diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index c850e9e2aba..f360d0a0d09 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -3,7 +3,7 @@ "actions-ecosystem/action-add-labels@v1.1.3": { "repo": "actions-ecosystem/action-add-labels", "version": "v1.1.3", - "sha": "c96b68fec76a0987cd93957189e9abd0b9a72ff1", + "sha": "18f1af5e3544586314bbe15c0273249c770b2daf", "inputs": { "github_token": { "description": "A GitHub token.", @@ -156,7 +156,7 @@ "safedep/pmg@v1": { "repo": "safedep/pmg", "version": "v1", - "sha": "46cc70db535107183c9e752bb55d1d5c5f1a9290" + "sha": "5ac0f275b83d9d5a9342c6aae977ec32fa330daa" }, "super-linter/super-linter@v8.7.0": { "repo": "super-linter/super-linter", diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index 78e2a8e9cea..e09dff51383 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -1,5 +1,5 @@ # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"cbdd289a6d9258b11c33d8d52c475584519e0b91fb42de2310cf87e2f2a6ca32","body_hash":"70341e53871b3268cc556e830b07973a73aea98d4a690fa199321c6fa8e22e70","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.75"}} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"safedep/pmg","sha":"46cc70db535107183c9e752bb55d1d5c5f1a9290","version":"v1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"safedep/pmg","sha":"5ac0f275b83d9d5a9342c6aae977ec32fa330daa","version":"v1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -52,7 +52,7 @@ # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 (source v9) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - safedep/pmg@46cc70db535107183c9e752bb55d1d5c5f1a9290 # v1 +# - safedep/pmg@5ac0f275b83d9d5a9342c6aae977ec32fa330daa # v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8 @@ -545,7 +545,7 @@ jobs: - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) - uses: safedep/pmg@46cc70db535107183c9e752bb55d1d5c5f1a9290 # v1 + uses: safedep/pmg@5ac0f275b83d9d5a9342c6aae977ec32fa330daa # v1 - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/hippo-embed.lock.yml b/.github/workflows/hippo-embed.lock.yml index cc72ef4951a..67a8fd88dcf 100644 --- a/.github/workflows/hippo-embed.lock.yml +++ b/.github/workflows/hippo-embed.lock.yml @@ -1,5 +1,5 @@ # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"5ebc2e584f0c457ac7fa6cd7f460b51cb5559c674bd97dc362255fff74718fbf","body_hash":"64de223dab4a4aa12680edd01e56b6af15403962b2e54339a9091359c073bb02","strict":true,"agent_id":"pi","agent_model":"copilot/gpt-5.4","engine_versions":{"pi":"0.82.0"},"agent_image_runner":"aw-gpu-runner-T4"} -# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"safedep/pmg","sha":"46cc70db535107183c9e752bb55d1d5c5f1a9290","version":"v1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"safedep/pmg","sha":"5ac0f275b83d9d5a9342c6aae977ec32fa330daa","version":"v1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -51,7 +51,7 @@ # - actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 (source v9) # - actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 -# - safedep/pmg@46cc70db535107183c9e752bb55d1d5c5f1a9290 # v1 +# - safedep/pmg@5ac0f275b83d9d5a9342c6aae977ec32fa330daa # v1 # # Container images used: # - ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8 @@ -468,7 +468,7 @@ jobs: - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) - uses: safedep/pmg@46cc70db535107183c9e752bb55d1d5c5f1a9290 # v1 + uses: safedep/pmg@5ac0f275b83d9d5a9342c6aae977ec32fa330daa # v1 - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index e88cd4c72f9..9b8a2880b20 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -1,5 +1,5 @@ # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"6490f0055ab7144941c2953acc5b8184e6aa171d8b35a4846f74a317e88bb83a","body_hash":"0aab91539d6958fcb52ce9bd406485ac2d4c28a9ee69c4c4fcc364480d39ac75","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.145.0"}} -# gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions-ecosystem/action-add-labels","sha":"c96b68fec76a0987cd93957189e9abd0b9a72ff1","version":"v1.1.3"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}],"has_pull_request":true} +# gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions-ecosystem/action-add-labels","sha":"18f1af5e3544586314bbe15c0273249c770b2daf","version":"v1.1.3"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"b7ad1dad31e06c5925ef5d2fc7ad053ef454303e","version":"v7.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41","digest":"sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.41@sha256:e39efa0edf10c0d0bfc572b59a186dfccb1973f0f77e224bcf6e5a7d81ee95c8"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41","digest":"sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@sha256:6e2200dcb6a62b183cdcf7ed86e44713ba5ed8eeaf8de143319458898b6e8118"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41","digest":"sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.41@sha256:5338ee1b80ebf194436d9368deb376296c09a833ca4d80293dee249f94c7ff73"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41","digest":"sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.41@sha256:cfadaba80ad857ecb6603727296b42d92a9e0ff2f956276c4a46bb35f6f1ac24"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.5","digest":"sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.5@sha256:7550c5132d007266b696d77218e8d1b01f29e6e55520875b2431ef4044df71c9"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"},{"image":"ghcr.io/github/serena-mcp-server:latest","digest":"sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5","pinned_image":"ghcr.io/github/serena-mcp-server:latest@sha256:bf343399e3725c45528f531a230f3a04521d4cdef29f9a5af6282ff0d3c393c5"}],"has_pull_request":true} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -49,7 +49,7 @@ # - OPENAI_API_KEY # # Custom actions used: -# - actions-ecosystem/action-add-labels@c96b68fec76a0987cd93957189e9abd0b9a72ff1 # v1.1.3 +# - actions-ecosystem/action-add-labels@18f1af5e3544586314bbe15c0273249c770b2daf # v1.1.3 # - actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 # - actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 # - actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -2358,7 +2358,7 @@ jobs: - name: Add the 'smoked' label to the current pull request id: action_add_smoked_label if: steps.process_safe_outputs.outputs.action_add_smoked_label_payload != '' - uses: actions-ecosystem/action-add-labels@c96b68fec76a0987cd93957189e9abd0b9a72ff1 # v1.1.3 + uses: actions-ecosystem/action-add-labels@18f1af5e3544586314bbe15c0273249c770b2daf # v1.1.3 env: GITHUB_TOKEN: ${{ github.token }} with: diff --git a/pkg/actionpins/data/action_pins.json b/pkg/actionpins/data/action_pins.json index c850e9e2aba..f360d0a0d09 100644 --- a/pkg/actionpins/data/action_pins.json +++ b/pkg/actionpins/data/action_pins.json @@ -3,7 +3,7 @@ "actions-ecosystem/action-add-labels@v1.1.3": { "repo": "actions-ecosystem/action-add-labels", "version": "v1.1.3", - "sha": "c96b68fec76a0987cd93957189e9abd0b9a72ff1", + "sha": "18f1af5e3544586314bbe15c0273249c770b2daf", "inputs": { "github_token": { "description": "A GitHub token.", @@ -156,7 +156,7 @@ "safedep/pmg@v1": { "repo": "safedep/pmg", "version": "v1", - "sha": "46cc70db535107183c9e752bb55d1d5c5f1a9290" + "sha": "5ac0f275b83d9d5a9342c6aae977ec32fa330daa" }, "super-linter/super-linter@v8.7.0": { "repo": "super-linter/super-linter", diff --git a/pkg/cli/compile_integration_test.go b/pkg/cli/compile_integration_test.go index fd9f8141bbf..af0bc40d26c 100644 --- a/pkg/cli/compile_integration_test.go +++ b/pkg/cli/compile_integration_test.go @@ -1572,9 +1572,9 @@ When done, call add_label with the appropriate label. t.Errorf("Lock file should contain GITHUB_TOKEN env var in the action step\nLock file content:\n%s", lockContentStr) } - // Verify the handler manager step is present (required to process action payloads) - if !strings.Contains(lockContentStr, "safe_output_handler_manager.cjs") { - t.Errorf("Lock file should contain the safe_output_handler_manager.cjs step\nLock file content:\n%s", lockContentStr) + // Verify the process safe outputs step is present (required to process action payloads) + if !strings.Contains(lockContentStr, "process_safe_outputs.cjs") { + t.Errorf("Lock file should contain the process_safe_outputs.cjs