Skip to content

Upgrade workflows to gh-aw v0.91.6 - #14638

Merged
lpcox merged 1 commit into
mainfrom
lpcox-upgrade-gh-aw-pre-release-8f3c
Oct 9, 2026
Merged

lpcox merged 1 commit into
mainfrom
lpcox-upgrade-gh-aw-pre-release-8f3c

Conversation

@lpcox

@lpcox lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

Upgrades the gh-aw extension and generated workflows from v0.91.4 to the latest available pre-release, v0.91.6.

Changes

  • Ran gh aw upgrade --pre-releases
  • Updated gh-aw setup actions to v0.91.6
  • Updated action and container digest pins
  • Refreshed the agentic-workflows agent and dispatcher skill
  • Recompiled all 34 agentic workflows

Validation

  • gh aw compile — 34/34 workflows compiled successfully
  • make agent-finished — passed

The compiler reports the same non-fatal workflow warnings for direct /tmp/ references, dispatch concurrency, and a secrets expression; there are no compilation errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 13:49
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔒 mcpg Read-Only Stress — default

Surface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Isolation runtime: default (normal container isolation)

Part Surface Op Result Expected Status
A MCP reads data returned (issues/PRs/README.md/commits) ALLOWED ✅
B MCP writes (reaction/star/issue/comment/branch/file/PR) all 7 targets absent from 23-tool catalog; attempted calls → -32602 unknown tool BLOCKED ⚠️
C CLI reads data returned via gateway-backed github CLI ALLOWED ✅
D CLI REST writes (reaction/star/issue/comment) not attempted — gh unauthenticated (You are not logged into any GitHub hosts) BLOCKED ⚠️
E CLI GraphQL mutations (addReaction/addStar/createIssue) not attempted — same gh auth gap BLOCKED ⚠️

Overall: INCONCLUSIVE

No write leaked in any surface. Gaps: (1) Part B's 7 write tools are entirely absent from the exposed MCP catalog (gh-aw's GITHUB_READ_ONLY=1 backend toolset config), so refusal only proves backend configuration, not mcpg's own gateway-level DIFC/guard blocking layer — that is covered separately by internal/guard/internal/difc unit tests, not by this probe. (2) gh CLI is not authenticated in this job, so Parts D/E (token-scope + GraphQL mutation boundary) could not be exercised at all this run.

🔒 mcpg read-only stress (default AWF runtime) by Read-Only Stress: default runtime

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The version, action pins, refreshed guidance, and all 34 generated workflows are consistent with v0.91.6 and reported validation passed.

0 open findings

What changed in this PR

Upgrades the repository’s agentic workflow toolchain to gh-aw v0.91.6 and regenerates all workflow artifacts.

Changes:

  • Updates gh-aw actions, container images, and digest pins.
  • Recompiles all 34 agentic workflows.
  • Refreshes dispatcher guidance for security reviews and Git-backed work queues.
File Description
.github/​agents/​agentic-workflows.md Adds work-queue routing guidance.
.github/​skills/​agentic-workflows/​SKILL.md Adds security-review and work-queue guidance.
.github/​aw/​actions-lock.json Updates action and container pins.
.github/​workflows/​agentics-maintenance.yml Updates maintenance actions to v0.91.6.
.github/​workflows/​daily-compliance-checker.lock.yml Recompiled workflow.
.github/​workflows/​duplicate-code-detector.lock.yml Recompiled workflow.
.github/​workflows/​gateway-issue-dispatcher.lock.yml Recompiled workflow.
.github/​workflows/​ghcr-download-tracker.lock.yml Recompiled workflow.
.github/​workflows/​github-mcp-guard-coverage-checker.lock.yml Recompiled workflow.
.github/​workflows/​go-fan.lock.yml Recompiled workflow.
.github/​workflows/​go-logger.lock.yml Recompiled workflow.
.github/​workflows/​gpl-dependency-checker.lock.yml Recompiled workflow.
.github/​workflows/​guard-status-tracker.lock.yml Recompiled workflow.
.github/​workflows/​integrity-filtering-audit.lock.yml Recompiled workflow.
.github/​workflows/​issue-monster.lock.yml Recompiled workflow.
.github/​workflows/​large-payload-tester.lock.yml Recompiled workflow.
.github/​workflows/​mcp-gateway-log-analyzer.lock.yml Recompiled workflow.
.github/​workflows/​nightly-docs-reconciler.lock.yml Recompiled workflow.
.github/​workflows/​nightly-schema-updater.lock.yml Recompiled workflow.
.github/​workflows/​nightly-workflow-compiler.lock.yml Recompiled workflow.
.github/​workflows/​plan.lock.yml Recompiled workflow.
.github/​workflows/​readonly-stress-default.lock.yml Recompiled workflow.
.github/​workflows/​release.lock.yml Recompiled workflow.
.github/​workflows/​repo-assist.lock.yml Recompiled workflow.
.github/​workflows/​rust-guard-improver.lock.yml Recompiled workflow.
.github/​workflows/​semantic-function-refactor.lock.yml Recompiled workflow.
.github/​workflows/​smoke-allowonly.lock.yml Recompiled workflow.
.github/​workflows/​smoke-copilot.lock.yml Recompiled workflow.
.github/​workflows/​smoke-long-session.lock.yml Recompiled workflow.
.github/​workflows/​smoke-otel-tracing.lock.yml Recompiled workflow.
.github/​workflows/​smoke-proxy-github-script.lock.yml Recompiled workflow.
.github/​workflows/​smoke-safeoutputs-discussions.lock.yml Recompiled workflow.
.github/​workflows/​smoke-safeoutputs-issues.lock.yml Recompiled workflow.
.github/​workflows/​smoke-safeoutputs-labels.lock.yml Recompiled workflow.
.github/​workflows/​smoke-safeoutputs-prs.lock.yml Recompiled workflow.
.github/​workflows/​smoke-safeoutputs-reviews.lock.yml Recompiled workflow.
.github/​workflows/​test-coverage-improver.lock.yml Recompiled workflow.
.github/​workflows/​test-improver.lock.yml Recompiled workflow.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants