Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); chore: record merge point with main by notgitika · Pull Request #1237 · aws/agentcore-cli · GitHub
Skip to content

chore: record merge point with main - #1237

Merged
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2
May 13, 2026
Merged

chore: record merge point with main#1237
notgitika merged 18 commits into
previewfrom
fix/record-merge-point-v2

Conversation

@notgitika

@notgitikanotgitika commented May 13, 2026

Copy link
Copy Markdown
Contributor

Records git merge ancestry so the sync-preview workflow knows main's commits are already incorporated (via squash-merged #1226). Also includes the workflow fix from #1235 (disambiguate sync-from-public branch checkout). Merge with 'Create a merge commit'.

Hweinstockand others added 16 commits May 11, 2026 13:56
Replace secrets.PAT_TOKEN and secrets.AUTOMATION_ACCOUNT_PAT_TOKEN with
short-lived tokens generated by the agentcore-devx-automation GitHub App
(ID: 3637953) via actions/create-github-app-token@v1.
This improves security by using ephemeral tokens scoped to the
installation rather than long-lived personal access tokens.
Requires adding repo variable APP_ID=3637953 and repo secret
APP_PRIVATE_KEY with the app's RSA private key.
Add telemetry recording to the create command in both CLI and TUI paths:
- CLI: wrap handleCreateCLI with runCliCommand to emit CreateAttrs on success/failure
- TUI: wrap useCreateFlow's run() with withCommandRunTelemetry
- Add telemetry assertions to existing integration tests (frameworks + edge cases)
Replaces all occurrences of \${{ github.token }} and \${{ secrets.GITHUB_TOKEN }}
across .github/workflows/ with a per-job GitHub App token generated via
actions/create-github-app-token@v1 using vars.APP_ID and secrets.APP_PRIVATE_KEY.
fix: bump versions to resolve security audit failure
…-token
chore: replace all github.token/GITHUB_TOKEN with GitHub App token
* feat(evaluator): Add kmsKeyArn support for custom evaluator
* fix: sync package-lock.json with package.json
The lock file was out of sync after dependency bumps on main were merged,
causing npm ci to fail in CI.
* fix: revert unrelated dep bumps and fix formatting
Reverts @opentelemetry/exporter-metrics-otlp-http ^0.217.0 back to
^0.214.0 and secretlint ^13.0.0 back to ^12.2.0 — these were
accidentally included in the feature commit from unmerged dependabot PRs
and introduce high-severity protobufjs vulnerabilities.
Restores fast-xml-parser and @aws-sdk/xml-builder overrides that were
also inadvertently removed.
Fixes Prettier formatting on agentcore-project.ts import lines.
* fix: sync package-lock.json with updated dependencies
---------
Co-authored-by: notgitika <gitijh@gmail.com>
…1125)
* refactor: unify result types with discriminated Result<T, E> union
Introduce a shared Result<T, E> type (inspired by Rust's Result) that
replaces ad-hoc { success: boolean; error?: string } patterns across
the codebase.
Key changes:
- Add src/lib/types.ts with Result<T, E> discriminated union type
- Add toError() helper in src/cli/errors.ts for catch blocks
- Migrate all command, operation, and primitive result types to Result<T>
- Error field is now Error (not string) on the failure branch
- Data fields only exist on the success branch (proper narrowing)
- Update all consumers to narrow before accessing branch-specific fields
- Update test assertions to match new Error objects and add narrowing
* docs: update AGENTS.md and telemetry README to reflect Result<T, E> type
)
* feat: record command attrs on telemetry failure via fallbackAttrs
Add optional fallbackAttrs parameter to client.withCommandRun so
command-specific attributes are recorded even when the callback throws.
- client.ts: accept fallbackAttrs, use on failure instead of {}
- client.ts: run resilientParse on all non-empty attrs (not just success)
- cli-command-run.ts: withCommandRunTelemetry passes attrs as fallbackAttrs
- cli-command-run.ts: runCliCommand accepts optional knownAttrs param
- command.tsx: extract knownAttrs upfront, pass to runCliCommand
- client.test.ts: add unit tests for fallbackAttrs behavior
- create-edge-cases.test.ts: assert attrs present on failure entry
* chore: rebase onto mainline
#1078)
* fix: sync-preview workflow restores version instead of ignoring files
Instead of keeping preview's entire package.json/package-lock.json
(which discards new deps, scripts, etc. from main), accept main's
content and surgically restore only the version field to preview's
value after merge.
* fix: push directly to preview on clean merge via GitHub App bypass
Use agentcore-devx-automation app token to bypass branch protection
and push directly when the merge is clean (or only version conflicts).
Only creates a PR when there are real conflicts in other files.
* chore: use app-slug instead of app-id for token generation
* fix: address review feedback on sync-preview workflow
- Pass PREVIEW_VERSION via env var instead of string interpolation in
node -e scripts (safer against special chars)
- Make git add of package-lock.json conditional on file existence to
match the earlier -f guard
- Replace loose title search for dedup with headRefName prefix filter
to avoid false positives from unrelated PRs
- Clarify why package.json/package-lock.json are special-cased (preview
carries a different version string that needs preserving)
* fix: restore preview-owned files after sync merge
Adds a step to restore schemas/agentcore.schema.v1.json and CHANGELOG.md
to preview's versions after merging main. These files are auto-generated
during preview releases — schema-check CI rejects direct modifications
to schemas/, and CHANGELOG.md tracks preview releases separately.
* fix: use app-id instead of app-slug for GitHub App token
Aligns with the pattern in PR #1210 and ci-failure-issue.yml.
After 'git remote add public' fetches the same branches that already exist
on origin, 'git checkout <branch>' becomes ambiguous and fails with:
fatal: 'preview' matched multiple (2) remote tracking branches
Both sync jobs now use 'git checkout -B <branch> origin/<branch>' which
explicitly resets the local branch from origin's tracking ref, removing
the ambiguity and combining the previous 'checkout + reset --hard' into
one step.
Last 4 scheduled runs of 'Sync from Public Repo' all failed with this
error; the workflow has been silently broken since the public/origin
branches collided.
fix: disambiguate sync-from-public branch checkout
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — this is exactly what it claims to be: a no-op merge commit (tree identical to preview HEAD, parents = preview HEAD + main HEAD) that records ancestry between preview and main so the sync-preview workflow stops re-syncing main commits that are already incorporated via the squash-merge in #1226.

Verified:

  • git diff 99239f44..24dfc8e9 is empty (zero file changes)
  • Both parent trees resolve to the same SHA 698ddc51
  • Parents are preview tip (99239f44) and main tip (95032396)
  • This addresses the merge-base check in .github/workflows/sync-preview.yml which uses git merge-base HEAD origin/main to decide whether sync is needed

⚠️ Reminder (already in the PR description, but worth re-emphasizing because getting it wrong silently undoes the fix): this must be merged with "Create a merge commit". Squash-merging would collapse the two-parent commit into a single linear commit and lose the ancestry to main, putting us right back in the state #1226 left us in. If repo settings allow squash as the default, double-check the dropdown before clicking merge.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika

Copy link
Copy Markdown
ContributorAuthor

wait I am making a change

@notgitikanotgitika reopened this May 13, 2026
@notgitika
notgitika requested a review from a teamMay 13, 2026 19:17
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from 4a40c0c to e1dc74cCompareMay 13, 2026 19:18
@notgitika
notgitikaforce-pushed the fix/record-merge-point-v2 branch from e1dc74c to 60872bcCompareMay 13, 2026 19:19

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-approved version of this PR was a clean no-op merge commit. Since then a second commit (e1dc74c1, "fix: disambiguate sync-from-public branch checkout") has been added that cherry-picks the fix from #1235, which changes the picture. Flagging two concerns inline.

To be clear: the cherry-picked workflow change itself is correct and matches what was already approved/merged into main in #1235. The concerns are about how it's being layered into this "record merge point" PR, and a stale ancestry reference that partially defeats the stated purpose.

Comment thread.github/workflows/sync-from-public.yml
Comment thread.github/workflows/sync-from-public.yml
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.5%10019 / 23029
🔵Statements42.77%10647 / 24893
🔵Functions40.38%1691 / 4187
🔵Branches40.24%6501 / 16154
Generated in workflow #2922 for commit 3d9a8a4 by the Vitest Coverage Report Action

@notgitika
notgitika merged commit 53928e7 into previewMay 13, 2026
19 checks passed
@notgitika
notgitika deleted the fix/record-merge-point-v2 branch May 13, 2026 20:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@notgitika@tejaskash@agentcore-cli-automation@Hweinstock@aidandaly24@aws-aditya21