Bump default AWF and MCP Gateway versions to v0.27.42 / v0.4.6 and refresh pinned artifacts#48236
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
🤖 PR Triage
Summary: Version bump for default AWF ( Next action: Defer — author undraft when ready; low-risk merge once CI passes.
|
There was a problem hiding this comment.
Pull request overview
Bumps default AWF/MCP Gateway versions and refreshes corresponding generated artifacts. Review found that AWF v0.27.42’s runtime schema still rejects apiProxy.providers, which this bump enables.
Changes:
- Updated runtime version defaults.
- Added synchronized container digest pins.
- Recompiled workflow locks and added a patch changeset.
Show a summary per file
| File | Description |
|---|---|
pkg/constants/version_constants.go |
Updates default versions. |
.github/aw/actions-lock.json |
Adds new image pins. |
pkg/actionpins/data/action_pins.json |
Syncs embedded pins. |
pkg/workflow/data/action_pins.json |
Syncs workflow pins. |
.github/workflows/smoke-ci.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/release.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/firewall.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/example-permissions-warning.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/daily-max-ai-credits-test.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/codex-github-remote-mcp-test.lock.yml |
Refreshes generated runtime pins. |
.github/workflows/ai-moderator.lock.yml |
Refreshes generated runtime pins. |
.changeset/patch-bump-awf-v0-27-42-mcpg-v0-4-6.md |
Records the patch release change. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 23/267 changed files
- Comments generated: 1
- Review effort level: Medium
| @@ -70,7 +70,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.7.0" | |||
| // | |||
| // The first recompile regenerates all lock files using the new version; the second recompile | |||
| // refreshes the container SHA pins that were resolved during the first pass. | |||
| const DefaultFirewallVersion Version = "v0.27.41" | |||
| const DefaultFirewallVersion Version = "v0.27.42" | |||
There was a problem hiding this comment.
Addressed in commits b4363ec and e4d45be:
- Bumped
AWFAPIProxyProvidersMinVersiontov0.27.43soawfSupportsAPIProxyProvidersreturnsfalsefor the defaultv0.27.42—apiProxy.providersis no longer emitted - Recompiled the two affected lock files (
daily-model-inventory,smoke-copilot) to remove the previously emittedapiProxy.providersfield
|
@copilot address review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
…sed for AWF v0.27.42 AWF v0.27.42 does not include apiProxy.providers in its config schema. Setting DefaultFirewallVersion=v0.27.42 matched the previous minimum version value, causing awfSupportsAPIProxyProviders to return true and emit a field that AWF v0.27.42 rejects. Advance the minimum to v0.27.43 so the feature stays gated off until a release that actually ships the schema support. Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
|
@copilot please run the
|
Fixed in commit |
…jects it) After bumping AWFAPIProxyProvidersMinVersion to v0.27.43, the compiled lock files that contained apiProxy.providers for the default AWF version needed regeneration. Two lock files (daily-model-inventory, smoke-copilot) had apiProxy.providers emitted; the recompile correctly drops that field. Also reverts an accidental one-line addition to SKILL.md from the plan commit. Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
PR finisher complete. Here's the state:
Actions taken: Regenerated wasm golden files ( Hand-off: CI must be re-triggered by a maintainer (close/reopen PR or push) before merge. |
|
@copilot merge main and recompile |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
…-to-v02742-and-mcpg-to-v046 Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Done. Merged main into the branch and recompiled all 263 workflow lock files (0 errors). |
🤖 PR Triage
Score breakdown: Impact 22/50 · Urgency 14/30 · Quality 16/20 Rationale: Routine version bump (AWF v0.27.42, MCP Gateway v0.4.6) with regenerated pinned artifacts. Large diff (5948+/5846−, 278 files) but mostly auto-generated artifacts. Smoke test results mixed (partly failing). No CI check runs found — needs CI to run before merging. Can be reviewed together with similar future version bumps.
