Overview
gh aw fix --write reports "No fixes needed" for a recurring, deterministic compile failure that appears in 4 of the 20 repos audited today (20% of sample), even though the compiler's own error message already spells out exactly how to fix it.
Key metrics
- 4 repos affected:
Azure/azure-sdk-for-net, microsoft/mcp, Azure/azure-sdk-for-js, Azure/azure-sdk-for-rust
- 0 repos auto-fixed by the existing
fix --write pass
- Pattern:
tools.web-fetch enabled + --strict + Copilot engine
The failure
error: [...] Validation failed for field 'tools.web-fetch'
Reason: strict mode: Copilot's 'web-fetch' tool does not follow the configured network restrictions
Suggestion: To enforce network restrictions, use Codex or Claude and configure network.hosted-web
separately for hosted tools (network.allowed does not cover them). Example:
engine: codex
network:
hosted-web:
allowed:
- example.com
Alternatively, disable this tool:
tools:
web-fetch: false
Why this is a good codemod candidate
The compiler's own diagnostic already contains both candidate remediations verbatim. A codemod could:
- Detect
tools.web-fetch truthy + engine: copilot (or any engine that doesn't enforce network.hosted-web) + --strict, and
- Either (a) set
tools.web-fetch: false automatically (safe, conservative default — matches the pattern used elsewhere in the fix tool for disabling tools under incompatible configs), or (b) prompt/flag for a manual engine switch when web-fetch is clearly load-bearing for the workflow's stated purpose (e.g. workflow body references fetching external URLs).
Given this affects 4 independent repos with the exact same error text, this looks like a stable, mechanical fix rather than something requiring per-repo judgment.
Representative repos
Azure/azure-sdk-for-net — issue-triage.md
.github/workflows/issue-triage.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'
microsoft/mcp — doc-gap-detector.md
.github/workflows/doc-gap-detector.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'
Azure/azure-sdk-for-js — sentinel.md
.github/workflows/sentinel.md:1:1: error: [...] Validation failed for field 'tools.web-fetch'
Next actions
- Add a codemod to
gh aw fix that recognizes this tools.web-fetch + strict-mode + incompatible-engine combination and applies the compiler's own suggested remediation automatically (or at minimum surfaces it as an actionable fix candidate rather than "No fixes needed").
Generated by 🔧 Daily AW Cross-Repo Compile Check · claude · agent · 751.6 AIC · ⌖ 7.23 AIC · ⊞ 6.4K · ◷
Overview
gh aw fix --writereports "No fixes needed" for a recurring, deterministic compile failure that appears in 4 of the 20 repos audited today (20% of sample), even though the compiler's own error message already spells out exactly how to fix it.Key metrics
Azure/azure-sdk-for-net,microsoft/mcp,Azure/azure-sdk-for-js,Azure/azure-sdk-for-rustfix --writepasstools.web-fetchenabled +--strict+ Copilot engineThe failure
Why this is a good codemod candidate
The compiler's own diagnostic already contains both candidate remediations verbatim. A codemod could:
tools.web-fetchtruthy +engine: copilot(or any engine that doesn't enforcenetwork.hosted-web) +--strict, andtools.web-fetch: falseautomatically (safe, conservative default — matches the pattern used elsewhere in the fix tool for disabling tools under incompatible configs), or (b) prompt/flag for a manual engine switch whenweb-fetchis clearly load-bearing for the workflow's stated purpose (e.g. workflow body references fetching external URLs).Given this affects 4 independent repos with the exact same error text, this looks like a stable, mechanical fix rather than something requiring per-repo judgment.
Representative repos
Azure/azure-sdk-for-net — issue-triage.md
microsoft/mcp — doc-gap-detector.md
Azure/azure-sdk-for-js — sentinel.md
Next actions
gh aw fixthat recognizes thistools.web-fetch+ strict-mode + incompatible-engine combination and applies the compiler's own suggested remediation automatically (or at minimum surfaces it as an actionable fix candidate rather than "No fixes needed").