Skip to content

[aw-compat] Missing codemod: auto-fix tools.web-fetch + strict-mode engine incompatibility (4 repos) #66081

Description

@github-actions

Overview

gh aw fix --write reports "No fixes needed" for a recurring, deterministic compile failure that appears in 4 of the 20 repos audited today (20% of sample), even though the compiler's own error message already spells out exactly how to fix it.

Key metrics

  • 4 repos affected: Azure/azure-sdk-for-net, microsoft/mcp, Azure/azure-sdk-for-js, Azure/azure-sdk-for-rust
  • 0 repos auto-fixed by the existing fix --write pass
  • Pattern: tools.web-fetch enabled + --strict + Copilot engine

The failure

error: [...] Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them). Example:

engine: codex
network:
  hosted-web:
    allowed:
      - example.com

Alternatively, disable this tool:

tools:
  web-fetch: false

Why this is a good codemod candidate

The compiler's own diagnostic already contains both candidate remediations verbatim. A codemod could:

  1. Detect tools.web-fetch truthy + engine: copilot (or any engine that doesn't enforce network.hosted-web) + --strict, and
  2. Either (a) set tools.web-fetch: false automatically (safe, conservative default — matches the pattern used elsewhere in the fix tool for disabling tools under incompatible configs), or (b) prompt/flag for a manual engine switch when web-fetch is clearly load-bearing for the workflow's stated purpose (e.g. workflow body references fetching external URLs).

Given this affects 4 independent repos with the exact same error text, this looks like a stable, mechanical fix rather than something requiring per-repo judgment.

Representative repos

Azure/azure-sdk-for-net — issue-triage.md
.github/workflows/issue-triage.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'
microsoft/mcp — doc-gap-detector.md
.github/workflows/doc-gap-detector.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'
Azure/azure-sdk-for-js — sentinel.md
.github/workflows/sentinel.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'

Next actions

  • Add a codemod to gh aw fix that recognizes this tools.web-fetch + strict-mode + incompatible-engine combination and applies the compiler's own suggested remediation automatically (or at minimum surfaces it as an actionable fix candidate rather than "No fixes needed").

Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 751.6 AIC · ⌖ 7.23 AIC · ⊞ 6.4K · ◷

  • expires on Oct 13, 2026, 1:17 AM UTC-08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions