Missing/incomplete codemod coverage — cross-repo audit 2026-09-29 (2nd consecutive day, same repos)
Three codemod gaps observed in yesterday's (2026-09-28) audit reproduced today with the identical
repo set, confirming these are stable, addressable gaps rather than transient noise.
1. copilot-web-fetch-strict-network — no codemod exists (highest impact: 6/20 repos, 30%)
Repos: github/spec-kit, py-why/dowhy, microsoft/mcp, drasi-project/drasi-platform,
Azure/azure-sdk-for-rust, NikiforovAll/keycloak-authorization-services-dotnet
error: Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them).
gh aw fix --write reports "No fixes needed" on all six files even though the validator gives a
concrete, mechanical suggestion (move network.allowed entries to network.hosted-web.allowed, or
switch engine: copilot → engine: codex/claude). Root cause pattern: users configure
engine: copilot + tools.web-fetch: true + a network: allow-list, not realizing Copilot's hosted
web-fetch tool ignores that restriction — the validator only catches it under --strict.
Suggested fix: add a codemod that either (a) mechanically moves the network allow-list into
network.hosted-web.allowed, or (b) is a guided-error codemod (like the existing bash-allowlist one)
that explains the two remediation choices inline instead of silently no-op'ing on a named, known rule.
2. add-checkout-false-for-pull-request-target — incomplete trigger-shape matching (1 repo, 2nd day)
Repo: elastic/kibana, file flaky-fix-verifier.md
The codemod correctly fixed 8 of 9 workflow files by adding checkout: false, but skipped
flaky-fix-verifier.md because its on: block combines pull_request_target with issue_comment
and workflow_dispatch (plus a custom bots: field and top-level if:), while the 8 successfully
fixed files use a simple single-trigger on: pull_request_target: shape.
Suggested fix: extend the codemod's trigger-shape matcher to handle pull_request_target
combined with other event keys in the same on: map. Also have gh aw fix report why a file was
left unfixed (e.g. "skipped: multi-event on: block not yet supported") rather than omitting it
silently from the summary — this is what made the gap easy to miss on 2026-09-28.
3. {{#import path}} deprecated syntax — warning-only, no rewrite codemod
Repo: elastic/kibana (3 occurrences this run)
⚠ Deprecated syntax: "{{#import path}}". Use {{#runtime-import path}} for content injection
or the 'imports:' frontmatter field for configuration merging.
This doesn't fail compilation, but the compiler already computes the exact replacement string in
its own warning message — a pure mechanical substitution gh aw fix --write should apply
automatically to live up to its "bring me current" framing.
Secondary, lower-priority item: codex bash-allowlist guided-error UX (3rd+ consecutive occurrence, by design)
Repos: OtterMind/Chat2DB, pockebot/openpocket
error: engine 'codex' does not support bash command allow-listing: ... Manual fix required
A codemod (bash-allowlist-unsupported-engine-guided-error) exists and correctly refuses to
auto-pick bash: ["*"] (which would be a security regression) — this is working as intended, not a
bug. The only ask: gh aw fix --write's exit code (2) doesn't distinguish "nothing to do" from
"couldn't finish, needs a human," which is easy to miss in CI scripts that only check for changed
files. A distinct summary line ("N files need manual intervention") would help.
Cache artifacts: runs/2026-09-29-08-55-32-060/error-clusters.json,
runs/2026-09-29-08-55-32-060/missing-codemods.json.
Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 263.8 AIC · ⌖ 7.03 AIC · ⊞ 6.1K · ◷
Missing/incomplete codemod coverage — cross-repo audit 2026-09-29 (2nd consecutive day, same repos)
Three codemod gaps observed in yesterday's (2026-09-28) audit reproduced today with the identical
repo set, confirming these are stable, addressable gaps rather than transient noise.
1.
copilot-web-fetch-strict-network— no codemod exists (highest impact: 6/20 repos, 30%)Repos: github/spec-kit, py-why/dowhy, microsoft/mcp, drasi-project/drasi-platform,
Azure/azure-sdk-for-rust, NikiforovAll/keycloak-authorization-services-dotnet
gh aw fix --writereports "No fixes needed" on all six files even though the validator gives aconcrete, mechanical suggestion (move
network.allowedentries tonetwork.hosted-web.allowed, orswitch
engine: copilot→engine: codex/claude). Root cause pattern: users configureengine: copilot+tools.web-fetch: true+ anetwork:allow-list, not realizing Copilot's hostedweb-fetch tool ignores that restriction — the validator only catches it under
--strict.Suggested fix: add a codemod that either (a) mechanically moves the network allow-list into
network.hosted-web.allowed, or (b) is a guided-error codemod (like the existing bash-allowlist one)that explains the two remediation choices inline instead of silently no-op'ing on a named, known rule.
2.
add-checkout-false-for-pull-request-target— incomplete trigger-shape matching (1 repo, 2nd day)Repo: elastic/kibana, file
flaky-fix-verifier.mdThe codemod correctly fixed 8 of 9 workflow files by adding
checkout: false, but skippedflaky-fix-verifier.mdbecause itson:block combinespull_request_targetwithissue_commentand
workflow_dispatch(plus a custombots:field and top-levelif:), while the 8 successfullyfixed files use a simple single-trigger
on: pull_request_target:shape.Suggested fix: extend the codemod's trigger-shape matcher to handle
pull_request_targetcombined with other event keys in the same
on:map. Also havegh aw fixreport why a file wasleft unfixed (e.g. "skipped: multi-event on: block not yet supported") rather than omitting it
silently from the summary — this is what made the gap easy to miss on 2026-09-28.
3.
{{#import path}}deprecated syntax — warning-only, no rewrite codemodRepo: elastic/kibana (3 occurrences this run)
This doesn't fail compilation, but the compiler already computes the exact replacement string in
its own warning message — a pure mechanical substitution
gh aw fix --writeshould applyautomatically to live up to its "bring me current" framing.
Secondary, lower-priority item: codex bash-allowlist guided-error UX (3rd+ consecutive occurrence, by design)
Repos: OtterMind/Chat2DB, pockebot/openpocket
A codemod (
bash-allowlist-unsupported-engine-guided-error) exists and correctly refuses toauto-pick
bash: ["*"](which would be a security regression) — this is working as intended, not abug. The only ask:
gh aw fix --write's exit code (2) doesn't distinguish "nothing to do" from"couldn't finish, needs a human," which is easy to miss in CI scripts that only check for changed
files. A distinct summary line ("N files need manual intervention") would help.
Cache artifacts:
runs/2026-09-29-08-55-32-060/error-clusters.json,runs/2026-09-29-08-55-32-060/missing-codemods.json.