Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: sync-preview pushes directly on clean merge, PRs only on conflict by notgitika · Pull Request #1078 · aws/agentcore-cli · GitHub
Skip to content

fix: sync-preview pushes directly on clean merge, PRs only on conflict - #1078

Merged
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr
May 12, 2026
Merged

fix: sync-preview pushes directly on clean merge, PRs only on conflict#1078
notgitika merged 6 commits into
mainfrom
fix/sync-preview-always-pr

Conversation

@notgitika

@notgitikanotgitika commented May 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Reworks the sync-preview workflow to push directly to preview when the merge is clean (using the agentcore-devx-automation GitHub App to bypass branch protection), and only creates a PR when there are real conflicts.

How it works

  1. Clean merge → merges main, restores preview's package version, pushes directly to preview. No PR.
  2. Only version conflicts (package.json/package-lock.json) → accepts main's content, restores preview's version field, pushes directly. No PR.
  3. Real conflicts in other files → opens a PR with conflict markers for manual resolution.

Key changes

  • Uses actions/create-github-app-token with the agentcore-devx-automation app to get a token that bypasses branch protection
  • Instead of ignoring package.json/lock entirely (which discards new deps, scripts, etc. from main), accepts main's full content and surgically restores only the version field
  • CHANGELOG.md and schema merge normally from main — no special handling
  • Dedup check prevents multiple conflict PRs

Test plan

  • Workflow YAML is valid (verified locally)
  • Push to main triggers sync-preview workflow
  • Clean merge pushes directly to preview with version restored
  • Version-only conflicts auto-resolve and push directly
  • Real conflicts in other files produce a PR with conflict markers
  • Existing open PR prevents duplicate creation
  • App token has push access to preview branch

@notgitika
notgitika requested a review from a teamMay 1, 2026 01:56
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Reviewed the workflow — a few things worth considering before merge:

1. PRs created by GITHUB_TOKEN won't trigger pull_request workflows

This is a documented GitHub limitation to prevent recursive workflow runs: "When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN will not create a new workflow run."

That means the sync PRs created here will not run build-and-test.yml or lint.yml (both of which trigger on pull_request without branch filters). Looking at the current preview branch ruleset, no status checks are required for merge, so this won't strictly block merging — but reviewers approving these PRs won't see CI signal, which somewhat defeats the purpose of going through a PR.

Options:

  • Use a PAT (or a GitHub App token via actions/create-github-app-token) stored as a secret in place of ${{ github.token }} for the gh pr create calls, so workflows fire.
  • Accept the trade-off and document that sync PRs intentionally bypass CI (in which case the PR body should probably call that out).
  • Add a workflow_dispatch/manual re-run step or trigger checks explicitly.

2. Rapid pushes to main while a sync PR is open will pile up silently

With the new logic, if commit A is pushed → sync PR opened → commit B is pushed before the sync PR is merged, the second run sees count != 0 and skips entirely. B only gets synced whenever the next push to main happens after the existing PR merges. In the old flow, clean merges pushed directly, so every main push was reflected immediately.

This is probably acceptable (it eventually catches up), but if sync PRs sit open for a while it could surprise people. Options:

  • Leave as-is and rely on "the next push will catch up" (worth a comment in the workflow).
  • Force-push the new merge onto the existing sync branch so the open PR stays current.

3. Orphan sync-preview/merge-main-* branches

Each run creates a fresh timestamped branch and nothing deletes them after the PR merges/closes. Over time these will accumulate. GitHub's "Automatically delete head branches" repo setting handles this cleanly if it's on; otherwise consider adding gh pr merge --delete-branch guidance or a cleanup step.