step\nLock file content:\n%s", lockContentStr) } } diff --git a/pkg/workflow/action_cache.go b/pkg/workflow/action_cache.go index 5ad8371408e..dc78c73a374 100644 --- a/pkg/workflow/action_cache.go +++ b/pkg/workflow/action_cache.go @@ -494,17 +494,19 @@ func (c *ActionCache) GetInputs(repo, version string) (map[string]*ActionYAMLInp } // SetInputs stores the action inputs in the cache entry for the given repo and version. -// If no cache entry exists for the key, a new entry is created with an empty SHA so that -// inputs fetched from the network are persisted even before the SHA is resolved. +// If no cache entry with a non-empty SHA exists for the key, the call is a no-op. +// Inputs are only stored for entries that already have a resolved SHA, preventing +// placeholder entries with empty SHAs from being written to the on-disk cache. func (c *ActionCache) SetInputs(repo, version string, inputs map[string]*ActionYAMLInput) { + if inputs == nil { + actionCacheLog.Printf("Nil inputs for %s@%s, skipping cache update", repo, version) + return + } key := formatActionCacheKey(repo, version) entry, exists := c.Entries[key] - if !exists { - actionCacheLog.Printf("No cache entry for key=%s, creating new entry to store inputs", key) - entry = ActionCacheEntry{ - Repo: repo, - Version: version, - } + if !exists || entry.SHA == "" { + actionCacheLog.Printf("No existing cache entry with SHA for key=%s, skipping inputs update", key) + return } entry.Inputs = inputs c.Entries[key] = entry @@ -524,7 +526,9 @@ func (c *ActionCache) GetActionDescription(repo, version string) (string, bool) } // SetActionDescription stores the action description in the cache entry for the given repo and version. -// If no cache entry exists for the key, a new entry is created. +// If no cache entry with a non-empty SHA exists for the key, the call is a no-op. +// Descriptions are only stored for entries that already have a resolved SHA, preventing +// placeholder entries with empty SHAs from being written to the on-disk cache. // Empty descriptions are not stored; actions without a description string are treated the same as // actions whose description has not yet been fetched, so we avoid caching an empty string that // would prevent a later fetch from populating the field. @@ -538,11 +542,9 @@ func (c *ActionCache) SetActionDescription(repo, version, description string) { } key := formatActionCacheKey(repo, version) entry, exists := c.Entries[key] - if !exists { - entry = ActionCacheEntry{ - Repo: repo, - Version: version, - } + if !exists || entry.SHA == "" { + actionCacheLog.Printf("No existing cache entry with SHA for key=%s, skipping description update", key) + return } entry.ActionDescription = description c.Entries[key] = entry @@ -562,15 +564,18 @@ func (c *ActionCache) GetReleasedAt(repo, version string) (time.Time, bool) { } // SetReleasedAt stores the release publication date for the given repo and version. -// If no cache entry exists for the key, a new entry is created. +// If no cache entry with a non-empty SHA exists for the key, the call is a no-op. +// Release dates are only stored for entries that already have a resolved SHA, preventing +// placeholder entries with empty SHAs from being written to the on-disk cache. +// This matters most when checking cooldown for a new target version that is not yet pinned: +// without this guard, storing the release date would create a shell entry whose empty SHA +// would later fail the actions-lock.json validation. func (c *ActionCache) SetReleasedAt(repo, version string, t time.Time) { key := formatActionCacheKey(repo, version) entry, exists := c.Entries[key] - if !exists { - entry = ActionCacheEntry{ - Repo: repo, - Version: version, - } + if !exists || entry.SHA == "" { + actionCacheLog.Printf("No existing cache entry with SHA for key=%s, skipping release date update", key) + return } entry.ReleasedAt = &t c.Entries[key] = entry diff --git a/pkg/workflow/action_cache_test.go b/pkg/workflow/action_cache_test.go index 6fb12638780..97e2f94ce1b 100644 --- a/pkg/workflow/action_cache_test.go +++ b/pkg/workflow/action_cache_test.go @@ -689,16 +689,16 @@ func TestActionCacheInputs(t *testing.T) { t.Error("Expected nil inputs after SHA change, got non-nil") } - // SetInputs on a missing key now creates a new entry + // SetInputs on a missing key is now a no-op — it does not create empty-SHA entries. cache.SetInputs("owner/repo", "v99", map[string]*ActionYAMLInput{ "x": {Description: "x"}, }) inputs, ok = cache.GetInputs("owner/repo", "v99") - if !ok { - t.Error("Expected SetInputs on missing key to create entry") + if ok { + t.Error("Expected SetInputs on missing key to be a no-op (not create entry)") } - if len(inputs) != 1 || inputs["x"] == nil { - t.Error("Expected created entry to have the given inputs") + if inputs != nil { + t.Error("Expected nil inputs for missing entry") } } @@ -1077,3 +1077,55 @@ func TestActionCache_Set_EmptySHARejected(t *testing.T) { t.Errorf("entry SHA = %q, want %q", entry.SHA, sha) } } + +func TestActionCache_SettersNoOpOnEmptySHAEntry(t *testing.T) { + cache := NewActionCache(t.TempDir()) + key := formatActionCacheKey("owner/action", "v9") + cache.Entries[key] = ActionCacheEntry{ + Repo: "owner/action", + Version: "v9", + } + cache.dirty = false + + cache.SetReleasedAt("owner/action", "v9", time.Now()) + cache.SetInputs("owner/action", "v9", map[string]*ActionYAMLInput{ + "input": {Description: "desc"}, + }) + cache.SetActionDescription("owner/action", "v9", "description") + + entry := cache.Entries[key] + if entry.ReleasedAt != nil { + t.Error("Expected ReleasedAt to remain nil for empty-SHA entry") + } + if entry.Inputs != nil { + t.Error("Expected Inputs to remain nil for empty-SHA entry") + } + if entry.ActionDescription != "" { + t.Error("Expected ActionDescription to remain empty for empty-SHA entry") + } + if cache.dirty { + t.Error("Expected cache to remain clean when setters are no-op on empty-SHA entry") + } +} + +func TestActionCache_SetInputsNilNoOp(t *testing.T) { + cache := NewActionCache(t.TempDir()) + cache.Set("owner/action", "v1", "sha1234567890123456789012345678901234567890") + cache.SetInputs("owner/action", "v1", map[string]*ActionYAMLInput{ + "existing": {Description: "existing"}, + }) + cache.dirty = false + + cache.SetInputs("owner/action", "v1", nil) + + inputs, ok := cache.GetInputs("owner/action", "v1") + if !ok { + t.Fatal("Expected existing inputs to remain cached") + } + if _, exists := inputs["existing"]; !exists { + t.Error("Expected existing input to be preserved after nil SetInputs") + } + if cache.dirty { + t.Error("Expected cache to remain clean after nil SetInputs") + } +} diff --git a/pkg/workflow/data/action_pins.json b/pkg/workflow/data/action_pins.json index c850e9e2aba..f360d0a0d09 100644 --- a/pkg/workflow/data/action_pins.json +++ b/pkg/workflow/data/action_pins.json @@ -3,7 +3,7 @@ "actions-ecosystem/action-add-labels@v1.1.3": { "repo": "actions-ecosystem/action-add-labels", "version": "v1.1.3", - "sha": "c96b68fec76a0987cd93957189e9abd0b9a72ff1", + "sha": "18f1af5e3544586314bbe15c0273249c770b2daf", "inputs": { "github_token": { "description": "A GitHub token.", @@ -156,7 +156,7 @@ "safedep/pmg@v1": { "repo": "safedep/pmg", "version": "v1", - "sha": "46cc70db535107183c9e752bb55d1d5c5f1a9290" + "sha": "5ac0f275b83d9d5a9342c6aae977ec32fa330daa" }, "super-linter/super-linter@v8.7.0": { "repo": "super-linter/super-linter", diff --git a/pkg/workflow/safe_outputs_actions.go b/pkg/workflow/safe_outputs_actions.go index 151370bd8c1..9b62b1e892c 100644 --- a/pkg/workflow/safe_outputs_actions.go +++ b/pkg/workflow/safe_outputs_actions.go @@ -235,6 +235,13 @@ func (c *Compiler) fetchAndParseActionYAML(actionName string, config *SafeOutput // Cache the fetched inputs and description so subsequent compilations are // deterministic even when the network is unavailable. if actionYAML != nil && data.ActionCache != nil { + seedSHA := fetchRef + if !gitutil.IsValidFullSHA(seedSHA) { + seedSHA = extractSHAFromPinnedRef(resolvedRef) + } + if gitutil.IsValidFullSHA(seedSHA) { + data.ActionCache.Set(ref.Repo, ref.Ref, seedSHA) + } if actionYAML.Inputs != nil { data.ActionCache.SetInputs(ref.Repo, ref.Ref, actionYAML.Inputs) }