Skip to content

[aw-compat] Missing/incomplete codemod coverage: web-fetch strict-network (6 repos), kibana trigger-shape gap, \{\{#import}} rewri [Conten #64234

Description

@github-actions

Missing/incomplete codemod coverage — cross-repo audit 2026-09-29 (2nd consecutive day, same repos)

Three codemod gaps observed in yesterday's (2026-09-28) audit reproduced today with the identical
repo set
, confirming these are stable, addressable gaps rather than transient noise.

1. copilot-web-fetch-strict-network — no codemod exists (highest impact: 6/20 repos, 30%)

Repos: github/spec-kit, py-why/dowhy, microsoft/mcp, drasi-project/drasi-platform,
Azure/azure-sdk-for-rust, NikiforovAll/keycloak-authorization-services-dotnet

error: Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them).

gh aw fix --write reports "No fixes needed" on all six files even though the validator gives a
concrete, mechanical suggestion (move network.allowed entries to network.hosted-web.allowed, or
switch engine: copilot → engine: codex/claude). Root cause pattern: users configure
engine: copilot + tools.web-fetch: true + a network: allow-list, not realizing Copilot's hosted
web-fetch tool ignores that restriction — the validator only catches it under --strict.

Suggested fix: add a codemod that either (a) mechanically moves the network allow-list into
network.hosted-web.allowed, or (b) is a guided-error codemod (like the existing bash-allowlist one)
that explains the two remediation choices inline instead of silently no-op'ing on a named, known rule.

2. add-checkout-false-for-pull-request-target — incomplete trigger-shape matching (1 repo, 2nd day)

Repo: elastic/kibana, file flaky-fix-verifier.md

The codemod correctly fixed 8 of 9 workflow files by adding checkout: false, but skipped
flaky-fix-verifier.md because its on: block combines pull_request_target with issue_comment
and workflow_dispatch (plus a custom bots: field and top-level if:), while the 8 successfully
fixed files use a simple single-trigger on: pull_request_target: shape.

Suggested fix: extend the codemod's trigger-shape matcher to handle pull_request_target
combined with other event keys in the same on: map. Also have gh aw fix report why a file was
left unfixed (e.g. "skipped: multi-event on: block not yet supported") rather than omitting it
silently from the summary — this is what made the gap easy to miss on 2026-09-28.

3. {{#import path}} deprecated syntax — warning-only, no rewrite codemod

Repo: elastic/kibana (3 occurrences this run)

⚠ Deprecated syntax: "{{#import path}}". Use {{#runtime-import path}} for content injection
  or the 'imports:' frontmatter field for configuration merging.

This doesn't fail compilation, but the compiler already computes the exact replacement string in
its own warning message — a pure mechanical substitution gh aw fix --write should apply
automatically to live up to its "bring me current" framing.

Secondary, lower-priority item: codex bash-allowlist guided-error UX (3rd+ consecutive occurrence, by design)

Repos: OtterMind/Chat2DB, pockebot/openpocket

error: engine 'codex' does not support bash command allow-listing: ... Manual fix required

A codemod (bash-allowlist-unsupported-engine-guided-error) exists and correctly refuses to
auto-pick bash: ["*"] (which would be a security regression) — this is working as intended, not a
bug. The only ask: gh aw fix --write's exit code (2) doesn't distinguish "nothing to do" from
"couldn't finish, needs a human," which is easy to miss in CI scripts that only check for changed
files. A distinct summary line ("N files need manual intervention") would help.

Cache artifacts: runs/2026-09-29-08-55-32-060/error-clusters.json,
runs/2026-09-29-08-55-32-060/missing-codemods.json.

Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 263.8 AIC · ⌖ 7.03 AIC · ⊞ 6.1K · ◷

  • expires on Oct 6, 2026, 1:07 AM UTC-08:00

Activity

  1. github-actions commented on Oct 5, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #65826

    View newer issue


    This action was performed automatically by the Daily AW Cross-Repo Compile Check workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions