","openai/*computer-use*"],"copilot":["agent"],"deep-research":["copilot/deep-research*","copilot/o3-deep-research*","copilot/o4-mini-deep-research*","google/deep-research*","gemini/deep-research*","openai/o3-deep-research*","openai/o4-mini-deep-research*"],"detection":["small"],"evals":["small"],"fable":["copilot/*fable*","anthropic/*fable*"],"gemini":["agent"],"gemini-3-flash":["copilot/gemini-3*flash*","google/gemini-3*flash*","gemini/gemini-3*flash*"],"gemini-3-pro":["copilot/gemini-3*pro*","google/gemini-3*pro*","google/nano-banana*","gemini/gemini-3*pro*"],"gemini-3.1-flash":["copilot/gemini-3.1*flash*","google/gemini-3.1*flash*","gemini/gemini-3.1*flash*"],"gemini-3.1-pro":["copilot/gemini-3.1*pro*","google/gemini-3.1*pro*","gemini/gemini-3.1*pro*"],"gemini-3.5-flash":["copilot/gemini-3.5*flash*","google/gemini-3.5*flash*","gemini/gemini-3.5*flash*"],"gemini-3.6-flash":["copilot/gemini-3.6*flash*","google/gemini-3.6*flash*","gemini/gemini-3.6*flash*"],"gemini-3.7-flash":["copilot/gemini-3.7*flash*","google/gemini-3.7*flash*","gemini/gemini-3.7*flash*"],"gemini-3.8-flash":["copilot/gemini-3.8*flash*","google/gemini-3.8*flash*","gemini/gemini-3.8*flash*"],"gemini-flash":["copilot/gemini-*flash*","google/gemini-*flash*","gemini/gemini-*flash*"],"gemini-flash-lite":["copilot/gemini-*flash*lite*","google/gemini-*flash*lite*","gemini/gemini-*flash*lite*"],"gemini-omni":["copilot/gemini-omni*","google/gemini-omni*","gemini/gemini-omni*"],"gemini-pro":["copilot/gemini-*pro*","google/gemini-*pro*","gemini/gemini-*pro*"],"gemma":["copilot/gemma*","google/gemma*","gemini/gemma*"],"gpt-5":["copilot/gpt-5*","openai/gpt-5*"],"gpt-5-codex":["copilot/gpt-5*codex*","openai/gpt-5*codex*"],"gpt-5-mini":["copilot/gpt-5*mini*","openai/gpt-5*mini*"],"gpt-5-nano":["copilot/gpt-5*nano*","openai/gpt-5*nano*"],"gpt-5-pro":["copilot/gpt-5*pro*","openai/gpt-5*pro*"],"gpt-5.1":["copilot/gpt-5.1*","openai/gpt-5.1*"],"gpt-5.2":["copilot/gpt-5.2*","openai/gpt-5.2*"],"gpt-5.3":["copilot/gpt-5.3*","openai/gpt-5.3*"],"gpt-5.4":["copilot/gpt-5.4*","openai/gpt-5.4*"],"gpt-5.5":["copilot/gpt-5.5*","openai/gpt-5.5*"],"gpt-5.6":["copilot/gpt-5.6*","openai/gpt-5.6*"],"gpt-6":["copilot/gpt-6*","openai/gpt-6*"],"grok":["copilot/*grok*","openai/*grok*"],"haiku":["copilot/*haiku*","anthropic/*haiku*"],"image-generation":["copilot/gpt-image*","openai/gpt-image*","openai/chatgpt-image*","copilot/gemini-*image*","google/gemini-*image*","gemini/gemini-*image*","google/imagen*"],"kimi":["copilot/kimi*","openai/kimi*"],"kiwi":["copilot/kiwi*","openai/kiwi*"],"large":["sonnet","gpt-6","gpt-5-pro","gpt-5","gemini-pro"],"lyria":["google/lyria*","gemini/lyria*","copilot/lyria*"],"mai-code":["copilot/MAI-Code*","copilot/mai-code*","openai/MAI-Code*"],"mai-code-1-flash-picker":["copilot/MAI-Code-1-Flash-picker*","copilot/mai-code-1-flash-picker*","openai/MAI-Code-1-Flash-picker*"],"mini":["haiku","gpt-5-mini","gpt-5-nano","gemini-flash-lite"],"nano-banana":["copilot/nano-banana*","google/nano-banana*","gemini/nano-banana*"],"opus":["copilot/*opus*","anthropic/*opus*"],"opusplan":["opus?effort=high"],"raptor-mini":["copilot/raptor*","openai/raptor*"],"reasoning":["copilot/o1*","copilot/o3*","copilot/o4*","openai/o1*","openai/o3*","openai/o4*"],"robotics":["copilot/*robotics*","google/*robotics*","gemini/*robotics*"],"small":["mini"],"small-agent":["haiku","gpt-5-mini","gemini-flash"],"sonnet":["copilot/*sonnet*","anthropic/*sonnet*"],"sonnet-6x":["copilot/*sonnet-4.5*","copilot/*sonnet-4.6*","copilot/*sonnet-5*","copilot/*sonnet-4-5-*","anthropic/*sonnet-4-5-*","copilot/*sonnet-4-6*","anthropic/*sonnet-4-6*","anthropic/*sonnet-5*"],"summarization":["haiku","gpt-5-mini","gemini-flash-lite","mini"],"veo":["google/veo*","gemini/veo*"],"vision":["copilot/gemini-*image*","google/gemini-*image*","gemini/gemini-*image*","copilot/gemini-*flash*","google/gemini-*flash*","gemini/gemini-*flash*"]}' | |
| GH_AW_PI_NATIVE_PROVIDER: github-copilot | |
| GH_AW_PI_SUBAGENT_ARGS: '["--print","--mode","json","--no-session","--no-approve"]' | |
| GH_AW_PI_SYSTEM_PROMPT: /tmp/gh-aw/aw-prompts/system.txt | |
| GH_AW_PI_TOOL_BUDGET_DIR: /tmp/gh-aw/pi-agent-dir/tool-budget | |
| GH_AW_PI_TOOL_POLICY: '{"bash":["echo","printf","ls","pwd","cat","head","tail","grep","wc","sort","uniq","date","yq","*"],"edit":true}' | |
| GH_AW_PI_USER_PROMPT: /tmp/gh-aw/aw-prompts/user.txt | |
| GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} | |
| GH_AW_TIMEOUT_MINUTES: 15 | |
| GH_AW_VERSION: dev | |
| GH_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN || github.token }} | |
| GITHUB_AW: true | |
| GITHUB_STEP_SUMMARY: /tmp/gh-aw/agent-step-summary.md | |
| GITHUB_WORKSPACE: ${{ github.workspace }} | |
| GIT_AUTHOR_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_AUTHOR_NAME: github-actions[bot] | |
| GIT_COMMITTER_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_COMMITTER_NAME: github-actions[bot] | |
| PI_CODING_AGENT_DIR: /tmp/gh-aw/pi-agent-dir | |
| PI_OFFLINE: 1 | |
| RUNNER_TEMP: ${{ runner.temp }} | |
| TRACEPARENT: ${{ env.GITHUB_AW_OTEL_TRACE_ID != '' && env.GITHUB_AW_OTEL_PARENT_SPAN_ID != '' && format('00-{0}-{1}-01', env.GITHUB_AW_OTEL_TRACE_ID, env.GITHUB_AW_OTEL_PARENT_SPAN_ID) || '' }} | |
| - name: Stop CLI Proxy | |
| if: always() | |
| continue-on-error: true | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/stop_cli_proxy.sh" | |
| - name: Configure Git credentials | |
| env: | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh" | |
| - name: Stop MCP Gateway | |
| if: always() | |
| continue-on-error: true | |
| env: | |
| MCP_GATEWAY_PORT: ${{ steps.start-mcp-gateway.outputs.gateway-port }} | |
| MCP_GATEWAY_AGENT_ID: ${{ steps.start-mcp-gateway.outputs.gateway-agent-id }} | |
| GATEWAY_PID: ${{ steps.start-mcp-gateway.outputs.gateway-pid }} | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/stop_mcp_gateway.sh" "$GATEWAY_PID" | |
| - name: Redact secrets in logs | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'redact_secrets.cjs')); | |
| await main(); | |
| env: | |
| GH_AW_SECRET_NAMES: 'AWI_MAINTENANCE_TOKEN,GH_AW_GITHUB_MCP_SERVER_TOKEN,GH_AW_GITHUB_TOKEN,GITHUB_TOKEN' | |
| SECRET_AWI_MAINTENANCE_TOKEN: ${{ secrets.AWI_MAINTENANCE_TOKEN }} | |
| SECRET_GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }} | |
| SECRET_GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }} | |
| SECRET_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Append agent step summary | |
| if: always() | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/append_agent_step_summary.sh" | |
| - name: Copy Safe Outputs | |
| if: always() | |
| env: | |
| GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} | |
| run: | | |
| mkdir -p /tmp/gh-aw | |
| cp "$GH_AW_SAFE_OUTPUTS" /tmp/gh-aw/safeoutputs.jsonl 2>/dev/null || true | |
| - name: Ingest agent output | |
| id: collect_output | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} | |
| GH_AW_ALLOWED_DOMAINS: "*.grafana.net,*.sentry.io,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,s.symcb.com,s.symcd.com,security.ubuntu.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_API_URL: ${{ github.api_url }} | |
| GH_AW_COMMANDS: "[\"souschef\"]" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'collect_ndjson_output.cjs')); | |
| await main(); | |
| - name: Parse agent logs for step summary | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: /tmp/gh-aw/pi-streaming.jsonl | |
| GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'parse_pi_log.cjs')); | |
| await main(); | |
| - name: Parse MCP Gateway logs for step summary | |
| if: always() | |
| id: parse-mcp-gateway | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'parse_mcp_gateway_log.cjs')); | |
| await main(); | |
| - name: Print firewall logs | |
| if: always() | |
| continue-on-error: true | |
| env: | |
| AWF_LOGS_DIR: /tmp/gh-aw/sandbox/firewall/logs | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/print_firewall_logs.sh" --rootless | |
| - name: Parse token usage for step summary | |
| if: always() | |
| id: parse-token-usage | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); | |
| await main(); | |
| - name: Print AWF reflect summary | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'awf_reflect_summary.cjs')); | |
| await main(); | |
| - name: Generate observability summary | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'generate_observability_summary.cjs')); | |
| await main(core); | |
| - name: Run graders | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'trace_graders.cjs')); | |
| await main('eyJ2ZXJzaW9uIjoxLCJncmFkZXJzIjpbeyJpZCI6InRvb2wtc3VjY2Vzcy1yYXRlIiwibmFtZSI6IlRvb2wgU3VjY2VzcyBSYXRlIiwiZGVzY3JpcHRpb24iOiJGcmFjdGlvbiBvZiB0b29sIGNhbGxzIHRoYXQgc3VjY2VlZGVkIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6ImhpZ2hlcl9pc19iZXR0ZXIiLCJ0aHJlc2hvbGQiOjAuOCwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJ0b29sLWZhaWx1cmUtY291bnQiLCJuYW1lIjoiVG9vbCBGYWlsdXJlIENvdW50IiwiZGVzY3JpcHRpb24iOiJOdW1iZXIgb2YgdG9vbCBjYWxscyB0aGF0IGZhaWxlZCIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoiY291bnQiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJ0aHJlc2hvbGQiOjV9LHsiaWQiOiJyZXRyaWVzIiwibmFtZSI6IlJldHJpZXMiLCJkZXNjcmlwdGlvbiI6Ik51bWJlciBvZiByZXRyeSBldmVudHMgZGV0ZWN0ZWQgaW4gZ2F0ZXdheSBsb2dzIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJjb3VudCIsImRpcmVjdGlvbiI6Imxvd2VyX2lzX2JldHRlciIsInRocmVzaG9sZCI6MTB9LHsiaWQiOiJsb29wcyIsIm5hbWUiOiJMb29wcyIsImRlc2NyaXB0aW9uIjoiQ29uc2VjdXRpdmUgaWRlbnRpY2FsIHRvb2wgY2FsbHMgKHNhbWUgbmFtZSBhbmQgYXJndW1lbnRzKSIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoiY291bnQiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJ0aHJlc2hvbGQiOjN9LHsiaWQiOiJ0cmFqZWN0b3J5LWVmZmljaWVuY3kiLCJuYW1lIjoiVHJhamVjdG9yeSBFZmZpY2llbmN5IiwiZGVzY3JpcHRpb24iOiJSYXRpbyBvZiB1bmlxdWUgdG9vbCBuYW1lcyB0byB0b3RhbCB0b29sIGNhbGxzIChoaWdoZXIgPSBtb3JlIGRpdmVyc2UgdXNhZ2UpIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6ImhpZ2hlcl9pc19iZXR0ZXIiLCJtYXgiOjEsIm1pbiI6MH0seyJpZCI6ImV4ZWN1dGlvbi1zdGVwLWNvdW50IiwibmFtZSI6IkV4ZWN1dGlvbiBTdGVwIENvdW50IiwiZGVzY3JpcHRpb24iOiJUb3RhbCBMTE0gcmVxdWVzdCBjb3VudCIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoiY291bnQiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIifSx7ImlkIjoiZXhlY3V0aW9uLWR1cmF0aW9uIiwibmFtZSI6IkV4ZWN1dGlvbiBEdXJhdGlvbiIsImRlc2NyaXB0aW9uIjoiVG90YWwgZXhlY3V0aW9uIGR1cmF0aW9uIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJtcyIsImRpcmVjdGlvbiI6Imxvd2VyX2lzX2JldHRlciJ9LHsiaWQiOiJ3b3JraW5nLXNldC1yZWJ1aWxkLWZhY3RvciIsIm5hbWUiOiJXb3JraW5nLVNldCBSZWJ1aWxkIEZhY3RvciIsImRlc2NyaXB0aW9uIjoiQ3VtdWxhdGl2ZSBpbnB1dCB0b2tlbnMgZGl2aWRlZCBieSBwZWFrIGludm9jYXRpb24gaW5wdXQgdG9rZW5zIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJmYWN0b3IiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJtaW4iOjF9LHsiaWQiOiJjb250ZXh0LWdyb3d0aCIsIm5hbWUiOiJDb250ZXh0IEdyb3d0aCIsImRlc2NyaXB0aW9uIjoiUmF0aW8gb2YgdG90YWwgdG9rZW5zIHRvIGZpcnN0LXJlcXVlc3QgdG9rZW5zIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJmYWN0b3IiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIifSx7ImlkIjoiYXJ0aWZhY3QtcHJvZHVjdGlvbiIsIm5hbWUiOiJBcnRpZmFjdCBQcm9kdWN0aW9uIiwiZGVzY3JpcHRpb24iOiJDb3VudCBvZiBvdXRwdXRzL2FydGlmYWN0cyBwcm9kdWNlZCBieSB0aGUgYWdlbnQiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6ImNvdW50IiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciJ9LHsiaWQiOiJwb2xpY3ktbmVhci1taXNzIiwibmFtZSI6IlBvbGljeSBOZWFyLU1pc3MgUmF0ZSIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2Ygc3VjY2Vzc2Z1bCB0cmFjZXMgdGhhdCBsZWZ0IGd1YXJkIG9yIHBvbGljeSBvYmplY3RpdmVzIHVuc2F0aXNmaWVkIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6Imxvd2VyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoic2tpbGwtY29uc3RyYWludC1jb3ZlcmFnZSIsIm5hbWUiOiJTa2lsbCBDb25zdHJhaW50IENvdmVyYWdlIiwiZGVzY3JpcHRpb24iOiJGcmFjdGlvbiBvZiBjb25maWd1cmVkIHNraWxsIGNvbnN0cmFpbnRzIHRoYXQgd2VyZSBleGVyY2lzZWQgYW5kIHBhc3NlZCIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJoaWdoZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJleHBsb3JhdGlvbi1lcnJvciIsIm5hbWUiOiJFeHBsb3JhdGlvbiBFcnJvciIsImRlc2NyaXB0aW9uIjoiVW5tZXQgb2JqZWN0aXZlcyBhdHRyaWJ1dGFibGUgdG8gaW5zdWZmaWNpZW50IHNlYXJjaCIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJtYXgiOjEsIm1pbiI6MH0seyJpZCI6ImV4cGxvaXRhdGlvbi1lcnJvciIsIm5hbWUiOiJFeHBsb2l0YXRpb24gRXJyb3IiLCJkZXNjcmlwdGlvbiI6IlVubWV0IG9iamVjdGl2ZXMgYXR0cmlidXRhYmxlIHRvIGdhdGhlcmVkIGV2aWRlbmNlIHRoYXQgd2FzIG5ldmVyIHVzZWQiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoibG93ZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJzdGF0ZS1yZXZpc2l0LXByb2JhYmlsaXR5LXJlcCIsIm5hbWUiOiJTdGF0ZSBSZXZpc2l0IFByb2JhYmlsaXR5IFJFUCIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2YgY2Fub25pY2FsIHN0YXRlIHZpc2l0cyB0aGF0IHJldmlzaXQgYW4gYWxyZWFkeSB2aXNpdGVkIHN0YXRlIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6Imxvd2VyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoicmVjdXJyZW5jZS1kZXRlcm1pbmlzbSIsIm5hbWUiOiJSZWN1cnJlbmNlIERldGVybWluaXNtIChSUUEgREVUKSIsImRlc2NyaXB0aW9uIjoiUlFBIERFVDogZnJhY3Rpb24gb2YgcmVjdXJyZW50IHBvaW50cyBmb3JtaW5nIGRpYWdvbmFsIChyZXBlYXRlZC1zdWJzZXF1ZW5jZSkgbGluZXMiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoibG93ZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJyZWN1cnJlbmNlLWxhbWluYXJpdHkiLCJuYW1lIjoiUmVjdXJyZW5jZSBMYW1pbmFyaXR5IChSUUEgTEFNKSIsImRlc2NyaXB0aW9uIjoiUlFBIExBTTogZnJhY3Rpb24gb2YgcmVjdXJyZW50IHBvaW50cyBmb3JtaW5nIHZlcnRpY2FsIChzdGFnbmF0aW9uKSBsaW5lcyIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJtYXgiOjEsIm1pbiI6MH0seyJpZCI6InJlY3VycmVuY2UtdHJhcHBpbmctdGltZSIsIm5hbWUiOiJSZWN1cnJlbmNlIFRyYXBwaW5nIFRpbWUgKFJRQSBUVCkiLCJkZXNjcmlwdGlvbiI6IlJRQSBUVDogYXZlcmFnZSBsZW5ndGggb2YgdmVydGljYWwgcmVjdXJyZW5jZSBsaW5lcyIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0Ijoic3RlcHMiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJtaW4iOjB9LHsiaWQiOiJyZWN1cnJlbmNlLXJhdGUiLCJuYW1lIjoiUmVjdXJyZW5jZSBSYXRlIChSUUEgUlIpIiwiZGVzY3JpcHRpb24iOiJSUUEgUlI6IGRlbnNpdHkgb2YgcmVjdXJyZW50IHN0YXRlIHBhaXJzIGFjcm9zcyB0aGUgcnVuIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6Imxvd2VyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoiZXZlbnQtZW50cm9weS1yYXRlIiwibmFtZSI6IkV2ZW50IEVudHJvcHkgUmF0ZSIsImRlc2NyaXB0aW9uIjoiTm9ybWFsaXplZCBjb25kaXRpb25hbCBTaGFubm9uIGVudHJvcHkgcmF0ZSBvZiB0aGUgb3JkZXJlZCBldmVudCBzZXF1ZW5jZSIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJoaWdoZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJsZW1wZWwteml2LXRyYWplY3RvcnktY29tcGxleGl0eSIsIm5hbWUiOiJMZW1wZWwtWml2IFRyYWplY3RvcnkgQ29tcGxleGl0eSIsImRlc2NyaXB0aW9uIjoiTm9ybWFsaXplZCBMWjc2IGNvbXBsZXhpdHkgb2YgdGhlIGNhbm9uaWNhbCBldmVudCBzZXF1ZW5jZSIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJoaWdoZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJ0b29sLW91dHB1dC1jb25zdW1wdGlvbi1yYXRlIiwibmFtZSI6IlRvb2wgT3V0cHV0IENvbnN1bXB0aW9uIFJhdGUiLCJkZXNjcmlwdGlvbiI6IkZyYWN0aW9uIG9mIHRvb2wgb3V0cHV0cyByZWZlcmVuY2VkIGJ5IGEgbGF0ZXIgYWN0aW9uIiwic291cmNlIjoiYnVpbHRpbiIsImVuYWJsZWQiOnRydWUsInVuaXQiOiJyYXRpbyIsImRpcmVjdGlvbiI6ImhpZ2hlcl9pc19iZXR0ZXIiLCJtYXgiOjEsIm1pbiI6MH0seyJpZCI6ImVuZC10by1lbmQtbGluZWFnZS1jb21wbGV0ZW5lc3MiLCJuYW1lIjoiRW5kLXRvLUVuZCBMaW5lYWdlIENvbXBsZXRlbmVzcyIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2YgZmluYWwgb3V0cHV0cyB0cmFjZWFibGUgdG8gdG9vbCBvciBvYnNlcnZhdGlvbiBldmlkZW5jZSByb290cyIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJoaWdoZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJhY3Rpb24tcHJvdmVuYW5jZS1jb3ZlcmFnZSIsIm5hbWUiOiJBY3Rpb24gUHJvdmVuYW5jZSBDb3ZlcmFnZSIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2YgY29uc2VxdWVudGlhbCBhY3Rpb25zIHdpdGggYSBwcm92ZW5hbmNlIHBhdGggdG8gdG9vbCBvciBvYnNlcnZhdGlvbiBldmlkZW5jZSIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoicmF0aW8iLCJkaXJlY3Rpb24iOiJoaWdoZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJwcmVtYXR1cmUtdGVybWluYXRpb24tZ2FwIiwibmFtZSI6IlByZW1hdHVyZSBUZXJtaW5hdGlvbiBHYXAiLCJkZXNjcmlwdGlvbiI6IkRlY2xhcmVkIGNvbXBsZXRpb24gY29uZGl0aW9ucyBzdGlsbCB1bnNhdGlzZmllZCBhdCB0ZXJtaW5hdGlvbiIsInNvdXJjZSI6ImJ1aWx0aW4iLCJlbmFibGVkIjp0cnVlLCJ1bml0IjoiY291bnQiLCJkaXJlY3Rpb24iOiJsb3dlcl9pc19iZXR0ZXIiLCJtaW4iOjB9LHsiaWQiOiJldmlkZW5jZS1zYXR1cmF0aW9uLXN0b3BwaW5nLWxhZyIsIm5hbWUiOiJFdmlkZW5jZSBTYXR1cmF0aW9uIFN0b3BwaW5nIExhZyIsImRlc2NyaXB0aW9uIjoiRXZlbnRzIGVsYXBzZWQgYmV0d2VlbiBhbGwgb2JqZWN0aXZlcyBiZWluZyBzYXRpc2ZpZWQgYW5kIHRoZSBydW4gc3RvcHBpbmciLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6ImNvdW50IiwiZGlyZWN0aW9uIjoibG93ZXJfaXNfYmV0dGVyIiwibWluIjowfSx7ImlkIjoiZGVwZW5kZW5jeS1vcmRlci12aW9sYXRpb24tcmF0ZSIsIm5hbWUiOiJEZXBlbmRlbmN5IE9yZGVyIFZpb2xhdGlvbiBSYXRlIiwiZGVzY3JpcHRpb24iOiJGcmFjdGlvbiBvZiBkZXBlbmRlbnQgb2JqZWN0aXZlcyBzYXRpc2ZpZWQgYmVmb3JlIHRoZWlyIHByZXJlcXVpc2l0ZXMiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoibG93ZXJfaXNfYmV0dGVyIiwibWF4IjoxLCJtaW4iOjB9LHsiaWQiOiJvYmplY3RpdmUtY292ZXJhZ2UiLCJuYW1lIjoiT2JqZWN0aXZlIENvdmVyYWdlIiwiZGVzY3JpcHRpb24iOiJGcmFjdGlvbiBvZiBkZWNsYXJlZCBvYmplY3RpdmVzIHRoYXQgd2VyZSBjb21wbGV0ZWQiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoiZ3JvdW5kaW5nLWFjY3VyYWN5IiwibmFtZSI6Ikdyb3VuZGluZyBBY2N1cmFjeSIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2YgYWN0aW9ucyB0aGF0IHdlcmUgdmFsaWQgaW4gdGhlIHN0YXRlIGluIHdoaWNoIHRoZXkgd2VyZSBpc3N1ZWQiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoidG9vbC13aXNlLXNjb3JlIiwibmFtZSI6IlRvb2wtV2lzZSBTY29yZSIsImRlc2NyaXB0aW9uIjoiTG9uZ2VzdCBjb3JyZWN0IGV4ZWN1dGlvbiBwcmVmaXggYWdhaW5zdCBhIHJlZmVyZW5jZSB0cmFqZWN0b3J5LCB3aXRoIHBhcmFtZXRlciBjcmVkaXQiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoidHJhamVjdG9yeS1uZHR3IiwibmFtZSI6IlRyYWplY3RvcnkgbkRUVyIsImRlc2NyaXB0aW9uIjoiTm9ybWFsaXplZCBkeW5hbWljIHRpbWUgd2FycGluZyBzaW1pbGFyaXR5IHRvIGEgcmVmZXJlbmNlIHN0YXRlIHRyYWplY3RvcnkiLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfSx7ImlkIjoiY29kZS1zZWFyY2gtcmVjYWxsIiwibmFtZSI6IkNvZGUgU2VhcmNoIFJlY2FsbCIsImRlc2NyaXB0aW9uIjoiRnJhY3Rpb24gb2YgcmVmZXJlbmNlIHBhdGNoIGZpbGVzIGxvY2F0ZWQgZHVyaW5nIHRoZSBydW4iLCJzb3VyY2UiOiJidWlsdGluIiwiZW5hYmxlZCI6dHJ1ZSwidW5pdCI6InJhdGlvIiwiZGlyZWN0aW9uIjoiaGlnaGVyX2lzX2JldHRlciIsIm1heCI6MSwibWluIjowfV19', 'bnVsbA=='); | |
| - name: Redact grader outputs | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { redactFilesInDir } = require(path.join(actionsDir, 'redact_secrets.cjs')); | |
| await redactFilesInDir('/tmp/gh-aw/agent/graders'); | |
| env: | |
| GH_AW_SECRET_NAMES: 'AWI_MAINTENANCE_TOKEN,GH_AW_GITHUB_MCP_SERVER_TOKEN,GH_AW_GITHUB_TOKEN,GITHUB_TOKEN' | |
| SECRET_AWI_MAINTENANCE_TOKEN: ${{ secrets.AWI_MAINTENANCE_TOKEN }} | |
| SECRET_GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }} | |
| SECRET_GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }} | |
| SECRET_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Write agent output placeholder if missing | |
| if: always() | |
| run: | | |
| if [ ! -f /tmp/gh-aw/agent_output.json ]; then | |
| echo '{"items":[]}' > /tmp/gh-aw/agent_output.json | |
| fi | |
| # Small dedicated copy of the agent output so safe-output processing | |
| # survives a failed or timed-out upload of the larger agent artifact | |
| - name: Upload agent output fallback artifact | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: agent-output-fallback | |
| path: | | |
| /tmp/gh-aw/agent_output.json | |
| /tmp/gh-aw/safeoutputs.jsonl | |
| /tmp/gh-aw/agent_execution.json | |
| /tmp/gh-aw/agent_execution_exit_code.txt | |
| /tmp/gh-aw/agent_usage.jsonl | |
| /tmp/gh-aw/agent_usage.json | |
| /tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl | |
| /tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/model-routing.jsonl | |
| /tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl | |
| /tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/model-routing.jsonl | |
| /tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl | |
| /tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/model-routing.jsonl | |
| /tmp/gh-aw/agent/graders/grader_manifest.json | |
| /tmp/gh-aw/agent/graders/grader_payload.json | |
| /tmp/gh-aw/agent/graders/grader_results.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Upload agent artifacts | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: agent | |
| path: | | |
| /tmp/gh-aw/aw-prompts/prompt.txt | |
| /tmp/gh-aw/agent_execution.json | |
| /tmp/gh-aw/agent_execution_exit_code.txt | |
| /tmp/gh-aw/agent-session.jsonl | |
| /tmp/gh-aw/agent-errors.jsonl | |
| /tmp/gh-aw/aw-prompts/user.txt | |
| /tmp/gh-aw/aw-prompts/system.txt | |
| /tmp/gh-aw/pi-streaming.jsonl | |
| /tmp/gh-aw/agent/pi-sessions/*.jsonl | |
| /tmp/gh-aw/pi-agent-dir/session.html | |
| /tmp/gh-aw/redacted-urls.log | |
| /tmp/gh-aw/mcp-logs/ | |
| /tmp/gh-aw/proxy-logs/ | |
| !/tmp/gh-aw/proxy-logs/proxy-tls/ | |
| /tmp/gh-aw/agent_usage.json | |
| /tmp/gh-aw/agent-stdio.log | |
| /tmp/gh-aw/pre-agent-audit.txt | |
| /tmp/gh-aw/github_rate_limits.jsonl | |
| /tmp/gh-aw/otel.jsonl | |
| /tmp/gh-aw/otlp-export-errors.jsonl | |
| /tmp/gh-aw/agent/graders/grader_manifest.json | |
| /tmp/gh-aw/agent/graders/grader_payload.json | |
| /tmp/gh-aw/agent/graders/grader_results.json | |
| /tmp/gh-aw/safeoutputs.jsonl | |
| /tmp/gh-aw/agent_output.json | |
| /tmp/gh-aw/aw-*.patch | |
| /tmp/gh-aw/aw-*.bundle | |
| /tmp/gh-aw/awf-config.json | |
| /tmp/gh-aw/sandbox/firewall/logs/ | |
| /tmp/gh-aw/sandbox/firewall/audit/ | |
| /tmp/gh-aw/sandbox/firewall/awf-reflect.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| conclusion: | |
| name: conclusion | |
| needs: | |
| - activation | |
| - agent | |
| - detection | |
| - evals | |
| - prefilter | |
| - push_evals_state | |
| - safe_outputs | |
| if: > | |
| always() && (needs.agent.result != 'skipped' || needs.activation.outputs.lockdown_check_failed == 'true' || | |
| needs.activation.outputs.oauth_token_check_failed == 'true' || needs.activation.outputs.stale_lock_file_failed == 'true') | |
| runs-on: ubuntu-slim | |
| # Permissions for the conclusion job (workflow permissions default to none). | |
| permissions: | |
| actions: write | |
| issues: write | |
| pull-requests: write | |
| concurrency: | |
| group: "gh-aw-conclusion-pr-sous-chef" | |
| cancel-in-progress: false | |
| queue: max | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| outputs: | |
| incomplete_count: ${{ steps.report_incomplete.outputs.incomplete_count }} | |
| noop_message: ${{ steps.noop.outputs.noop_message }} | |
| tools_reported: ${{ steps.missing_tool.outputs.tools_reported }} | |
| total_count: ${{ steps.missing_tool.outputs.total_count }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Download agent output artifact | |
| id: download-agent-output | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: "{agent,agent-output-fallback}" | |
| merge-multiple: true | |
| path: /tmp/gh-aw/ | |
| - name: Setup agent output environment variable | |
| id: setup-agent-output-env | |
| if: steps.download-agent-output.outcome == 'success' | |
| run: | | |
| mkdir -p /tmp/gh-aw/ | |
| find "/tmp/gh-aw/" -type f -print | |
| if [ -f "/tmp/gh-aw/agent_output.json" ]; then | |
| echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Warn if threat detection produced no verdict | |
| if: always() && needs.detection.result != 'skipped' && (needs.detection.outputs.detection_reason == 'agent_failure' || needs.detection.outputs.detection_reason == 'parse_error' || needs.detection.outputs.detection_conclusion == '') | |
| run: echo "::warning::Threat detection produced no security verdict. Review the detection job logs before trusting the agent outputs." | |
| - name: Download detection artifact | |
| id: download-detection-artifact | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| name: detection | |
| path: /tmp/gh-aw/threat-detection/ | |
| - name: Download Safe Outputs Items Manifest | |
| id: download-safe-outputs-manifest | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: safe-outputs-items | |
| merge-multiple: true | |
| path: /tmp/gh-aw/ | |
| - name: Download evals artifact | |
| id: download-evals-artifact | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: evals | |
| merge-multiple: true | |
| path: /tmp/gh-aw/evals/ | |
| - name: Process no-op messages | |
| id: noop | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_NOOP_MAX: "2" | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_ENGINE_MODEL: "copilot/claude-haiku-4.5" | |
| GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} | |
| GH_AW_NOOP_REPORT_AS_ISSUE: "false" | |
| GH_AW_AIC: ${{ needs.agent.outputs.aic }} | |
| GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} | |
| GH_AW_EVALS_AIC: ${{ needs.evals.outputs.aic }} | |
| GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} | |
| GH_AW_WORKFLOW_ID: "pr-sous-chef" | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'handle_noop_message.cjs')); | |
| await main(); | |
| - name: Log detection run | |
| id: detection_runs | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} | |
| GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'handle_detection_runs.cjs')); | |
| await main(); | |
| - name: Record missing tool | |
| id: missing_tool | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_ENGINE_MODEL: "copilot/claude-haiku-4.5" | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'missing_tool.cjs')); | |
| await main(); | |
| - name: Record incomplete | |
| id: report_incomplete | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_ENGINE_MODEL: "copilot/claude-haiku-4.5" | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'report_incomplete_handler.cjs')); | |
| await main(); | |
| - name: Handle agent failure | |
| id: handle_agent_failure | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} | |
| GH_AW_WORKFLOW_ID: "pr-sous-chef" | |
| GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "12" | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_CHECKOUT_PR_SUCCESS: ${{ needs.agent.outputs.checkout_pr_success }} | |
| GH_AW_AI_CREDITS_RATE_LIMIT_ERROR: ${{ needs.agent.outputs.ai_credits_rate_limit_error || 'false' }} | |
| GH_AW_UNKNOWN_MODEL_AI_CREDITS: ${{ needs.agent.outputs.unknown_model_ai_credits || 'false' }} | |
| GH_AW_AIC: ${{ needs.agent.outputs.aic }} | |
| GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} | |
| GH_AW_EVALS_AIC: ${{ needs.evals.outputs.aic }} | |
| GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_MAX_AI_CREDITS || '1000' }} | |
| GH_AW_DEFAULT_CHECKOUT_USES_TRIGGER_REF: "true" | |
| GH_AW_LOCKDOWN_CHECK_FAILED: ${{ needs.activation.outputs.lockdown_check_failed }} | |
| GH_AW_OAUTH_TOKEN_CHECK_FAILED: ${{ needs.activation.outputs.oauth_token_check_failed }} | |
| GH_AW_STALE_LOCK_FILE_FAILED: ${{ needs.activation.outputs.stale_lock_file_failed }} | |
| GH_AW_SAFE_OUTPUT_MESSAGES: "{\"runStarted\":\"🍳 [{workflow_name}]({run_url}) is preparing PRs for maintainer investigation.\",\"runSuccess\":\"✅ [{workflow_name}]({run_url}) finished PR sous-chef nudges.\",\"runFailure\":\"⚠️ [{workflow_name}]({run_url}) {status} while preparing PRs.\"}" | |
| GH_AW_GROUP_REPORTS: "false" | |
| GH_AW_FAILURE_REPORT_AS_ISSUE: "true" | |
| GH_AW_MISSING_TOOL_REPORT_AS_FAILURE: "true" | |
| GH_AW_MISSING_DATA_REPORT_AS_FAILURE: "true" | |
| GH_AW_TIMEOUT_MINUTES: "15" | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'handle_agent_failure.cjs')); | |
| await main(); | |
| - name: Report failed jobs | |
| id: report_failed_jobs | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| GH_AW_JOB_RESULTS: ${{ toJSON(needs) }} | |
| GH_AW_JOB_DISPLAY_NAMES: "{\"activation\":\"Activation\",\"agent\":\"Agent\",\"check_token_telemetry\":\"Check token telemetry\",\"conclusion\":\"Conclusion\",\"detection\":\"Detection\",\"evals\":\"Evaluations\",\"pre_activation\":\"Pre-activation\",\"push_evals_state\":\"Push evaluations state\",\"push_experiments_state\":\"Push experiments state\",\"push_ledger_changes\":\"Push ledger changes\",\"push_repo_memory\":\"Push repository memory\",\"safe_outputs\":\"Safe outputs\",\"send_slack_message\":\"Send Slack message\",\"unlock\":\"Unlock\",\"update_cache_memory\":\"Update cache memory\",\"update_drive_memory\":\"Update drive memory\",\"upload_assets\":\"Upload assets\",\"upload_code_coverage\":\"Upload code coverage\",\"upload_code_scanning_sarif\":\"Upload code scanning results\"}" | |
| GH_AW_REPORT_FAILED_JOBS: "true" | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'report_failed_jobs.cjs')); | |
| await main(); | |
| - name: Update reaction comment with completion status | |
| id: conclusion | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_COMMENT_ID: ${{ needs.activation.outputs.comment_id }} | |
| GH_AW_COMMENT_REPO: ${{ needs.activation.outputs.comment_repo }} | |
| GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} | |
| GH_AW_SAFE_OUTPUTS_RESULT: ${{ needs.safe_outputs.result }} | |
| GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} | |
| GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} | |
| GH_AW_SAFE_OUTPUT_MESSAGES: "{\"runStarted\":\"🍳 [{workflow_name}]({run_url}) is preparing PRs for maintainer investigation.\",\"runSuccess\":\"✅ [{workflow_name}]({run_url}) finished PR sous-chef nudges.\",\"runFailure\":\"⚠️ [{workflow_name}]({run_url}) {status} while preparing PRs.\"}" | |
| with: | |
| github-token: ${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'notify_comment_error.cjs')); | |
| await main(); | |
