From 326d76c1613bc694483c38fe7613afa5bae6afff Mon Sep 17 00:00:00 2001 From: jcant0n Date: Sun, 2 Aug 2026 22:41:45 +0200 Subject: [PATCH] chore: update agents to toolbox v1.7.1 --- .github/workflows/binding-updater.lock.yml | 20 ++++++++-------- .github/workflows/binding-updater.md | 2 +- .github/workflows/ci-doctor.lock.yml | 28 +++++++++++----------- .github/workflows/ci-doctor.md | 16 ++++++++++++- 4 files changed, 40 insertions(+), 26 deletions(-) diff --git a/.github/workflows/binding-updater.lock.yml b/.github/workflows/binding-updater.lock.yml index 3d6c13c..132f18d 100644 --- a/.github/workflows/binding-updater.lock.yml +++ b/.github/workflows/binding-updater.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"937fb183617b555a073b98d819c0f285a24931c7fb1f1941fe3545c7ed11de7a","body_hash":"45d1c2b3efae662b437e8dfd88e3a77869ea681364da69fc5c4535b1be535c6e","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-5","engine_versions":{"copilot":"1.0.75"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"10373116d342d2a5a2b5f780711cda2937b7cbda489e91bfdad564ef857aeb27","body_hash":"45d1c2b3efae662b437e8dfd88e3a77869ea681364da69fc5c4535b1be535c6e","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-5","engine_versions":{"copilot":"1.0.75"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"EvergineTeam/Evergine.Bindings/.github/actions/binding-fetch-upstream","sha":"1e1c380bfed92b3f51e8bf32a550c2cb5b278ea7","version":"v1"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-dotnet","sha":"26b0ec14cb23fa6904739307f278c14f94c95bf1","version":"v5"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"e89c65e17eb281bbd5ff2ff9e9199a03e96654c7","version":"v0.83.4"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42","digest":"sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42","digest":"sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42","digest":"sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42","digest":"sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.6","digest":"sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw (v0.83.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -17,7 +17,7 @@ # \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/ # # -# To update this file, edit EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e and run: +# To update this file, edit EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 and run: # gh aw compile # Not all edits will cause changes to this file. # @@ -25,7 +25,7 @@ # # Keeps a binding current with its upstream specification, fixing the generator when a new construct breaks it. # -# Source: EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e +# Source: EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 # # Frontmatter env variables: # - DOTNET_CLI_TELEMETRY_OPTOUT: (main workflow) @@ -149,7 +149,7 @@ jobs: GH_AW_INFO_AWF_VERSION: "v0.27.42" GH_AW_INFO_AWMG_VERSION: "" GH_AW_INFO_FIREWALL_TYPE: "squid" - GH_AW_INFO_FRONTMATTER_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_INFO_FRONTMATTER_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_INFO_BODY_MODIFIED: "false" GH_AW_INFO_FRONTMATTER_EMOJI: "🔄" GH_AW_COMPILED_STRICT: "true" @@ -1214,7 +1214,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" @@ -1235,7 +1235,7 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1253,7 +1253,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1268,7 +1268,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1283,7 +1283,7 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_WORKFLOW_ID: "binding-updater" @@ -1635,7 +1635,7 @@ jobs: GH_AW_WORKFLOW_EMOJI: "🔄" GH_AW_WORKFLOW_ID: "binding-updater" GH_AW_WORKFLOW_NAME: "Binding Updater" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" outputs: code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }} diff --git a/.github/workflows/binding-updater.md b/.github/workflows/binding-updater.md index 0bf3ac8..07aee3e 100644 --- a/.github/workflows/binding-updater.md +++ b/.github/workflows/binding-updater.md @@ -66,7 +66,7 @@ safe-outputs: allowed-labels: [agent:needs-human, agent:upstream-break] deduplicate-by-title: true max: 1 -source: EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e +source: EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 --- # Binding Updater diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index 65caa45..be2c600 