diff --git a/.github/workflows/daily-rig-claude-compat.lock.yml b/.github/workflows/daily-rig-claude-compat.lock.yml index 41b61a4..219a3bd 100644 --- a/.github/workflows/daily-rig-claude-compat.lock.yml +++ b/.github/workflows/daily-rig-claude-compat.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e37aed8a6fa38190a46f6d50d5402773a3c1cf357f4c24f9ba33451efb30d62e","body_hash":"0bee5677caf760a87044da948274b08b94e4f50ea5a06085aafaa3d19b49921c","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-4.6","engine_versions":{"copilot":"1.0.92"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8263f85ec06c561b928ed116dfdc81c523cfeecc96d61b38a8284f2e88d80d75","body_hash":"2f25f0d3965d687fb0f9dc0bbad1cabc4bc2c769641a5e9ebcab2de7f49bc444","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-4.6","engine_versions":{"copilot":"1.0.92"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_CI_TRIGGER_TOKEN","GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31","digest":"sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31@sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"safeoutputs","tools":["create_pull_request","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -568,7 +568,7 @@ jobs: env: GH_AW_FILE_ROOT: "${{ runner.temp }}/gh-aw" GH_AW_FILE_CONFIG: "{\"files\":[{\"path\":\"safeoutputs/config.json\",\"content_env\":\"GH_AW_SAFE_OUTPUTS_CONFIG\"}]}" - GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/references/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" with: script: | const path = require('path'); @@ -1956,7 +1956,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.githubusercontent.com,api.npms.io,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,bun.sh,cdn.jsdelivr.net,codeload.github.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,deb.nodesource.com,deno.land,docs.github.com,esm.sh,get.pnpm.io,github-cloud.githubusercontent.com,github-cloud.s3.amazonaws.com,github.blog,github.com,github.githubassets.com,googleapis.deno.dev,googlechromelabs.github.io,json-schema.org,json.schemastore.org,jsr.io,keyserver.ubuntu.com,lfs.github.com,nodejs.org,npm.pkg.github.com,npmjs.com,npmjs.org,objects.githubusercontent.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,patch-diff.githubusercontent.com,patchdiff.githubusercontent.com,ppa.launchpad.net,raw.githubusercontent.com,registry.bower.io,registry.npmjs.com,registry.npmjs.org,registry.yarnpkg.com,repo.yarnpkg.com,s.symcb.com,s.symcd.com,security.ubuntu.com,skimdb.npmjs.com,storage.googleapis.com,telemetry.vercel.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com,www.npmjs.com,www.npmjs.org,yarnpkg.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/references/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" GH_AW_CI_TRIGGER_TOKEN: ${{ secrets.GH_AW_CI_TRIGGER_TOKEN }} with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/daily-rig-claude-compat.md b/.github/workflows/daily-rig-claude-compat.md index e651084..87e1d4d 100644 --- a/.github/workflows/daily-rig-claude-compat.md +++ b/.github/workflows/daily-rig-claude-compat.md @@ -46,7 +46,7 @@ safe-outputs: allowed-files: - "README.md" - "skills/rig/SKILL.md" - - "skills/rig/references/*.md" + - "skills/rig/*.md" - "skills/rig/samples/*.md" - "skills/rig/rig.ts" - "skills/rig/engines/anthropic.ts" @@ -66,8 +66,8 @@ Read these files before deciding whether to edit anything: - `README.md` - `skills/rig/SKILL.md` -- `skills/rig/references/dynamic-workflows.md` -- `skills/rig/references/claude-workflow-conversion.md` +- `skills/rig/dynamic-workflows.md` +- `skills/rig/claude-workflow-conversion.md` - `skills/rig/rig.ts` - `skills/rig/engines/anthropic.ts` - `src/workflow.test.ts` diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index d17e40d..6ea427e 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8e266e9f7a66edd0057ec75a6bef022bff9d3cdcb1a01df6fbfd9e3fe856c7d8","body_hash":"6f4dc2fcc0ba95073a0f1f0179efb77ab15c2f021309cf526077ab8622f8517d","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"da900faf4bd6debca1a91315e7a45aee7e523ba07305646aae91ed7f34f0b6d6","body_hash":"c9910baf835a9df17f75dc56750dc304220d4853cbaae74347cfeb6fc8312aae","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -27,6 +27,10 @@ # # Intent: Detect regressions in the Rig skill's ability to run typed judgments through the Copilot SDK. # +# Resolved workflow manifest: +# Imports: +# - shared/rig.md +# # Frontmatter env variables: # - RIG_DEBUG: (main workflow) # @@ -301,7 +305,7 @@ jobs: GH_AW_ACTIONS_DIR: ${{ runner.temp }}/gh-aw/actions GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt GH_AW_SAFE_OUTPUTS: ${{ runner.temp }}/gh-aw/safeoutputs/outputs.jsonl - GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_mcp_transport_prompt.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"file\":\"safe_outputs_auto_create_issue.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"}],\"system_item_count\":13}" + GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_mcp_transport_prompt.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"file\":\"safe_outputs_auto_create_issue.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0006\"}],\"system_item_count\":13}" GH_AW_EXPR_76DF9333: ${{ github.event.pull_request.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'pull_request' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} GH_AW_EXPR_77C1A4D2: ${{ github.event.comment.id || fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').comment_id }} GH_AW_EXPR_7C248226: ${{ github.event.issue.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'issue' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} @@ -315,7 +319,8 @@ jobs: GH_AW_PROMPT_CONTENT_0002: "\n" GH_AW_PROMPT_CONTENT_0003: "\nThe following GitHub context information is available for this workflow:\n{{#if github.actor}}\n- **actor**: __GH_AW_GITHUB_ACTOR__\n{{/if}}\n{{#if github.repository}}\n- **repository**: __GH_AW_GITHUB_REPOSITORY__\n{{/if}}\n{{#if github.workspace}}\n- **workspace**: __GH_AW_GITHUB_WORKSPACE__\n{{/if}}\n{{#if github.event.issue.number || (github.aw.context.item_type == 'issue' && github.aw.context.item_number)}}\n- **issue-number**: #__GH_AW_EXPR_7C248226__\n{{/if}}\n{{#if github.event.discussion.number || (github.aw.context.item_type == 'discussion' && github.aw.context.item_number)}}\n- **discussion-number**: #__GH_AW_EXPR_C19C384F__\n{{/if}}\n{{#if github.event.pull_request.number || (github.aw.context.item_type == 'pull_request' && github.aw.context.item_number)}}\n- **pull-request-number**: #__GH_AW_EXPR_76DF9333__\n{{/if}}\n{{#if github.event.comment.id || github.aw.context.comment_id}}\n- **comment-id**: __GH_AW_EXPR_77C1A4D2__\n{{/if}}\n{{#if github.run_id}}\n- **workflow-run-id**: __GH_AW_GITHUB_RUN_ID__\n{{/if}}\n\n\n" GH_AW_PROMPT_CONTENT_0004: "\n" - GH_AW_PROMPT_CONTENT_0005: "{{#runtime-import .github/workflows/rig-skill-integration.md}}\n" + GH_AW_PROMPT_CONTENT_0005: "{{#runtime-import .github/workflows/shared/rig.md}}\n" + GH_AW_PROMPT_CONTENT_0006: "{{#runtime-import .github/workflows/rig-skill-integration.md}}\n" with: script: | const { setupGlobals } = require(process.env.GH_AW_ACTIONS_DIR + '/setup_globals.cjs'); @@ -507,6 +512,11 @@ jobs: evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" + - name: Setup Node.js + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: '24' + package-manager-cache: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -1718,7 +1728,7 @@ jobs: if [[ ! "$GH_AW_MAX_AI_CREDITS" =~ ^[0-9]+$ ]]; then GH_AW_MAX_AI_CREDITS="400" fi - printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.31/awf-config.schema.json\",\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.31,squid=sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d,agent=sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76,api-proxy=sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a,cli-proxy=sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" + printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.31/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"api.npms.io\",\"bun.sh\",\"cdn.jsdelivr.net\",\"deb.nodesource.com\",\"deno.land\",\"esm.sh\",\"get.pnpm.io\",\"googleapis.deno.dev\",\"googlechromelabs.github.io\",\"jsr.io\",\"nodejs.org\",\"npm.pkg.github.com\",\"npmjs.com\",\"npmjs.org\",\"registry.bower.io\",\"registry.npmjs.com\",\"registry.npmjs.org\",\"registry.yarnpkg.com\",\"repo.yarnpkg.com\",\"skimdb.npmjs.com\",\"storage.googleapis.com\",\"telemetry.vercel.com\",\"www.npmjs.com\",\"www.npmjs.org\",\"yarnpkg.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.31,squid=sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d,agent=sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76,api-proxy=sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a,cli-proxy=sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" GH_AW_DOCKER_HOST="" diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index 8645d49..428a546 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -15,15 +15,15 @@ engine: copilot-sdk: true skills: - skills/rig +imports: + - shared/rig.md strict: true timeout-minutes: 10 env: RIG_DEBUG: "agent:failure,workflow:event" tools: - bash: ["node"] + bash: ["printf", "node"] edit: false -network: - allowed: [defaults, github, node] safe-outputs: noop: report-as-issue: false @@ -49,19 +49,41 @@ post-steps: # Rig skill integration -Read the installed Rig skill and its running/engines reference. Run the following -`rig` fence **once**, unchanged, using the installed skill's launcher in inline -mode. First generate a fresh delimiter: `RIG_` followed by -`randomBytes(16).toString("hex")` from Node's `node:crypto`. Verify it is not a -complete line of the fence contents; regenerate on collision. Use -`node /run.ts <<'RIG_'`, substituting the -generated literal in both the single-quoted opener and the unquoted, -unindented closing line. Never use a fixed delimiter or a shell variable. -Redirect stdout to `/tmp/gh-aw/agent/rig-skill-integration.json`. -Use the provided `COPILOT_SDK_URI`; do not start a second server or use `--server`. -Use the SDK dependencies already installed in the agent container. The entry -point does not install packages; do not run npm, npx, cat, mkdir, or other -bootstrap commands. If dependencies are missing, report the error and stop. +Execute this prevalidated fixture, not a setup or environment-diagnosis task. +Bash execution is enabled for `printf` and `node`. Your only Bash invocation must +be the launch pipeline below; a denial of another command does not mean Bash +or Node is unavailable. + +1. Load the installed `rig` skill. Read `.github/skills/rig/SKILL.md` and + `.github/skills/rig/runtime.md` with file-reading tools, not Bash commands. +2. Copy the following `rig` fence **unchanged** into one single-quoted `printf` + argument per source line, including `''` for blank lines. Escape each literal + apostrophe as `'"'"'`. Use the fixed format `'%s\n'`, not the source as a format + string; preserve percent signs, backslashes, dollar signs, and backticks. + Do not double-quote source, encode it, use shell variables or substitutions, + or generate delimiters. Do not use a heredoc with the Copilot SDK driver. +3. Run the fence **once** using this pipeline. Replace the placeholder argument + with all source-line arguments, without markdown fence markers: + +```bash +printf '%s\n' \ + '' \ + | node .github/skills/rig/run.ts > /tmp/gh-aw/agent/rig-skill-integration.json +``` + +The command must begin with `printf`. Do not prepend `mkdir`, `cd`, `env`, `export`, +or any command joined by `&&`. +The working directory is already the repository root, `/tmp/gh-aw/agent` +already exists, and Node.js and SDK dependencies are already provisioned. +Do not run version checks, dependency checks, package installation, linting, +typechecking, directory creation, or other bootstrap commands for this fixture. +Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not inspect or print +them, start a second server, or use `--server`. If the Node launch returns a +nonzero exit code, call `report_incomplete` immediately with that code and the +exact stderr error. Do not read the result file, run `cat` or another command, +diagnose the environment, or retry model calls after a failed launch. +If that launch is denied, do not repeat or reformulate the Bash command: +call `report_incomplete` immediately. The one-invocation limit includes denials. The scenario makes exactly three Rig model calls: clarity, safety, and feasibility judgments of the same harmless dummy request. TypeScript owns orchestration and @@ -102,8 +124,12 @@ export default workflow({ }); ``` -After a successful run, call `noop` with a brief summary of the three judgments -and majority verdict; success requires no repository write. If the launcher, -SDK, schema validation, or expected verdict fails, report the exact error and -stop. Do not fabricate results, modify the fixture, or retry model calls. The +After the Node launch succeeds, read the result JSON using a file-reading tool +and call `noop` with a brief summary of the three judgments and majority verdict. +Do not invoke Bash again to read or validate the result: the post-step owns +validation. Success requires no repository write. If the launcher, +SDK, schema validation, or expected verdict fails, report the exact error with +`report_incomplete` and stop. Never call `noop` on failure. A rejected launch pipeline +is a permission failure, not evidence that Node or the SDK is missing. +Do not fabricate results, modify the fixture, or retry model calls. The post-step fails the workflow when the result file is missing or invalid. diff --git a/.github/workflows/shared/rig.md b/.github/workflows/shared/rig.md new file mode 100644 index 0000000..693c0c7 --- /dev/null +++ b/.github/workflows/shared/rig.md @@ -0,0 +1,36 @@ +--- +runtimes: + node: + version: "24" +tools: + bash: ["printf", "node"] +network: + allowed: [defaults, github, node] +--- + + + + +Load the installed `rig` skill and read its Running and engines reference before +creating or running Rig programs. +Run Rig programs with Node.js 24 or later using the installed skill's `run.ts` +launcher and host-provisioned dependencies. Do not install packages from the +agent prompt; report missing dependencies and stop. Pipe literal source using +`printf '%s\n' ... | node /run.ts`, with one single-quoted argument +per line and each literal apostrophe escaped as `'"'"'`. Do not use heredocs +with the Copilot SDK driver. Start the pipeline with `printf`; do not prepend +`mkdir`, `cd`, `env`, or any `&&` preparation. +Use existing output directories; `/tmp/gh-aw/agent` is already provisioned. +Read only named environment variables needed by the program; do not dump the +environment or print credentials. + +When using the Copilot SDK engine, inherit `COPILOT_SDK_URI` and +`COPILOT_CONNECTION_TOKEN`; do not start another server or use `--server`. +If a command is denied, report that specific command, not that all shell access +is unavailable. Do not replace a failed run with fabricated output. + diff --git a/AGENTS.md b/AGENTS.md index 2f5b753..5b383d2 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -9,7 +9,7 @@ Rig is a minimal TypeScript agent harness. The core runtime (`skills/rig/rig.ts` ``` skills/rig/rig.ts — Core runtime (agent, p, copilotEngine, schemas) skills/rig/samples/ — 51 sample agents demonstrating patterns -skills/rig/references/ — Focused documentation loaded on demand from SKILL.md +skills/rig/ — Focused documentation loaded on demand from SKILL.md src/engines/copilot.test.ts — Copilot engine unit tests (vitest) src/rig.test.ts — Unit tests (vitest) scripts/run-sample.test.ts — Sample runner with a stub Copilot SDK client (dry-run) @@ -42,13 +42,13 @@ All imports use the `"rig"` path alias (resolved via tsconfig paths + vitest ali - Treat `skills/rig/SKILL.md` as prompt context: keep only high-frequency construction rules, decisions, and a minimal canonical example. - Target roughly 200 lines or fewer. Use line/word/byte counts as regression signals, not as a reason to compress prose until it is unclear. -- Put detailed API tables, edge cases, provider behavior, and scenario-specific patterns in focused files under `skills/rig/references/`. +- Put detailed API tables, edge cases, provider behavior, and scenario-specific patterns in focused files under `skills/rig/`. - Route every reference from `SKILL.md` with a short “read when” description so an agent can load only the relevant secondary context. - Prefer one representative example, decision tables, and checklists over repeated prose. Remove duplication before adding guidance. - Keep each fact canonical. A compact rule may be summarized in `SKILL.md`, but its examples and edge cases should live in one reference file. - Add new material to `SKILL.md` only when it changes how most Rig programs should be generated; otherwise update or add a focused reference. - When the API changes, update the affected reference and then audit `SKILL.md`, `README.md`, and samples for stale summaries or links. -- Before finishing documentation changes, verify relative links and compare `wc -l -w -c skills/rig/SKILL.md skills/rig/references/*.md` with the previous version. +- Before finishing documentation changes, verify relative links and compare `wc -l -w -c skills/rig/*.md` with the previous version. ## Testing diff --git a/README.md b/README.md index a576594..c2e41f5 100644 --- a/README.md +++ b/README.md @@ -22,24 +22,51 @@ checkout; for an installed skill, substitute its directory for `skills/rig`. `skills/rig/SKILL.md` is the canonical, publishable skill manifest. +To run from a checkout: + +```bash +git clone https://github.com/githubnext/rig.git +cd rig +npm ci +``` + +On the Microsoft network or VPN, use the 1ES public npm feed without changing +your npm configuration: + +```bash +npm ci --registry=https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/ --replace-registry-host=npmjs +``` + +The dependency overrides pin compatible versions available in that feed, +including Vite and its test/build dependencies. When updating them, verify both +package metadata and tarball availability before refreshing the lockfile. + ## Use Rig in 2 ways ### 1) As a skill for Rig programs that use the Copilot SDK -Pin the skill in your workflow: +Pin the skill and shared launcher template in your workflow: ```yaml +imports: + - githubnext/rig/.github/workflows/shared/rig.md@ engine: id: copilot copilot-sdk: true skills: - githubnext/rig/skills/rig/SKILL.md@ tools: - bash: ["node"] + bash: ["printf", "node"] ``` -Only `node` needs a Bash grant to launch the installed skill. -Use heredocs or redirections rather than `cat`/`echo` pipelines. Grant additional +The [shared Rig template](.github/workflows/shared/rig.md) provisions Node.js 24 +and allows `printf` and `node`. In this repository, import +`shared/rig.md` instead. Without the template, configure these prerequisites +explicitly; see the [runtime reference](skills/rig/runtime.md#github-agentic-workflows). +Grant `copilot-requests: write` and provision the skill's dependencies in the host. +For Copilot SDK workflows, use `printf '%s\n' ... | node` rather than heredocs, +which gh-aw v0.91.1's SDK permission parser rejects. Single-quote each source +line and escape literal apostrophes as `'"'"'`. Grant additional commands only for the program's own tool calls. This is a smaller tool allowlist, not a security boundary: Node can still start subprocesses. @@ -92,24 +119,23 @@ supported provider API-key variables. Without those settings it uses Copilot over HTTP at `localhost:7777`. To have the launcher start Copilot over stdio, append `--server` to a run command; this requires an installed, authenticated Copilot CLI. Other engines require their SDK dependencies or CLI and credentials; -see the [runtime reference](skills/rig/references/runtime.md). -Its [integration guide](skills/rig/references/runtime.md#choosing-an-integration) +see the [runtime reference](skills/rig/runtime.md). +Its [integration guide](skills/rig/runtime.md#choosing-an-integration) compares engine capabilities, model selection, tool ownership, and output enforcement. -For every heredoc below, replace `RIG_` with a fresh `RIG_` -delimiter generated using `node:crypto`'s `randomBytes(16).toString("hex")`. -Check it is not an entire line of the contents, single-quote the opener, and -repeat the exact unquoted delimiter alone on the closing line. See the -[inline-program guide](skills/rig/references/runtime.md#inline-programs) for the -generation command; do not reuse fixed delimiters or shell variables. +Use the fixed `printf '%s\n'` format with one single-quoted argument per source +line. Escape literal apostrophes as `'"'"'`; do not use source as the format +string or double-quote it. See the +[inline-program guide](skills/rig/runtime.md#inline-programs) for quoting rules +and heredoc alternatives outside the Copilot SDK workflow driver. **Design on the fly** — just describe what you want as a string and let the model figure out the rest: ```bash -node skills/rig/run.ts <<'RIG_' -export default "Run npm test, diagnose any failures, apply the smallest safe fix, and repeat up to 3 times."; -RIG_ +printf '%s\n' \ + 'export default "Run npm test, diagnose any failures, apply the smallest safe fix, and repeat up to 3 times.";' \ + | node skills/rig/run.ts ``` Or ask Copilot (with the skill) to generate a full program for you. Describe your goal in natural language and Copilot returns a runnable `rig` markdown fence like this: @@ -141,20 +167,18 @@ export default ralfLoop; ``` ```` -Pass the fence contents directly to the launcher with a heredoc: +Pass the fence contents directly to the launcher with a literal pipeline: ```bash -node skills/rig/run.ts <<'RIG_' -// Paste the rig fence contents here. -RIG_ +printf '%s\n' \ + '' \ + | node skills/rig/run.ts ``` Or run a program file: ```bash -node skills/rig/run.ts src/program.ts <<'RIG_' -Review this diff -RIG_ +printf '%s\n' 'Review this diff' | node skills/rig/run.ts src/program.ts ``` Use `--typecheck` to validate a program without running it: @@ -170,6 +194,6 @@ tree; Rig does not download it or invoke npm/npx. ## Docs See [skills/rig/SKILL.md](skills/rig/SKILL.md) for construction rules, -[skills/rig/references/runtime.md](skills/rig/references/runtime.md) for launcher and engine details, and -[skills/rig/references/claude-workflow-conversion.md](skills/rig/references/claude-workflow-conversion.md) +[skills/rig/runtime.md](skills/rig/runtime.md) for launcher and engine details, and +[skills/rig/claude-workflow-conversion.md](skills/rig/claude-workflow-conversion.md) for porting Claude Code dynamic workflows to rig. diff --git a/docs/rig-api-review.md b/docs/rig-api-review.md index 1f36d19..54c03fb 100644 --- a/docs/rig-api-review.md +++ b/docs/rig-api-review.md @@ -42,7 +42,7 @@ scripts, which is the primary reason the workflow layer exists. | `budget.total/spent()/remaining()` | Direct Claude parity, even though rig meters agent calls rather than tokens. | **Recommendation:** document these four explicitly as "intentional parity -duplicates" in `references/claude-workflow-conversion.md` so future reviews do +duplicates" in `skills/rig/claude-workflow-conversion.md` so future reviews do not try to collapse them. ## 3. Duplication that should be removed @@ -167,7 +167,7 @@ caveat that `.use()` accepts *only* addons. ## 5. Claude background-workflow compatibility checklist Every proposal above was checked against the Claude primitive mapping in -`references/claude-workflow-conversion.md`: +`skills/rig/claude-workflow-conversion.md`: | Proposal | Claude primitive affected | Verdict | | --- | --- | --- | @@ -246,7 +246,7 @@ churn to a single reviewable PR. ## 8. Related references -- [Converting Claude dynamic workflows to rig](../skills/rig/references/claude-workflow-conversion.md) -- [Dynamic workflows](../skills/rig/references/dynamic-workflows.md) -- [Agent API and schemas](../skills/rig/references/agent-api.md) -- [Prompt intents](../skills/rig/references/prompt-intents.md) +- [Converting Claude dynamic workflows to rig](../skills/rig/claude-workflow-conversion.md) +- [Dynamic workflows](../skills/rig/dynamic-workflows.md) +- [Agent API and schemas](../skills/rig/agent-api.md) +- [Prompt intents](../skills/rig/prompt-intents.md) diff --git a/package-lock.json b/package-lock.json index d0ce832..c54f2cd 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,6 +12,7 @@ "@github/copilot-sdk": "^1.0.16", "@openai/codex-sdk": "^0.159.0", "@types/node": "^25.9.1", + "postcss": "8.5.28", "source-map-js": "file:packages/source-map-compat", "typescript": "^5.8.0", "vitest": "^4.1.11", @@ -1613,16 +1614,6 @@ "node": ">=16" } }, - "node_modules/@oxc-project/types": { - "version": "0.152.0", - "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.152.0.tgz", - "integrity": "sha512-oM/5rLBm2tPkg0iBgkH/FOeR3PCDpY19GTgAZjMFM8h9WI9VW7cLgzp6nwtarYKmovavIQZ+Fe/RKX/8C8O/Rw==", - "dev": true, - "license": "MIT", - "funding": { - "url": "https://github.com/sponsors/oxc-project" - } - }, "node_modules/@protobufjs/aspromise": { "version": "1.1.2", "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@protobufjs/aspromise/-/aspromise-1.1.2.tgz", @@ -1689,279 +1680,6 @@ "dev": true, "license": "BSD-3-Clause" }, - "node_modules/@rolldown/binding-android-arm-eabi": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.12.tgz", - "integrity": "sha512-dB/a1214qKfHMXCpgqR4OZT+jS4kTyEXbQGJPqzobt5EwH5rX080pxE37alt3RzvR1bf1Yz/yGqRfrYAxuPw0A==", - "cpu": [ - "arm" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "android" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-android-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.12.tgz", - "integrity": "sha512-7KHFgQ5VJxIHcLlrwrc3Xbds7oTNQT7Pgi9gQCJKrd2VGab/UksIOYp6VD8MzCstGxOKMgNamPwUCfxPdP1OHg==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "android" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-darwin-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.12.tgz", - "integrity": "sha512-3YIhqHD96nA5SaYNRBR16HnGv4oavZvXfD/ayHM+oYZ0WD/8lBAtf6zQua4kEyAvpqrluKXl0lnOBoiNby7x9w==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "darwin" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-darwin-x64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.12.tgz", - "integrity": "sha512-UuuJ35MFw4gmFOrE9pEqIV+K3syIKveph+Qc1/ljHZVdoDW4pz/JHR/eMVom+TZGl/5OOvGJOWaOCVt3ZfqhxA==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "darwin" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-freebsd-x64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.12.tgz", - "integrity": "sha512-uMvssit0a4W+/7D8CbHUvG719mH3R2jwXAlh/XcPvuHTE0g++LymF88DCGNX0HM2rBOn0xrzgXktIB6fLSJBTQ==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "freebsd" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm-gnueabihf": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.12.tgz", - "integrity": "sha512-XcFu0R0xWnwzSf4IQgFH1rJIckPN1pLy2R+4r9IDB7Yfu/ys9cVqfa4pBrMHj7a3gl8mIR4nRNPg0e5IvEVs6g==", - "cpu": [ - "arm" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.12.tgz", - "integrity": "sha512-260UrKgn8tz39ak+SMDOirKzr7V04M9dWPw5llW00SwBivCZoWcRBKV1d8cXnRkUmSZA3BdiUmBHWk7734Ulpw==", - "cpu": [ - "arm64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm64-musl": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.12.tgz", - "integrity": "sha512-5YK1I9SqDkbPgc1IA8BgDl34suqUS2q0KWnBrirm0E51YjOs6eo6dV6jbQfNE/argHRSvd0QUGgtpIoYx+WWpw==", - "cpu": [ - "arm64" - ], - "dev": true, - "libc": [ - "musl" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-ppc64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.12.tgz", - "integrity": "sha512-Rkcrmp7eFRg74yL5fXEU91JEWbdEPLevWwGtXpmhbjlD1StScbWTmO94Bhly+Mo+ketKYkdmM1vNUKeWSlx8cQ==", - "cpu": [ - "ppc64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-s390x-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.12.tgz", - "integrity": "sha512-qvK4DuAsQc2BSjlx+Xr+IzOIvvxbGZqxFwdWfG6F518Erj0GGISyQbJ6pIappnOxlNPzNHvo/L0BwB30GZ+zVw==", - "cpu": [ - "s390x" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-x64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.12.tgz", - "integrity": "sha512-Q9uLBO53Xd4QIq1WOycVQyPP1O4HhraEV2qqb3uTrnVw6QZih9duY4vNXOivL1xoUS1/z+W8eF4NMfl2a8Sdjw==", - "cpu": [ - "x64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-x64-musl": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.12.tgz", - "integrity": "sha512-3IBxWFMjbOZskDPKv8Lf9BCnahlKuHthWkYnyIxOH/QcJrFcS4EmcenthApkwr/5+nEqZlLzeYbxeMaX7A5u4g==", - "cpu": [ - "x64" - ], - "dev": true, - "libc": [ - "musl" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-openharmony-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.12.tgz", - "integrity": "sha512-xtX61xg4LKPkPWilZU1ynKClz5Gj4bf74LML4r3eVLWumKnGjoEr1OSHQhMdbBDoYTi+yjrujvpZe2pUnqCrrA==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "openharmony" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-win32-arm64-msvc": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.12.tgz", - "integrity": "sha512-At7fPB6PCaIjzgIhEZFxuT+BBFqiQibJDT4d3PhiR3f4E7bbMZF4aKblbFfEM3sETRDd1YiQx/+U/g/B/ou5Ew==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "win32" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-win32-x64-msvc": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.12.tgz", - "integrity": "sha512-WIw2haVKwjuYdXkHaoC0mF8Le71TuCBxjrdKqLbJGctbBABj+ClfmNvtbOnzpq3RokNo5+V1qhtSzJyXorsklQ==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "win32" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, "node_modules/@rolldown/pluginutils": { "version": "1.0.1", "resolved": "https://registry.npmjs.org/@rolldown/pluginutils/-/pluginutils-1.0.1.tgz", @@ -2130,6 +1848,26 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/expect/node_modules/chai": { + "version": "6.2.2", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/chai/-/chai-6.2.2.tgz", + "integrity": "sha1-rkG1LJrKh3NFBTYnF/MlX6zaNg4=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=18" + } + }, + "node_modules/@vitest/expect/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/@vitest/mocker": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-4.1.11.tgz", @@ -2170,6 +1908,16 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/pretty-format/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/@vitest/runner": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/@vitest/runner/-/runner-4.1.11.tgz", @@ -2225,6 +1973,16 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/utils/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/agent-base": { "version": "9.0.0", "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/agent-base/-/agent-base-9.0.0.tgz", @@ -2290,16 +2048,6 @@ "dev": true, "license": "BSD-3-Clause" }, - "node_modules/chai": { - "version": "6.3.0", - "resolved": "https://registry.npmjs.org/chai/-/chai-6.3.0.tgz", - "integrity": "sha512-XWAtwJ6OHO+tj0EKCs0Y2UamnyOxseZWltU4x2U2wh8g4AigdjwvtUjvLP2tqkA/avxHEtzxNaqGq/YGNwckKg==", - "dev": true, - "license": "MIT", - "engines": { - "node": ">=18" - } - }, "node_modules/convert-source-map": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/convert-source-map/-/convert-source-map-2.0.0.tgz", @@ -3016,9 +2764,9 @@ "license": "MIT" }, "node_modules/nanoid": { - "version": "3.3.20", - "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.20.tgz", - "integrity": "sha512-uKdg2G3GNCKQn9byYOpxbGqrT2fGO5KRt5J/8b3pok8rT6qxGWF6hxMyJiEYtAf+FVyYuD9hRaDqX5uPFYJ4ZQ==", + "version": "3.3.19", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/nanoid/-/nanoid-3.3.19.tgz", + "integrity": "sha512-Y2tUNy4ouw6tq5oDSKeQYGOyhkUBhNOcGV/02KC+6kd9eDGqdZd++mjMiIDilrBYvjEnCYvVtsuHCuP+okSfug==", "dev": true, "funding": [ { @@ -3153,9 +2901,9 @@ } }, "node_modules/postcss": { - "version": "8.5.29", - "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.29.tgz", - "integrity": "sha512-49cGhUbXj8Qenv0iTMxA1cFBzxXoctpC9Ujd77t1WcbJIr6nF/eI7g/8MgxrYldFRuAXvja7xQRwavoW7kgrxQ==", + "version": "8.5.28", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/postcss/-/postcss-8.5.28.tgz", + "integrity": "sha1-2kVjqZoG5i1sHNGsrjYyJLyu1uk=", "dev": true, "funding": [ { @@ -3173,9 +2921,9 @@ ], "license": "MIT", "dependencies": { - "nanoid": "^3.3.19", + "nanoid": "^3.3.18", "picocolors": "^1.1.1", - "source-map-js": "^1.2.2" + "source-map-js": "^1.2.1" }, "engines": { "node": "^10 || ^12 || >=14" @@ -3233,44 +2981,10 @@ "node": ">= 4" } }, - "node_modules/rolldown": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.12.tgz", - "integrity": "sha512-8wafseiaG80xmXSfqidUNqZcylTlhmPZZt+za2m+js2sFZ8dTNlhIOV2WcbIPx2hgwPBJpEUGFAMZ9bgBBLTSQ==", - "dev": true, - "license": "MIT", - "dependencies": { - "@oxc-project/types": "=0.152.0", - "@rolldown/pluginutils": "^1.0.0" - }, - "bin": { - "rolldown": "bin/cli.mjs" - }, - "engines": { - "node": "^20.19.0 || >=22.12.0" - }, - "optionalDependencies": { - "@rolldown/binding-android-arm-eabi": "1.2.12", - "@rolldown/binding-android-arm64": "1.2.12", - "@rolldown/binding-darwin-arm64": "1.2.12", - "@rolldown/binding-darwin-x64": "1.2.12", - "@rolldown/binding-freebsd-x64": "1.2.12", - "@rolldown/binding-linux-arm-gnueabihf": "1.2.12", - "@rolldown/binding-linux-arm64-gnu": "1.2.12", - "@rolldown/binding-linux-arm64-musl": "1.2.12", - "@rolldown/binding-linux-ppc64-gnu": "1.2.12", - "@rolldown/binding-linux-s390x-gnu": "1.2.12", - "@rolldown/binding-linux-x64-gnu": "1.2.12", - "@rolldown/binding-linux-x64-musl": "1.2.12", - "@rolldown/binding-openharmony-arm64": "1.2.12", - "@rolldown/binding-win32-arm64-msvc": "1.2.12", - "@rolldown/binding-win32-x64-msvc": "1.2.12" - } - }, - "node_modules/safe-buffer": { - "version": "5.2.1", - "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/safe-buffer/-/safe-buffer-5.2.1.tgz", - "integrity": "sha1-Hq+fqb2x/dTsdfWPnNtOa3gn7sY=", + "node_modules/safe-buffer": { + "version": "5.2.