Skip to content

[aw-compat] Daily AW compatibility audit: 20 repos, 7 real compile gaps found (2026-10-06) #66080

Description

@github-actions

Overview

Daily cross-repo compatibility audit against 20 public repositories using gh-aw (ranked by stars), using a local build of gh-aw at commit 18889ac.

Key metrics

  • 20/20 repos cloned successfully (0 clone failures)
  • 8/20 compiled clean (gh aw compile --strict) on the first attempt
  • 12/20 failed initial compile
  • 4/12 were auto-resolved by gh aw fix --write + recompile: cli/cli, dotnet/maui, microsoft/AI-Engineering-Coach, Azure/azure-sdk-for-go (all via the existing "add explicit tools.bash: false when tools.github.min-integrity is none" codemod — working well)
  • 8/20 still fail after fix + recompile, of which 7 are real gh-aw compatibility gaps and 1 (dotnet/dotnet) is a false positive of this audit's own discovery method (see below)

Still-failing repos and root causes

Cluster: tools.web-fetch + strict-mode engine incompatibility (4 repos)

Azure/azure-sdk-for-net, microsoft/mcp, Azure/azure-sdk-for-js, Azure/azure-sdk-for-rust

error: [...] Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions

gh aw fix --write reports "No fixes needed" for all four, even though the compiler's own error message already describes two concrete remediations. See the companion missing-codemod issue for detail.

Cluster: reserved workflow_dispatch.inputs.aw_context (1 repo, 5 files)

remix-run/react-router — aw-command-implement.md, aw-command-iterate.md, aw-command-review-issue.md, aw-command-review-proposal.md, aw-comment-router.md all fail identically:

error: on.workflow_dispatch.inputs.aw_context is reserved and managed by the compiler; remove it from workflow inputs

gh aw fix --write does not touch this. See the companion syntax-errors issue for detail.

Cluster: codex engine + unsupported bash allow-listing (1 repo, 4 files)

remix-run/react-router — the existing bash-allowlist-unsupported-engine-guided-error codemod correctly detects engine: codex combined with bash allow-listing and declines to auto-fix, requiring a human to pick an engine that enforces allow-lists or make unrestricted access explicit. This is working as intended, not a gap.

Cluster: pull_request_target "pwn request" checkout pattern (1 repo)

elastic/kibana — the compiler correctly flags a fork-PR checkout under pull_request_target as a dangerous security pattern and declines to auto-fix it. Working as intended.

Cluster: create-github-app-token missing permission-* scoping (1 repo)

microsoft/aspire — pr-docs-check.md fails strict-mode validation because actions/create-github-app-token has no explicit permission-* inputs. gh aw fix --write reports "No fixes needed". Single-repo occurrence in this run, tracked but below the cross-repo bar for a formal codemod proposal.

Methodology note (not a gh-aw defect)

dotnet/dotnet is a Virtual Monolithic Repository that vendors other repos' full trees (e.g. src/runtime, src/sdk), each with their own nested .github/workflows/*.lock.yml. gh aw compile correctly only looks at the top-level .github/workflows; the 55 nested lock files this audit's discovery step found belong to vendored component repos, not to dotnet/dotnet itself.

Next actions

  • See companion issue for the tools.web-fetch + strict-mode missing-codemod proposal.
  • See companion issue for the reserved aw_context input / codex-bash-allowlist syntax-error patterns.

Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 751.6 AIC · ⌖ 7.23 AIC · ⊞ 6.4K · ◷

  • expires on Oct 13, 2026, 1:17 AM UTC-08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions