Overview
Daily cross-repo compatibility audit against 20 public repositories using gh-aw (ranked by stars), using a local build of gh-aw at commit 18889ac.
Key metrics
- 20/20 repos cloned successfully (0 clone failures)
- 8/20 compiled clean (
gh aw compile --strict) on the first attempt
- 12/20 failed initial compile
- 4/12 were auto-resolved by
gh aw fix --write + recompile: cli/cli, dotnet/maui, microsoft/AI-Engineering-Coach, Azure/azure-sdk-for-go (all via the existing "add explicit tools.bash: false when tools.github.min-integrity is none" codemod — working well)
- 8/20 still fail after fix + recompile, of which 7 are real gh-aw compatibility gaps and 1 (
dotnet/dotnet) is a false positive of this audit's own discovery method (see below)
Still-failing repos and root causes
Cluster: tools.web-fetch + strict-mode engine incompatibility (4 repos)
Azure/azure-sdk-for-net, microsoft/mcp, Azure/azure-sdk-for-js, Azure/azure-sdk-for-rust
error: [...] Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
gh aw fix --write reports "No fixes needed" for all four, even though the compiler's own error message already describes two concrete remediations. See the companion missing-codemod issue for detail.
Cluster: reserved workflow_dispatch.inputs.aw_context (1 repo, 5 files)
remix-run/react-router — aw-command-implement.md, aw-command-iterate.md, aw-command-review-issue.md, aw-command-review-proposal.md, aw-comment-router.md all fail identically:
error: on.workflow_dispatch.inputs.aw_context is reserved and managed by the compiler; remove it from workflow inputs
gh aw fix --write does not touch this. See the companion syntax-errors issue for detail.
Cluster: codex engine + unsupported bash allow-listing (1 repo, 4 files)
remix-run/react-router — the existing bash-allowlist-unsupported-engine-guided-error codemod correctly detects engine: codex combined with bash allow-listing and declines to auto-fix, requiring a human to pick an engine that enforces allow-lists or make unrestricted access explicit. This is working as intended, not a gap.
Cluster: pull_request_target "pwn request" checkout pattern (1 repo)
elastic/kibana — the compiler correctly flags a fork-PR checkout under pull_request_target as a dangerous security pattern and declines to auto-fix it. Working as intended.
Cluster: create-github-app-token missing permission-* scoping (1 repo)
microsoft/aspire — pr-docs-check.md fails strict-mode validation because actions/create-github-app-token has no explicit permission-* inputs. gh aw fix --write reports "No fixes needed". Single-repo occurrence in this run, tracked but below the cross-repo bar for a formal codemod proposal.
Methodology note (not a gh-aw defect)
dotnet/dotnet is a Virtual Monolithic Repository that vendors other repos' full trees (e.g. src/runtime, src/sdk), each with their own nested .github/workflows/*.lock.yml. gh aw compile correctly only looks at the top-level .github/workflows; the 55 nested lock files this audit's discovery step found belong to vendored component repos, not to dotnet/dotnet itself.
Next actions
- See companion issue for the
tools.web-fetch + strict-mode missing-codemod proposal.
- See companion issue for the reserved
aw_context input / codex-bash-allowlist syntax-error patterns.
Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 751.6 AIC · ⌖ 7.23 AIC · ⊞ 6.4K · ◷
Overview
Daily cross-repo compatibility audit against 20 public repositories using gh-aw (ranked by stars), using a local build of
gh-awat commit18889ac.Key metrics
gh aw compile --strict) on the first attemptgh aw fix --write+ recompile:cli/cli,dotnet/maui,microsoft/AI-Engineering-Coach,Azure/azure-sdk-for-go(all via the existing "add explicittools.bash: falsewhentools.github.min-integrityisnone" codemod — working well)dotnet/dotnet) is a false positive of this audit's own discovery method (see below)Still-failing repos and root causes
Cluster: tools.web-fetch + strict-mode engine incompatibility (4 repos)
Azure/azure-sdk-for-net,microsoft/mcp,Azure/azure-sdk-for-js,Azure/azure-sdk-for-rustgh aw fix --writereports "No fixes needed" for all four, even though the compiler's own error message already describes two concrete remediations. See the companion missing-codemod issue for detail.Cluster: reserved workflow_dispatch.inputs.aw_context (1 repo, 5 files)
remix-run/react-router—aw-command-implement.md,aw-command-iterate.md,aw-command-review-issue.md,aw-command-review-proposal.md,aw-comment-router.mdall fail identically:gh aw fix --writedoes not touch this. See the companion syntax-errors issue for detail.Cluster: codex engine + unsupported bash allow-listing (1 repo, 4 files)
remix-run/react-router— the existingbash-allowlist-unsupported-engine-guided-errorcodemod correctly detectsengine: codexcombined withbashallow-listing and declines to auto-fix, requiring a human to pick an engine that enforces allow-lists or make unrestricted access explicit. This is working as intended, not a gap.Cluster: pull_request_target "pwn request" checkout pattern (1 repo)
elastic/kibana— the compiler correctly flags a fork-PR checkout underpull_request_targetas a dangerous security pattern and declines to auto-fix it. Working as intended.Cluster: create-github-app-token missing permission-* scoping (1 repo)
microsoft/aspire—pr-docs-check.mdfails strict-mode validation becauseactions/create-github-app-tokenhas no explicitpermission-*inputs.gh aw fix --writereports "No fixes needed". Single-repo occurrence in this run, tracked but below the cross-repo bar for a formal codemod proposal.Methodology note (not a gh-aw defect)
dotnet/dotnetis a Virtual Monolithic Repository that vendors other repos' full trees (e.g.src/runtime,src/sdk), each with their own nested.github/workflows/*.lock.yml.gh aw compilecorrectly only looks at the top-level.github/workflows; the 55 nested lock files this audit's discovery step found belong to vendored component repos, not todotnet/dotnetitself.Next actions
tools.web-fetch+ strict-mode missing-codemod proposal.aw_contextinput / codex-bash-allowlist syntax-error patterns.