Issue #1 is the one I'd most want resolved (or at least explicitly decided on) before merging.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.33%9083 / 20958
🔵Statements42.61%9646 / 22636
🔵Functions40.11%1569 / 3911
🔵Branches40.14%5862 / 14601
Generated in workflow #2840 for commit 7e9f6a1 by the Vitest Coverage Report Action

@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 1cdd7ec to a36a123CompareMay 1, 2026 02:01
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 1, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

1/ is a real issue. unfortunately we need a PAT token or github app token to resolve that
2/ acceptable trade-off imo
3/ Automatically delete head branches is enabled in settings so this is not an issue

Hweinstock
Hweinstock previously approved these changes May 1, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from a36a123 to 4377fedCompareMay 11, 2026 20:48
@notgitikanotgitika changed the title fix: sync-preview workflow always creates PR instead of direct pushfix: sync-preview restores version instead of ignoring filesMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.13.1.tgz

How to install

npm install https://github.com/aws/agentcore-cli/releases/download/pr-1078-tarball/aws-agentcore-0.13.1.tgz

avi-alpert
avi-alpert previously approved these changes May 11, 2026
@notgitika
notgitika requested a review from HweinstockMay 11, 2026 21:01
@notgitikanotgitika changed the title fix: sync-preview restores version instead of ignoring filesfix: sync-preview pushes directly on clean merge, PRs only on conflictMay 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M agentcore-harness-reviewing AgentCore Harness review in progress and removed size/m PR size: M labels May 11, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from cceae68 to 664aff9CompareMay 12, 2026 17:56
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@github-actionsgithub-actionsBot added the size/m PR size: M label May 12, 2026
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
@notgitika
notgitikaforce-pushed the fix/sync-preview-always-pr branch from 64b3783 to 7e9f6a1CompareMay 12, 2026 19:26
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels May 12, 2026
@notgitika
notgitika merged commit 0153694 into mainMay 12, 2026
25 of 26 checks passed
@notgitika
notgitika deleted the fix/sync-preview-always-pr branch May 12, 2026 21:47
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
notgitika added a commit that referenced this pull request May 13, 2026
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
tejaskash pushed a commit that referenced this pull request May 13, 2026
* docs: add telemetry instrumentation guide (#1197)
* chore: replace PAT tokens with GitHub App token (#1198)
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
* fix: add batch eval, recommendation, and CloudWatch Logs write permissions to docs (#1113)
* feat: instrument telemetry for create command (CLI + TUI) (#1202)
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
* chore: replace all github.token/GITHUB_TOKEN with GitHub App token
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
* fix: bump versions to resolve security audit failure
* revert: keep pr-title.yml using GITHUB_TOKEN (read-only access sufficient)
* feat(evaluator): add kmsKeyArn support for custom evaluator (#994)
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
* refactor: unify result types with discriminated Result<T, E> union (#1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
* feat: record command attrs on telemetry failure via fallbackAttrs (#1204)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
* fix: sync-preview pushes directly on clean merge, PRs only on conflict (#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
* feat: instrument telemetry for deploy command (CLI + TUI) (#1206)
* chore: sync safe commits from main into preview
Cherry-picks non-breaking changes from main:
- docs: add telemetry instrumentation guide (#1197)
- chore: replace PAT tokens with GitHub App token (#1198)
- fix: add batch eval, recommendation, CloudWatch Logs permissions (#1113)
- feat(evaluator): add kmsKeyArn support (#994)
- chore: replace github.token with GitHub App token (#1210)
- fix: sync-preview workflow rewrite (#1078)
Skipped (requires dedicated effort due to Result type refactor):
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for create/deploy (#1202, #1206)
- feat: record command attrs on failure (#1204)
* chore: merge main into preview with Result refactor
Brings in all remaining main commits including:
- refactor: unify result types with Result<T, E> (#1125)
- feat: instrument telemetry for deploy command (#1206)
- feat: record command attrs on failure (#1204)
- feat: instrument telemetry for create command (#1202)
Adapts preview's deploy flow to use OperationResult with string errors
for compatibility with the telemetry layer.
---------
Co-authored-by: Hweinstock <42325418+Hweinstock@users.noreply.github.com>
Co-authored-by: Aidan Daly <99039782+aidandaly24@users.noreply.github.com>
Co-authored-by: Gitika <53349492+notgitika@users.noreply.github.com>
Co-authored-by: Aidan Daly <aidandal@amazon.com>
Co-authored-by: Harrison Weinstock <hkobew@amazon.com>
Co-authored-by: aws-aditya21 <saivenki@amazon.com>
Co-authored-by: notgitika <gitijh@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@notgitika@agentcore-cli-automation@Hweinstock@avi-alpert