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/safe-buffer/-/safe-buffer-5.2.1.tgz", + "integrity": "sha1-Hq+fqb2x/dTsdfWPnNtOa3gn7sY=", "dev": true, "funding": [ { @@ -3358,16 +3072,6 @@ "url": "https://github.com/sponsors/SuperchupuDev" } }, - "node_modules/tinyrainbow": { - "version": "3.2.0", - "resolved": "https://registry.npmjs.org/tinyrainbow/-/tinyrainbow-3.2.0.tgz", - "integrity": "sha512-LgO3D9yZJjApUiuUfl9iFAwrtaX4+lok3wJIqttGoKCHlWUqHqbQpnxCf82L8FjgKsh4iGo78hqJwgL8F6To2A==", - "dev": true, - "license": "MIT", - "engines": { - "node": ">=14.0.0" - } - }, "node_modules/ts-algebra": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/ts-algebra/-/ts-algebra-2.0.0.tgz", @@ -3411,16 +3115,16 @@ "license": "MIT" }, "node_modules/vite": { - "version": "8.3.3", - "resolved": "https://registry.npmjs.org/vite/-/vite-8.3.3.tgz", - "integrity": "sha512-cTAldKPImjg6c+gk48U19POPn3GCBzZwpdsN8ZMEEcbpes+6/wvfqUd0C2y3qYY4wsj8PwgFwrZ/1jBPVttMSg==", + "version": "8.3.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/vite/-/vite-8.3.1.tgz", + "integrity": "sha512-/bvH9E9tmCXRGp2uXY3WbOldqpTwFkbha/8ANaEQ6VkxhH60KyqLwgZq6lG2y+4uT55x9+9eUHMpQ7uGnOCKjA==", "dev": true, "license": "MIT", "dependencies": { "lightningcss": "^1.33.0", "picomatch": "^4.0.7", "postcss": "^8.5.28", - "rolldown": "~1.2.11", + "rolldown": "~1.2.9", "tinyglobby": "^0.2.17" }, "bin": { @@ -3488,6 +3192,323 @@ } } }, + "node_modules/vite/node_modules/@oxc-project/types": { + "version": "0.151.0", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@oxc-project/types/-/types-0.151.0.tgz", + "integrity": "sha512-J1yXrIlNDZVzE3ada310xeAw7nH8yCAyLPuUIsjKatFPmfn5bS1oW+cM+QsGOtVWd5nhSpbwZWx/rue+r5Z+PA==", + "dev": true, + "license": "MIT", + "funding": { + "url": "https://github.com/sponsors/oxc-project" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-android-arm-eabi": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.11.tgz", + "integrity": "sha512-A5kXfGKvKWWZE0TtPrfsvT+q4Y5d1QG8gGUzpYjGydM+fARM9MuX90PrXYXe0XbsDVgyxxNzHo6giCj90bsFNw==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-android-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.11.tgz", + "integrity": "sha512-z6cTycz+iJ4PVkuL4HHW4DfTfoeU/2nqYYuSOrTmH7yHK5Y0LCOnA03V4ZNxavyVaU1oOqUgIg2klN/s+USGOA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-darwin-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.11.tgz", + "integrity": "sha512-jShvqNtP6vDC6/A5JOAzbVV+DkgHqhl/ScVCJEbt+TUY6QYz7YnXcrg3sLtFBniro0f/Ld50ZwCWA6f7KYD1nQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-darwin-x64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.11.tgz", + "integrity": "sha512-f2i2xiNWq1Z1l2++q2fuhZRdLAT3aqxD6vRNm1RAxpUoBcdqNB3C0s1Bt+K+PbEx2F5F4gQp6hqKkphCY/xF9w==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-freebsd-x64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.11.tgz", + "integrity": "sha512-4Ir5FSOKIAMr4r0kExpt1s3bMgzJU3rA45AYOHtQpls0oNeqcYBKrWMlckrYH4KCfGLfkfn1tN1dmZPMVsdXow==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm-gnueabihf": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.11.tgz", + "integrity": "sha512-/gnRDM+39BROzAN/k1OZjDPnDMcZxB/0EUxKjONO5yVkNEvlsoMDrxGNKgZi/ttFriS2gwlDNzB65pvNbFOXIQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.11.tgz", + "integrity": "sha512-PFaK8HwvAHbaKbBcDNQihjMKYvFnA5hiENx/l5tphTDz1E0WFp32l0A7aq7lyUwGsRw/xSrNIy/gIK4thrSCrw==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm64-musl": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.11.tgz", + "integrity": "sha512-AskzJUIKRLPxkruR1wLKewGbOw+EYfU/9lOrBFj4AFrEA8hPpKFnODWNu2WLaNs0QNkEb9QIJufmVZZIL/bJlg==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-ppc64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.11.tgz", + "integrity": "sha512-qlUGAheh2yh8afH7QBgx0PrRHN85hKnNd78x8MeMhXivuevgd8vgf6/CstOzmNKY/lLTHvNTrPy98cLnAugzJw==", + "cpu": [ + "ppc64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-s390x-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.11.tgz", + "integrity": "sha512-secpEad+0vCbSfn8upFySkDskv+bGPk3THSDS9Y89yc4rb4kzqHp8Dmyd9BkQW4SnhNXBZCl/6CrO//hZahNJQ==", + "cpu": [ + "s390x" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-x64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.11.tgz", + "integrity": "sha512-mOVBT3dPpkWm8XBWPmU4bf+U6dYDLeMo/9ojUmis4N0L5uu10qra5vOyngZ7/PSdoE4G9KvRt4bloRxNjLas7A==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-x64-musl": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.11.tgz", + "integrity": "sha512-Is78i9A8Ui4SqcxUwFJ9uMmjDn58IbVTjFWYdQestFEgeuEmHMLGNriXnVJKkwG2YiZjw8cP0zCTyDMdDGtOOg==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-openharmony-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.11.tgz", + "integrity": "sha512-dUCXneZ87INUMyQ0D+C0HrEBNUPNXHaPmU5GTjyKTJEiussw9Kaj5Ln8UztPe4epV/ffvgNBEadksdYhmW6xJA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-win32-arm64-msvc": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.11.tgz", + "integrity": "sha512-jByxb6qfd+bH1xUd0qnfFnb17i9sWBPY2tOavJ0l3tdr3OTu+Kvtm8cd/JV5nFt657b1VqGltxg9olOEfofXWw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-win32-x64-msvc": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.11.tgz", + "integrity": "sha512-/PzKqzAJ03i19oy2ItPvyvaVjOjBCNnfaJs8yvUdGBKmiESgnrJSQ2awd81QzFbbnAmu7YO9ZnJrDCb9VSJPRA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/rolldown": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/rolldown/-/rolldown-1.2.11.tgz", + "integrity": "sha512-qpSwIyz0jHQq5qXBTNxFmE6664rJ7O+4TvPFOiOaBSrz8IOHc1koKKSqTM2H6u1UG1+TveuC6vaDHKXFOvb1Kw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@oxc-project/types": "=0.151.0", + "@rolldown/pluginutils": "^1.0.0" + }, + "bin": { + "rolldown": "bin/cli.mjs" + }, + "engines": { + "node": "^20.19.0 || >=22.12.0" + }, + "optionalDependencies": { + "@rolldown/binding-android-arm-eabi": "1.2.11", + "@rolldown/binding-android-arm64": "1.2.11", + "@rolldown/binding-darwin-arm64": "1.2.11", + "@rolldown/binding-darwin-x64": "1.2.11", + "@rolldown/binding-freebsd-x64": "1.2.11", + "@rolldown/binding-linux-arm-gnueabihf": "1.2.11", + "@rolldown/binding-linux-arm64-gnu": "1.2.11", + "@rolldown/binding-linux-arm64-musl": "1.2.11", + "@rolldown/binding-linux-ppc64-gnu": "1.2.11", + "@rolldown/binding-linux-s390x-gnu": "1.2.11", + "@rolldown/binding-linux-x64-gnu": "1.2.11", + "@rolldown/binding-linux-x64-musl": "1.2.11", + "@rolldown/binding-openharmony-arm64": "1.2.11", + "@rolldown/binding-win32-arm64-msvc": "1.2.11", + "@rolldown/binding-win32-x64-msvc": "1.2.11" + } + }, "node_modules/vitest": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/vitest/-/vitest-4.1.11.tgz", @@ -3578,6 +3599,16 @@ } } }, + "node_modules/vitest/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/vscode-jsonrpc": { "version": "8.2.1", "resolved": "https://registry.npmjs.org/vscode-jsonrpc/-/vscode-jsonrpc-8.2.1.tgz", diff --git a/package.json b/package.json index ffbf64e..364618f 100644 --- a/package.json +++ b/package.json @@ -26,12 +26,19 @@ "@github/copilot-sdk": "^1.0.16", "@openai/codex-sdk": "^0.159.0", "@types/node": "^25.9.1", + "postcss": "8.5.28", "source-map-js": "file:packages/source-map-compat", "typescript": "^5.8.0", "vitest": "^4.1.11", "zx": "^8.8.5" }, "overrides": { - "source-map-js": "$source-map-js" + "source-map-js": "$source-map-js", + "vite": "8.3.1", + "chai": "6.2.2", + "nanoid": "3.3.19", + "postcss": "$postcss", + "rolldown": "1.2.11", + "tinyrainbow": "3.1.1" } } diff --git a/skills/rig/SKILL.md b/skills/rig/SKILL.md index ef90c9a..c567dbe 100644 --- a/skills/rig/SKILL.md +++ b/skills/rig/SKILL.md @@ -46,6 +46,12 @@ export default reviewDiff; Defaults: `name: "agent"`, `model: "small"`, `maxTurns: 4`, string input/output, and no addons. +For GitHub Agentic Workflows, tell the user to import the +[shared Rig template](../../.github/workflows/shared/rig.md) or explicitly allow +`node` in `tools.bash` and provision Node.js 24+ with the skill's dependencies. +See [Running and engines](./runtime.md) for +the import syntax and Copilot SDK configuration. + ## High-frequency decisions | Need | Choose | @@ -93,17 +99,19 @@ node skills/rig/run.ts --typecheck < program.ts ``` For an installed skill, replace `skills/rig` with its installed directory. Use -`run.ts` to launch without installing packages; inline programs use -`node /run.ts <<'RIG_'`. For each heredoc, generate a -fresh `RIG_` delimiter with `node:crypto`'s `randomBytes(16).toString("hex")`. -Ensure it is not a complete line in the contents; regenerate on collision. -Single-quote the opening delimiter and repeat the same literal, unquoted -delimiter alone on the closing line. Never use a fixed delimiter or shell -variable; see [Running and engines](references/runtime.md). +`run.ts` to launch without installing packages. For Copilot SDK workflows, pipe +literal source with `printf '%s\n' '' ... | node /run.ts`. +Use one single-quoted argument per source line, escaping each literal apostrophe +as `'"'"'`. Keep `%s\n` as the fixed format; never use source as a format string, +double-quote source, or expand shell variables. Do not use heredocs with the +SDK driver; see [Running and engines](./runtime.md) for quoting and alternatives. Install the skill with `gh skill install githubnext/rig rig`. Assume SDKs are already installed in the agent container; do not install them. -Only `node` needs a Bash tool grant for launching an installed skill; grant -additional commands only when the program itself needs them. +Import the shared Rig workflow template or explicitly allow `printf` and `node` +with `bash: ["printf", "node"]`. Grant other commands only when the program needs +them. The launch pipeline must begin with `printf`: no `mkdir`, `cd`, `env`, +package manager, or other preparation, and no `&&` prefix. Use existing output +directories and inherit the SDK environment. Report denied commands accurately. ## Final check @@ -118,10 +126,10 @@ additional commands only when the program itself needs them. Read only when the task needs the listed detail: -- [Agent API and schemas](references/agent-api.md) — spec fields, schema overloads, tools, and invocation options. -- [Prompt intents](references/prompt-intents.md) — complete helper semantics, dynamic inputs, writes, and failure behavior. -- [Composition and addons](references/composition.md) — delegation patterns, dynamic sets, repair, steering, and addon lifecycle. -- [Dynamic workflows](references/dynamic-workflows.md) — bounded fan-out, failure semantics, limits, budget, events, and convergence loops. -- [Claude workflow conversion](references/claude-workflow-conversion.md) — mapping Claude Code dynamic-workflow scripts onto rig primitives, including model selection and the Anthropic engine. -- [Running and engines](references/runtime.md) — markdown/file launch modes, typechecking, Agentic Workflows, and SDK adapters. -- [Linting](references/linting.md) — linter usage, autofixes, rules, and rule development. +- [Agent API and schemas](./agent-api.md) — spec fields, schema overloads, tools, and invocation options. +- [Prompt intents](./prompt-intents.md) — complete helper semantics, dynamic inputs, writes, and failure behavior. +- [Composition and addons](./composition.md) — delegation patterns, dynamic sets, repair, steering, and addon lifecycle. +- [Dynamic workflows](./dynamic-workflows.md) — bounded fan-out, failure semantics, limits, budget, events, and convergence loops. +- [Claude workflow conversion](./claude-workflow-conversion.md) — mapping Claude Code dynamic-workflow scripts onto rig primitives, including model selection and the Anthropic engine. +- [Running and engines](./runtime.md) — markdown/file launch modes, typechecking, Agentic Workflows, and SDK adapters. +- [Linting](./linting.md) — linter usage, autofixes, rules, and rule development. diff --git a/skills/rig/references/agent-api.md b/skills/rig/agent-api.md similarity index 100% rename from skills/rig/references/agent-api.md rename to skills/rig/agent-api.md diff --git a/skills/rig/references/claude-workflow-conversion.md b/skills/rig/claude-workflow-conversion.md similarity index 87% rename from skills/rig/references/claude-workflow-conversion.md rename to skills/rig/claude-workflow-conversion.md index 92f2726..df8b662 100644 --- a/skills/rig/references/claude-workflow-conversion.md +++ b/skills/rig/claude-workflow-conversion.md @@ -16,12 +16,12 @@ Choose the migration path that matches your script's structure: | My script looks like… | Start here | | --- | --- | -| Top-level `phase` / `call` / `pipeline` at module scope (flat script) | [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) — swap injected globals for `"rig/globals"` imports with minimal changes | -| `body` function with `args` and structured output (canonical pattern) | [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) — direct `args`→`input` + `agent`→`call.json` port | -| Nested `workflow(ref, args)` calls | [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) — `call.workflow` shares the parent's limiter and budget | -| `log`, `budget`, open-ended `while` loop | [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) — `log`/`budget.remaining()` + bounded `until` loop | -| Two or more chained `pipeline` stages | [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) — note the `(prev, item, index)` stage signature | -| Running on Claude (not Copilot) | [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) — `anthropicEngine()` + full Claude model IDs | +| Top-level `phase` / `call` / `pipeline` at module scope (flat script) | [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) — swap injected globals for `"rig/globals"` imports with minimal changes | +| `body` function with `args` and structured output (canonical pattern) | [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) — direct `args`→`input` + `agent`→`call.json` port | +| Nested `workflow(ref, args)` calls | [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) — `call.workflow` shares the parent's limiter and budget | +| `log`, `budget`, open-ended `while` loop | [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) — `log`/`budget.remaining()` + bounded `until` loop | +| Two or more chained `pipeline` stages | [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) — note the `(prev, item, index)` stage signature | +| Running on Claude (not Copilot) | [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) — `anthropicEngine()` + full Claude model IDs | Then read [Behavior differences](#behavior-differences-to-keep-in-mind) before you finalize the port. @@ -233,7 +233,7 @@ pick a model tier that matches the task's quality requirement. where `previous` is the prior stage's output (or the item itself for stage 1). Claude's stage signature is `(item, index)`, so when porting add `_prev` as the first parameter and access the prior result through it in stage 2+. See - [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) + [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) for a worked example. - **Budget units.