| - name: Collect usage artifact files | |
| if: always() | |
| continue-on-error: true | |
| env: | |
| GH_AW_DETECTION_JOB_RESULT: ${{ needs.detection.result }} | |
| GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} | |
| GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/collect_usage_artifact_files.sh" | |
| - name: Generate usage activity summary and unified session | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_DAILY_AI_CREDITS_GUARDRAIL_STATUS: ${{ needs.activation.outputs.daily_ai_credits_guardrail_status }} | |
| GH_AW_DAILY_AI_CREDITS_EXCEEDED: ${{ needs.activation.outputs.daily_ai_credits_exceeded }} | |
| GH_AW_DAILY_AI_CREDITS_TOTAL: ${{ needs.activation.outputs.daily_ai_credits_total }} | |
| GH_AW_DAILY_AI_CREDITS_ESTIMATED: ${{ needs.activation.outputs.daily_ai_credits_estimated }} | |
| GH_AW_DAILY_AI_CREDITS_THRESHOLD: ${{ needs.activation.outputs.daily_ai_credits_threshold }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'generate_usage_artifacts.cjs')); | |
| await main(); | |
| - name: Upload usage artifact | |
| id: upload-usage-artifact | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: usage | |
| path: | | |
| /tmp/gh-aw/usage/aw_session.jsonl | |
| /tmp/gh-aw/usage/aw_info.json | |
| /tmp/gh-aw/usage/aw-info.jsonl | |
| /tmp/gh-aw/usage/agent_usage.json | |
| /tmp/gh-aw/usage/agent_usage.jsonl | |
| /tmp/gh-aw/usage/detection_usage.jsonl | |
| /tmp/gh-aw/usage/evals.jsonl | |
| /tmp/gh-aw/usage/graders/grader_manifest.json | |
| /tmp/gh-aw/usage/graders/grader_results.json | |
| /tmp/gh-aw/usage/github_rate_limits.jsonl | |
| /tmp/gh-aw/usage/agent/token_usage.jsonl | |
| /tmp/gh-aw/usage/agent/model-routing.jsonl | |
| /tmp/gh-aw/usage/agent/execution.json | |
| /tmp/gh-aw/usage/detection/token_usage.jsonl | |
| /tmp/gh-aw/usage/detection/execution.json | |
| /tmp/gh-aw/usage/detection/detection_result.json | |
| /tmp/gh-aw/usage/evals/token_usage.jsonl | |
| /tmp/gh-aw/usage/evals/execution.json | |
| /tmp/gh-aw/usage/experiment/state.jsonl | |
| /tmp/gh-aw/usage/experiment/state.json | |
| /tmp/gh-aw/usage/experiment/assignments.json | |
| /tmp/gh-aw/usage/activity/summary.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Wait before retrying usage artifact upload | |
| if: always() && steps.upload-usage-artifact.outcome == 'failure' | |
| run: sleep 10 | |
| - name: Retry upload usage artifact | |
| id: upload-usage-artifact-retry | |
| if: always() && steps.upload-usage-artifact.outcome == 'failure' | |
| continue-on-error: true | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: usage | |
| path: | | |
| /tmp/gh-aw/usage/aw_session.jsonl | |
| /tmp/gh-aw/usage/aw_info.json | |
| /tmp/gh-aw/usage/aw-info.jsonl | |
| /tmp/gh-aw/usage/agent_usage.json | |
| /tmp/gh-aw/usage/agent_usage.jsonl | |
| /tmp/gh-aw/usage/detection_usage.jsonl | |
| /tmp/gh-aw/usage/evals.jsonl | |
| /tmp/gh-aw/usage/graders/grader_manifest.json | |
| /tmp/gh-aw/usage/graders/grader_results.json | |
| /tmp/gh-aw/usage/github_rate_limits.jsonl | |
| /tmp/gh-aw/usage/agent/token_usage.jsonl | |
| /tmp/gh-aw/usage/agent/model-routing.jsonl | |
| /tmp/gh-aw/usage/agent/execution.json | |
| /tmp/gh-aw/usage/detection/token_usage.jsonl | |
| /tmp/gh-aw/usage/detection/execution.json | |
| /tmp/gh-aw/usage/detection/detection_result.json | |
| /tmp/gh-aw/usage/evals/token_usage.jsonl | |
| /tmp/gh-aw/usage/evals/execution.json | |
| /tmp/gh-aw/usage/experiment/state.jsonl | |
| /tmp/gh-aw/usage/experiment/state.json | |
| /tmp/gh-aw/usage/experiment/assignments.json | |
| /tmp/gh-aw/usage/activity/summary.json | |
| if-no-files-found: ignore | |
| overwrite: true | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| detection: | |
| name: detection | |
| needs: | |
| - activation | |
| - agent | |
| if: always() && needs.agent.result != 'skipped' | |
| runs-on: ubuntu-latest | |
| # Permissions for the detection job (workflow permissions default to none). | |
| permissions: | |
| contents: read | |
| copilot-requests: write | |
| timeout-minutes: 10 | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| outputs: | |
| aic: ${{ steps.parse_detection_token_usage.outputs.aic }} | |
| detection_conclusion: ${{ steps.detection_conclusion.outputs.conclusion }} | |
| detection_reason: ${{ steps.detection_conclusion.outputs.reason }} | |
| detection_success: ${{ steps.detection_conclusion.outputs.success }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Download activation artifact | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| name: activation | |
| path: /tmp/gh-aw | |
| - name: Download agent output artifact | |
| id: download-agent-output | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: "{agent,agent-output-fallback}" | |
| merge-multiple: true | |
| path: /tmp/gh-aw/ | |
| - name: Setup agent output environment variable | |
| id: setup-agent-output-env | |
| if: steps.download-agent-output.outcome == 'success' | |
| run: | | |
| mkdir -p /tmp/gh-aw/ | |
| find "/tmp/gh-aw/" -type f -print | |
| if [ -f "/tmp/gh-aw/agent_output.json" ]; then | |
| echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Checkout repository for patch context | |
| if: needs.agent.outputs.has_patch == 'true' | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # --- Threat Detection --- | |
| - name: Initialize detection execution evidence | |
| run: | | |
| mkdir -p "/tmp/gh-aw/threat-detection" | |
| evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" | |
| printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" | |
| - name: Clear inherited Copilot session state | |
| run: rm -rf /tmp/gh-aw/sandbox/agent/logs/copilot-session-state | |
| - name: Clean stale firewall files from agent artifact | |
| run: | | |
| rm -rf /tmp/gh-aw/sandbox/firewall/logs | |
| rm -rf /tmp/gh-aw/sandbox/firewall/audit | |
| - name: Download container images | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.50@sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50@sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50@sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce ghcr.io/github/gh-aw-firewall/squid:0.28.50@sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9 | |
| - name: Check if detection needed | |
| id: detection_guard | |
| if: always() | |
| env: | |
| OUTPUT_TYPES: ${{ needs.agent.outputs.output_types }} | |
| HAS_PATCH: ${{ needs.agent.outputs.has_patch }} | |
| run: | | |
| if [[ -n "$OUTPUT_TYPES" || "$HAS_PATCH" == "true" ]]; then | |
| echo "run_detection=true" >> "$GITHUB_OUTPUT" | |
| echo "Detection will run: output_types=$OUTPUT_TYPES, has_patch=$HAS_PATCH" | |
| else | |
| echo "run_detection=false" >> "$GITHUB_OUTPUT" | |
| echo "Detection skipped: no agent outputs or patches to analyze" | |
| fi | |
| - name: Clear MCP Config for detection | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| run: | | |
| rm -f "${RUNNER_TEMP}/gh-aw/mcp-config/mcp-servers.json" | |
| rm -f "$HOME/.copilot/mcp-config.json" | |
| rm -f "$GITHUB_WORKSPACE/.gemini/settings.json" | |
| - name: Prepare threat detection files | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/prepare_threat_detection_files.sh" | |
| - name: Setup threat detection | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| WORKFLOW_NAME: "PR Sous Chef" | |
| WORKFLOW_DESCRIPTION: "Nudges PRs idle for ten minutes with unanswered reviews and a branch update, without duplicate agent work" | |
| HAS_PATCH: ${{ needs.agent.outputs.has_patch }} | |
| GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" | |
| GH_AW_DETECTION_SKIP_PROMPT_SUMMARY: "true" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'setup_threat_detection.cjs')); | |
| await main(); | |
| - name: Ensure threat-detection directory and log | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| run: | | |
| mkdir -p /tmp/gh-aw/threat-detection | |
| touch /tmp/gh-aw/threat-detection/detection.log | |
| - name: Install AWF binary | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.28.50 --rootless | |
| - name: Setup Node.js | |
| uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 | |
| with: | |
| node-version: '24' | |
| package-manager-cache: false | |
| - name: Install GitHub Copilot CLI | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" | |
| env: | |
| GH_HOST: github.com | |
| GH_AW_COMPILED_VERSION: dev | |
| - name: Install threat-detect binary | |
| id: threat_detect_install | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| continue-on-error: true | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.2 --artifact-base-url https://github.com/github/gh-aw-threat-detection/releases/download --sha256-amd64 b4ecda6a8f1ee09913c40b58e5e9d3337d2173618d41b1bfdef9207e4e7959b9 --sha256-arm64 f6260a0f9ad72bcb67c7af19c4ce262ca34e2c3d5ccbf912832a8bd277200904 | |
| - name: Execute threat detection with AWF | |
| id: detection_agentic_execution | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' && steps.threat_detect_install.outcome == 'success' | |
| continue-on-error: true | |
| timeout-minutes: 10 | |
| env: | |
| AWF_REFLECT_ENABLED: 1 | |
| COPILOT_AGENT_RUNNER_TYPE: STANDALONE | |
| COPILOT_DUMMY_BYOK: dummy-byok-key-for-offline-mode | |
| COPILOT_GITHUB_TOKEN: ${{ github.token }} | |
| COPILOT_MODEL: claude-haiku-4.5 | |
| GH_AW_HARNESS_MAX_RETRIES: 0 | |
| GH_AW_LLM_PROVIDER: github | |
| GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_DETECTION_MAX_AI_CREDITS || '400' }} | |
| GH_AW_MAX_TURNS: ${{ vars.GH_AW_DEFAULT_MAX_TURNS || '' }} | |
| GH_AW_PHASE: detection | |
| GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_TIMEOUT_MINUTES: 10 | |
| GH_AW_VERSION: dev | |
| GITHUB_API_URL: ${{ github.api_url }} | |
| GITHUB_AW: true | |
| GITHUB_COPILOT_INTEGRATION_ID: agentic-workflows | |
| GITHUB_COPILOT_PROMPT_MODE_EXTENSIONS: false | |
| GITHUB_HEAD_REF: ${{ github.head_ref }} | |
| GITHUB_REF_NAME: ${{ github.ref_name }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_STEP_SUMMARY: /tmp/gh-aw/agent-step-summary.md | |
| GITHUB_WORKSPACE: ${{ github.workspace }} | |
| GIT_AUTHOR_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_AUTHOR_NAME: github-actions[bot] | |
| GIT_COMMITTER_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_COMMITTER_NAME: github-actions[bot] | |
| RUNNER_TEMP: ${{ runner.temp }} | |
| S2STOKENS: true | |
| TRACEPARENT: ${{ env.GITHUB_AW_OTEL_TRACE_ID != '' && env.GITHUB_AW_OTEL_PARENT_SPAN_ID != '' && format('00-{0}-{1}-01', env.GITHUB_AW_OTEL_TRACE_ID, env.GITHUB_AW_OTEL_PARENT_SPAN_ID) || '' }} | |
| WORKFLOW_NAME: "PR Sous Chef" | |
| WORKFLOW_DESCRIPTION: "Nudges PRs idle for ten minutes with unanswered reviews and a branch update, without duplicate agent work" | |
| HAS_PATCH: ${{ needs.agent.outputs.has_patch }} | |
| GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" | |
| run: | | |
| mkdir -p "/tmp/gh-aw/threat-detection" | |
| evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" | |
| printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" | |
| export GH_AW_AWF_EXECUTION_COMPONENT="detection" | |
| export GH_AW_AWF_EXECUTION_EVIDENCE_FILE="/tmp/gh-aw/threat-detection/execution.json" | |
| set -o pipefail | |
| printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt | |
| GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" | |
| if [ -z "$GH_AW_COPILOT_SRC" ] || [ ! -x "$GH_AW_COPILOT_SRC" ]; then | |
| echo "GitHub Copilot CLI executable not found on PATH after installation" >&2 | |
| exit 127 | |
| fi | |
| GH_AW_COPILOT_BIN="${RUNNER_TEMP}/gh-aw/bin/copilot" | |
| mkdir -p "${RUNNER_TEMP}/gh-aw/bin" | |
| if [ "$GH_AW_COPILOT_SRC" != "$GH_AW_COPILOT_BIN" ]; then | |
| cp "$GH_AW_COPILOT_SRC" "$GH_AW_COPILOT_BIN" | |
| fi | |
| chmod 755 "$GH_AW_COPILOT_BIN" | |
| (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) | |
| GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-400}" | |
| if [[ ! "$GH_AW_MAX_AI_CREDITS" =~ ^[0-9]+$ ]]; then | |
| GH_AW_MAX_AI_CREDITS="400" | |
| fi | |
| printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.50/awf-config.schema.json\",\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"providers\":{\"github-copilot\":{\"models\":{\"claude-haiku-4.5\":{\"cost\":{\"cache_read\":\"1.0000000000000001e-07\",\"cache_write\":\"1.25e-06\",\"input\":\"1e-06\",\"output\":\"5e-06\"}}}}},\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.50,squid=sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9,agent=sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620,api-proxy=sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965,cli-proxy=sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" | |
| cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json | |
| export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" | |
| GH_AW_DOCKER_HOST="" | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| GH_AW_DOCKER_HOST="${DOCKER_HOST}" | |
| fi | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| _GH_AW_CHROOT_JSON=$(jq -c --arg src "${RUNNER_TEMP}/gh-aw" --arg user "$(id -un)" --argjson uid "$(id -u)" --argjson gid "$(id -g)" --arg home "${RUNNER_TEMP}/gh-aw/home" '.chroot={"binariesSourcePath":$src,"identity":{"user":$user,"uid":$uid,"gid":$gid,"home":$home}}' "${RUNNER_TEMP}/gh-aw/awf-config.json") || { echo "chroot config patch failed" >&2; exit 1; } | |
| printf '%s\n' "$_GH_AW_CHROOT_JSON" > "${RUNNER_TEMP}/gh-aw/awf-config.json" | |
| fi | |
| GH_AW_TOOL_CACHE_MOUNT="" | |
| GH_AW_TOOL_CACHE="${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}" | |
| if [ -d "$GH_AW_TOOL_CACHE" ]; then | |
| if [[ "$GH_AW_TOOL_CACHE" != /opt/* ]]; then | |
| GH_AW_TOOL_CACHE_MOUNT="$GH_AW_TOOL_CACHE:$GH_AW_TOOL_CACHE:ro" | |
| fi | |
| fi | |
| # shellcheck disable=SC1003,SC2016,SC2086 | |
| awf --config "${RUNNER_TEMP}/gh-aw/awf-config.json" --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" ${GH_AW_TOOL_CACHE_MOUNT:+--mount "$GH_AW_TOOL_CACHE_MOUNT"} ${GH_AW_DOCKER_HOST:+--docker-host "$GH_AW_DOCKER_HOST"} --env-all --exclude-env ACTIONS_ID_TOKEN_REQUEST_TOKEN --exclude-env ACTIONS_ID_TOKEN_REQUEST_URL --exclude-env COPILOT_GITHUB_TOKEN --exclude-env GH_AW_OTLP_ENDPOINTS --exclude-env OTEL_EXPORTER_OTLP_ENDPOINT --exclude-env OTEL_EXPORTER_OTLP_HEADERS --mount /tmp/gh-aw:/tmp/gh-aw:rw --mount /tmp/gh-aw/threat-detection:/tmp/gh-aw/threat-detection:rw --log-level info --session-state-dir /tmp/gh-aw/sandbox/agent/session-state --skip-pull \ | |
| -- /bin/bash -c 'set +o histexpand; export PATH="${RUNNER_TEMP}/gh-aw/bin:$PATH" && : "${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}"; GH_AW_TOOL_CACHE="$RUNNER_TOOL_CACHE"; GH_AW_TOOL_BINS="$(find "$GH_AW_TOOL_CACHE" -maxdepth 5 -type d -name bin 2>/dev/null | tr "\n" ":")"; GH_AW_TOOL_BINS="${GH_AW_TOOL_BINS%:}"; export PATH="$PATH${GH_AW_TOOL_BINS:+:}$GH_AW_TOOL_BINS"; [ -n "$GOROOT" ] && export PATH="$GOROOT/bin:$PATH" || true; [ -n "$ERLANG_HOME" ] && export PATH="$ERLANG_HOME/bin:$PATH" || true && threat-detect --engine copilot --output /tmp/gh-aw/threat-detection/detection_result.json /tmp/gh-aw/threat-detection' 2>&1 | tee -a /tmp/gh-aw/threat-detection/detection.log | |
| - name: Render detection log | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'render_detection_log.cjs')); | |
| await main(); | |
| - name: Copy detection firewall logs | |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | |
| continue-on-error: true | |
| run: | | |
| mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall | |
| if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi | |
| if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi | |
| - name: Parse threat detection token usage for step summary | |
| id: parse_detection_token_usage | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_TOKEN_USAGE_SUMMARY_TITLE: Threat Detection Token Usage | |
| GH_AW_PHASE: detection | |
| GH_AW_AGENT_USAGE_PATH: /tmp/gh-aw/threat-detection/detection_usage.json | |
| GH_AW_AGENT_USAGE_JSONL_PATH: /tmp/gh-aw/threat-detection/detection_usage.jsonl | |
| GH_AW_WRITE_EMPTY_USAGE: "true" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); | |
| await main(); | |
| - name: Upload threat detection artifact | |
| if: always() | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: detection | |
| path: | | |
| /tmp/gh-aw/threat-detection/detection_result.json | |
| /tmp/gh-aw/threat-detection/execution.json | |
| /tmp/gh-aw/threat-detection/detection_usage.json | |
| /tmp/gh-aw/threat-detection/detection_usage.jsonl | |
| /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ | |
| /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Conclude threat detection | |
| id: detection_conclusion | |
| if: always() | |
| continue-on-error: true | |
| env: | |
| RUN_DETECTION: ${{ steps.detection_guard.outputs.run_detection }} | |
| DETECTION_AGENTIC_EXECUTION_OUTCOME: ${{ steps.detection_agentic_execution.outcome }} | |
| THREAT_DETECT_INSTALL_OUTCOME: ${{ steps.threat_detect_install.outcome }} | |
| GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" | |
| run: | | |
| bash "${RUNNER_TEMP}/gh-aw/actions/conclude_threat_detection.sh" /tmp/gh-aw/threat-detection/detection_result.json | |
| evals: | |
| name: evals | |
| needs: | |
| - activation | |
| - agent | |
| - detection | |
| if: always() && needs.agent.result == 'success' | |
| runs-on: ubuntu-latest | |
| # Permissions for the evals job (workflow permissions default to none). | |
| permissions: | |
| contents: read | |
| copilot-requests: write | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| outputs: | |
| aic: ${{ steps.parse-mcp-gateway.outputs.aic }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Download agent output artifact | |
| id: download-agent-output | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: "{agent,agent-output-fallback}" | |
| merge-multiple: true | |
| path: /tmp/gh-aw/ | |
| - name: Setup agent output environment variable | |
| id: setup-agent-output-env | |
| if: steps.download-agent-output.outcome == 'success' | |
| run: | | |
| mkdir -p /tmp/gh-aw/ | |
| find "/tmp/gh-aw/" -type f -print | |
| if [ -f "/tmp/gh-aw/agent_output.json" ]; then | |
| echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT" | |
| fi | |
| # --- BinEval Evaluations --- | |
| - name: Initialize evals execution evidence | |
| if: always() | |
| run: | | |
| mkdir -p "/tmp/gh-aw/evals" | |
| evidence_tmp="/tmp/gh-aw/evals/execution.json.tmp" | |
| printf '{"version":1,"component":"evals","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/evals/execution.json" | |
| - name: Clean stale firewall files from agent artifact | |
| run: | | |
| rm -rf /tmp/gh-aw/sandbox/firewall/logs | |
| rm -rf /tmp/gh-aw/sandbox/firewall/audit | |
| - name: Download container images | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.50@sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.50@sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.50@sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce ghcr.io/github/gh-aw-firewall/squid:0.28.50@sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9 | |
| - name: Prepare evals files | |
| run: | | |
| mkdir -p /tmp/gh-aw/evals | |
| cp /tmp/gh-aw/agent_output.json /tmp/gh-aw/evals/agent_output.json 2>/dev/null || true | |
| cp /tmp/gh-aw/aw-prompts/prompt.txt /tmp/gh-aw/evals/prompt.txt 2>/dev/null || true | |
| ls -la /tmp/gh-aw/evals/ 2>/dev/null || true | |