|
|
@copilot merge main and recompile |
…-to-v02742-and-mcpg-to-v046 # Conflicts: # .github/workflows/ab-testing-advisor.lock.yml # .github/workflows/ace-editor.lock.yml # .github/workflows/agent-performance-analyzer.lock.yml # .github/workflows/agent-persona-explorer.lock.yml # .github/workflows/agentic-token-audit.lock.yml # .github/workflows/agentic-token-optimizer.lock.yml # .github/workflows/agentic-token-trend-audit.lock.yml # .github/workflows/ai-moderator.lock.yml # .github/workflows/api-consumption-report.lock.yml # .github/workflows/approach-validator.lock.yml # .github/workflows/archie.lock.yml # .github/workflows/architecture-guardian.lock.yml # .github/workflows/artifacts-summary.lock.yml # .github/workflows/audit-workflows.lock.yml # .github/workflows/auto-triage-issues.lock.yml # .github/workflows/avenger.lock.yml # .github/workflows/aw-failure-investigator.lock.yml # .github/workflows/blog-auditor.lock.yml # .github/workflows/bot-detection.lock.yml # .github/workflows/brave.lock.yml # .github/workflows/breaking-change-checker.lock.yml # .github/workflows/changeset.lock.yml # .github/workflows/chaos-pr-bundle-fuzzer.lock.yml # .github/workflows/ci-coach.lock.yml # .github/workflows/ci-doctor.lock.yml # .github/workflows/claude-code-user-docs-review.lock.yml # .github/workflows/cli-consistency-checker.lock.yml # .github/workflows/cli-version-checker.lock.yml # .github/workflows/cloclo.lock.yml # .github/workflows/code-scanning-fixer.lock.yml # .github/workflows/code-simplifier.lock.yml # .github/workflows/codex-github-remote-mcp-test.lock.yml # .github/workflows/commit-changes-analyzer.lock.yml # .github/workflows/constraint-solving-potd.lock.yml # .github/workflows/contribution-check.lock.yml # .github/workflows/copilot-agent-analysis.lock.yml # .github/workflows/copilot-centralization-drilldown.lock.yml # .github/workflows/copilot-centralization-optimizer.lock.yml # .github/workflows/copilot-cli-deep-research.lock.yml # .github/workflows/copilot-opt.lock.yml # .github/workflows/copilot-pr-merged-report.lock.yml # .github/workflows/copilot-pr-nlp-analysis.lock.yml # .github/workflows/copilot-pr-prompt-analysis.lock.yml # .github/workflows/copilot-session-insights.lock.yml # .github/workflows/craft.lock.yml # .github/workflows/daily-agent-of-the-day-blog-writer.lock.yml # .github/workflows/daily-agentrx-trace-optimizer.lock.yml # .github/workflows/daily-ambient-context-optimizer.lock.yml # .github/workflows/daily-architecture-diagram.lock.yml # .github/workflows/daily-assign-issue-to-user.lock.yml # .github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml # .github/workflows/daily-aw-cross-repo-compile-check.lock.yml # .github/workflows/daily-awf-spec-compiler-surfacing.lock.yml # .github/workflows/daily-byok-ollama-test.lock.yml # .github/workflows/daily-cache-strategy-analyzer.lock.yml # .github/workflows/daily-caveman-optimizer.lock.yml # .github/workflows/daily-choice-test.lock.yml # .github/workflows/daily-cli-performance.lock.yml # .github/workflows/daily-cli-tools-tester.lock.yml # .github/workflows/daily-code-metrics.lock.yml # .github/workflows/daily-community-attribution.lock.yml # .github/workflows/daily-compiler-quality.lock.yml # .github/workflows/daily-compiler-threat-spec-optimizer.lock.yml # .github/workflows/daily-credit-limit-test.lock.yml # .github/workflows/daily-doc-healer.lock.yml # .github/workflows/daily-doc-updater.lock.yml # .github/workflows/daily-elixir-credo-snippet-audit.lock.yml # .github/workflows/daily-evals-report.lock.yml # .github/workflows/daily-experiment-report.lock.yml # .github/workflows/daily-fact.lock.yml # .github/workflows/daily-file-diet.lock.yml # .github/workflows/daily-firewall-report.lock.yml # .github/workflows/daily-formal-spec-verifier.lock.yml # .github/workflows/daily-function-namer.lock.yml # .github/workflows/daily-geo-optimizer.lock.yml # .github/workflows/daily-github-docs-seo-optimizer.lock.yml # .github/workflows/daily-go-test-parallelizer.lock.yml # .github/workflows/daily-hippo-learn.lock.yml # .github/workflows/daily-issues-report.lock.yml # .github/workflows/daily-malicious-code-scan.lock.yml # .github/workflows/daily-max-ai-credits-test.lock.yml # .github/workflows/daily-mcp-concurrency-analysis.lock.yml # .github/workflows/daily-model-inventory.lock.yml # .github/workflows/daily-model-resolution.lock.yml # .github/workflows/daily-multi-device-docs-tester.lock.yml # .github/workflows/daily-news.lock.yml # .github/workflows/daily-observability-report.lock.yml # .github/workflows/daily-performance-summary.lock.yml # .github/workflows/daily-regulatory.lock.yml # .github/workflows/daily-reliability-review.lock.yml # .github/workflows/daily-rendering-scripts-verifier.lock.yml # .github/workflows/daily-repo-chronicle.lock.yml # .github/workflows/daily-safe-output-integrator.lock.yml # .github/workflows/daily-safe-output-optimizer.lock.yml # .github/workflows/daily-safe-outputs-conformance.lock.yml # .github/workflows/daily-safeoutputs-git-simulator.lock.yml # .github/workflows/daily-secrets-analysis.lock.yml # .github/workflows/daily-security-observability.lock.yml # .github/workflows/daily-security-red-team.lock.yml # .github/workflows/daily-semgrep-scan.lock.yml # .github/workflows/daily-sentrux-report.lock.yml # .github/workflows/daily-skill-optimizer.lock.yml # .github/workflows/daily-spdd-spec-planner.lock.yml # .github/workflows/daily-squid-image-scan.lock.yml # .github/workflows/daily-syntax-error-quality.lock.yml # .github/workflows/daily-team-evolution-insights.lock.yml # .github/workflows/daily-team-status.lock.yml # .github/workflows/daily-testify-uber-super-expert.lock.yml # .github/workflows/daily-token-consumption-report.lock.yml # .github/workflows/daily-vulnhunter-scan.lock.yml # .github/workflows/daily-windows-terminal-integration-builder.lock.yml # .github/workflows/daily-workflow-updater.lock.yml # .github/workflows/daily-yamllint-fixer.lock.yml # .github/workflows/dataflow-pr-discussion-dataset.lock.yml # .github/workflows/dead-code-remover.lock.yml # .github/workflows/deep-report.lock.yml # .github/workflows/deepsec-security-scan.lock.yml # .github/workflows/delight.lock.yml # .github/workflows/dependabot-burner.lock.yml # .github/workflows/dependabot-go-checker.lock.yml # .github/workflows/deployment-incident-monitor.lock.yml # .github/workflows/design-decision-gate.lock.yml # .github/workflows/designer-drift-audit.lock.yml # .github/workflows/detection-analysis-report.lock.yml # .github/workflows/dev-hawk.lock.yml # .github/workflows/dev.lock.yml # .github/workflows/developer-docs-consolidator.lock.yml # .github/workflows/dictation-prompt.lock.yml # .github/workflows/discussion-task-miner.lock.yml # .github/workflows/docs-noob-tester.lock.yml # .github/workflows/draft-pr-cleanup.lock.yml # .github/workflows/duplicate-code-detector.lock.yml # .github/workflows/eslint-miner.lock.yml # .github/workflows/eslint-monster.lock.yml # .github/workflows/eslint-refiner.lock.yml # .github/workflows/example-failure-category-filter.lock.yml # .github/workflows/example-permissions-warning.lock.yml # .github/workflows/example-workflow-analyzer.lock.yml # .github/workflows/firewall-escape.lock.yml # .github/workflows/firewall.lock.yml # .github/workflows/functional-pragmatist.lock.yml # .github/workflows/github-mcp-structural-analysis.lock.yml # .github/workflows/github-mcp-tools-report.lock.yml # .github/workflows/github-remote-mcp-auth-test.lock.yml # .github/workflows/glossary-maintainer.lock.yml # .github/workflows/go-fan.lock.yml # .github/workflows/go-logger.lock.yml # .github/workflows/go-pattern-detector.lock.yml # .github/workflows/gpclean.lock.yml # .github/workflows/grumpy-reviewer.lock.yml # .github/workflows/hippo-embed.lock.yml # .github/workflows/hourly-ci-cleaner.lock.yml # .github/workflows/impeccable-skills-reviewer.lock.yml # .github/workflows/instructions-janitor.lock.yml # .github/workflows/issue-arborist.lock.yml # .github/workflows/issue-monster.lock.yml # .github/workflows/issue-triage-agent.lock.yml # .github/workflows/jsweep.lock.yml # .github/workflows/layout-spec-maintainer.lock.yml # .github/workflows/lint-monster.lock.yml # .github/workflows/linter-miner.lock.yml # .github/workflows/lockfile-stats.lock.yml # .github/workflows/mattpocock-skills-reviewer.lock.yml # .github/workflows/mcp-inspector.lock.yml # .github/workflows/mergefest.lock.yml # .github/workflows/metrics-collector.lock.yml # .github/workflows/necromancer.lock.yml # .github/workflows/notion-issue-summary.lock.yml # .github/workflows/objective-impact-report.lock.yml # .github/workflows/org-health-report.lock.yml # .github/workflows/outcome-collector.lock.yml # .github/workflows/pdf-summary.lock.yml # .github/workflows/plan.lock.yml # .github/workflows/poem-bot.lock.yml # .github/workflows/portfolio-analyst.lock.yml # .github/workflows/pr-code-quality-reviewer.lock.yml # .github/workflows/pr-description-caveman.lock.yml # .github/workflows/pr-nitpick-reviewer.lock.yml # .github/workflows/pr-sous-chef.lock.yml # .github/workflows/pr-triage-agent.lock.yml # .github/workflows/prompt-clustering-analysis.lock.yml # .github/workflows/python-data-charts.lock.yml # .github/workflows/q.lock.yml # .github/workflows/refactoring-cadence.lock.yml # .github/workflows/refiner.lock.yml # .github/workflows/release.lock.yml # .github/workflows/repo-audit-analyzer.lock.yml # .github/workflows/repo-tree-map.lock.yml # .github/workflows/repository-quality-improver.lock.yml # .github/workflows/research.lock.yml # .github/workflows/ruflo-backed-task.lock.yml # .github/workflows/safe-output-health.lock.yml # .github/workflows/schema-consistency-checker.lock.yml # .github/workflows/schema-feature-coverage.lock.yml # .github/workflows/scout.lock.yml # .github/workflows/security-compliance.lock.yml # .github/workflows/security-review.lock.yml # .github/workflows/semantic-function-refactor.lock.yml # .github/workflows/sergo.lock.yml # .github/workflows/sighthound-security-scan.lock.yml # .github/workflows/skillet.lock.yml # .github/workflows/slide-deck-maintainer.lock.yml # .github/workflows/smoke-agent-all-merged.lock.yml # .github/workflows/smoke-agent-all-none.lock.yml # .github/workflows/smoke-agent-public-approved.lock.yml # .github/workflows/smoke-agent-public-none.lock.yml # .github/workflows/smoke-agent-scoped-approved.lock.yml # .github/workflows/smoke-antigravity.lock.yml # .github/workflows/smoke-call-workflow.lock.yml # .github/workflows/smoke-ci.lock.yml # .github/workflows/smoke-claude-on-copilot.lock.yml # .github/workflows/smoke-claude.lock.yml # .github/workflows/smoke-codex.lock.yml # .github/workflows/smoke-copilot-aoai-apikey.lock.yml # .github/workflows/smoke-copilot-aoai-entra.lock.yml # .github/workflows/smoke-copilot-arm.lock.yml # .github/workflows/smoke-copilot-mai.lock.yml # .github/workflows/smoke-copilot-sdk.lock.yml # .github/workflows/smoke-copilot-small.lock.yml # .github/workflows/smoke-copilot-sub-agents.lock.yml # .github/workflows/smoke-copilot.lock.yml # .github/workflows/smoke-create-cross-repo-pr.lock.yml # .github/workflows/smoke-gemini.lock.yml # .github/workflows/smoke-github-claude.lock.yml # .github/workflows/smoke-multi-pr.lock.yml # .github/workflows/smoke-opencode.lock.yml # .github/workflows/smoke-otel-backends.lock.yml # .github/workflows/smoke-pi.lock.yml # .github/workflows/smoke-project.lock.yml # .github/workflows/smoke-service-ports.lock.yml # .github/workflows/smoke-temporary-id.lock.yml # .github/workflows/smoke-test-tools.lock.yml # .github/workflows/smoke-update-cross-repo-pr.lock.yml # .github/workflows/smoke-workflow-call-with-inputs.lock.yml # .github/workflows/smoke-workflow-call.lock.yml # .github/workflows/spec-enforcer.lock.yml # .github/workflows/spec-extractor.lock.yml # .github/workflows/spec-librarian.lock.yml # .github/workflows/stale-pr-cleanup.lock.yml # .github/workflows/stale-repo-identifier.lock.yml # .github/workflows/static-analysis-report.lock.yml # .github/workflows/step-name-alignment.lock.yml # .github/workflows/sub-issue-closer.lock.yml # .github/workflows/super-linter.lock.yml # .github/workflows/technical-doc-writer.lock.yml # .github/workflows/terminal-stylist.lock.yml # .github/workflows/test-quality-sentinel.lock.yml # .github/workflows/tidy.lock.yml # .github/workflows/typist.lock.yml # .github/workflows/ubuntu-image-analyzer.lock.yml # .github/workflows/uk-ai-operational-resilience.lock.yml # .github/workflows/unbloat-docs.lock.yml # .github/workflows/update-astro.lock.yml # .github/workflows/video-analyzer.lock.yml # .github/workflows/visual-regression-checker.lock.yml # .github/workflows/weekly-blog-post-writer.lock.yml # .github/workflows/weekly-editors-health-check.lock.yml # .github/workflows/weekly-issue-summary.lock.yml # .github/workflows/weekly-safe-outputs-spec-review.lock.yml # .github/workflows/workflow-generator.lock.yml # .github/workflows/workflow-health-manager.lock.yml # .github/workflows/workflow-normalizer.lock.yml # .github/workflows/workflow-skill-extractor.lock.yml # pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden # pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden # pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden # pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden # pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden # pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden # pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden # pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden # pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Done. Merged main (resolved conflicts in generated lock files and wasm goldens), recompiled all 263 workflows (0 errors), regenerated wasm golden files, and validated with |
This updates gh-aw’s default pinned runtime versions to the latest AWF and MCP Gateway releases and regenerates pinned workflow artifacts to match those defaults.
Version pins
/pkg/constants/version_constants.go:DefaultFirewallVersion:v0.27.41→v0.27.42DefaultMCPGatewayVersion:v0.4.5→v0.4.6Container digest pin set
/.github/aw/actions-lock.json:ghcr.io/github/gh-aw-firewall/{agent,agent-act,api-proxy,cli-proxy,squid}:0.27.42ghcr.io/github/gh-aw-mcpg:v0.4.6/pkg/actionpins/data/action_pins.json/pkg/workflow/data/action_pins.jsonRecompiled generated workflow locks
.github/workflows/*.lock.ymlso compiled outputs use the updated defaults and refreshed digest pins.Changeset
/.changeset/patch-bump-awf-v0-27-42-mcpg-v0-4-6.md.Run: https://github.com/github/gh-aw/actions/runs/30233154470
✨ PR Review Safe Output Test - Run 30236132659
Warning
Firewall blocked 6 domains
The following domains were blocked by the firewall during workflow execution:
accounts.google.comandroid.clients.google.comclients2.google.comcontentautofill.googleapis.comsafebrowsingohttpgateway.googleapis.comwww.google.comSee Network Configuration for more information.