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"200a09abac3736608cdd2b3ac0816109841a972fa21079fd40b9f8a1cd85450b","body_hash":"9dd8fe3830589ac917acec372324a3ff09ef62a01f87587a8dabfccbde43ae65","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-5","engine_versions":{"copilot":"1.0.75"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"18d854b870ceaf4936424332a260eb76338d079158d513047070d1e85e0f822d","body_hash":"9dd8fe3830589ac917acec372324a3ff09ef62a01f87587a8dabfccbde43ae65","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-5","engine_versions":{"copilot":"1.0.75"}} # gh-aw-manifest: {"version":1,"secrets":["APP_PRIVATE_KEY","COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/create-github-app-token","sha":"bcd2ba49218906704ab6c1aa796996da409d3eb1","version":"v3.2.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"e89c65e17eb281bbd5ff2ff9e9199a03e96654c7","version":"v0.83.4"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42","digest":"sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42","digest":"sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42","digest":"sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42","digest":"sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.6","digest":"sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw (v0.83.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -17,7 +17,7 @@ # \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/ # # -# To update this file, edit EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e and run: +# To update this file, edit EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 and run: # gh aw compile # Not all edits will cause changes to this file. # @@ -25,7 +25,7 @@ # # Triages failed CI/CD runs in a binding repository and fixes workflow configuration problems. # -# Source: EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e +# Source: EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 # # Secrets used: # - APP_PRIVATE_KEY @@ -147,7 +147,7 @@ jobs: GH_AW_INFO_AWF_VERSION: "v0.27.42" GH_AW_INFO_AWMG_VERSION: "" GH_AW_INFO_FIREWALL_TYPE: "squid" - GH_AW_INFO_FRONTMATTER_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_INFO_FRONTMATTER_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_INFO_BODY_MODIFIED: "false" GH_AW_INFO_FRONTMATTER_EMOJI: "🩺" GH_AW_COMPILED_STRICT: "true" @@ -538,9 +538,9 @@ jobs: mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_a20ba2fb408f6eef_EOF' - {"create_issue":{"allowed_labels":["agent:needs-regen","agent:upstream-break","agent:needs-human"],"deduplicate_by_title":true,"labels":["agent:needs-human"],"max":1,"title_prefix":"CI failure: "},"create_pull_request":{"allowed_files":[".github/workflows/**"],"draft":false,"if_no_changes":"ignore","labels":["agent:ci-fix"],"max":1,"max_patch_files":100,"max_patch_size":4096,"protect_top_level_dot_folders":true,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS","DESIGN.md","README.md","CONTRIBUTING.md","CHANGELOG.md","SECURITY.md","CODE_OF_CONDUCT.md","AGENTS.md","CLAUDE.md","GEMINI.md"],"protected_files_policy":"request_review","title_prefix":"fix(ci): "},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{}} - GH_AW_SAFE_OUTPUTS_CONFIG_a20ba2fb408f6eef_EOF + cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_e0559502996c586f_EOF' + {"create_issue":{"allowed_labels":["agent:needs-regen","agent:upstream-break","agent:needs-human"],"deduplicate_by_title":true,"labels":["agent:needs-human"],"max":1,"title_prefix":"CI failure: "},"create_pull_request":{"allowed_files":[".github/workflows/**"],"draft":false,"if_no_changes":"ignore","labels":["agent:ci-fix"],"max":1,"max_patch_files":100,"max_patch_size":4096,"protect_top_level_dot_folders":true,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS","DESIGN.md","README.md","CONTRIBUTING.md","CHANGELOG.md","SECURITY.md","CODE_OF_CONDUCT.md","AGENTS.md","CLAUDE.md","GEMINI.md"],"protected_files_policy":"allowed","title_prefix":"fix(ci): "},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{}} + GH_AW_SAFE_OUTPUTS_CONFIG_e0559502996c586f_EOF - name: Generate Safe Outputs Tools env: GH_AW_TOOLS_META_JSON: | @@ -1210,7 +1210,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" @@ -1231,7 +1231,7 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1249,7 +1249,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" with: github-token: ${{ steps.safe-outputs-app-token.outputs.token }} script: | @@ -1264,7 +1264,7 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" with: github-token: ${{ steps.safe-outputs-app-token.outputs.token }} script: | @@ -1279,7 +1279,7 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_WORKFLOW_ID: "ci-doctor" @@ -1634,7 +1634,7 @@ jobs: GH_AW_WORKFLOW_EMOJI: "🩺" GH_AW_WORKFLOW_ID: "ci-doctor" GH_AW_WORKFLOW_NAME: "CI Doctor" - GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e" + GH_AW_WORKFLOW_SOURCE: "EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321" outputs: app_token_minting_failed: ${{ steps.safe-outputs-app-token.outcome == 'failure' }} code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} @@ -1727,7 +1727,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.githubusercontent.com,api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,codeload.github.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,docs.github.com,github-cloud.githubusercontent.com,github-cloud.s3.amazonaws.com,github.blog,github.com,github.githubassets.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,lfs.github.com,objects.githubusercontent.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,patch-diff.githubusercontent.com,patchdiff.githubusercontent.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"allowed_labels\":[\"agent:needs-regen\",\"agent:upstream-break\",\"agent:needs-human\"],\"deduplicate_by_title\":true,\"labels\":[\"agent:needs-human\"],\"max\":1,\"title_prefix\":\"CI failure: \"},\"create_pull_request\":{\"allowed_files\":[\".github/workflows/**\"],\"draft\":false,\"if_no_changes\":\"ignore\",\"labels\":[\"agent:ci-fix\"],\"max\":1,\"max_patch_files\":100,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"CHANGELOG.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\",\"CLAUDE.md\",\"GEMINI.md\"],\"protected_files_policy\":\"request_review\",\"title_prefix\":\"fix(ci): \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"allowed_labels\":[\"agent:needs-regen\",\"agent:upstream-break\",\"agent:needs-human\"],\"deduplicate_by_title\":true,\"labels\":[\"agent:needs-human\"],\"max\":1,\"title_prefix\":\"CI failure: \"},\"create_pull_request\":{\"allowed_files\":[\".github/workflows/**\"],\"draft\":false,\"if_no_changes\":\"ignore\",\"labels\":[\"agent:ci-fix\"],\"max\":1,\"max_patch_files\":100,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"CHANGELOG.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\",\"CLAUDE.md\",\"GEMINI.md\"],\"protected_files_policy\":\"allowed\",\"title_prefix\":\"fix(ci): \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" GH_AW_CI_TRIGGER_TOKEN: ${{ secrets.GH_AW_CI_TRIGGER_TOKEN }} GITHUB_TOKEN: ${{ steps.safe-outputs-app-token.outputs.token }} with: diff --git a/.github/workflows/ci-doctor.md b/.github/workflows/ci-doctor.md index 6bba967..ffdbab5 100644 --- a/.github/workflows/ci-doctor.md +++ b/.github/workflows/ci-doctor.md @@ -37,6 +37,20 @@ safe-outputs: title-prefix: "fix(ci): " labels: [agent:ci-fix] allow-workflows: true + # Two independent gates guard the patch, and both must pass. `allowed-files` + # is an exclusive allowlist: nothing outside these globs can ever be written, + # not even ordinary source. `protected-files` is a separate policy covering + # manifests, instruction files and everything under a top-level dot folder -- + # which is all of `.github/`, so it applies to every fix this agent exists to + # make. Its default (`request_review`) cannot be honoured on this path: with a + # GitHub App the push goes through the signed-commit API, which has no way to + # open a pull request and then ask for changes, so it refuses outright and the + # run degrades to an issue carrying a patch bundle. + # + # `allowed` lifts the second gate only. The first still confines the agent to + # workflow files, and the pull request is reviewed by a human before merge -- + # which is where that judgement belongs, rather than blocking the proposal. + protected-files: allowed allowed-files: - ".github/workflows/**" draft: false @@ -47,7 +61,7 @@ safe-outputs: allowed-labels: [agent:needs-regen, agent:upstream-break, agent:needs-human] deduplicate-by-title: true max: 1 -source: EvergineTeam/Evergine.Bindings@19dd071f1863ac632c22c023bbcc45008c49dc1e +source: EvergineTeam/Evergine.Bindings@34c1fd0511086f987615f62836ef84040c193321 --- # CI Doctor