Skip to content

Add repo-memory backend for daily AIC guardrail - #62958

Merged
pelikhan merged 20 commits into
mainfrom
copilot/consider-repo-memory-backed-rollup
Sep 23, 2026
Merged

pelikhan merged 20 commits into
mainfrom
copilot/consider-repo-memory-backed-rollup

Conversation

Copilot AI commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The daily AIC guardrail currently scales with trailing 24h workflow volume because cache misses require Actions API scans plus artifact downloads per run. This adds an opt-in repo-memory JSONL ledger backend so high-volume workflows can read a rolling total from git-backed state instead.

  • Backend configuration
    • Added object-form support for max-daily-ai-credits.backend.
    • Currently supports repo-memory.
    • Requires tools.repo-memory when selected.
max-daily-ai-credits:
  value: 10000
  backend: repo-memory

tools:
  repo-memory: true
  • Repo-memory ledger

    • Stores daily AIC observations in timestamp-bucketed JSONL files under repo-memory.
    • Reads current and previous UTC buckets to cover the trailing 24h window.
    • Filters ledger entries by repository, workflow, actor, timestamp, run ID, and AIC validity.
  • Workflow wiring

    • Activation clones the configured repo-memory ledger before the guardrail check.
    • Repo-memory backend skips scan-cache restore/publish and avoids per-run artifact lookup.
    • Post-agent phase appends the current run’s AIC before the existing repo-memory upload/push flow.
  • Schema and tests

    • Updated frontmatter schema for the new backend key.
    • Added focused parser, compiler, and JavaScript coverage for backend validation, generated workflow wiring, ledger reads, and ledger writes.

Run: https://github.com/github/gh-aw/actions/runs/35894938867

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 35.6 AIC · ⌖ 8.87 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

Copilot AI and others added 3 commits September 23, 2026 13:25
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Comment on lines +670 to +682
const countedRuns = readLedgerEntries({
repoMemoryDir: options.repoMemoryDir || process.env.GH_AW_DAILY_AIC_REPO_MEMORY_DIR,
repository,
workflowId: process.env.GH_AW_WORKFLOW_ID || workflowName,
actor: actorLogin,
}).map(entry => ({
id: entry.run_id,
html_url: entry.run_url || "",
created_at: entry.timestamp,
conclusion: "completed",
aic: entry.aic,
}));
const totalAIC = countedRuns.reduce((sum, run) => sum + run.aic, 0);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The repo-memory backend derives the entire 24h AI-credit total from JSONL files under the agent-writable repo-memory directory (/tmp/gh-aw/repo-memory/..., synced from a branch that agentic runs push to). Since agent output is untrusted (prompt-injectable) and entries carry no integrity protection, an attacker can cause the ledger files to be truncated/rewritten so that totalAIC reads as 0, fully bypassing the max-daily-ai-credits guardrail on every subsequent run. Consider keeping an authoritative, non-agent-writable source (e.g. Actions cache/artifact scan) as a cross-check, or signing/validating ledger files against data the agent cannot modify before trusting them for the guardrail decision.


Best fix without changing core functionality: fail closed for enforcement when using repo-memory backend unless an integrity signal is present, instead of trusting raw ledger contents unconditionally. Given only this file can be edited, the safest minimal remediation is to require an explicit integrity acknowledgement/env gate before honoring repo-memory totals; otherwise mark status as structural_error and stop. This preserves existing behavior when operators intentionally enable trusted repo-memory mode, while preventing silent bypass by default in untrusted setups.

Concretely, in actions/setup/js/check_daily_aic_workflow_guardrail.cjs, inside the if (backend === REPO_MEMORY_BACKEND) { ... } block (before calling readLedgerEntries), add a check for an env var such as GH_AW_TRUST_REPO_MEMORY_LEDGER === "true". If absent, set:

  • daily_ai_credits_guardrail_status = structural_error
  • daily_ai_credits_guardrail_error with a clear message explaining repo-memory ledger is untrusted unless explicitly trusted
  • core.setFailed(message) and return

No new imports or dependencies are needed.

Copilot AI and others added 2 commits September 23, 2026 13:38
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Comment on lines +669 to +681
const countedRuns = readLedgerEntries({
repoMemoryDir: options.repoMemoryDir || process.env.GH_AW_DAILY_AIC_REPO_MEMORY_DIR,
repository,
workflowId: process.env.GH_AW_WORKFLOW_ID || workflowName,
actor: actorLogin,
}).map(entry => ({
id: entry.run_id,
html_url: entry.run_url || "",
created_at: entry.timestamp,
conclusion: "completed",
aic: entry.aic,
}));
const totalAIC = countedRuns.reduce((sum, run) => sum + run.aic, 0);
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Consider repo-memory-backed rollup for daily AIC guardrail cost Add repo-memory backend for daily AIC guardrail Sep 23, 2026
@pelikhan
pelikhan marked this pull request as ready for review September 23, 2026 16:12
Copilot AI balanced review requested due to automatic review settings September 23, 2026 16:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Current wiring can skip or undercount ledger writes and exposes trusted guardrail state to agent modification.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 6 High severity

Open (6)
What changed in this PR

Adds an opt-in repo-memory ledger backend for the daily AIC guardrail, reducing Actions API and artifact lookups.

Changes:

  • Adds backend parsing, validation, schema, and compiler wiring.
  • Implements JSONL ledger reads/writes and activation integration.
  • Adds focused Go and JavaScript tests.
File Description
pkg/​workflow/​workflow_data.go Stores the selected backend.
pkg/​workflow/​daily_aic_workflow.go Resolves and validates backend configuration.
pkg/​workflow/​daily_aic_workflow_guardrail_test.go Tests compilation and validation.
pkg/​workflow/​compiler_yaml_post_agent.go Invokes ledger persistence.
pkg/​workflow/​compiler_string_api.go Resolves backend during string parsing.
pkg/​workflow/​compiler_orchestrator_workflow.go Resolves backend during compilation.
pkg/​workflow/​compiler_daily_aic_repo_memory.go Generates the ledger append step.
pkg/​workflow/​compiler_activation_daily_aic.go Generates clone and guardrail wiring.
pkg/​parser/​schemas/​main_workflow_schema.json Defines the backend field.
pkg/​parser/​schema_test.go Tests schema acceptance.
actions/​setup/​js/​daily_aic_workflow_helpers.cjs Identifies AIC usage files.
actions/​setup/​js/​daily_aic_repo_memory_ledger.test.cjs Tests ledger reads and writes.
actions/​setup/​js/​daily_aic_repo_memory_ledger.cjs Implements ledger storage.
actions/​setup/​js/​check_daily_aic_workflow_guardrail.cjs Reads ledger totals during activation.

repoMemoryDir: options.repoMemoryDir || process.env.GH_AW_DAILY_AIC_REPO_MEMORY_DIR,
repository,
workflowId: process.env.GH_AW_WORKFLOW_ID || workflowName,
actor: actorLogin,
const { findJSONLFiles, isDailyAICUsageJSONLFile, sumAICFromUsageJSONLFiles } = require("./daily_aic_workflow_helpers.cjs");
const { getErrorMessage } = require("./error_helpers.cjs");

const LEDGER_SUBDIR = "daily-aic-ledger";

// generateDailyAICRepoMemoryLedgerStep appends the current run's AIC usage to
// the repo-memory ledger when the repo-memory backend is configured. It must run
// before the repo-memory artifact upload so the existing push job persists the
return
}
builder.WriteString(" - name: Append daily AIC repo-memory ledger\n")
fmt.Fprintf(builder, " if: always() && %s\n", maxDailyAICreditsConfiguredIfExpr)
}
}

c.generateDailyAICRepoMemoryLedgerStep(yaml, data)
Comment thread pkg/workflow/daily_aic_workflow.go Outdated
if !ok {
return nil
}
backend, hasBackend := extractMaxDailyAICBackend(raw)
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #62958

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

Testing safeoutputs transport availability only; no GitHub action taken in this probe.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

Copy link
Copy Markdown
Contributor
🏗️ ADR required — draft added for PR #62958

I enforced the design-decision gate for this PR because it adds >100 new lines in business-logic directories (default_business_additions: 286).

Result

A draft ADR was added at docs/adr/62958-add-repo-memory-backend-for-daily-aic-guardrail.md and pushed to this PR branch.

Evidence used

  • PR title: Add repo-memory backend for daily AIC guardrail
  • PR description: introduces an opt-in repo-memory backend for max-daily-ai-credits
  • Diff: adds a new repo-memory ledger module, compiler wiring for clone/append steps, schema support, and tests validating the backend behavior

Inferred architectural decision

Use an opt-in git-backed repo-memory JSONL ledger as an alternative backend for the daily AIC guardrail so high-volume workflows can avoid repeated Actions API scans and artifact downloads.

