Skip to content

Bump gh-aw-firewall to v0.28.50 - #67035

Merged
pelikhan merged 6 commits into
mainfrom
copilot/bump-gh-aw-firewall-v0-28-50
Oct 9, 2026
Merged

pelikhan merged 6 commits into
mainfrom
copilot/bump-gh-aw-firewall-v0-28-50

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Update gh-aw’s pinned firewall release to v0.28.50, which fixes --env-all handling for paths under unmounted RUNNER_TEMP subtrees.

  • Version pin: Set DefaultFirewallVersion to v0.28.50 and update its test.
  • Generated workflows: Refresh compiled lockfiles to use the new firewall image.
  • Release metadata: Add a patch changeset.


✨ PR Review Safe Output Test - Run 37864205681

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 64.9 AIC · ⌖ 4.14 AIC · ⊞ 853 · ◷
Comment /smoke-claude to run again

Copilot AI linked an issue Oct 9, 2026 that may be closed by this pull request
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Update gh-aw to use gh-aw-firewall v0.28.50 Bump gh-aw-firewall to v0.28.50 Oct 9, 2026
Copilot AI requested a review from lpcox October 9, 2026 00:21

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 64.9 AIC · ⌖ 4.14 AIC · ⊞ 853
Comment /smoke-claude to run again

@@ -0,0 +1,5 @@
---

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Changeset file looks good! The patch bump format is correct.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changeset remains a patch bump for gh-aw; no adjustment was needed. The generated lockfiles now retain immutable v0.28.50 firewall image digests in baa13b7.

"gh-aw": patch
---

Upgrade gh-aw-firewall to v0.28.50.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clear and concise description of the firewall version upgrade. 👍

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The version-upgrade description remains concise and accurate. I restored the firewall image digest pins across the generated lockfiles in baa13b7.

@lpcox
lpcox marked this pull request as ready for review October 9, 2026 00:37
Copilot AI balanced review requested due to automatic review settings October 9, 2026 00:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The generated workflows lost digest pins for all gh-aw-firewall containers, creating a supply-chain regression.

0 open findings

What changed in this PR

Updates gh-aw’s default firewall from v0.28.49 to v0.28.50 for corrected --env-all handling.

Changes:

  • Updates the firewall constant, test, and patch changeset.
  • Regenerates 333 workflow lockfiles for v0.28.50.
  • Upstream introduces no related schema changes.

Blocking finding: Every regenerated lockfile records unresolved container pins and uses mutable firewall tags.

File Description
pkg/​constants/​version_constants.go Bumps the default firewall version.
pkg/​constants/​version_constants_test.go Updates the expected version.
.changeset/​patch-bump-awf-v0-28-50.md Adds patch release metadata.
.github/​workflows/​*.lock.yml (333 files) Regenerates workflows for v0.28.50; firewall image pins remain unresolved.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch PR file list

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

PR #67035 is a routine version bump (gh-aw-firewall v0.28.50): the only human-authored files are the version constant + test (not shown in diff, excluded as it matched no diff hunks) and a changeset entry, plus 99 auto-generated .lock.yml files from recompilation. No custom logic, architecture change, or test gap exists to apply Matt Pocock skills against. The changeset already has two positive automated review comments. Skipping further review — nothing actionable to add.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

No ADR enforcement needed: PR #67035 does not have the implementation label (has_implementation_label=false) and has 0 new lines of code in default business logic directories (default_business_additions=0, threshold=100, requires_adr_by_default_volume=false).

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Pre-fetched PR diff is empty; no changed lines were available for the requested over-engineering review.

Generated by Ponytail Reviewer for #67035

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes

This bump moves the default AWF version to a tag whose container images are still unresolved, so the regenerated lockfiles drop immutable firewall image pins.

Blocking theme
  • The generated lockfiles now carry resolution_failures for ghcr.io/github/gh-aw-firewall/{agent,api-proxy,squid}:0.28.50 and compile bare image tags instead of @sha256 pins.
  • That turns a routine version bump into a reproducibility and supply-chain regression across hundreds of workflows.

Please publish/resolution-check the 0.28.50 images first, then rerun the full double recompile so the lockfiles are pinned again.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 52.2 AIC · ⌖ 8.01 AIC · ⊞ 19.4K
Comment /review to run again

@@ -68,7 +68,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.12.2"
//
// The first recompile regenerates all lock files using the new version; the second recompile
// refreshes the container SHA pins that were resolved during the first pass.
const DefaultFirewallVersion Version = "v0.28.49"
const DefaultFirewallVersion Version = "v0.28.50"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bumping DefaultFirewallVersion to v0.28.50 before the firewall images are digest-resolvable breaks lockfile pinning across the regenerated workflows.

💡 Why this blocks merge

git grep 'resolution_failures' HEAD -- .github/workflows/*.lock.yml now finds 333 lockfiles recording container_pin_not_found for the AWF agent, api-proxy, and squid images, and the generated download_docker_images.sh steps use bare :0.28.50 tags instead of @sha256-pinned refs.

That is a real reproducibility and supply-chain regression: workflows built from this change stop using immutable AWF image pins and start pulling whatever happens to be published under that tag. Please wait until the 0.28.50 images can be resolved to digests, then rerun the double recompile so the lockfiles are pinned again.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot address this review feedback

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot address this review feedback

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added and verified digest pins for the agent, api-proxy, squid, and cli-proxy images, then regenerated the workflow lockfiles. Fixed in baa13b7.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in baa13b7: all v0.28.50 firewall image roles used by the workflows now have immutable SHA-256 pins.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed: the firewall image digests are in the action pin cache and all generated workflow lockfiles were refreshed in baa13b7.

@lpcox

lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot run the pr-finisher skill

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot run the pr-finisher skill

Ran the pr-finisher pass and pushed baa13b7, restoring digest pins across the generated lockfiles. Local formatting, lint, and impacted tests passed; CI needs a human re-trigger after this push. The prior govulncheck failure on Go 1.26.8 remains.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: baa13b7
Sous-chef work:
Sous-chef state: 7447148aabef72a7906809a708a96a36ee7fd396a93236b23893943277e3fc2d

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 5.01 AIC · ⌖ 7.7 AIC · ⊞ 1K · ◷
Comment /souschef to run again

…rewall-v0-28-50

# Conflicts:
#	.github/workflows/eslint-factory-dispatcher.lock.yml
#	.github/workflows/eslint-miner.lock.yml
#	.github/workflows/eslint-monster.lock.yml

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts on this branch.

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes....

Merged the latest main in df650ad and regenerated the workflow locks; v0.28.50 digest pins are preserved. Formatting, lint, and the impacted test gate pass. The existing review threads already have substantive Copilot replies, but this environment has no thread-resolution control. CI needs a maintainer re-trigger; I did not trigger it.

Copilot AI and others added 2 commits October 9, 2026 03:24
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
…rewall-v0-28-50

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts on this branch.

Merged the latest main (c268866) in 1d704f8. make merge-main completed, regenerated all 333 workflow locks, and left no merge conflicts; formatting, lint, and impacted tests passed.

Copilot AI requested a review from pelikhan October 9, 2026 03:33
@pelikhan
pelikhan merged commit 6974432 into main Oct 9, 2026
3 checks passed
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump gh-aw-firewall to v0.28.50

5 participants