** rig counts agent calls, not tokens, so guard loops with `budget.remaining() > n` where `n` is a call count. @@ -295,13 +295,13 @@ workflow patterns — use them as starting points when converting a script: | Sample | Demonstrates | | --- | --- | -| [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | -| [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | -| [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | -| [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | -| [360-parallel-branch-analysis-workflow.md](../samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | -| [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | -| [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | +| [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | +| [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | +| [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | +| [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | +| [360-parallel-branch-analysis-workflow.md](./samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | +| [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | +| [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | ## Related references diff --git a/skills/rig/references/composition.md b/skills/rig/composition.md similarity index 100% rename from skills/rig/references/composition.md rename to skills/rig/composition.md diff --git a/skills/rig/references/dynamic-workflows.md b/skills/rig/dynamic-workflows.md similarity index 86% rename from skills/rig/references/dynamic-workflows.md rename to skills/rig/dynamic-workflows.md index 1321ef9..7471576 100644 --- a/skills/rig/references/dynamic-workflows.md +++ b/skills/rig/dynamic-workflows.md @@ -218,10 +218,10 @@ workflow patterns — use them as starting points when converting a script: | Sample | Demonstrates | | --- | --- | -| [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | -| [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | -| [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | -| [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | -| [360-parallel-branch-analysis-workflow.md](../samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | -| [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | -| [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | +| [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | +| [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | +| [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | +| [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | +| [360-parallel-branch-analysis-workflow.md](./samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | +| [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | +| [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | diff --git a/skills/rig/references/linting.md b/skills/rig/linting.md similarity index 100% rename from skills/rig/references/linting.md rename to skills/rig/linting.md diff --git a/skills/rig/references/prompt-intents.md b/skills/rig/prompt-intents.md similarity index 100% rename from skills/rig/references/prompt-intents.md rename to skills/rig/prompt-intents.md diff --git a/skills/rig/references/runtime.md b/skills/rig/runtime.md similarity index 78% rename from skills/rig/references/runtime.md rename to skills/rig/runtime.md index a4dc436..e1a5bc3 100644 --- a/skills/rig/references/runtime.md +++ b/skills/rig/runtime.md @@ -4,27 +4,44 @@ Read this reference when launching or typechecking programs, handling stdin, or ## Inline programs -Treat a fenced `rig` block as a runnable program. Pass its contents to the launcher with a heredoc: - -Before constructing each heredoc command, generate a fresh delimiter using -Node's cryptographic random source (no additional Bash tool grant): +Treat a fenced `rig` block as a runnable program. For Copilot SDK workflows, +pass its contents to the launcher through a literal `printf` pipeline: ```bash -node --input-type=module -e 'import { randomBytes } from "node:crypto"; console.log("RIG_" + randomBytes(16).toString("hex"));' +printf '%s\n' \ + '// Agent role: summarize this repository in one sentence.' \ + 'export default "Summarize this repository in one sentence.";' \ + | node skills/rig/run.ts ``` +Use one single-quoted argument per source line, including `''` for empty lines. +Escape each literal apostrophe as `'"'"'`; for example, the source line +`const label = "don't";` becomes `'const label = "don'"'"'t";'`. +Always use the fixed format `'%s\n'`, never the source as a format string. +This preserves percent signs, backslashes, dollar signs, and backticks literally. +Do not double-quote source, expand variables, encode it, or execute substitutions. +Each argument emits its original line followed by a newline. Copy the whole +fence without markdown markers; do not rewrite the TypeScript. + +Heredocs remain an alternative outside the Copilot SDK workflow driver: + +Before constructing each heredoc command, generate a fresh 7-character +pseudo-random alphanumeric string to use as the delimiter. Choose the seven +characters yourself while composing the command; do not call a tool or run +Python, Node, `/dev/urandom`, `base64`, `tr`, or a shell pipeline to generate them. + Check that the generated delimiter is not an entire line of the contents, including a possible trailing `\r`; regenerate if it collides. Substitute the -result for `RIG_` below. Single-quote the opener to suppress shell +result for `` below. Single-quote the opener to suppress shell expansion, and put the same literal delimiter, unquoted and unindented, alone on the closing line. Do not reuse a fixed delimiter or use a shell variable as the delimiter: Bash does not expand delimiter words. ```bash -node skills/rig/run.ts <<'RIG_' +node skills/rig/run.ts <<'' // Agent role: summarize this repository in one sentence. export default "Summarize this repository in one sentence."; -RIG_ + ``` Inline mode: @@ -55,10 +72,32 @@ container. Do not attempt to install them from the driver or agent prompt. Missing dependencies stop the run with a nonzero exit and an error on stderr. `rig.ts` remains the direct runtime entry point. Node.js 24 or later is required. -For agentic workflows, the launch Bash allowlist is just -`bash: ["node"]`. Heredocs and input/output redirections avoid `cat`, `echo`, -and separate file-creation commands. Neither launch nor typechecking invokes +For inline agentic workflows, explicitly grant both stages with +`bash: ["printf", "node"]`, or import the shared Rig template below. This avoids +`cat`, `echo`, and separate file-creation commands. Neither launch nor typechecking invokes npm or npx, and neither downloads dependencies. +Start the inline launch pipeline with `printf`; do not prepend `mkdir`, `cd`, +`env`, dependency checks, or any other command with `&&`. Read the installed +skill and its reference with file-reading tools, not shell bootstrap commands. +For a provided, unchanged, prevalidated fixture, skip lint and typecheck +preflights and execute the launcher once. For newly generated programs, retain +the skill's lint and typecheck checks. + +Redirect output only into an existing directory. In GitHub Agentic Workflows, +`/tmp/gh-aw/agent` is already provisioned; never run `mkdir` for it. If another +required directory is missing, report that prerequisite instead of adding a +disallowed preparation command. Inherit SDK environment variables without +`env` or `export` commands. If an unrelated command is denied before the launcher +runs, remove that command and use the permitted `printf` plus `node` pipeline; do not +claim that Bash is unavailable. If the launcher itself fails, report its exact +error and respect the workflow's retry policy. + +GitHub Agentic Workflows v0.91.1's Copilot SDK permission parser treats heredoc +body lines as shell commands. Use the explicitly permitted `printf` plus `node` +pipeline instead, not a heredoc or a blanket shell grant. If either stage is +denied, report the exact command and required grant, not a missing Node runtime +or SDK. Respect the workflow's retry policy. + This reduces tool configuration, not sandbox permissions: allowing arbitrary Node code still permits filesystem and subprocess operations. Add commands required by the program's own tool calls separately. @@ -68,9 +107,7 @@ required by the program's own tool calls separately. Export the root and pass stdin plus the file path: ```bash -node skills/rig/run.ts src/program.ts <<'RIG_' -Review this diff -RIG_ +printf '%s\n' 'Review this diff' | node skills/rig/run.ts src/program.ts ``` Stdin coercion follows the root schema: @@ -110,25 +147,51 @@ For a standalone `.ts` program outside an ESM package, the launcher uses a tempo ## GitHub Agentic Workflows -Enable Copilot SDK driver mode and pin the Rig skill to an immutable commit: +Tell the user to import the [shared Rig template](../../.github/workflows/shared/rig.md) +and pin both the template and skill to an immutable commit. The template provisions +Node.js 24 and enables the `node` command needed to launch programs using +host-provisioned dependencies: ```yaml +imports: + - githubnext/rig/.github/workflows/shared/rig.md@ engine: id: copilot copilot-sdk: true skills: - githubnext/rig/skills/rig/SKILL.md@ tools: - bash: ["node"] + bash: ["printf", "node"] ``` Import `configureAgent` and `copilotEngine` in the fenced program and call `configureAgent(copilotEngine())` before defining agents. Launch with the installed skill's `run.ts` and host-provisioned dependencies. Grant `copilot-requests: write`, and enable only the additional tools and network access the program uses. +In this repository, use `imports: [shared/rig.md]`. If the user does not import +the template, tell them to configure the equivalent prerequisites explicitly: + +```yaml +runtimes: + node: + version: "24" +tools: + bash: ["printf", "node"] +network: + allowed: [defaults, github, node] +``` + +The template does not install dependencies or select the skill or engine. +Provision dependencies in the host before running; do not install them from +the agent prompt. Report missing dependencies and stop. +Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not use `--server` +or start another server. Inspect only named environment variables, never dump +credentials. A denied command does not mean all shell execution is blocked: +report the exact denial and check it against `tools.bash`. + Edit workflows with an agent or run `gh aw compile --watch` for immediate feedback. Before committing, run `gh aw compile --strict` and include the generated `.lock.yml`. For testing changes to the skill itself, declare `skills: [skills/rig]` to install the current checkout instead of a released commit. The repository's -[Rig Skill Integration workflow](../../../.github/workflows/rig-skill-integration.md) +[Rig Skill Integration workflow](../../.github/workflows/rig-skill-integration.md) does this daily or on manual dispatch. Its no-input `rig` fence runs exactly three `small` judges through the SDK endpoint, with `maxTurns: 1`, no repair addon, and deterministic majority voting. A post-step validates the result and diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index 73ee28d..9e5da2d 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -1,5 +1,6 @@ import assert from "node:assert/strict"; import { readFileSync } from "node:fs"; +import { execFileSync } from "node:child_process"; import { Readable, Writable } from "node:stream"; import { runInNewContext } from "node:vm"; import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"; @@ -70,11 +71,43 @@ afterEach(() => { }); describe("Rig skill agentic workflow", () => { - it("requires only node for installed-skill bootstrap and launch", () => { - expect(markdown).toContain('bash: ["node"]'); - expect(markdown).toContain("node /run.ts <<'RIG_'"); - expect(markdown).toContain('randomBytes(16).toString("hex")'); - expect(markdown).toContain("regenerate on collision"); + it("explicitly grants both stages of the installed-skill launch pipeline", () => { + expect(markdown).toContain('bash: ["printf", "node"]'); + expect(markdown).toContain("printf '%s\\n' \\"); + expect(markdown).toContain("| node .github/skills/rig/run.ts >"); + expect(markdown).toContain("Do not use a heredoc"); + const shared = readFileSync(new URL("../.github/workflows/shared/rig.md", import.meta.url), "utf8"); + expect(shared).toContain('bash: ["printf", "node"]'); + }); + + it.each([program, 'const value = "don\'t expand $HOME, $(exit 42), `exit 42`, %s, \\\\n";\n\n// literal | && ; < >'])( + "transports literal source through printf without shell expansion: %s", + source => { + const arguments_ = source.split("\n").map((line: string) => `'${line.replaceAll("'", "'\"'\"'")}'`).join(" \\\n "); + const command = `printf '%s\\n' \\\n ${arguments_} \\\n | "${process.execPath}" --input-type=module -e 'for await (const chunk of process.stdin) process.stdout.write(chunk)'`; + expect(execFileSync("bash", ["-o", "pipefail", "-c", command], { encoding: "utf8" })).toBe(`${source}\n`); + }, + ); + + it("keeps runtime printf examples executable and literal", () => { + const runtime = readFileSync(new URL("../skills/rig/runtime.md", import.meta.url), "utf8"); + const example = runtime.match(/```bash\n(printf[\s\S]*?)\n```/)?.[1]; + expect(example).toBeDefined(); + const command = example!.replace("| node skills/rig/run.ts", `| "${process.execPath}" --input-type=module -e 'for await (const chunk of process.stdin) process.stdout.write(chunk)'`); + expect(execFileSync("bash", ["-o", "pipefail", "-c", command], { encoding: "utf8" })) + .toBe('// Agent role: summarize this repository in one sentence.\nexport default "Summarize this repository in one sentence.";\n'); + }); + + it("directs one standalone launch without repeating denied preparation", () => { + expect(markdown).toContain("Your only Bash invocation"); + expect(markdown).toContain("The command must begin with `printf`"); + expect(markdown).toContain("Do not prepend `mkdir`, `cd`, `env`, `export`"); + expect(markdown).toContain("already exists, and Node.js and SDK dependencies are already provisioned"); + expect(markdown).toContain("Do not double-quote source"); + expect(markdown).toContain("Do not invoke Bash again"); + expect(markdown).toContain("Never call `noop` on failure"); + expect(markdown).toContain("The one-invocation limit includes denials"); + expect(markdown).toContain("Do not read the result file, run `cat` or another command"); }); it("runs the actual workflow fence with exactly three small SDK calls", async () => { diff --git a/src/skill.test.ts b/src/skill.test.ts index ea11918..3e4fb8e 100644 --- a/src/skill.test.ts +++ b/src/skill.test.ts @@ -18,18 +18,29 @@ it("keeps the exportable Rig skill as the only manifest", () => { }); it("keeps every canonical skill reference available", () => { - const links = [...canonicalManifest.matchAll(/\]\((references\/[^)]+)\)/g)]; + const links = [...canonicalManifest.matchAll(/\]\((\.\/[^)]+)\)/g)]; expect(links.length).toBeGreaterThan(0); for (const link of links) { expect(existsSync(resolve(skillRoot, link[1]!)), link[1]).toBe(true); } }); -it("requires fresh crypto-generated and quoted heredoc delimiters", () => { - expect(canonicalManifest).toContain('randomBytes(16).toString("hex")'); - expect(canonicalManifest).toContain("regenerate on collision"); - expect(canonicalManifest).toContain("Single-quote the opening delimiter"); - expect(canonicalManifest).not.toContain("<<'RIG'"); +it("requires literal printf source transport for Copilot SDK workflows", () => { + expect(canonicalManifest).toContain("printf '%s\\n'"); + expect(canonicalManifest).toContain("one single-quoted argument per source line"); + expect(canonicalManifest).toContain("`'\"'\"'`"); + expect(canonicalManifest).toContain("Do not use heredocs"); + expect(canonicalManifest).toContain('bash: ["printf", "node"]'); +}); + +it("requires a literal launch pipeline without shell preparation", () => { + expect(canonicalManifest).toContain("The launch pipeline must begin with `printf`"); + expect(canonicalManifest).toContain("no `&&` prefix"); + const runtime = readFileSync(resolve(skillRoot, "runtime.md"), "utf8"); + expect(runtime).toContain("`/tmp/gh-aw/agent` is already provisioned"); + expect(runtime).toContain("prevalidated fixture, skip lint and typecheck"); + expect(runtime).toContain("permission parser treats heredoc"); + expect(runtime).toContain("pipeline instead, not a heredoc or a blanket shell grant"); }); it("exposes the same public modules from the standalone skill and repository", () => { diff --git a/vitest.config.ts b/vitest.config.ts index 333b998..cbb6414 100644 --- a/vitest.config.ts +++ b/vitest.config.ts @@ -2,6 +2,14 @@ import { defineConfig } from "vitest/config"; import { resolve } from "path"; export default defineConfig({ + test: { + server: { + deps: { + // Keep ESM imports and require() on Node's shared CommonJS cache. + external: [/\/packages\/source-map-compat\//], + }, + }, + }, resolve: { alias: [ { find: /^rig$/, replacement: resolve(__dirname, "skills/rig/rig.ts") },