Next action

Please review and refine the drafted ADR, then keep it with the PR as the decision record for this backend addition.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 22.8 AIC · ⌖ 7.78 AIC · ⊞ 10.4K · ◷
Comment /review to run again

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-09-23T16:32:53Z
review_event: BLOCKED_WRITE
top_themes:
  - repo-memory backend has fail-open ledger read/write paths
  - existing review threads already flag actor scoping and persistence gaps
  - imported backend wiring/validation is inconsistent
files_reviewed:
  - actions/setup/js/check_daily_aic_workflow_guardrail.cjs
  - actions/setup/js/daily_aic_repo_memory_ledger.cjs
  - actions/setup/js/daily_aic_workflow_helpers.cjs
  - pkg/parser/schema_test.go
  - pkg/parser/schemas/main_workflow_schema.json
  - pkg/workflow/compiler_activation_daily_aic.go
  - pkg/workflow/compiler_daily_aic_repo_memory.go
  - pkg/workflow/compiler_orchestrator_workflow.go
  - pkg/workflow/compiler_string_api.go
  - pkg/workflow/compiler_yaml_post_agent.go
  - pkg/workflow/daily_aic_workflow.go
  - pkg/workflow/daily_aic_workflow_guardrail_test.go
  - pkg/workflow/workflow_data.go
comment_count: 0
notes: Unable to post review comments or submit the final review because safeoutputs review-write tools returned "Permission denied and could not request permission from user".

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 67.8 AIC · ⌖ 9.41 AIC · ⊞ 20.3K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd and /codebase-design to the new repo-memory backend for the daily AIC guardrail. Note: several prior review threads (github-advanced-security[bot], Copilot) already flag security/correctness concerns on the agent-writable ledger, actor-scoping semantics, and push-job gating that remain unresolved — this review focuses on additional design/test-coverage gaps.

📋 Key Themes & Highlights

Key Themes

  • Untested repo-memory branch in main(): the new ledger-read path in check_daily_aic_workflow_guardrail.cjs (threshold comparison, rateLimit === null summary rendering) has no dedicated JS unit test, unlike the well-tested artifact-scan path.
  • Implicit "first memory wins" fallback: dailyAICRepoMemoryEntry picks an arbitrary repo-memory entry when none is named default and multiple are configured, with no test or documented behavior for that case.
  • Minor clarity nit: firstRepoMemoryEntry slices memories[:1] and loops instead of directly indexing, which obscures a trivial operation.
  • Existing unresolved threads on this PR (actor-filtering semantics, agent-writable ledger tamper risk, push-job gating on agent failure, missing GH_AW_MAX_DAILY_AI_CREDITS env in imported-config case, and post-agent job timing) remain valid and should be resolved before merge.

Positive Highlights

  • ✅ Clear separation between artifact-scan and repo-memory code paths in the activation step builder.
  • ✅ Good test coverage for the Go compiler wiring (clone step ordering, env var propagation, requires tools.repo-memory validation).
  • ✅ Ledger entry validation (validEntry) is defensive about malformed/stale data and correctly handles per-run de-duplication by latest timestamp.

@copilot please address the review comments above.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 110.4 AIC · ⌖ 14.7 AIC · ⊞ 10.1K
Comment /matt to run again

return RepoMemoryEntry{}, false
}
var first RepoMemoryEntry
for _, memory := range memories[:1] {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/codebase-design] firstRepoMemoryEntry slices memories[:1] and loops over a single-element slice just to assign first — this obscures intent versus a plain memories[0].

💡 Suggested simplification
func firstRepoMemoryEntry(memories []RepoMemoryEntry) (RepoMemoryEntry, bool) {
	if len(memories) == 0 {
		return RepoMemoryEntry{}, false
	}
	return memories[0], true
}

A deep, simple helper should read as directly as the operation it performs; the loop-over-one-element pattern makes a reader pause to check whether there is hidden logic (e.g. skipping/merging) that isn't actually there.

@copilot please address this.

return memory, true
}
}
return firstRepoMemoryEntry(data.RepoMemoryConfig.Memories)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/codebase-design] dailyAICRepoMemoryEntry silently falls back to "the first configured memory" when no memory is named default, but this selection is never exercised by a test with more than one tools.repo-memory entry — so a config with two memories (neither named default) will silently pick whichever one happens to be first in frontmatter order, which is fragile and unannounced to the user.

💡 Suggested improvement

Either:

  1. Require the repo-memory backend to name which memory id it targets (e.g. backend: {repo-memory: {memory: my-id}}), removing the implicit "first wins" behavior, or
  2. Add a compiler test with 2+ memories (none named default) asserting the documented fallback, and mention the fallback explicitly in the frontmatter schema description so users aren't surprised.

Implicit ordering-dependent selection is the kind of interface leakiness /codebase-design flags — the caller has no way to know which memory was picked without reading the compiler source.

@copilot please address this.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot this PR still has substantial outstanding review feedback. Please refresh the branch if needed and run the pr-finisher skill before handing back to maintainers.

Outstanding themes to finish:

  • repo-memory backend trust boundary / agent-writable ledger risk
  • daily cap scoping and failed-run persistence semantics
  • imported-config validation and downstream usage accounting

After pushing fixes, resolve the remaining review threads and summarize focused validation results in-thread.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 35.6 AIC · ⌖ 8.87 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@copilot this PR still has substantial outstanding review feedback. Please refresh the branch if needed and run the pr-finisher skill before handing back to maintainers.

Outstanding themes to finis...

Addressed in 0c32592.

Focused fixes:

  • moved repo-memory daily AIC ledger writes into the trusted push_repo_memory post-processing path
  • removed agent-supplied ledger files before appending the current run’s trusted usage row
  • kept push persistence for failed agent runs and added evals dependency for downstream usage accounting
  • simplified firstRepoMemoryEntry and updated the ADR actor-scope note

Validation:

  • make fmt ✅
  • targeted Go workflow tests ✅
  • targeted JS guardrail/ledger tests ✅
  • make test-unit ✅
  • parallel_validation ✅
  • make agent-report-progress is still blocked by pre-existing custom-linter findings in compiler_string_api.go, compiler_orchestrator_workflow.go, and an existing JS warning in check_daily_aic_workflow_guardrail.cjs:396.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot enable on a few agentic workflows in this repo

Copilot AI and others added 2 commits September 23, 2026 18:48
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@copilot enable on a few agentic workflows in this repo

Enabled repo-memory daily AIC guardrails on Daily CLI Performance, Daily Code Metrics, and Daily Community Attribution in 32e7d04; regenerated their lock files.

Comment on lines +80 to +82
const ledgerPath = ledgerPathForDay(root, utcDay(now));
try {
fs.appendFileSync(ledgerPath, `${JSON.stringify(entry)}\n`, "utf8");
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please move this PR forward.

Open review feedback remains from: github-advanced-security, github-actions, copilot-pull-request-reviewer, a48204179-maker.

Please refresh the branch, address the outstanding review comments, and run the pr-finisher skill before handing back for maintainer review.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 29.1 AIC · ⌖ 8.59 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

… append

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please move this PR forward.

Open review feedback remains from: github-advanced-security, github-actions, copilot-pull-request-reviewer, a48204179-maker....

Fixed in the latest push: the push_repo_memory job now clones a trusted, read-only snapshot of the ledger branch and hydrates the reset ledger directory from it before appending the current run's entry (previously the reset+append sequence discarded every other run's entry recorded earlier the same day, even without any tampering). Focused Go and JS tests pass, make fmt and make test-impacted-go/make test-impacted-js are clean.

The other themes from this thread were already addressed in earlier commits on this branch: read-side trust gate (GH_AW_ALLOW_INSECURE_REPO_MEMORY_AIC), no actor-based filtering of the daily cap, failed-agent-run persistence, and imported-config backend validation.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot Ensure the final aic cost is written to the repo backend

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Ensure the final aic cost is written to the repo backend

Addressed in 5ac654a. The repo-memory ledger writer now defaults to /tmp/gh-aw/usage, the final collected usage staging directory, so the persisted ledger entry records the final per-run AIC total once rather than rescanning raw and copied files. Added a regression test covering duplicate raw usage files. Focused Go/JS tests and parallel validation passed; final progress validation remains blocked only by pre-existing unrelated custom-linter findings.

@pelikhan
pelikhan merged commit e8c0814 into main Sep 23, 2026
44 checks passed
@pelikhan
pelikhan deleted the copilot/consider-repo-memory-backed-rollup branch September 23, 2026 21:03
github-actions Bot added a commit that referenced this pull request Sep 24, 2026
Add glossary entries for user-facing terms introduced since the last
scan (through commit 2b90c3a):

- Grouped Audit Findings (`gh aw audit --group`, #63032)
- Gateway Steering Events (token_steering/timeout_steering in audit
  output, #62943)
- Custom Safe-Output Job Artifacts (`safe-outputs.jobs.<job>.artifacts`,
  #63017)
- Native Web Search (`tools.web-search` on the Copilot engine, #62957)

Reviewed but intentionally skipped as internal-only (no dedicated
user-facing docs): repo-memory backend for the daily AIC guardrail
(#62958) and container image override propagation to threat-detection
jobs (#63014). Confirmed no stale gVisor/Docker sbx glossary entries
remain after their removal (#63034).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.22

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Daily AIC guardrail cost scales with 24h run volume — consider a repo-memory-backed rollup instead of per-run artifact download

6 participants