| - name: Setup BinEval evaluations | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_EVALS_QUESTIONS: '[{"id":"nudge-targeted","question":"Did every Copilot nudge list only unanswered review feedback or concrete blockers, request a branch update, and include its Sous-chef state fingerprint?"},{"id":"dedup-respected","question":"Did the agent avoid nudging PRs classified as unchanged, stale, dependency_bot, opted_out, agent_active, not_idle, approval_required, or nothing_actionable, and entries with nudge_needed false, repeating unchanged work only for behind or conflicting branches?"},{"id":"progress-or-noop","question":"Did the agent either perform a specific forward-progress action on an eligible PR or stop with an explicit no-op when none remained?"}]' | |
| GH_AW_EVALS_MODEL: "copilot/claude-haiku-4.5" | |
| GH_AW_EVALS_PHASE: setup | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'run_evals.cjs')); | |
| await main(); | |
| - name: Ensure evals directory and log | |
| run: | | |
| mkdir -p /tmp/gh-aw/evals | |
| touch /tmp/gh-aw/evals/evals.log | |
| - name: Setup Node.js | |
| uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 | |
| with: | |
| node-version: '24' | |
| package-manager-cache: false | |
| - name: Install AWF binary | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.28.50 --rootless | |
| - name: Install Pi CLI | |
| run: npm install --ignore-scripts -g @earendil-works/pi-coding-agent@1.0.0 | |
| - name: Record Pi package location | |
| run: | | |
| GH_AW_PI_PACKAGE_ROOT="$(npm root -g)/@earendil-works/pi-coding-agent" | |
| printf 'GH_AW_PI_PACKAGE_ROOT=%s\n' "$GH_AW_PI_PACKAGE_ROOT" >> "$GITHUB_ENV" | |
| - name: Execute Pi CLI | |
| if: always() | |
| continue-on-error: true | |
| id: evals_agentic_execution | |
| timeout-minutes: 15 | |
| run: | | |
| set -o pipefail | |
| gh_aw_exit_code=0 | |
| trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT | |
| printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt | |
| touch /tmp/gh-aw/agent-step-summary.md | |
| GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) | |
| export GH_AW_NODE_BIN | |
| (umask 177 && touch /tmp/gh-aw/evals/evals.log) | |
| GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-400}" | |
| if [[ ! "$GH_AW_MAX_AI_CREDITS" =~ ^[0-9]+$ ]]; then | |
| GH_AW_MAX_AI_CREDITS="400" | |
| fi | |
| printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.50/awf-config.schema.json\",\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"providers\":{\"github-copilot\":{\"models\":{\"claude-haiku-4.5\":{\"cost\":{\"cache_read\":\"1.0000000000000001e-07\",\"cache_write\":\"1.25e-06\",\"input\":\"1e-06\",\"output\":\"5e-06\"}}}}},\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.50,squid=sha256:cc9b6b979edf4aafbb3811c2bdc4891039d5346473afa88e304aa692167004f9,agent=sha256:91fe4af8373c723d4d2e0706a0c35d310c2eeadaea5e0738c725b3861042f620,api-proxy=sha256:11f12bcd3dde377ba822df7c670d6b937e9e0cebc46218946d4edc972d7fd965,cli-proxy=sha256:afa9c2c1ef66009ab88eee8af0dd43a31b6cc5a481a990d0b1b93ebda4f744ce\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" | |
| cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json | |
| export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" | |
| GH_AW_DOCKER_HOST="" | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| GH_AW_DOCKER_HOST="${DOCKER_HOST}" | |
| fi | |
| if [[ "${DOCKER_HOST:-}" =~ ^tcp:// ]]; then | |
| GH_AW_CHROOT_BINARIES_SOURCE_PATH="${RUNNER_TEMP}/gh-aw" GH_AW_CHROOT_IDENTITY_HOME="${RUNNER_TEMP}/gh-aw/home" node "${RUNNER_TEMP}/gh-aw/actions/patch_awf_chroot_config.cjs" | |
| fi | |
| GH_AW_TOOL_CACHE_MOUNT="" | |
| GH_AW_TOOL_CACHE="${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}" | |
| if [ -d "$GH_AW_TOOL_CACHE" ]; then | |
| if [[ "$GH_AW_TOOL_CACHE" != /opt/* ]]; then | |
| GH_AW_TOOL_CACHE_MOUNT="$GH_AW_TOOL_CACHE:$GH_AW_TOOL_CACHE:ro" | |
| fi | |
| fi | |
| # shellcheck disable=SC1003,SC2016,SC2086 | |
| mkdir -p "/tmp/gh-aw/evals" | |
| evidence_tmp="/tmp/gh-aw/evals/execution.json.tmp" | |
| printf '{"version":1,"component":"evals","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" | |
| mv "$evidence_tmp" "/tmp/gh-aw/evals/execution.json" | |
| export GH_AW_AWF_EXECUTION_COMPONENT="evals" | |
| export GH_AW_AWF_EXECUTION_EVIDENCE_FILE="/tmp/gh-aw/evals/execution.json" | |
| GH_AW_AWF_ENGINE_NAME=pi \ | |
| GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ | |
| GH_AW_AWF_LOG_FILE=/tmp/gh-aw/evals/evals.log \ | |
| GH_AW_AWF_ATTEMPT_LOG_NAME=pi \ | |
| bash "${RUNNER_TEMP}/gh-aw/actions/run_awf_with_startup_retries.sh" -- \ | |
| awf --config "${RUNNER_TEMP}/gh-aw/awf-config.json" --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" ${GH_AW_TOOL_CACHE_MOUNT:+--mount "$GH_AW_TOOL_CACHE_MOUNT"} ${GH_AW_DOCKER_HOST:+--docker-host "$GH_AW_DOCKER_HOST"} --env-all --exclude-env ACTIONS_ID_TOKEN_REQUEST_TOKEN --exclude-env ACTIONS_ID_TOKEN_REQUEST_URL --exclude-env AI_GATEWAY_API_KEY --exclude-env ANTHROPIC_API_KEY --exclude-env ANTHROPIC_AUTH_TOKEN --exclude-env ANTHROPIC_OAUTH_TOKEN --exclude-env AWS_ACCESS_KEY_ID --exclude-env AWS_BEARER_TOKEN_BEDROCK --exclude-env AWS_SECRET_ACCESS_KEY --exclude-env AWS_SESSION_TOKEN --exclude-env AZURE_OPENAI_API_KEY --exclude-env BASETEN_API_KEY --exclude-env CEREBRAS_API_KEY --exclude-env CODEX_API_KEY --exclude-env COPILOT_GITHUB_TOKEN --exclude-env DEEPSEEK_API_KEY --exclude-env FIREWORKS_API_KEY --exclude-env GEMINI_API_KEY --exclude-env GH_AW_OTLP_ENDPOINTS --exclude-env GOOGLE_CLOUD_API_KEY --exclude-env GROQ_API_KEY --exclude-env HF_TOKEN --exclude-env KIMI_API_KEY --exclude-env MINIMAX_API_KEY --exclude-env MISTRAL_API_KEY --exclude-env NVIDIA_API_KEY --exclude-env OPENAI_API_KEY --exclude-env OPENCODE_API_KEY --exclude-env OPENROUTER_API_KEY --exclude-env OTEL_EXPORTER_OTLP_ENDPOINT --exclude-env OTEL_EXPORTER_OTLP_HEADERS --exclude-env RADIUS_API_KEY --exclude-env TOGETHER_API_KEY --exclude-env TYPESAFE_API_KEY --exclude-env XAI_API_KEY --mount /tmp/gh-aw:/tmp/gh-aw:rw --log-level info --skip-pull \ | |
| -- /bin/bash -c 'set +o histexpand; GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" ${RUNNER_TEMP}/gh-aw/actions/shell_harness.cjs pi '\'': "${RUNNER_TOOL_CACHE:?RUNNER_TOOL_CACHE must be set}"; GH_AW_TOOL_CACHE="$RUNNER_TOOL_CACHE"; GH_AW_TOOL_BINS="$(find "$GH_AW_TOOL_CACHE" -maxdepth 5 -type d -name bin 2>/dev/null | tr "\n" ":")"; GH_AW_TOOL_BINS="${GH_AW_TOOL_BINS%:}"; export PATH="$PATH${GH_AW_TOOL_BINS:+:}$GH_AW_TOOL_BINS"; [ -n "$GOROOT" ] && export PATH="$GOROOT/bin:$PATH" || true; [ -n "$ERLANG_HOME" ] && export PATH="$ERLANG_HOME/bin:$PATH" || true && cd "${GITHUB_WORKSPACE}" && GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" "${RUNNER_TEMP}/gh-aw/actions/pi_runtime.cjs" && export GH_AW_PI_MODEL_ID=claude-haiku-4.5 && export GH_AW_PI_GATEWAY_SECRET_ENV=COPILOT_GITHUB_TOKEN GH_AW_PI_GATEWAY_FALLBACK_PORT=10002 GH_AW_LLM_PROVIDER=github && ( GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || true)"; fi; if [ -z "$GH_AW_NODE_EXEC" ]; then echo "node runtime missing on this runner — check runtimes.node in workflow YAML" >&2; exit 127; fi; GH_AW_NPM_GLOBAL_ROOT="$(npm root -g 2>/dev/null || true)"; if [ -n "$GH_AW_NPM_GLOBAL_ROOT" ]; then export NODE_PATH="${GH_AW_NPM_GLOBAL_ROOT}${NODE_PATH:+:${NODE_PATH}}"; fi; "$GH_AW_NODE_EXEC" "${RUNNER_TEMP}/gh-aw/actions/pi_models_json.cjs" ) && cat /tmp/gh-aw/aw-prompts/user.txt | pi --print --mode json --no-session --no-approve --model aw-gateway/claude-haiku-4.5 --append-system-prompt /tmp/gh-aw/aw-prompts/system.txt --extension "${RUNNER_TEMP}/gh-aw/actions/pi_provider.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_steering_extension.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_tool_policy.cjs" --extension "${RUNNER_TEMP}/gh-aw/actions/pi_subagent_extension.cjs" --extension builtin:mcp --extension builtin:codemode --extension builtin:tool-search 2>&1 | tee /tmp/gh-aw/pi-streaming.jsonl'\''' | |
| env: | |
| AWF_REFLECT_ENABLED: 1 | |
| COPILOT_GITHUB_TOKEN: ${{ github.token }} | |
| GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_EVALS_MAX_AI_CREDITS || '400' }} | |
| GH_AW_MAX_TURNS: ${{ vars.GH_AW_DEFAULT_MAX_TURNS || '' }} | |
| GH_AW_PHASE: evals | |
| GH_AW_PI_BARE: false | |
| GH_AW_PI_CONFIG: '{}' | |
| GH_AW_PI_MODEL: copilot/claude-haiku-4.5 | |
| GH_AW_PI_MODEL_ALIASES: '{"agent":["sonnet-6x","gpt-6","gpt-5.4","gpt-5.5","gpt-5.6","gpt-5.3","gemini-pro","any"],"antigravity":["copilot/antigravity*","google/antigravity*","gemini/antigravity*"],"any":["copilot/*","anthropic/*","openai/*","google/*","gemini/*"],"auto":["copilot/auto","large"],"claude":["agent"],"codex":["agent"],"coding":["copilot/gpt-5*codex*","openai/gpt-5*codex*","gpt-5-codex","kimi"],"computer-use":["copilot/*computer-use*","google/*computer-use*","gemini/*computer-use*","openai/*computer-use*"],"copilot":["agent"],"deep-research":["copilot/deep-research*","copilot/o3-deep-research*","copilot/o4-mini-deep-research*","google/deep-research*","gemini/deep-research*","openai/o3-deep-research*","openai/o4-mini-deep-research*"],"detection":["small"],"evals":["small"],"fable":["copilot/*fable*","anthropic/*fable*"],"gemini":["agent"],"gemini-3-flash":["copilot/gemini-3*flash*","google/gemini-3*flash*","gemini/gemini-3*flash*"],"gemini-3-pro":["copilot/gemini-3*pro*","google/gemini-3*pro*","google/nano-banana*","gemini/gemini-3*pro*"],"gemini-3.1-flash":["copilot/gemini-3.1*flash*","google/gemini-3.1*flash*","gemini/gemini-3.1*flash*"],"gemini-3.1-pro":["copilot/gemini-3.1*pro*","google/gemini-3.1*pro*","gemini/gemini-3.1*pro*"],"gemini-3.5-flash":["copilot/gemini-3.5*flash*","google/gemini-3.5*flash*","gemini/gemini-3.5*flash*"],"gemini-3.6-flash":["copilot/gemini-3.6*flash*","google/gemini-3.6*flash*","gemini/gemini-3.6*flash*"],"gemini-3.7-flash":["copilot/gemini-3.7*flash*","google/gemini-3.7*flash*","gemini/gemini-3.7*flash*"],"gemini-3.8-flash":["copilot/gemini-3.8*flash*","google/gemini-3.8*flash*","gemini/gemini-3.8*flash*"],"gemini-flash":["copilot/gemini-*flash*","google/gemini-*flash*","gemini/gemini-*flash*"],"gemini-flash-lite":["copilot/gemini-*flash*lite*","google/gemini-*flash*lite*","gemini/gemini-*flash*lite*"],"gemini-omni":["copilot/gemini-omni*","google/gemini-omni*","gemini/gemini-omni*"],"gemini-pro":["copilot/gemini-*pro*","google/gemini-*pro*","gemini/gemini-*pro*"],"gemma":["copilot/gemma*","google/gemma*","gemini/gemma*"],"gpt-5":["copilot/gpt-5*","openai/gpt-5*"],"gpt-5-codex":["copilot/gpt-5*codex*","openai/gpt-5*codex*"],"gpt-5-mini":["copilot/gpt-5*mini*","openai/gpt-5*mini*"],"gpt-5-nano":["copilot/gpt-5*nano*","openai/gpt-5*nano*"],"gpt-5-pro":["copilot/gpt-5*pro*","openai/gpt-5*pro*"],"gpt-5.1":["copilot/gpt-5.1*","openai/gpt-5.1*"],"gpt-5.2":["copilot/gpt-5.2*","openai/gpt-5.2*"],"gpt-5.3":["copilot/gpt-5.3*","openai/gpt-5.3*"],"gpt-5.4":["copilot/gpt-5.4*","openai/gpt-5.4*"],"gpt-5.5":["copilot/gpt-5.5*","openai/gpt-5.5*"],"gpt-5.6":["copilot/gpt-5.6*","openai/gpt-5.6*"],"gpt-6":["copilot/gpt-6*","openai/gpt-6*"],"grok":["copilot/*grok*","openai/*grok*"],"haiku":["copilot/*haiku*","anthropic/*haiku*"],"image-generation":["copilot/gpt-image*","openai/gpt-image*","openai/chatgpt-image*","copilot/gemini-*image*","google/gemini-*image*","gemini/gemini-*image*","google/imagen*"],"kimi":["copilot/kimi*","openai/kimi*"],"kiwi":["copilot/kiwi*","openai/kiwi*"],"large":["sonnet","gpt-6","gpt-5-pro","gpt-5","gemini-pro"],"lyria":["google/lyria*","gemini/lyria*","copilot/lyria*"],"mai-code":["copilot/MAI-Code*","copilot/mai-code*","openai/MAI-Code*"],"mai-code-1-flash-picker":["copilot/MAI-Code-1-Flash-picker*","copilot/mai-code-1-flash-picker*","openai/MAI-Code-1-Flash-picker*"],"mini":["haiku","gpt-5-mini","gpt-5-nano","gemini-flash-lite"],"nano-banana":["copilot/nano-banana*","google/nano-banana*","gemini/nano-banana*"],"opus":["copilot/*opus*","anthropic/*opus*"],"opusplan":["opus?effort=high"],"raptor-mini":["copilot/raptor*","openai/raptor*"],"reasoning":["copilot/o1*","copilot/o3*","copilot/o4*","openai/o1*","openai/o3*","openai/o4*"],"robotics":["copilot/*robotics*","google/*robotics*","gemini/*robotics*"],"small":["mini"],"small-agent":["haiku","gpt-5-mini","gemini-flash"],"sonnet":["copilot/*sonnet*","anthropic/*sonnet*"],"sonnet-6x":["copilot/*sonnet-4.5*","copilot/*sonnet-4.6*","copilot/*sonnet-5*","copilot/*sonnet-4-5-*","anthropic/*sonnet-4-5-*","copilot/*sonnet-4-6*","anthropic/*sonnet-4-6*","anthropic/*sonnet-5*"],"summarization":["haiku","gpt-5-mini","gemini-flash-lite","mini"],"veo":["google/veo*","gemini/veo*"],"vision":["copilot/gemini-*image*","google/gemini-*image*","gemini/gemini-*image*","copilot/gemini-*flash*","google/gemini-*flash*","gemini/gemini-*flash*"]}' | |
| GH_AW_PI_NATIVE_PROVIDER: github-copilot | |
| GH_AW_PI_SUBAGENT_ARGS: '["--print","--mode","json","--no-session","--no-approve"]' | |
| GH_AW_PI_SYSTEM_PROMPT: /tmp/gh-aw/aw-prompts/system.txt | |
| GH_AW_PI_TOOL_BUDGET_DIR: /tmp/gh-aw/pi-agent-dir/tool-budget | |
| GH_AW_PI_TOOL_POLICY: '{"bash":["*"]}' | |
| GH_AW_PI_USER_PROMPT: /tmp/gh-aw/aw-prompts/user.txt | |
| GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt | |
| GH_AW_TIMEOUT_MINUTES: 15 | |
| GH_AW_VERSION: dev | |
| GITHUB_AW: true | |
| GITHUB_STEP_SUMMARY: /tmp/gh-aw/agent-step-summary.md | |
| GITHUB_WORKSPACE: ${{ github.workspace }} | |
| GIT_AUTHOR_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_AUTHOR_NAME: github-actions[bot] | |
| GIT_COMMITTER_EMAIL: github-actions[bot]@users.noreply.github.com | |
| GIT_COMMITTER_NAME: github-actions[bot] | |
| PI_CODING_AGENT_DIR: /tmp/gh-aw/pi-agent-dir | |
| PI_OFFLINE: 1 | |
| RUNNER_TEMP: ${{ runner.temp }} | |
| TRACEPARENT: ${{ env.GITHUB_AW_OTEL_TRACE_ID != '' && env.GITHUB_AW_OTEL_PARENT_SPAN_ID != '' && format('00-{0}-{1}-01', env.GITHUB_AW_OTEL_TRACE_ID, env.GITHUB_AW_OTEL_PARENT_SPAN_ID) || '' }} | |
| - name: Parse MCP Gateway logs for step summary | |
| if: always() | |
| id: parse-mcp-gateway | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'parse_mcp_gateway_log.cjs')); | |
| await main(); | |
| - name: Parse BinEval results | |
| if: always() | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_EVALS_QUESTIONS: '[{"id":"nudge-targeted","question":"Did every Copilot nudge list only unanswered review feedback or concrete blockers, request a branch update, and include its Sous-chef state fingerprint?"},{"id":"dedup-respected","question":"Did the agent avoid nudging PRs classified as unchanged, stale, dependency_bot, opted_out, agent_active, not_idle, approval_required, or nothing_actionable, and entries with nudge_needed false, repeating unchanged work only for behind or conflicting branches?"},{"id":"progress-or-noop","question":"Did the agent either perform a specific forward-progress action on an eligible PR or stop with an explicit no-op when none remained?"}]' | |
| GH_AW_EVALS_MODEL: "copilot/claude-haiku-4.5" | |
| GH_AW_EVALS_PHASE: parse | |
| GITHUB_RUN_ID: ${{ github.run_id }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'run_evals.cjs')); | |
| await main(); | |
| - name: Redact secrets in evals results | |
| id: redact_evals_results | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'redact_evals_results.cjs')); | |
| await main(); | |
| - name: Render evals results to step summary | |
| if: always() && steps.redact_evals_results.outcome == 'success' | |
| continue-on-error: true | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'render_evals_summary.cjs')); | |
| await main(); | |
| - name: Collect evals token usage | |
| if: always() | |
| run: | | |
| for root in "/tmp/gh-aw/sandbox/firewall/audit" "/tmp/gh-aw/sandbox/firewall/logs"; do | |
| source="$root/api-proxy-logs/token-usage.jsonl" | |
| if [ -s "$source" ]; then cp "$source" /tmp/gh-aw/evals_token_usage.jsonl; fi | |
| done | |
| - name: Upload evals results | |
| if: always() && steps.redact_evals_results.outcome == 'success' | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: evals | |
| path: | | |
| /tmp/gh-aw/evals.jsonl | |
| /tmp/gh-aw/evals_token_usage.jsonl | |
| /tmp/gh-aw/evals/execution.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Upload evals accounting after failure | |
| if: always() && steps.redact_evals_results.outcome != 'success' | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: evals | |
| path: | | |
| /tmp/gh-aw/evals_token_usage.jsonl | |
| /tmp/gh-aw/evals/execution.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} | |
| - name: Restore actions folder | |
| if: always() | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions/setup | |
| sparse-checkout-cone-mode: true | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| pre_activation: | |
| name: pre_activation | |
| runs-on: ubuntu-slim | |
| # Permissions for the pre_activation job (workflow permissions default to none). | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| outputs: | |
| activated: ${{ steps.check_membership.outputs.is_team_member == 'true' && steps.check_skip_if_no_match.outputs.skip_no_match_check_ok == 'true' && steps.check_command_position.outputs.command_position_ok == 'true' }} | |
| matched_command: ${{ steps.check_command_position.outputs.matched_command }} | |
| setup-parent-span-id: ${{ steps.setup.outputs.parent-span-id || steps.setup.outputs.span-id }} | |
| setup-span-id: ${{ steps.setup.outputs.span-id }} | |
| setup-trace-id: ${{ steps.setup.outputs.trace-id }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Check command position | |
| id: check_command_position | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_COMMANDS: "[\"souschef\"]" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'check_command_position.cjs')); | |
| await main(); | |
| - name: Check team membership for command workflow | |
| id: check_membership | |
| if: steps.check_command_position.outputs.command_position_ok == 'true' | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_REQUIRED_ROLES: "admin,maintainer,write" | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'check_membership.cjs')); | |
| await main(); | |
| - name: Check skip-if-no-match query | |
| id: check_skip_if_no_match | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_SKIP_QUERY: "is:pr is:open -is:draft -author:app/dependabot -author:app/renovate -label:broccoli" | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_SKIP_MIN_MATCHES: "1" | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'check_skip_if_no_match.cjs')); | |
| await main(); | |
| prefilter: | |
| name: prefilter | |
| needs: activation | |
| runs-on: ubuntu-latest | |
| # Permissions for the prefilter job (workflow permissions default to none). | |
| permissions: | |
| actions: read | |
| contents: read | |
| issues: read | |
| pull-requests: read | |
| outputs: | |
| eligible_count: ${{ steps.fetch-prs.outputs.eligible_count }} | |
| eligible_pull_request_numbers: ${{ steps.fetch-prs.outputs.eligible_pull_request_numbers }} | |
| rate_limit_low: ${{ steps.fetch-prs.outputs.rate_limit_low }} | |
| steps: | |
| - name: Configure GH_HOST for enterprise compatibility | |
| id: ghes-host-config | |
| shell: bash | |
| run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input. | |
| # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct | |
| # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op. | |
| GH_HOST="${GITHUB_SERVER_URL#https://}" | |
| GH_HOST="${GH_HOST#http://}" | |
| echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV" | |
| - name: Checkout prefilter script | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| sparse-checkout: | | |
| scripts | |
| .github/scripts | |
| - name: Fetch actionable PR queue | |
| id: fetch-prs | |
| run: node scripts/pr-sous-chef.mjs | |
| env: | |
| GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| - name: Upload compact queue | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: pr-sous-chef-queue | |
| path: /tmp/gh-aw/agent/pr-sous-chef-candidates-compact.json | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '1' }} | |
| push_evals_state: | |
| name: push_evals_state | |
| needs: | |
| - activation | |
| - evals | |
| if: always() && (!cancelled()) && needs.evals.result != 'skipped' | |
| runs-on: ubuntu-slim | |
| # Permissions for the push_evals_state job (workflow permissions default to none). | |
| permissions: | |
| contents: write | |
| env: | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Checkout repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| sparse-checkout: . | |
| - name: Configure Git credentials | |
| env: | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh" | |
| - name: Download evals artifact | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| continue-on-error: true | |
| with: | |
| pattern: evals | |
| merge-multiple: true | |
| path: /tmp/gh-aw/evals-state | |
| - name: Push evals results to git | |
| id: push_evals_state | |
| if: always() | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GITHUB_RUN_ID: ${{ github.run_id }} | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GH_AW_STATE_DIR: /tmp/gh-aw/evals-state | |
| GH_AW_STATE_BRANCH: evals/prsouschef | |
| GH_AW_STATE_FILES: evals.jsonl | |
| GH_AW_STATE_LABEL: evals results | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit); | |
| const { main } = require(path.join(actionsDir, 'push_experiment_state.cjs')); | |
| await main(); | |
| - name: Restore actions folder | |
| if: always() | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions/setup | |
| sparse-checkout-cone-mode: true | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| safe_outputs: | |
| name: safe_outputs | |
| needs: | |
| - activation | |
| - agent | |
| - detection | |
| - prefilter | |
| if: (!cancelled()) && needs.agent.result != 'skipped' && needs.detection.result == 'success' | |
| runs-on: ubuntu-slim | |
| # Permissions for the safe_outputs job (workflow permissions default to none). | |
| permissions: | |
| actions: write | |
| issues: write | |
| pull-requests: write | |
| timeout-minutes: 45 | |
| env: | |
| GH_AW_AGENT_AIC: ${{ needs.agent.outputs.aic }} | |
| GH_AW_AIC: ${{ needs.agent.outputs.aic }} | |
| GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} | |
| GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/pr-sous-chef" | |
| GH_AW_COMMANDS: "[\"souschef\"]" | |
| GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} | |
| GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} | |
| GH_AW_ENGINE_ID: "pi" | |
| GH_AW_ENGINE_MODEL: "copilot/claude-haiku-4.5" | |
| GH_AW_PROJECT_UTC: "-08:00" | |
| GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} | |
| GH_AW_SAFE_OUTPUT_MESSAGES: "{\"runStarted\":\"🍳 [{workflow_name}]({run_url}) is preparing PRs for maintainer investigation.\",\"runSuccess\":\"✅ [{workflow_name}]({run_url}) finished PR sous-chef nudges.\",\"runFailure\":\"⚠️ [{workflow_name}]({run_url}) {status} while preparing PRs.\"}" | |
| GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} | |
| GH_AW_WORKFLOW_EMOJI: "👨\u200d🍳" | |
| GH_AW_WORKFLOW_ID: "pr-sous-chef" | |
| GH_AW_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/pr-sous-chef.md" | |
| outputs: | |
| code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} | |
| code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }} | |
| comment_id: ${{ steps.process_safe_outputs.outputs.comment_id }} | |
| comment_url: ${{ steps.process_safe_outputs.outputs.comment_url }} | |
| create_discussion_error_count: ${{ steps.process_safe_outputs.outputs.create_discussion_error_count }} | |
| create_discussion_errors: ${{ steps.process_safe_outputs.outputs.create_discussion_errors }} | |
| created_issue_number: ${{ steps.process_safe_outputs.outputs.created_issue_number }} | |
| created_issue_url: ${{ steps.process_safe_outputs.outputs.created_issue_url }} | |
| process_safe_outputs_items_applied: ${{ steps.process_safe_outputs.outputs.items_applied }} | |
| process_safe_outputs_items_cancelled: ${{ steps.process_safe_outputs.outputs.items_cancelled }} | |
| process_safe_outputs_items_deferred: ${{ steps.process_safe_outputs.outputs.items_deferred }} | |
| process_safe_outputs_items_failed: ${{ steps.process_safe_outputs.outputs.items_failed }} | |
| process_safe_outputs_items_skipped: ${{ steps.process_safe_outputs.outputs.items_skipped }} | |
| process_safe_outputs_items_succeeded: ${{ steps.process_safe_outputs.outputs.items_succeeded }} | |
| process_safe_outputs_items_warnings: ${{ steps.process_safe_outputs.outputs.items_warnings }} | |
| process_safe_outputs_processed_count: ${{ steps.process_safe_outputs.outputs.processed_count }} | |
| process_safe_outputs_status: ${{ steps.process_safe_outputs.outputs.status }} | |
| steps: | |
| - name: Checkout actions folder | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: github/gh-aw | |
| sparse-checkout: | | |
| actions | |
| fetch-depth: 1 | |
| clean: false | |
| persist-credentials: false | |
| - name: Setup Scripts | |
| id: setup | |
| uses: ./actions/setup | |
| with: | |
| destination: ${{ runner.temp }}/gh-aw/actions | |
| job-name: ${{ github.job }} | |
| trace-id: ${{ needs.activation.outputs.setup-trace-id }} | |
| parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} | |
| env: | |
| GH_AW_SETUP_WORKFLOW_NAME: "PR Sous Chef" | |
| GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/pr-sous-chef.lock.yml@${{ github.ref }} | |
| GH_AW_INFO_VERSION: "1.0.0" | |
| GH_AW_INFO_AWF_VERSION: "v0.28.50" | |
| GH_AW_INFO_ENGINE_ID: "pi" | |
| GH_AW_SETUP_AW_CONTEXT: ${{ inputs.aw_context }} | |
| - name: Mask OTLP telemetry headers | |
| run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" | |
| - name: Download agent output artifact | |
| id: download-agent-output | |
| continue-on-error: true | |
| uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 | |
| with: | |
| pattern: "{agent,agent-output-fallback}" | |
| merge-multiple: true | |
| path: /tmp/gh-aw/ | |
| - name: Setup agent output environment variable | |
| id: setup-agent-output-env | |
| if: steps.download-agent-output.outcome == 'success' | |
| run: | | |
| mkdir -p /tmp/gh-aw/ | |
| find "/tmp/gh-aw/" -type f -print | |
| if [ -f "/tmp/gh-aw/agent_output.json" ]; then | |
| echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Configure GH_HOST for enterprise compatibility | |
| id: ghes-host-config | |
| shell: bash | |
| run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input. | |
| # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct | |
| # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op. | |
| GH_HOST="${GITHUB_SERVER_URL#https://}" | |
| GH_HOST="${GH_HOST#http://}" | |
| echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV" | |
| - name: Process Safe Outputs | |
| id: process_safe_outputs | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} | |
| GH_AW_COMMENT_ID: ${{ needs.activation.outputs.comment_id }} | |
| GH_AW_MENTIONS_GITHUB_TOKEN: ${{ github.token }} | |
| GH_AW_ALLOWED_DOMAINS: "*.grafana.net,*.sentry.io,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,s.symcb.com,s.symcd.com,security.ubuntu.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" | |
| GITHUB_SERVER_URL: ${{ github.server_url }} | |
| GITHUB_API_URL: ${{ github.api_url }} | |
| GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"add_comment\":{\"github-token\":\"${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}\",\"max\":5,\"target\":\"*\"},\"approve_workflow_run\":{\"allowed_pull_requests\":${{ toJSON(needs.prefilter.outputs.eligible_pull_request_numbers) }},\"allowed_workflows\":[\"cjs.yml\",\"cgo.yml\",\"CWI.yml\"],\"comment\":true,\"github-token\":\"${{ secrets.AWI_MAINTENANCE_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}\",\"max\":8,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"CHANGELOG.md\",\"PI.md\",\"AGENTS.md\",\"AGENTS.override.md\",\"AGENTS.MD\",\"CLAUDE.md\",\"CLAUDE.MD\"]},\"create_issue\":{\"close_older_issues\":true,\"expires\":72,\"group_by_day\":true,\"labels\":[\"automation\"],\"max\":1,\"title_prefix\":\"[pr-sous-chef] \"},\"create_report_incomplete_issue\":{},\"dismiss_pull_request_review\":{\"max\":20,\"target\":\"*\"},\"mentions\":{\"allowed\":[\"copilot\"]},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" | |
| GH_AW_GITHUB_TOKEN_SOURCE: ${{ secrets.GH_AW_GITHUB_TOKEN != '' && 'pat' || 'github_actions' }} | |
| with: | |
| github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} | |
| script: | | |
| const path = require('path'); | |
| const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); | |
| const { setupGlobals } = require(path.join(actionsDir, 'setup_globals.cjs')); | |
| setupGlobals(core, github, context, exec, io, getOctokit, process.env.GH_AW_GITHUB_TOKEN_SOURCE); | |
| const { main } = require(path.join(actionsDir, 'process_safe_outputs.cjs')); | |
| await main(); | |
| - name: Upload Safe Outputs Items | |
| if: always() | |
| uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7.0.2 | |
| with: | |
| name: safe-outputs-items | |
| path: | | |
| /tmp/gh-aw/safe-output-items.jsonl | |
| /tmp/gh-aw/temporary-id-map.json | |
| /tmp/gh-aw/safe-output-errors.json | |
| if-no-files-found: ignore | |
| retention-days: ${{ vars.GH_AW_DEFAULT_ARTIFACT_RETENTION_DAYS || '0' }} |