Skip to content

[aw-compat] Missing codemod: strict-mode tools.web-fetch incompatible with engine: copilot (5 repos) #65827

Description

@github-actions

Missing codemod candidate: tools.web-fetch + strict mode + engine: copilot

In today's cross-repo compat audit, 5 of 18 compiled repositories fail gh aw compile --strict with the same error, and gh aw fix --write currently leaves it untouched:

error: Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them). Example:

engine: codex
network:
  hosted-web:
    allowed:
      - example.com

Alternatively, disable this tool:

tools:
  web-fetch: false

Affected repositories (3 of 5 shown): Azure/azure-sdk-for-rust, drasi-project/drasi-platform, microsoft/mcp (also NikiforovAll/keycloak-authorization-services-dotnet, py-why/dowhy).

Why this isn't auto-fixed today

Both remedies in the error's own suggestion change workflow behavior:

  • Switching engine: copilot → engine: codex/claude changes the runtime engine.
  • Disabling tools.web-fetch: false removes a tool the workflow author presumably wanted.

Neither is safe as a default, unconditional codemod.

Proposed options

  1. Opt-in codemod (e.g. gh aw fix --write --allow-behavior-change) that applies the error's own suggested rewrite (either disable the tool or restructure network.hosted-web.allowed), clearly flagged as a behavior change in the fix report — not bundled into default --write.
  2. Earlier warning: surface this as a non-strict-mode warning (e.g. during normal gh aw compile or gh aw fix dry-run) when a workflow uses engine: copilot + tools.web-fetch + any network: restriction, so authors see it before they turn on strict mode in CI, rather than discovering it only when --strict is enforced.
Repro
git clone --depth 1 https://github.com/microsoft/mcp
cd mcp
gh-aw compile --strict
# .github/workflows/doc-gap-detector.md:1:1: error: Validation failed for field 'tools.web-fetch'

References: gh-aw build under test: 0dc1f7e. See companion daily summary issue for full run metrics.

Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 346.8 AIC · ⌖ 8.19 AIC · ⊞ 6.4K · ◷

  • expires on Oct 12, 2026, 1:11 AM UTC-08:00

Activity

  1. github-actions commented on Oct 6, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #66080

    View newer issue


    This action was performed automatically by the Daily AW Cross-Repo Compile Check workflow.

  2. github-actions commented on Oct 6, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #66081

    View newer issue


    This action was performed automatically by the Daily AW Cross-Repo Compile Check workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions