Repository navigation
Bump gh-aw-firewall to v0.28.50 - #67035
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
clients2.google.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 64.9 AIC · ⌖ 4.14 AIC · ⊞ 853
Comment /smoke-claude to run again
| @@ -0,0 +1,5 @@ | |||
| --- | |||
There was a problem hiding this comment.
✅ Changeset file looks good! The patch bump format is correct.
There was a problem hiding this comment.
The changeset remains a patch bump for gh-aw; no adjustment was needed. The generated lockfiles now retain immutable v0.28.50 firewall image digests in baa13b7.
| "gh-aw": patch | ||
| --- | ||
|
|
||
| Upgrade gh-aw-firewall to v0.28.50. |
There was a problem hiding this comment.
Clear and concise description of the firewall version upgrade. 👍
There was a problem hiding this comment.
The version-upgrade description remains concise and accurate. I restored the firewall image digest pins across the generated lockfiles in baa13b7.
There was a problem hiding this comment.
🔵 Needs a closer look
The generated workflows lost digest pins for all gh-aw-firewall containers, creating a supply-chain regression.
0 open findings
What changed in this PR
Updates gh-aw’s default firewall from v0.28.49 to v0.28.50 for corrected --env-all handling.
Changes:
- Updates the firewall constant, test, and patch changeset.
- Regenerates 333 workflow lockfiles for v0.28.50.
- Upstream introduces no related schema changes.
Blocking finding: Every regenerated lockfile records unresolved container pins and uses mutable firewall tags.
| File | Description |
|---|---|
pkg/constants/version_constants.go |
Bumps the default firewall version. |
pkg/constants/version_constants_test.go |
Updates the expected version. |
.changeset/patch-bump-awf-v0-28-50.md |
Adds patch release metadata. |
.github/workflows/*.lock.yml (333 files) |
Regenerates workflows for v0.28.50; firewall image pins remain unresolved. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch PR file list
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅ PR #67035 is a routine version bump (gh-aw-firewall v0.28.50): the only human-authored files are the version constant + test (not shown in diff, excluded as it matched no diff hunks) and a changeset entry, plus 99 auto-generated .lock.yml files from recompilation. No custom logic, architecture change, or test gap exists to apply Matt Pocock skills against. The changeset already has two positive automated review comments. Skipping further review — nothing actionable to add.
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft. No ADR enforcement needed: PR #67035 does not have the implementation label (has_implementation_label=false) and has 0 new lines of code in default business logic directories (default_business_additions=0, threshold=100, requires_adr_by_default_volume=false).
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
✅ Ponytail Reviewer completed successfully! Pre-fetched PR diff is empty; no changed lines were available for the requested over-engineering review.
|
There was a problem hiding this comment.
Request changes
This bump moves the default AWF version to a tag whose container images are still unresolved, so the regenerated lockfiles drop immutable firewall image pins.
Blocking theme
- The generated lockfiles now carry
resolution_failuresforghcr.io/github/gh-aw-firewall/{agent,api-proxy,squid}:0.28.50and compile bare image tags instead of@sha256pins. - That turns a routine version bump into a reproducibility and supply-chain regression across hundreds of workflows.
Please publish/resolution-check the 0.28.50 images first, then rerun the full double recompile so the lockfiles are pinned again.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 52.2 AIC · ⌖ 8.01 AIC · ⊞ 19.4K
Comment /review to run again
| @@ -68,7 +68,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.12.2" | |||
| // | |||
| // The first recompile regenerates all lock files using the new version; the second recompile | |||
| // refreshes the container SHA pins that were resolved during the first pass. | |||
| const DefaultFirewallVersion Version = "v0.28.49" | |||
| const DefaultFirewallVersion Version = "v0.28.50" | |||
There was a problem hiding this comment.
Bumping DefaultFirewallVersion to v0.28.50 before the firewall images are digest-resolvable breaks lockfile pinning across the regenerated workflows.
💡 Why this blocks merge
git grep 'resolution_failures' HEAD -- .github/workflows/*.lock.yml now finds 333 lockfiles recording container_pin_not_found for the AWF agent, api-proxy, and squid images, and the generated download_docker_images.sh steps use bare :0.28.50 tags instead of @sha256-pinned refs.
That is a real reproducibility and supply-chain regression: workflows built from this change stop using immutable AWF image pins and start pulling whatever happens to be published under that tag. Please wait until the 0.28.50 images can be resolved to digests, then rerun the double recompile so the lockfiles are pinned again.
There was a problem hiding this comment.
Added and verified digest pins for the agent, api-proxy, squid, and cli-proxy images, then regenerated the workflow lockfiles. Fixed in baa13b7.
There was a problem hiding this comment.
Addressed in baa13b7: all v0.28.50 firewall image roles used by the workflows now have immutable SHA-256 pins.
There was a problem hiding this comment.
Addressed: the firewall image digests are in the action pin cache and all generated workflow lockfiles were refreshed in baa13b7.
|
@copilot run the pr-finisher skill |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Ran the pr-finisher pass and pushed |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: baa13b7
|
…rewall-v0-28-50 # Conflicts: # .github/workflows/eslint-factory-dispatcher.lock.yml # .github/workflows/eslint-miner.lock.yml # .github/workflows/eslint-monster.lock.yml Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot resolve the merge conflicts on this branch. |
Merged the latest |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
…rewall-v0-28-50 Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |
Update gh-aw’s pinned firewall release to v0.28.50, which fixes
--env-allhandling for paths under unmountedRUNNER_TEMPsubtrees.DefaultFirewallVersiontov0.28.50and update its test.✨ PR Review Safe Output Test - Run 37864205681
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
clients2.google.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.